Individual Fined for Unlawful CCTV Surveillance Violating GDPR
A Polish individual was fined for operating camera surveillance systems that extended beyond their own property onto public roads and neighbors' land, in direct violation of GDPR principles. The core failure was a disregard for a prior regulatory order to cease and remove the cameras, demonstrating willful non-compliance rather than ignorance. This case illustrates that personal data collection — including video footage of individuals in public or private spaces — is subject to strict legal boundaries under GDPR, even for private citizens. The potential use of surveillance to harass data subjects compounds the severity, highlighting how technology misuse can constitute both a data protection and a human rights violation. Regulators will impose financial penalties and may escalate enforcement when controllers fail to demonstrate corrective action.
Tactical Insight
Immediate actions
- Conduct a legal review of any surveillance systems to ensure camera coverage is strictly limited to your own property boundaries.
- Cease and document the removal of any recording equipment that captures public spaces or neighboring properties without a lawful basis.
Compliance & governance
- Establish a formal Data Protection Impact Assessment (DPIA) process before deploying any surveillance technology that may capture third-party individuals.
- Appoint or consult a Data Protection Officer (DPO) or legal advisor to ensure all monitoring activities align with applicable GDPR articles and national law.
- Maintain documented records of lawful basis, retention periods, and access controls for any personal data collected via surveillance.
Awareness & training
- Educate individuals and small business operators on GDPR obligations related to CCTV and video surveillance through accessible guidance materials.
- Implement clear signage and notification procedures wherever lawful surveillance is conducted to inform data subjects of recording activities.