CNPD (Luxembourg) - 3FR/2025 du 30 avril 2025

From GDPRhub
CNPD - 3FR/2025 du 30 avril 2025
Authority: CNPD (Luxembourg)
Jurisdiction: Luxembourg
Relevant Law: Article 30(1)(a) GDPR
Article 30(1)(c) GDPR
Article 30(1)(f) GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided: 30.04.2025
Published: 13.11.2025
Fine: 7.000 EUR
Parties: n/a
National Case Number/Name: 3FR/2025 du 30 avril 2025
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): French
Original Source: CNPD (in FR)
Initial Contributor: RP

The DPA fined a controller €7,000 for keeping an incomplete record of processing activities , violating Article 30 GDPR.

English Summary

Facts

The CNPD investigated the controller and found that its register of processing activities was incomplete. The controller had not included information required under Article 30(1)(a), (c) and (f) GDPR.

During the procedure, the controller explained that the statement of objections helped them understand the missing elements, after which they updated the register and appointed a new Data Protection Officer. The controller also stated that no harm resulted from the incomplete register.

Holding

The CNPD held that the controller violated Article 30(1)(a), (c) and (f) GDPR. After considering the company’s size, resources, turnover, and neutral mitigating factors such as the fact that the breach had not caused any harm to individuals, the authority concluded that it was a low-severity breach and imposed a €7,000 fine under Article 83 GDPR. The CNPD considered this amount effective, proportionate and dissuasive and did not issue additional corrective measures since the controller had already corrected its register.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the French original. Please refer to the French original for more details.

Decision of the National Commission sitting in restricted session on

the outcome of investigation no. […] conducted with Company A

Deliberation no. 3FR/2025 of April 30, 2025

The National Commission for Data Protection sitting in restricted session,

composed of Ms. Tine A. Larsen, Chair, Mr. Marc Lemmer, Commissioner, and

Mr. Marc Hemmerling, Alternate Member;

Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on

the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;

Having regard to the Law of August 1, 2018, on the organization of the National Commission for Data Protection and the general data protection regime, in particular Article 41 thereof;

Having regard to the Rules of Procedure of the National Commission for Data Protection

adopted by Decision No. 07AD/2024 dated February 23, 2024, in particular Article 10,

paragraph 2 thereof;

Having regard to the Rules of Procedure of the National Commission for Data Protection relating to the

investigation procedure adopted by Decision No. 08AD/2024 dated February 23, 2024, in particular

Article 9 thereof;

Considering the following:

______________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with Company A 1/22I. Facts and Procedure

1. At its deliberation session of November 10, 2023, the National Commission for Data Protection (hereinafter: the “CNPD” or the “National Commission”), sitting in plenary session, decided to open an investigation into Company A pursuant to Article 38 of the Law of August 1, 2018, concerning the organization of the National Commission for Data Protection and the general data protection regime (hereinafter: the “Law of August 1, 2018”), and to appoint Mr. Alain Herrmann as head of the investigation.

2. The said decision specified that the purpose of the CNPD's investigation was to

monitor the application of and compliance with Regulation (EU) 2016/679 of the European Parliament and of the

Council of 27 April 2016 on the protection of natural persons with regard to the processing

of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the “GDPR”) and the Law of 1 August 2018, and “more

in particular, compliance with Article 30 of the GDPR relating to the record of processing activities

and the legal texts providing for specific provisions regarding the protection of

personal data”.

3. Company A is […] registered with the Luxembourg Trade and Companies Register under number […] and has its registered office at […] (hereinafter: the “audited”). The

2
under investigation concerns [engineering and technical studies].

4. On December 19, 2023, CNPD agents conducted an on-site visit

to the registered office of the party under investigation (hereinafter: the “on-site visit”).

This moment is referred to later in this decision as the “start of the investigation”.

5. By email dated December 20, 2023, the party under investigation provided the CNPD with additional information requested during the on-site visit.

6. The official report no. […] relating to the on-site visit conducted on December 19, 2023, at the party under investigation, drawn up by the CNPD agents (hereinafter: the “official report”), was sent to the party under investigation by email on January 17, 2024. 3

1Deliberation No. […] of November 10, 2023, of the National Commission for Data Protection concerning
the opening of an investigation at Company A.
2Consolidated Articles of Association of the audited entity […].

3The minutes also contained the decision to open investigation No. […], a list of photos taken during

the on-site visit, and an inventory of the documents collected and/or requested by the CNPD agents.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
investigation No. […] conducted at Company A

2/22It appears from these minutes, among other things, that the audited entity was able to provide the
CNPD agents with a digital copy of its register of processing activities pursuant to

Article 30 of the GDPR.

7. By letter dated January 26, 2024, the person being inspected submitted their position regarding the report.

8. On September 6, 2024, a request for further information was

sent to the audited party, to which they replied by email on September 16, 2024.

9. In response to the audited party's last email, the CNPD agents sent
follow-up questions on September 26, 2024, to which the audited party replied by

email on October 7, 2024.

10. Following its investigation, the lead investigator notified the audited party on

October 30, 2024, of a statement of objections (hereinafter: the “statement of objections”)
detailing the breaches it considered to have occurred in this case with regard to the requirements

prescribed by Article 30(1) of the GDPR (the obligation to maintain a record of processing activities).

The lead investigator proposed to the National Commission sitting in restricted session (hereinafter: the “Restricted Session”) that it adopt two different corrective measures, as well as

imposing an administrative fine of €11,964 on the audited party.

The audited party was given the opportunity to submit written observations on the statement of objections.

11. By letter dated November 12, 2024, the audited party submitted their

observations regarding the statement of objections.

12. On November 25, 2024, the lead investigator forwarded the case file to the

Restricted Session for a decision regarding the outcome of the investigation.

13. The Chair of the Restricted Panel informed the auditee by letter dated January 20, 2025, that his case would be scheduled for the Restricted Panel meeting on February 26, 2025, and that he was given the opportunity to be heard.

14. By email dated February 6, 2025, the auditee confirmed his attendance at the said meeting.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of investigation no. […] conducted with Company A 3 22 15. During this meeting, the lead investigator, accompanied by […], and the auditee,

represented by […], Data Protection Officer, and by […], former Data Protection Officer, presented their oral submissions in support of their written submissions and answered questions posed by the Restricted Panel.

16. The Restricted Panel's decision on the outcome of the investigation will be based on:

- the auditee's maintenance of a record of processing activities pursuant to Article 30(1),(3), and(4) of the GDPR; and

- the relevant legal and regulatory provisions.

II. Legal Basis

II.1. Grounds for the Decision

A. Status of the Auditee

17. According to Article 4(7) of the GDPR, the controller is defined as the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing.

The Restricted Panel notes that the auditee declared, during the on-site visit of December 19, 2023, that it "processes personal data for which it considers itself to be the controller." At the request of the CNPD agents, he

further clarified on October 7, 2024, that he is the data controller for

all processing activities listed in his register of processing activities.

Therefore, the Restricted Panel shares the opinion of the lead investigator as set forth in his

statement of objections and maintains that the audited party is to be considered the data controller, within the meaning of the GDPR, for the processing activities listed in his register of processing activities.

4 See point 12 of the statement of objections.

5 See email from the audited party dated October 7, 2024, Appendix 1.
6 See Statement of objections, page 6, points 11 to 13.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with Company A

4/22 B. On the breach of the obligation to maintain a record of processing activities

(Article 30 of the GDPR)

1. On the principles

18. Pursuant to Article 30(1) of the GDPR, the controller has an obligation

to maintain a record of the processing activities carried out under its responsibility. This
record must contain the following information:

"(a) the name and contact details of the controller and, where applicable, of the

joint controller, the controller's representative and

the data protection officer;

(b) the purposes of the processing;

(c) a description of the categories of data subjects and the categories of

personal data;

" (d) the categories of recipients to whom the personal data have been

or will be disclosed, including recipients in third countries or international organizations;

(e) where applicable, transfers of personal data to a third country

or an international organization, including the identification of that third country or international organization and, in the case of transfers referred to in Article 49(1), second subparagraph, documentation of the existence of appropriate safeguards;

(f) where possible, the envisaged time limits for the erasure of the different categories of data;

(g) where possible, a general description of the technical and organizational security measures referred to in Article 32(1).

Article 30(3) to (4) of the GDPR provides that:

"3. The records referred to in paragraphs 1 and 2 shall be kept in written form, including electronic form.

___________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A 5/22 4. The controller or the processor and, where applicable, their representative

shall make the register available to the supervisory authority upon request."

2. In this case

19. During the on-site visit on December 19, 2023, the audited party showed

the register of processing activities entitled "GDPR 2.1 Personal Data Mapping Form" to the

CNPD agents and a digital copy of said register was provided to them (hereinafter: the

7 "processing register"). The processing register is in Excel format and consists of
8
thirteen separate processing records in the form of tabs.

20. In his statement of objections, the lead investigator noted that the processing register was incomplete because certain information required under Article 30(1) of the GDPR was incomplete or missing.
9(a) Regarding the names and contact details of the data controller and the contact details of the data protection officer (Article 30(1)(a) of the GDPR):

21. It was clear from the processing register and its thirteen separate processing records that they did not include the name and contact details of the data controller,

nor the contact details of the data protection officer. Only the name of the data protection officer of the audited entity appeared in each processing record. 10

22. However, the Restricted Panel recalls that, pursuant to Article 30(1)(a) of the GDPR,

the register of processing activities must include the name and contact details of the controller

and the data protection officer. Therefore, the Restricted Panel

agrees with the opinion of the lead investigator and concludes that the audited party failed to comply with its obligation under Article 30(1)(a) of the GDPR.

b) Regarding the description of the categories of personal data (Article 30(1)(c)

of the GDPR)

23. It appeared from the register of processing activities, and more specifically from the entry entitled

“COMP-1”, that data relating to political opinions (see line 46: “data related

to political opinions”) and data relating to criminal convictions and

7
8 See Minutes, item F, page 2.

See Statement of Objections, page 7, item 14.

See Statement of Objections, page 8, items 18 to 19.

See Statement of Objections, page 8 (items 20 to 23); Exhibit 10 of the Statement of Objections.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A

6/22 offenses (see line 53: “data related to criminal convictions and offenses”) are processed.
These two categories of personal data do not contain any description

of said generic categories. 11

24. The Restricted Panel notes that, pursuant to Article 30(1)(c) of the GDPR,

the record of processing activities must include a description of the categories of

personal data. The description of a particular category of
personal data should, among other things, clarify whether special categories of

personal data as defined in Articles 9 and 10 of the GDPR are being processed. Consequently,

it is not sufficient to simply list generic categories without providing a description.

Therefore, the Restricted Panel agrees with the lead investigator's opinion and concludes that the audited party
failed to comply with its obligation under Article 30(1)(c) of the GDPR.

(c) Regarding the time limits for erasure of the different categories of data (Article 30(1)(f) of the GDPR)

25. It appeared from the processing register that, for certain categories of data, no time limit for erasure was specified or that the specified time limit was imprecise.

For the following categories of data, information regarding the erasure time limit was missing:

- data category “national identification number” (entry “HR-3”, line 54, column E);

- Data category "location data (travel, GPS data, GSM, etc.)" (record "HR-10", line 42, column E; record "HR-7", line 42, column E; record "HR-8", line 42, column E; record "HR-9", line 42, column E; record "PROC-1", line 42; record "IT-1", line 42, column E);

- Data category "civil status, identity, images, etc." (record "HR-7", line 38, column E; record "HR-8", line 38, column E; record "HR-9", line 38, column E; record "PROC-1", line 38; record "IT-1", line 38, column E; record "COMP-1", line 38, column E);

11Cf. Statement of Objections, pages 8-9, points 24-28; Exhibit 10 of the Statement of Objections.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with Company A

7/22 - data category “connection data (IP address, logs, etc.)” (form “IT-1”,

line 41, column E);

- data category “financial information (salary, tax situation, etc.)” (form

“COMP-1”, line 40, column E);

- data category “data related to political opinions” (form “COMP-1”,

line 46, column E);

- data category “data related to criminal convictions and offences” (form

“COMP-1”, line 53, column E).

For the following data category, the information regarding the erasure period was imprecise:

- Data category “civil status, identity, images, etc.” (HR-10 form, line 38,

column E): the period stipulated by the auditee was expressed as follows: “ASAP after the end
of the employment”.

26. The Restricted Panel recalls that Article 30(1)(f) of the GDPR requires that the
periods stipulated for the erasure of the different categories of data must, to the extent

possible, be included in the register of processing activities. This obligation is

closely linked to the principle of storage limitation provided for in Article 5(1)(e) of the GDPR

which requires that personal data must not be kept longer

than necessary for the purposes for which they were

collected. Beyond that point, this data must be deleted or anonymized. In this regard,

recital (39) of the GDPR specifies that “[a] in order to ensure that data are not kept longer than necessary, time limits should be set by the controller

for erasure or for periodic review.” However, the GDPR

does not require rigid erasure periods for the different categories of data under

Article 30(1)(f) of the GDPR, but it does require a case-by-case review and “where possible.”

27. Like the lead investigator and considering the seven categories of data

mentioned above, the Restricted Panel considers that the erasure period should be
determined or at least determinable. In this regard, and in light of paragraph 25 of this decision,

it notes that information regarding the erasure period was lacking with respect to the seven

categories of data mentioned above. Furthermore, the wording “ASAP after the end of

the employment” did not meet the requirement of a specific erasure period or

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Investigation No. […] conducted with Company A 8 22. Therefore, the Restricted Session agrees with the opinion of the lead investigator and finds
that the audited party failed to comply with its obligation under Article 30(1)(f) of the GDPR.

28. In light of the foregoing in paragraphs 21 to 27, the Restricted Session concludes

that at the start of the CNPD investigation, the audited party failed to comply with its obligation under

Article 30(1)(a), (c), and (f) of the GDPR.

II.2. On the administrative fine and corrective measures

1. On the principles

29. In accordance with Article 12 of the Law of 1 August 2018, the National Commission

has the powers provided for in Article 58(2) of the GDPR:

"(a) to notify a controller or processor that the
envisaged processing operations are likely to infringe the provisions of

this Regulation;

(b) to issue a warning to a controller or processor where the

processing operations have resulted in an infringement of the provisions of this
Regulation;

(c) to order the controller or processor to comply with the

requests made by the data subject to exercise their rights under

this Regulation;

(d) to order the controller or processor to bring the

processing operations into compliance with the provisions of this Regulation,

where appropriate, specifically and within a specified period;"

(e) order the controller to notify the data subject of a personal data breach;

(f) impose a temporary or permanent restriction, including a ban, on processing;

(g) order the rectification or erasure of personal data or the restriction of processing pursuant to Articles 16, 17 and 18 and notification of these measures to the recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19;

[…]

Decision of the National Commission sitting in restricted session on the outcome of the investigation No. […] conducted with Company A 9 22 (h) withdraw a certification or order the certification body to withdraw a

certification issued pursuant to Articles 42 and 43, or order the

certification body not to issue a certification if the requirements applicable to the
certification are not or are no longer met;

(i) impose an administrative penalty pursuant to Article 83, in addition to

or instead of the measures referred to in this paragraph, depending on the

specific characteristics of each case;

(j) order the suspension of data flowsdata transferred to a recipient located in

a third country or to an international organization.”

30. In accordance with Article 48 of the Law of 1 August 2018, the CNPD may impose

administrative fines as provided for in Article 83 of the GDPR, except against

the State or municipalities.

31. Article 83(1) of the GDPR provides that each supervisory authority shall ensure that

the administrative fines imposed are, in each case, effective, proportionate, and

dissuasive.

32. Article 83(2) specifies the criteria to be taken into account when deciding whether to impose an administrative fine and when deciding on the amount of that fine:

"(a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected and the level of damage they have suffered;

(b) whether the infringement was committed intentionally or negligently;

(c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;

(d) the degree of responsibility of the controller or processor, taking into account the technical and organisational measures they have implemented pursuant to Articles 25 and 32;

" ________________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A 10 22 e) any relevant breach previously committed by the controller or processor;

f) the degree of cooperation established with the supervisory authority with a view to remedying the breach and mitigating its potential adverse effects;

g) the categories of personal data concerned by the breach;

h) how the supervisory authority became aware of the breach,

in particular whether, and to what extent, the controller or processor notified the breach;

i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned for the same purpose, compliance with those measures;

(j) the application of codes of conduct approved pursuant to Article 40 or

certification mechanisms approved pursuant to Article 42; and

(k) any other aggravating or mitigating circumstances applicable to the circumstances

of the case, such as financial benefits obtained or losses avoided,

directly or indirectly, as a result of the breach.

33. The imposition of administrative fines was clarified by the Article 29 Working Party in its “Guidelines on the application and setting of administrative fines for the purposes of Regulation (EU) 2016/679” (WP 253) adopted on 3 October 2017

(hereinafter: the “Guidelines on the application and setting of fines”). These guidelines

were approved by the European Data Protection Board (hereinafter: the “EDPB”).

34. The Restricted Panel notes that the Guidelines on the application and

setting of fines have been supplemented by the EDPB’s “Guidelines 04/2022 on the calculation

of administrative fines under the GDPR”, version 2.1 of which was adopted

on 24 May 2023 (hereinafter: the “Guidelines on the calculation of fines”). These guidelines
specify a method that supervisory authorities may apply in order to

calculate administrative fines in light of the circumstances of each individual case.

12EDPC, Decision “Endorsement 1/2018” of 25 May 2018.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A

11 22 This method consists of five steps. However, supervisory authorities are not

required to apply all the steps if they are not relevant in a given case,

nor to provide reasons relating to aspects of the guidelines that are not

applicable.

35. The Restricted Session wishes to clarify that the facts and elements taken into account

in this decision are those existing at the beginning of the investigation, as
subsequently commented on by the party being supervised. Any modifications made by the party under investigation during the investigation and before the Restricted Panel's decision, even if they establish full or partial compliance, do not retroactively invalidate a found breach (see Administrative Court, judgment of May 14, 2024, Case No. 46401, ECLI:LU:TADM:2024:46401, pp. 26-27).

36. Nevertheless, steps taken by the party under investigation to comply with the GDPR during the investigation procedure, or to remedy the breaches identified by the lead investigator in the statement of objections, may be taken into account by the Restricted Panel when considering any corrective measures and/or administrative fines.

2. In this case

2.1. Regarding the imposition of an administrative fine

37. In the statement of objections, the lead investigator proposed to the Restricted Panel

that the audited party be fined an administrative amount of
€11,964 solely for the violation of Article 30(1)(f) of the GDPR.

He emphasized that the failure to comply with the obligations in paragraphs (c) and (f) of Article 30(1) of the GDPR

"is of a more significant nature" than the failure to comply with the obligation in Article 30(1)(a) of the

GDPR, as the latter would have lesser consequences for "achieving

the objectives pursued by the obligation to establish a record of processing activities." Furthermore,

it was of the opinion that non-compliance with Article 30(1)(f) of the GDPR, and more specifically,

the fact that “for more than half of the processing operations listed in the register of processing operations,

the time limits for erasure of the categories of data are lacking or are

13
Guidelines on the calculation of fines, page 3; for an overview of the methodology, see point 17 of the
14 guidelines.

Guidelines on the calculation of fines, point 6.
15 Statement of objections, point 60.
16 Statement of objections, pages 12-13, point 48.

___________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A

12/22 incomplete”, would amount to “a non-negligible degree of seriousness”, while the failure to

comply with paragraphs (a) and (c) of Article 30(1) of the GDPR would amount to “a negligible degree of seriousness”.

17

38. In its written submissions to the statement of objections, the auditee stated that the instructive approach of the statement of objections enabled it to

amend the processing register and correct and include all missing information

in its processing register. It also informed the lead investigator of the appointment

of a new data protection officer in April 2024 and appealed for leniency

18
in the face of the imposition of an administrative fine.

39. At the hearing of the Restricted Panel on 26 February 2025, the auditee reiterated its statements and explained how this learning process may also have

influenced the global code of conduct of the corporate group to which it belongs.

It further clarified that the incomplete nature of its processing register at the beginning of

the investigation had not caused any harm to the data subjects.

40. The Restricted Panel took note of the auditee's request to waive

the imposition of an administrative fine. It will focus below on analyzing the

criteria necessary to determine whether an administrative fine should be imposed
and, if so, the amount of the administrative fine under Article 83 of the GDPR.

In this context, the Restricted Panel will apply the five-step method

specified in the Guidelines on the Calculation of Fines.

2.1.1. Step 1: Identify the processing operations relevant to the case

41. In accordance with the Guidelines on the Calculation of Fines, it is essential

that the supervisory authority determine, firstly, whether one or more of the auditee's

conducts are subject to sanctions and whether these conduct constitute one or more
violations attributable to the auditee, taking into account the specific circumstances of the case. 19

42. These guidelines specify that when assessing a

same processing operation or related processing operations, the supervisory authority may

take into account, in its assessment of infringements, all

legally necessary obligations for the processing operations to be

17Statement of objections, page 13, paragraph 49.
18 See the auditee's letter of 12 November 2024 in response to the statement of objections.

19 Guidelines on the calculation of fines, Chapter 3; paragraphs 25 et seq.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with Company A

13 22 carried out in compliance with the law, including, for example, obligations regarding

20
transparency (for example, Article 13 of the GDPR).

43. In this case, the auditee is to be considered the data controller within

the meaning of the GDPR for the establishment of the processing register and for the processing activities listed therein

within the meaning of Article 30(1) of the GDPR (see paragraph 17 of this decision). The implementation of a record of processing activities is carried out within the framework of a unified objective

which is closely linked in context, space, and time. In this case, the Restricted Panel therefore considers that it is a matter of penalizing a single act of conduct within the meaning of Chapter

3.1 of the Guidelines on the Calculation of Fines.

2.1.2. Step 2: Setting the Starting Amount for the Subsequent Calculation of the Fine

44. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority must, secondly, set the starting amount for the subsequent calculation of the fine

21 in light of the specific circumstances and based on an assessment of three elements:

- the classification of the infringement under Article 83(4) to (6) of the GDPR;

- the seriousness of the infringement; and

22

- the company's turnover.

2.1.2.1. Classification of violations under Article 83(4) to (6) of the GDPR

45. Regarding the classification of violations, the GDPR provides for two categories:

violations punishable under Article 83(4) of the GDPR and violations punishable under Article 83(5) and (6) of the GDPR. For the first category of violations,

the maximum fine that may be imposed is €10 million or 2% of the company’s annual turnover, whichever is higher.

For the second category of violations,

the maximum fine that may be imposed is €20 million or 4% of the company’s annual turnover,

whichever is higher.

20
Guidelines on the calculation of fines, paragraph 27.
21Guidelines on the calculation of fines, Chapter 4.
22Guidelines on the calculation of fines, paragraph 48.

___________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A

14 22 46. By this categorization, the European legislator provided an initial

(abstract) indication of the seriousness of the infringement. Indeed, the more serious the infringement, the higher

23
the fine is likely to be.

47. The Restricted Panel notes that the alleged breach by the audited party,
in particular the breach of Article 30(1)(a), (c), and (f) of the GDPR, falls under the provisions of

Article 83(4) of the GDPR, meaning that this breach belongs to the first category

of violations and is therefore among the less serious violations.

2.1.2.2. The seriousness of the breach

48. When determining the seriousness of the breach, it is necessary

to examine the nature, seriousness, and duration of the breach (Article 83(2)(a) of the GDPR), as well as

whether it was intentional or negligent (Article 83(2)(b) of the GDPR) and the categories of
personal data concerned by the breach (Article 83(2)(g) of the GDPR). 24

49. Regarding the nature of the violation (Article 83(2)(a) of the GDPR), the Restricted Panel

Concerning the breach of Article 30(1)(a), (c), and (f) of the GDPR,

the European legislator intended to strengthen the documentation obligations of the data controller

by requiring them to document all their data processing activities in a

record of processing activities. This record is intended to facilitate the analysis and inventory

of all the data processing activities of the data controller and, consequently, the
demonstration of its compliance with the GDPR.

50. Regarding the seriousness of the violation (Article 83(2)(a) of the GDPR), the Restricted Panel

takes into account the number of data subjects affected and the level of

damage they have suffered.

51. Regarding the number of affected individuals, the

25 Restricted Panel notes that the audited entity employs [more than 400 employees] and that the number

of potentially affected third parties is undefined.

52. Regarding the level of harm suffered by the affected individuals, it considers that the individuals concerned did not suffer harm due to the

incomplete processing register.

23 Guidelines on the calculation of fines, paragraphs 49 and 50.
24 Guidelines on the calculation of fines, paragraph 51 et seq.

25

See letter from the audited party dated December 20, 2023.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Investigation No. […] conducted at Company A

1522 53. Regarding the criterion of the duration of the breach (Article 83(2)(a) of the GDPR), the

Restricted Session notes that, as the GDPR entered into force in May 2018, the duration of the

breach on the date of the on-site visit of December 19, 2023, was at least 5 years and 6 months.

54. Regarding the question of whether the infringement was committed intentionally or through

negligence (Article 83(2)(b) of the GDPR), the Restricted Panel reiterates that an administrative fine

under Article 83 of the GDPR can only be imposed if it is

established that the controller committed, intentionally or negligently, a

26 infringement as defined in paragraphs (4) and (6) of that article.

“Intent,” meaning an infringement committed intentionally, includes both

knowledge and will in relation to the characteristics of an infringement, whereas

“not intentionally” (through negligence) means that there was no intention to commit the

infringement, although the controller or processor failed to comply with

27 its duty of care under the law.

The Restricted Panel considers that the audited party could not have been unaware of the existence of
28
the violated obligation. It agrees with the lead investigator who determined that the violation resulted from “a

improper execution of this obligation as well as a lack of adequate verification by the
[o]rector”.

In light of the foregoing, the Restricted Panel is of the opinion that the facts and the observed breach

do not demonstrate a deliberate intention to violate the GDPR on the part of the audited party.

Nevertheless, it finds that the breach was committed through negligence.

55. Regarding the categories of personal data concerned (Article 83(2)(g) of the GDPR), the Restricted Panel finds that the processing register does not contain

personal data.

26
In a judgment of 5 December 2023, the CJEU (Grand Chamber) held that an administrative fine under Article 83 of the GDPR may be imposed “only if it is established that the controller, which is both a legal person and an undertaking, has committed, deliberately or negligently, an infringement referred to in paragraphs 4 to 6 of that article”. In this regard, the CJEU clarified that “a controller may be sanctioned for conduct falling within the scope of the GDPR provided that the controller could not have been unaware of the unlawful nature of its conduct, whether or not it was aware of infringing the provisions of the GDPR […]” (Judgments of 5 December 2023 (Grand Chamber), Deutsche Wohnen, C-807/21, ECLI:EU:C:2023:950, paragraph 76).

27 Guidelines on the application and setting of fines, pages 11 to 12.

28 Judgments of 5 December 2023 (Grand Chamber), Deutsche Wohnen, C-807/21, ECLI:EU:C:2023:950, paragraph 76 and
Nacionalinis visuomenės sveikatos centras, C-683/21, ECLI:EU:C:2023:949, paragraph 81.

29 Statement of objections, paragraph 91.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A

16/22 56. Having regard to its assessment of the relevant criteria of Article 83(2)(a), (b)

and (g) of the GDPR above, the Restricted Session considers that the classification the degree of

severity of the violations is to be considered low.

2.1.2.3. The company's turnover

57. To complete step 2, the Restricted Panel takes into account the company's turnover

in accordance with the Guidelines on the calculation of fines. 30

58. The Restricted Panel recalls that, in accordance with EU law

and the case law of the CJEU, the reference, made in recital (150)

31 of the GDPR, to the concept of "undertaking" within the meaning of Articles 101 and 102 of the TFEU must be understood within the specific context of calculating

administrative fines. Therefore, the

concept of "enterprise" is defined as the "economic unit," which consists of a

unitary organization of personal, tangible, and intangible elements pursuing a specific economic goal in a sustainable manner, even if, from a legal point of view, this economic unit is made up of several natural or legal persons. 32

59. Thus, it considers that in this case the relevant economic unit,

with regard to the alleged infringement, is the group of companies headed by the company […], a

company incorporated under […] law, which indirectly holds 100% of the share capital of the controlled entity. 33

60. It notes that the consolidated net turnover of the company […] for the year

2023 amounted to EUR [company with turnover exceeding 500 million

euros]. 4

Furthermore, the net turnover of the controlled entity for the year 2023 amounted to EUR […] with a

net profit of EUR […] according to the 2023 annual accounts.

2.1.3. Step 3: Assessing Aggravating and Mitigating Circumstances

61. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority must, as a third step, assess whether there are aggravating or mitigating circumstances.

30 See Guidelines on the Calculation of Fines, Chapter 4.3, paragraphs 63 to 69.
31 The Treaty on the Functioning of the European Union (TFEU).

32 Judgment of 5 December 2023, Deutsche Wohnen, C-807/21, ECLI:EU:C:2023:950, paragraphs 56 and 57; see also
Guidelines on the Application and Setting of Fines, page 6 and Guidelines on the Calculation of Fines, paragraph 118 et seq.

33 See Statement of objections, point 7 and Exhibits Nos. 2 and 5.
34 Statement of objections, point 7 and Exhibits Nos. 6, 7 and 8.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Inquiry No. […] conducted with Company A

17/22 35
are applicable to the circumstances of the case. The guidelines specify that the supervisory authority

must consider each criterion provided for in Article 83(2) of the GDPR only once. Thus, after assessing, in step 2, the nature, seriousness, and duration of the

violation (Article 83(2)(a) of the GDPR), as well as whether it was intentional or negligent

(Article 83(2)(b) of the GDPR), and the categories of personal data concerned

(Article 83(2)(g) of the GDPR), the Restricted Panel will assess the other

aggravating and mitigating circumstances under Article 83(2) of the GDPR (Article 83(2)(c), (d), (e), (f), (h), (i), (j), and (k) of the GDPR).

62. Regarding the measures taken by the audited party to mitigate the harm suffered by

data subjects (Article 83(2)(c) of the GDPR), the Restricted Panel considers, initially,

that the data subjects have not suffered any harm (see paragraph 52 of

this decision). Next, it notes, without prejudging the satisfactory nature of the measures

taken by the audited party, that the audited party sent, on November 12, 2024, a copy of
its amended processing register in order to address the deficiencies raised by the

lead investigator in his statement of objections. It notes that these measures were

implemented after the statement of objections was sent. These measures will be analyzed

in Chapter II.2, Section 2.2 of this decision. In summary, it observes that all the

measures taken by the audited party were implemented only after the start of the investigation. Therefore, the
Restricted Panel is of the opinion that these circumstances should be considered neutral.

63. Regarding the degree of cooperation established with the CNPD (National Commission for Data Protection) in order to remedy the

violation and mitigate its potential negative effects (Article 83(2)(f) of the GDPR), the Restricted Panel

notes that, in light of the investigation file and, in particular, the responses provided by the

responsible party during the investigation procedure, it must be concluded that the responsible party's cooperation

was satisfactory. However, it reiterates that the responsible party is subject to a general obligation of
cooperation under Article 31 of the GDPR. Therefore, it considers these circumstances

to be neutral.

64. Regarding any other aggravating or mitigating circumstances applicable to the

circumstances of the case (Article 83(2)(k) of the GDPR), the lead investigator noted, “as

aggravating circumstances, that in this case, it could reasonably be expected that the

[t]omitted entity, given its size and resources, would establish a register of

35Guidelines on the calculation of fines, Chapter 5.

36Guidelines on the calculation of fines, paragraphs 70 to 72.

___________________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Investigation No. […] conducted with Company A

18/22 processing in accordance with the requirements of the GDPR and that it carries out regular reviews” of said 37

register.

As mitigating circumstances, the lead investigator noted that the audited party had “gone

beyond the obligations imposed by Article 30.1 of the GDPR by including in the register of

processing activities additional information such as the legal basis for the processing”. 38

The Restricted Panel takes into account the aforementioned elements and concurs with the opinion of the lead investigator.

65. The Restricted Panel finds that the other criteria of Article 83(2) of the

GDPR are neither relevant nor likely to influence its decision regarding the imposition of an

39
administrative fine and its amount, and therefore it will not analyze them.

66. Therefore, taking into account the assessment of the relevant criteria in Article 83(2)

of the GDPR, the Restricted Panel considers that the imposition of an administrative fine is

justified for the breach of Article 30(1)(a), (c), and (f) of the GDPR.

2.1.4. Step 4: Determining the applicable maximum statutory amount

67. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority

40 must, fourthly, determine the applicable maximum statutory amounts. The

guidelines reiterate that the GDPR does not assign fixed amounts to specific

breaches, but that the GDPR provides for general maximum amounts. Therefore, it is necessary

to ensure that these maximum amounts are not exceeded. 41

68. The Restricted Panel has already noted that the consolidated net turnover of the

company […] for the year 2023 amounted to EUR [company with turnover exceeding

500 million euros] (see paragraph 60 of this decision).

69. The Restricted Panel notes that insofar as the sole infringement alleged against the audited party (namely, the infringement of Article 30(1)(a), (c) and (f) of the GDPR)

falls within the scope of Article 83(4) of the GDPR, the maximum amount of the fine

that may be imposed is €10 million or 2% of the annual turnover of

37Statement of objections, paragraph 51.
38Statement of objections, paragraph 52.
39
40Guidelines on the calculation of fines, paragraph 6.

Guidelines on the calculation of fines, Chapter 6.
41Guidelines on the calculation of fines, paragraphs 112 and 113.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with the Company A

19/22 the company, “the higher amount being retained,” in accordance with Article 83(4) of the GDPR.

Therefore, the Panel determines that in this case the maximum amount of an administrative fine

42
is EUR […] (i.e., 2% of the company’s annual turnover).

70. In the present case, taking into account steps 1 to 4 of this decision (see paragraphs 41 to 69), and more specifically the fact that a single infringement has been established in this case, the classification of the infringement under Article 83(4) of the GDPR, its low severity, and the assessment of the aggravating and mitigating circumstances in this case, the Restricted Panel considers that the administrative fine to be imposed should amount to €7,000.

2.1.5. Step 5: Determine whether the final amount of the calculated fine is effective,

proportionate, and dissuasive

71. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority must, fifthly, ensure that the administrative fine imposed for the

GDPR infringement(s) referred to in Article 83(4) to (6) is, in each case, effective,
proportionate, and dissuasive, as required by Article 83(1) of the GDPR. According to the EDPB, it is the responsibility of

the supervisory authority to verify whether the amount of the fine meets these requirements

or whether further adjustments to the amount are necessary.

72. The Restricted Panel considers that the amount of the fine appears to be

effective, proportionate, and dissuasive, in accordance with the requirements of Article 83(1) of the

GDPR.

2.2. Regarding the implementation of corrective measures

73. In the statement of objections, the lead investigator also proposed to the

Restricted Panel that it adopt the following corrective measures (excluding administrative fines):

• “remind the Controlled Party of the need to include in the Register of

processing activities the information required under Article 30.1(a), (c), and (f) of the GDPR;

42
According to the sliding scale specified in point 115 et seq. of the Guidelines on the Calculation of Fines.

43Guidelines on the Calculation of Fines, Chapter 7.
44Guidelines on the Calculation of Fines, paragraph 132.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of
Inquiry No. […] conducted with Company A

20/22 • to issue an order against the Inspected Party, giving it a period of 1 month

from the date of notification of the decision on the outcome of the inquiry, to

bring the Register of Processing Activities into compliance with the provisions of Article 30.1

(a), (c) of the GDPR and more specifically to complete the Register of Processing Activities as follows:


- by indicating the name and contact details of the data controller as well as the

contact details of the data protection officer,

- by providing descriptions of each category of data processed, for example, by listing, within each category, examples of the types of

processed data,

- by indicating, in a specific or determinable manner, the planned deadlines for

the deletion of the different categories of processed data,

as well as providing any supporting documentation that can demonstrate compliance with
this injunction; […]”.5

74. Regarding the corrective measures proposed by the lead investigator and by

reference to paragraph 36 of this decision, the Restricted Panel takes into account the

steps taken by the audited party to comply with the provisions of the GDPR, as

detailed in its letter of 12 November 2024. In particular, it notes

the following facts:

75. Regarding the warning (see paragraph 73, first point of this decision)

proposed by the lead investigator for the breach identified under Article 30(1)(a), (c) and

(f) of the GDPR, the Restricted Panel considers the compliance measures taken by

the audited party in this case and finds that there is no need to impose the corrective measure
proposed by the lead investigator in this regard.

76. Regarding the order for bringing the processing into compliance (see point 73, second point

of this decision) proposed by the lead investigator for the breach identified under

Article 30(1)(a), (c), and (f) of the GDPR, the Restricted Panel notes that the audited party, in its

response to the statement of objections, sent a revised processing register (hereinafter:

the “new processing register”). It mentioned in its letter of November 12

45 Statement of objections, point 63.

______________________________________________________________

Decision of the National Commission sitting in restricted session on the outcome of

Investigation No. […] conducted with Company A

21/222024 that all missing or inaccurate information noted by the lead investigator
in his statement of objections has been completed and/or corrected. The Restricted Panel

notes that the new processing register does indeed contain all the

information required by Article 30(1) of the GDPR.

Considering the sufficient compliance measures taken by the audited party in
this case, the Restricted Panel therefore considers that there is no need to impose the

corrective measure proposed by the lead investigator in this regard.

In light of the foregoing, the National Commission, sitting

in its restricted panel, after deliberation, decides:

- to find a breach of Article 30(1)(a), (c), and (f) of the GDPR;

- to impose an administrative fine on Company A in the amount of

7,000 (seven thousand euros) for the breach of Article 30(1)(a), (c), and (f) of the GDPR.

Belvaux, April 30, 2025

The National Commission for Data Protection, sitting in restricted session

Tine A. Larsen, Marc Lemmer, Marc Hemmerling

Chair, Commissioner, Alternate Member

Information on appeal procedures

This administrative decision may be appealed within three
months of its notification. This appeal must be brought before the Administrative Court and must

be filed through a lawyer admitted to the Bar of one of the Bar Associations.

______________________________________________________________

Decision of the National Commission, sitting in restricted session, on the outcome of

Inquiry No. […] conducted with Company A 22/22