“The increase in complaints is undoubtedly one of the most significant lessons of the year,” said Tine A. Larsen the chairwoman of the CNPD Photo: Paperjam

“The increase in complaints is undoubtedly one of the most significant lessons of the year,” said Tine A. Larsen the chairwoman of the CNPD Photo: Paperjam

A heavier caseload, new EU duties and more complex digital disputes are pushing Luxembourg’s privacy watchdog to rank cases by harm, resolve straightforward breaches faster and create clearer routes for companies and citizens seeking help.

The National Commission for Data Protection (CNPD) said on Thursday it would change how it handles cases after receiving 846 complaints in 2025, up from 516 a year earlier.

“More citizens are exercising their rights, more organisations are turning to the CNPD and more issues require legal expertise,” CNPD chairwoman Tine A. LarsenTine A. Larsen said as she presented the authority’s annual report. “These developments reflect growing trust in the CNPD, but also greater awareness of data-protection issues.”

Its 2026–2028 strategy will give greater weight to the harm a suspected breach could cause, while allowing quicker resolution where an organisation can correct the problem without a full investigation. The authority also plans dedicated contact points for businesses and citizens and a broad overhaul of its digital systems.

The shift matters because the CNPD is handling more complaints while taking on responsibilities under a growing body of EU digital law. Rather than simply expanding enforcement, it wants to decide more deliberately which cases require formal action and which can be resolved through direct contact and corrective measures.

Cases ranked by harm

The CNPD handled 1,909 complaint files during 2025, including new and existing cases, and closed 737 of them. It had closed 448 complaints in 2024.

“The increase in complaints is undoubtedly one of the most significant lessons of the year,” Larsen said. “Citizens know their rights better and do not hesitate to exercise them.”

Most new cases involved access to personal data, requests to erase information and disputes over whether organisations were processing data lawfully. The strategy calls for complaints and investigations to be handled in a more structured way, with resources directed towards matters that have the greatest effect on people.

“The third objective reflects a change in our regulatory approach towards one based more on risk analysis and the real impact of processing on people’s rights and freedoms,” Larsen said. She said the change would require the authority to adjust its internal working culture as well as its procedures.

“This will involve preparing and carrying out a cultural change within the CNPD, as well as modernising the handling of complaints and investigations,” she said. “Where circumstances allow, it should also be possible to resolve situations of non-compliance quickly and amicably through direct and constructive exchanges.”

The authority dealt with 59 investigation files in 2025. Nineteen remained active at the end of the year, including six opened during 2025.

Earlier help for businesses

Companies are to get a dedicated contact point intended to help them raise questions while projects are still being designed. The aim is to address privacy requirements before a product, service or internal system is already in use.

“We want to establish a more structured dialogue with companies, in particular through the creation of a dedicated Business Corner designed as a genuine point of entry for economic operators,” Larsen said. She said the CNPD wanted to support organisations from the design stage so that data protection was built in from the outset rather than added later.

“Our objective remains above all to help organisations move towards data protection integrated from the design stage of their projects, through prevention, dialogue and education,” she said.

The service reflects a broader attempt to make the regulator easier to approach without weakening its ability to intervene. The strategic plan says it should provide businesses with a clearer route into the CNPD and support more regular exchanges with companies.

A route in for citizens

Citizens are to receive a separate central contact point offering both online and face-to-face access. During the public Q&A, CNPD commissioner Florent Kling said the two channels would not necessarily be introduced at the same time, but both were planned.

“The objective also includes accessibility, so we obviously have to think about the part of the population that may not have natural access to digital services,” Kling said. “For that reason, a physical element is essential.”

He said the form of the service should follow what people actually needed. “If that means sitting around a table, then it means sitting around a table,” Kling said. “If it means an accessible website or a smartphone service, that is also a success.”

An initial improvement could be introduced by the end of 2026, possibly through changes to the CNPD website. The broader service would be developed over the three-year strategy period.

Regulator updates its own tools

The authority is also planning a wider digital overhaul covering complaints, investigations and its contacts with the public and businesses. It will first assess its internal and external needs before setting out a phased programme.

“The fourth objective is the digitalisation of our tools and processes, which is essential to the effectiveness and long-term viability of all our work,” Larsen said. “We will first carry out a structured analysis of our internal and external needs in order to establish a coherent and progressive digitalisation plan.”

One project described in the annual report would use a large language model to help staff prepare draft answers to recurring information requests. Staff would continue to check, amend and approve every response before it was sent.

The CNPD answered 623 written enquiries in 2025, up from 594, and said the four-person team responsible also dealt with about 900 telephone calls a year. The most common questions concerned video surveillance, people’s rights over their data and the duties of data-protection officers.

The authority said the tool was intended to reduce time spent searching previous answers and preparing routine drafts, leaving staff more time for difficult legal questions. It could later be extended to other work, including complaint handling, but would not make decisions or send replies without human approval.

Enforcement remains in place

The move towards faster correction does not remove the CNPD’s formal powers. Its restricted decision-making panel issued eight decisions involving corrective measures in 2025, seven of which included fines totalling €216,061.

“Beyond their individual effect, these decisions also have an educational purpose,” Larsen said. “They clarify how the rules are interpreted, illustrate the CNPD’s expectations and encourage organisations to embed data protection in their practices.”

Five decisions involved organisations’ records of their data-processing activities, while two concerned video surveillance. The remaining case dealt with repeated failures to answer people exercising their rights within the required time.

The CNPD also received 425 notifications of personal-data breaches, down from 442 in 2024. Human error caused 49% of the reported incidents, with sending information to the wrong recipient the most common type of breach, followed by hacking.

“A good level of data protection depends on technology, but also on internal organisation, procedures and, above all, staff awareness,” Larsen said.

Staff numbers reached 79 in 2025, compared with 53 when the EU’s General Data Protection Regulation took effect in 2018. Larsen said the expansion reflected both the authority’s heavier workload and the specialist knowledge required as artificial intelligence, data-sharing rules and other EU digital laws broaden its remit.