Greek DPA Fines Two Companies €160,000 for GDPR Violations Over CCTV Data Mishandling
MEDE S.A. and MARKET IN S.A. failed to adequately respond to data subject access requests related to CCTV footage, unlawfully processed personal data, and disclosed it without authorization — all core GDPR obligations. Delayed cooperation with the Hellenic Data Protection Authority during the investigation compounded the violations and likely contributed to the severity of the fines. These failures highlight that GDPR compliance is not only about technical safeguards but also about having clear, documented processes for handling data subject rights and regulatory inquiries. Organizations operating CCTV systems must treat video footage as personal data subject to the full scope of GDPR protections. Failure to respond promptly to both data subjects and supervisory authorities signals a systemic lack of data governance maturity.
Tactical Insight
Immediate actions
- Establish a documented, time-bound procedure for handling Data Subject Access Requests (DSARs) within the statutory 30-day GDPR deadline.
- Audit all CCTV systems to confirm retention periods, access controls, and lawful basis for processing are properly documented.
- Designate a responsible point of contact (e.g., DPO) to coordinate promptly with supervisory authorities during investigations.
Long-term improvements
- Implement a Data Subject Rights Management platform to track, log, and escalate all incoming DSARs automatically.
- Conduct annual GDPR compliance reviews covering all personal data processing activities, including physical surveillance systems.
- Train legal, compliance, and operations staff on obligations when responding to DPA investigations, including cooperation requirements.
Detection & Governance measures
- Maintain detailed access logs for CCTV footage to provide an auditable trail in response to regulatory inquiries.
- Perform regular Data Protection Impact Assessments (DPIAs) for high-risk processing activities such as video surveillance in public or commercial spaces.
- Implement a breach and complaint register to identify recurring data handling failures before they escalate to regulatory action.