The Luxembourg administrative tribunal found that the CNPD wrongly dismissed complaints against US‑based data controllers Apollo and RocketReach and ordered the DPA to reopen the cases. The decision follows earlier appeals by privacy NGO noyb and a higher court that annulled a prior inadmissibility ruling.
Why it matters: The ruling reinforces the GDPR's extraterritorial reach by obligating Luxembourg's data protection authority to enforce rights against non‑EU companies.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.