Back to all lessons
Awareness Lessons
5 days ago

Croatian Court Upholds GDPR Fine Against INA for Exposing Live CCTV Feeds to Customers

INA, a petrol station operator, exposed real-time CCTV footage to customers without a valid legal basis under GDPR, resulting in a €5,000 fine upheld by the Administrative Court of Split. The core failure was a lack of proper access controls and a flawed legitimate interest assessment, meaning sensitive surveillance data was accessible to anyone present without authorization. This case illustrates that CCTV systems are not exempt from GDPR obligations — any system capturing personal data must have clearly defined access restrictions and documented lawful bases. The risk of unauthorized copying or sharing of live feeds compounded the violation, demonstrating that physical security systems can create significant data protection liabilities when misconfigured.

Tactical Insight

Immediate actions

  • Restrict access to live and recorded CCTV feeds to authorized security or management personnel only.
  • Conduct an urgent audit of all surveillance systems to identify any feeds inadvertently exposed to customers, staff, or public-facing displays.

Policy & Compliance improvements

  • Perform and document a formal Legitimate Interest Assessment (LIA) or identify an alternative lawful basis before deploying any CCTV system under GDPR Article 6.
  • Implement a CCTV usage policy that explicitly defines who can access feeds, for what purpose, and for how long footage is retained.
  • Display clear and compliant GDPR privacy notices at all locations where CCTV is in operation.

Long-term improvements

  • Integrate CCTV system design into your Privacy by Design framework to ensure data protection controls are built in from the outset.
  • Schedule periodic third-party privacy impact assessments (DPIAs) for all surveillance and monitoring technologies.
  • Train facilities and operations staff on GDPR obligations related to physical surveillance systems.