INA, a petrol station chain in Croatia, appealed, AZOP's, the DPA's, €5000 fine
The fine was based on AZOP's decision that INA, as a controller, did not take all necessary measures to prevent unauthorised access and visibility of the real-time CCTV feeds to all customers.
Status Not cited by any decision here yet
Judgment
Holding
The Court upheld the DPA's decision regardless, on two crucial grounds: the lack of compliance with the cumulative requirements to fulfil Art 6 GDPR and Art 32 (1 and 2) GDPR. Firstly, the Court sided with the DPA, stating INA, did not meet two of the three cumulative conditions, in depicting a legitimate interest for the purpose of ensuring a timely response by employees and deterring perpetrators of criminal and infringing acts. Therefore, the Court accepted the reasoning that, the requirement of necessity is not met, as the timely reaction by employees and a rapid response in the event of a harmful incident, can be achieved even without customers having real-time access to the video surveillance system. As Art 6(1)(f) prescribes that three conditions must be met cumulatively for the data controller to be able to demonstrate its legitimate interest for a lawful basis, the prescribed conditions are not cumulatively met. Secondly, the Court highlights that the screen's placement in the premises of the retail shop of the petrol station itself, with clear visibility for all, is contrary to Art 32(1) and (2) GDPR. The Court stresses INA failed to take necessary protection measures in accordance with existing and foreseeable risks of unauthorized disclosure of personal data. This becomes especially relevant, as the the controller allows customers, as unauthorised persons, access to the live feed in real time, exposing the personal data to risks such as copying, recording, or other unauthorised use of the video surveillance footage, or the sharing of such footage with third parties in any way.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
INA disputed this decision, claiming legitimate grounds for such data processing, stressing that projecting real-time CCTV feeds in petrol station shops to customers is an accepted and normal practice in the industry and by the consumers themselves.
Full text
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Case No.: US I-2709/2025-11 REPUBLIC OF CROATIA ADMINISTRATIVE COURT IN SPLIT Put Supavla l IN THE NAME OF THE REPUBLIC OF CROATIA JUDGMENT The Administrative Court in Split, before Leandra Mojtić, judge of that court, as the single judge, and Milka Škaro Grozdanić, court clerk, in the administrative dispute of the plaintiff INA – Industrija nafte d.d., Zagreb, Avenija Većeslava Holjevca 10, OIB: 27759560625, represented by Tarja Krehić, attorney-at-law in Zagreb, against the defendant, the Personal Data Protection Agency (AZOP), Zagreb, Selska cesta 136, OIB: 28454963989, represented by Matija Kontak, Counsel in the Sector for EU, International Cooperation, and Legal Affairs, employed by the Agency for Personal Data Protection (AZOP), for violation of the right to personal data protection, following an oral and public hearing concluded on April 10, 2026, and published on May 5, 2026, HELD: I. The plaintiff's claim for the annulment of the decision of the Personal Data Protection Agency, Zagreb, CLASSE: UP/I-034-01/24-01/1, URBROJ: 567-04-01107-24-1 of April 12, 2024, as unfounded. II. The plaintiff's request for reimbursement of administrative litigation costs is denied as unfounded. Rationale 1. By the contested decision of the respondent, the Personal Data Protection Agency, Zagreb, CLASSE: UP/I-034-01/24-01/1, URBROJ: 567-04-01107-24-1 of April 12, 2024. in point 1 of the dispositive part, it is determined that the company INA - Industrija nafte d.d. Zagreb, as the data controller, within the retail location (gas station) INA Zadar – Jazine at [address], contrary to Article 32(1) and (2) of the General Data Protection Regulation, did not take appropriate technical measures to ensure that personal data would not be accessed without authorization. General Data Protection Regulation, failed to implement appropriate technical measures to ensure unauthorized access to personal data processed by the video surveillance system installed at the premises of the subject retail location. Paragraph 2 of the dispositive part provides that for the violation described in paragraph 1 of the dispositive part of this decision, in accordance with the provisions of Article 83. General Data Protection Regulation, imposes an administrative fine in the amount of 5,000.00 EUR on the company INA - Industrija nafte d.d. of Zagreb, Avenija Većeslava Holjevca 10 (in words: five thousand euros) Paragraph 3 of the dispositive section provides that INA - Industrija nafte d.d. Zagreb is obligated to pay the imposed administrative fine to the state budget within 15 days from the date of the finality of this decision to the designated account. Paragraph 4 of the dispositive section provides that if the company INA - Industrija nafte d.d. Zagreb does not pay the administrative fine within 15 days of the entry of this decision, the Personal Data Protection Agency will, in accordance with Article 46(2) the Personal Data Protection Agency shall, in accordance with Article 46(2) of the Law on the Implementation of the General Data Protection Regulation, notify the Regional Office of the Tax Administration of the Ministry of Finance in whose jurisdiction the company's headquarters is located, for the purpose of the forced collection of the administrative fine in accordance with regulations on the forced collection of taxes.Point 5 of the judgment ruled that INA - Industrija nafte d.d. of Zagreb is required to submit proof of payment to the Personal Data Protection Agency within 15 days of the payment.2. The plaintiff timely filed an extensive lawsuit with the Administrative Court in Zagreb against the contested decision, challenging its legality on the grounds of an erroneously established factual state, incorrect application of substantive law, and a violation of administrative procedure provisions. In the lawsuit, the plaintiff describes the chronology of the administrative case in question, essentially stating that the dispositive part of the contested decision is unclear and contradictory to the evidence and the statements in the reasoning of the contested decision, that the General Data Protection Regulation was not properly applied, that the 3/2019 Guidelines on the processing of personal data were not properly applied, and citing an example of permitted practice involving video surveillance on a monitor visible in accordance with the Supervisory Body's Guidelines, stating that the ICO Guidelines are also relevant to the present situation even though the United Kingdom is no longer a member of the EU, that the reasoning of the contested decision is not consistent with the provision of Article 98, paragraph Article 5 of the ZUP, which indicates arbitrariness on the part of the respondent, and that the respondent's action is unlawful because it is contrary to the provisions of Article 8 and Article 47(1) of the ZUP, as the facts and circumstances essential to the proper resolution of the subject administrative matter were not established, or that the respondent body failed in the contested decision to determine whether the availability of video surveillance footage of locations that are already visible to the customer by simply being present at the retail location constitutes an excessive invasion of the individual's privacy, i.e., the subjects of the video surveillance, and what constitutes the key circumstance essential for the lawful and proper resolution of the administrative matter. The plaintiff states in the lawsuit that the dispositive part of the decision is not sufficiently specific and is unclear because it does not unequivocally establish what was decided and in what respects the technical measures are insufficient, since the reasoning of the contested decision lists numerous technical measures that the plaintiff has taken to ensure that no to prevent unauthorized access to the personal data in question, and that the defendant body states that the inadequate technical security measures relate only to the screen for viewing real-time video surveillance camera footage inside the room of the subject gas station, which is positioned in such a way that it is visible to all visitors to the gas station, and which, according to the reasoning, is considered contrary to the provisions of Article 32(1) and (2) of the General Data Protection Regulation. The plaintiff points out that the contested decision was made by the incorrect application of the law and other regulations based on the law, that the contested decision was made by the improper application of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter, the "Regulation"). Article 32(1) of the Regulation, which the defendant claims was violated by the plaintiff's actions, provides that the controller (in this case, the Plaintiff) shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account, including, among other things, the nature, scope, context, and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. Furthermore, Article 32(2) of the Regulation provides that "in assessing the appropriate level of security, particular consideration is given to the risks that the processing entails, in particular the risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of personal data, or unauthorized access to personal data that have been transmitted, stored, or otherwise processed." The Prosecutor points out that in the present case, and given that according to the reasoning of the contested decision, this concerns the installation of a display for viewing real-time video surveillance camera footage, i.e., without the existence of a recording that is available to visitors of the gas station, the risks posed by the beard for the purposes of paragraph 1 of Article 32 of the Regulation, which the Prosecutor was required to consider, do not relate to the risk "accidental or unlawful destruction, loss, alteration" or "unauthorized access to personal data transmitted, stored or otherwise processed" because these are not possible given that this is a real-time video surveillance display and not a recording. That any eventual risks, which the plaintiff as the data controller should have taken into account, would pertain to the "unauthorized disclosure of personal data." That although the defendant does not specify the type of video surveillance system display in the dispositive part of the contested decision (i.e., does not differentiate between viewing real-time video surveillance camera footage and that which is recorded on storage systems), given the reasoning of the contested decision, which does not question the lawfulness of the video surveillance system as such or the technical and organizational measures applied, that the plaintiff, in the present lawsuit, refers only to the real-time viewing of the video surveillance cameras inside the room of the subject gas station, which is positioned so that it is visible to all visitors of the gas station. Namely, that the defendant only considers that part of the video surveillance camera installation in the rationale of the Disputed Decision to be contrary to what is prescribed by Article 32, paragraphs 1 and 2 of the Regulation. The Claimant contends that the Defendant incorrectly applied the provisions of Article 32(1) and (2) of the Regulation and improperly concluded that the Claimant "failed to implement appropriate technical measures to protect against the risk of unauthorized disclosure of personal data." In fact, the Plaintiff maintains that it has precisely implemented all appropriate technical protection measures in accordance with the existing and foreseeable risks of unauthorized disclosure of personal data. Specifically, the real-time surveillance camera view screen displays a view of 4 surveillance cameras that only show what is visible to visitors by their mere presence at the retail location. Specifically, it is a display of the relevant areas of the retail location: (i) a view of Aggregates 1 and 2, (ii) a view of Aggregates 3 and 4, (iii) a view of the exit road from the retail location, and (iv) a view of the retail store area. As stated in the contested decision, there are a total of 9 CCTV cameras at the subject retail location, while only the views from 4 CCTV cameras are visible on the screen that is also visible to visitors of the retail location. The views from the other CCTV cameras, as well as the recordings from the surveillance cameras are not visible or accessible to visitors of the retail location, and very detailed and rigorous security measures, both technical and organizational, have been applied with respect to them, as even the defendant itself states in the reasoning of the contested decision. The plaintiff further briefly states the reasons why it is clear that the real-time monitoring by video surveillance cameras within the room of the subject gas station, which is positioned so that it is visible to all visitors to the gas station, does not conflict with the Regulation, and particularly with Article 32(1). and 2. of Article 32: that such processing is expected from the perspective of the data subject. The use of video surveillance in retail locations, and especially at gas stations, including the installation of video surveillance display monitors, is common practice throughout Europe and that such a method of video surveillance is widely common in the Republic of Croatia, particularly in retail locations and for the sale of consumer goods;- that such a monitor is in the interest of customers because it serves as a necessary means of protecting property and people at the retail location. That real-time video surveillance display monitors increase security and have a deterrent effect on potential criminal activity, as they increase awareness of video recording. That such screens are also reassuring (in the sense that employees, customers, and visitors feel safer) to the respondents—other customers in the retail premises, as well as employees who are alone on duty;- that empirical findings from business practice have also revealed the expectations of respondents, specifically customers, to be visible to sales staff at retail locations, regardless of which part of the retail location they are in, for the reason that they want to be seen by the sales associates while waiting to be served, as well as for security reasons, and this expectation is closely linked to the need for customers' needs to be recognized, i.e., to be provided with a certain standard of service and security appropriate for this type of service business. That the aforementioned claims are also supported by the Survey on Safety at INA Retail Locations, conducted among 10,445 users of the INA Loyalty Program between May 27 and 28, 2024.(hereinafter: "the Survey"). That the Survey shows, among other things, that customers consider video surveillance monitors visible to customers to be a common sight at gas stations, a fact confirmed by a full 92.16% of the users surveyed. Additionally, the Survey clearly shows that users feel safer when they see monitors in a space that are used for video surveillance for security reasons, which 87.18% of users confirmed. Finally, the Survey shows that 86.88% of users believe that the visibility of video surveillance monitors in stores does not infringe on their privacy. A key factor supporting the conclusion that the use of such monitors does not constitute an undue invasion of privacy is what is actually displayed on them. That this also represents the technical security measure implemented by the plaintiff, namely that the monitors display real-time video surveillance of certain locations within the retail space that are part of a publicly accessible area, and are therefore already visible and accessible to the customer. In other words, that under no circumstances do such monitors display video surveillance of locations that are not accessible to the customer or for which the customer does not have authorization to see, or for which they do not have permission to enter. Therefore, considering that these are locations already visible to employees, customers, and visitors in a publicly accessible area, the principle of confidentiality and security under Article 32 of the Regulation has not been violated, and this does not constitute unauthorized access. The plaintiff notes that to date, it has not received a single complaint from any data subject regarding the display of video surveillance at the plaintiff's retail location. In light of the foregoing, and particularly considering that this is expected processing, that all data subjects are necessarily aware of such processing, and that technical measures have been implemented regarding the exact locations displayed on the monitors. The plaintiff emphasizes that such processing does not constitute unauthorized access to the video surveillance system or an disproportionate violation of the data subject's privacy.3. The defendant agency, in its response to the lawsuit dated July 4, 2024. disputed the plaintiff's allegations and responded to them by stating that the defendant, as a supervisory authority for the implementation of the General Data Protection Regulation, is obligated to conduct investigations into the application of the General Data Protection Regulation and, upon determining a violation of its provisions, among other things, that it has the authority to impose an administrative monetary fine for violations of the controller's obligations prescribed by Article 32 of the GDPR, all in accordance with the provisions of Article 57(1)(h), Article 58(2)( i) and Article 83(4)(a) of the General Data Protection Regulation. Therefore, that the contested decision imposed an administrative monetary fine for a violation of the controller's obligation—here, the plaintiff's—which arises from Article 32(1) and (2) of the General Data Protection Regulation. That, given that in the present case the plaintiff had already previously been subject to a corrective measure under Article 58(2)(d) of the General Data Protection Regulation in the form of an order to bring its processing procedures into compliance with the provisions of the General Data Protection Regulation for the same breach of obligations, pursuant to which the plaintiff complied, the defendant decided to apply a second corrective measure in the form of an administrative fine instead of the corrective measure from Article 58(2)(d) of the General Data Protection Regulation. Namely, that pursuant to the provision of Article 58(2)(d) of the GDPR, the supervisory authority has the corrective power to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, in a precisely specified manner and within a specified deadline, in which case the plaintiff's argument that the order should contain a clear finding as to which technical measures are insufficient could be considered. It also stated that the plaintiff's arguments are not relevant, arguing that the contested decision's order is unclear because it does not specifically separate the finding as to which parts of the technical measures are insufficient, in a case where the order contains a decision to impose an administrative fine for a violation of Articles 32(1) and (2). General Data Protection Regulation, while the reasoning contains a detailed description of the violation of that article. Furthermore, it emphasizes that the defendant is authorized to impose an administrative fine for violations of Article 32. General Data Protection Regulation, regardless of whether the security breach resulted in a risk of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of personal data, or merely unauthorized access to personal data. Regarding the plaintiff's claim that the provisions of the Regulation were improperly applied, because the risks posed by the processing within the meaning of Article 32(1) of the Regulation that the plaintiff was required to consider do not relate to the risk of "accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data," or simply "unauthorized access to personal data," because these are not possible. loss, alteration" nor "unauthorized access to personal data that has been transmitted, stored, or otherwise processed" because these are not possible given that it is a real-time video surveillance display and not a recording, but rather a risk of "unauthorized disclosure of personal data," the defendant body stated that the key difference between the disclosure and access of personal data is that disclosure refers to specific, isolated personal data that have, for example, been published, whereas unauthorized persons do not have access to all the data processed by the data controller. In the case of processing personal data via a video surveillance system, an example of unauthorized disclosure of personal data would be viewing a specific recording by unauthorized persons. It points out that in this specific case, the processing of personal data is carried out through a video surveillance system where personal data is accessed via a screen for viewing recordings. This screen continuously displays new footage collected by the video surveillance cameras and is positioned in such a way that unauthorized persons can see it. Accordingly, it cannot be said that this is an unauthorized disclosure of personal data, but rather unauthorized access to personal data. That in accordance with Article 32(1) and (2) of the General Data Protection Regulation, the data controller is required to implement technical and organizational measures to ensure a level of security appropriate to the risk of, among other things, unauthorized access to personal data, in accordance with the principle of confidentiality. The security of the video surveillance system relates, among other things, to the physical security of the system's components and the access control for the video surveillance system, which, it is undisputed, in addition to the video surveillance cameras and the recorder for storing the footage, also consists of a monitor for viewing the video surveillance system's recordings. Furthermore, it states that the plaintiff is obligated to implement in practice the organizational measures prescribed in an internal document titled "User Access Levels" in order to ensure the secure processing of personal data. In this regard, the plaintiff developed user access levels in the specific case in question, in which, in accordance with the "least privilege" principle, he granted, among other things, permissions for live camera monitoring access, fully at certain locations, he did not ensure the implementation of the said organizational measure. That the plaintiff stated in its November 23, 2023, submission that due to the varying architecture of the retail locations, it is not possible to achieve a uniform solution, but rather that each retail location is approached individually in seeking the optimal solution, and that such monitors are placed in a high location within the retail store so they are visible to employees while they perform their duties at the cash register. Regarding the results of the Survey conducted by the plaintiff, the defendant stated that the opinion of the respondents regarding the legally mandated application of technical and organizational measures, in accordance with the risk of unauthorized access to personal data as an obligation of the data controller, is not relevant, especially considering the public's low awareness of the potential misuse of personal data in the digital age. That the expectations of the data subject are taken into account in accordance with Article 6 of the General Data Protection Regulation as part of the balancing test when assessing the legitimate interest of the controller or a third party as one of the three cumulatively prescribed elements. That the plaintiff demonstrates the lawfulness of the legal basis for processing personal data under Article 6(1)(f). f) of the General Data Protection Regulation, the controller's legitimate interest in using video surveillance monitors to display real-time surveillance, facing visitors, on the justification that the same locations are visible to customers by their mere presence on the premises and that the processing at issue is in line with the data subjects' expectations. In this regard, the defendant body repeats the reasoning from the rationale of the contested decision and emphasizes that to prove the lawfulness of the processing, it is necessary to satisfy three cumulative conditions in the form of proof that the specific processing is necessary, further that it is legitimate or lawful, and that the controller's interests outweigh the interests and rights of the data subject. Given that the processing in question is not necessary and is contrary to Article 32 of the General Data Protection Regulation, the same argument cannot be considered sufficient to prove a legitimate interest, as it only proves one of the three cumulative conditions for establishing a legitimate interest. The defendant agency then responded to the plaintiff's allegations regarding Guidelines 3/2019 on the processing of personal data, which the plaintiff claims were not properly applied, and fully maintained the arguments and reasons contained in the reasoning of the contested decision, proposing that the Court dismiss the plaintiff's claim.4. By submission of December 9, 2024, the plaintiff responded to the defendant's answer to the complaint and persisted in the allegations of the complaint.5. By Decision No. UsI-2639/2024-7 of October 28, 2025, the Administrative Court in Zagreb declared itself to be lacking territorial jurisdiction and transferred the case to the Administrative Court in Split as the court with substantive and territorial jurisdiction.6. Acting on the present lawsuit, the Court scheduled a hearing for April 10, 2026, at which the parties' representatives persisted in their previously made allegations, both in the complaint and in the responses to the complaint.7. The Court gathered evidence by reviewing and reading the documents attached to the file and the dossier submitted by the defendant agency, as well as all documents appended thereto, and concluded the hearing in the present administrative dispute.8. The plaintiff's counsel itemized and requested reimbursement of administrative dispute costs.9. The plaintiff's lawsuit is unfounded.10. The subject of the dispute is the legality of the contested decision of the Personal Data Protection Agency, CLASS: UP/I-034-01/24-01/1, REGISTRY NUMBER: 567-04-01107-24-1 of April 12, 2024.11. The parties dispute whether the contested decision correctly and lawfully imposed an administrative fine on the plaintiff for violating the obligation of the data controller—here, the plaintiff—which arises from Article 32(1) and (2) of the General Data Protection Regulation.12. The only dispute between the parties is whether, in the present case and with respect to the subject administrative matter, there was a violation of Article 32(1) and (2) of the General Data Protection Regulation.13. Thus, the facts are not in dispute between the parties; the application of substantive law is in dispute.14. Upon assessing the legality of the contested decision, this Court finds that the law was not violated to the detriment of the plaintiff, as the plaintiff unsuccessfully contends, but rather that the substantive law was correctly applied based on a properly and fully established factual record.15. From the record and the content of the reasoning of the contested decision, it follows that the administrative procedure preceding the issuance of the contested decision was conducted ex officio in such a way that the defendant body on October 26, 2023. conducted an unannounced inspection of the processing of personal data through video surveillance and the compliance of the video surveillance system with the provisions of the General Data Protection Regulation and the Act on the Implementation of the General Data Protection Regulation at the INA gas station, Zadar-Jazine, located at [address], of which a Record of the Inspection was prepared, CLASS: 042-03/23-01/100, REGISTRY NO: 567-12/09-23-03 of October 26, 2023.16. Furthermore, it appears that in connection with the conducted inspection, the Agency on October 30, 2023. from the data controller, here the plaintiff, among other things requested a statement regarding the finding in the supervisory proceeding concerning the placement of a screen for viewing the cameras' real-time feed inside the room of the subject gas station in a way that it is visible to all visitors of the subject gas station, the company's internal documents regarding the collection of personal data through video surveillance, and a statement regarding the measures taken when assessing an appropriate level of security in relation to the risks posed by the processing, particularly the risks of unauthorized disclosure of personal data or unauthorized access to personal data being processed, taking into account the Decision of the Agency, CLASS: UP/I-042-01/23-01/01, REGISTRY NO: 567-12/04-23-01 of January 30, 2023.17. It is also evident that the plaintiff acted on the request of the Agency, the defendant body herein, and submitted a statement on November 23, 2023, in which it essentially stated, among other things, with respect to the Agency's Decision CLASS: UP/I-042-01/23-01/01, REGISTRY NO:567-12/04-23-01 of January 30, 2023, that it had complied with the decision's ruling. 567-12/04-23-01 of January 30, 2023, essentially stated that it had complied with the decision's order and that at the INA Črnomerec S 355 retail location, at the address [address], discontinued the real-time video surveillance feed on a monitor visible to visitors, which he timely notified the Agency about, while regarding Art. 32 para. 2. of the Regulation, the data controller, the plaintiff herein, stated that this was not an unauthorized access to personal data via video surveillance by visitors, since the monitors do not display anything that is not already visible to any visitor by simply being present at the retail location.18. According to the provision of Article 4(1)(1) of the Regulation, personal data is any information relating to an identified or identifiable natural person. of the General Data Protection Regulation, personal data is any information relating to an identified or identifiable natural person, and an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or by means of one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that individual.19. According to Article 4(1)(2) of the General Data Protection Regulation, processing means any operation or set of operations performed on personal data or on sets of personal data, whether or not automated, such as collection, recording, organizing, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transfer, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.20. Article 5(1) of the General Data Protection Regulation provides that personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject (the principle of lawfulness, fairness, and transparency); collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes (principle of purpose limitation); adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (principle of data minimization); accurate and, where necessary, kept up to date (principle of accuracy); kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (principle of storage limitation) and processed in a manner that ensures appropriate security of the personal data, including protection against inappropriate or unlawful processing and against accidental loss or destruction, by applying appropriate technical or organizational measures (principle of integrity and confidentiality). 21. Provision no. 6(1)(f) provides that processing is lawful if and to the extent that it is necessary for the purposes of the legitimate interests of the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, particularly where the data subject is a child.22. The provision of Article 32(1) of the General Data Protection Regulation stipulates that, taking into account the latest state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor implement appropriate technical and organizational measures to ensure an appropriate level of security in relation to the risk, including, where necessary: (b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services and (d) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.Paragraph 2 of the same article provides that when assessing the appropriate level of security, particular consideration shall be given to the risks posed by the processing, in particular the risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of personal data transmitted, stored or otherwise processed, and paragraph 4 of the same article provides that the controller and the processor shall take measures to ensure that any person acting under the authority of the controller or the processor who has access to personal data, does not process those data unless instructed to do so by the controller, unless required to do so by Union or Member State law.23. Furthermore, Guidelines 3/2019 on the processing of personal data through video devices, Version 2.0, adopted on January 29, 2020. at point 135, further clarify the protective measure of "access control," which ensures that only authorized persons can access the system and data, while others are prevented from doing so. As a measure to support physical and logical access control, the placement of screens (especially in open areas, such as a reception desk) is mentioned, so that only authorized operators can view them.24. In the specific case and in the subject administrative matter, the sole issue is whether a violation of Article 32(2) occurred. General Data Protection Regulation, or whether in the specific case this constitutes unauthorized access to personal data via video surveillance by visitors, on which the parties to this dispute hold opposing views.25. The plaintiff, as the data controller, points out that the monitors do not show anything that is not already visible to any visitor by simply being present at the retail location, and therefore it cannot be said that there was unauthorized access to personal data processed through the video surveillance system installed at the location of the subject retail outlet.26. The defendant, however, believes that the data controller, the plaintiff here, has not satisfactorily met two of the three cumulative conditions, for which reason there is no legitimate interest in processing personal data by broadcasting a real-time video surveillance system feed on a screen in the gas station's premises, for the purpose of ensuring a timely response by employees and deterring perpetrators of criminal and infringing acts, in a way that the same footage is also accessible to other unauthorized persons.27. In this Court's assessment, the properly named defendant, among other things, states in the reasoning of the contested decision that the manner in which the screen for viewing real-time video surveillance camera footage is placed inside the room of the subject gas station, namely in a way that it is visible to all visitors of the gas station, is contrary to the aforementioned provision of Article 32(1) and (2). General Data Protection Regulation, and that the data controller failed to implement appropriate technical protection measures in accordance with existing and foreseeable risks of unauthorized disclosure of personal data, all in order to minimize risks and prevent potential future incidents. This is because, if the controller allows visitors, as unauthorized persons, to view the video surveillance system in real time, which is precisely the case, the controller will not be able to prevent the copying, recording, or other unauthorized use of the video surveillance footage, or the sharing of such footage with third parties in any way.28. The Court fully accepts the reasoning of the contested decision that, in the present case, the requirement of necessity is not met, because a timely reaction by employees in the event of a business need, as well as a rapid response in the event of a harmful incident, can be achieved even without visitors to the gas station having real-time access to the video surveillance system. Therefore, and since the aforementioned provision of Article 6(1)(f) prescribes that three conditions must be met cumulatively for the data controller to be able to demonstrate its legitimate interest as a lawful basis, the prescribed conditions are not cumulatively met in the present case, consequently, the defendant agency acted properly when it issued the contested decision, which is in its entirety found to be correct and lawful.29. In light of the foregoing findings, this Court finds that in the proceedings preceding the issuance of the contested Decision, no procedural rules that would have been relevant to the resolution of the administrative matter at hand were violated, nor was the legal provision on which the administrative matter was decided incorrectly applied, and the plaintiff's allegations have not successfully challenged the legality or correctness of the defendant's contested decision.30. Nor have the grounds for nullity of the contested decision under Article 128(1) of the General Administrative Procedure Act (Official Gazette, No: 47/09), which this Court takes into account on its own motion pursuant to Article 47(3) of the ZUS, the claim of the plaintiff is to be dismissed as unfounded on the basis of Article 116(1) of the ZUS and judgment is to be entered as in point I of the dispositive part of the judgment.31. The decision on costs is based on the provision of Article 147(1) of the ZUS, according to which the party who loses the dispute bears all costs of the proceedings, unless otherwise provided by law.32. Since the plaintiff was unsuccessful in the dispute, it was appropriate to apply the aforementioned provision of Article 147. para. 1 of the ZUS, to dismiss the plaintiff's request for reimbursement of administrative litigation costs and to rule as set forth under item II of the judgment. In Split, May 5, 2026. J U D G E Leandra Mojtić NOTICE OF APPEAL:An appeal may be filed against this judgment with the Supreme Administrative Court of the Republic of Croatia. The appeal is to be submitted through this court to the Supreme Administrative Court, in a sufficient number of copies for the court and all parties to the proceedings, within 15 days from the date of service of the judgment. An appeal suspends the enforcement of the judgment. DNA: - to the plaintiff by power of attorney - to the defendant - upon finality, to summon the plaintiff to pay the filing fee for the lawsuit and the judgment - return of the case file of the defendant authority, upon finality - to the file - calendar until 06/25/2026.