IMY (Sweden) - 2025-10429
| IMY - 2025-10429 | |
|---|---|
| Authority: | IMY (Sweden) |
| Jurisdiction: | Sweden |
| Relevant Law: | Article 6(1) GDPR Article 32(1) GDPR Article 58(2) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 03.06.2025 |
| Decided: | 16.06.2026 |
| Published: | 16.06.2026 |
| Fine: | n/a |
| Parties: | n/a |
| National Case Number/Name: | 2025-10429 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Swedish |
| Original Source: | IMY (in SV) |
| Initial Contributor: | av |
The DPA reprimanded a security services company for installing cameras in its patrol vehicles and recording its drivers without a legal basis under Article 6(1) GDPR.
English Summary
Facts
A security services company (the controller) had installed cameras in its patrol vehicles that filmed the drivers (the data subjects) during their shifts. The video surveillance was part of a temporary pilot project that was conducted in December 2024 as well as April and May 2025. The surveillance technology was installed in around 50 cars and affected 119 drivers.
The technology was meant to detect certain potentially dangerous behaviours of the driver, such as not wearing a seat belt or using a cell phone. The most recent 100 hours of the footage were stored on local memory cards in the cars. If especially risky behaviour was detected, short video clips or still images were stored for 90 days.
The supervisory authority launched an investigation into this practice to determine whether it had a legal basis for the processing of personal data of the drivers. The DPA also investigated whether the controller had ensured an appropriate level of security in accordance with Article 32(1) GDPR when storing the personal data collected.
The controller relied on Articles 6(1)(c) and 6(1)(f) GDPR as legal bases. First, the controller argued that it had a legal obligation to guarantee a safe work environment and eliminate risks under national legislation on employee safety. Second, the controller relied on its legitimate interests to minimise damage, investigate alleged misconduct, and protect itself against disputes with insurance companies.
Holding
The DPA issued the controller a reprimand under Article 58(2)(b) GDPR and held that there had been no legal basis under Article 6(1) GDPR for filming the data subjects during their shifts.
First, the DPA held that the processing of personal data could not be based on Article 6(1)(c) GDPR. According to the DPA, the processing was of sensitive nature as it involved the real-time monitoring of employees. It stated that the provisions the controller relied on were not sufficiently clear and precise to constitute a legal obligation within the meaning of Article 6(1)(c).
Second, the DPA held that the controller had legitimate interests for the processing as defined in Article 6(1)(f) GDPR. Furthermore, the processing may have been necessary for the purposes of the legitimate interests pursued. However, the DPA held that the legitimate interests of the controller were overridden by the right of the data subjects not to be subject to continuous video surveillance at work. In particular, the DPA took into account the imbalance of power between the controller and the data subjects in an employment relationship when determining the outcome of the balancing test.
Third, the DPA found no infringement of Article 32(1) GDPR. It held that the controller had implemented appropriate technical and organisational measures when storing the personal data.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.
Swedish Data Protection Authority Registration number: IMY-2025-10429 3(12) Date: 2026-06-16 Legal obligation, Article 6.1 c Securitas has a legal obligation under Article 6.1 c of the Data Protection Regulation as an employer and as a company regarding the company's responsibility for the working environment of its employees. This is stated in Chapter 3, Section 2 of the Work Environment Act (1977:1160), which states that the employer shall take all necessary measures to prevent the employee from being exposed to ill health and accidents and to eliminate risks and take into account special risks that may result from the employee working alone, and in Chapter 3, Section 2 a of the same Act, which states that the employer shall systematically plan, manage and control the activities in a way that leads to the work environment meeting the prescribed requirements for a good working environment. This also refers to the rules in Sections 11–12 of the Swedish Work Environment Authority's regulations and general advice (AFS 2023:1) on systematic work environment work 3 regarding investigation and risk assessments. The above includes that Securitas as an employer has a broad responsibility regarding employee safety, where the solution as a whole was evaluated during the pilot project as part of preventing ill health and accidents and investigating such incidents and taking risks into account. It should be taken into account that the work environment with vehicles in traffic is associated with high risks, especially within the framework of Securitas' operations. Legitimate interest, Article 6(1)(f) Securitas has further stated that the camera surveillance was necessary for the company's legitimate interest according to Article 6(1)(f) of the Data Protection Regulation, i.e. to minimize damages and ensure good vehicle economy through follow-up on insurance investigation and repair costs. The processing is also necessary for Securitas' legitimate interest in handling incident reports and investigating alleged malpractice, misconduct, non-compliance with Securitas' applicable policies and to protect itself against disputes with insurance companies. Securitas is a large public security company in a socially important sector with a particular trust and requirement for security, reliability and accountability. The company operates in particularly risky environments with a higher degree of stress than in many other companies. The data subjects work with the execution of assignments in the security industry, which justifies higher requirements for both processing, security routines, damage minimization efforts and follow-up. The processing has been reasonable, predictable, informed and has also brought clear benefits for the data subjects; including through direct feedback on unsafe driving and the creation of a safer working environment. There have also been benefits for the public in the form of a reduction in the number of accidents and injuries involving vehicles, and for Securitas in terms of a reduction in injuries and the ability to follow up on injuries. Without the processing, the possibilities to detect, warn and follow up on the performance of vehicles are significantly limited, which prevents the fulfilment of the purposes. Appropriate security measures have also been in place. The processing was deemed necessary as, without the technology, it was not possible to provide clear and direct feedback to drivers about unsafe driving behaviour and thus be able to achieve the purposes, and recorded material is a crucial basis for investigating and following up on incidents in the event of accidents, including the handling of insurance cases and insurance disputes. The recordings were limited by not including sound and the generated film clips were predetermined to a few predefined events that were deemed relevant. The saved film clips were also stored for a shorter period of time. 3 The Swedish Work Environment Authority's regulations and general advice (AFS 2023:1) on systematic work environment work – basic obligations for you with employer responsibility. Page 3 of 12 Integrity Protection Authority Case number: IMY-2025-10429 4(12) Date: 2026-06-16 For several years before the current camera surveillance, Securitas has tried other alternative measures but without the intended effect. This has included, among other things, the implementation of various information efforts in the form of messages, films, written rules, etc., with varying but insufficient results. Most alternative solutions had been tried over a longer period of time, including sensor-based systems, but were not deemed to be sufficient or fully able to meet the objectives. The processing in question has taken place within the framework of a limited pilot project to evaluate the effect and has proven to be an effective solution from the point of view of the objectives. A balance was struck between Securitas' need for surveillance and the employees' privacy. When balancing this with the interests of the data subjects, their interest in not being monitored during working hours was taken into account. The main risks were assessed to be lack of confidentiality and damage to reputation if the film clips were disseminated more widely than intended. However, the risks were not assessed to be high and risk-minimizing measures had been taken to reduce the risk of unauthorized disclosure. It was also taken into account that the processing had been transparent through the provision of information at several levels, including in connection with the car. It was also taken into account that the processing aimed to improve safety, reduce the risk of personal and property damage and facilitate the handling of insurance cases, which could also benefit the data subjects. The company assessed that the processing was necessary to achieve the purposes, especially since alternative measures had not had sufficient effect. The pilot project was therefore designed to evaluate a more targeted solution, where drivers received direct feedback on their driving behavior. The scope of IMY's examination in the case IMY has limited the examination in the case to the question of whether Securitas had a legal basis according to Article 6(1) of the Data Protection Regulation for the camera surveillance that took place inside the company's cars, and the question of whether the security level has been appropriate when storing the personal data according to Article 32(1) of the Data Protection Regulation. IMY has on the other hand not examined the surveillance that allegedly took place outside Securitas' cars or whether other provisions of the Data Protection Regulation have been met. Justification of the decision What legislation applies to the current camera surveillance? Camera surveillance typically involves the processing of personal data. Whether and to what extent it is permissible to use camera surveillance is regulated in the Data Protection Regulation and the Camera Surveillance Act (2018:1200). In light of the scope of the supervision, however, no provisions in the Camera Surveillance Act are relevant in this case. According to Article 2(1), the Data Protection Regulation shall apply to the processing of personal data that is carried out in whole or in part by automated means. Article 4(1) of the Data Protection Regulation states that any information relating to an identified or identifiable natural person is personal data. If a surveillance camera films an identifiable person, or any other personal data, personal data is processed and the rules in the Data Protection Regulation must be followed. Page 4 of 12 Integrity Protection Authority Case number: IMY-2025-10429 5(12) Date: 2026-06-16 IMY notes that Securitas' surveillance cameras have filmed identifiable persons and that the provisions of the Data Protection Regulation therefore apply to the current personal data processing. IMY will initially determine whether Securitas is the data controller for the current processing of personal data. IMY will then examine whether Securitas has had a legal basis for the processing and whether the company has had sufficient security when storing the personal data it has processed, in the manner required by the General Data Protection Regulation. Data controller According to Article 4(7) of the General Data Protection Regulation, a natural or legal person, public authority, institution or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Securitas has stated that the company is the data controller for the personal data processing to which the supervision applies. The investigation has shown that the company has determined how the personal data shall be processed and for what purposes. IMY therefore assesses that Securitas is the data controller for the current processing of personal data. Legal basis for the processing In order for the current camera surveillance to be permissible, the provisions of the GDPR must be complied with. In accordance with the principle of accountability in Article 5(2) of the GDPR, it is the controller who is responsible for and must be able to demonstrate that the rules of the GDPR are complied with, including that the processing is lawful. This means, among other things, that Securitas must have support for its camera surveillance in at least one of the legal bases set out in Article 6(1) of the GDPR. Did Securitas have a legal basis for its camera surveillance in accordance with Article 6(1)(c) of the GDPR? Securitas has stated that one of the legal bases on which they support their camera surveillance is a legal obligation in accordance with Article 6(1)(c) of the GDPR. The company believes that the provisions of Chapter 3 Sections 2–2 a of the Work Environment Act and Sections 11– 12 of AFS 2023:1 state that there is a legal obligation as referred to in Article 6.1 c of the Data Protection Regulation. Applicable provisions, etc. Article 6.1 c of the Data Protection Regulation states that the processing shall be necessary for compliance with a legal obligation to which the controller is subject. Article 6.3 of the Data Protection Regulation states that the basis for the processing as referred to in Article 6.1 c shall be determined in accordance with Union law or the national law of a Member State to which the controller is subject. Page 5 of 12 Integrity Protection Authority Registration number: IMY-2025-10429 6(12) Date: 2026-06-16 According to Chapter 2 Section 1 of the Data Protection Act (2018:218) 4 personal data may be processed in accordance with Article 6(1)(c) of the General Data Protection Regulation, if the processing is necessary for the controller to fulfil a legal obligation under a law or other regulation, a collective agreement or a decision issued in accordance with law or other regulation. A legal obligation cannot constitute a legal basis for the processing of personal data if the obligation is too broad and gives the controller too much freedom of action in terms of how it is to be fulfilled. 5 The degree of clarity and precision required in terms of the legal basis for a particular processing of personal data to be considered necessary must be assessed on a case-by-case basis, based on the nature of the processing and the activity. Processing of personal data that does not constitute a genuine violation of personal integrity can be carried out on the basis of a legal basis that is general. A more significant infringement requires that the legal basis be more precise and thus makes the infringement foreseeable. 6 In Chapter 3 Sections 2–2 a of the Work Environment Act state that the employer shall take all measures that are necessary to prevent the employee from being exposed to ill health and accidents and to eliminate risks and take into account special risks that may result from the employee working alone. It further states that the employer shall systematically plan, manage and control the operations in a way that leads to the work environment meeting the prescribed requirements for a good work environment, including investigating occupational injuries, continuously examining the risks in the operations and taking the measures that arise from this, and documenting the work environment and working with it. According to sections 11–12 of AFS 2023:1, the employer shall regularly examine the work environment conditions in order to assess risks of ill health and accidents at work. When changes to the operations are planned, the employer shall examine whether the changes entail risks of ill health or accidents and assess these. Risk assessments shall always be documented in writing. The documentation shall indicate what the risks are and whether they are serious. If an employee suffers ill health or an accident at work, or if a serious incident occurs at work, the employer shall investigate the causes so that risks of ill health and accidents can be prevented. IMY's assessment IMY notes that the obligation under Chapter 3, Sections 2–2 a of the Work Environment Act and Sections 11–12 of AFS 2023:1 that Securitas invoked is established in the manner specified in Chapter 2, Section 1 of the Data Protection Act. IMY assesses that the processing in question was of a privacy-sensitive nature. This because it involved real-time monitoring of employees while they were driving their work cars during the period 2–18 December 2024 and between 9 April–31 May 2025 , and with recording between 2–16 December 2024. The monitoring has included employees at their workplace where they must be during their work shift. The data subjects have been in a position of dependence on their employer and have not been able to avoid the monitoring when they have driven their vehicles. This means that higher requirements are placed on the specification of the legal obligation. 4 Act (2018:218) with supplementary provisions to the EU Data Protection Regulation. 5 Cf. SOU 2017:39 p. 114 f., recital 41 to the Data Protection Regulation and the Administrative Court in Stockholm's judgment of 2020-06-17 in cases no. 9379-19 and 9408-19. 6 Prop. 2017/18:105, New Data Protection Act, p. 51. Page 6 of 12 Integrity Protection Authority Date number: IMY-2025-10429 7(12) Date: 2026-06-16 IMY believes that the provisions in Chapter 3, Sections 2–2 a of the Work Environment Act and Sections 11–12 of AFS 2023:1 are of general application. IMY believes that the provisions, neither alone nor together, are sufficiently clear and precise to make the infringement foreseeable. The current provisions cannot therefore form the basis for the privacy-sensitive personal data processing at issue in this case. The current processing cannot therefore be based on Article 6(1)(c) of the GDPR. Did Securitas have a legal basis for its camera surveillance pursuant to Article 6(1)(f) of the GDPR? Securitas has also stated that they base their personal data processing on the legal basis of legitimate interest in Article 6(1)(f) of the GDPR. Applicable provisions, etc. In order for processing to be based on the legal basis of legitimate interest (also known as balancing of interests) in Article 6(1)(f) of the GDPR, three conditions must be met. Firstly, there must be one or more legitimate interests of the controller or a third party. Secondly, the processing of personal data must be necessary for the purposes of the legitimate interest. Thirdly, the interests or fundamental rights and freedoms of the data subjects must not override the legitimate interests of the controller or a third party (balancing of interests). 7 The legitimate interest must be legitimate, which means that it must not conflict with EU or national law. 8 Furthermore, the interest must be clearly and unambiguously formulated and relate to an actual interest which exists at the time of the processing and is not hypothetical. 9 In order for the pursuit of such a legitimate interest to enable the processing of personal data on the basis of Article 6(1)(f), the controller must comply with all other obligations under the GDPR. 10 The case-law of the Court of Justice of the European Union shows that the requirement of necessity is met if the legitimate interest cannot reasonably be achieved equally effectively by other means which are less intrusive in the fundamental rights and freedoms of the data subjects, in particular the right to respect for private life and the right to the protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights of the European Union. It is not sufficient that the processing is useful for the fulfilment of the legitimate interest; the Court of Justice of the European Union has also stated that the processing must be strictly necessary. 11 The requirement of necessity must be examined together with the principle of data minimisation under Article 5(1)(c) of the GDPR. This means that the personal data processed shall be adequate and relevant and shall not exceed what is 7 See, inter alia, judgment of the Court of Justice of the European Union of 4 May 2017, Rīgas satiksme, C ‑ 13/16, EU:C:2017:336, paragraph 28, judgment of the Court of Justice of the European Union of 11 December 2019, Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, EU:C:2019:1064, paragraph 40 and judgment of the Court of Justice of the European Union of 4 July 2023, Meta Platforms and Others, C-252/21, EU:C:2023:537, paragraph 106. 8 See judgment of the Court of Justice of the European Union of 4 October 2024, Koninklijke Nederlandse Lawn Tennisbond, C-621/22, EU:C:2024:857, paragraph 49. 9 See Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, paragraph 44. 10 See Koninklijke Nederlandse Lawn Tennisbond, C-621/22, paragraph 50. 11 See Meta Platforms and Others, C-252/21, paragraph 126 and EDPB Guidelines 1/2024, paragraphs 28 and 29. Please note that the Guidelines have not been finally adopted by the EDPB at the time of this decision. Page 7 of 12 Privacy Authority Case number: IMY-2025-10429 8(12) Date: 2026-06-16 necessary in relation to the purposes for which they were collected and for which they are subsequently processed. 12 The balancing of interests required by the third condition shall be carried out in the light of the specific circumstances of the case. 13 The controller shall, in carrying out the balancing, identify and take into account the interests, rights and freedoms of the data subject, the impact of the processing on the data subject and whether the data subject can reasonably expect the processing to be carried out for the purpose in question. The assessment of the impact of the processing shall take into account the nature of the data processed, whether it concerns sensitive personal data, the context of the processing and other consequences. Based on these circumstances, a balancing of competing rights and interests shall be carried out, which shall include the possibility of additional mitigating measures that go beyond what the controller is required to take in order to comply with the rules of the GDPR. 14 IMY's assessment Legitimate interest Securitas has stated that they have had the following legitimate interests for the processing they have carried out. Partly to ensure good vehicle economy by following up on insurance investigation and repair costs. Partly to handle incident reports and investigate alleged misconduct, misconduct and non-compliance with Securitas's applicable policies and to protect themselves against disputes against insurance companies. IMY assesses that the company's interests in the processing have been lawful, real and actual. IMY therefore concludes that Securitas has had a legitimate interest in the sense referred to in Article 6(1)(f) of the Data Protection Regulation. Necessity and balancing of interests For the processing to be lawful, it is also required that it is necessary to satisfy the legitimate interest. The necessity requirement shall be examined together with the principle of data minimisation in Article 5(1)(c) of the GDPR, according to which personal data shall be adequate, relevant and not excessive in relation to the purposes for which they are processed. The company has stated that it has tried alternative measures but that these have not had the desired effect. Furthermore, the processing has been carried out within the framework of a limited pilot project to evaluate the effect of the measure. The pilot project has shown that the measure has been effective in achieving the stated purposes. According to the company, the possibilities to detect, warn and monitor the movement of vehicles would have been significantly limited without this processing. As regards the third condition, the company's legitimate interest shall be weighed against the interests and fundamental rights and freedoms of the data subjects, in particular the right to respect for private life and the right to the protection of personal data in the case at hand. 12 See, inter alia, Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, paragraphs 47 and 48, and Meta Platforms and Others, C-252/21, paragraphs 108 and 109. 13 See, inter alia, Asociaţia de Proprietari bloc M5A-ScaraA, paragraphs 52-58. 14 See EDPB Guidelines 1/2024, paragraphs 32–34. Page 8 of 12 Privacy Protection Authority Case number: IMY-2025-10429 9(12) Date: 2026-06-16 For processing of personal data based on legitimate interest to be lawful, the interests or fundamental rights and freedoms of the data subject must not outweigh the legitimate interests of the company. In working life, where the employee is in a position of dependency towards the employer, high demands are placed on the employer to demonstrate that the processing is proportionate and that the employer's interest outweighs the employees' interest in protecting their personal privacy. CCTV surveillance of workplaces may pose particular risks to the employees' personal privacy. Many employees must regularly be in places that are monitored by their employer and may at the same time feel reluctant to object to the camera surveillance or point out shortcomings due to the special dependency that the employment relationship entails. 15 As mentioned above, IMY has found that the camera surveillance in question was of a privacy-sensitive nature. This is because it involved real-time surveillance of employees during the entire time they were driving their work cars during the period 2–18 December 2024 and 9 April–31 May 2025, as well as surveillance with recording from 2–16 December 2024. The surveillance carried out by the company has included employees at their workplace where they must be during their work shift. The surveillance has thus been continuous during the work shift and the employees in the current case have had limited opportunities to avoid the processing since they needed to be in the vehicle to be able to perform their work tasks. They have thus had no real opportunity to opt out of the surveillance or to evade the processing during working hours. IMY assesses that this constituted systematic surveillance of employees and that the processing is of a privacy-sensitive nature. In its assessment, IMY takes into account that the surveillance in question has involved a camera being aimed at the employee and recording him/her throughout the entire time the vehicle has been driven. The surveillance has taken place in a limited space where the employee has been alone in front of the camera for a long time. The camera's recording area has been the front seat of the car. The employee has thus been in focus and the surveillance has been aimed at the employee's behavior and actions in the workplace. The system that detected certain events through image analysis not only warned the driver, but certain warnings were also conveyed to the employer. Continuous recording risks creating a feeling of constant control and can significantly affect personal integrity. The fact that the camera has also recorded the data subject for a period of time increases the privacy violation. IMY assesses that the processing that has taken place has involved systematic surveillance of employees, who have not been able to escape surveillance, during large parts of their working day and has thus been of a privacy-sensitive nature. The dependency relationship between the employee and the employer means that the requirements are tightened and that employers must be restrictive in the case of such processing as has occurred in the current case. IMY believes that the investigation provides some support for the fact that the current processing can be considered to have been necessary for the purposes. This is particularly supported by the fact that the company has taken alternative measures but that these have been deemed insufficient. Although the processing may have been necessary to achieve the stated interests, IMY finds, in an overall assessment, that the company's interests do not outweigh the employees' right not to be subject to such continuous camera surveillance at work. It is therefore not demonstrated that the third condition in Article 6(1)(f) of the Data Protection Regulation is met. The current processing cannot therefore be based on Article 6(1)(f) of the Data Protection Regulation. Given that IMY does not believe that the monitoring has a legal basis in the GDPR, IMY does not find it necessary to assess whether the company has provided the information to the data subjects that they are obliged to do according to Article 13 of the GDPR. Has Securitas had sufficient security for the personal data it has processed? Applicable provisions, etc. Article 5(1)(f) of the GDPR states that when personal data are processed, they shall be processed in a manner that ensures appropriate security for the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (integrity and confidentiality). Article 32(1) of the GDPR further states that the controller shall, taking into account the latest developments, the costs of implementation and the nature, scope, context and purposes of the processing and the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. IMY's assessment Securitas has explained how the stored surveillance material from the cars was handled and how long the material has been stored. This includes the handling of the memory cards where recorded material is stored, as well as technical and organisational measures, e.g. who has had access to the surveillance material. In a comprehensive assessment of the evidence in the case, IMY finds that Securitas has taken appropriate technical and organizational measures in accordance with Article 32(1) of the Data Protection Regulation to ensure adequate protection of the personal data it has processed in connection with the storage of the surveillance material. IMY finds nothing to indicate that the handling of the stored material has violated the requirements for appropriate security contained in Article 32(1) of the Data Protection Regulation. Summary assessment In summary, IMY finds that Securitas has not been able to base the current processing of personal data on either Article 6(1)(c) or Article 6(1)(f) of the Data Protection Regulation. It has also not emerged that the company has supported the processing on any of the other legal bases in Article 6(1) of the Data Protection Regulation. Securitas has thus processed personal data in violation of Article 6(1) of the General Data Protection Regulation during the period from 2 to 18 December 2024 and from 9 April to 31 May 2025 in connection with the use of cameras inside the company's cars. IMY assesses that Securitas has taken appropriate technical and organizational measures in accordance with Article 32(1) of the General Data Protection Regulation to ensure adequate protection of the personal data it has processed in connection with the surveillance. Page 10 of 12 Integrity Protection Authority Case number: IMY-2025-10429 11(12) Date: 2026-06-16 Choice of intervention Article 58(2) and Article 83(2) of the Data Protection Regulation state that the IMY has the power to impose administrative fines in accordance with Article 83 of the Data Protection Regulation for infringements of Article 6 of the Regulation. Depending on the circumstances of the individual case, administrative fines shall be imposed in addition to or instead of the other measures referred to in Article 58(2), such as reprimands, injunctions and prohibitions. Article 83(2) further states the factors to be taken into account when deciding whether to impose administrative fines and when determining the amount of the fine. If the infringement is minor, IMY may, as stated in recital 148, issue a reprimand in accordance with Article 58(2)(b) instead of imposing a penalty. Consideration shall be given to aggravating and mitigating circumstances in the case, such as the nature, severity and duration of the infringement and previous relevant infringements. IMY has assessed that Securitas has lacked a legal basis for the processing of personal data to which the review relates. Furthermore, IMY notes that the current camera surveillance has taken place within the framework of a limited pilot project in terms of the number of cars affected by the surveillance and for a limited period of time. The processing has been terminated and it has not emerged that the personal data has been used for purposes other than those stated. Nor have any previous relevant infringements on the part of the company emerged. The violation also concerns privacy-sensitive processing in the workplace, which is a circumstance that speaks in a more stringent direction. Unlawful monitoring of employees that occurs repeatedly or otherwise in a systematic manner should normally justify a significant penalty fee. However, in this case, it concerns a pilot project where the processing has been ongoing for a limited period of time. In an overall assessment, IMY therefore believes that this is a minor violation as referred to in recital 148 of the Data Protection Regulation and that a reprimand is a sufficient and proportionate measure to highlight the violation and ensure compliance with the Data Protection Regulation. Against this background, IMY considers that Securitas should be given a reprimand in accordance with Article 58(2)(b) of the Data Protection Regulation for the violation. __________________________ This decision has been made by Unit Manager Jenny Bård following a presentation by lawyer Anders Haag. Lawyer Sebastian Caicedo Gordh, departmental lawyer Sarah Bodlander and IT and information security specialist Andreas Majunie also participated in the final handling of the case.




