[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2Mv-ldeOQvZ6ojNZbDLJLWRgTg6WBc2YiiYzo7gf8Jc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"2c29a8da-acf0-4e9d-a88d-41a14b7d4a46","croatian-court-upholds-gdpr-fine-against-ina-for-exposing-live-cctv-feeds-to-customers","723a18b0-07fa-4f25-a389-280850955bb2","Croatian Court Upholds GDPR Fine Against INA for Exposing Live CCTV Feeds to Customers","INA, a petrol station operator, exposed real-time CCTV footage to customers without a valid legal basis under GDPR, resulting in a €5,000 fine upheld by the Administrative Court of Split. The core failure was a lack of proper access controls and a flawed legitimate interest assessment, meaning sensitive surveillance data was accessible to anyone present without authorization. This case illustrates that CCTV systems are not exempt from GDPR obligations — any system capturing personal data must have clearly defined access restrictions and documented lawful bases. The risk of unauthorized copying or sharing of live feeds compounded the violation, demonstrating that physical security systems can create significant data protection liabilities when misconfigured.","**Immediate actions:**\n- Restrict access to live and recorded CCTV feeds to authorized security or management personnel only.\n- Conduct an urgent audit of all surveillance systems to identify any feeds inadvertently exposed to customers, staff, or public-facing displays.\n\n**Policy & Compliance improvements:**\n- Perform and document a formal Legitimate Interest Assessment (LIA) or identify an alternative lawful basis before deploying any CCTV system under GDPR Article 6.\n- Implement a CCTV usage policy that explicitly defines who can access feeds, for what purpose, and for how long footage is retained.\n- Display clear and compliant GDPR privacy notices at all locations where CCTV is in operation.\n\n**Long-term improvements:**\n- Integrate CCTV system design into your Privacy by Design framework to ensure data protection controls are built in from the outset.\n- Schedule periodic third-party privacy impact assessments (DPIAs) for all surveillance and monitoring technologies.\n- Train facilities and operations staff on GDPR obligations related to physical surveillance systems.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(f) – Integrity and confidentiality","GDPR Article 6 – Lawfulness of processing (Legitimate Interest)","GDPR Article 13\u002F14 – Transparency and privacy notices","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 PE-6 – Monitoring Physical Access","CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","ISO\u002FIEC 27001 Annex A.7 – Physical and Environmental Security","ITIL Service Design – Information Security Management","published","2026-10-06T14:20:23.053943+00:00","2026-10-06T14:20:22.695+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=US_Split_-_Us_I-2709\u002F2025-11&diff=53307&oldid=0","us-split-us-i-2709-2025-11-5dc365","US Split - Us I-2709\u002F2025-11",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]