The Workplace Surveillance Setup: A.A.A. (appearing again in AEPD records) operates a dental clinic at a specific address in Spain. The clinic had installed a video surveillance system comprising two cameras: one in the reception area (a photo detector) and one inside the dental treatment room (gabinete). Both cameras were installed and managed by a security company under a contract dating back to 2016, which specified the system included "audio verification (speak/listen)" and "image verification (photo detector/video sensor)."
The Employee's Complaint: On 26 February 2025, a former employee filed a complaint with the AEPD. She had worked at the clinic from 9 April 2024 until 2 January 2025, when she was dismissed (she claims improperly). During her employment, she observed the video surveillance system and its use. Her specific allegations included:
The employee provided photographic evidence showing the cameras installed but no visible video surveillance warning signs in the reception area. She also provided a WhatsApp audio recording from 26 February 2025 documenting her dismissal process.
The Clinic Owner's Defence: Following the AEPD's Article 65.4 LOPDGDD notification on 27 March 2025, A.A.A. responded on 7 April 2025 (and again on 11 April 2025) with the following explanations:
The Contract Evidence: A.A.A. provided the 2016 security contract showing the system was designed for "installation, maintenance and exploitation of alarm centres" and explicitly included:
The AEPD's Legal Analysis: The AEPD admitted the claim on 26 May 2025 and initiated a formal sanction procedure on 3 December 2025. The core legal issue centred on Article 5.1(c) RGPD - the principle of data minimisation. The AEPD's reasoning:
On Security Videovigilance (Article 22 LOPDGDD): Data controllers can install video surveillance systems to preserve security of persons, property, and installations, but ONLY if the treatment is:
On The Treatment Room Camera - The Fatal Flaw: The camera inside the dental treatment room recorded:
The AEPD determined this violated data minimisation because:
The Proportionality Test Failure: The AEPD applied a three-part proportionality test and found the treatment room surveillance failed:
The Data Minimisation Violation: Per EDPB Guidelines 4/2019 on Article 25 (Data Protection by Design and by Default):
"Controllers must determine whether they even need to process personal data for their relevant purposes... verification must take place before any processing, but can also be carried out at any time during the processing cycle."
The principle prohibits "excessive, dispensable, or irrelevant data processing." Once it's determined that less intrusive alternatives exist, the excessive processing must cease.
Why NOT Article 89 LOPDGDD (Worker Surveillance): The clinic owner claimed the system was for security, not labour control. The AEPD accepted this characterisation for purposes of the proceeding, applying Article 22 LOPDGDD (security videovigilance) rather than Article 89 LOPDGDD (worker control). However, the AEPD warned that per Article 5.1(b) RGPD (purpose limitation), images collected for security purposes CANNOT subsequently be repurposed for labour control unless Article 89's stricter requirements are met.
The Resolution - Early Payment Discount: On 18 December 2025, A.A.A. promptly paid €1,200 and admitted responsibility, taking advantage of:
The case was terminated through this voluntary compliance mechanism, but the fine and corrective measures were still imposed.
Corrective Measures Ordered: Within 3 months of the resolution becoming final, A.A.A. must:
Failure to comply could trigger a new sanction procedure per Article 83.5 and 83.6 RGPD.
I'll revise the summary with those style requirements. Here's the corrected version:
AEPD Resolution: EXP202504969 Official Resolution Date: 19 January 2026 Date Published: 10 January 2026 AEPD Reference Number: EXP202504969 Sanction Procedure Number: PS-00463-2025
Fine Amount: €1,200 (reduced from €2,000 through early payment and admission of responsibility)
Full Description
The Workplace Surveillance Setup: A.A.A. (appearing again in AEPD records) operates a dental clinic at a specific address in Spain. The clinic had installed a video surveillance system comprising two cameras: one in the reception area (a photo detector) and one inside the dental treatment room (gabinete). Both cameras were installed and managed by a security company under a contract dating back to 2016, which specified the system included "audio verification (speak/listen)" and "image verification (photo detector/video sensor)."
The Employee's Complaint: On 26 February 2025, a former employee filed a complaint with the AEPD. She had worked at the clinic from 9 April 2024 until 2 January 2025, when she was dismissed (she claims improperly). During her employment, she observed the video surveillance system and its use. Her specific allegations included:
The employee provided photographic evidence showing the cameras installed but no visible video surveillance warning signs in the reception area. She also provided a WhatsApp audio recording from 26 February 2025 documenting her dismissal process.
The Clinic Owner's Defence: Following the AEPD's Article 65.4 LOPDGDD notification on 27 March 2025, A.A.A. responded on 7 April 2025 (and again on 11 April 2025) with the following explanations:
The Contract Evidence: A.A.A. provided the 2016 security contract showing the system was designed for "installation, maintenance and exploitation of alarm centres" and explicitly included:
The AEPD's Legal Analysis: The AEPD admitted the claim on 26 May 2025 and initiated a formal sanction procedure on 3 December 2025. The core legal issue centred on Article 5.1(c) RGPD - the principle of data minimisation. The AEPD's reasoning:
On Security Videovigilance (Article 22 LOPDGDD): Data controllers can install video surveillance systems to preserve security of persons, property, and installations, but ONLY if the treatment is:
On The Treatment Room Camera - The Fatal Flaw: The camera inside the dental treatment room recorded:
The AEPD determined this violated data minimisation because:
The Proportionality Test Failure: The AEPD applied a three-part proportionality test and found the treatment room surveillance failed:
The Data Minimisation Violation: Per EDPB Guidelines 4/2019 on Article 25 (Data Protection by Design and by Default):
"Controllers must determine whether they even need to process personal data for their relevant purposes... verification must take place before any processing, but can also be carried out at any time during the processing cycle."
The principle prohibits "excessive, dispensable, or irrelevant data processing." Once it's determined that less intrusive alternatives exist, the excessive processing must cease.
Why NOT Article 89 LOPDGDD (Worker Surveillance): The clinic owner claimed the system was for security, not labour control. The AEPD accepted this characterisation for purposes of the proceeding, applying Article 22 LOPDGDD (security videovigilance) rather than Article 89 LOPDGDD (worker control). However, the AEPD warned that per Article 5.1(b) RGPD (purpose limitation), images collected for security purposes CANNOT subsequently be repurposed for labour control unless Article 89's stricter requirements are met.
The Resolution - Early Payment Discount: On 18 December 2025, A.A.A. promptly paid €1,200 and admitted responsibility, taking advantage of:
The case was terminated through this voluntary compliance mechanism, but the fine and corrective measures were still imposed.
Corrective Measures Ordered: Within 3 months of the resolution becoming final, A.A.A. must:
Failure to comply could trigger a new sanction procedure per Article 83.5 and 83.6 RGPD.
Articles Infringed
Article 5.1(c) RGPD (Data Minimisation): The data controller processed personal data (images and audio) that were not "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed." The continuous capture of patient images and audio during dental procedures, retained for 7 days, exceeded what was necessary to achieve legitimate security objectives.
Actionable Steps
Based on Resolution EXP202504969, here is the protocol for workplace and medical facility video surveillance:
1. The Data Minimisation Principle is Paramount
2. The Three-Part Proportionality Test Before installing surveillance in sensitive areas, apply this mandatory test:
Part 1: Is the measure capable of achieving the security objective? Part 2: Is there a less intrusive alternative with equal effectiveness? Part 3: Do the benefits outweigh the harm to fundamental rights?
Critical Rule: You must pass ALL THREE parts. This case passed Part 1 but failed Parts 2 and 3.
3. Treatment Rooms, Medical Areas, and Sensitive Spaces - Extreme Caution Required Red Zones for Continuous Surveillance:
Why These Are Different:
Action: If you MUST have security coverage in these areas:
4. Audio Recording - Presumptively Prohibited Constitutional Standard (STC 98/2000): Audio surveillance is viewed as FAR more intrusive than video surveillance because it captures:
Presumption: Audio recording in workplaces is disproportionate and violates Article 18.1 Spanish Constitution (right to privacy)
The Narrow Exception (Article 89.3 LOPDGDD): Audio may ONLY be used when:
Action for Medical/Dental Practices:
5. The 7-Day Retention Rule - Not Always Appropriate Standard Rule: Article 22.5 LOPDGDD allows retention of up to one month for general security purposes
But Minimisation Requires: Shorter retention when appropriate
Action: Document your retention period decision in writing, explaining why that specific duration is necessary for your security objectives.
6. Informative Signage - Mandatory First Layer Even though this wasn't the primary violation in this case, the employee correctly noted the initial absence of warning signs.
Article 22.4 LOPDGDD "Two-Layer" Information:
Layer 1 - Physical Sign (mandatory):
Layer 2 - Detailed Information (accessible):
7. Security Purpose vs. Labour Control - The Bright Line Rule If Installed for Security (Article 22 LOPDGDD):
If Installed for Worker Control (Article 89 LOPDGDD):
Critical Rule: You CANNOT install cameras under Article 22 (security) and then repurpose the footage for Article 89 (labour control) unless you meet Article 89's additional requirements. This violates Article 5.1(b) RGPD (purpose limitation).
8. Who Is the Data Controller? Misconception: "The security company manages the cameras, so they're responsible"
Reality: The clinic owner (or business owner) is the data controller per Article 4.7 RGPD because they:
The security company is merely the "processor" per Article 4.8 RGPD. You cannot outsource legal responsibility.
9. Medical Facilities - Additional Considerations For dental clinics, medical offices, therapy centres, and similar healthcare environments:
Heightened Sensitivity:
Best Practice:
10. The Early Payment Discount Strategy Whilst this case involved wrongdoing, the procedural outcome demonstrates AEPD's incentive system:
Article 85 LPACAP Reductions:
When This Makes Sense:
Critical Requirement: Accepting the discount means renouncing any administrative appeal. You get the discount but lose the right to challenge.
Summary of Business Risk
This case represents moderate-to-high business risk for small medical practices, dental clinics, therapy offices, and similar healthcare facilities. The violations:
The Broader Message: This case illustrates that the GDPR's data minimisation principle has real teeth. You cannot simply install cameras everywhere and claim "security purposes." Each camera, in each location, capturing each type of data, must pass rigorous necessity and proportionality tests. Medical and treatment spaces receive heightened protection. Audio recording is presumptively excessive.
For small businesses, the lesson is: Less surveillance is often legally safer than more surveillance - even if your instinct is to install cameras "just to be safe."
Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.
No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.
No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.
Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.
Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.
Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.