Back to all lessons
Awareness Lessons
2 months ago

Romanian Railways Faces Court Damages for GDPR Access Request Refusal

The National Railways Company violated GDPR Article 15 by refusing to provide a data subject with their requested CCTV footage, ignoring both the individual's right of access and a subsequent DPA enforcement order. This case demonstrates that non-compliance with data subject access requests (DSARs) carries real legal and financial consequences beyond regulatory fines, including civil liability for immaterial damages such as stress and suffering. Organizations that dismiss or delay DSARs without lawful justification expose themselves to compounding liability — first from the supervisory authority and then from the courts. The root failure was an absence of clear internal procedures for handling access requests involving surveillance data, combined with a lack of accountability for GDPR obligations.

Tactical Insight

Immediate actions

  • Establish a documented DSAR (Data Subject Access Request) handling procedure that explicitly covers CCTV and surveillance footage retrieval.
  • Assign a responsible owner (e.g., DPO or legal team) to track, respond to, and escalate all DSARs within the mandatory 30-day GDPR deadline.

Long-term improvements

  • Maintain a CCTV and surveillance data inventory that maps footage retention periods, storage locations, and the legal basis for processing to enable swift responses to access requests.
  • Integrate GDPR compliance obligations into staff training programs for all teams that handle personal data, including security and operations personnel.
  • Conduct periodic DSAR process audits to identify bottlenecks or gaps that could result in non-compliance.

Detection & response measures

  • Implement a case management system to log all DSARs and monitor response timelines, triggering alerts before deadlines are breached.
  • Define an escalation protocol so that ambiguous or disputed DSARs are reviewed by legal counsel rather than simply refused.