Warnings over storing employee data after H&M hit with €35 million fine

-

On 2nd October 2020, the clothing retail company, H&M, were fined €35 million after monitoring and recording “extensive details about their [employees’] private lives” in Nuremburg. HRreview asks professionals how employers can ensure they do not breach the General Data Protection Regulation (GDPR).

H&M were hit with a €35 million fine after a German data protection watchdog found that, in Nuremberg, the retailer had monitored hundreds of employees since at least 2014.

The Hamburg Commission for Data Protection and the Freedom of Information stated that:

Corresponding notes [linked to the monitoring] were permanently stored on a network drive.

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

After absences such as vacations and sick leave, the supervising team leaders conducted so-called Welcome Back Talks with their employees. After these talks, in many cases, not only the employees’ concrete vacation experiences were recorded but also symptoms of illness and diagnoses.

In addition, some supervisors acquired a broad knowledge of their employees’ private lives through personal and floor talks, ranging from rather harmless details to family issues and religious beliefs.

The Commission also found that some of these issues were updated on the network drive over longer periods of time as H&M received more information.

This data was able to be partly read by up to 50 managers after it was digitally stored. According to the report, this data was “used, among other things, to obtain a detailed profile of employees for measures and decisions regarding their employment.”

This breach of data became public after an internal error in October 2019 leaked the data company-wide.

H&M issued a public statement in its June to August earnings report, stating:

The regional data protection authority in Hamburg has imposed an administrative fine of 35 million euros. The H&M group admits shortcomings at the service centre and has taken forceful measures to correct this.

In addition, the company agreed to pay out compensation to employees who have worked at that site for at least a month since May 2018. It has also stressed that it has carried out “additional training for leaders in relation to data privacy and labour law”.

Dr. Francis Gaffney, director of threat intelligence at Mimecast, a cyber security specialist company, said:

GDPR is not just something else an organisation needs to comply with, but rather benefit from the behaviours GDPR is designed to encourage. Organisations shouldn’t view regulation such as this as a burden and start to view it through the lens of their customers, partners, or employees. If someone trusts you with their data, you owe it to them to be completely honest about what data you are collecting and to protect it, know exactly how (and where) it is stored, and who can access that data.

Because GDPR focuses on the protection of personal data, and not just data privacy, compliance requires a more rigorous approach. To remain GDPR-compliant, organisations must demonstrate GDPR compliance across organisational and technological operations, including specific requirements for data processors and data controllers. It is also necessary for organisations to establish a legal basis for processing personal data, must be able to defend the method of processing, and comply with any request to stop processing when consent is withdrawn or was found to never have been given. Implementing archiving technology can also help organisations remain compliant, especially if they ever go through an audit process.

Emma Erskine-Fox, associate at UK law firm TLT, said:

Employee monitoring is very privacy-intrusive and requires a robust justification to demonstrate that it is proportionate, considering the impact on employees’ privacy. Employers should always consider less intrusive ways to achieve the purpose of any proposed monitoring before proceeding, and monitoring on a “blanket” basis will generally be difficult to justify.

Transparency is also key; covert monitoring is unlikely to meet the GDPR requirements except in very exceptional circumstances.

It is crucial that employers carry out a thorough data protection impact assessment to fully assess the risks of any proposed monitoring and ensure that their approach is proportionate and justified.

Monica Sharma is an English Literature graduate from the University of Warwick. As Editor for HRreview, her particular interests in HR include issues concerning diversity, employment law and wellbeing in the workplace. Alongside this, she has written for student publications in both England and Canada. Monica has also presented her academic work concerning the relationship between legal systems, sexual harassment and racism at a university conference at the University of Western Ontario, Canada.

Latest news

Helen Wada: Why engagement initiatives fail without human-centric leadership

Workforce engagement has become a hot topic across the boardroom and beyond, particularly as hybrid working practices have become the norm.

Recruiters warned to move beyond ‘post and pray’ as passive talent overlooked

Employers risk missing most candidates by relying on job boards as hiring methods struggle to deliver quality applicants.

Employment tribunal roundup: Appeal fairness, dismissal reasoning, discrimination tests and religious belief clarified

Decisions examine appeal failures, dismissal reasoning, discrimination claims and religious belief, offering practical guidance on fairness, causation and proportionality.

Fears of AI cheating in hiring ‘overblown’ as employers urged to rethink assessments

Employers may be overstating concerns about AI misuse in recruitment as evidence of candidate manipulation remains limited.
- Advertisement -

More employees use workplace health benefits, but barriers still limit access

Many workers struggle to access employer healthcare support due to confusion, costs and unclear processes.

Gender pay gap in tech widens to nine-year high as AI roles drive salaries

Women in IT earn less as salaries rise faster in male-dominated AI and cybersecurity roles, widening pay differences.

Must read

Rina Goldberg Lynch: 10 ways to leverage diversity as a business opportunity

Rina Goldberg Lynch from leading diversity group Voice at the Table discusses 10 ways to leverage diversity as a business opportunity.

Robert Leeming: The view in America – the fight for paid sick leave

With all the tumult and fire of the American presidential election season currently being focused on Donald Trump and his often delusional and downright bizarre statements on immigration, one of the key policy battlegrounds of the campaign so far is being neglected: the fight for the American worker.
- Advertisement -

You might also likeRELATED
Recommended to you