[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f659s1RVEosVfH4V4_4F-sfjoWvJ6TeCDgc-ijanjvXg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"70a7d8d5-f3e9-48a9-8f52-690edd200bed","romanian-railway-company-fined-for-refusing-gdpr-data-access-request","998458fa-7bc0-4f07-8ae0-55fdfc5f7831","Romanian Railway Company Fined for Refusing GDPR Data Access Request","CFR SA violated a fundamental GDPR right by refusing to provide a data subject with their own CCTV footage, resulting in a court-awarded damages ruling and a prior DPA warning. The root failure was an inadequate internal process for handling Data Subject Access Requests (DSARs), leaving staff unable or unwilling to fulfill a legally mandated obligation. This case demonstrates that GDPR compliance is not merely a policy exercise — non-compliance carries tangible legal and financial consequences. Organizations holding personal data in any form, including video surveillance, must treat access requests with the same rigor as any other legal obligation.","**Immediate actions:**\n- Establish a documented, time-bound DSAR (Data Subject Access Request) handling procedure that complies with GDPR Article 15 and the 30-day response window.\n- Designate a responsible owner (e.g., DPO or Legal team) to review and approve all incoming data access requests before any refusal is issued.\n\n**Long-term improvements:**\n- Train all staff who handle personal data or CCTV systems on GDPR data subject rights and the legal consequences of non-compliance.\n- Implement a DSAR tracking register to log request receipt dates, actions taken, and response deadlines to ensure auditability.\n- Conduct periodic internal audits of CCTV retention policies to confirm footage is accessible and retrievable within legally required timeframes.\n\n**Detection & oversight measures:**\n- Assign the Data Protection Officer (DPO) authority to escalate unresolved DSARs to senior management before statutory deadlines expire.\n- Set up automated alerts or calendar reminders when DSAR response deadlines are approaching to prevent inadvertent non-compliance.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 15 – Right of Access by the Data Subject","GDPR Article 12 – Transparent Information and Communication","GDPR Article 82 – Right to Compensation and Liability","GDPR Article 83 – General Conditions for Imposing Administrative Fines","NIST SP 800-53 IP-1 (Individual Access)","NIST SP 800-53 AR-5 (Privacy Awareness and Training)","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27001 Annex A.7.1 – Privacy and Protection of Personally Identifiable Information","ITIL Service Operation – Request Fulfillment Process","published","2026-08-07T14:20:38.830303+00:00","2026-08-07T14:20:38.513+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=TS_-_703\u002F2026&diff=52642&oldid=0","ts-703-2026-3c9fe8","TS - 703\u002F2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]