Spain's data protection authority (AEPD) has fined security firm Securitas Direct 100,000 EUR, according to the European Data Protection Board.
The authority found that the company made it more difficult for individuals to exercise their data subject rights by directing them to a telephone number that incurred charges.
Under the GDPR, organisations are generally expected to provide accessible channels for individuals to submit requests, such as those relating to access, rectification or erasure, without imposing undue cost or friction.
The case illustrates a recurring enforcement theme across EU data protection authorities: mechanisms that appear to offer a route for exercising rights but that in practice deter or burden individuals can themselves constitute a breach, separate from any underlying data handling issue.
Chargeable or hard-to-reach contact points have been flagged in previous enforcement actions across member states, suggesting that regulators view the design of rights-request channels as a compliance area in its own right, not merely an administrative detail.
While this decision concerns the GDPR rather than the EU AI Act, it is relevant to organisations preparing for the latter, since the Act also builds in expectations around transparency and the ability of affected individuals to seek information or redress in connection with AI systems.
As a compliance matter, organisations deploying AI systems that process personal data should review how they route requests from individuals, ensuring that any contact channel used to satisfy rights obligations, whether under GDPR or emerging AI Act transparency provisions, does not impose costs or unreasonable barriers.
This case serves as a reminder that regulators scrutinise the practical accessibility of compliance mechanisms, not just their formal existence, a principle likely to extend to AI-specific obligations as enforcement practice develops.