CNPD (Luxembourg) - 3FR/2025 du 30 avril 2025
| CNPD - 3FR/2025 du 30 avril 2025 | |
|---|---|
![]() | |
| Authority: | CNPD (Luxembourg) |
| Jurisdiction: | Luxembourg |
| Relevant Law: | Article 30(1)(a) GDPR Article 30(1)(c) GDPR Article 30(1)(f) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 30.04.2025 |
| Published: | 13.11.2025 |
| Fine: | 7.000 EUR |
| Parties: | n/a |
| National Case Number/Name: | 3FR/2025 du 30 avril 2025 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | French |
| Original Source: | CNPD (in FR) |
| Initial Contributor: | RP |
The DPA fined a controller €7,000 for keeping an incomplete record of processing activities , violating Article 30 GDPR.
English Summary
Facts
The CNPD investigated the controller and found that its register of processing activities was incomplete. The controller had not included information required under Article 30(1)(a), (c) and (f) GDPR.
During the procedure, the controller explained that the statement of objections helped them understand the missing elements, after which they updated the register and appointed a new Data Protection Officer. The controller also stated that no harm resulted from the incomplete register.
Holding
The CNPD held that the controller violated Article 30(1)(a), (c) and (f) GDPR. After considering the company’s size, resources, turnover, and neutral mitigating factors such as the fact that the breach had not caused any harm to individuals, the authority concluded that it was a low-severity breach and imposed a €7,000 fine under Article 83 GDPR. The CNPD considered this amount effective, proportionate and dissuasive and did not issue additional corrective measures since the controller had already corrected its register.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the French original. Please refer to the French original for more details.
Decision of the National Commission sitting in restricted session on the outcome of investigation no. […] conducted with Company A Deliberation no. 3FR/2025 of April 30, 2025 The National Commission for Data Protection sitting in restricted session, composed of Ms. Tine A. Larsen, Chair, Mr. Marc Lemmer, Commissioner, and Mr. Marc Hemmerling, Alternate Member; Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC; Having regard to the Law of August 1, 2018, on the organization of the National Commission for Data Protection and the general data protection regime, in particular Article 41 thereof; Having regard to the Rules of Procedure of the National Commission for Data Protection adopted by Decision No. 07AD/2024 dated February 23, 2024, in particular Article 10, paragraph 2 thereof; Having regard to the Rules of Procedure of the National Commission for Data Protection relating to the investigation procedure adopted by Decision No. 08AD/2024 dated February 23, 2024, in particular Article 9 thereof; Considering the following: ______________________________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Investigation No. […] conducted with Company A 1/22I. Facts and Procedure 1. At its deliberation session of November 10, 2023, the National Commission for Data Protection (hereinafter: the “CNPD” or the “National Commission”), sitting in plenary session, decided to open an investigation into Company A pursuant to Article 38 of the Law of August 1, 2018, concerning the organization of the National Commission for Data Protection and the general data protection regime (hereinafter: the “Law of August 1, 2018”), and to appoint Mr. Alain Herrmann as head of the investigation. 2. The said decision specified that the purpose of the CNPD's investigation was to monitor the application of and compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the “GDPR”) and the Law of 1 August 2018, and “more in particular, compliance with Article 30 of the GDPR relating to the record of processing activities and the legal texts providing for specific provisions regarding the protection of personal data”. 3. Company A is […] registered with the Luxembourg Trade and Companies Register under number […] and has its registered office at […] (hereinafter: the “audited”). The 2 under investigation concerns [engineering and technical studies]. 4. On December 19, 2023, CNPD agents conducted an on-site visit to the registered office of the party under investigation (hereinafter: the “on-site visit”). This moment is referred to later in this decision as the “start of the investigation”. 5. By email dated December 20, 2023, the party under investigation provided the CNPD with additional information requested during the on-site visit. 6. The official report no. […] relating to the on-site visit conducted on December 19, 2023, at the party under investigation, drawn up by the CNPD agents (hereinafter: the “official report”), was sent to the party under investigation by email on January 17, 2024. 3 1Deliberation No. […] of November 10, 2023, of the National Commission for Data Protection concerning the opening of an investigation at Company A. 2Consolidated Articles of Association of the audited entity […]. 3The minutes also contained the decision to open investigation No. […], a list of photos taken during the on-site visit, and an inventory of the documents collected and/or requested by the CNPD agents. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of investigation No. […] conducted at Company A 2/22It appears from these minutes, among other things, that the audited entity was able to provide the CNPD agents with a digital copy of its register of processing activities pursuant to Article 30 of the GDPR. 7. By letter dated January 26, 2024, the person being inspected submitted their position regarding the report. 8. On September 6, 2024, a request for further information was sent to the audited party, to which they replied by email on September 16, 2024. 9. In response to the audited party's last email, the CNPD agents sent follow-up questions on September 26, 2024, to which the audited party replied by email on October 7, 2024. 10. Following its investigation, the lead investigator notified the audited party on October 30, 2024, of a statement of objections (hereinafter: the “statement of objections”) detailing the breaches it considered to have occurred in this case with regard to the requirements prescribed by Article 30(1) of the GDPR (the obligation to maintain a record of processing activities). The lead investigator proposed to the National Commission sitting in restricted session (hereinafter: the “Restricted Session”) that it adopt two different corrective measures, as well as imposing an administrative fine of €11,964 on the audited party. The audited party was given the opportunity to submit written observations on the statement of objections. 11. By letter dated November 12, 2024, the audited party submitted their observations regarding the statement of objections. 12. On November 25, 2024, the lead investigator forwarded the case file to the Restricted Session for a decision regarding the outcome of the investigation. 13. The Chair of the Restricted Panel informed the auditee by letter dated January 20, 2025, that his case would be scheduled for the Restricted Panel meeting on February 26, 2025, and that he was given the opportunity to be heard. 14. By email dated February 6, 2025, the auditee confirmed his attendance at the said meeting. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of investigation no. […] conducted with Company A 3 22 15. During this meeting, the lead investigator, accompanied by […], and the auditee, represented by […], Data Protection Officer, and by […], former Data Protection Officer, presented their oral submissions in support of their written submissions and answered questions posed by the Restricted Panel. 16. The Restricted Panel's decision on the outcome of the investigation will be based on: - the auditee's maintenance of a record of processing activities pursuant to Article 30(1),(3), and(4) of the GDPR; and - the relevant legal and regulatory provisions. II. Legal Basis II.1. Grounds for the Decision A. Status of the Auditee 17. According to Article 4(7) of the GDPR, the controller is defined as the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing. The Restricted Panel notes that the auditee declared, during the on-site visit of December 19, 2023, that it "processes personal data for which it considers itself to be the controller." At the request of the CNPD agents, he further clarified on October 7, 2024, that he is the data controller for all processing activities listed in his register of processing activities. Therefore, the Restricted Panel shares the opinion of the lead investigator as set forth in his statement of objections and maintains that the audited party is to be considered the data controller, within the meaning of the GDPR, for the processing activities listed in his register of processing activities. 4 See point 12 of the statement of objections. 5 See email from the audited party dated October 7, 2024, Appendix 1. 6 See Statement of objections, page 6, points 11 to 13. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 4/22 B. On the breach of the obligation to maintain a record of processing activities (Article 30 of the GDPR) 1. On the principles 18. Pursuant to Article 30(1) of the GDPR, the controller has an obligation to maintain a record of the processing activities carried out under its responsibility. This record must contain the following information: "(a) the name and contact details of the controller and, where applicable, of the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and the categories of personal data; " (d) the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organizations; (e) where applicable, transfers of personal data to a third country or an international organization, including the identification of that third country or international organization and, in the case of transfers referred to in Article 49(1), second subparagraph, documentation of the existence of appropriate safeguards; (f) where possible, the envisaged time limits for the erasure of the different categories of data; (g) where possible, a general description of the technical and organizational security measures referred to in Article 32(1). Article 30(3) to (4) of the GDPR provides that: "3. The records referred to in paragraphs 1 and 2 shall be kept in written form, including electronic form. ___________________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 5/22 4. The controller or the processor and, where applicable, their representative shall make the register available to the supervisory authority upon request." 2. In this case 19. During the on-site visit on December 19, 2023, the audited party showed the register of processing activities entitled "GDPR 2.1 Personal Data Mapping Form" to the CNPD agents and a digital copy of said register was provided to them (hereinafter: the 7 "processing register"). The processing register is in Excel format and consists of 8 thirteen separate processing records in the form of tabs. 20. In his statement of objections, the lead investigator noted that the processing register was incomplete because certain information required under Article 30(1) of the GDPR was incomplete or missing. 9(a) Regarding the names and contact details of the data controller and the contact details of the data protection officer (Article 30(1)(a) of the GDPR): 21. It was clear from the processing register and its thirteen separate processing records that they did not include the name and contact details of the data controller, nor the contact details of the data protection officer. Only the name of the data protection officer of the audited entity appeared in each processing record. 10 22. However, the Restricted Panel recalls that, pursuant to Article 30(1)(a) of the GDPR, the register of processing activities must include the name and contact details of the controller and the data protection officer. Therefore, the Restricted Panel agrees with the opinion of the lead investigator and concludes that the audited party failed to comply with its obligation under Article 30(1)(a) of the GDPR. b) Regarding the description of the categories of personal data (Article 30(1)(c) of the GDPR) 23. It appeared from the register of processing activities, and more specifically from the entry entitled “COMP-1”, that data relating to political opinions (see line 46: “data related to political opinions”) and data relating to criminal convictions and 7 8 See Minutes, item F, page 2. See Statement of Objections, page 7, item 14. See Statement of Objections, page 8, items 18 to 19. See Statement of Objections, page 8 (items 20 to 23); Exhibit 10 of the Statement of Objections. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 6/22 offenses (see line 53: “data related to criminal convictions and offenses”) are processed. These two categories of personal data do not contain any description of said generic categories. 11 24. The Restricted Panel notes that, pursuant to Article 30(1)(c) of the GDPR, the record of processing activities must include a description of the categories of personal data. The description of a particular category of personal data should, among other things, clarify whether special categories of personal data as defined in Articles 9 and 10 of the GDPR are being processed. Consequently, it is not sufficient to simply list generic categories without providing a description. Therefore, the Restricted Panel agrees with the lead investigator's opinion and concludes that the audited party failed to comply with its obligation under Article 30(1)(c) of the GDPR. (c) Regarding the time limits for erasure of the different categories of data (Article 30(1)(f) of the GDPR) 25. It appeared from the processing register that, for certain categories of data, no time limit for erasure was specified or that the specified time limit was imprecise. For the following categories of data, information regarding the erasure time limit was missing: - data category “national identification number” (entry “HR-3”, line 54, column E); - Data category "location data (travel, GPS data, GSM, etc.)" (record "HR-10", line 42, column E; record "HR-7", line 42, column E; record "HR-8", line 42, column E; record "HR-9", line 42, column E; record "PROC-1", line 42; record "IT-1", line 42, column E); - Data category "civil status, identity, images, etc." (record "HR-7", line 38, column E; record "HR-8", line 38, column E; record "HR-9", line 38, column E; record "PROC-1", line 38; record "IT-1", line 38, column E; record "COMP-1", line 38, column E); 11Cf. Statement of Objections, pages 8-9, points 24-28; Exhibit 10 of the Statement of Objections. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 7/22 - data category “connection data (IP address, logs, etc.)” (form “IT-1”, line 41, column E); - data category “financial information (salary, tax situation, etc.)” (form “COMP-1”, line 40, column E); - data category “data related to political opinions” (form “COMP-1”, line 46, column E); - data category “data related to criminal convictions and offences” (form “COMP-1”, line 53, column E). For the following data category, the information regarding the erasure period was imprecise: - Data category “civil status, identity, images, etc.” (HR-10 form, line 38, column E): the period stipulated by the auditee was expressed as follows: “ASAP after the end of the employment”. 26. The Restricted Panel recalls that Article 30(1)(f) of the GDPR requires that the periods stipulated for the erasure of the different categories of data must, to the extent possible, be included in the register of processing activities. This obligation is closely linked to the principle of storage limitation provided for in Article 5(1)(e) of the GDPR which requires that personal data must not be kept longer than necessary for the purposes for which they were collected. Beyond that point, this data must be deleted or anonymized. In this regard, recital (39) of the GDPR specifies that “[a] in order to ensure that data are not kept longer than necessary, time limits should be set by the controller for erasure or for periodic review.” However, the GDPR does not require rigid erasure periods for the different categories of data under Article 30(1)(f) of the GDPR, but it does require a case-by-case review and “where possible.” 27. Like the lead investigator and considering the seven categories of data mentioned above, the Restricted Panel considers that the erasure period should be determined or at least determinable. In this regard, and in light of paragraph 25 of this decision, it notes that information regarding the erasure period was lacking with respect to the seven categories of data mentioned above. Furthermore, the wording “ASAP after the end of the employment” did not meet the requirement of a specific erasure period or ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Investigation No. […] conducted with Company A 8 22. Therefore, the Restricted Session agrees with the opinion of the lead investigator and finds that the audited party failed to comply with its obligation under Article 30(1)(f) of the GDPR. 28. In light of the foregoing in paragraphs 21 to 27, the Restricted Session concludes that at the start of the CNPD investigation, the audited party failed to comply with its obligation under Article 30(1)(a), (c), and (f) of the GDPR. II.2. On the administrative fine and corrective measures 1. On the principles 29. In accordance with Article 12 of the Law of 1 August 2018, the National Commission has the powers provided for in Article 58(2) of the GDPR: "(a) to notify a controller or processor that the envisaged processing operations are likely to infringe the provisions of this Regulation; (b) to issue a warning to a controller or processor where the processing operations have resulted in an infringement of the provisions of this Regulation; (c) to order the controller or processor to comply with the requests made by the data subject to exercise their rights under this Regulation; (d) to order the controller or processor to bring the processing operations into compliance with the provisions of this Regulation, where appropriate, specifically and within a specified period;" (e) order the controller to notify the data subject of a personal data breach; (f) impose a temporary or permanent restriction, including a ban, on processing; (g) order the rectification or erasure of personal data or the restriction of processing pursuant to Articles 16, 17 and 18 and notification of these measures to the recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19; […] Decision of the National Commission sitting in restricted session on the outcome of the investigation No. […] conducted with Company A 9 22 (h) withdraw a certification or order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or order the certification body not to issue a certification if the requirements applicable to the certification are not or are no longer met; (i) impose an administrative penalty pursuant to Article 83, in addition to or instead of the measures referred to in this paragraph, depending on the specific characteristics of each case; (j) order the suspension of data flowsdata transferred to a recipient located in a third country or to an international organization.” 30. In accordance with Article 48 of the Law of 1 August 2018, the CNPD may impose administrative fines as provided for in Article 83 of the GDPR, except against the State or municipalities. 31. Article 83(1) of the GDPR provides that each supervisory authority shall ensure that the administrative fines imposed are, in each case, effective, proportionate, and dissuasive. 32. Article 83(2) specifies the criteria to be taken into account when deciding whether to impose an administrative fine and when deciding on the amount of that fine: "(a) the nature, seriousness and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected and the level of damage they have suffered; (b) whether the infringement was committed intentionally or negligently; (c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller or processor, taking into account the technical and organisational measures they have implemented pursuant to Articles 25 and 32; " ________________________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 10 22 e) any relevant breach previously committed by the controller or processor; f) the degree of cooperation established with the supervisory authority with a view to remedying the breach and mitigating its potential adverse effects; g) the categories of personal data concerned by the breach; h) how the supervisory authority became aware of the breach, in particular whether, and to what extent, the controller or processor notified the breach; i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned for the same purpose, compliance with those measures; (j) the application of codes of conduct approved pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and (k) any other aggravating or mitigating circumstances applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, as a result of the breach. 33. The imposition of administrative fines was clarified by the Article 29 Working Party in its “Guidelines on the application and setting of administrative fines for the purposes of Regulation (EU) 2016/679” (WP 253) adopted on 3 October 2017 (hereinafter: the “Guidelines on the application and setting of fines”). These guidelines were approved by the European Data Protection Board (hereinafter: the “EDPB”). 34. The Restricted Panel notes that the Guidelines on the application and setting of fines have been supplemented by the EDPB’s “Guidelines 04/2022 on the calculation of administrative fines under the GDPR”, version 2.1 of which was adopted on 24 May 2023 (hereinafter: the “Guidelines on the calculation of fines”). These guidelines specify a method that supervisory authorities may apply in order to calculate administrative fines in light of the circumstances of each individual case. 12EDPC, Decision “Endorsement 1/2018” of 25 May 2018. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 11 22 This method consists of five steps. However, supervisory authorities are not required to apply all the steps if they are not relevant in a given case, nor to provide reasons relating to aspects of the guidelines that are not applicable. 35. The Restricted Session wishes to clarify that the facts and elements taken into account in this decision are those existing at the beginning of the investigation, as subsequently commented on by the party being supervised. Any modifications made by the party under investigation during the investigation and before the Restricted Panel's decision, even if they establish full or partial compliance, do not retroactively invalidate a found breach (see Administrative Court, judgment of May 14, 2024, Case No. 46401, ECLI:LU:TADM:2024:46401, pp. 26-27). 36. Nevertheless, steps taken by the party under investigation to comply with the GDPR during the investigation procedure, or to remedy the breaches identified by the lead investigator in the statement of objections, may be taken into account by the Restricted Panel when considering any corrective measures and/or administrative fines. 2. In this case 2.1. Regarding the imposition of an administrative fine 37. In the statement of objections, the lead investigator proposed to the Restricted Panel that the audited party be fined an administrative amount of €11,964 solely for the violation of Article 30(1)(f) of the GDPR. He emphasized that the failure to comply with the obligations in paragraphs (c) and (f) of Article 30(1) of the GDPR "is of a more significant nature" than the failure to comply with the obligation in Article 30(1)(a) of the GDPR, as the latter would have lesser consequences for "achieving the objectives pursued by the obligation to establish a record of processing activities." Furthermore, it was of the opinion that non-compliance with Article 30(1)(f) of the GDPR, and more specifically, the fact that “for more than half of the processing operations listed in the register of processing operations, the time limits for erasure of the categories of data are lacking or are 13 Guidelines on the calculation of fines, page 3; for an overview of the methodology, see point 17 of the 14 guidelines. Guidelines on the calculation of fines, point 6. 15 Statement of objections, point 60. 16 Statement of objections, pages 12-13, point 48. ___________________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 12/22 incomplete”, would amount to “a non-negligible degree of seriousness”, while the failure to comply with paragraphs (a) and (c) of Article 30(1) of the GDPR would amount to “a negligible degree of seriousness”. 17 38. In its written submissions to the statement of objections, the auditee stated that the instructive approach of the statement of objections enabled it to amend the processing register and correct and include all missing information in its processing register. It also informed the lead investigator of the appointment of a new data protection officer in April 2024 and appealed for leniency 18 in the face of the imposition of an administrative fine. 39. At the hearing of the Restricted Panel on 26 February 2025, the auditee reiterated its statements and explained how this learning process may also have influenced the global code of conduct of the corporate group to which it belongs. It further clarified that the incomplete nature of its processing register at the beginning of the investigation had not caused any harm to the data subjects. 40. The Restricted Panel took note of the auditee's request to waive the imposition of an administrative fine. It will focus below on analyzing the criteria necessary to determine whether an administrative fine should be imposed and, if so, the amount of the administrative fine under Article 83 of the GDPR. In this context, the Restricted Panel will apply the five-step method specified in the Guidelines on the Calculation of Fines. 2.1.1. Step 1: Identify the processing operations relevant to the case 41. In accordance with the Guidelines on the Calculation of Fines, it is essential that the supervisory authority determine, firstly, whether one or more of the auditee's conducts are subject to sanctions and whether these conduct constitute one or more violations attributable to the auditee, taking into account the specific circumstances of the case. 19 42. These guidelines specify that when assessing a same processing operation or related processing operations, the supervisory authority may take into account, in its assessment of infringements, all legally necessary obligations for the processing operations to be 17Statement of objections, page 13, paragraph 49. 18 See the auditee's letter of 12 November 2024 in response to the statement of objections. 19 Guidelines on the calculation of fines, Chapter 3; paragraphs 25 et seq. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 13 22 carried out in compliance with the law, including, for example, obligations regarding 20 transparency (for example, Article 13 of the GDPR). 43. In this case, the auditee is to be considered the data controller within the meaning of the GDPR for the establishment of the processing register and for the processing activities listed therein within the meaning of Article 30(1) of the GDPR (see paragraph 17 of this decision). The implementation of a record of processing activities is carried out within the framework of a unified objective which is closely linked in context, space, and time. In this case, the Restricted Panel therefore considers that it is a matter of penalizing a single act of conduct within the meaning of Chapter 3.1 of the Guidelines on the Calculation of Fines. 2.1.2. Step 2: Setting the Starting Amount for the Subsequent Calculation of the Fine 44. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority must, secondly, set the starting amount for the subsequent calculation of the fine 21 in light of the specific circumstances and based on an assessment of three elements: - the classification of the infringement under Article 83(4) to (6) of the GDPR; - the seriousness of the infringement; and 22 - the company's turnover. 2.1.2.1. Classification of violations under Article 83(4) to (6) of the GDPR 45. Regarding the classification of violations, the GDPR provides for two categories: violations punishable under Article 83(4) of the GDPR and violations punishable under Article 83(5) and (6) of the GDPR. For the first category of violations, the maximum fine that may be imposed is €10 million or 2% of the company’s annual turnover, whichever is higher. For the second category of violations, the maximum fine that may be imposed is €20 million or 4% of the company’s annual turnover, whichever is higher. 20 Guidelines on the calculation of fines, paragraph 27. 21Guidelines on the calculation of fines, Chapter 4. 22Guidelines on the calculation of fines, paragraph 48. ___________________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 14 22 46. By this categorization, the European legislator provided an initial (abstract) indication of the seriousness of the infringement. Indeed, the more serious the infringement, the higher 23 the fine is likely to be. 47. The Restricted Panel notes that the alleged breach by the audited party, in particular the breach of Article 30(1)(a), (c), and (f) of the GDPR, falls under the provisions of Article 83(4) of the GDPR, meaning that this breach belongs to the first category of violations and is therefore among the less serious violations. 2.1.2.2. The seriousness of the breach 48. When determining the seriousness of the breach, it is necessary to examine the nature, seriousness, and duration of the breach (Article 83(2)(a) of the GDPR), as well as whether it was intentional or negligent (Article 83(2)(b) of the GDPR) and the categories of personal data concerned by the breach (Article 83(2)(g) of the GDPR). 24 49. Regarding the nature of the violation (Article 83(2)(a) of the GDPR), the Restricted Panel Concerning the breach of Article 30(1)(a), (c), and (f) of the GDPR, the European legislator intended to strengthen the documentation obligations of the data controller by requiring them to document all their data processing activities in a record of processing activities. This record is intended to facilitate the analysis and inventory of all the data processing activities of the data controller and, consequently, the demonstration of its compliance with the GDPR. 50. Regarding the seriousness of the violation (Article 83(2)(a) of the GDPR), the Restricted Panel takes into account the number of data subjects affected and the level of damage they have suffered. 51. Regarding the number of affected individuals, the 25 Restricted Panel notes that the audited entity employs [more than 400 employees] and that the number of potentially affected third parties is undefined. 52. Regarding the level of harm suffered by the affected individuals, it considers that the individuals concerned did not suffer harm due to the incomplete processing register. 23 Guidelines on the calculation of fines, paragraphs 49 and 50. 24 Guidelines on the calculation of fines, paragraph 51 et seq. 25 See letter from the audited party dated December 20, 2023. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Investigation No. […] conducted at Company A 1522 53. Regarding the criterion of the duration of the breach (Article 83(2)(a) of the GDPR), the Restricted Session notes that, as the GDPR entered into force in May 2018, the duration of the breach on the date of the on-site visit of December 19, 2023, was at least 5 years and 6 months. 54. Regarding the question of whether the infringement was committed intentionally or through negligence (Article 83(2)(b) of the GDPR), the Restricted Panel reiterates that an administrative fine under Article 83 of the GDPR can only be imposed if it is established that the controller committed, intentionally or negligently, a 26 infringement as defined in paragraphs (4) and (6) of that article. “Intent,” meaning an infringement committed intentionally, includes both knowledge and will in relation to the characteristics of an infringement, whereas “not intentionally” (through negligence) means that there was no intention to commit the infringement, although the controller or processor failed to comply with 27 its duty of care under the law. The Restricted Panel considers that the audited party could not have been unaware of the existence of 28 the violated obligation. It agrees with the lead investigator who determined that the violation resulted from “a improper execution of this obligation as well as a lack of adequate verification by the [o]rector”. In light of the foregoing, the Restricted Panel is of the opinion that the facts and the observed breach do not demonstrate a deliberate intention to violate the GDPR on the part of the audited party. Nevertheless, it finds that the breach was committed through negligence. 55. Regarding the categories of personal data concerned (Article 83(2)(g) of the GDPR), the Restricted Panel finds that the processing register does not contain personal data. 26 In a judgment of 5 December 2023, the CJEU (Grand Chamber) held that an administrative fine under Article 83 of the GDPR may be imposed “only if it is established that the controller, which is both a legal person and an undertaking, has committed, deliberately or negligently, an infringement referred to in paragraphs 4 to 6 of that article”. In this regard, the CJEU clarified that “a controller may be sanctioned for conduct falling within the scope of the GDPR provided that the controller could not have been unaware of the unlawful nature of its conduct, whether or not it was aware of infringing the provisions of the GDPR […]” (Judgments of 5 December 2023 (Grand Chamber), Deutsche Wohnen, C-807/21, ECLI:EU:C:2023:950, paragraph 76). 27 Guidelines on the application and setting of fines, pages 11 to 12. 28 Judgments of 5 December 2023 (Grand Chamber), Deutsche Wohnen, C-807/21, ECLI:EU:C:2023:950, paragraph 76 and Nacionalinis visuomenės sveikatos centras, C-683/21, ECLI:EU:C:2023:949, paragraph 81. 29 Statement of objections, paragraph 91. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 16/22 56. Having regard to its assessment of the relevant criteria of Article 83(2)(a), (b) and (g) of the GDPR above, the Restricted Session considers that the classification the degree of severity of the violations is to be considered low. 2.1.2.3. The company's turnover 57. To complete step 2, the Restricted Panel takes into account the company's turnover in accordance with the Guidelines on the calculation of fines. 30 58. The Restricted Panel recalls that, in accordance with EU law and the case law of the CJEU, the reference, made in recital (150) 31 of the GDPR, to the concept of "undertaking" within the meaning of Articles 101 and 102 of the TFEU must be understood within the specific context of calculating administrative fines. Therefore, the concept of "enterprise" is defined as the "economic unit," which consists of a unitary organization of personal, tangible, and intangible elements pursuing a specific economic goal in a sustainable manner, even if, from a legal point of view, this economic unit is made up of several natural or legal persons. 32 59. Thus, it considers that in this case the relevant economic unit, with regard to the alleged infringement, is the group of companies headed by the company […], a company incorporated under […] law, which indirectly holds 100% of the share capital of the controlled entity. 33 60. It notes that the consolidated net turnover of the company […] for the year 2023 amounted to EUR [company with turnover exceeding 500 million euros]. 4 Furthermore, the net turnover of the controlled entity for the year 2023 amounted to EUR […] with a net profit of EUR […] according to the 2023 annual accounts. 2.1.3. Step 3: Assessing Aggravating and Mitigating Circumstances 61. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority must, as a third step, assess whether there are aggravating or mitigating circumstances. 30 See Guidelines on the Calculation of Fines, Chapter 4.3, paragraphs 63 to 69. 31 The Treaty on the Functioning of the European Union (TFEU). 32 Judgment of 5 December 2023, Deutsche Wohnen, C-807/21, ECLI:EU:C:2023:950, paragraphs 56 and 57; see also Guidelines on the Application and Setting of Fines, page 6 and Guidelines on the Calculation of Fines, paragraph 118 et seq. 33 See Statement of objections, point 7 and Exhibits Nos. 2 and 5. 34 Statement of objections, point 7 and Exhibits Nos. 6, 7 and 8. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 17/22 35 are applicable to the circumstances of the case. The guidelines specify that the supervisory authority must consider each criterion provided for in Article 83(2) of the GDPR only once. Thus, after assessing, in step 2, the nature, seriousness, and duration of the violation (Article 83(2)(a) of the GDPR), as well as whether it was intentional or negligent (Article 83(2)(b) of the GDPR), and the categories of personal data concerned (Article 83(2)(g) of the GDPR), the Restricted Panel will assess the other aggravating and mitigating circumstances under Article 83(2) of the GDPR (Article 83(2)(c), (d), (e), (f), (h), (i), (j), and (k) of the GDPR). 62. Regarding the measures taken by the audited party to mitigate the harm suffered by data subjects (Article 83(2)(c) of the GDPR), the Restricted Panel considers, initially, that the data subjects have not suffered any harm (see paragraph 52 of this decision). Next, it notes, without prejudging the satisfactory nature of the measures taken by the audited party, that the audited party sent, on November 12, 2024, a copy of its amended processing register in order to address the deficiencies raised by the lead investigator in his statement of objections. It notes that these measures were implemented after the statement of objections was sent. These measures will be analyzed in Chapter II.2, Section 2.2 of this decision. In summary, it observes that all the measures taken by the audited party were implemented only after the start of the investigation. Therefore, the Restricted Panel is of the opinion that these circumstances should be considered neutral. 63. Regarding the degree of cooperation established with the CNPD (National Commission for Data Protection) in order to remedy the violation and mitigate its potential negative effects (Article 83(2)(f) of the GDPR), the Restricted Panel notes that, in light of the investigation file and, in particular, the responses provided by the responsible party during the investigation procedure, it must be concluded that the responsible party's cooperation was satisfactory. However, it reiterates that the responsible party is subject to a general obligation of cooperation under Article 31 of the GDPR. Therefore, it considers these circumstances to be neutral. 64. Regarding any other aggravating or mitigating circumstances applicable to the circumstances of the case (Article 83(2)(k) of the GDPR), the lead investigator noted, “as aggravating circumstances, that in this case, it could reasonably be expected that the [t]omitted entity, given its size and resources, would establish a register of 35Guidelines on the calculation of fines, Chapter 5. 36Guidelines on the calculation of fines, paragraphs 70 to 72. ___________________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Investigation No. […] conducted with Company A 18/22 processing in accordance with the requirements of the GDPR and that it carries out regular reviews” of said 37 register. As mitigating circumstances, the lead investigator noted that the audited party had “gone beyond the obligations imposed by Article 30.1 of the GDPR by including in the register of processing activities additional information such as the legal basis for the processing”. 38 The Restricted Panel takes into account the aforementioned elements and concurs with the opinion of the lead investigator. 65. The Restricted Panel finds that the other criteria of Article 83(2) of the GDPR are neither relevant nor likely to influence its decision regarding the imposition of an 39 administrative fine and its amount, and therefore it will not analyze them. 66. Therefore, taking into account the assessment of the relevant criteria in Article 83(2) of the GDPR, the Restricted Panel considers that the imposition of an administrative fine is justified for the breach of Article 30(1)(a), (c), and (f) of the GDPR. 2.1.4. Step 4: Determining the applicable maximum statutory amount 67. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority 40 must, fourthly, determine the applicable maximum statutory amounts. The guidelines reiterate that the GDPR does not assign fixed amounts to specific breaches, but that the GDPR provides for general maximum amounts. Therefore, it is necessary to ensure that these maximum amounts are not exceeded. 41 68. The Restricted Panel has already noted that the consolidated net turnover of the company […] for the year 2023 amounted to EUR [company with turnover exceeding 500 million euros] (see paragraph 60 of this decision). 69. The Restricted Panel notes that insofar as the sole infringement alleged against the audited party (namely, the infringement of Article 30(1)(a), (c) and (f) of the GDPR) falls within the scope of Article 83(4) of the GDPR, the maximum amount of the fine that may be imposed is €10 million or 2% of the annual turnover of 37Statement of objections, paragraph 51. 38Statement of objections, paragraph 52. 39 40Guidelines on the calculation of fines, paragraph 6. Guidelines on the calculation of fines, Chapter 6. 41Guidelines on the calculation of fines, paragraphs 112 and 113. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with the Company A 19/22 the company, “the higher amount being retained,” in accordance with Article 83(4) of the GDPR. Therefore, the Panel determines that in this case the maximum amount of an administrative fine 42 is EUR […] (i.e., 2% of the company’s annual turnover). 70. In the present case, taking into account steps 1 to 4 of this decision (see paragraphs 41 to 69), and more specifically the fact that a single infringement has been established in this case, the classification of the infringement under Article 83(4) of the GDPR, its low severity, and the assessment of the aggravating and mitigating circumstances in this case, the Restricted Panel considers that the administrative fine to be imposed should amount to €7,000. 2.1.5. Step 5: Determine whether the final amount of the calculated fine is effective, proportionate, and dissuasive 71. In accordance with the Guidelines on the Calculation of Fines, the supervisory authority must, fifthly, ensure that the administrative fine imposed for the GDPR infringement(s) referred to in Article 83(4) to (6) is, in each case, effective, proportionate, and dissuasive, as required by Article 83(1) of the GDPR. According to the EDPB, it is the responsibility of the supervisory authority to verify whether the amount of the fine meets these requirements or whether further adjustments to the amount are necessary. 72. The Restricted Panel considers that the amount of the fine appears to be effective, proportionate, and dissuasive, in accordance with the requirements of Article 83(1) of the GDPR. 2.2. Regarding the implementation of corrective measures 73. In the statement of objections, the lead investigator also proposed to the Restricted Panel that it adopt the following corrective measures (excluding administrative fines): • “remind the Controlled Party of the need to include in the Register of processing activities the information required under Article 30.1(a), (c), and (f) of the GDPR; 42 According to the sliding scale specified in point 115 et seq. of the Guidelines on the Calculation of Fines. 43Guidelines on the Calculation of Fines, Chapter 7. 44Guidelines on the Calculation of Fines, paragraph 132. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Inquiry No. […] conducted with Company A 20/22 • to issue an order against the Inspected Party, giving it a period of 1 month from the date of notification of the decision on the outcome of the inquiry, to bring the Register of Processing Activities into compliance with the provisions of Article 30.1 (a), (c) of the GDPR and more specifically to complete the Register of Processing Activities as follows: - by indicating the name and contact details of the data controller as well as the contact details of the data protection officer, - by providing descriptions of each category of data processed, for example, by listing, within each category, examples of the types of processed data, - by indicating, in a specific or determinable manner, the planned deadlines for the deletion of the different categories of processed data, as well as providing any supporting documentation that can demonstrate compliance with this injunction; […]”.5 74. Regarding the corrective measures proposed by the lead investigator and by reference to paragraph 36 of this decision, the Restricted Panel takes into account the steps taken by the audited party to comply with the provisions of the GDPR, as detailed in its letter of 12 November 2024. In particular, it notes the following facts: 75. Regarding the warning (see paragraph 73, first point of this decision) proposed by the lead investigator for the breach identified under Article 30(1)(a), (c) and (f) of the GDPR, the Restricted Panel considers the compliance measures taken by the audited party in this case and finds that there is no need to impose the corrective measure proposed by the lead investigator in this regard. 76. Regarding the order for bringing the processing into compliance (see point 73, second point of this decision) proposed by the lead investigator for the breach identified under Article 30(1)(a), (c), and (f) of the GDPR, the Restricted Panel notes that the audited party, in its response to the statement of objections, sent a revised processing register (hereinafter: the “new processing register”). It mentioned in its letter of November 12 45 Statement of objections, point 63. ______________________________________________________________ Decision of the National Commission sitting in restricted session on the outcome of Investigation No. […] conducted with Company A 21/222024 that all missing or inaccurate information noted by the lead investigator in his statement of objections has been completed and/or corrected. The Restricted Panel notes that the new processing register does indeed contain all the information required by Article 30(1) of the GDPR. Considering the sufficient compliance measures taken by the audited party in this case, the Restricted Panel therefore considers that there is no need to impose the corrective measure proposed by the lead investigator in this regard. In light of the foregoing, the National Commission, sitting in its restricted panel, after deliberation, decides: - to find a breach of Article 30(1)(a), (c), and (f) of the GDPR; - to impose an administrative fine on Company A in the amount of 7,000 (seven thousand euros) for the breach of Article 30(1)(a), (c), and (f) of the GDPR. Belvaux, April 30, 2025 The National Commission for Data Protection, sitting in restricted session Tine A. Larsen, Marc Lemmer, Marc Hemmerling Chair, Commissioner, Alternate Member Information on appeal procedures This administrative decision may be appealed within three months of its notification. This appeal must be brought before the Administrative Court and must be filed through a lawyer admitted to the Bar of one of the Bar Associations. ______________________________________________________________ Decision of the National Commission, sitting in restricted session, on the outcome of Inquiry No. […] conducted with Company A 22/22




