# Video Surveillance — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/camerabewaking
> Sources are cited per item. Verify against the official texts before relying on them.

Use of cameras for monitoring and recording individuals

## Overview

## Legal Framework

Video surveillance falls squarely within the scope of the GDPR whenever cameras capture identifiable individuals. Article 4(1) defines personal data to include any information relating to an identified or identifiable natural person, and the image of a person recorded by a camera constitutes personal data because it enables identification of the data subject. The household exemption under Article 2(2)(c) GDPR (formerly Article 3(2) of Directive 95/46) removes purely personal or domestic processing from the regulation's scope, but the boundaries of that exemption are narrow and contested where cameras capture anything beyond the controller's own private sphere.

Controllers deploying video surveillance must identify a lawful basis under Article 6 GDPR, most commonly Article 6(1)(f) (legitimate interests), which requires a three-part balancing test: the controller's interest, its necessity, and proportionality against the data subject's rights. Additional obligations attach under Articles 5, 12–14, and 35 GDPR, including purpose limitation, data minimisation, transparency, and—where systematic monitoring occurs—data protection impact assessments.

The AI Act adds a further layer. Recital 43 establishes that AI systems which create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage are prohibited. This reflects the legislature's concern that such practices contribute to a sense of mass surveillance and risk gross violations of fundamental rights, including the right to privacy under Article 8 ECHR.

## Key Developments

The CJEU's ruling in *Ryneš v. Úřad pro ochranu osobních údajů* (11 December 2014) remains the foundational authority on the household exemption. The Court held that video surveillance covering even partially a public space cannot qualify as a purely personal or household activity, because the camera is directed outward from the private setting. A homeowner who installed a camera to identify vandals and whose footage captured a public street was therefore fully subject to data protection law.

Dutch civil courts have extended this logic to neighbour disputes, ordering removal or reconfiguration of cameras where they capture neighbouring property without a sufficient legal basis. Meanwhile, criminal courts have applied Article 139h of the Dutch Criminal Code to penalise covert photography where the presence of the recording device was not made apparent to the subject.

Enforcement by national DPAs has been granular. The Spanish DPA fined a landlord €1,800 for deploying cameras inside rental apartments without a sufficient legal basis, and fined a dental clinic €1,200 for surveillance that exceeded its stated security purpose. Both decisions underscore that purpose limitation and proportionality are actively policed.

The EDPB's Guidelines 3/2019 on video devices provide the operational standard, covering signage, retention periods, and access restrictions. The EDPB's Guidelines 05/2022 on facial recognition in law enforcement signal increasing scrutiny of biometric processing through cameras.

## Practical Guidance

- **Assess the household exemption carefully.** Any camera capturing a public space or a third party's property—even incidentally—removes the processing from the Article 2(2)(c) exemption and triggers full GDPR compliance, per *Ryneš* ¶33.
- **Establish a documented lawful basis and purpose.** Relying on Article 6(1)(f) requires a written legitimate-interests assessment demonstrating necessity and proportionality. Security is a valid interest, but recording inside private living spaces (as in the Spanish landlord case) will rarely survive the balancing test.
- **Provide visible notice.** Signage must inform data subjects of the surveillance, the controller's identity, the purpose, and retention periods, satisfying Articles 13–14 GDPR. Covert recording risks both administrative fines and criminal liability under national law.
- **Minimise capture scope and retention.** Configure camera angles to avoid public spaces and third-party property where feasible. Set retention periods to the shortest duration consistent with the stated purpose; indefinite storage is disproportionate.
- **Prohibit untargeted facial-image scraping.** Building or expanding facial recognition databases by scraping images from the internet or CCTV footage is prohibited under the AI Act. Any biometric processing through video devices requires a DPIA under Article 35 GDPR and, in most contexts, explicit consent under Article 9(2)(a).

## Legislation (full text of key provisions)

### Recital 43 — Prohibition untargeted facial image scraping

*Source: AI Act, aiact-rec-43-en, 2024-06-12 — https://overview.legal/posts/93768*

The placing on the market, the putting into service for that specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage, should be prohibited because that practice adds to the feeling of mass surveillance and can lead to gross violations of fundamental rights, including the right to privacy.

## Case law

### Bulgarian SAC upholds DPA finding on neighbour's CCTV covering adjacent property

*Source: Supreme Administrative Court of Bulgaria‎, 2026-07-13 — https://overview.legal/posts/184723 — original: https://gdprhub.eu/index.php?title=BAC_(Bulgaria)_-_7890/2026*

Facts — A data subject lodged a complaint with the Bulgarian DPA (CPDP), alleging that her neighbour (the controller) was unlawfully monitoring her property through CCTV. She claimed that a camera had been mounted on a metal structure on a third-floor terrace of the neighbouring building and installed in a manner that extended into the space above her property. According to the data subject, the camera had the technical capacity to identify individuals and objects throughout her property. The controller did not deny installing the camera but argued that it was directed towards the fence and an outbuilding on his own property. He also stated that a second camera had been installed on the western façade of the building. The controller claimed that both cameras were used solely to monitor his own property and the processing was lawful under the GDPR. The DPA carried out an on-site investigation and found that the CCTV system consisted of two independent cameras operated through separate software applications. Both cameras could be rotated in all directions and could use an automatic tracking function. The recordings were stored on memory cards for approximately 15 days before being automatically deleted, and only the controller had access to the system. The DPA noted that Camera 1 recorded the northern part of the controller’s yard, his house and the fence bordering the data subject’s property and Camera 2 recorded the roof of the controller’s house and a small part of the data subject’s yard. The DPA reviewed the oldest available footage and noticed that Camera 2 had recorded the data subject’s house and yard. The inspection report stated that the system could process personal data relating to individuals on both properties, but did not allow the identification of individuals or facial recognition. The DPA pointed out that warning stickers informing individuals of the video surveillance were displayed at the property. It found the complaint well founded in relation to Camera 1 and established a violation of Article 5(1)(c) GDPR, for which it issued an official warning to the controller. However, it found the complaint unfounded in relation to Camera 2, considering that the surveillance was permissible on the basis of the controller’s legitimate interest in protecting his property. The data subject appealed the part of the decision concerning Camera 2. The court of first instance annulled that part of the DPA’s decision and remitted the case to the DPA for reconsideration. It found that the DPA had relied entirely on the findings of the inspection team without carrying out a thorough, objective and independent examination of the relevant facts. Both the DPA and the controller appealed that judgment before the Bulgarian Supreme Administrative Court. Holding — The Supreme Administrative Court rejected the appeals and upheld the judgment of the court of first instance. The court noted that Camera 2 recorded the roof of the controller’s building and part of the data subject’s yard. It further pointed out that the DPA had found that, due to their technical characteristics, both cameras could alter their surveillance coverage and process personal data relating to individuals on both properties, while the CCTV system allowed individuals to be identified. Moreover, the court agreed with the first-instance court that the DPA had failed to provide adequate reasons for treating the two cameras differently. In particular, the DPA had not explained how the partial recording of the data subject’s yard contributed to the protection of the controller’s legitimate interest in safeguarding his property. It determined that it had also failed to establish whether adjusting the field of view of Camera 2 could expand its recording perimeter and allow it to capture a larger part of the data subject’s property.

### Sibiu Tribunal: CNCF denied CCTV access request; court rules on immaterial damage claim

*Source: Sibiu Tribunal, 2026-07-03 — https://overview.legal/posts/187485 — original: https://gdprhub.eu/index.php?title=TS_-_703/2026*

Facts — On 5 June 2025, an individual (the data subject) made an access request under Article 15 GDPR to the Romanian National Railways Company, Societatea Națională de Căi Ferate SA (the controller). The data subject requested CCTV footage from 30 May 2025 and information regarding the processing of his personal data following an alleged altercation between the data subject and police agents in front of a railway station. The controller refused to provide the data subject with the requested footage citing the protection of the rights and interests of other persons in the CCTV images. Subsequently, the data subject filed a complaint with the Romanian DPA (ANSPDCP). The DPA found violations of Article 12(6) GDPR, Article 15(3) GDPR and Article 83(5)(b) GDPR and issued the controller with a warning. Moreover, the DPA ordered the controller, among other things, to provide the requested footage, to the extent that it was still available, while following guidelines about sharing such images. In court, the data subject sued the controller for immaterial damages worth RON 3,500 (€665) claiming that its failure to provide the requested footage led to feelings of frustration, stress, injustice and helplessness by being forced to undertake additional steps to make use of his rights and by making it impossible to use the requested footage in other legal cases. Holding — The court held that the DPA’s decision attested the infringement of the data subject’s right to access by the controller, meeting the requirements of an illicit act under Article 1357 Romanian Civil Code. Moreover, the court accepted the data subject’s stress and suffering and the causal link between them and the controller’s access request refusal. Therefore, the court awarded RON 1,000 (€190) in immaterial damages to the data subject in accordance with Article 1381(1) Romanian Civil Code, Article 1381(2) Romanian Civil Code and Article 1385 Romanian Civil Code. At the same time, the court considered that the damage was not severe nor prolonged and took this into account when deciding on the amount of damages awarded. Finally, the court dismissed the data subject’s request to order the controller to provide the requested footage since it had already been deleted.

### Judgment of the Court (Third Chamber) of 11 December 2019.#TK v Asociaţia de Proprietari bloc M5A-ScaraA.#Request for a preliminary ruling from the Tribunalul Bucureşti.#Reference for a preliminary ruling — Protection of individuals with regard to the processing of personal data — Charter of Fundamental Rights of the European Union — Articles 7 and 8 — Directive 95/46/EC — Article 6(1)(c) and Article 7(f) — Making the processing of personal data legitimate — National legislation allowing video s

*Source: Court of Justice of the European Union, C-708/18, 2019-12-11 — https://overview.legal/posts/132336 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0708*

In Case C-708/18, the Court of Justice of the European Union (Third Chamber) issued a preliminary ruling on a reference from the Tribunalul București (Romania) in proceedings between TK and Asociaţia de Proprietari bloc M5A-ScaraA concerning the installation of video surveillance cameras in the common areas of a residential building without the data subject's consent. The Court interpreted Directive 95/46/EC and Articles 7 and 8 of the EU Charter of Fundamental Rights, holding that national legislation may permit processing of personal data based on the pursuit of legitimate interests under Article 7(f) of the Directive, but only if the processing is necessary

### CJEU - C‑708/18 - Asociaţia de Proprietari bloc M5A-ScaraA

*Source: GDPRhub, 2019-12-11 — https://overview.legal/posts/158446 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑708/18_-_Asociaţia_de_Proprietari_bloc_M5A-ScaraA*

Facts — The data subject owns and lives in a flat. The building in which the flat is situated belongs to the controller (a co-owner association). After a request of co-owners of the building the controller decided to install video cameras on the premises. The data subject objected to the video cameras being installed and he claimed it constituted an infringement of the right to respect for private life. The data subject sued the controller requesting the court ordering the controller to remove the cameras. The data subject argued that the video surveillance system installed by the controller infringed his right to respect for private life both under EU and national law. The controller stated that the video cameras were installed in order to monitor who is entering the building because there had been vandalism, thefts and burglaries, and that other measures previously taken had not been effective. The Romanian court stayed the proceedings and referred the following questions to the CJEU: (1) Are Article 8 CFR and Article 52 CFR and Article 7(f) Directive 95/46/EC to be interpreted as precluding provisions of national law such as those at issue in the main proceedings, namely Article 5(2) of [Law No 677/2001], and Article 6 of [Decision No 52/2012 of the ANSPDCP], in accordance with which video surveillance may be used to ensure the safety and protection of individuals, property and valuables and for the pursuit of legitimate interests, without the data subject’s consent? (2) Are Article 8 CFR and Article 52 CFR to be interpreted as meaning that the limitation of rights and freedoms which results from video surveillance is in accordance with the principle of proportionality, satisfies the requirement of being ‘necessary’ and ‘meets objectives of general interest or the need to protect the rights and freedoms of others’, where the controller is able to take other measures to protect the legitimate interest in question? (3) Is Article 7(f) Directive 95/46/EC to be interpreted as meaning that the ‘legitimate interests’ of the controller must be proven, present and effective at the time of the data processing? (4) Is Article 6(1)(e) Directive 95/46/EC to be interpreted as meaning that data processing (video surveillance) is excessive or inappropriate where the controller is able to take other measures to protect the legitimate interest in question? Holding — The court held that the operation of a video surveillance camera amounted to processing of personal data and therefore it needs to rely on one of the legal basis laid down in Article 7 Directive 95/46/EC. The relevant national law that enacts Directive 95/46/EC bases video surveillance on Article 7(f) Directive 95/46/EC (legitimate interest). The court held further that this provision lays down three cumulative conditions in order for the processing to be lawful: (a) the pursuit of a legitimate interest by the controller or by the third party to whom the data are disclosed; (b) the need to process personal data for the purposes of the legitimate interests pursued; (c) the fundamental rights of the data subject do not take precedence over the legitimate interest pursued. Additionally, the court held that that a consent of the data subject was not needed. Protecting the property, health, and life of the co-owners of the building is a legitimate interest. This interest must be present and effective during the data processing and must not be hypothetical. The court further held that to match the condition (b) from above there must be no other means that could have been used to achieve the given goal that as effective but less privacy-invasive. Furthermore, the second condition has to be assessed in conjunction with Article 6(1)(c) Directive 95/46/EC (data minimisation principle). This criterion was met due to the fact that previously taken measures did not have the intended effect. To assess the third point (c) from above, a balancing test needs to be done between the legitimate interest on the one hand and the rights and freedoms of the data subject on the other hand, in this case, the rights arising from Article 7 CFR and Article 8 CFR. The court concluded that member states cannot anticipate the result of this balancing test for certain categories of personal data or certain cases (such as video surveillance) in their national law without leaving room to the possibility of a different result due to the individual circumstances in a certain case. The court held that in the particular case the referring court has to balance the interests against each other to determine which interest prevails. Answering the preliminary question, it held that EU law does not preclude national provisions that allow for the installation of video surveillance systems installed in the common parts of a residential building in order to protect individuals and property as long as the criteria laid down in Article 7(f) Directive 95/46/EC are met.

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/6155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212&ref=6155*

Personal data: The image of a person recorded by a camera constitutes personal data because it makes it possible to identify the person concerned. (¶ 22)

### Norges Høyesterett - 2021-2403-A

*Source: Norges Høyesterett, 2021-12-07 — https://overview.legal/posts/125647 — original: https://gdprhub.eu/index.php?title=Norges_Høyesterett_-_2021-2403-A*

Facts — In 2012, a company "Legelisten.no AS" launched a website where people could submit anonymous reviews of healthcare personnel. From the same year, the Norwegian DPA Datatilsynet received multiple complaints from affected individuals. In one case in 2015, the DPA held that Legelisten did not have a legal basis for processing personal data related to the website reviews and, further, that Legelisten had to offer an opt-out arrangement for healthcare personnel not wanting their personal data published on the website. The decision was appealed to the Norwegian Privacy Appeals Board, who overturned parts of the DPA's decision, importantly relating to the (lack of) legal basis and the opt-out arrangement. Following this, the Norwegian Medical Association brought an action to the Norwegian courts, claiming that the website had no legal basis as per Article 6(1)(f) GDPR for registering and publishing subjective user reviews of healthcare personnel. Holding — After a balancing of the legitimate interests safeguarded by the website operator Legelisten against the interests of the healthcare personnel, the Supreme Court agreed with the Privacy Appeal Board's decision and found that Legelisten had a legal basis for the processing as per Article 6(1)(f) GDPR. The Court emphasised that Legelisten.no is an important source for the general public to acquire information about healthcare providers. The measures taken to limit privacy concerns also satisfied what could reasonably be expected. Thus, the DPA's initial decision was overturned and the appeal appeal against the Privacy Appeals Board's decision was rejected.

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/6154 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212&ref=6154*

Household exception: The household exception must be interpreted narrowly. Video surveillance that covers, even partially, a public space cannot be regarded as a purely personal or household activity. (¶¶ 28–35)

### TSJ PV: Accidental Teams recordings after meetings ended cannot justify trust-based

*Source: High Court of Justice of the Basque Country, 2026-07-17 — https://overview.legal/posts/53074 — original: https://gdprhub.eu/index.php?title=TSJ_PV_-_1713/2026*

Facts — The data subject had worked for Fineco Sociedad de Valores, SA and GIIC Fineco Sociedad Gestora de Instituciones de Inversión Colectiva, SAU, the controller, since 2004. The data subject held a senior position and was presented externally as responsible for fixed income management. In May and June 2024, several work meetings took place via Microsoft Teams. After some of these meetings had ended, one participant failed to deactivate Teams correctly. As a result, the system continued recording for several hours conversations which no longer formed part of any professional meeting. The conversations involved the data subject, the former CEO and another board member. The participants were unaware that they were still being recorded. During the conversations, they discussed, among other matters, possible strategies connected to substantial changes in working conditions and compensation. The recordings were automatically stored in the company’s Teams environment. Months later, the new management accessed the recordings. In January 2025, the controller held a meeting with the data subject and referred to extracts of the recordings, stating that their content had affected the trust placed in her. The data subject questioned the legality of the recordings. The data subject brought a labour claim seeking judicial termination of her employment contract for serious breach by the controller. She argued that the controller had accessed and used private conversations obtained without her knowledge or consent, thereby infringing her rights to privacy, secrecy of communications and personal data protection. The Social Court No. 9 of Bilbao dismissed the claim. It considered the recordings admissible as evidence, rejected the alleged violation of fundamental rights and imposed a €4,500 penalty on the data subject for bad faith and procedural recklessness. The data subject appealed before the Court. Holding — The Court partially upheld the appeal. The Court departed from the first instance court’s reasoning on the key issue of admissibility. The first instance court had held that the recordings were admissible because they had been generated after another participant failed to deactivate Teams. By contrast, the Court held that this mistake could not remove the data subject’s reasonable expectation of privacy. The Court found that the data subject had not been informed that Teams continued recording after the meetings had ended, had not consented to it and had not caused the technical error. The conversations took place after the professional meetings had ended and the participants believed that they were speaking privately. The controller had not shown any prior policy or information allowing it to access and use such recordings for employment purposes. The Court therefore held that the controller infringed the data subject’s rights to privacy and secrecy of communications under Articles 18.1 and 18.3 of the Spanish Constitution, read together with Article 18.4 of the Spanish Constitution, Article 8 ECHR and Article 7 CFR and Article 8 CFR . It also relied on Articles 87, 88 and 89 LOPDGDD and the Workers’ Statute rules on digital rights at work, which require prior information, proportionality and respect for workers’ privacy. The Court clarified that the relevant breach was not merely the accidental creation of the recordings, but the controller’s subsequent access to and use of them in the employment relationship. The recordings could not be used as evidence against the data subject because they had been obtained and used in breach of fundamental rights. However, this did not prevent the Court from assessing the controller’s own conduct, namely that it had accessed the recordings and relied on them in the meeting with the data subject. On that basis, the Court found a serious breach by the controller and granted the data subject’s request to terminate the employment contract for cause under Article 50.1(c) of the Spanish Workers’ Statute. It ordered the controller to pay €328,491.62 as statutory compensation for the termination of the employment relationship. The Court also awarded €7,501 as compensation for moral damages caused by the violation of the data subject’s fundamental rights. It did not award the €100,000 requested by the data subject, considering that the initial recording was accidental and that the controller had not installed a deliberate surveillance system. No administrative fine or GDPR corrective measure was imposed, as this was a labour court case rather than a DPA enforcement procedure.

## Guidance

### Guidelines 3/2019 on processing of personal data through video devices

*Source: EDPB, edpb-guidelines-on-processing-of-personal-data-through-video-devices, 2020-01-30 — https://overview.legal/posts/38059 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en*

The European Data Protection Board (EDPB) adopted Guidelines 3/2019 to provide comprehensive guidance on the processing of personal data through video devices,including CCTV and smart camera systems, under the GDPR. The guidelines address key issues such as the scope of application, the household exemption, lawfulness of processing under Article 6(1)(f) GDPR (legitimate interests), data subjects' rights, and obligations of controllers, while also clarifying the boundary with the Law Enforcement Directive (EU 2016/680). The guidelines were adopted on 29 January 2020 following public consultation and do not impose fines but serve as interpretative guidance for controllers and supervisory authorities.

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

### Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria

*Source: EDPB, edpb-opinion-202534-el-sacertificationcriteriacecl-en, 2025-12-02 — https://overview.legal/posts/51416 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-342025-on-the-draft-decision-of-the-greek-supervisory_en*

Adopted Opinion 34/ 2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria Adopted on 02 December 2025 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### EDPB Annual Report 2023

*Source: EDPB, edpb-annual-report-2023-en, 2024-04-23 — https://overview.legal/posts/125756 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2023_en*

EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023 9 1.2. RE-ORGANISING THE SECRETARIAT IN 2023 12 2. EUROPEAN DATA PROTECTION BOARD - ACTIVITIES IN 2023 14 2.1. BINDING DECISIONS 14 2.2. CONSISTENCY OPINIONS 19 2.3. GENERAL GUIDANCE 21 2.3.1. Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them 21 2.3.2.…

### Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR)

*Source: EDPB, opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro-en, 2024-04-18 — https://overview.legal/posts/125762 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-62024-on-the-draft-list-of-the-latvian-sa-on-pro_en*

Adopted 1 Opinion 6/2024 on the draft list of the Latvian SA on pro- cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) Adopted on 16 April 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 35 (1), (5) and (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data…

### EDPB Article 97 GDPR application report: GDPR successful but improvements needed

*Source: EDPB, contribution-of-the-edpb-to-the-report-on-the-application-en, 2023-12-15 — https://overview.legal/posts/125790 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-report-on-the-application_en*

1 Adop ted Contribution of the EDPB to the report on the application of the GDPR under Article 97 Adopted on 12 December 2023 2 Adop ted 3 Adop ted Ge neral EDPB policy messages 1 The application of the GDPR in the first 5 and a half years has been successful. The GDPR has strengthened, modernised and harmonised data protection principles across the EU. Awareness of data protection rights and obligations was raised significantly among data subjects, as well as public and private organisations.…

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

## Enforcement decisions

### Garante per la protezione dei dati personali (Italy) - 9794895

*Source: Garante per la protezione dei dati personali (Italy), 2022-06-09 — https://overview.legal/posts/6314 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9794895*

Facts — The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the Municipality had breached their data protection right of fair, transparent and lawful processing under art. 5(1)(a) as the sign signaling the CCTV monitoring referred to an outdated legislative decree. They also alleged a breach of art. 5(1)(e) and art. 13 GDPR, in so far the municipality never defined a data retention period for each processing purpose pursued. The last complaint moved forward by the data subject was that by being legally represented in Court by the same lawyer, who also acted as DPO of Policoro, the Municipality gave rise to a conflict of interest situation and breached art. 38(6) GDPR. The Municipality argued that the claim had been done in front of the Justice of Peace, who had no competency to decide on issues of privacy. It was also alleged the judgement only pertained an administrative matter, without rising any data protection concerns or a situation of conflict of interest with the Municipality's DPO. The last argument alleged the processing and retention of the CCTV footage was related to illegal dumps within the municipal territory, meaning the filming had been carried out in the course of judicial police investigations and the data retention periods of the GDPR did not apply in this case. Holding — The Italian DPA held that in this case the Municipality was carrying activities of data processing, by surveilling public entities by means of surveillance cameras. It also noted, that in par. 41 of the Guidelines 3/2019 on the Processing of Personal Data by Video Devices, waste management is "among the institutional activities entrusted to local authorities". This means the surveillance done by the Municipality of Policoro, a task carried out in the public interest in connection with the exercise of official authority as per art.6(1)(e) GDPR, was unrelated to public security and/or judicial police and obliging the controller to comply with data protection principles. The DPA found that the information provided in regards to the processing of personal data by means of surveillance cameras, did not meet the requirements of conciseness, transparency, intelligibility and easy readability contained in art. 5(1)(a) GDPR. The Municipality of Policoro had failed to provide suitable first-level information to the data subject, in so far the sign signaling the CCTV surveillance made reference to an outdated legislative decree (d.lgs 196/03) instead of the one currently in force (d.lgs 101/18). Furthermore, the data controller failed to provide the data subject with an adequate notice on second-level processing of their data. The signage did not include information on the most suitable impacts of the processing or an indication of a website, where to consult an extended version of the explanation. The DPA also found a violation of art. 13 GDPR as well as the principles of storage limitation and accountability in art. 5(1)(e) and art. 5(2). It stated that "the longer the intended storage period (especially if longer than 72 hours), the more reasoned the analysis referring to the legitimacy of the purpose and necessity of storage must be". In this case, the data controller not only failed to set a maximum retention period for the images taken for the purpose of combating illegal littering, but also established the administrative fines for the violation two months after the images were recorded. This did not allow for the data controller to respect the principle of accountability. Lastly, the DPA addressed the alleged conflict of interest raised by the involvement of the Policoro's DPO in the legal proceedings brought against the data subject. The DPA ruled DPOs "may perform other duties and functions," with the understanding that "the controller must ensure that such duties and functions do not give rise to a conflict of interest." The DPA also made reference to the Article 29 WP's Guidelines on Data Protection Officers, in which it is urged to not designate DPOs already acting as defense counsel for the same court. In the case at hand, it resulted that the DPO shared with the Municipality an interest in obtaining a rejection of the appeal. Consequently, the Italian Garante held this to be in violation of art. 38(6) GDPR, as well the fact that it undermined the DPO's independence. The Italian DPA held a cumulative breach of art. 5(1)(a) and (e) and (2) (in conjunction with article 24), 12, 13 and 38(6) GDPR. It balanced the fact that the personal data processing affected all other citizens, who passed through the areas under surveillance, against the lack of previous violations committed by the data controller. The DPA issued a fine of €26,000 EUR to the Municipality of Policoro.

### DPC (Ireland) - 06/SIU/2018

*Source: DPC (Ireland), 2023-08-22 — https://overview.legal/posts/125614 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_06/SIU/2018*

Facts — The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance technologies deployed by state authorities, including the Galway County Council and by the An Garda Síochána (the Irish police). More specifically, the Galway County Council Officials make use of CCTV systems, body-worn cameras and automated number plate recognition (ANPR) technologies for various purposes including law enforcement purposes. The DPC carried out its assessment both on the basis of the GDPR and of the Law Enforcement Directive (LED) for activities meant to prevent, investigate, detect and prosecute crime or for the execution of criminal penalties. Holding — In its inquiry, the DPC assessed the legitimacy of processing activities by the controller in light of both the GDPR and the Irish Data Protection Act and the LED, as different processing activities pursued different purposes. The DPC held with respect to body-worn cameras and ANPR systems that the GDPR applies to these processing activities as they mainly serve health and safety and traffic management purposes respectively, thus no law enforcement purposes. Making reference to the strict interpretation in CJEU jurisprudence, the DPC held that in order for a processing activity to fall under the scope of the LED, it must be specifically and concretely used for law enforcement purposes and it does not suffice that the data could potentially (emphasis added) be processed for law enforcement purposes. Firstly, as regards ANPR cameras used for traffic management, the DPC held that the latter enable identification of data subjects within the vehicle and thus constitutes processing of personal data. The legal basis referred to by the Council is Article 6(1)(e) GDPR. The DPC held that processing ex Article 6(1)(e) GDPR, read in light of Article 6(3) GDPR and Recital 41 GDPR requires a legal basis to set out the conditions for processing clearly, precisely and in a foreseeable way. In this case, the DPC held that the use of ANPR cameras does aid to the traffic management function of officials but it may also have significant impacts on the rights and freedoms of data subjects. The DPC concluded that the national provisions relied on by the controller to make use of such cameras are too broad and cannot constitute a legal basis for the Council to deploy APNR cameras for traffic management purposes. Hence, the DPC found the Council had acted in violation of Article 5(1)(a) GDPR. In addition to this, the DPC considered whether the controller complied with its Article 24(1) GDPR obligation to adopt appropriate technical and organizational measures to ensure and demonstrate GDPR-compliant processing activities, also by means of a data protection policy as per Article 24(2) GDPR. The DPC held that the controller failed to comply with its obligation under Article 24(1) GDPR with respect to the use of ANPR cameras for traffic management purposes as it failed to demonstrate compliance with the GDPR. Further, the DPC also found the controller had failed to comply with its obligation to carry out a Data Protection Impact Assessment by virtue of Article 35(1) GDPR for the use of APNR cameras for the systematic monitoring, tracking and observing of individuals. Secondly, the DPC considered the use of a body-worn camera by a Housing Tenacy Officer who had been threatened while conducting official activities. The legal basis relied upon by the Council in this case was Article 6(1)(d) GDPR, which allows for processing activities that are necessary to protect the vital interest of an individual. Further the Council also relied on Article 6(1)(e) GDPR as it is required to comply with health and safety obligations towards its employees set out in two specific Acts. As regards the use of body-worn cameras on the basis of Article 6(1)(d) GDPR, the DPC held that the controller failed to carry out a test for proving the necessity of the use of such cameras before their actual use. Hence, the controller failed to prove that such measure was necessary to protect the vital interest of the officer or to perform a task in the public interest. As for the use of such cameras on the basis of Article 6(1)(e) GDPR, the DPC held that again the controller did not rely on a clear, precise and foreseeable provision in the law allowing specifically for the body-worn cameras to be used. In this case too, the DPC held that the Council had infringed Article 5(1)(a) GDPR. Lastly, the DPC held that the controller infringed Article 24(1) GDPR to the extent that it failed to raise staff awareness on the principles of data processing, which counts as an organizational measure to be adopted by the controller under Article 24(1) GDPR. With respect to all the above mentioned violations, the DPC decided to adopt the following corrective powers: it provisionally banned the use of body-worn cameras and APNR cameras until a valid legal basis is identified and issued a reprimand concerning the violation of Article 24 GDPR. The rest of the activities carried out by the Galway County Council were assessed in light of the provisions of the LED, and the DPC found several violations in that respect too.

### DPC (Ireland) - 05/SIU/2018

*Source: DPC (Ireland), 2023-01-16 — https://overview.legal/posts/125613 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_05/SIU/2018*

Facts — This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special Investigations Unit of the DPC were authorised to conduct a range of inquiries pertaining to surveillance technologies deployed by state authorities, including An Garda Síochána (the national police) and various local authorities, including Kildare County Council. These inquiries sought to determine whether the data processing was lawful, and also to ensure that full accountability measures for the collection and processing of personal data were in place, in advance of further investment in and deployment of newer surveillance technology. The investigation into Kildare County Council focused on the following: the legal basis for surveillance technology employed for the purposes of preventing, investigating, detecting or prosecuting crime; the legal basis for surveillance tech deployed for purposes other than preventing, investigating, detecting, or prosecuting crime; appropriate signage and general transparency; and the question of a joint controller agreement between the council and the national police. Furthermore, the authority sought to examine the security measures for traffic management CCTV; housing department CCTV; and the transmission of CCTV footage to An Garda Síochána. Holding — Issuing its final decision, the DPC began by establishing that not all of the processing of personal data in question is regulated by the GDPR. Any processing of personal data for the purposes of prevention, investigation, detection, or prosecution of criminal offences is regulated by the Law Enforcement Directive (LED) supplemented into Irish law by the Irish Data Protection Act 2018 (“the 2018 Act”). The other personal data processing at issue here is covered by the GDPR. For further information and relevant legal provisions, please see Article 2(2)(d) GDPR, Articles 1 and 2 LED, and Part 5 and 6 of the 2018 Act. The first issue addressed in the DPC’s decision was the legal basis for the surveillance technologies employed for the purposes of preventing, investigating, detecting or prosecuting crime. In particular, this concerned CCTV systems deployed in a number of housing estates and Traveller caravan parks in the area. While the County Council initially submitted that the lawful basis for this processing was Article 6(1)(c) and 6(1)(d) GDPR, after clarifying that the relevant regime is the LED, the DPC sought to examine the justification for processing in light of this Directive and the 2018 Act. The controller sought to rely on its ‘estate management functions’ as set out in domestic housing legislation, and the powers to combat anti-social behaviour afforded therein. In accordance with the 2018 Act, personal data must be processed lawfully and fairly (Section 71(1)(a)) and the processing will only be lawful where the subject has given their consent, or where the processing is necessary for the performance of a function of the controller for a purpose specified in Section 70(1)(a) and the function has a legal basis in the law of the EU or Ireland (Section 71(2)). Furthermore, for special category data, one of the additional nine conditions in Article 73(1)(b) must be met. After examining the case, the DPC found no requirement to support the development of CCTV cameras in the estates as described above. The cited Irish legislation places no requirement upon the local authority to monitor in this way, and makes no reference to CCTV cameras. Furthermore, given that Irish Travellers are an ethnic group, and their accommodation has a distinct design and layout, the activities also represented the illegal processing of special category data. The DPC found an infringement of Sections 71(1)(a) and 73 of the 2018 Act. With regards to CCTV cameras located on the grounds of 2 supermarkets for the purpose of detecting illegal dumping. The investigation found that these cameras had not been operational before, during or after the investigation, and accordingly the DPC found no violation of the 2018 Act. Thereafter the DPC decision addressed the second issue: the legal basis for the surveillance technologies employed for purposes other than for preventing, investigating, detecting or prosecuting crime. In particular, the authority investigated CCTV used for: traffic management; the sharing of live feed traffic with An Garda Síochána; and the use of ANPR cameras, which recognise and digitise number plates. With regard to processing for traffic management, the Council sought to rely on the Irish Roads Act 1993, which places obligations upon public authorities to, among other things, provide for the safety or convenience of road users. Accordingly, the council argued they had a lawful basis for processing was in the public interest (Article 6(1)(e) GDPR). The DPC held that, given the significant potential impact to fundamental rights of a widespread video surveillance system, the Roads Act is not sufficiently clear, precise or foreseeable to constitute a valid legal basis for the processing of personal data in accordance with Article 6(1)(e) GDPR. There was also a complete lack of legal basis for the sharing of a live traffic feed with An Garda Síochána. Furthermore, for the use of ANPR cameras to be lawful under Article 6(1)(e) GDPR, it would be necessary for the legislature to specifically grant power to the local authority to carry out such processing in a manner which is clear, precise and foreseeable for the data subjects. As the Roads Act does not explicitly permit such processing, the Council does not have a lawful basis to operate ANPR cameras. In light of the above, the DPC found that the Council had violated Article 5(1)(a) GDPR in all 3 respects. The third question investigated was the presence of appropriate signage and general transparency. The investigation found that no appropriate signage had been installed to inform data subjects of the use of CCTV for traffic management purposes. Accordingly, the DPC held there had been a violation of Article 13 GDPR. Regarding the fourth issue, the DPC investigated the question of whether the Kildare County Council could be considered “joint controllers” with respect to Article 26 GDPR. The Decision finds that while An Garda Síochána used the CCTV footage for the prevention of crime, there is no evidence that the two entities “jointly” determined the purposes of processing. In other words, there is no connection between the Council’s decision to use the cameras for traffic management purposes and An Garda Síochána’s decision to then use the live feed for monitoring and preventing crime. Accordingly, the Council has not violated Article 26 GDPR. The DPC also made a number of findings regarding the security measures implemented by the Council. The Council failed to maintain a data log that recorded which users had accessed the CCTV cameras, thereby infringing Article 32(1) GDPR. The Council also violated Sections 71(1)(f), 72(1) and 78 of the 2018 Act by failing to implement appropriate technical or organisational security measures when installing the CCTV cameras. Furthermore, by failing to keep a data log, the Council also violated Section 82(2) of the 2018 Act. The Council also infringed Section 71(1)(c) and Section 76(2) of the 2018 Act by recording CCTV of private properties, in the absence of any privacy masking technology. Additionally, the Council infringed Section 71(10) of the 2018 Act by failing to be in a position to demonstrate that its processing of personal data via CCTV cameras at one location was not excessive to its purpose of preventing anti-social behaviour. Finally, The Council infringed its obligations under Sections 71(1)(f), 72(1) and 78 of the 2018 Act in connection with arrangements surrounding the transfer of personal data to An Garda Síochána using unencrypted USB sticks. Exercising its corrective powers, the DPC imposed a temporary ban on the processing of personal data with CCTV for the purposes of criminal law enforcement and traffic management, until a legal basis can be identified. Furthermore, they imposed an order for Kildare County Council to bring its processing into compliance with the legislation, and imposed an administrative fine of €50,000.

### Betting place: Insufficient fulfilment of information obligations

*Source: Croatian Data Protection Authority (azop), 2022-12-05 — https://overview.legal/posts/47703 — original: https://www.enforcementtracker.com/ETid-1588*

The Croation DPA (azop) has imposed a fine of EUR 1,991 on a betting place. The controller had installed a video surveillance system in its premises, however the DPA found that the video surveillance notice was not visible for data subjects entering the video perimeter. Furthermore the the video surveillance notice did not contain all relevant information on the CCTV. The DPA therefore concluded that the controller had violated Art. 27 (1) and (2) of the Croatian Act on the Implementation of the

### Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles

*Source: Data Protection Authority of Sweden (Integritetsskyddsmyndigheten), 2021-06-09 — https://overview.legal/posts/46837 — original: https://www.enforcementtracker.com/ETid-722*

The Swedish DPA has imposed a fine of EUR 34,800 on the directorate of the Östra Skaraborg Rescue Service. The DPA had received information that several fire stations in Östra Skaraborg operated surveillance cameras that filmed areas where firefighters were changing during an emergency, whereupon it initiated a review of the camera surveillance. The video surveillance was taking place around the clock, although the controller itself stated that video surveillance was only required in case of eme

### AEPD: No fine for surveillance cameras facing public road; no evidence of rights

*Source: AEPD (Spain), 2026-07-17 — https://overview.legal/posts/125611 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202103746*

Facts — A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim, there is also documentary evidence provided, proving the presence of the surveillance devices. Holding — In this case the DPA, stated that private individuals are responsible for ensuring that systems installed comply with current legislation. Also, that installations of this type of device must be accompanied by mandatory informative signs. The DPA held that there is no violation of data minimisation, Article 5(1)(c) GDPR. No fines can be imposed against the controller and Article 83(5) GDPR can therefore not be imposed. This is because there is no evidence of any infringement of the rights of third parties or the taking of public space.

### Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs

*Source: Garante per la protezione dei dati personali (Italy), 2026-01-16 — https://overview.legal/posts/52452 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10214411*

Facts — The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security cameras by the business “Macelleria La Costata s.r.l.s.”, a local butcher . The data controller installed the cameras (three, of which one was not functioning), positioned in two external areas of the business, without signs informing about the presence of the aforementioned cameras. The Local Territorial Agency for Residential Housing requested further investigations by the Local Police command, that was able to confirm violations of the Regulation. The Agency then submitted a complaint to the DPA. Despite being asked to submit written defenses in relation to the disciplinary proceedings against him, the data controller did not send any response to the Authority. Holding — The DPA found the data controller in breach of GDPR for the data processing being unlawful, and imposed a fine of €1,500. The DPA confirmed that the data processing through the video surveillance system did not comply with Article 5(1)(a) GDPR and violated the principle of transparency for not being equipped with suitable information signs. The controller also was found in breach of disclosure obligations, even in simplified form, specifically provided for by Article 13 of the Regulation. In fact, the data controller did not provide data subjects with all information relating to the essential characteristics of the processing performed. Furthermore, the processing was considered unlawful, as it violated Article 6 of GDPR, for lacking legal basis. The cameras were capable of recording areas other than those under the exclusive ownership (specifically, the public parking area in front of and to the side of the business entrance and part of the public road), as the initial local police report confirmed as well. In light of these considerations, the DPA fined data controller for €1,500, and ordered to provide information on processing and to stop the filming of public spaces.

### Private individual: Insufficient legal basis for data processing

*Source: Italian Data Protection Authority (Garante), 2024-09-12 — https://overview.legal/posts/48591 — original: https://www.enforcementtracker.com/ETid-2476*

The Italian DPA has imposed a fine of EUR 400 on a private individual. The individual had installed video surveillance cameras, which however also recorded parts of neighboring properties.

## Recent developments

### VG Berlin - 42 K 51.25

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291291 — original: https://gdprhub.eu/index.php?title=VG_Berlin_-_42_K_51.25*

English Summary The data subject appealed the DPA decision in April 2025. He argued that there was no particular threat that would justify the installation of a video surveillance system. According to the data subject, an on-site investigation carried out by the Berlin police supported this view.The data subject appealed the DPA decision in April 2025. He argued that there was no particular threat that would justify the installation of a video surveillance system. According to the data subject,

### VG Berlin - 42 K 73/25

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291280 — original: https://gdprhub.eu/index.php?title=VG_Berlin_-_42_K_73/25*

A court annulled a reprimand issued by the DPA and held that requiring a photo ID to access outdoor swimming pools and video surveillance in the entry and exit areas constituted necessary processing for a task carried out in the public interest.A court held that requiring a photo ID to access outdoor swimming pools and video surveillance in the entry and exit areas were necessary to prevent crimes and provide safety to swimmers and staff members. Therefore, the court considered the processing la

### Garante onderzoekt het gebruik van "cookie walls".

*Source: Garante Privacy, 2022-10-25 — https://overview.legal/posts/51828*

De Garante (de Italiaanse Autoriteit voor de bescherming van persoonsgegevens) merkt op dat de Europese wetgeving inzake de bescherming van persoonsgegevens in principe niet verhindert dat de eigenaar van een website de toegang tot content voor gebruikers afhankelijk maakt van hun toestemming voor het verzamelen van gegevens voor profilering (via cookies of andere trackingtools), of, als alternatief, van het betalen van een bedrag. Dit verwijst naar de initiatieven die de afgelopen dagen zijn genomen door verschillende online kranten, websites en bedrijven die actief zijn op internet.

### Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/6276 — original: https://www.datatilsynet.dk/english/google-analytics/use-of-google-analytics-for-web-analytics#entry-800*

The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

### De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen.

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/51817*

De Deense Autoriteit voor Persoonsgegevens heeft onderzoek gedaan naar het instrument Google Analytics en de bijbehorende instellingen, evenals de voorwaarden waaronder het instrument wordt aangeboden. Op basis van dit onderzoek concludeert de Deense Autoriteit voor Persoonsgegevens dat het instrument, zonder aanvullende maatregelen, niet op een wettelijke manier kan worden gebruikt. Wettelijk gebruik vereist de implementatie van aanvullende maatregelen, naast de instellingen die door Google worden aangeboden.

## Literature

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132480 — original: https://doi.org/10.21552/edpl/2020/4/15*

### GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132488 — original: https://doi.org/10.21552/edpl/2020/1/15*

### GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132484 — original: https://doi.org/10.21552/edpl/2019/2/13*

### GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132482 — original: https://doi.org/10.21552/edpl/2019/4/12*

## Tools

### ICO data protection self-assessment checklists

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125624 — original: https://ico.org.uk/for-organisations/advice-for-small-organisations/checklists/*

Self-assessment checklists by the UK regulator for small organisations: controllers, processors, information security, direct marketing, records management and CCTV — each producing a rating with suggested actions.

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Processing Agreement** — https://overview.legal/topics/verwerkersovereenkomst
  Contract between controller and processor defining processing terms
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/camerabewaking · 2026-08-22
