[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuCpa6n4o6NYJoRPkQy9gyKQDelGlE_O19tID8sm_UAU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"e785d8dc-8ed8-4a56-86a9-92721c259dc0","romanian-railways-faces-court-damages-for-gdpr-access-request-refusal","de6b1997-8647-4729-9825-1857bdaecaa1","Romanian Railways Faces Court Damages for GDPR Access Request Refusal","The National Railways Company violated GDPR Article 15 by refusing to provide a data subject with their requested CCTV footage, ignoring both the individual's right of access and a subsequent DPA enforcement order. This case demonstrates that non-compliance with data subject access requests (DSARs) carries real legal and financial consequences beyond regulatory fines, including civil liability for immaterial damages such as stress and suffering. Organizations that dismiss or delay DSARs without lawful justification expose themselves to compounding liability — first from the supervisory authority and then from the courts. The root failure was an absence of clear internal procedures for handling access requests involving surveillance data, combined with a lack of accountability for GDPR obligations.","**Immediate actions:**\n- Establish a documented DSAR (Data Subject Access Request) handling procedure that explicitly covers CCTV and surveillance footage retrieval.\n- Assign a responsible owner (e.g., DPO or legal team) to track, respond to, and escalate all DSARs within the mandatory 30-day GDPR deadline.\n\n**Long-term improvements:**\n- Maintain a CCTV and surveillance data inventory that maps footage retention periods, storage locations, and the legal basis for processing to enable swift responses to access requests.\n- Integrate GDPR compliance obligations into staff training programs for all teams that handle personal data, including security and operations personnel.\n- Conduct periodic DSAR process audits to identify bottlenecks or gaps that could result in non-compliance.\n\n**Detection & response measures:**\n- Implement a case management system to log all DSARs and monitor response timelines, triggering alerts before deadlines are breached.\n- Define an escalation protocol so that ambiguous or disputed DSARs are reviewed by legal counsel rather than simply refused.",[12,13,14,15,16,17,18,19,20],"GDPR Article 15 (Right of Access)","GDPR Article 12 (Transparent Information and Communication)","GDPR Article 58 (Supervisory Authority Powers)","GDPR Article 82 (Right to Compensation and Liability)","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 IR-7 (Incident Response Assistance)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27001:2022 A.5.34 (Privacy and Protection of Personal Data)","ITIL Service Management — Request Fulfilment Process","published","2026-08-07T16:21:03.825126+00:00","2026-08-07T16:21:03.739+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=TS_-_703\u002F2026&diff=52643&oldid=52642","ts-703-2026-e5d4b8","TS - 703\u002F2026",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]