Back to all lessons
Awareness Lessons
2 months ago

Spanish DPA Fines Company €4,000 for Unlawful Workplace Audio Recording via CCTV

BODENSE ESTRUCTURAS Y CALDELERÍA violated GDPR's data minimisation principle by continuously recording workplace audio through its CCTV system, a practice the AEPD deemed disproportionate and unjustified. The core failure was deploying surveillance technology with capabilities beyond what was necessary for the stated legitimate purpose, without assessing whether audio recording was proportionate or legally justified. This case highlights that enabling a technical feature — even passively — constitutes data processing and carries full GDPR accountability. Organisations must treat every capability of a surveillance system as a deliberate data processing decision, not a default configuration to be ignored.

Tactical Insight

Immediate actions

  • Audit all CCTV and surveillance systems to identify and disable any audio recording functionality not explicitly justified by a documented legal basis.
  • Conduct a Data Protection Impact Assessment (DPIA) for any surveillance technology that captures personal data beyond video.

Policy & Governance improvements

  • Establish a formal review process requiring Privacy by Design sign-off before deploying or configuring any monitoring or recording system.
  • Update employee privacy notices and internal data protection policies to accurately reflect all data collected via surveillance systems.
  • Define and document the minimum data collection scope for each surveillance use case, applying the data minimisation principle explicitly.

Detection & Compliance measures

  • Schedule periodic configuration audits of physical security systems to verify they remain aligned with approved data processing activities.
  • Integrate surveillance system settings into the organisation's Records of Processing Activities (RoPA) to ensure ongoing regulatory visibility.