The Spanish authority imposes a sanction on COFAMA XXI S.L. for failures in information regarding a video surveillance system

Obsolete and incomplete video surveillance signage, even if corrected during the procedure, constitutes a breach of the transparency obligation under Article 13 of the GDPR.

Facts and context

The Spanish Data Protection Agency (AEPD) has today published a sanction decision against the company COFAMA XXI S.L., including the imposition of a fine of €1,200, for failures related to the information provided to individuals filmed by its video surveillance system.

The procedure was initiated following a complaint dated 9 July 2024 concerning the signage and management of the video surveillance system at a service station.

Reasons for the decision

The authority found a breach against the company:

  • Information obligation (Article 13 of the GDPR): The investigation established that the company, as the controller, operated a system of 16 cameras at its service station. The authority judged that the signage in place was deficient, as it was obsolete and did not provide effective and up-to-date information to the data subjects, as required by the transparency principle. Although the company updated its information panels on 24 February 2025, the authority considered that the breach occurred during the prior period, in violation of the requirements of Article 13 of the GDPR, specified for video surveillance by Article 22, paragraph 4, of the Spanish Organic Data Protection Law.

Authority's decision

Consequently, the authority imposed a fine of €1,200 on COFAMA XXI S.L. This final amount results from an initial fine of €2,000, reduced by 40% following the acknowledgment of responsibility and voluntary payment by the company before the closure of the procedure, in accordance with Article 85 of Spanish Law 39/2015.

Lessons learned

This decision reminds that:

  • Signage of a video surveillance system must provide complete and updated information, in accordance with Article 13 of the GDPR; a simple pictogram or obsolete mention is insufficient.
  • Compliance during the investigation procedure, although positive, does not erase the initial breach and does not prejudge the outcome of the procedure.
  • The controller is the entity that determines the purposes and means of the processing and cannot exempt itself from its obligations by denying this status during the initial stages of an investigation.
  • Procedures for exercising rights, notably the right of access to images, must be clearly defined and communicated, ensuring that requirements (such as providing a recent photo for identification) are justified and proportionate.
  • National procedural mechanisms, such as acknowledgment of responsibility and voluntary payment, can be a strategic option allowing a significant reduction of the fine amount.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire