← Regulators
GDPR EU 2016/679 Luxembourg

Who is the CNPD: Luxembourg's data regulator behind the €746M Amazon fine

The CNPD is Luxembourg's GDPR supervisory authority — a small national regulator that issued the second-largest GDPR fine in history, €746 million against Amazon, because so many global companies base their EU operations in the Grand Duchy. What it is, how its collège is composed after the 2025 change, and why a tiny country's regulator carries outsized weight. Every fact sourced.

Luxembourg has fewer than 700,000 inhabitants, yet its data regulator issued the second-largest GDPR fine ever — €746 million against Amazon. The reason is the same one that explains so much of EU data enforcement: companies pick their corporate home for tax and structure, and that home’s regulator inherits them. Amazon Europe Core is headquartered in Luxembourg, so the Commission nationale pour la protection des données (CNPD) became its lead GDPR regulator. This is a profile of what the CNPD is, how it is run, and why it punches so far above its size. Every fact is sourced.

Quick facts

  • Full name: Commission nationale pour la protection des données (CNPD) — Luxembourg’s National Data Protection Commission
  • Role: Luxembourg’s GDPR supervisory authority; a member of the EDPB
  • Legal basis: the Law of 1 August 2018 organising the CNPD and the general data protection framework (CNPD — Composition)
  • Structure: a collège of a President and three Commissioners, backed by reserve commissioners (CNPD — Composition)
  • President: Tine A. Larsen (CNPD — Composition)
  • Commissioners: Thierry Lallemang, Alain Herrmann and Florent Kling — Kling sworn in on 29 August 2025, succeeding Marc Lemmer (CNPD)
  • Seat: 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg (CNPD — Composition)
  • Website: cnpd.public.lu

What the CNPD is — and why it matters more than its size suggests

The CNPD is Luxembourg’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and its GDPR supervisory authority, one of the 27 national authorities on the EDPB. It is organised under the Law of 1 August 2018 (CNPD — Composition).

On paper it is the regulator of a very small country. In practice it carries weight far beyond Luxembourg’s borders, for one structural reason: the Grand Duchy is a corporate and financial domicile. A great many multinationals — in e-commerce, fund management, payments and technology — locate an EU holding or operating company there. Under the GDPR’s one-stop-shop, the regulator of a company’s EU main establishment becomes its lead supervisory authority for cross-border processing. So when a company’s European base sits in Luxembourg, the CNPD inherits a case that affects people across the whole EU. That is exactly how a 700,000-person country ended up issuing a €746 million fine.

It is not an AI Act authority and not a court; like every DPA, its AI-relevant work runs through the GDPR.

The defining case: Amazon, €746 million

The CNPD’s single most consequential decision — and the one that put it on the global map — was its €746 million fine against Amazon Europe Core in July 2021 (ICLG), the second-largest GDPR fine ever imposed. It followed a 2018 complaint about how Amazon obtained consent for behavioural advertising, and the CNPD found Amazon could not rely on “legitimate interest” as the legal basis.

The story did not end there. On 12 March 2026, Luxembourg’s Cour administrative annulled the fine — but on procedure, not substance: the court confirmed that Amazon’s reliance on legitimate interest was not justified, yet held that the CNPD had not properly analysed Amazon’s degree of negligence under EU case law that developed after the decision. The CNPD must now re-run that analysis. The full case — amount, articles, the annulment and what it means — is detailed in the Big Tech GDPR fines registry.

That single case captures the CNPD’s profile: a small authority handling some of the largest, most legally complex matters in Europe, precisely because of who is headquartered on its territory.

How the CNPD is run

The CNPD is run by a collège — a collegiate body, not a single director. As confirmed on its official composition page, the collège is President Tine A. Larsen with Commissioners Thierry Lallemang, Alain Herrmann and Florent Kling, supported by four reserve commissioners (Romy Schaus, Martine Kraus, Marc Hemmerling and François Thill) (CNPD — Composition). The most recent change was the swearing-in of Florent Kling on 29 August 2025, who replaced Marc Lemmer (CNPD) — so a profile that still lists Lemmer is out of date.

Decisions of a collegiate authority are the institution’s, not one person’s — and in cross-border cases they are also subject to the EDPB’s Article 65 dispute-resolution power, the same mechanism that shaped the largest fines elsewhere.

What this means for you

  • If your EU holding or operating company is in Luxembourg: the CNPD is very likely your lead GDPR regulator — and the Amazon case shows it will take on the biggest questions. Domiciling in a small country does not mean a small regulator.
  • If you rely on “legitimate interest” for advertising: the Amazon decision is the cautionary tale. Even after the annulment, the CNPD’s substantive finding — that legitimate interest did not justify the behavioural-advertising processing — was upheld.
  • If you are a journalist or researcher: “Luxembourg’s privacy regulator” = the Commission nationale pour la protection des données (CNPD), organised under the Law of 1 August 2018, a collège chaired by Tine A. Larsen, seated in Belvaux.

TL;DR

The CNPD (Commission nationale pour la protection des données) is Luxembourg’s GDPR supervisory authority and a member of the EDPB, organised under the Law of 1 August 2018 and run by a collège chaired by Tine A. Larsen (commissioners Thierry Lallemang, Alain Herrmann and Florent Kling, the last sworn in 29 August 2025). Despite governing a country of under 700,000 people, it carries outsized weight because so many multinationals base their EU operations in Luxembourg — which is how it came to issue the €746 million Amazon fine, the second-largest in GDPR history, later annulled on procedure by the Cour administrative in 2026. Its detailed enforcement is in the Big Tech GDPR fines registry.

Sources