September Data Protection Newsletter

Consulting

By: Pasquale Esposito

Grant Thornton Luxembourg welcomes you to the September Data Protection Newsletter!
Contents

We are here to share clear and practical insights on the latest developments in data protection, AI, and tech regulation, helping you stay informed and compliant in this ever-changing digital landscape.

Whether you manage compliance or simply want to stay safer and better informed online, this newsletter is for you.

As always, our Data Protection Team is here to help. If you would like tailored advice or to discuss a specific issue, please contact us using the details at the end of this page.

 

Smart glasses: Luxembourg CNPD and UK ICO set out their expectations

On 26 August 2026, the Luxembourg data protection authority (CNPD) published practical guidance on smart glasses (the Guidance). A few weeks later, on 17 September 2026, the UK regulator (ICO) shared a similar message about smart glasses and other AI-enabled wearable devices.

 

🧩Key takeaway

Smart glasses look like ordinary glasses but can capture images, video and audio, and may transmit recordings to online services for analysis or enable users to share them on social media. They can also offer AI-powered features, such as real-time translation and visual descriptions.

Given their ordinary appearance and these capabilities, smart glasses raise important privacy concerns, particularly where people are recorded without their knowledge or consent and their personal data is subsequently collected, processed or shared.

The CNPD’s Guidance includes the following main recommendations:

  • Respect people’s privacy: Do not record identifiable individuals without their  consent. Do not rely solely on the glasses’ recording indicator to inform others.
  • Respect recording restrictions: Follow signs, venue rules and workplace policies, and avoid recording in sensitive or private areas.
  • Check privacy settings: Review the privacy settings of the glasses and associated applications, particularly those relating to recording, cloud storage, data sharing and AI features.
  • Keep devices secure and updated: Install security updates, use strong authentication, disconnect old devices, and take prompt action if the glasses are lost or stolen.
  • Delete data when no longer needed: Avoid keeping recordings longer than necessary, including checking and deleting copies stored in associated online services. Reset the glasses before selling, giving away or recycling them.

The ICO’s Chief Executive also published a blog on the ICO’s website discussing how smart glasses could significantly affect society in areas such as surveillance, safety and trust, by combining cameras, AI and audio feedback.

 

❔Why is it important?

Smart glasses can make our daily lives easier, but they also raise important privacy concerns. When using them, individuals and organisations should respect people’s privacy and image rights. As highlighted by the CNPD, complying with the GDPR is not enough: users should also follow applicable privacy and image-rights rules, as well as any specific rules that apply in certain places, such as workplaces, schools or other private areas.

In particular, recording someone’s image or voice without their consent in a place that is not open to the public may constitute a criminal offence. Under Article 2 of the Law of 11 August 1982, such conduct may be punishable by imprisonment for eight days to one year and/or a fine of €251 to €5,000.

 

Fine or warning? EDPB explains how regulators impose GDPR fines

On 17 September 2026, the European Data Protection Board (EDPB) adopted the Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR (the “Imposition Guidelines”). They are open for public consultation until 13 November 2026.

 

🧩Key takeaway

The Imposition Guidelines replace the 2017 WP29 guidelines on fines (WP253) and complement the EDPB Guidelines 04/2022 on the calculation of fines. While the 2022 guidelines answer “how much?”, the new guidelines answer “should a fine be imposed, instead of or in addition to a warning, reprimand, order, ban or withdrawal of certification?”. 

The EDPB has established a five-step methodology for supervisory authorities to determine whether an administrative fine should be imposed for an infringement of the GDPR.

  • Check whether the GDPR or applicable national law directly allows an administrative fine for the infringement.
  • Determine whether the party responsible for the infringement, such as the controller or processor, can be held liable.
  • Establish whether the infringement was committed intentionally or through negligence. 
  • Consider the mitigating factors set out in Article 83(2) GDPR. Where an infringement is considered “minor” after taking these factors into account, an administrative fine should generally not be imposed.
  • Assess whether imposing a fine would be effective, proportionate and dissuasive in the circumstances. 

 

❔Why is it important?

These Guidelines make it easier for organisations to understand and anticipate how regulators may respond when data protection requirements are not fully met. 

In its practical examples, the EDPB highlights cases where a fine may not be appropriate. For example: if you miss an access request, respond promptly once you become aware of it, apologise, explain the situation and take corrective action. If it is a one-off incident with no previous similar cases, the infringement may be considered minor, and a reprimand may be issued instead of a fine.

 

Revolut confirms customer data breach after fake government data requests

On 12 September 2026, the fintech Revolut confirmed a customer data breach after an unauthorised third party impersonated a government agency and, using a legitimate government email domain, sent fraudulent data requests that Revolut fulfilled before detecting and blocking them.

 

🧩Key takeaway

This was not a technical intrusion into Revolut’s systems but a social engineering attack on the process for handling authority requests. According to press reports and customer notifications reviewed by researchers, the exposed data included:

  • Identity and contact data: full names, dates of birth, postal and email addresses, phone numbers and occupations;
  • KYC data: copies of passports or driving licences and verification selfies;
  • Financial data: IBANs, account statements and transaction histories.

Revolut stated that only a limited number of customers were affected (without giving a figure), that its systems and customer funds were unaffected, and that it had informed affected customers, the government agency concerned, law enforcement, and data protection and financial regulators. The attackers reportedly published data samples on Telegram and made a ransom demand.

 

❔Why is it important?

The combination of ID documents, selfies and bank details gives fraudsters a “complete identity theft kit”, which creates a high risk for the individuals concerned. 

Any organisation that receives requests from police, courts, tax or regulatory authorities, especially banks and financial institutions in Luxembourg, is exposed to the same risk. Disclosing data in response to such a request requires a valid legal basis and checking that the request is genuine is part of the security obligation under Article 32 GDPR. 

 

Luxembourg DPO of the year 2026 application

Every year, the Luxembourg House of Cybersecurity recognises an outstanding professional as DPO of the Year in Luxembourg.

This is an excellent opportunity to gain visibility, connect with Luxembourg’s data protection & cybersecurity community and showcase your achievements.

Apply Now!

French application form

English application form

Want to Learn More?

If you would like to hear first-hand about the experience, listen to our Senior Manager's podcast discussing his journey and insights after receiving the award in 2025.

We encourage all interested colleagues to consider applying and wish the best of luck to all future candidates!

 

Contact

Need advice on Data Protection, AI, or Whistleblowing compliance?

Our Data Protection team is here to support you. Contact us today to discuss your needs and explore how we can assist you: Dara Kelly, Head of Advisory, or Pasquale Esposito, Data Protection Officer.

Our expertise
Discover our GDPR, AI & data protection compliance solutions
Find out more