The Greek authority fines MEDÉE AE and MARKET IN AEVE for GDPR violations related to video surveillance

The Hellenic authority sanctions two companies for a total of €140,000 for breaches related to the use of a video surveillance system, notably failure to respect the right of access, lack of information, and unlawful communication of images to judicial authorities.

Facts and context

The Hellenic Data Protection Authority today published a sanction decision against the companies MEDÉE AE and MARKET IN AEVE (including the imposition of a total fine of €140,000) for breaches related to the management of a video surveillance system and respect for the rights of data subjects.

The case originated from a complaint by a natural person denouncing the unlawful processing of their data via a video surveillance system, the communication of images to third parties, and the failure to respect their right of access.

Grounds of the decision

The authority found several breaches against the two data controllers.

Regarding the company MEDÉE AE:

  • Obligation of lawfulness, fairness, transparency, and purpose limitation (Article 5 of the GDPR): The authority found that the company had used images from its video surveillance system, initially installed for the protection of property and persons, to defend its rights in judicial proceedings. This subsequent processing for a different purpose was deemed incompatible and unfair, as the data subject had not been informed at the time of collection. The authority recalls that, according to the case law of the Court of Justice of the European Union (case C-201/14, Smaranda Bara), prior information to the data subject is an essential condition for the lawfulness of processing.
  • Obligation to facilitate the exercise of rights and respond to the right of access (Articles 12 and 15 of the GDPR): The company did not respond satisfactorily and within deadlines to the complainant's access request. It requested clarifications without justifying the complexity of the request, which was interpreted as a delaying tactic aimed at hindering the exercise of the data subject's rights.
  • Obligation to inform (Article 13 of the GDPR): The video surveillance signage in place was deemed insufficient. It did not inform individuals of the possibility of subsequent processing of images, notably their communication to judicial authorities, violating the obligation to provide complete information at the time of collection.
  • Obligation to communicate the contact details of the data protection officer (Article 37, paragraph 7, of the GDPR): The company did not communicate to the supervisory authority the contact details of its data protection officer, thus failing its publication obligations.

Regarding the company MARKET IN AEVE:

  • Obligation of lawfulness, transparency, and data minimization (Article 5 of the GDPR): It was established that security agents manually directed cameras to photograph the complainant's vehicle during an incident, then transmitted these images to judicial authorities. The authority considered this processing unlawful, as it was not covered by the initial purpose of the system, and not minimized, as it specifically targeted an individual. The argument that a photo of a vehicle does not constitute personal data was rejected.
  • Obligation to facilitate the exercise of rights and respond to the right of access (Articles 12 and 15 of the GDPR): Like the first data controller, this company did not adequately respond to the complainant's access request.
  • Obligation to inform (Article 13 of the GDPR): The company provided no information to the complainant regarding the targeted collection of the image of their vehicle and its subsequent transmission, thus violating the transparency principle.
  • Obligation to cooperate with the supervisory authority (Article 31 of the GDPR): The authority noted a lack of cooperation from the company throughout the investigation procedure, constituting a separate breach.

Authority's decision

Consequently, the authority imposed a fine of €65,000 on MEDÉE AE and a fine of €75,000 on MARKET IN AEVE.

Lessons learned

This decision confirms / specifies / recalls that:

  • The use of data from video surveillance, initially collected for the security of property and persons, in judicial proceedings constitutes subsequent processing that requires specific and prior information to the data subject.
  • A data controller cannot delay or refuse to respond to an access request by invoking a need for clarification unless the request is indeed complex or excessive, which it must be able to demonstrate, notably with regard to the guidelines of the European Data Protection Board.
  • Video surveillance system signage must not only mention the main purpose but also inform data subjects of any intended subsequent processing, including the communication of data to third parties such as judicial authorities.
  • An image of a vehicle, when deliberately captured and associated with an incident involving an identifiable person, constitutes personal data whose processing must comply with the GDPR principles.
  • Lack of cooperation with the supervisory authority during an investigation constitutes a separate breach and may be subject to a specific financial penalty.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire