H&M Hit with Record-Breaking GDPR Fine over Illegal Employee Surveillance
forbes.com
forbes.com
> "After absences such as vacations and sick leave the supervising team leaders conducted so-called Welcome Back Talks with their employees. After these talks, in many cases not only the employees' concrete vacation experiences were recorded, but also symptoms of illness and diagnoses,”
I'm trying to come up with any legal, ethical reason to want to have and keep records on this. Every manager collecting these records has to somehow justify to themselves that this is okay, and I can't fathom how.
Many employers take advantage of the power they have over employees. The real outrage to me is how this is definitely happening in the US and we have no way to combat it.
I've had no issues with any of them.
About equal amounts of money are stolen through wage theft as through petty property crime.
Yet you don't see law enforcement going undercover as workers to make sure that labor laws aren't being violated.
It's pretty clear that even if we have the laws on the books, the issues that affect affluent people more are going to be the ones that police prioritize.
It is not uncommon to have OSHA ignored or have your boss tell you that if you try to unionize, "we'll fire all of you."
Even eliminating the two-party consent requirement for workplace audio recording would do a ton for workers rights, but of course there is no desire among the professional/managerial class to do that.
I'm not sure that's true, at least not in a healthy company. Still, if those are the only options and what they're told to do breaks the law, which option do you think they should choose?
European countries tend to have quite strong employee protections in law, so anyone who did end up quitting over something like this might get some compensation as well.
The company itself is likely to have the legal liability anyway, unless perhaps there was actually criminal conduct on the part of its staff. However, surely those managers should expect at a minimum to be disciplined. Depending on the severity of the mistake, the seniority of each manager and the level of awareness of the relevant issues that they should have had, something like this might even constitute gross misconduct and be a firing matter.
Most people don’t know their rights, or when they do, they feel powerless because even if they could win a retaliation lawsuit, those cost money and time they don’t have. It also doesn’t help that when you do file a complaint with the government, it seems like it goes into a void because they don’t investigate without enough complaints.
What's even the non-legal, non-ethical point of recording employees' vacation experiences? Feel like I'm missing something.
* Do I think this employee has a chronic illness that will them have future absences?
* Is this employee a woman expecting to have more kids, and will that cause future absences?
* Is this employee visiting family out of state? If so, they might want to move to that state in the future. (Acceptable vacation locations include Disneyland, Paris, and anywhere with beaches.)
Illegal and unethical response: If the answer to any of the above is "yes", then slightly rank them lower than coworkers, avoid giving them important projects, and be on the lookout for unrelated reasons to fire them.
Visiting family much more often than not will just be visiting family. The tiny possibility that it might mean something doesn't seem worth the Q&A time.
Why would anyone want to fire an employee who might soon leave off their own accord?
> A comprehensive action plan has been launched to improve the internal auditing practices to ensure data privacy compliance, strengthen leadership knowledge to assure a safe and compliant work environment, and continue to train and educate both staff and leaders in this area
How is the response to this incident to try prevent further breaches rather than vowing to not collect this data in the first place? Why is this an acceptable response at all?
We're so used to the only kind of data protection enforcement being for data leakage - but this is actually a great example of what GDPR is really for: putting a framework around what personal data it's acceptable for companies to process in the first place.
One of the ways in which a business can harm you through abusing the data they have about you is certainly allowing it to leak out - but that is very much not the only intention of data protection law.
Note that this is 2% of profits, not revenue.
Compare this to the average German citizen. It would be 2% of the amount they manage to save, not 2% of their income. That would be 2% of about €4500, or €90. [1]
That's a parking fine level.
[1] https://www.bundesbank.de/resource/blob/617492/cd59713c156ad...
⇒ it’s about 2% of their global profits, for something some they did in Germany. Reading https://www.statista.com/statistics/252187/sales-of-the-hund..., it seems their German revenues are about 20% of global revenues, so I would guess it’s about 10% of their profits made in Germany.
Germany is really the world leader in personal liberty / privacy.
> "After absences such as vacations and sick leave the supervising team leaders conducted so-called Welcome Back Talks with their employees. After these talks, in many cases not only the employees' concrete vacation experiences were recorded, but also symptoms of illness and diagnoses,”
Are you sure? That sounds very Americanesk dystopian to me.