Spain's data protection authority (AEPD) has fined security company Securitas Direct EUR 100,000 after finding that the company made it harder for individuals to exercise their data subject rights.
According to the European Data Protection Board, the infringement centred on the company directing individuals seeking to exercise their rights to a chargeable telephone number, rather than providing a straightforward, cost-free route to do so.
This decision falls under the General Data Protection Regulation rather than the EU AI Act, but it is relevant to organisations building AI systems that process personal data, since many such systems rely on the same underlying data subject access mechanisms.
Companies operating AI systems that use personal data, including those that will fall within scope of the EU AI Act, often rely on customer service or call centre channels to handle data subject requests. This enforcement action signals that regulators continue to scrutinise whether those channels create unnecessary friction or cost for individuals.
As a compliance matter, organisations preparing for the EU AI Act should review how they handle related data protection obligations, including the channels used for data subject rights requests, to ensure these do not introduce unjustified barriers or costs.
The case is a reminder that overlapping regulatory regimes, data protection and AI governance, often intersect in practice, and that deficiencies identified under one framework can carry reputational and operational implications relevant to the other.