H&M fined 35 million euros for GDPR violation

Society of Corporate Compliance and Ethics (SCCE)
Contact

Society of Corporate Compliance and Ethics (SCCE)

CEP Magazine (December 2020)

The Hamburg Data Protection Authority issued their largest fine[1] ever under the General Data Protection Regulation (GDPR) for employee-related offenses. A fine of more than €35 million was levied against Hennes and Mauritz AB (H&M), a Swedish clothing company.

According to the investigation, H&M recorded and stored gigabytes of recorded one-on-one conversations with employees. The details provided in those conversations were used in decisions regarding the employees. The Hamburg Data Protection Authority found that the personal details revealed, the recording and storage of those details, the fact that multiple managers had access to the data, and that the data were used to make work-related decisions violated the GDPR and infringed on employees’ civil rights.

According to Dr. Johannes Caspar, Hamburg’s commissioner for data protection and freedom of information:

This case documents a serious disregard for employee data protection at the H&M site in Nuremberg. The amount of the fine imposed is therefore adequate and effective to deter companies from violating the privacy of their employees. Management’s efforts to compensate those affected on site and to restore confidence in the company as an employer have to be seen expressly positively. The transparent information provided by those responsible and the guarantee of financial compensation certainly show the intention to give the employees the respect and appreciation they deserve as dependent workers in their daily work for their company.

1 Jonathan Armstrong and Andre Bywater, “Client Alert: Hamburg Data Protection Authority fines H&M €35.2m for GDPR violations,” Cordery, October 1, 2020, https://bit.ly/3dGfm8x.

[View source.]

Written by:

Society of Corporate Compliance and Ethics (SCCE)
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Society of Corporate Compliance and Ethics (SCCE) on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide