[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYX6ojOL731mAuE7N9xRrrvQlQoKooTPTn2MiEJsurmM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"e104b5f2-e63a-4a2f-85f6-deeeea7c9116","german-court-upholds-gdpr-lawful-basis-for-public-pool-id-and-video-surveillance","76ddbd6b-3d26-437e-8b96-d714ed86038e","German Court Upholds GDPR Lawful Basis for Public Pool ID and Video Surveillance","A Berlin administrative court overturned a DPA reprimand against a public swimming pool operator, affirming that requiring photo ID and operating entry\u002Fexit video surveillance were lawful under GDPR Article 6(1)(e) — the public interest basis — rather than a violation of Article 5(1)(a). This case highlights how organizations can face regulatory action when the legal basis for data processing activities is not clearly documented and communicated upfront. It underscores that not all data collection constitutes a GDPR violation; the proportionality and necessity of the measure in context are critical factors. Organizations must proactively establish and document the correct lawful basis for each processing activity to withstand regulatory scrutiny, rather than reacting after a complaint or reprimand.","**Immediate actions:**\n- Conduct a rapid audit of all existing data processing activities to verify that the correct GDPR lawful basis (e.g., consent, public interest, legitimate interest) is documented for each.\n- Post clear, accessible privacy notices at points of data collection (e.g., entry gates, camera zones) explaining the purpose and legal basis for processing.\n\n**Long-term improvements:**\n- Maintain a comprehensive Record of Processing Activities (RoPA) as required by GDPR Article 30, updated whenever new processing activities are introduced.\n- Perform Data Protection Impact Assessments (DPIAs) for all high-risk processing activities, including video surveillance, before deployment.\n- Engage a qualified Data Protection Officer (DPO) or legal counsel to review processing activities against applicable national and EU legal frameworks on an annual basis.\n\n**Regulatory engagement measures:**\n- Establish a proactive communication channel with your local DPA to seek informal guidance before implementing new surveillance or ID-verification measures.\n- Develop and rehearse a DPA inquiry response procedure so that documented justifications can be submitted promptly and accurately if a reprimand or investigation arises.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) — Lawfulness, fairness, and transparency","GDPR Article 6(1)(e) — Processing necessary for public interest tasks","GDPR Article 30 — Records of Processing Activities (RoPA)","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","GDPR Article 37-39 — Data Protection Officer obligations","NIST Privacy Framework PR.PP-P4 — Privacy policies and notices","NIST SP 800-53 IP-1 — Consent and Authority","CIS Control 3 — Data Protection","ISO\u002FIEC 27701:2019 — Privacy Information Management (PIMS)","ITIL — Service Design: Compliance and Policy Management","published","2026-08-17T12:20:23.448714+00:00","2026-08-17T12:20:23.104+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=VG_Berlin_-_42_K_73\u002F25&diff=52699&oldid=0","vg-berlin-42-k-73-25-9b4839","VG Berlin - 42 K 73\u002F25",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]