[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1UsS0eNgyZL4lmTAirp0XGE2tLqZcn3kvt0IZdfgUvs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"c93c4417-d9a1-4591-9937-80aabd08b28d","polish-dpa-fines-individual-for-unlawful-cctv-surveillance-beyond-property-boundaries","aada0715-4858-41cf-ada7-3d3f703edc51","Polish DPA Fines Individual for Unlawful CCTV Surveillance Beyond Property Boundaries","A Polish individual was fined nearly €6,174 after continuing to operate a camera surveillance system that captured public roads and neighboring properties, even after regulatory intervention and police involvement. The core failure was a deliberate disregard for both GDPR principles and a prior DPA enforcement decision, compounded by an apparent intent to harass data subjects. This case highlights that personal or residential data processing activities are not exempt from GDPR obligations, including the accountability principle under Article 5(2). The escalating penalties demonstrate that regulators will pursue repeat non-compliance aggressively, and that ignoring enforcement decisions dramatically worsens legal outcomes. Organizations and individuals alike must understand that surveillance systems must be scoped strictly to legitimate purposes and confined to spaces where there is a lawful basis for processing.","**Immediate actions:**\n- Audit the physical coverage of all surveillance cameras to ensure they capture only the controller's own property and do not extend to public areas or third-party land.\n- Cease any data processing activities that have been deemed unlawful by a regulatory authority without delay, and document the remediation steps taken.\n\n**Compliance & governance improvements:**\n- Conduct a Data Protection Impact Assessment (DPIA) before deploying any camera surveillance system, identifying legal basis, data minimization measures, and retention limits.\n- Establish a clear internal policy for responding to DPA decisions and regulatory correspondence, including defined timelines and accountable owners.\n- Engage a qualified data protection advisor or DPO to review surveillance practices against GDPR Articles 5, 6, and 13 requirements on an annual basis.\n\n**Detection & accountability measures:**\n- Maintain documented records of the lawful basis and scope of all surveillance systems as required by GDPR Article 5(2) accountability obligations.\n- Implement a regular review cycle (e.g., quarterly) to reassess whether existing surveillance systems remain proportionate and within legal boundaries.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 5(1)(c) – Data minimisation","GDPR Article 5(2) – Accountability principle","GDPR Article 6 – Lawfulness of processing","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 58(2) – Corrective powers of supervisory authorities","NIST Privacy Framework PR.DS-P1 – Data processing ecosystem management","CIS Control 3 – Data Protection","ISO\u002FIEC 27001 Annex A.6.4 – Disciplinary process","EDPB Guidelines 3\u002F2019 on processing of personal data through video devices","published","2026-07-14T10:21:27.070888+00:00","2026-07-14T10:21:26.762+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKE.561.4.2026&diff=52208&oldid=52207","uodo-poland-dke-561-4-2026-74f48f","UODO (Poland) - DKE.561.4.2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]