Back to all lessons
Awareness Lessons
3 months ago

Greek DPA Fines Two Organizations €160K for CCTV and DSAR GDPR Violations

Two Greek organizations — an exhibition center and a supermarket chain — were fined a combined €160,000 for failing to comply with core GDPR obligations, including improper disclosure of CCTV footage, inadequate responses to data subject access requests (DSARs), and breaches of fundamental data protection principles. These violations indicate systemic gaps in privacy governance, staff training, and operational procedures for handling personal data. CCTV systems are a common blind spot where organizations fail to implement proper retention limits, access controls, and disclosure policies. Ignoring or mishandling DSARs further compounds legal exposure and erodes the trust of data subjects. This case underscores that regulators are actively enforcing GDPR across routine operational practices, not just high-profile data breaches.

Tactical Insight

Immediate actions

  • Audit all CCTV systems to ensure footage retention periods comply with GDPR minimisation principles and are documented in a retention schedule.
  • Establish a formal DSAR intake and response process with assigned ownership, templated responses, and a tracked 30-day deadline.
  • Review and restrict access to CCTV footage so only authorised personnel can view, share, or disclose recordings.

Long-term improvements

  • Conduct a Data Protection Impact Assessment (DPIA) for all surveillance systems and update privacy notices to reflect CCTV data processing activities.
  • Implement a Records of Processing Activities (RoPA) register that captures all personal data flows, including video surveillance, to support accountability obligations.
  • Appoint or empower a Data Protection Officer (DPO) to perform periodic internal compliance audits against GDPR requirements.

Detection & monitoring measures

  • Deploy a centralised log management solution to record who accesses CCTV systems, when, and for what stated purpose.
  • Set up automated alerts for DSAR deadlines and escalation triggers to prevent regulatory breaches due to missed response windows.
  • Schedule quarterly privacy compliance reviews to identify and remediate gaps before they result in regulatory action.