Luxembourg LDP LU-DPA-Breach Personal Data Breach Notification - GDPR Article 33 implementation: controller must notify CNPD within 72 hours of becoming aware where likely to result in risk to rights and freedoms + notify affected data subjects without undue delay where likely high-risk + content (nature + categories + approximate number + likely consequences + measures taken or proposed + DPO contact). CNPD online breach notification portal (operational since 2018). Sectoral parallel notifications: (a) CSSF (financial sector) under Loi du 5 April 1993 Article 23-1 + CSSF Circulars + 72-hour notification to CSSF Major Incident Reporting; (b) CAA (insurance) under Loi du 7 December 2015 + similar 72-hour notification; (c) BCE (Banque Centrale du Luxembourg) for credit institutions; (d) CIRCL (Computer Incident Response Centre Luxembourg) for cyber security incidents + voluntary reporting; (e) CSIRT Luxembourg coordination; (f) ILR (Institut Luxembourgeois de Regulation) for telecommunications; (g) NIS Directive transposition by Loi du 28 May 2019 for Operators of Essential Services + Digital Service Providers + Luxembourg National Cybersecurity Strategy 2021-2025 + High Commission for National Protection; (h) NIS2 Directive transposition Loi du 30 May 2024 effective 17 October 2024 - significantly expanded scope including financial market infrastructure + ICT service providers. Coordination with EU CSIRTs Network + EU-CyCLONE crisis cooperation + ENISA + national emergency response.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.