[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbTvcT24TRCTYKQRHOO2YPWB9_67yi9woOYSuv-D3epg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"be4c1219-12bd-4a01-ac07-b13c1e5dc348","greek-dpa-fines-two-organizations-160k-for-cctv-and-dsar-gdpr-violations","838fff4b-6830-40a2-aa79-946ac3e3db59","Greek DPA Fines Two Organizations €160K for CCTV and DSAR GDPR Violations","Two Greek organizations — an exhibition center and a supermarket chain — were fined a combined €160,000 for failing to comply with core GDPR obligations, including improper disclosure of CCTV footage, inadequate responses to data subject access requests (DSARs), and breaches of fundamental data protection principles. These violations indicate systemic gaps in privacy governance, staff training, and operational procedures for handling personal data. CCTV systems are a common blind spot where organizations fail to implement proper retention limits, access controls, and disclosure policies. Ignoring or mishandling DSARs further compounds legal exposure and erodes the trust of data subjects. This case underscores that regulators are actively enforcing GDPR across routine operational practices, not just high-profile data breaches.","**Immediate actions:**\n- Audit all CCTV systems to ensure footage retention periods comply with GDPR minimisation principles and are documented in a retention schedule.\n- Establish a formal DSAR intake and response process with assigned ownership, templated responses, and a tracked 30-day deadline.\n- Review and restrict access to CCTV footage so only authorised personnel can view, share, or disclose recordings.\n\n**Long-term improvements:**\n- Conduct a Data Protection Impact Assessment (DPIA) for all surveillance systems and update privacy notices to reflect CCTV data processing activities.\n- Implement a Records of Processing Activities (RoPA) register that captures all personal data flows, including video surveillance, to support accountability obligations.\n- Appoint or empower a Data Protection Officer (DPO) to perform periodic internal compliance audits against GDPR requirements.\n\n**Detection & monitoring measures:**\n- Deploy a centralised log management solution to record who accesses CCTV systems, when, and for what stated purpose.\n- Set up automated alerts for DSAR deadlines and escalation triggers to prevent regulatory breaches due to missed response windows.\n- Schedule quarterly privacy compliance reviews to identify and remediate gaps before they result in regulatory action.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 12 – Transparent information and communication","GDPR Article 15 – Right of access by the data subject","GDPR Article 25 – Data protection by design and by default","GDPR Article 30 – Records of processing activities","GDPR Article 35 – Data protection impact assessment","NIST Privacy Framework PR.DS-P1 – Data management policies","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL – Service Request Management (for DSAR handling workflows)","published","2026-07-01T10:21:10.010415+00:00","2026-07-01T10:21:09.702+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=HDPA_(Greece)_-_10\u002F2026&diff=52040&oldid=52012","hdpa-greece-10-2026-712eb0","HDPA (Greece) - 10\u002F2026",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]