Polish DPA Fines Individual for Unlawful CCTV Surveillance Beyond Property Boundaries
A Polish individual was fined nearly €6,174 after continuing to operate a camera surveillance system that captured public roads and neighboring properties, even after regulatory intervention and police involvement. The core failure was a deliberate disregard for both GDPR principles and a prior DPA enforcement decision, compounded by an apparent intent to harass data subjects. This case highlights that personal or residential data processing activities are not exempt from GDPR obligations, including the accountability principle under Article 5(2). The escalating penalties demonstrate that regulators will pursue repeat non-compliance aggressively, and that ignoring enforcement decisions dramatically worsens legal outcomes. Organizations and individuals alike must understand that surveillance systems must be scoped strictly to legitimate purposes and confined to spaces where there is a lawful basis for processing.
Tactical Insight
Immediate actions
- Audit the physical coverage of all surveillance cameras to ensure they capture only the controller's own property and do not extend to public areas or third-party land.
- Cease any data processing activities that have been deemed unlawful by a regulatory authority without delay, and document the remediation steps taken.
Compliance & governance improvements
- Conduct a Data Protection Impact Assessment (DPIA) before deploying any camera surveillance system, identifying legal basis, data minimization measures, and retention limits.
- Establish a clear internal policy for responding to DPA decisions and regulatory correspondence, including defined timelines and accountable owners.
- Engage a qualified data protection advisor or DPO to review surveillance practices against GDPR Articles 5, 6, and 13 requirements on an annual basis.
Detection & accountability measures
- Maintain documented records of the lawful basis and scope of all surveillance systems as required by GDPR Article 5(2) accountability obligations.
- Implement a regular review cycle (e.g., quarterly) to reassess whether existing surveillance systems remain proportionate and within legal boundaries.