ANRO Privacy Logo

AEPD Resolution: EXP202504969

Resolution Signed: 19/01/2026

AEPD Reference Number: EXP202504969

Sanction Procedure Number: PS-00463-2025 

Fine Amount: €1200

Full Description

The Workplace Surveillance Setup: A.A.A. (appearing again in AEPD records) operates a dental clinic at a specific address in Spain. The clinic had installed a video surveillance system comprising two cameras: one in the reception area (a photo detector) and one inside the dental treatment room (gabinete). Both cameras were installed and managed by a security company under a contract dating back to 2016, which specified the system included "audio verification (speak/listen)" and "image verification (photo detector/video sensor)."

The Employee's Complaint: On 26 February 2025, a former employee filed a complaint with the AEPD. She had worked at the clinic from 9 April 2024 until 2 January 2025, when she was dismissed (she claims improperly). During her employment, she observed the video surveillance system and its use. Her specific allegations included:

  1. No consent obtained: She never authorised the capture of her image during her employment
  2. No informative signage: The clinic lacked proper video surveillance warning signs
  3. Patients uninformed: Patients were not informed they would be recorded during dental procedures
  4. Audio recording: Both cameras captured not just images but also audio
  5. Improper retention: The clinic owner failed to delete recordings within legally established timeframes

The employee provided photographic evidence showing the cameras installed but no visible video surveillance warning signs in the reception area. She also provided a WhatsApp audio recording from 26 February 2025 documenting her dismissal process.

The Clinic Owner's Defence: Following the AEPD's Article 65.4 LOPDGDD notification on 27 March 2025, A.A.A. responded on 7 April 2025 (and again on 11 April 2025) with the following explanations:

  • They acknowledged being the data controller
  • The video camera in the treatment room served "exclusively security functions in a closed and restricted-access environment"
  • The photo camera in reception also served "dissuasive and security purposes"
  • Both cameras now had informative signs posted (photos provided showing signs added after the complaint)
  • Access to images was exclusively via mobile app with password and facial recognition
  • No monitors were exposed to public or authorised personnel
  • Video images were recorded and retained for a maximum of 7 days, then automatically overwritten
  • Audio was only captured in the treatment room for "exclusive security purposes"
  • The system was used only for security, NOT for labour control (which was done via printed time sheets signed by staff)
  • A separate company managed GDPR compliance for the clinic

The Contract Evidence: A.A.A. provided the 2016 security contract showing the system was designed for "installation, maintenance and exploitation of alarm centres" and explicitly included:

  • Magnetic detector
  • 1 image capture and recording equipment connected to alarm control centre
  • Inhibition detection
  • Audio verification element (speak/listen)
  • 2 image verification elements (photo detector/video sensor)

The AEPD's Legal Analysis: The AEPD admitted the claim on 26 May 2025 and initiated a formal sanction procedure on 3 December 2025. The core legal issue centred on Article 5.1(c) RGPD - the principle of data minimisation. The AEPD's reasoning:

On Security Videovigilance (Article 22 LOPDGDD): Data controllers can install video surveillance systems to preserve security of persons, property, and installations, but ONLY if the treatment is:

  1. Capable of achieving the proposed objective
  2. No other less intrusive measure exists with equal efficacy
  3. Proportionate (more benefits than harm to conflicting rights)

On The Treatment Room Camera - The Fatal Flaw: The camera inside the dental treatment room recorded:

  • Continuous images of patients during dental procedures
  • Continuous audio of conversations between patients and dental staff
  • 7-day retention of all this highly sensitive data

The AEPD determined this violated data minimisation because:

  1. Excessive intrusion: Patients remain in treatment rooms for extended periods in vulnerable situations where other fundamental rights (intimacy, privacy) are implicated
  2. Disproportionate capture: Continuous recording during medical procedures far exceeds what's "adequate, relevant, and limited to what is necessary"
  3. Audio recording particularly problematic: Citing Constitutional Court jurisprudence (STC 98/2000), audio recording is held to much stricter standards than image recording. The Constitutional Court ruled that audio capture in workplaces allows recording of "private comments, both from clients and workers... comments completely unrelated to business interests and therefore irrelevant from the perspective of labour control," causing workers to "feel constrained from making any type of personal comment"
  4. Alternative measures available: Security objectives could be achieved through less intrusive means

The Proportionality Test Failure: The AEPD applied a three-part proportionality test and found the treatment room surveillance failed:

  • Whilst it COULD achieve security objectives (part 1 passes)
  • Less moderate alternatives existed (part 2 fails)
  • The sacrifice of patients' and workers' fundamental rights (intimacy, data protection) outweighed any marginal security benefit (part 3 fails)

The Data Minimisation Violation: Per EDPB Guidelines 4/2019 on Article 25 (Data Protection by Design and by Default):

"Controllers must determine whether they even need to process personal data for their relevant purposes... verification must take place before any processing, but can also be carried out at any time during the processing cycle."

The principle prohibits "excessive, dispensable, or irrelevant data processing." Once it's determined that less intrusive alternatives exist, the excessive processing must cease.

Why NOT Article 89 LOPDGDD (Worker Surveillance): The clinic owner claimed the system was for security, not labour control. The AEPD accepted this characterisation for purposes of the proceeding, applying Article 22 LOPDGDD (security videovigilance) rather than Article 89 LOPDGDD (worker control). However, the AEPD warned that per Article 5.1(b) RGPD (purpose limitation), images collected for security purposes CANNOT subsequently be repurposed for labour control unless Article 89's stricter requirements are met.

The Resolution - Early Payment Discount: On 18 December 2025, A.A.A. promptly paid €1,200 and admitted responsibility, taking advantage of:

  • 20% reduction for admission of responsibility (€2,000 → €1,600)
  • 20% reduction for voluntary early payment (€1,600 → €1,200)
  • These reductions are cumulative per Article 85 LPACAP

The case was terminated through this voluntary compliance mechanism, but the fine and corrective measures were still imposed.

Corrective Measures Ordered: Within 3 months of the resolution becoming final, A.A.A. must:

  • Reorient the treatment room camera so it cannot continuously capture image and sound from the dental treatment area
  • If reorientation insufficient: Remove the camera entirely from the treatment room interior
  • Provide proof of compliance to the AEPD

Failure to comply could trigger a new sanction procedure per Article 83.5 and 83.6 RGPD.

Articles Infringed

Article 5.1(c) RGPD (Data Minimisation): The data controller processed personal data (images and audio) that were not "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed." The continuous capture of patient images and audio during dental procedures, retained for 7 days, exceeded what was necessary to achieve legitimate security objectives.

Actionable Steps

I'll revise the summary with those style requirements. Here's the corrected version:


AEPD Resolution: EXP202504969 Official Resolution Date: 19 January 2026 Date Published: 10 January 2026 AEPD Reference Number: EXP202504969 Sanction Procedure Number: PS-00463-2025

Fine Amount: €1,200 (reduced from €2,000 through early payment and admission of responsibility)

Full Description

The Workplace Surveillance Setup: A.A.A. (appearing again in AEPD records) operates a dental clinic at a specific address in Spain. The clinic had installed a video surveillance system comprising two cameras: one in the reception area (a photo detector) and one inside the dental treatment room (gabinete). Both cameras were installed and managed by a security company under a contract dating back to 2016, which specified the system included "audio verification (speak/listen)" and "image verification (photo detector/video sensor)."

The Employee's Complaint: On 26 February 2025, a former employee filed a complaint with the AEPD. She had worked at the clinic from 9 April 2024 until 2 January 2025, when she was dismissed (she claims improperly). During her employment, she observed the video surveillance system and its use. Her specific allegations included:

  1. No consent obtained: She never authorised the capture of her image during her employment
  2. No informative signage: The clinic lacked proper video surveillance warning signs
  3. Patients uninformed: Patients were not informed they would be recorded during dental procedures
  4. Audio recording: Both cameras captured not just images but also audio
  5. Improper retention: The clinic owner failed to delete recordings within legally established timeframes

The employee provided photographic evidence showing the cameras installed but no visible video surveillance warning signs in the reception area. She also provided a WhatsApp audio recording from 26 February 2025 documenting her dismissal process.

The Clinic Owner's Defence: Following the AEPD's Article 65.4 LOPDGDD notification on 27 March 2025, A.A.A. responded on 7 April 2025 (and again on 11 April 2025) with the following explanations:

  • They acknowledged being the data controller
  • The video camera in the treatment room served "exclusively security functions in a closed and restricted-access environment"
  • The photo camera in reception also served "dissuasive and security purposes"
  • Both cameras now had informative signs posted (photos provided showing signs added after the complaint)
  • Access to images was exclusively via mobile app with password and facial recognition
  • No monitors were exposed to public or authorised personnel
  • Video images were recorded and retained for a maximum of 7 days, then automatically overwritten
  • Audio was only captured in the treatment room for "exclusive security purposes"
  • The system was used only for security, NOT for labour control (which was done via printed time sheets signed by staff)
  • A separate company managed GDPR compliance for the clinic

The Contract Evidence: A.A.A. provided the 2016 security contract showing the system was designed for "installation, maintenance and exploitation of alarm centres" and explicitly included:

  • Magnetic detector
  • 1 image capture and recording equipment connected to alarm control centre
  • Inhibition detection
  • Audio verification element (speak/listen)
  • 2 image verification elements (photo detector/video sensor)

The AEPD's Legal Analysis: The AEPD admitted the claim on 26 May 2025 and initiated a formal sanction procedure on 3 December 2025. The core legal issue centred on Article 5.1(c) RGPD - the principle of data minimisation. The AEPD's reasoning:

On Security Videovigilance (Article 22 LOPDGDD): Data controllers can install video surveillance systems to preserve security of persons, property, and installations, but ONLY if the treatment is:

  1. Capable of achieving the proposed objective
  2. No other less intrusive measure exists with equal efficacy
  3. Proportionate (more benefits than harm to conflicting rights)

On The Treatment Room Camera - The Fatal Flaw: The camera inside the dental treatment room recorded:

  • Continuous images of patients during dental procedures
  • Continuous audio of conversations between patients and dental staff
  • 7-day retention of all this highly sensitive data

The AEPD determined this violated data minimisation because:

  1. Excessive intrusion: Patients remain in treatment rooms for extended periods in vulnerable situations where other fundamental rights (intimacy, privacy) are implicated
  2. Disproportionate capture: Continuous recording during medical procedures far exceeds what's "adequate, relevant, and limited to what is necessary"
  3. Audio recording particularly problematic: Citing Constitutional Court jurisprudence (STC 98/2000), audio recording is held to much stricter standards than image recording. The Constitutional Court ruled that audio capture in workplaces allows recording of "private comments, both from clients and workers... comments completely unrelated to business interests and therefore irrelevant from the perspective of labour control," causing workers to "feel constrained from making any type of personal comment"
  4. Alternative measures available: Security objectives could be achieved through less intrusive means

The Proportionality Test Failure: The AEPD applied a three-part proportionality test and found the treatment room surveillance failed:

  • Whilst it COULD achieve security objectives (part 1 passes)
  • Less moderate alternatives existed (part 2 fails)
  • The sacrifice of patients' and workers' fundamental rights (intimacy, data protection) outweighed any marginal security benefit (part 3 fails)

The Data Minimisation Violation: Per EDPB Guidelines 4/2019 on Article 25 (Data Protection by Design and by Default):

"Controllers must determine whether they even need to process personal data for their relevant purposes... verification must take place before any processing, but can also be carried out at any time during the processing cycle."

The principle prohibits "excessive, dispensable, or irrelevant data processing." Once it's determined that less intrusive alternatives exist, the excessive processing must cease.

Why NOT Article 89 LOPDGDD (Worker Surveillance): The clinic owner claimed the system was for security, not labour control. The AEPD accepted this characterisation for purposes of the proceeding, applying Article 22 LOPDGDD (security videovigilance) rather than Article 89 LOPDGDD (worker control). However, the AEPD warned that per Article 5.1(b) RGPD (purpose limitation), images collected for security purposes CANNOT subsequently be repurposed for labour control unless Article 89's stricter requirements are met.

The Resolution - Early Payment Discount: On 18 December 2025, A.A.A. promptly paid €1,200 and admitted responsibility, taking advantage of:

  • 20% reduction for admission of responsibility (€2,000 → €1,600)
  • 20% reduction for voluntary early payment (€1,600 → €1,200)
  • These reductions are cumulative per Article 85 LPACAP

The case was terminated through this voluntary compliance mechanism, but the fine and corrective measures were still imposed.

Corrective Measures Ordered: Within 3 months of the resolution becoming final, A.A.A. must:

  • Reorient the treatment room camera so it cannot continuously capture image and sound from the dental treatment area
  • If reorientation insufficient: Remove the camera entirely from the treatment room interior
  • Provide proof of compliance to the AEPD

Failure to comply could trigger a new sanction procedure per Article 83.5 and 83.6 RGPD.

Articles Infringed

Article 5.1(c) RGPD (Data Minimisation): The data controller processed personal data (images and audio) that were not "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed." The continuous capture of patient images and audio during dental procedures, retained for 7 days, exceeded what was necessary to achieve legitimate security objectives.

Actionable Steps

Based on Resolution EXP202504969, here is the protocol for workplace and medical facility video surveillance:

1. The Data Minimisation Principle is Paramount

  • Action: Before installing ANY surveillance camera, complete a written assessment asking: "Is this specific camera, in this specific location, capturing this specific scope of data, truly necessary for our security objective?"
  • Test: Could we achieve the same security goal with a narrower camera angle? A motion-activated system? A dummy camera? A different security measure entirely?
  • Legal Basis: Article 5.1(c) RGPD - you may ONLY process data that is "adequate, relevant and limited to what is necessary"

2. The Three-Part Proportionality Test Before installing surveillance in sensitive areas, apply this mandatory test:

Part 1: Is the measure capable of achieving the security objective? Part 2: Is there a less intrusive alternative with equal effectiveness? Part 3: Do the benefits outweigh the harm to fundamental rights?

Critical Rule: You must pass ALL THREE parts. This case passed Part 1 but failed Parts 2 and 3.

3. Treatment Rooms, Medical Areas, and Sensitive Spaces - Extreme Caution Required Red Zones for Continuous Surveillance:

  • Medical treatment rooms during patient care
  • Therapy or counselling spaces
  • Areas where patients/clients are physically vulnerable
  • Spaces where sensitive conversations naturally occur
  • Private consultation rooms

Why These Are Different:

  • Patients spend extended time in vulnerable states
  • Multiple fundamental rights implicated (intimacy, dignity, data protection)
  • The Constitutional Court applies heightened scrutiny to surveillance in such spaces
  • Alternative security measures nearly always exist

Action: If you MUST have security coverage in these areas:

  • Use motion-activated recording (not continuous)
  • Restrict recording to unoccupied periods
  • Use narrow-angle cameras capturing only entry points
  • Never combine with audio recording
  • Reduce retention periods to 24-48 hours maximum

4. Audio Recording - Presumptively Prohibited Constitutional Standard (STC 98/2000): Audio surveillance is viewed as FAR more intrusive than video surveillance because it captures:

  • Private comments unrelated to business interests
  • Personal conversations between colleagues
  • Confidential discussions with clients
  • Tone, emotion, and context that reveals personality

Presumption: Audio recording in workplaces is disproportionate and violates Article 18.1 Spanish Constitution (right to privacy)

The Narrow Exception (Article 89.3 LOPDGDD): Audio may ONLY be used when:

  1. There are relevant risks to security of installations, property, and persons
  2. These risks derive from the specific activity conducted
  3. The principle of proportionality is respected
  4. The principle of minimal intervention is respected
  5. Prior information guarantees are provided
  6. Audio is deleted per Article 22.3 timeframes

Action for Medical/Dental Practices:

  • DO NOT install audio recording capability in treatment areas
  • If your existing system has audio, DISABLE it technically
  • If you cannot disable it, REMOVE the cameras from treatment areas
  • Document that audio is disabled in your data protection records

5. The 7-Day Retention Rule - Not Always Appropriate Standard Rule: Article 22.5 LOPDGDD allows retention of up to one month for general security purposes

But Minimisation Requires: Shorter retention when appropriate

  • High-risk areas capturing sensitive activities: 24-72 hours
  • General retail/office areas: 7-15 days
  • High-security facilities: Up to 30 days

Action: Document your retention period decision in writing, explaining why that specific duration is necessary for your security objectives.

6. Informative Signage - Mandatory First Layer Even though this wasn't the primary violation in this case, the employee correctly noted the initial absence of warning signs.

Article 22.4 LOPDGDD "Two-Layer" Information:

Layer 1 - Physical Sign (mandatory):

  • Sufficiently visible location
  • Must include at minimum:
    • Existence of video surveillance
    • Identity of data controller
    • How to exercise Articles 15-22 RGPD rights
    • Where to obtain more detailed information

Layer 2 - Detailed Information (accessible):

  • Available at reception, website, or other easily accessible location
  • Must include all Article 13 RGPD elements

7. Security Purpose vs. Labour Control - The Bright Line Rule If Installed for Security (Article 22 LOPDGDD):

  • Follow security video surveillance rules
  • May monitor premises, assets, general safety
  • Cannot use footage for employee disciplinary proceedings (unless you also comply with Article 89)

If Installed for Worker Control (Article 89 LOPDGDD):

  • Must provide prior, express, clear, and concise information to workers and their representatives
  • Cannot install in rest areas (break rooms, bathrooms, changing rooms, cafeterias)
  • Audio ONLY when relevant security risks exist, with proportionality
  • If you capture evidence of flagrant illegal acts, the information duty is satisfied if warning signs exist

Critical Rule: You CANNOT install cameras under Article 22 (security) and then repurpose the footage for Article 89 (labour control) unless you meet Article 89's additional requirements. This violates Article 5.1(b) RGPD (purpose limitation).

8. Who Is the Data Controller? Misconception: "The security company manages the cameras, so they're responsible"

Reality: The clinic owner (or business owner) is the data controller per Article 4.7 RGPD because they:

  • Determine the purposes (security)
  • Determine the means (camera locations, retention, access)
  • Decide whether to install cameras at all

The security company is merely the "processor" per Article 4.8 RGPD. You cannot outsource legal responsibility.

9. Medical Facilities - Additional Considerations For dental clinics, medical offices, therapy centres, and similar healthcare environments:

Heightened Sensitivity:

  • Patients are in states of physical vulnerability
  • Medical information (even visual) is Article 9 RGPD special category data
  • Trust relationship is paramount
  • Informed consent expectations are higher

Best Practice:

  • Limit cameras to reception, waiting areas, and corridors
  • NEVER surveil actual treatment spaces during patient care
  • If you must have security coverage in treatment rooms, use systems that only activate when the room is unoccupied
  • Consider whether locked doors and controlled access achieve the same security objective

10. The Early Payment Discount Strategy Whilst this case involved wrongdoing, the procedural outcome demonstrates AEPD's incentive system:

Article 85 LPACAP Reductions:

  • Admission of responsibility: 20% reduction (€2,000 → €1,600)
  • Voluntary early payment: Additional 20% reduction (€1,600 → €1,200)
  • These reductions are cumulative (total 40% off)

When This Makes Sense:

  • If the violation is clear and defence is weak
  • If the proposed fine is proportionate to the violation
  • If contesting would cost more in legal fees than the discount saves
  • If you want to avoid prolonged proceedings

Critical Requirement: Accepting the discount means renouncing any administrative appeal. You get the discount but lose the right to challenge.

Summary of Business Risk

This case represents moderate-to-high business risk for small medical practices, dental clinics, therapy offices, and similar healthcare facilities. The violations:

  1. Direct fine: €2,000 proposed (€1,200 after discounts) - meaningful for a small dental practice
  2. Corrective measures: Must remove or reorient cameras within 3 months
  3. Capital expenditure: May need to purchase new security systems
  4. Reputational damage: Public AEPD resolution naming the clinic owner
  5. Employee relations: Former employee has documented proof of surveillance concerns
  6. Patient trust: Patients may question privacy practices
  7. Future vulnerability: If corrective measures not implemented, new sanction procedure with higher fines (€20 million or 4% global revenue under Article 83.5 RGPD)

The Broader Message: This case illustrates that the GDPR's data minimisation principle has real teeth. You cannot simply install cameras everywhere and claim "security purposes." Each camera, in each location, capturing each type of data, must pass rigorous necessity and proportionality tests. Medical and treatment spaces receive heightened protection. Audio recording is presumptively excessive.

For small businesses, the lesson is: Less surveillance is often legally safer than more surveillance - even if your instinct is to install cameras "just to be safe."

Link to Official AEPD PDF

Legal Disclaimer

Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.

No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.

No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.

Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.

Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.

Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.

ANRO Privacy Logo
Providing clear, reliable information on GDPR and data privacy standards to help you navigate the digital landscape securely.
Legal
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram