CNPD (Luxembourg) - 2FR/2025

From GDPRhub
CNPD - 2FR/2025
Authority: CNPD (Luxembourg)
Jurisdiction: Luxembourg
Relevant Law: Article 5(1)(c) GDPR
Article 5(1)(e) GDPR
Article 5(1)(f) GDPR
Article 5(1)(a) GDPR
Article 5(2) GDPR
Article 6(1)(f) GDPR
Article 13(1) GDPR
Article 13(2) GDPR
Article 25 GDPR
Article 32(1) GDPR
1er août 2018 portant organisation de la Commission nationale pour la protection de données
Type: Investigation
Outcome: Violation Found
Started: 15.12.2022
Decided: 26.11.2024
Published:
Fine: n/a
Parties: Ministry
Secundary school
National Case Number/Name: 2FR/2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): French
Original Source: CNPD (in FR)
Initial Contributor: lszabo

The DPA ordered a school to bring its use of CCTV surveillance into compliance by providing more detailed information to data subjects, and by taking other steps to ensure transparency, security, and the minimisation of the processing of personal data.

English Summary

Facts

In October 2022 the DPA opened an inquiry into the video surveillance measures implemented by a secondary school (the controller).

Following two on-site inspections and an exchange of information with the controller, the DPA found the following facts:

  • video surveillance cameras operated 24/7 and stored footage for 57 days (the controller clarified that 57 days was the longest possible time the direction could take leave for the summer holidays);
  • 6 members of the technical staff had access to real-time footage through a shared account;
  • only the principal and deputy principal had access to recorded footage. Each of them accessed footage through an individual account;
  • the system did not log access to either real time footage or recordings;
  • three posters at the entrance of the school, informed the data subjects (i.e.: the people whose footage were capture) about the use of CCTV surveillance.

During the procedure, the controller stated that the legal basis for the processing of personal data, was its interest in preventing theft and vandalism. However, the DPA found that the controller did not assess the balancing of this interest with the rights and freedoms of the data subjects (i.e.: the people whose footage was captured).

Holding

First, the DPA held that the school was the controller for the processing of personal data via CCTV cameras. It did not matter that the school did not have legal personality under Luxembourgish law. In this regard, the DPA pointed out that the school could determine the purposes and means of the processing, and could freely choose its processor for installing and operating the CCTV system.

Second, the DPA observed that the controller relied on the legal basis of legitimate interest, without balancing its interest against the data subject’s. For this reason, the controller violated its accountability obligations.

Third, the DPA held that the controller violated its transparency obligation. The information posters at the entrance of the school, did not provide sufficient information about the processing of personal data. Furthermore, the controller failed to prove that it provided information orally, as it claimed during the exchange with the DPA.

Additionally, the DPA held that the controller violated the principles of data minimisation and storage limitation in several ways:

  • The field of view of the cameras inside the building, was too broad. The DPA held that the cameras should have only covered people entering or waiting to enter;
  • The cameras covered areas dedicated to free time and sports. The DPA held that this was excessive, and that cameras covering those areas should have been active only outside of school hours;
  • The DPA held that 57 days was an excessive storage period for the footage and suggested 30 days instead.


Finally, the DPA held that the controller violated the principle of security by failing to log access to the system and by allowing technical staff to access the system via a shared account.

On these bases, the DPA held that the data controller violated Articles 51(1)(a),5(1)(c), 5(1)(e), 5(2), 13(1), 13(2), 32(1) GDPR.

The DPA ordered the controller to bring its use of CCTV into compliance within three months. In particular, the DPA prescribed the following steps:

  • providing all the necessary information to data subjects (either via a single document, or through a layered privacy notice[1])
  • limiting the field of vision of the cameras to what was strictly necessary, to prevent theft and vandalism
  • limiting the retention time for CCTV footage to 30 days;
  • setting up individual accounts for the technical staff;
  • setting up an access and event logging system for the CCTV system, and periodically examining the system logs to detect anomalies.

Comment

The decision spells out the requirements for video surveillance following from the principles of lawfulness, transparency, data minimisation, storage limitation and security. In this regard, the DPA consistently refers to EDPB guidance through the decision (see, in particular, EDPB, 'Guidelines 3/2019 on processing of personal data through video devices', 29 January 2020 (version 2.0), available here).

The "second layer" of information mentioned by the DPA, is discussed extensively in those guidelines. In certain cases (including the use of CCTV surveillance), a data controller may provide a privacy notice containing only very essential information, as well as a "link" to a deeper layer of information (for instance, via a hyperlink, a web address, or a QR code to scan). In certain scenarios, the EDPB suggests layered notices as a way for the controller to provide information in a way that is both accessible, and comprehensive enough to cover all the required information under Article 13 GDPR.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the French original. Please refer to the French original for more details.

Decision of the National Commission sitting in restricted session on

the outcome of investigation no. […] conducted with the Ministry […] on the Lycée site

[…]

Deliberation no. 2FR/2025 of March 26, 2025

The National Commission for Data Protection sitting in restricted session,

composed of Ms. Tine A. Larsen, Chair, Mr. Marc Lemmer, Commissioner, and
Mr. Marc Hemmerling, alternate member;

Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on

the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;

Having regard to the Law of August 1, 2018, establishing the organization of the National Commission for Data Protection

Having regard to the internal regulations of the National Commission for Data Protection

adopted by Decision No. 07AD/2024 dated February 23, 2024, in particular Article 10, paragraph 2 thereof;

Having regard to the regulations of the National Commission for Data Protection relating to the

investigation procedure, adopted by Decision No. 08AD/2024 dated February 23, 2024, in particular Article 9 thereof;

Considering the following:

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome
of investigation no. […] conducted with the Ministry […] on the site of the Lycée […]
1/27I. Facts and Procedure

1. At its deliberation meeting on October 21, 2022, the National Commission for Data Protection (hereinafter: the "CNPD" or the "National Commission"), sitting in plenary session, decided to open an investigation with the Ministry

[…] on the Lycée […] site, based on Article 38 of the Law of August 1, 2018, establishing the organization of the National Commission for Data Protection and the general regime

on data protection (hereinafter: the "Law of August 1, 2018"), and to appoint Mr.

Alain Herrmann as head of the investigation. 2. The said decision specified that the purpose of the investigation conducted by the CNPD was

to monitor the application and compliance with Regulation (EU) 2016/679 of the European Parliament and

of the Council of 27 April 2016 on the protection of natural persons with regard to the

processing of personal data and on the free movement of such data, and

repealing Directive 95/46/EC (hereinafter: the "GDPR") and the Law of 1 August 2018, and "the
compliance of any surveillance measures implemented by the Ministry […] and

the Management of the said establishment, where applicable, by means of a video

surveillance system."

3. The Ministry […], located in […], […], is a government administration […]

(hereinafter: the "Ministry").

4. The Lycée […] located in […], […] (hereinafter: the "Lycée"), is an educational institution
2
administered as a separately managed state department, without legal personality, but enjoying administrative and financial autonomy under the supervision of the Ministry […].

5. On December 15, 2022, CNPD agents conducted an on-site visit to the Lycée site (hereinafter: the "on-site visit"). This moment is referred to

subsequently in this decision as the "start of the investigation".

1Deliberation No. […] of October 21, 2022 of the National Commission for Data Protection relating to the opening of an investigation mission with the Ministry […] on the Lycée site […]. 2Under Article 29 of the Law of April 26, 2024, concerning the State revenue and expenditure budget for the 2024 financial year, "[…]".
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […]
2/27 6. By email dated December 20, 2022, the Lycée provided the CNPD with

additional information requested during the on-site visit.

7. Report No. […] relating to the on-site visit carried out on December 15, 2022, on the Lycée’s site (hereinafter: the “report”), drawn up by CNPD officials, was sent to the person audited by mail dated December 22, 2022, along with

a request for additional information.

8. It follows from this report that:

- the video surveillance system within the school grounds consists of 12 cameras,

including 8 fixed cameras and 4 dome cameras (hereinafter: the "video surveillance system");

- the video surveillance system operates continuously (24 hours a day) and has night vision but only records when movement is detected within the field of vision;

- the images from the video surveillance system can be viewed in real time

by the six members of the school's technical team "from computers installed in

boxes A and B." However, these individuals do not have access to the images from the aforementioned system.

Access to the images recorded by the system is reserved exclusively for the

principal and the deputy principal of the school in the event of suspicion or problems. 5

The persons inspected did not make any comments regarding the report.

9. On January 26, 2023, the CNPD sent a supplementary questionnaire to the Ministry.

10. Following several reminders regarding the response to the supplementary questionnaire, the Ministry finally responded the same day. 7

3
Report, Finding 1.
4Report, Finding 9.
5Report, Finding 13.
6
7[…].
Statement of Objections, Exhibit No. 1.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée site […] 3/27 11. On July 27, 2023, additional inspections were carried out on the Lycée site by CNPD agents (hereinafter: "the additional inspections").

12. Report No. […] relating to the on-site visit carried out on July 27, 2023 on the Lycée site (hereinafter: the "second report") drawn up by CNPD agents was sent to the person being inspected by mail dated July 31, 2023. On July 28, 2023, a request for additional information was sent to the Lycée. 13. The second report shows that:

- the security system for the access door to Building A is protected by a locked door.

The security system for the access door to Building B is protected by an access badge system.

8
- access to the technical room housing the hard drive containing recordings from the video surveillance system in the basement of Building B is protected by a locked door.

14. On September 5, 2023, the Lycée submitted observations regarding the second report and responded to the request for additional information on September 21.

15. Following his investigation, the head of investigation notified the Ministry on

June 6, 2024, of a statement of objections (hereinafter: the "initial statement of objections")
detailing the failures he considered to have occurred in this case with respect to the requirements

prescribed by Article 5.2 of the GDPR (principle of accountability), Articles 13.1 and 13.2 of the GDPR

(right to information), Article 5.1.a) of the GDPR (principle of transparency), Article 25.2 of the

GDPR (obligation to minimize the data processed in relation to the purpose pursued),

Article 25.2 of the GDPR (principle of limitation of retention), and Article 32.1 of the GDPR
(obligation of security of processing).

The head of the investigation proposed to the National Commission sitting in a restricted session (hereinafter: the "Restricted Session") the adoption of five different corrective measures.

The Ministry was given the opportunity to submit its written comments on the statement of objections. 8Second Minutes, Point G.
9Second Minutes, Point G.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […]
427 16. By letter dated July 26, 2024, the Ministry provided its observations

regarding the initial statement of objections, contesting its status as data controller.10

17. On August 1, 2024, the head of investigation endorsed the Ministry's interpretation

regarding the reclassification of the data controller. Thus, a second statement

of objections dated August 8, 2024, was sent to the Lycée (hereinafter: "the statement of

objections"). The school was given the opportunity to submit its written observations on the statement of grievances, but did not submit any observations to the head of the investigation.18. The head of investigation referred the case to the Restricted Panel for a decision on the outcome of the investigation.

19. The chair of the Restricted Panel informed the persons being investigated by letter dated October 2, 2024, that the case would be scheduled for the Restricted Panel meeting on November 26, 2024, and that they would be given the opportunity to be heard.

20. The persons being investigated indicated that they would not attend this invitation from the Restricted Panel.

21. During this meeting, the head of investigation presented his oral observations in support of his written observations and answered questions posed by the Restricted Panel.

22. The decision of the Restricted Panel on the outcome of the investigation will be based on:

- the processing carried out by the persons inspected, taken into account by the head of the investigation in

his statement of objections; and

- the relevant legal and regulatory provisions.

10
Statement of Objections, Exhibit No. 77.
________________________________________________________________________

Decision of the National Commission sitting in Restricted Panel on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […]
527II. In Law

II.1. On the grounds for the decision

A. On the quality of the audits and the determination of the controller

1. On the principles

23. In accordance with Article 4.7 of the GDPR, the controller is "the

natural or legal person, public authority, agency or other body which, alone

or jointly with others, determines the purposes and means of the processing [...]".

24. The European Data Protection Board (hereinafter: the "EDPB"),

in its Guidelines 07/2020 on the concepts of controller and processor, specifies that "in principle, there are no limits to the type of entity that may

11
assume the role of controller".

25. The EDPB further states that the concept of controller is a functional concept and that "it is therefore based on a factual rather than a formal analysis. […]

In most cases, the "determining body" can be easily and clearly identified
by reference to certain legal and/or factual circumstances from which "influence" can normally be inferred, unless other elements indicate otherwise." 12

26. Finally, the EDPB specifies that "[i]n the absence of control resulting from legal provisions, the designation of a party as controller must be established based on an assessment of the factual circumstances surrounding the processing. All relevant factual circumstances must be taken into account to determine whether a given entity exercises decisive influence over the processing of personal data in question." 13

11 EDPB, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, Version 2.0, adopted on July 7, 2021, page 3.

EDPB, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, Version 2.0, adopted on July 7, 2021, point 21, page 12.

13 EDPB, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, Version 2.0, adopted on July 7, 2021, point 25, page 13.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […]
6/272. In this case,

27. During the on-site visit, the school stated that "the Ministry was not

involved in the implementation of the video surveillance system and that the decision was made

by the school administration in its capacity as head of the school, the latter enjoying a

certain autonomy in implementing the means deemed adequate to fulfill its

various missions."4

28. Furthermore, the school further stated during the on-site visit that "the school administration

chose the service provider responsible for installing the video surveillance system, approved the

service provider's estimate, and financed the system from the school's own budget (EXHIBIT 01, cf.
Q4, Q8, Q16, pp. 6-8). The School Principal also stated that the School administration,

either alone or in consultation with the service provider, decided on the operating procedures

of the system, the installation location, the field of vision, the operating hours and

camera settings, as well as the retention period for data collected using the cameras (EXHIBIT 01, see Q9-Q14, pp. 6-7).

29. The Restricted Committee considers that the School should be classified as the "data controller" within the meaning of Article 4.7 of the GDPR, even though it follows from the above that it

determined the means and purposes of the processing of personal data resulting from the video surveillance system. B. On the breach of the accountability principle (Article 5.2 of the GDPR)

1. On the principles

30. Article 5.2 of the GDPR provides that "[t]he controller shall be responsible for ensuring compliance with paragraph 1 and shall be able to demonstrate compliance with it (accountability)." Paragraph 1 of the said article provides, in particular, that "[p]ersonal data must: (a) be processed lawfully, fairly, and in a transparent manner with regard to the data subject (lawfulness, fairness, transparency)."

31. Recital 74 of the GDPR states, in particular, that "[i]t is important, in

particular, that the controller be required to implement appropriate and effective measures

14Statement of Objections, point 12.
15Statement of Objections, point 13.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with the Ministry […] on the Lycée […]
727 site and be capable of demonstrating the compliance of processing activities

with this Regulation, including the effectiveness of the measures."

32. Furthermore, the Court of Justice of the European Union (hereinafter: the “CJEU”)

states that “[u]nder Article 5(2) of the GDPR, the controller, in accordance with the principle of “accountability” set out in that provision, is

responsible for compliance with Article 5(1) and must be able to demonstrate

compliance with each of the principles set out in that paragraph 1, the burden of proof being
16
on the controller.”

33. Article 6.1(f) of the GDPR provides that “processing is necessary for the purposes

of the legitimate interests pursued by the controller or by a third party, except where

the interests or fundamental rights and freedoms of the data subject which

require protection of personal data, in particular where the data subject

is a child, are overridden.”

34. Recital (47) of the GDPR states, in particular, that "the legitimate interests

of a controller (...) may constitute a legal basis for processing,

unless the interests or fundamental rights and freedoms of the data subject

override, taking into account the reasonable expectations of data subjects based on their
relationship with the controller."

35. Thus, as noted by the CJEU, Article 6.1(f) of the GDPR

"provides for three cumulative conditions for the processing of personal data to which it refers to to be lawful, namely, first, the pursuit of a legitimate interest

by the controller or a third party; second, the necessity of the processing

of personal data for the purposes of the legitimate interest pursued; and,

third, the condition that the interests or fundamental rights and freedoms of the data subject do not prevail over the legitimate interest of the

controller or a third party."7

16Judgment of the CJEU of 4 May 2023, UZ v. Bundesrepublik Deutschland, C-60/22, ECLI:EU:C:2023:373, paragraphs 53 and 54.

17 Judgment of the CJEU of 17 June 2021, M.I.C.M., C-597/19, EU:C:2021:492, paragraph 106 and case law cited,
Judgment of the CJEU of 4 July 2023, Meta v. Bundeskartellamt. C-252/21, ECLI:EU:C:2023:357), paragraph 106.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with the Ministry […] on the site of the Lycée […]
827 36. Consequently, under the principle of accountability, the controller

who bases its processing on the legal basis of legitimate interest must be able

to prove that the aforementioned cumulative conditions are met. Thus, it is
incumbent on the controller, in particular, to demonstrate that the balancing test was carried out

appropriately and that the interests or fundamental rights and freedoms of the data subject

do not outweigh the legitimate interests it pursues.2. In this case

37. During the on-site visit, the school informed the CNPD officers that the lawful basis for the processing implemented by the video surveillance system was its legitimate interest, namely access control and the protection of property with a view to detecting break-ins, thefts, and/or vandalism.

38. The school also stated that no balancing exercise had been carried out between its legitimate interests and the interests or fundamental rights and freedoms of the data subjects.

By acting in this way, the school failed to comply with one of the three cumulative conditions set out in point 35 above, namely carrying out the balancing test and demonstrating that the interests or fundamental rights and freedoms of the data subject do not outweigh the legitimate interests it pursues. The Lycée was therefore unable
to provide proof that this condition was met. However, this burden of proof falls on it pursuant to Article 5.2 of the GDPR.

39. Therefore, the Restricted Committee agrees with the head of the investigation and considers

that non-compliance with Article 5.2 of the GDPR was established on the day of the on-site visit by

CNPD officials.

18 Minutes, Finding 6.
19 Minutes, Finding 6.

________________________________________________________________________

Decision of the National Commission sitting in Restricted Committee on the outcome
of investigation no. […] conducted with the Ministry […] on the Lycée […]
9 27C. On the breach of the principle of transparency (Article 5.1.a) of the GDPR) and the information obligations (Articles 13.1 and 13.2 of the GDPR)

1. On the principles

40. Providing data subjects with information relating to the processing of their data is an essential element in complying with the general transparency obligations under the GDPR.

41. Indeed, pursuant to Article 5.1.a) of the GDPR, personal data must be processed, among other things, in a transparent manner with regard to data subjects (transparency principle). Article 12 of the GDPR provides that "the controller shall take appropriate measures to provide the data subject with any information referred to in Articles 13 and 14 (...) concerning the processing in a concise, transparent, intelligible, and easily accessible manner."

42. Furthermore, when requested by the data subject, the information
20
may be provided orally. The Article 29 Working Party Guidelines on

Transparency under Regulation (EU) 2016/679, adopted on 11 April 2018, state
that "[t]he controller should (…) ensure that it keeps a written record, and

ensure that it is able to demonstrate (for the purposes of compliance with the accountability requirement), of: (i) the oral request for information, (ii) the method by which

the identity of the data subject was verified (…) and (iii) the fact that the information was
21
provided to the data subject."

43. Article 13 of the GDPR provides as follows:

"1. When personal data relating to a data subject are collected from that data subject, the controller shall provide them, at the time

the data in question are obtained, with all the following information:

a) the identity and contact details of the controller and, where applicable, of the

controller's representative;

20Article 12.1 of the GDPR.
21Guidelines of the Article 29 Working Party on Transparency within the meaning of Regulation (EU) 2016/679,
adopted on April 11, 2018, point 21.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome
of investigation no. […] conducted at the Ministry […] on the Lycée […]
10 27b) where applicable, the contact details of the Data Protection Officer; (c) the purposes of the processing for which the personal data are intended and

the legal basis for the processing;

(d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued

by the controller or by a third party;

(e) the recipients or categories of recipients of the personal data,
if any; and

(f) where applicable, the fact that the controller intends to transfer

personal data to a third country or an international organization, and

the existence or absence of an adequacy decision issued by the Commission or, in the
case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1),

a reference to the appropriate or suitable safeguards and the means of obtaining a copy or

the location where they have been made available;

2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject, at the time the personal data are obtained, with the following additional information necessary to ensure fair and transparent processing:

a) the period for which the personal data will be stored or, where this is not possible, the criteria used to determine that period;

b) the existence of the right to request from the controller access to, rectification or erasure of, or restriction of processing of, personal data relating to the data subject, or the right to object to processing and the right to data portability;

(c) where processing is based on Article 6(1)(a) or Article 9(2)(a), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal;

(d) the right to lodge a complaint with a supervisory authority;

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted at the Ministry […] on the Lycée […]

11/27e) information on whether the requirement to provide personal data is regulatory or contractual or whether it is a condition for entering into a contract and whether the data subject is required to provide the personal data, as well as the possible consequences of failure to provide such data;

(f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4), and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

3. Where the controller intends to carry out further processing of personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject with information about that other purpose and any other relevant information referred to in paragraph 2 in advance.

4. Paragraphs 1, 2, and 3 shall not apply where and to the extent that the data subject already has such information.

44. Finally, in its Guidelines 3/2019 on the processing of personal data by video devices, the EDPB provides clarification on the methods for providing the aforementioned information. It states that "in light of the volume of information to be provided to the data subject, the controller may adopt a multi-layered approach, choosing to use several methods to ensure transparency (WP 260, paragraph 35, P 89, paragraph 22). With regard to video surveillance, the most important information should be displayed on the warning sign itself (first level), while other mandatory details may be provided by other means (second level)." 22EDPB Guidelines 3/2019 on the processing of personal data for video devices, adopted on 29 January 2020.
23EDPB Guidelines 3/2019 on the processing of personal data for video devices, adopted on 29 January 2020, point 11.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with the Ministry […] on the site of the Lycée […]
12/272. In this case

45. During the on-site visit, the CNPD officers noted that the only

signage posted at the entrances to Lycée 24 regarding video surveillance consisted of

three signs featuring a camera pictogram and the words "area under video surveillance," with no other information. 25

46. However, the Restricted Committee recalls that the CNPD's guidelines on video surveillance state that "[i]n order to inform data subjects of

the presence of a video surveillance system, the CNPD recommends communicating, for example

via notice boards, a first level of information containing:

the identity and contact details of the data controller; the purpose(s) of the processing;

the existence of the rights available to data subjects; a statement that

more comprehensive information exists (second level of information) and the means of accessing it (for example,

a hyperlink to the data controller's website, the use of a QR code, a telephone number to call, or an indication of the location where this

more detailed information is available."47. The Restricted Committee therefore notes that the first-level information (the

signs), as observed on the day of the on-site visit, did not include any of the

abovementioned information, nor did it refer to a second-level document containing the

missing information.

48. Furthermore, the Lycée stated during the on-site visit that information

regarding video surveillance had been provided orally to students and teaching staff.

49. According to the Lycée, this information had been provided to students by the class regents,

as reflected in their administrative duties. However, the Restricted Committee

agrees with the opinion of the Head of Investigation, who "believes that the extract of administrative tasks does not

24
Statement of Objections, point 40, Exhibits 45 to 47, Exhibits 48 and 23, and Exhibits 49 and 50.
25Statement of Objections, point 40, Minutes, Finding 20.
26 CNPD Guidelines on Video Surveillance: https://cnpd.public.lu/fr/dossiers-
thematiques/surveillance/videosurveillance.html.
27
28Statement of Objections, points 41 to 42, Exhibits 51 to 54.
Statement of Objections, point 41, Exhibits 51 and 52.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée website […] 13/27 does not demonstrate that information within the meaning of the GDPR was actually provided

to students."9

50. Regarding information provided to teaching staff, the Lycée

still fails to provide proof of any information. The latter having stated

that it had no record of such communication. In any event, a simple oral statement from the school would not have been sufficient to prove that the requirements of the GDPR were complied with.32

51. Furthermore, no information appears to have been provided regarding the persons

concerned outside the school (e.g., parents) other than students

or teaching staff.33

52. Thus, in the absence of any form of information, the Restricted Committee

considers that the school failed to comply with the requirements of Articles 5.1.a), 13.1, and 13.2 of the GDPR.

53. Furthermore, the school fails to demonstrate that the oral provision of this information

was requested by the persons concerned, in violation of Article

12.1 of the GDPR. 34

54. In view of the above, the Restricted Committee agrees with the opinion of the head of investigation

and concludes that non-compliance with Article 5.1.a) linked to Articles 13.1 and 13.2 of the GDPR

was established on the day of the on-site visit by CNPD officials.

D. On the breach related to the principle of data minimization (Article 5.1.c) of the GDPR)

and the obligation of data protection by default (Article 25.2 of the GDPR)

1. On the principles

55. Article 5.1.c) of the GDPR provides that "[p]ersonal data

must be adequate, relevant, and limited to what is necessary in relation to the purposes

for which they are processed (data minimization)." Recital (39) of

29 Statement of Objections, point 41.
30
Statement of Objections, point 42, Exhibits Nos. 53 and 54.
31 Statement of Objections, point 42; email from the Lycée dated December 21, 2022.
32 Statement of Objections, point 42.
33 Minutes, Finding 21.
34
Article 12.1 of the GDPR.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with the Ministry […] on the Lycée website […] 14/27 GDPR specifies that "personal data should only be processed if the

purpose of the processing cannot reasonably be achieved by other means."

56. The aforementioned Guidelines 3/2019 on the processing of personal data for video devices state that "[b]efore installing a video surveillance system, the controller should always critically assess whether the measure is, on the one hand, appropriate to achieve the intended purpose and, on the other hand, adequate and necessary for that purpose. Video surveillance measures should be used only if the purpose of the processing cannot reasonably be achieved by means less likely to adversely affect the fundamental rights and freedoms of the data subjects."

57. As for the principle of data protection by default detailed in Article 25.2 of the GDPR, this requires the adoption of measures limiting processing by default to what is strictly necessary. 36
58. In its Guidelines 4/2019 relating to Article 25 of the GDPR, the EDPB
specifies that "[i]n its common definition in IT, the term 'default' refers

to the pre-existing or pre-selected value of a configurable parameter that is

assigned to a software application, a computer program, or a computing device.

These settings are also referred to as 'presets' or 'factory settings,'
37
particularly for electronic devices."

59. The EDPB then clarifies that "the term 'by default', in the context of the

processing of personal data, means making choices regarding

configuration values or processing options defined or prescribed in a
processing system, such as a software application, service, or device, or a

manual processing procedure, which affect the amount of personal data

35
EDPB Guidelines 3/2019 on the processing of personal data for video devices, adopted on 29 January 2020, point 24.
36
EDPB Guidelines 4/2019 on Article 25, Data Protection by Design and Data Protection by Default, Version 2.0, adopted on 20 October 2020.
37
EDPB Guidelines 4/2019 on Article 25, Data Protection by Design and Data Protection by Default, Version 2.0, adopted on October 20, 2020, point 40.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […]
15/27 collected, the scope of their processing, the duration of their retention, and their
accessibility."

2. In this case

60. It should be noted that the Lycée implemented a video surveillance system

for access control purposes and for the protection of property in order
39
to detect break-ins, thefts, and/or vandalism. This system operated
40
permanently, including during the Lycée's opening hours.

61. During the on-site visit, CNPD officers noted that the fields of vision

of the INNENHOF 41 and EINGANG TURNHALLE 42 cameras included entrances
43
but also areas intended for leisure and sports, […].

62. The Restricted Committee agrees with the head of the investigation in that it

considered that "the living and leisure areas of a school, where students,

teachers, and staff are likely to spend their breaks and can move freely between class periods, such as the schoolyard, a sports field

or a cafeteria, should not, in principle, be subject to video surveillance measures
44
during school opening hours" and considered that "the surveillance

of students, teachers, and staff in areas intended for leisure time

and sports, […], is, in principle, disproportionate to the purposes pursued by the

Controller and constitutes an excessive invasion of the privacy of
45
students."

63. Thus, with regard to access control, the Restricted Committee recalls that

"[c]ameras intended to monitor an access point (entrance and exit, threshold, steps, door,

awning, hall, etc.) must have a field of vision limited to the area strictly necessary."

38EDPB Guidelines 4/2019 relating to Article 25, Data Protection by Design and Data Protection by Default, Version 2.0, adopted on 20 October 2020, paragraph 41.
39
Minutes, Finding 5, Finding 6; Statement of Objections, paragraph 51, Exhibit No. 55.
40Minutes, Finding 9.
41Statement of Objections, Exhibit No. 10.
42
43Statement of Objections, Exhibit No. 09.
Minutes, Finding 17.
44 Statement of Objections, point 58.
45 Statement of Objections, point 59.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée site […]
16/27 to view people preparing to access it." Therefore, it notes, like the head of the investigation, that it was not necessary to include the Lycée's living and leisure areas within the field of vision of the aforementioned cameras.64. Regarding the protection of property, the Restricted Committee agrees with the opinion

of the Head of Investigation and considers that the School has not demonstrated why it would have been

necessary to film living and leisure areas during the School's opening hours.

65. In any event, the Restricted Committee reiterates that "[t]he principle of

necessity implies, first of all, that a data controller must only use a

video surveillance system when there are no alternative means less

invasive of the privacy of the data subjects to achieve the desired purpose." Therefore, it considers, like the Head of Investigation, that during the School's opening hours, the School could have implemented alternative means, such as

staff supervision. 49

66. With regard to the complaint under Article 25.2 of the GDPR raised by the head of investigation in his statement of objections, the Restricted Committee is of the opinion that it is

not in possession of sufficient technical details regarding the specific presets of the video surveillance system to allow it to conclude that the principle of data protection by default as such was not respected. It follows that it is unable

to find a failure to comply with the obligation of data protection by default under Article

25.2 of the GDPR.

67. In view of the foregoing, the Restricted Committee concludes that non-

compliance with Article 5.1.c) of the GDPR existed on the day of the on-site visit by CNPD officials.

46 CNPD Guidelines on Video Surveillance:

https://cnpd.public.lu/content/dam/cnpd/fr/dossiers-thematiques/videosurveillance/cnpd-lignes-directrices-
47dosurveillance-2024.pdf.
Statement of Objections, point 60.
48 CNPD Guidelines on Video Surveillance:
https://cnpd.public.lu/content/dam/cnpd/fr/dossiers-thematiques/videosurveillance/cnpd-lignes-directrices-
vidosurveillance-2024.pdf.
49
Statement of Objections, point 61.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Investigation No. […] conducted with the Ministry […] on the site of the Lycée […] 17 27E. On the breach of the principle of data retention limitation (Article

5.1.e) of the GDPR) and the obligation of data protection by default (Article 25.2 of the GDPR)

1. On the principles

68. Under Article 5.1.e) of the GDPR, "[p]ersonal data

must be kept in a form which permits identification of data subjects

for no longer than necessary in relation to the purposes for which

they are processed."

69. According to recital (39) of the GDPR, the principle of data retention limitation requires, in particular, "to ensure that the retention period of data is

limited to the strict minimum (...) In order to ensure that data are not kept longer

than necessary, time limits should be set by the controller

for their erasure or for periodic review."

70. The CNPD guidelines on video surveillance state that "images may be stored in principle for up to 8 days. The data controller may exceptionally store the images for 30 days.

However, the reasons justifying such a storage period must be indicated in the processing register."

71. Regarding the principle of data protection by default, please refer to points 57 to 59 of this decision.

2. In the present case

72. During the on-site visit, CNPD officers noted that the video surveillance system was equipped with a recording function and that the oldest video recordings dated from October 19, 2022. On the day of the on-site visit, the images had therefore been stored for 57 days.

50. Report, Finding 19; Statement of Objections, point 69, Exhibits Nos. 56 to 61.
51 Minutes, Finding 19; Statement of Objections, point 69, Exhibits Nos. 56 to 61.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée site […]
18 27 73. The Lycée argues that the installation form for the video surveillance system

provided for a 30-day retention period for images. The Lycée further argues

that this period corresponds to "the maximum length of absence of members of the

management during the summer break. Upon a member of the management returning from vacation, it would
53
always be possible to review the incidents that occurred during our absence."

74. The Restricted Committee agrees with the head of investigation in that he held that "a

period of 57 days is largely disproportionate given the purpose of the Processing (access control and protection of property), as a break-in or theft could be detected in the short term by a reasonably diligent data controller."

75. Regarding the 30-day retention period, the Restricted Committee reiterates that "[t]he longer the retention period set (...), the more it is appropriate
to develop the reasoning justifying the legitimacy of the purpose pursued and the necessity
of the retention period." It agrees with the Head of Investigation in that he considers that in

this case, "extended school holiday periods" may justify the use of a longer

retention period due to the absence of staff, in this case the

members of management authorized to review the recordings. Indeed, the Head of Investigation is

of the opinion that the specific circumstances "may justify, in this case, the retention of the
56
video recordings for a maximum period of 30 days."

76. With regard to the complaint under Article 25.2 of the GDPR raised by the Head of Investigation in his

statement of objections, the Restricted Committee is of the opinion that it is

not in possession of sufficient technical details on the specific presets of the

video surveillance system to allow it to conclude that the principle of data protection by default as such has not been respected. It follows that it is unable

to establish a failure to comply with the obligation of data protection by default under Article

25.2 of the GDPR. 52
Statement of Objections, paragraph 71, Exhibits Nos. 53 and 55.
53Statement of Objections, paragraph 72, Exhibit No. 52
54Statement of Objections, paragraph 70.
55
EDPB Guidelines 3/2019 on the processing of personal data for 56déo devices, adopted on January 29, 2020, paragraph 121.
Statement of Objections, paragraph 74, Exhibit No. 52
________________________________________________________________________

Decision of the National Commission sitting in Restricted Composition on the outcome of
Investigation No. […] conducted with the Ministry […] on the site of the Lycée […] 19/27 77. In view of the above, the Restricted Composition concludes that non-compliance with Article 5.1.e) of the GDPR was established on the day of the on-site visit by CNPD officials.

F. On the breach related to the security of processing (Article 32.1 of the GDPR)

1. On the principles

78. Article 32.1 of the GDPR provides that "[t]aking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, as well as the risks, the likelihood and severity of which vary, to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (...)" and in particular "means to restore the availability of and access to personal data within an appropriate timeframe in the event of a physical or technical incident" and "a procedure for regularly testing, analyzing, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing."

79. Article 32.2 of the GDPR provides that "[w]hen assessing the appropriate level of security, particular account shall be taken of the risks posed by processing, in particular resulting from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data transmitted, stored, or otherwise processed."

80. The EDPB, in its aforementioned Guidelines 3/2019, specifies that "[a]ccess control ensures that only authorized persons can access the system and data (...)." The CNPD's guidelines on video surveillance state that "access to data must be

secured (for example, by using a strong password and username) and each person

accessing the data must have an individual access account. An access log

must also be available so that it is possible to trace the persons who

57
EDPB Guidelines 3/2019 on the processing of personal data for video devices, adopted on 29 January 2020, point 135.
________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée site […]
20 27 accessed the data, as well as the data consulted by these persons, in the event
58
of abuse."

2. In this case

81. It emerged from the first on-site visit that the images captured by the video

surveillance system could be viewed in real time by the six members of the Lycée's technical team

from the computers installed in lodges A and B. The members

of the technical team therefore only had access to the images in real time.

Only the Lycée's principal and deputy principal had access to the recorded images

via an individual user account. 61

82. Furthermore, each member of the technical team had individual access

to the computer but accessed the video surveillance system's operating software via a shared

account. Indeed, the head of the investigation noted that access to the video surveillance system's operating software

is secured by a username and password shared by all six members of the technical team, who thus use a single user

account."

83. Furthermore, the CNPD officers noted during the on-site visit that

access to Lodges A and B is physically secured by a locked door, as well

as by a door secured by an access badge system. 64

84. Finally, during the on-site visit, the Lycée stated that no traceability of
65
access to the video surveillance system's operating software was possible.

85. Like the head of the investigation, the Restricted Committee considers that access to a

video surveillance device via software must, in principle, be secured by means of

individual user accounts that allow for good traceability of access and actions.

58
CNPD Guidelines on Video Surveillance:
https://cnpd.public.lu/content/dam/cnpd/fr/dossiers-thematiques/videosurveillance/cnpd-lignes-directrices-
vidosurveillance-2024.pdf.
59 Statement of Objections, paragraph 80; Minutes, Finding 12.
60
Statement of Objections, point 83.
61 Statement of Objections, point 83.
62 Statement of Objections, point 81.
63
Statement of Objections, point 82.
64 Statement of Objections, point 84.
65 Statement of Objections, point 85, Minutes, Finding 25.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […]
21/27 site on the system, such as, for example, the deletion or modification of video recordings. Furthermore, a password, in accordance with the basic rules relating to the

security of information systems, must, to be effective, remain secret and individual.

This rule is not respected in the case of a shared account. 86. Consequently, the Restricted Committee finds that in order to comply with the requirements of Article 32.1 of the GDPR, the School must implement a system for

logging access and events, as well as a periodic review of log files to detect potential anomalies and ensure that members of the School's

technical team authorized to access the video surveillance system each have an individual account with a specific password to access the operating software

for said system.

87. In view of the above, the Restricted Committee concludes that non-compliance with Article 32.1 existed on the day of the on-site visit by CNPD officials.

II.2. On the administrative fine and corrective measures

1. On the principles

88. In accordance with Article 12 of the Law of August 1, 2018, the National Commission

has the powers provided for in Article 58.2 of the GDPR:

"a) warn a controller or processor that the proposed processing operations may infringe the provisions of this Regulation;

b) reprimand a controller or processor when the processing operations have resulted in a violation of the provisions of this Regulation;

c) order the controller or processor to comply with requests made by the data subject to exercise their rights under this Regulation;

d) order the controller or processor to bring the processing operations into compliance with the provisions of this Regulation, where applicable, in a specific manner and within a specified time period;

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted at the Ministry […] on the Lycée […]
22 27e) order the data controller to notify the data subject of a

personal data breach;

f) impose a temporary or permanent restriction, including a ban, on processing;

g) order the rectification or erasure of personal data or the restriction

of processing pursuant to Articles 16, 17, and 18 and the notification of these measures to the

recipients to whom the personal data have been disclosed pursuant

to Article 17(2) and Article 19;

h) withdraw a certification or order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or order the certification body not to issue a certification if the requirements applicable to the certification are not or no longer met;

i) impose an administrative fine pursuant to Article 83, in addition to or instead of the measures referred to in this paragraph, depending on the specific characteristics of each case;

j) order the suspension of data flows addressed to a recipient located in a third country or to an international organization.

89. In accordance with Article 48 of the Law of August 1, 2018, the CNPD may impose administrative fines as provided for in Article 83 of the GDPR, except against the State or municipalities. 90. The Restricted Committee wishes to clarify that the facts taken into account in the context of this decision are those observed at the beginning of the investigation. Any subsequent changes to the data processing under investigation, even if they allow for full or partial compliance to be established, do not allow for the retroactive cancellation of an observed breach.

91. However, the steps taken by the person being investigated to comply with the GDPR during the investigation procedure or to remedy the breaches noted by the head of investigation in the statement of objections are taken into account.

66
See Trib. adm., May 14, 2024, No. 46401 of the docket, page 27, paragraphs 1 and 2.
________________________________________________________________________

Decision of the National Commission sitting in a restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the site of the Lycée […]
23/27 taken into account by the Restricted Session in the context of possible corrective measures to be issued.

2. In this case

92. In the statement of objections, the head of investigation proposed that the Restricted

Committee adopt the following corrective measures within "a period of 3 months from
notification of the decision" taken by the Restricted
Committee to the High School:

a) "call the Data Controller to order, within the meaning of Article 58.2 b)

of the GDPR, regarding its obligation to respect the principle of accountability

arising from Article 5.2 of the GDPR";

b) "order the Processing to be brought into compliance, within the meaning of Article 58.2 d) of the
GDPR, regarding the violation of the obligation to inform data

data subjects arising from Article 5.1 a) of the GDPR in conjunction with

Articles 13.1 and 13.2 of the GDPR";

c) "order the processing to be brought into compliance, within the meaning of Article 58.2 d) of the GDPR, with regard to the violation of the obligation to minimize the data processed in relation to the purpose pursued, arising from Article 25.2 of the GDPR";

d) "order the processing to be brought into compliance, within the meaning of Article 58.2 d) of the GDPR, with regard to the violation of the obligation to limit data retention, arising from Article 25.2 of the GDPR";

e) "order the processing to be brought into compliance, within the meaning of Article 58.2 d) of the GDPR, with regard to the violation of the obligation to implement appropriate technical and organizational measures, arising from Article 32.1 of the GDPR."93. As for the classification proposed by the head of investigation, set out in point 92(a) of this decision, the Restricted Committee considers, in light of the above, that the violation of Article 5.2 of the GDPR is proven and that it is therefore appropriate to uphold the breach as proposed by the head of investigation in this regard and set out in point 92(a) of this decision. ________________________________________________________________________

Decision of the National Commission sitting in restricted formation on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée […] site

24/27 94. As for the corrective measure proposed by the head of investigation set out in point b)

of point 92 of this decision, the Restricted Formation considers that the disputed processing operation resulted in a breach of the GDPR. It is appropriate to issue the corrective measure

proposed by the head of investigation in this regard and set out in point b) of point 92 of this decision.

95. As for the corrective measure proposed by the head of investigation set out in point c)

of point 92 of this decision, the Restricted Formation considers, in light of the

foregoing, that the violation of Article 5.1. c) of the GDPR is proven and that
therefore, the breach as proposed by the head of investigation in this regard

and reproduced in point 92 of this decision under c) should be upheld.

96. As for the corrective measure proposed by the head of investigation, reproduced in point d) of point 92 of this decision, the Restricted Committee considers that the breach of

Article 5.1.e) of the GDPR is proven and that the corrective measure proposed by

the head of investigation in this regard and reproduced in point 92 of this decision under d) should be upheld.

97. As for the corrective measure proposed by the head of investigation, set out in point e) of paragraph 92 of this decision, the Restricted Committee considers that the breach of

Article 32.1 of the GDPR is proven; it is appropriate to issue the corrective measure proposed by

the head of investigation in this regard and set out in point 92 of this decision under point e).

In view of the foregoing, the National Commission, sitting
in a Restricted Committee, after deliberation, decides:

- to uphold the breaches of Articles 5.2, 5.1.a) linked to Articles 13.1 and 13.2, 5.1.c), 5.1.e)

and 32.1 of the GDPR;

- to issue a warning to the school regarding its breaches of Articles 5.2, 5.1.a) linked to Articles 13.1 and 13.2, 5.1.c), 5.1.e), and 32.1 of the GDPR;

- to issue an injunction against the Lycée to bring the processing into compliance

with the provisions of Articles 13.1 and 2 of the GDPR, within 3 (three) months following

notification of the Restricted Panel's decision, and, in particular

• to inform the data subjects clearly and precisely about the video

surveillance system, either by providing them in a single location or in a

________________________________________________________________________

Decision of the National Commission sitting in Restricted Panel on the outcome of

Investigation No. […] conducted with the Ministry […] on the Lycée site […]

25/27 the same document (in paper or electronic format) with information on all

the elements required under Article 13 of the GDPR, or by proceeding at a

first and second level by:

o adapting the signs in place so that they include the identity and
contact details of the data controller; the purpose(s) of the processing;

the existence of the rights available to data subjects; the indication

that more comprehensive information exists (second level of information) and

the means of accessing it (for example, a hyperlink to the data controller's website, the use of a QR code, a telephone number

to call, or an indication of the location where this more detailed information is available);

o by providing a second level of information so that the

information is addressed to data subjects "in a concise, transparent, understandable, and easily accessible manner, in

clear and plain language" and that it contains all the

information within the meaning of Article 13 of the GDPR;

- to issue an injunction against the School to bring the processing

into compliance with Article 5.1. c) of the GDPR, within 3 (three) months following notification of the

decision of the Restricted Committee, and, in particular:

• limit the field of vision of the INNENHOF camera to the area strictly

necessary to view the persons preparing to access the entrances of the

School filmed by said camera;

• limit the field of vision of the EINGANG TURNHALLE camera to the area

strictly necessary to view the persons preparing to access the

School entrances of the School filmed by said camera;

- issue an injunction against the School to bring the processing

into compliance with Article 5.1. e) of the GDPR, within 3 (three) months following notification of the
decision of the Restricted Committee, and, in particular, limit the retention period

of video surveillance images to a maximum of 30 days and permanently delete

any recording exceeding the aforementioned retention period;

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with the Ministry […] on the Lycée site […]
26 27- to issue an injunction against the Lycée to bring its processing into compliance
with Article 32.1 of the GDPR, within 3 (three) months following notification of the

Restricted Session's decision, and, in particular, to implement a system for

logging access and events, as well as a periodic review of log files to detect any anomalies and ensure that members of the Lycée's

technical team authorized to access the video surveillance system

each have an individual account with a specific password to access the

operating software for said system.

Belvaux, March 26, 2025.

The National Commission for Data Protection sitting in restricted session

Tine A. Larsen Marc Lemmer Marc Hemmerling
President Commissioner Alternate Member

Indication of appeals

This administrative decision may be subject to an appeal for review within three

months of its notification. This appeal must be brought before the administrative court and must

be filed through a lawyer at the Court of one of the Bar Associations.

________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome
of investigation no. […] conducted with the Ministry […] on the site of the Lycée […]
27 27
  1. In this regard, the DPA referenced the EDPB's Guidelines on video devices (see the "Comment" section).