Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
DPO + ROPA + DPIA + Codes + Articles 4 + 9 + 50 + 69

Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) LU-LDP-Governance-DPO-Article-50-ROPA-DPIA-Codes-Article-69-CNPD-Article-4-9-Investigatory-Powers: Luxembourg LDP DPO + ROPA + DPIA + Codes + Articles 4 + 9 + 50 + 69

Luxembourg LDP Articles 4 + 9 + 50 + 69 Governance and Accountability. Article 4 CNPD Composition and Independence - 5 Commissioners appointed by Grand-Duc + 6-year term + multi-year strategic plan + Annual Report to Government + Chambre des Deputes + Belval HQ + Luxembourg financial sector cooperation. Article 9 CNPD Investigatory and Corrective Powers (GDPR Article 58 transposition) - investigations + audits + on-site inspection + access to premises + production of records + reprimands + warnings + temporary or definitive bans + processing suspension + Cross-Border data flow suspension + administrative fines + corrective orders + EU consistency mechanism participation. Article 50 Designation of the Data Protection Officer (DPO - Delegue a la Protection des Donnees) - GDPR Article 37 implementation + Luxembourg additional requirements: (a) public bodies; (b) core activities consisting of systematic monitoring on large scale; (c) core activities involving processing of special categories on large scale; (d) Luxembourg additional designation requirements: financial sector entities (banks + asset managers + investment funds + insurance companies + fintech + crypto-asset service providers + virtual asset service providers); CSSF Circular 21/787 specific DPO requirements for financial entities. DPO qualifications + Luxembourg DPO Association (ADAB - Association des Delegues a la Protection des Donnees Luxembourg) + CNPD notification within 1 month + DPO contact published + reporting to highest management + independence + sufficient resources + CSSF coordination for financial sector DPO. Records of Processing Activities (LU-DPA-RoPA - Registre des activites de traitement) - controllers and processors must maintain detailed records + provided to CNPD on request + Luxembourg simplified template available. Data Protection Impact Assessments (LU-DPA-DPIA - Analyse d'Impact relative a la Protection des Donnees - AIPD) - mandatory for high-risk processing + CNPD AIPD list (CNPD Decision 2018-2019) + financial sector specific AIPD requirements. Article 69 Codes of Conduct and Certification (Codes de conduite et certification) - voluntary CNPD-approved sectoral codes + Luxembourg Bankers Association (ABBL) Code + Luxembourg Investment Funds Industry (ALFI) Code + Luxembourg Insurance Association (ACA) Code + EU consistency mechanism for cross-border codes + ISO 27701 ISMS-P + Europrivacy + EDPB-approved schemes + certification body accreditation by ILNAS (Luxembourg Accreditation Body).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.