GDPR and data protection: compliance that works for your business.
Reassured clients, tenders won, clearer processes, stronger security. Well-built compliance becomes a commercial asset.
Our approach to GDPR.
Your real data flows first
We start by understanding how you collect, why you store and with whom you share your data. Compliance follows from your business, not from a generic template.
Sector knowledge
B2B SaaS, e-commerce, recruitment, HR services, healthcare: each sector has its own issues, and our advice reflects them.
Crisis experience
Data breaches handled under pressure, CNPD inspections supported, DPO roles held for SMEs.
A security mindset
Protecting your clients’ data also protects your trade secrets. We approach compliance with an overall view of security.
Responsiveness
A data breach does not wait. We mobilise immediately, including outside normal hours.
Compliance that evolves
New tools, new markets, new activities: your compliance keeps pace with your growth.
Method
We build the framework, your teams bring it to life.
Our role
Compliance analysis, drafting policies and procedures, team training, breach management, responses to inspections.
Your role
Applying procedures day to day, keeping operational information up to date, ongoing team awareness.
You know your processes better than anyone. Compliance built into the way you work lasts. We give you the framework and the tools, and you call us whenever a question comes up.
Our services
What we do for your GDPR.
Compliance projects
Audit of your situation, data mapping, record of processing, privacy policies, team training.
Outsourced DPO
Our firm appointed as your data protection officer, from €600 excl. VAT per month.
The DPO serviceData breaches
Incident assessment, notification to the CNPD within 72 hours, informing the people concerned where required.
Data subject requests
Compliant, documented answers to access, rectification or erasure requests, within the one-month legal deadline.
CNPD inspections and proceedings
Preparing the inspection, support before the authority, responses to the measures required.
GDPR litigation
Defending your interests in court in disputes involving personal data.
Common topics
The GDPR questions we see most often in Luxembourg.
- Data processing agreements required by your clients or imposed by your suppliers.
- Workplace monitoring (CCTV, geolocation, monitoring of IT tools) and its specific rules under Luxembourg employment law.
- Candidate and employee data: what you can collect, and for how long.
- Email marketing and consent.
- Data transfers outside the European Union (cloud tools, international providers).
- Artificial intelligence: using AI tools with personal data.
- Cybersecurity: the new obligations under the NIS2 directive.
Our services
Three ways to entrust us with your GDPR.
Legal subscription
- Who it’s for
- Companies that want comprehensive legal support
- GDPR scope
- Advice, compliance work, emergencies
- Price
- €1,210 excl. VAT per month
- €750 excl. VAT for small businesses
Outsourced DPO
- Who it’s for
- Companies that need an appointed DPO
- GDPR scope
- DPO role and ongoing monitoring
- Price
- From €600 excl. VAT per month
Fixed-fee matter
- Who it’s for
- One-off need (audit, inspection, litigation)
- GDPR scope
- Scope defined in the proposal
- Price
- Priced before we start
Free resource
How compliant are you?
Our 10-question self-assessment gives you a first view of your GDPR priorities. Free, in five minutes.
Take the self-assessmentFrequently asked questions
Your questions about GDPR.
Do I have to appoint a DPO?
Appointment is mandatory for public bodies, for companies whose core activities involve regular and systematic monitoring of individuals on a large scale, and for those processing sensitive data on a large scale. Otherwise, it is often still useful, especially to meet your clients’ expectations.
What should I do after a data breach?
Contact us immediately. Where a breach poses a risk to the people concerned, it must be notified to the CNPD within 72 hours of becoming aware of it. We assess the incident, prepare the notification and help you limit its consequences.
How long do I have to answer an access request?
The GDPR sets a one-month deadline, which can be extended by two months for complex requests, provided the person is informed.
What penalties can a company face?
Administrative fines can reach €20M or 4% of worldwide annual turnover. In practice, the main risk for an SME is often commercial: a lost client, a missed tender, a stalled due diligence.
Is GDPR included in the legal subscription?
Yes, for advice, compliance work and emergencies. The appointed DPO role is part of the outsourced DPO service.
Contact
Let’s turn your GDPR into an asset.
Let’s discuss your situation, identify your priorities and build compliance that fits your business.
Write to us or call us
Describe your situation in a few lines: a lawyer will reply within the business day.
Or by email: info@infuero.lu