Compliance Gaps in Privacy Notices
A recent enforcement action by the Spanish Data Protection Authority (DPA) against Securitas Direct highlights a widespread issue in privacy notices. The company was fined EUR 100,000 for directing individuals to a chargeable 902 telephone number to exercise their rights, violating Article 12(2) of the General Data Protection Regulation. This case underscores that partial compliance isn't enough; if your privacy notice leads to any paid channel, it creates an obstacle that regulators will penalize, regardless of other free options available elsewhere.
Key Findings
Liability from Channel-Specific Guidance
The Spanish DPA dismissed Securitas Direct's argument that free channels were available on their website. The violation stemmed from the video surveillance notice directing individuals to a paid line. Your privacy notice must immediately point to free channels, not require data subjects to search for them.
Affirmative Facilitation Duty Under Article 12(2)
Article 12(2) doesn't just prohibit fees; it mandates that you facilitate the exercise of rights under Articles 15 through 22. This means removing friction, not just avoiding explicit costs. A chargeable phone number adds friction, even if you don't profit from it.
Scrutiny of Video Surveillance Notices
This enforcement action focused on notices at physical locations where video recording occurred. These disclosures receive more regulatory attention because individuals encounter them in real-world contexts, limiting their ability to research alternatives or delay their response.
Beyond Financial Penalties
The Spanish DPA required Securitas Direct to replace all non-compliant notices within 12 months. Expect regulators to demand operational changes that involve physical infrastructure updates, not just policy revisions. Plan your budget accordingly.
Consumer Complaints and Pattern Investigations
This case was initiated by a consumer association. Regulators increasingly rely on advocacy groups to identify systemic compliance failures. Design your privacy notices with the expectation of third-party review, not just casual end-user reading.
Implications for Your Team
Failing to comply with Article 12 can lead to penalties under Article 83(5)(b), which allows fines up to EUR 20 million or 4% of annual global turnover. The EUR 100,000 penalty here was specific to Securitas Direct, but the violation category allows for much larger fines.
Operational disruption is another risk. The 12-month remediation deadline required Securitas Direct to update and replace physical notices across their video surveillance infrastructure. For organizations with widespread operations, this timeline poses coordination challenges across facilities management, legal review, and vendor procurement.
The decision clarifies that offering free channels elsewhere doesn't satisfy Article 12 if specific notices direct data subjects to paid channels. Each disclosure point must independently meet the facilitation standard. Your Data Subject Access Request process needs a channel-by-channel audit, not just an enterprise-wide policy review.
Action Items by Priority
Immediate (This Week)
Audit all privacy notices at data collection points. This includes physical signage, web forms, mobile app disclosures, and call center scripts. Identify any instance where you direct data subjects to channels that impose costs, such as premium-rate numbers or postal addresses requiring paid postage.
Review video surveillance notices specifically. If you operate cameras in the EU, ensure every notice provides a free contact method for exercising rights under Articles 15-22. The notice itself must include this information, not just reference it as available "on our website."
Near-Term (This Month)
Map your Data Subject Access Request intake channels by cost to the data subject. Create a matrix showing telephone (toll-free vs. premium), email (free vs. paid support), web form (open vs. authenticated), and postal (prepaid envelope vs. data subject stamp). Flag any channel imposing direct or indirect costs.
Replace paid channels with free alternatives in all privacy notices. Substitute premium-rate numbers with toll-free alternatives or email addresses. Consider providing prepaid return envelopes for rights requests, especially in video surveillance contexts where digital access may be inconvenient.
Document your channel facilitation analysis. Create records showing your evaluation of whether each contact method facilitates or hinders rights exercise. This documentation supports your Article 5(2) accountability obligation and demonstrates good faith if regulators question your channel design.
Strategic (This Quarter)
Implement channel-specific testing for Data Subject Access Requests. Test response times, staff training, and technical functionality for each method published in privacy notices. Ensure your intake process handles requests correctly when a data subject uses the specified channel in a physical notice.
Develop remediation timelines for physical infrastructure. If you find non-compliant notices in physical locations, create a replacement schedule accounting for printing, distribution, and installation logistics. The Spanish DPA's 12-month deadline is a reasonable timeframe for distributed operations, but regulators may expect faster action for digital channels.
Train your facilities and operations teams on Article 12 requirements. Privacy notice compliance isn't just a legal team responsibility when it involves physical signage, building access systems, or customer service scripts. Your operational staff need to understand that channel design affects regulatory risk.





