GDPR and data protection: compliance that works for your business.

Reassured clients, tenders won, clearer processes, stronger security. Well-built compliance becomes a commercial asset.

A woman working on a tablet in front of a server room

Our approach to GDPR.

Your real data flows first

We start by understanding how you collect, why you store and with whom you share your data. Compliance follows from your business, not from a generic template.

Sector knowledge

B2B SaaS, e-commerce, recruitment, HR services, healthcare: each sector has its own issues, and our advice reflects them.

Crisis experience

Data breaches handled under pressure, CNPD inspections supported, DPO roles held for SMEs.

A security mindset

Protecting your clients’ data also protects your trade secrets. We approach compliance with an overall view of security.

Responsiveness

A data breach does not wait. We mobilise immediately, including outside normal hours.

Compliance that evolves

New tools, new markets, new activities: your compliance keeps pace with your growth.

Method

We build the framework, your teams bring it to life.

Our role

Compliance analysis, drafting policies and procedures, team training, breach management, responses to inspections.

Your role

Applying procedures day to day, keeping operational information up to date, ongoing team awareness.

You know your processes better than anyone. Compliance built into the way you work lasts. We give you the framework and the tools, and you call us whenever a question comes up.

Our services

What we do for your GDPR.

  • Compliance projects

    Audit of your situation, data mapping, record of processing, privacy policies, team training.

  • Outsourced DPO

    Our firm appointed as your data protection officer, from €600 excl. VAT per month.

    The DPO service
  • Data breaches

    Incident assessment, notification to the CNPD within 72 hours, informing the people concerned where required.

  • Data subject requests

    Compliant, documented answers to access, rectification or erasure requests, within the one-month legal deadline.

  • CNPD inspections and proceedings

    Preparing the inspection, support before the authority, responses to the measures required.

  • GDPR litigation

    Defending your interests in court in disputes involving personal data.

Common topics

The GDPR questions we see most often in Luxembourg.

  • Data processing agreements required by your clients or imposed by your suppliers.
  • Workplace monitoring (CCTV, geolocation, monitoring of IT tools) and its specific rules under Luxembourg employment law.
  • Candidate and employee data: what you can collect, and for how long.
  • Email marketing and consent.
  • Data transfers outside the European Union (cloud tools, international providers).
  • Artificial intelligence: using AI tools with personal data.
  • Cybersecurity: the new obligations under the NIS2 directive.

Our services

Three ways to entrust us with your GDPR.

Legal subscription

Who it’s for
Companies that want comprehensive legal support
GDPR scope
Advice, compliance work, emergencies
Price
€1,210 excl. VAT per month
€750 excl. VAT for small businesses
Explore the subscription

Outsourced DPO

Who it’s for
Companies that need an appointed DPO
GDPR scope
DPO role and ongoing monitoring
Price
From €600 excl. VAT per month
Explore the DPO service

Fixed-fee matter

Who it’s for
One-off need (audit, inspection, litigation)
GDPR scope
Scope defined in the proposal
Price
Priced before we start
See fixed-fee matters

Frequently asked questions

Your questions about GDPR.

Do I have to appoint a DPO?

Appointment is mandatory for public bodies, for companies whose core activities involve regular and systematic monitoring of individuals on a large scale, and for those processing sensitive data on a large scale. Otherwise, it is often still useful, especially to meet your clients’ expectations.

What should I do after a data breach?

Contact us immediately. Where a breach poses a risk to the people concerned, it must be notified to the CNPD within 72 hours of becoming aware of it. We assess the incident, prepare the notification and help you limit its consequences.

How long do I have to answer an access request?

The GDPR sets a one-month deadline, which can be extended by two months for complex requests, provided the person is informed.

What penalties can a company face?

Administrative fines can reach €20M or 4% of worldwide annual turnover. In practice, the main risk for an SME is often commercial: a lost client, a missed tender, a stalled due diligence.

Is GDPR included in the legal subscription?

Yes, for advice, compliance work and emergencies. The appointed DPO role is part of the outsourced DPO service.

Contact

Let’s turn your GDPR into an asset.

Let’s discuss your situation, identify your priorities and build compliance that fits your business.

Write to us or call us

Describe your situation in a few lines: a lawyer will reply within the business day.

Or by email: info@infuero.lu