A privacy notice can point people towards a rights-exercise route and still make that route harder to use than the GDPR permits. The Spanish data protection authority (AEPD) has fined Securitas Direct España, S.A.U. €100,000 after notices directed people exercising access and objection rights to a chargeable 902 telephone number.
The lesson for managers is practical: a free alternative hidden elsewhere on a website may not cure a paid or inconvenient route that the notice itself presents. Rights-exercise channels need to be designed, monitored and tested as a practical process.
What happened in the Securitas Direct case
The EDPB summary records that a consumer association complained about video-surveillance notices referring people to a chargeable 902 number to exercise their rights of access and objection. The AEPD decision found that imposing a cost could discourage people from using those rights.
The finding was an infringement of GDPR Article 12(2), which requires controllers to facilitate the exercise of data-subject rights. The penalty was imposed under Article 83(5)(b). Alongside the €100,000 fine, the AEPD ordered Securitas Direct to replace the notices that referred to the 902 number within 12 months.
The important operational point is that the organisation had other free channels available on its website. The EDPB summary says those channels did not remedy the problem because the notice specifically directed people to the chargeable number. A route presented in the notice must work on its own terms; an alternative that a person has to discover elsewhere may not be enough.
Why a free alternative may not be enough
Article 12(2) is about facilitation, not merely the existence of a theoretical method. A person reading a notice should be able to understand how to exercise a right and use the signposted route without paying a fee to the organisation or being pushed through avoidable friction.
That does not mean every organisation must offer every possible channel. It does mean that each channel it presents should be free, accessible and operational for the rights it claims to support. A website form that accepts only general enquiries, a mailbox that is not monitored, or a telephone route that charges the caller can each undermine the practical promise in the notice.
Managers should also avoid treating this as a narrow telephone-number issue. The same control weakness can arise when a notice links to a broken portal, requires unnecessary account creation, uses an inaccessible form, or sends a person between teams without a clear owner.
How to audit your rights-exercise routes
1. Inventory every route in every notice
Collect current privacy notices, CCTV notices, product notices, employee notices and customer-help pages. Record every email address, telephone number, postal address, form, portal and in-person route used for access, objection and other data-subject rights. Include translated and legacy versions that may still be displayed.
2. Test the route as a member of the public
Follow the exact instruction in each notice. Check whether the telephone number is chargeable, whether the form works on mobile, whether the mailbox is monitored, and whether the route creates unnecessary barriers. Record the time, date, evidence and outcome. Do not assume that a link works because it worked when the notice was approved.
3. Check scope and ownership
Confirm that each channel can receive the rights named in the notice and that staff know what to do next. A front-line team should be able to recognise an access or objection request, capture it accurately and route it to the responsible privacy team without making the person repeat the request.
4. Remove cost and accessibility barriers
Replace premium-rate or otherwise chargeable routes with free options. Check keyboard access, screen-reader labels, plain-language instructions, language support and alternatives for people who cannot use a web form or telephone. Accessibility is part of making the right usable, not a later website improvement.
5. Monitor performance and change control
Set an owner for each route, monitor failed submissions and missed responses, and review notices whenever a phone system, help centre, form or supplier changes. Keep a short audit record showing the test, result, remediation and next review date.
What managers should take from the fine
The case turns a familiar compliance statement into a testable control: can a person use the route the notice gives them, without paying and without avoidable obstacles? Organisations should answer that question with evidence rather than relying on policy wording.
For wider operational context, our guide to operationalising privacy policies explains why published wording needs supporting processes. Our coverage of erasure requests also shows how rights handling can fail when ownership and response controls are unclear.
Teams building baseline knowledge can use GDPR Essentials training to support consistent handling of data-protection responsibilities.
Frequently asked questions
Does GDPR require every rights request channel to be a web form?
No. The practical requirement is that the routes an organisation provides facilitate the exercise of rights and do not impose an unjustified cost or barrier. The right mix of channels depends on the organisation and the people it serves.
Can a free website form cure a chargeable number in a privacy notice?
Not necessarily. In the Securitas Direct case, the EDPB summary says that other free website channels did not remedy the problem because the notice specifically directed people to the chargeable number.
What should a manager test first?
Start with the exact route shown in each notice. Test cost, availability, accessibility, ownership and hand-off, then retain evidence of the result and fix any notice that points to a route that no longer works.
