Enforcement & finesData subject rights
When the GDPR Clock Never Stops: Lessons from a EUR 175,000 Fine for Delayed Data Subject Responses
In a recent decision (n° 1FR/2025 of 6 January 2025), the Luxembourg National Data Protection Authority (the “CNPD”) sanctioned a major credit institution for non complying with access request’s deadlines as set by the GDPR- despite arguments of force majeure and operational challenges. The initial sanction suggested by the CNPD during the investigation phase to fine the credit institution amounted EUR 493,560 for the breach of Art. 12 (3) and (4) of the GDPR comprinsing 47 access right requests made by data subjects.
10 July 2025