Regulatory Watch  /  Luxembourg  /  Court ruling
Moderate impactCourt rulingDecided

Luxembourg administrative tribunal rules CNPD must handle GDPR complaints against US controllers

The Luxembourg administrative tribunal found that the CNPD wrongly dismissed complaints against US‑based data controllers Apollo and RocketReach and ordered the DPA to reopen the cases. The decision follows earlier appeals by privacy NGO noyb and a higher court that annulled a prior inadmissibility ruling.

Why it matters: The ruling reinforces the GDPR's extraterritorial reach by obligating Luxembourg's data protection authority to enforce rights against non‑EU companies.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Luxemburg’s watchdog refuses to show its teeth to US companies
noyb · primary source · Jan 25, 2021
Luxemburg’s watchdog refuses to show its teeth to US companies
noyb · Jan 25, 2021
Details
JurisdictionLuxembourg
RegulatorCommission Nationale pour la Protection des Données (CNPD)
CourtAdministrative Tribunal of Luxembourg (first instance)
LawGeneral Data Protection Regulation
StatusDecided
PublishedJanuary 25, 2021
Effectivenot stated
DecisionSeptember 24, 2024
OrganisationsApollo, RocketReach, CNPD, noyb
Topicsaccess, cross border transfer, privacy, data brokers, deletion
Datapersonal