Data protection in focusTine Larsen: 'It is not data protection law that stands in the way of fighting crime'

François Aulner
adapted for RTL Today
National Data Protection Commission (CNPD) president Tine Larsen says legal exceptions, not data protection rules, determine how authorities can share information to tackle crime.
© François Aulner

Amid recent public debate following corruption allegations at the General Department of Immigration, questions arose about whether data protection law hinders efforts to combat crime. Minister of the Interior Léon Gloden had suggested to the press that authorities are hitting a wall because of data protection rules, while the public prosecutor complained it could not inform municipal and state services about victims due to data protection constraints.

Tine A. Larsen, president of Luxembourg’s National Data Protection Commission (CNPD), clarified that it is not data protection itself that prevents information sharing because it primarily exists to protect citizens’ privacy and their fundamental rights. However, in specific cases, exemptions can be discussed and defined, referencing a recent amendment to criminal procedure law that allows the prosecutor’s office to inform employers or institutions dealing with youth about individuals accused in certain cases.

Larsen stressed that what is missing is not a relaxation of data protection rules, but rather a legal basis that specifically enables the desired communication. A central tenet of the ongoing debate is the protection of individuals who have not yet been convicted of a crime. When asked whether the presumption of innocence complicates information sharing, Larsen emphasised that the principle is one of our greatest rights, which must always be upheld. However, she acknowledged that exceptions could be made to other principles, such as investigative secrecy, provided these are established by law.

The once only principle: Simplifying administration, but risks remain

The conversation also touched on the government’s digitalisation agenda, particularly the so-called once only principle. The idea is that citizens should only have to provide their data once, and then different government services can access it as needed. However, both the CNPD and the Council of State have raised concerns that the draft law is not clear enough about who is responsible for the data and who may use it, when, and how.

Larsen clarified that the once only principle is a European idea intended to help administrations work more efficiently. It is not a mass surveillance tool and cannot be specifically used to detect corruption. She explained that the proposed law does not clearly set out which administrations may exchange data, for what purposes, or under what safeguards. Therefore, further legislative improvements are necessary to increase clarity and to ensure that constitutional rights to privacy and informational self-determination remain guaranteed and respected.

Artificial intelligence: Regulation, coordination, and fundamental rights

Turning to artificial intelligence, Larsen discussed the regulatory framework that is gradually coming into force in Luxembourg and across Europe. She confirmed that the EU AI Act is already partially effective, with more rules entering into force as of 2 August. It operates simultaneously to the GDPR, ensuring that personal data continues to be protected, even in AI applications.

Responsibility for different aspects of AI oversight is distributed among various authorities, such as the Luxembourg Independent Audiovisual Authority (ALIA), the Ministry of Digitalisation, and others. Larsen clarified that while the CNPD is not directly responsible for all AI oversight, it will play a coordinating role once the new law is passed.

On the question of European sovereignty and the global development of AI, Larsen noted that while everything can be regulated, the most important question remains how our society wants to live with AI. She observes that excessive regulation risks reducing innovation and Europe’s competitiveness. However, letting AI develop without any constraints also entails risks of misuse, discrimination, and mass profiling. Therefore, in Luxembourg and Europe, a balance must be struck to ensure that AI can innovate and help within a clear legislative framework that guarantees absolute respect for fundamental rights.

Back to Top
CIM LOGO