Germany fines H&M 35 million euros for data protection breaches
marketscreener.com
marketscreener.com
Very different from the usual concerns about large-scale, organized collection of data about end users.
If it's automated, it's always GDPR.
If it's not automated, it's GDPR under the condition that the data is part of a filing system.
So if you order your stone tablets alphabetically by their title, it's GDPR, but jumble a sufficiently large pile of stone tablets and you're in the clear.
In practice, this means that if you have a warehouse full of unordered boxes full of unordered forms, then somebody exercising their right to be forgotten cannot force you to go through every single box to see if there is data in there.
Conversely and frustratingly, if you have one gigantic folder of digital media, then you are technically required to actually go through that data, although I've heard of cases argued with authorities where this can be forgone in cases where it would be extremely uneconomical.
I'm still anxiously waiting for the first big decision on e-mail, for example. In large-scale corporate environments, good luck identifying every email containing personal data of a particular person, should that person ever exercise their right to be forgotten.
(Edit: no idea why you got downvoted, you raise an important point)
Finding out where that line is is probably going to be an interesting academic exercise which will result in lots of fines that could have been avoided easily: if you don't have a right to process certain data in an automated way pretend you don't have that right at all to stay safe.
After all, once the data is sufficiently disorganized to be searched efficiently it is also sufficiently disorganized to keep it secure and a data leak of disorganized data would be just as big an issue as gathering the data itself.
I don't recall the source at the moment, but one convincing argument I've heard was that an amount of disorganized data that you can organize given a few hours time would probably be treated as equivalent to organized data in the eyes of the authorities, otherwise you'd have a trivial loophole.
The article says that "H&M collected information on illnesses [...]".
Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting this data does not fall under any of the exceptions.
[1] https://gdpr.eu/article-9-processing-special-categories-of-p...
Training people in basic IT security is difficult, too, but it's still done. Of course the results aren't going to be perfect, but at least most people will then understand that writing down a password on a post-it under a keyboard is a no-no.
In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) the data leaked because they did not secure it properly.
This sort of files on employees used to be very common. Regulations have made them 'tricky' especially if managed "as it's always been done" without expert, up-to-date, input on what's allowed and acceptable, and how to keep it secure, which seems to have happened at H&M... So definitely a failure of the company management and I'm sure that all managers have been put through compulsory training since with a very clear message that ignoring it means instant dismissal.
That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer.
Speaking only for NL here, but I think the regulation is the same EU-wide. When you call in sick, you are not obligated to answer any questions from your employer except:
- whether the cause of the illness is (or might be) work-related
- how much time you expect to be out
- discuss a next moment of contact (phone appointment or presence in the office)
Any data regarding the illness itself is off-limits for the employer, you are allowed to volunteer the information but the employer strictly isn't even allowed to ask.
I am not suggesting that an employer has access to employees' medical records. However, the fact is that employers will reasonably keep track of sicks leave and will in practice (and quite reasonably) have knowledge of health information very often including the illness.
Personally, I think things start to go too far. Saying that "employee health is a personal matter" is going too far. Intimate details are of course personal and people may not want to share too much (and that's fine) but an employee's health insofar it impacts their job very much concerns the employer, but it must be handled lawfully, reasonably, and tactfully by them. If the employer has a clear picture it is not necessarily negative for the employee as it means that the employer can adapt and take the appropriate supportive action. I think that the legislator recognises this, seeing that employment is an exception to the GDPR's ban on health information processing (obviously without reason).
In Germany the doctor only certifies that the employee is unable to carry out their work duties. The reason why is a secret between doctor and patient.
In Finland the doctor sends the ICD code to the employer.
So there is no EU-wide regulation. IIRC GDPR says that data is protected unless the exchange is regulated by a law or the subject has consented. (It's been a while I read it...) Laws are national.
35 million € of that isn't quite a small number and that is basically a warning shot to stop. The maximum fine would be 720 million €, which would eat into the years profit quite a lot (and in turn, the shareholder's dividends).
From the GDPR enforcement tracker.
But it's quite the opposite, they intentionally collected data on their employees that they were not legally allowed to.
It's not a problem of a lack of reporting.
I do donate generously to noyb.eu, which is using those donations to hire full-time people to do exactly that, plus trigger lawsuits where necessary.
I did talk to people working DPAs though, and they seem obsessed with the irrelevant small stuff (particularly keeping people from easily communicating via e-mail is their pet peeve, ignoring the improvements in transport security that happened in the past two decades since they developed their policies), instead of dealing with what affects everyone.
Last year HN was complaining that GDPR made high fines possible that would sink any company. Now it's not enough.
If they do it again the fine will certainly be higher and sting a lot more. Possibly sink them.
It's certainly a shot before the bow, close enough to do some damage to the ship but not sink it quite yet.
The agencies are quite ready but it would take a pretty stupid management to step in front of that train willingly. Note that H&M was adamant that they would cease to collect this data (as they should be).
The only case I know of where there was a multiple-repeat-offender the eventual fine was 250K for a violation involving a single individual (hospital employees in NL thought it was 'fun' to peek on the records of a minor celebrity).
Last year you read comments from people who said one thing, now you read a comment saying the opposite. That does not mean that HN has shifted. There are a lot of individuals on this platform with individual opinions.
Now, if you want a truly pointless fine, look no further than: https://www.wsj.com/articles/u-s-regulators-fine-pork-giant-... . A whole $13,494!
As a general rule, once the penalties are seen as both likely and as more expensive than doing things properly, compliance will improve.