ARTICLE
20 October 2020

H&M Fined €35 Million For GDPR Breaches

VW
Veale Wasbrough Vizards

Contributor

Veale Wasbrough Vizards
Fashion retail company, H&M, have been fined €35 million by the Hamburg Commission for Data Protection and Freedom of Information
UK Wealth Management
To print this article, all you need is to be registered or login on Mondaq.com.

Fashion retail company, H&M, have been fined €35 million by the Hamburg Commission for Data Protection and Freedom of Information following issues with the way they stored personal data...

...and the extent to which they engaged in covert monitoring of their employees.

In Nuremburg, H&M had a practice of requiring team leaders at one of the store's service centres to find out in-depth information about their teams.The practice dated back to around 2014. The supervisors collated that information and added it to a database which included broader information about the employee's private lives and religious beliefs - in some cases information shared in informal conversations. Experiences from holidays and symptoms of illnesses were recorded following back to work meetings after periods of annual leave and sickness absence.

The database was made digitally accessible to up to 50 managers within the Nuremburg location and the information was used to create a profile of each employee. The profiles could be used by managers when making decisions about the structures of individual stores or teams. The profiles were used to make decisions in relation to the employment relationship.

In October 2019, the database was leaked internally and a data protection complaint was subsequently made. In addition to the fine imposed for the GDPR breaches, H&M has agreed to make a compensation payment to its employees and provided additional training for leaders on data privacy and labour law.

Preventing Data Protection Risks

There is a real risk of significant fines if employers are engaging in covert monitoring of this nature. If an employer does need to collate information relating to its employees, it should do so transparently. Employees should be provided with a privacy notice identifying, amongst other things, what employee personal data is processed and the sources of that data. Employers who systematically monitor their employees must carry out a Data Protection Impact Assessment (DPIA) to help identify and minimise the data protection risks of any such project. Covert monitoring is very unlikely to be lawful.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
20 October 2020

H&M Fined €35 Million For GDPR Breaches

UK Wealth Management

Contributor

Veale Wasbrough Vizards
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More