Retail company (name not available at the moment) – €89,250 Fine (Croatia, 2022)

€89,250Agencija za zaštitu osobnih podataka8 March 2022Croatia
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A retail company in Croatia was fined for not preventing employees from leaking video surveillance footage to social media. The company failed to implement strong security measures to protect personal data, which led to the unauthorized sharing of the footage. This case highlights the importance of having effective data protection practices in place to prevent data breaches.

What happened

Employees of a retail company recorded and leaked video surveillance footage without authorization.

Who was affected

Individuals captured in the leaked video surveillance footage.

What the authority found

The Croatian data protection authority found the company did not have adequate security measures to protect personal data, violating GDPR requirements.

Why this matters

This case underscores the need for businesses to enforce strict data protection measures and regularly monitor their effectiveness. It serves as a warning that companies can be held accountable for data breaches caused by internal failures.

GDPR Articles Cited

Art. 32(1)(b) GDPR
Art. 32(2) GDPR
Art. 32(4) GDPR
Full Legal Summary
Detailed

A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone which was unauthorised and contrary to the company’s internal acts and instructions. The recording was made public by leaking to social media and consequently other media outlets. The DPA determined that the data controller did not take adequate actions to prevent its employees from creating the footage. Although the company did undertake certain measures such as adopting internal acts on access to video surveillance footage, educating employees and implementing confidentiality statements, the DPA determined the company did not ensure – neither before nor after the disclosure of the unauthorised footage – appropriate organisational and technical security measures for the purpose of minimising risk of such or similar data breaches. In addition, the data controller did not regularly monitor or inspect efficiency of the technical and organisational measures implemented for the purpose of maintaining confidentiality, integrity and accessibility of personal data. Thus, the DPA imposed a fine of HRK 675,000.00 for the failure to take appropriate technical measures and clarified that this fine should also have general preventive effects and raise awareness among the data controllers and processor on the obligations concerning data processing.

Related Enforcement Actions (0)

No other enforcement actions found for Retail company (name not available at the moment) in HR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

8 March 2022

Authority

Agencija za zaštitu osobnih podataka

Fine Amount

€89,250

Enforcement Tracker ID

ETid-1093

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Retail company (name not available at the moment) - Croatia (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: