ANSPDCP (Romania) - Fine against LORIS FUEL SHOP SRL
ANSPDCP - Fine against LORIS FUEL SHOP SRL | |
---|---|
Authority: | ANSPDCP (Romania) |
Jurisdiction: | Romania |
Relevant Law: | Article 29 GDPR Article 32(4) GDPR Article 58(2)(d) GDPR |
Type: | Investigation |
Outcome: | Violation Found |
Started: | |
Decided: | |
Published: | 12.05.2022 |
Fine: | 1000 EUR |
Parties: | LORIS FUEL SHOP SRL |
National Case Number/Name: | Fine against LORIS FUEL SHOP SRL |
European Case Law Identifier: | n/a |
Appeal: | Unknown |
Original Language(s): | Romanian |
Original Source: | ANSPDCP (in RO) |
Initial Contributor: | Diana Rosu |
The Romanian DPA fined a gas station €1,000 after a video footage captured by its surveillance cameras was accessed by an unauthorised person and further uploaded on Facebook unlawfully, in breach of Articles 29 and 32(4).
English Summary
Facts
The controller - LORIS FUEL SHOP SRL - is a gas station. The data subjects complained to the ANSPDCP (Romania) that images of him were which were taken by a video surveillance system installed in the controller's gas station were published on Facebook without their consent. In its investigation of the incident, the ANSPDCP found that the controller did not sufficiently train its employees to handle personal data captured by the video surveillance system which let to third parties viewing and filming the images of the video cameras.
it was found that the operator LORIS FUEL SHOP SRL, as a proxy, did not adopt sufficient appropriate technical and organizational measures to ensure the confidentiality of personal data processed on images recorded through the television system installed in the stations used in especially in terms of training data controllers under its authority (employees). This led to the viewing and filming by unauthorized third parties of the images of the video cameras from the working point in Harghita County, later being revealed on a social network, thus violating the provisions of art. 29 and 32 para. (4) of Regulation (EU) 2016/679.
ame time, during the investigation of the operator LORIS FUEL SHOP SRL, a corrective measure was applied to ensure compliance with RGPD of personal data processing operations, by implementing appropriate technical and organizational measures, especially in terms of training data processors under the authority (employees or collaborators), by regularly organizing training sessions with them, in connection with their obligations regarding the processing of personal data through the video system installed in stations, the verification of access to recordings of images stored on DVR, rapid detection, management and reporting of personal data breaches
Holding
The ANSPDCP fined LORIS FUEL SHOP SRL for violating Articles 29 and 32(4) GDPR by not implementing the necessary technical and organisational measures to protect the video footage from unauthorised access.
Romanian DPA started an investigation against the gas station responsible for the unlawful processing of the video footage and found a violation of GDPR Articles 29 and 32(2). Namely, the controller LORIS FUEL SHOP SRL did not implement the necessary technical and organisational measures, especially, it did not train its employees to ensure adequate protection of the personal data. The controller was fined approximately EUR 1,000 (RON 4.941,3) and it is now required to implement the necessary technical and organisational measures, including to train its employees to protect and to enable the security of the personal data processed through video surveillance.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details.
12.05.2022 Sanction for violating the RGPD The National Supervisory Authority completed in April 2022 an investigation at the operator LORIS FUEL SHOP SRL and found the violation of the provisions of art.29 and art.32 par. (4) of the General Data Protection Regulation (RGPD). The operator LORIS FUEL SHOP SRL was sanctioned with a fine in the amount of 4,941.3 lei, the equivalent of 1,000 EURO. The investigation was initiated following a complaint in which the petitioner claimed the publication on Facebook of some images in which he was caught and which came from the monitor belonging to a video surveillance system installed in a gas station in Harghita County. During the investigation, it was found that the operator LORIS FUEL SHOP SRL, as a proxy, did not adopt sufficient appropriate technical and organizational measures to ensure the confidentiality of personal data processed on images recorded through the television system installed in the stations used, in especially in terms of training data controllers under its authority (employees). This led to the viewing and filming by unauthorized third parties of the images of the video cameras from the working point in Harghita County, later being revealed on a social network, thus violating the provisions of art. 29 and 32 para. (4) of Regulation (EU) 2016/679. At the same time, during the investigation of the operator LORIS FUEL SHOP SRL, a corrective measure was applied to ensure compliance with RGPD of personal data processing operations, by implementing appropriate technical and organizational measures, especially in terms of training data processors under the authority (employees or collaborators), by regularly organizing training sessions with them, in connection with their obligations regarding the processing of personal data through the video system installed in stations, the verification of access to recordings of images stored on DVR, rapid detection, management and reporting of personal data breaches. Legal and Communication Department A.N.S.P.D.C.P