[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjduv9HCBbhjYALPw7zzFCNUJnimSLhlpFY4FQVsV9SI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"0d00c410-133e-4ebf-bf43-9adf04e2a9b2","italian-research-institute-fined-for-unlawful-video-surveillance-of-employees","efb1a0cf-9aac-4756-9264-eef1c930869c","Italian Research Institute Fined for Unlawful Video Surveillance of Employees","The National Institute of Meteorological Research failed to meet basic GDPR obligations by deploying workplace video surveillance without properly informing employees and third parties of its existence or purpose. Compounding the violation, the institute expanded and relocated cameras without conducting a mandatory Data Protection Impact Assessment (DPIA), a critical safeguard required when processing activities pose high risks to individuals' rights. This case highlights how physical security measures are not exempt from data protection law and must follow the same compliance lifecycle as digital data processing. Organizations that treat surveillance as a purely operational decision—rather than a legal and privacy matter—expose themselves to regulatory fines and reputational harm.","**Immediate actions:**\n- Conduct a full audit of all existing surveillance systems to verify that proper employee and visitor notifications are displayed and documented.\n- Halt any planned expansion or relocation of cameras until a DPIA has been formally completed and approved.\n\n**Long-term improvements:**\n- Embed DPIA requirements into the project approval workflow for any new data processing activity, including physical surveillance installations.\n- Establish a Privacy by Design policy that mandates legal and DPO review before deploying any monitoring technology in the workplace.\n- Maintain an up-to-date Record of Processing Activities (RoPA) that includes all surveillance systems, their locations, purposes, and legal bases.\n\n**Governance & Training:**\n- Train HR, facilities, and IT teams on GDPR obligations specific to employee monitoring so compliance is understood across departments.\n- Assign clear ownership to the Data Protection Officer (DPO) to review and sign off on all surveillance-related changes before implementation.",[12,13,14,15,16,17,18,19],"GDPR Article 13 – Information to be provided where personal data are collected from the data subject","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 88 – Processing in the context of employment","NIST SP 800-53 IP-1: Individual Consent","NIST SP 800-53 AR-1: Governance and Privacy Program","CIS Control 3: Data Protection","ISO\u002FIEC 27701 Section 7.2.3 – Privacy Impact Assessment","ITIL Service Design – Compliance and Legal Requirements","published","2026-10-01T14:21:23.934961+00:00","2026-10-01T14:21:23.63+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10297167&diff=53263&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-10297167-ed54f6","Garante per la protezione dei dati personali (Italy) - 10297167",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]