Back to all lessons
Awareness Lessons
4 weeks ago

Romanian Railway Company Fined for Refusing GDPR Data Access Request

CFR SA violated GDPR by refusing to fulfil a legitimate Subject Access Request (SAR) for CCTV footage, a clear breach of data subject rights under Article 15. The refusal triggered a DPA investigation, a formal warning, a compliance order, and ultimately a court-awarded damages payment — all of which were avoidable with proper internal processes. This case demonstrates that ignoring or mishandling access requests is not a low-risk option; it exposes organisations to regulatory sanctions, civil litigation, and reputational harm. Organisations that hold video surveillance data must understand it constitutes personal data under GDPR and is fully subject to data subject rights obligations.

Tactical Insight

Immediate actions

  • Establish a documented Subject Access Request (SAR) procedure with clearly assigned ownership and a tracked 30-day response deadline.
  • Audit all CCTV and video surveillance systems to confirm they are catalogued in the organisation's data inventory and retention schedules.

Process & Policy improvements

  • Train all staff who handle personal data requests on GDPR obligations, valid grounds for refusal, and escalation paths.
  • Create pre-approved response templates and a legal-review checklist to ensure SAR decisions are defensible and consistently applied.
  • Define and document retention periods for CCTV footage to ensure requested data is preserved and retrievable within statutory timeframes.

Detection & Governance measures

  • Implement a centralised SAR tracking register so that response deadlines, decisions, and outcomes are logged and auditable.
  • Schedule quarterly compliance reviews with the Data Protection Officer (DPO) to identify patterns of non-compliance or process gaps before they escalate to DPA complaints.