Austria’s First GDPR Fine Is For Video Surveillance

By: Charles Rollet, Published on Jan 29, 2019

Should EU businesses be concerned if police see a business' surveillance cameras filming public areas?

This is what happened with Austria’s first GDPR fine, imposed on a betting shop for filming public areas with its security cameras.

austria gdpr fine

The case racked up a total of almost $6,000 in fines, some of which were for non-GDPR violations. It has been appealed, so is not final. The case is nevertheless an important example of the heightened risk faced by end users in the GDPR era, particularly since it was the GDPR-related fine that was by far the highest.

In this note, we examine:

  • How They Got Caught
  • Alleged Violations
  • GDPR vs non-GDPR Violations
  • How The Fines Were Calculated
  • Why the GDPR Fine was the Highest
  • The frequency of Video Surveillance Fines in Austria
  • Timing & Gravity of Offense
  • Broader Meaning

*** *** **** *** Caught

********* ** ********** **** *******, ***** ****** ******** ******* two ************ ******* ******* public ***** ***** *** entrance ** * ******* shop ** *** ****** of****** ** ***** **, ****. (Betting ***** *** ****** in ***** ** ****** and ******* ******* ** a ***** *****/*** ***** patrons *** *** **** machines ** ***** ****.)

* **** *** ****** which *** *********** ** the ******** **** ********** agency,*** ***, ***** *** **, 2018, *** **** *** GDPR *** *******. **** is ******* ***** ** the ****, ******* ***** surveillance ***** **** ******* by ***** ***********, *** the ***, *** ****** told ****.

List ** **********

*** *** ****** **** the ******* **** ********* four ******** ******* **********:

  1. *** ******** ******* ******* at *** ****’* ******** monitored * ****** ******* lot *** ******* *****, recording ****** ******* ** and ********’ ******* ******.
  2. *** ******* **** *** registered **** ***********.
  3. ***** ************ ******* *** kept *** ** ********** time ****** **** ** justification ********. (******** ******* law ******** ***** ************* for *** ***** ************ storage ******* ****** **** 72 *****.)
  4. ***** *** ** ****** sign ********** **** ***** surveillance *** ***** ****.

*** ******* **** *** unnamed ** *** *** does *** **** **********, although *** ******* *** mention ** *** **** of * *****. 

GDPR ** ***-**** **********

*** ***** ********* – filming ****** ***** – was *** **** ****** listed ** ********* *** GDPR, **** *** *** highlighting *** ******** ******** of *** ***:

  • ******* *, ***** ****** **** the ********** ** ******** data ** “******* ** **** ** necessary ** ******** ** the ******** *** ***** they *** *********”. *** DSB ***** **** *** betting ****’* ********** *********** *** *** cameras’ ******** ******* ** surveilling *** ********.
  • ******* *, ***** **** *** the ********** *** ****** processing, **** ** “*******” and “********** ********”. *** DSB ***** **** *** betting ****’* ******* ********* none ** ***** **********.

*** ***** ***** ******* were *** ********** *********’* ******** ******* ***, ***** *** ****** in ****.

*** ****** ****** *** GDPR ** ***-**** ***** is **** “*** ******** of *** ******* ******* occurred ****** ** *** 2018” *.*. *** **** the **** *** *******. Therefore ********** *, *, and * **** ******* under ******** ******* *********** while *** ***** *** charged ***** *** ****.

How *** ***** **** **********

*** *** **** *********, the **** *** ***** 2,400 ***** ($*,***). *** other *****, ***-**** ********** received ***** ** *** euros **** ($***), ** laid *** ** ******** Austrian ******* ***. *** ***** ** ***** was **** *,*** ***** ($5,435). * **% ***** fee *** *****, ******** the ***** ** *,*** euros ** $*,***.

(**********: “**** ** *****”, “Penalty ** **** ***** are *** *********”, “************ period”, “[*****] *********”)

GDPR ****** ****** *****

*** **** **** *** GDPR ********* *** ***** was *,*** ***** ***** the ***-**** ***** **** only *** ***** ** not * ***********.

*** ***'* ****** **** Matthis ******* ********* ** IPVM (******** *****):

********* ********, *** **** allows ****** ****** **(*) *** (*)significantly ****** **** concerning the determination of the total amount of an imposed fine in relation to prior legal provisions in force before the GDPR.

************, ******* **** ************* ********************* **** ***** **** ** proportional ** *** **** of *** ********; * small ******* **** ***** not ** ******* **** the ******* **** ****, which *** ***** ** million ***** ** *% of ****** ****** *******.

*** **** ** ** proportionate. *** *******, * cannot **** * ******** who *** ** ****** income ** **,*** ***** [$45,300] **** * **-*******-**** fine [$** *******].

Frequency ** ***** ************ ***** ** *******

**** ** *** *** first **** ******* ***** surveillance ** ***** ** Austria. ******** ** *** not ******* **********, ******* told **** **** ***** are * "****** **********", before *** ***** *** GDPR:

*** ******** ** *** fining ***** ******* *** presumed ******* *** ** CCTV.

Timing/Gravity ** *******

*** ****** ************* ** the ******* **** ***** in ***** **** *** the ***** **** ********* in ********* ****. *** shop *** ******** *** case *** *** *** to *******’* ******* *****, which *** *** ** rule ** **, *** DSB ********* ** ****.

*** *** **** ********* that **** ** *******’* first **** ****. *** months-long ***** ** **** fines ***** **** *** fact **** **** ********** are ***** ******* * backlog ** ***** ***** began **** ****** *** GDPR’s *********.

*** *** ****** *** shop’s ******* ** ** “negligent” ****** “**********” ** “aggravating”. **** ** ******* the ******* **** ****’* have *** ******** ****** of **********, ******* *** illegal *** ******-**** ***** surveillance.

**********

**** **** ******** * particularly ************ ******* ** how ***** *** ** higher ****** ** *** GDPR. * $*,*** **** *** a ****** ***** **** can ** ***** * significant ******, *** ** is ****** **** *** total **** ***** **** been ****** *** *** the ********** ***** ***** after *** ****’* ********* on *** **. 

**** ** ********* *** users, ***********, *** *** others ********** ***** ************ data ****** ****** **** in ****.

Comments (34)

**** *****. 

* **** *** "******* Public *****"???

"*** ******* **** *** registered **** ***********"

*** ****!

***** ** *** **, however ** ******* **** have *** * **** time ********* ***** ************ much **** *********** (*** this ******** *** ****.) For ******* ** ****** the ******************** **** ********** **** ********** ******** cameras **** **** ****** areas, "**** ** **** want ** ****** *** security ** ***** ******* parked ** ***** ** their ****.”

"***** *****" ** *** best....

************** *********, *** ***** are ****** ** ***** unknown “*******” ******** ******** of ****** ***** ******. Out ** ***** *** of ****...

*** ****** ****** *** GDPR ** ***-**** ***** is **** “*** ******** of *** ******* ******* occurred ****** ** *** 2018” *.*. *** **** the **** *** *******. Therefore ********** *, *, and * **** ******* under ******** ******* *********** while *** ***** *** charged ***** *** ****.

**** ******* **** *** the *************************** ** **** **** just *** **** **** of $*,*** ***** **** been ******; *** **********, had *********************** ** ****, **** just *** * $*** fines ***** **** **** imposed.

** **** ** **, why ** *** *** that

** *** *** ****-******* fine **** *** ** far *** *******.

**** ** **** ****** to **** ** $****, just **** *** ***-**** spread **** ***** *****, but **** *** *** same *******?

 

 

****, *** ** *******. What *'* ****** ** that *** *** *** alleged ********** ***** ***** after *** **, *** 4 ********** ***** **** been *********** ** **** violations, ****** **** **** 1. ***** *** **** gives *********** ************* **** leeway ** ******** *****, each ** *** ********** could **** **** *****, for *******, *,*** ***** - ** ****'* *,*** x * = *,*** euros ***** ** *****, or ****** $**,***.

**** *** ***-**** ********** were *** "****** **** three *****"; **** *** was * ********** ********* of ******* ***********.

* **** **** ** check ** ************** **** fines *** **** ********** are ********* ****** **** the ****** **** ** the ******** **** ********** agency ******** *******. ** confirmed **** ** **, stating ** **** (******** added):

"********* ********, *** **** allows ****** *** *** 83 (*) *** (*)significantly ****** **** concerning the determination of the total amount of an imposed fine in relation to prior legal provisions in force before the GDPR. In addition, in this particular case, the Austrian DPA had to take transitional provisions into account, which ******* *** ***** ***** ***** ** *** ******** ***** ********* prior to the GDPR in which the infringing action started before the 25th of Mai 2018."

**** *'* ****** ** that *** *** *** alleged ********** ***** ***** after *** **, *** 4 ********** ***** **** been *********** ** **** violations, ****** **** **** 1.

** *** *** ****** that******** **, *** **** illegal ******* *** *** filming ** ******* *****?

*** **** *********, ***************** **, **** *** registered *** *******, *** signs **, ******** *** retention ****** ***?

**** ****** ******** ** me, *** **’* ********.

** *** ***** ****, if *** ** *** 4 ******** ******** ** both ************* * *** ******* under **** ********, ** would **** * *** arbitrary ** ****** **** capriciously *** **************, **** because **** **** ********* over * ****** ** shorter **** ******.

**** **** **** ***** :)

* *** *** ** check ******, *** *** link *** **** ******** the *******  “*** ***** wurde ***** ********”...

** *** *** ****** that ***** *** **, *** **** illegal ******* *** *** filming ** ******* *****?

*** **** *********, ******** ****** *** **, **** *** registered *** *******, *** signs **, ******** *** retention ****** ***?

*** **** ***** **** "most ** *** ******* misconduct ******** ****** *** 25." ** ********** *, 3, *** * **** found ** *********** ****** the ****, *** ********* 1 *** **** ********* afterwards. ******* ********** *-* were ******* ***** ************ prior ** ****, *** shop ***'* ** ********** for *** **** ******* post-GDPR. There ** ** ******* of *** **** *********** cameras, ******* ** *****, etc.

* *** *** ** check ******, *** *** link *** **** ******** the ******* “*** ***** wurde ***** ********”...

** ***, * ***** the **** ** *** article. *** *** ********* ****.

* **** * *** camera **** ****** *** cars **** ***** ** my *******, ** ****** don't **** ** **** drive ******* ***. *** cops ***** *** ***** when **** ********* ******* up *** ** *** cars.

*** ** *** ****** the ****** ******* *****? Also, *** *** ****** the **** *** *** retrieved ** **** ******** firmware ************* ** ***** in ******** ** *** switch?

* ***** *** ********** a ****** ******* ** person ******** *** ******* where * *****.

***** ** ******** ** the ******?

** *** ******... :)

**** *** ***** ** the ****** ** ****** :)

* ****** ***'* ********** the ******** ********* ** GDPR. **** ***-** ******* seem ** **** ** nothing **** **** * hassle.

** ** * *** two ***** *********

- **** ************* ** data
- **** ***** *** trunkslammers

********** *** ****** ****** should ** *********. **** makes * ****** ***** for *** ******** *** better *** * ****** level ** ********* *** installation.
********** **** ****** **** a ****** ******* *** higher ******.

******* ****, ****** ******* design, *** **** **** the *********** ******, (**** up *** *** **). 

* **** * ****** that's ***** ** ** driveway ** ***, * see *** **** ** cars ******* **, *** no ****** **** **** turn **** ** ********. It *****'* *** *** of ***** *****, *********, or ***** *****. **'* a "***** ************" ** if * ******* *** angle ** **** ****** driving ** **** ******'* mind.

* ****** **** *** of ** ********* *** a *** ******* **' off *** ****** ** the **** ** ***** house, ****** **** ** don't ** * **** comes **** ****. ******* just ******* ** ** neighborhood *** * ***** wifi ****** *** **** in ******* **** **** decided ** **** ******** of * ***** **** student ******* ******* ***** backyard **** ***** ******** them. *** *** *******'* of **** *****, *** posting ** ** *** towns ******* ******** ***** (over ** ******* ** see) *** ****** ** get **** ** ******* for ****.

* **** * *** camera **** ****** *** cars **** ***** ** my *******, ** ****** don't **** ** **** drive ******* ***.

* ****** **** **** message ** *** ********* all ***, ***** *** no ********* ** **** driveway ******** ***** ********.

** **'* **** ******** you *** ****** *** rights, **** **** *** the *** *******. ** argument *****.

**'* *** ****** ** not ****** * ****** of ***** ******, ** public ***** ** ******* looking ** ** **** private ********. **** *** enter ******** ******* ******** you ***'* **** *** say ** ***** ****** choices. *********** **** *** need ** ** ***** though... * ***'* ***** agree **** **** ****

** ******* **** ** odd ******, * ******* road **** **** ******* to ** ** *** property **** ******* *** of *** *********, ** someone **** *** **** to ***** **** *** vs *** ***** * entrances ** *** ***** they **** ** ** that's ***** ******.

** *** ** *****, my *** ****** ****** on * ****** ****, I *** *** **** of ***** ***, *** only *** ***** ** the **** **** **** down ** ********, **** if **'* **** ** turn ******. ****** * PTZ *** * ****** story **** *** **** into ****** * ******* isn't *** **** ** a ***** ****** **** sees * ******** ****. 

*** ** *** ****** who **** ** *****/******** of ****** ** ***** backyard ** ********, ** my ******** ** * felt *** **** ** shame ****** ****** ** would ** ******* **** issues ** *** ***. I'm *** **** ** the **, *** ** the ******, **** ** intended ** ** **** private, *** ********* ****** to ********.

******** *** ******** ** law *** *** ******** different ******.

******, ***** *** ********* already **** ********** ***** us.

  **** *** ******** camera ************, ** **** sounds **** * *** for *** **** ** have ********* *** ****** to *** ******* **** a **** ** *** public ******* ****** ** pay/install **********. ** ***** is ******* ******** ***** on ** *** ******* that *** **** ** wanting ** ****.

  ****, * ***** think * **** ** unnecessary ** *** ******* are ** ***** ****.  Call ** *********** ** you ****

**** **** ** ************** on * ********* *****, however, *****'* ** ********* anywhere ** *** **** or ******** ** ******* laws **** ***** ******** video ************ *** *** required ** **** ** the ******* *** ** plain ****. (*** *** see ***: * *********** may ***** ***** ******* are ****** ******* **** many ******** ***'* **** bother ** **** ** and ****** ****).

*** * **** ** eye ***** *** **** won't **** *** **.

**** ** *****, "***'** on ******".

 

* *** ********** *** feel **** ***, *** what ******* **** **** not ** ******** ********* installs ******* ** *** house, ******* ** *** road *** **** ******* at **** ****** *** private ****?

**** ** * ******, but * **** ***** for *** *** ****

...*** **** ******* **** your *** ** ******** neighbour ******** ******* ** his *****, ******* ** the **** *** **** looking ** **** ****** and ******* ****?

****?

* ******* ****** *********** of **** ***** ***** they *****, *** * advocate *** ********* ********* in ***** ***** *** laws ** *** *****.  The ************ ** ********** surveillance ** ******** **** is ********* ** * notionally **** *******.

*'* ****** **** **** we ***'* **** **** laws ** *********, ***** private ******* ** ***** that ****** ** **** the ******** ** ***** of *** ***** **** been ******* *********** *** the ************ ** * rapist/murderers, *** ******* * number ** ***** ******.  The ****** ********* **** on ******* **** *****.

** ** **** **** other ****** **** ****** encryption ******.

 

***, **** *****. * similar ******** ****** ** the ** **** ******* to ***** ******* ******* to **** ***** ****** cases. ******, ** *** US, * ****** ** local ****** *********** ***** databases ** ******* ******* to **** ***** ******. It ** ** ** interesting ******** ******* *******, security, *** **** (*.*., those ******* ******* *** much **** ********* **** building *** ********** ****** systems).

*********** *******, ****** **** them ****** ** *** learn ***** **** ********** and *****.  **** *** knowledge ** **** **** privacy **** *** ***** in *** ****** ****** and ***** *********.

*********: 

****** ********* * ******* privacy ***

****** ******* *** *** on *******

******* ********* ******* ** the ********** ******* **** and *********.  ** **** really ***** **** *** people ***** *** ****** are ***** ** ****** with ***** *** ***********.  I'm *** *** **** practices, ******** ******* *** controlling ** ******** ****, but ****** **** ** be ********* ***** **** makes ***** *** ***** are **** *** *** ones **** ****** ****.

******: **** **** *** weeks ***** **** ******* shop **** *** ******, Austria's **** ********** **************** * $*,*** ****** * *** *** violating *** **** ***** he ********* ******** ******* in *** ********* **** filmed ****** ***** ** the *******.

** ******** **, ****, the ******** *** ***** that * *** ***** Mr. ****** - *** first **** *** *** disclosed - ********* * cameras (*** ** *** doorway, *** ***** ** his ******) **** **** filmed "***** ** *** property ******** *** ******* use" **** **:

****** **** "********* ** ****** *****" at ***** **** ** the ******* *** ****'* put ** * **** indicating *** ***** ************.

*** *** ***** *** this ******** ******** * and * ** *** GDPR, **** **** *** betting **** ****, *** fined **. ****** *,*** euros ** ***** $*,***:

*** **** ******** **** Rudolf's ****: ****** ***** in ********** **** *******, walkways, *** *** **** considered "******"; ** ** GDPR *********, ********* *** only **** ***** *** property.

* *** ***** **. Rudolf - *** ***** name *** *** *********...

******* ** ****? ;)

**, **, * ***** this ** **** ************ policy (**** ******** *** GDPR) ** *********** *** naming ********/****** ******** ** court *****/***. **** ******** countries **** ******* ********.

******, * ***** **** his **** **** ** not *********, *****?

******: **** ********** ********* Appeal

** ***** ****, *******'* highest *************** *** ********* ** * ***** technicality ********* ** ***** surveillance. *** **** ***** determined **** *** *** had *** ************ **** the ****'* ******* ***** surveillance ** * ******** person, *.*. *** *******:

**** ******** *** ******** without *********** *** *** proceedings **** ************, ******* it *** * **** against * **** [******* liability *******] *** ************ acts ** *********** ******* a ******* ****** ("******" within *** ******* ********* ** ***) ** *** ************** proceedings ** *** *** (at ***** **** **** appear ** *** *****; out *** ****** *** a ******** **** **********) set ****.

******* * ***** ********** *** **** *****'* move **** ******** *** firm ****** ***** **********:

********* ** ******** ************, the **** ********** ********* can ****** ************** ***** on * ***** ****** for ********** ** *** GDPR *** *** ******** Data ******* *** ************, if *** ********** *** committed ** *********** *** hold * ******* ******** in *** ***** ****** concerned ** ** *** violations *** ****** ** lack ** *********** ** control ** * ****** in * ********** ****. However, ******* *** ******** nor *** ***** ********** act ** *** **** Protection ********* ********* **** behaviour ** ***** ********** had *** ** *** infringements *** *** ********* attributable ** *** ***** entity *** ***** ********* be **** ** * basis *** *** ************** fine *******. ** *** leading ********** ******** *** never ***** *** **** never ********* ** *** Data ********** ********* ****** the ********* **** ****** for ***********, *** ******* Administrative ***** *** ** annul *** ************** ******* imposed ** *** *******.

**** ** ** *****, there ** ** ******** where ********* *** *** away **** * ********* if ** ****'* *** manager/leader ************ *** ********* one. ** * ******* employee ******* * *********, the ********** ***** ****** ***********:

*** ******** ********* ** the ***** ****** [...] is ***** ** *** accusation **** *** ********** named ***** **** *** violated *** "***********" ******or **** **** *** **** ** "******** ***" ******** ******* **** ** ******* ** **********

Login to read this IPVM report.

Related Reports

Dahua Taunts Australian Government, Continues To Sell Illegal Fever Cameras on Aug 10, 2020
Dahua is effectively taunting the Australian government by continuing to sell...
Gait Recognition Examined on Sep 14, 2020
Facial recognition faces increasing ethical and political criticisms while...
Facial Recognition: Weak Sales, Anti Regulation, No Favorite, Says Security Integrators on Jul 07, 2020
While facial recognition has gained greater prominence, a new IPVM study of...
Terrible Convergint Coronavirus Thermal Camera Recommendation on Apr 01, 2020
A week after Convergint disclosed falling revenue, pay and job cuts,...
Australia Dahua Faked Advertisement, Government Warns of 'Criminal Offense' for Not Registering As Medical Device on Jun 25, 2020
A full-page advertisement in a national Australia newspaper for Dahua's...
The US Fight Over Facial Recognition Explained on Jul 08, 2020
The controversy around facial recognition has grown significantly in 2020,...
Wrong Dahua Australia Medical Device Approved on Jul 20, 2020
Dahua's body temperature system is now in Australia's medical device...
Google Invests in ADT, ADT Stock Soars on Aug 03, 2020
Google has announced a $450 million investment in the Florida-based security...
South Korea Bus Outdoor Temperature Screening Endangers Public on Aug 26, 2020
These $80,000+ South Korea bus stations have gained world-wide attention but...
False: Verkada: "If You Want To Remote View Your Cameras You Need To Punch Holes In Your Firewall" on Jul 31, 2020
Verkada falsely declared to “3,000+ customers”, “300 school districts”, and...
ADI Branch Burglary on Apr 03, 2020
A security systems distributor branch is an odd target for burglary but that...
Junk Debt Laden Convergint Facing Coronavirus Crisis on Apr 08, 2020
Convergint has $1+ billion in junk debt putting significant pressure on the...
Convergint Outlook Turns Negative on Apr 16, 2020
Convergint's outlook has turned negative, according to bond rater Moody's,...
The Problem With Fever Detecting Thermal Sunglasses on Apr 15, 2020
While the media has promoted using thermal sunglasses to detect fevers, this...
Verkada: "IPVM Should Never Be Your Source of News" on Jul 02, 2020
Verkada was unhappy with IPVM's recent coverage declaring that reading IPVM...

Recent Reports

Virtual ISC West and GSX+ Exhibiting Contrasted on Sep 17, 2020
Both ISC West and ASIS GSX are going virtual this year, just weeks apart, but...
X.Labs Sues FLIR on Sep 16, 2020
X.Labs, the maker of Feevr, has sued FLIR, the publicly traded thermal...
Video Surveillance 101 September Course - Last Chance on Sep 16, 2020
Today is the last chance to sign up for the Fall Video Surveillance 101...
No Blackbody Mistake, Half Million Dollar, Hikvision Fever Camera System in Georgia on Sep 16, 2020
A Georgia school district touted buying Hikvision fever screening "about...
Costar Technologies / Arecont H1 2020 Financials Examined on Sep 16, 2020
Costar's financial results have been hit by the coronavirus with the company...
Startup Cawamo Presents Live Alerts With Edge AI and Cloud VMS on Sep 15, 2020
Cawamo, an Israeli edge-to-cloud analytics and VMS startup, presented its...
Favorite Access Control Credentials 2020 on Sep 15, 2020
Credential choice is more debated than ever, with hacking risk for 125kHz and...
Dangerous Hikvision Fever Screening Marketing In Africa on Sep 15, 2020
A multi-national African Hikvision distributor is marketing dangerously...
New Products Show Fall 2020 Announced - Register Now on Sep 14, 2020
IPVM's sixth online show will feature New Products from over 25...
Hanwha 8K / 33MP Camera Tested on Sep 14, 2020
Hanwha Techwin has released an 8K / 33MP resolution camera, the TNB-9000 with...
Gait Recognition Examined on Sep 14, 2020
Facial recognition faces increasing ethical and political criticisms while...
Comparing 2020 Reality To 2010 Expectations on Sep 11, 2020
What can we learn from where the industry was in 2010 and what was believed...
China Dali Fever Cameras and Booming Sales Examined on Sep 11, 2020
Zhejiang Dali, one of China's original thermal technology developers, has...
Risks Of Managing End User Passwords (Statistics) 2020 on Sep 11, 2020
Alarmingly, most integrators used spreadsheets to manage passwords, IPVM...
Dedicated Vs Converged IP Video Networks Statistics 2020 on Sep 10, 2020
Running one's video system on a converged network with other devices can save...