Spanish Car Park Fined €90,000 for Ignoring GDPR Access Request and Destroying Evidence
ACVIL Aparcamientos violated GDPR in two compounding ways: it failed to respond to a data subject access request (DSAR) within the legally required one-month timeframe, and it deleted video surveillance footage that had been explicitly requested for preservation in legal proceedings. These failures demonstrate a lack of both procedural controls and staff awareness around data subject rights obligations. Deleting data after a preservation request transforms a compliance failure into potential evidence destruction, significantly escalating legal and financial risk. This case underscores that organisations handling video surveillance data must treat DSARs as time-critical operational tasks, not administrative afterthoughts.
Tactical Insight
Immediate actions
- Establish a formal, tracked DSAR intake process with automated deadline reminders set to trigger at day 14 and day 25 of the 30-day response window.
- Implement a documented legal hold procedure that immediately suspends any deletion or overwriting of data once a preservation or legal request is received.
- Train all staff who handle physical or digital records on how to escalate and action DSARs and legal hold notices.
Long-term improvements
- Appoint or designate a Data Protection Officer (or responsible contact) with clear ownership of DSAR response workflows and legal hold obligations.
- Review and extend video surveillance retention policies to ensure footage can be preserved on demand without being overwritten by automated loops.
- Conduct annual GDPR compliance audits covering data subject rights fulfilment, retention schedules, and legal hold capabilities.
Detection & monitoring measures
- Maintain a centralised DSAR register logging receipt date, response deadline, actions taken, and outcome for every request.
- Configure surveillance system alerts to flag when footage subject to a hold request is approaching scheduled deletion or overwrite cycles.