Just Data Lawgic

Just Data Lawgic Boutique legal practice advising on tech, data protection, AI governance and digital regulation.

04/05/2026

Email tracking just caught up with cookie rules.
CNIL makes one thing clear: visibility of the technology doesn’t reduce obligations.
Email tracking pixels are firmly regulated under ePrivacy: organisations must reassess how they inform users, collect consent, and evidence compliance across marketing and communication practices.

Email tracking just caught up with cookie rules.CNIL makes one thing clear: visibility of the technology doesn’t reduce ...
04/05/2026

Email tracking just caught up with cookie rules.
CNIL makes one thing clear: visibility of the technology doesn’t reduce obligations.
Email tracking pixels are firmly regulated under ePrivacy: organisations must re-assess how they inform users, collect consent, and evidence compliance across marketing and communication practices.

17/04/2026

Happy to have been part of ! Where top minds in AI, quantum, and supercomputing come together to explore what’s next in technology.

Two full days of mind-stimulating discussions but there is one that stood out. When Professor Vincent Lenders and Polina Tapal came on the stage we were intrigued by the format: a professor in cybersecurity and a 2nd year student in computer science interviewing each other. When they started talking we were inspired and amazed by Polina's brilliant mind.

She ran a project and published a paper on brainwave authentication, examining whether it's safer and more accurate than fingerprints, retinas, and other commonly used biometric authentication methods.

Is a brainwave personal data? Its signal is unique and it can be used to identify an individual, so absolutely yes: personal AND sensitive data! So what are the legal and ethical considerations? Oh it would take an entire paper to analyze this...

But once again a reminder that the future is not sci-fi, it's already here, and a thank you to the University of Luxembourg and the Luxembourg AI Factory for nurturing the ideas and providing the infrastructure for their realisation.

Whether you’re celebrating or not, we hope you enjoy a well-deserved spring break — time to clear your cache, refresh yo...
05/04/2026

Whether you’re celebrating or not, we hope you enjoy a well-deserved spring break — time to clear your cache, refresh your system, and maybe even back up a few good memories.
Come back recharged, more creative… and with your data (and ideas) flowing smoothly.

Most companies are already using AI; in fact if you are not using it you risk being tagged as “overly conservative and r...
17/03/2026

Most companies are already using AI; in fact if you are not using it you risk being tagged as “overly conservative and risk-averse” or too “legacy thinking”… The use is not the problem though, the problem is the lack of control around it.

From a legal and governance perspective there is a clear gap: AI is moving fast inside organisations, taken lightly as “just IT”, or even gatekept by IT teams as a “project within their remit”. Oversight is not keeping up. And don’t take me wrong, I am not talking about legal compliance here, I am talking about data architecture and governance (a concept that is very often repeated but rarely understood).

Wanna make it more concise? Here are the top 5 risks I see:

1. Lack of visibility: No inventory – no clear view of WHAT (ai tools are being used), WHO, WHY.
2. Lack of legal grounding: No purpose mapping (what we call “legal basis”) – no documentation to support the processing activities (often linked to personal data).
3. External dependency: Tools adopted quickly without understanding who your vendors are, where your data goes, if it’s reused or retained and if it contributes to machine learning/AI model training.
4. Lack of internal governance: No policy, no rules, no ownership. In the name of flexibility and innovation.
5. Regulatory positioning: All jurisdictions are in one way or another trying to regulate AI, ignoring this already at the design phase just means having to catch up later under pressure.

AI is not just another IT tool. Nor is it just another law. It eventually affects how organisations innovate and position themselves, with risks that we may only discover in the future. It’s high time organisations got the right people around the table and gave this clear ownership – and please, this does not mean that another committee will save the day!

https://jdlawgic.eu/what-companies-are-getting-wrong-about-ai/

The Luxembourg Administrative Court has annulled the €746M GDPR fine against Amazon.Our analysis of the decision and its...
16/03/2026

The Luxembourg Administrative Court has annulled the €746M GDPR fine against Amazon.

Our analysis of the decision and its implications for GDPR enforcement is available here 👇

https://jdlawgic.eu/amazon-gdpr-fine-luxembourg/

Adresse

Luxembourg

Notifications

Soyez le premier à savoir et laissez-nous vous envoyer un courriel lorsque Just Data Lawgic publie des nouvelles et des promotions. Votre adresse e-mail ne sera pas utilisée à d'autres fins, et vous pouvez vous désabonner à tout moment.

Raccourcis

Partager