Warnings over storing employee data after H&M hit with €35 million fine

-

On 2nd October 2020, the clothing retail company, H&M, were fined €35 million after monitoring and recording “extensive details about their [employees’] private lives” in Nuremburg. HRreview asks professionals how employers can ensure they do not breach the General Data Protection Regulation (GDPR).

H&M were hit with a €35 million fine after a German data protection watchdog found that, in Nuremberg, the retailer had monitored hundreds of employees since at least 2014.

The Hamburg Commission for Data Protection and the Freedom of Information stated that:

Corresponding notes [linked to the monitoring] were permanently stored on a network drive.

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

After absences such as vacations and sick leave, the supervising team leaders conducted so-called Welcome Back Talks with their employees. After these talks, in many cases, not only the employees’ concrete vacation experiences were recorded but also symptoms of illness and diagnoses.

In addition, some supervisors acquired a broad knowledge of their employees’ private lives through personal and floor talks, ranging from rather harmless details to family issues and religious beliefs.

The Commission also found that some of these issues were updated on the network drive over longer periods of time as H&M received more information.

This data was able to be partly read by up to 50 managers after it was digitally stored. According to the report, this data was “used, among other things, to obtain a detailed profile of employees for measures and decisions regarding their employment.”

This breach of data became public after an internal error in October 2019 leaked the data company-wide.

H&M issued a public statement in its June to August earnings report, stating:

The regional data protection authority in Hamburg has imposed an administrative fine of 35 million euros. The H&M group admits shortcomings at the service centre and has taken forceful measures to correct this.

In addition, the company agreed to pay out compensation to employees who have worked at that site for at least a month since May 2018. It has also stressed that it has carried out “additional training for leaders in relation to data privacy and labour law”.

Dr. Francis Gaffney, director of threat intelligence at Mimecast, a cyber security specialist company, said:

GDPR is not just something else an organisation needs to comply with, but rather benefit from the behaviours GDPR is designed to encourage. Organisations shouldn’t view regulation such as this as a burden and start to view it through the lens of their customers, partners, or employees. If someone trusts you with their data, you owe it to them to be completely honest about what data you are collecting and to protect it, know exactly how (and where) it is stored, and who can access that data.

Because GDPR focuses on the protection of personal data, and not just data privacy, compliance requires a more rigorous approach. To remain GDPR-compliant, organisations must demonstrate GDPR compliance across organisational and technological operations, including specific requirements for data processors and data controllers. It is also necessary for organisations to establish a legal basis for processing personal data, must be able to defend the method of processing, and comply with any request to stop processing when consent is withdrawn or was found to never have been given. Implementing archiving technology can also help organisations remain compliant, especially if they ever go through an audit process.

Emma Erskine-Fox, associate at UK law firm TLT, said:

Employee monitoring is very privacy-intrusive and requires a robust justification to demonstrate that it is proportionate, considering the impact on employees’ privacy. Employers should always consider less intrusive ways to achieve the purpose of any proposed monitoring before proceeding, and monitoring on a “blanket” basis will generally be difficult to justify.

Transparency is also key; covert monitoring is unlikely to meet the GDPR requirements except in very exceptional circumstances.

It is crucial that employers carry out a thorough data protection impact assessment to fully assess the risks of any proposed monitoring and ensure that their approach is proportionate and justified.

Monica Sharma is an English Literature graduate from the University of Warwick. As Editor for HRreview, her particular interests in HR include issues concerning diversity, employment law and wellbeing in the workplace. Alongside this, she has written for student publications in both England and Canada. Monica has also presented her academic work concerning the relationship between legal systems, sexual harassment and racism at a university conference at the University of Western Ontario, Canada.

Latest news

Transgender staff excluded from single-sex toilets under new equality guidance

Transgender people must be excluded from single-sex toilets and changing rooms that correspond with their lived gender under updated...

Simon Coker: Closing the emotional gap – why AI in the workplace is as much a human challenge as a technological one

AI adoption is transforming how work gets done across every sector. But its deeper impact is less visible: it is reshaping how people feel about their work.

Employment tribunal delays stretch towards 2030 as lawyers warn system is nearing collapse

Employment tribunal hearings are being delayed for years as lawyers warn mounting backlogs are undermining workplace justice.

Keeping culture and purpose at the centre of a growing fintech

A fintech people leader explains how culture, wellbeing and purpose are being protected during rapid business growth.
- Advertisement -

Migrant worker with no right to work in UK wins discrimination case against employer

An employment tribunal has ruled that a migrant worker without the legal right to work in Britain can still pursue successful discrimination claims.

Government to replace some GP sick notes with return-to-work plans

Workers in four English regions will be directed towards personalised health and employment support as ministers test alternatives to GP-issued fit notes.

Must read

Nimesh Shah: The HR secrets to getting your employees out of a March slump

"HR departments need to work in synch with their leadership team."

Dr Mark Winwood: Some employees will lie when they’re sick – but it’s not all dishonest

The first Monday of February has come to be known as ‘National Sickie Day’ – the day that employees are supposed to be most likely to call in sick. Employment law firm ELAS, which has promoted the notion, maintains that a combination of miserable weather, commuting in the dark, post-Christmas credit card bills and long gap between holidays makes the first Monday of February the day that people are most likely to take some unofficial time off.
- Advertisement -

You might also likeRELATED
Recommended to you