Live data from Hacker News

Germany fines H&M 35 million euros for data protection breaches

marketscreener.com

11–20 of 53 posts

Re: Germany fines H&M 35 million euros for data protection breaches

#12

"Breach" feels weird in these circumstances, that sounds like they accidentally failed to protect the data of their employees. But it's quite the opposite, they intentionally collected data on their employees that they were not legally allowed to.

A breach of contract doesn't imply that the action is accidental. I believe that's the same for breach of data protection regulations.

Re: Germany fines H&M 35 million euros for data protection breaches

#13
post #5

Very little money. If companies can screw up their customers that cheap, they would rather not do data protection at all.

That's only a warning shot. If they are found to violate it again it will be much higher. Last year HN was complaining that GDPR made high fines possible that would sink any company. Now it's not enough.

HN != HN

Last year you read comments from people who said one thing, now you read a comment saying the opposite. That does not mean that HN has shifted. There are a lot of individuals on this platform with individual opinions.

Re: Germany fines H&M 35 million euros for data protection breaches

#14
post #9

Good first step. Hope it leads to less data collection to be honest.

The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.

I think that's actually excellent. It shows that any kind of data collection is subject to the GDPR. This is something I've been warning companies about for a while now, they believe - quite erroneously - that as long as the system isn't automated that they are free and clear but the GDPR doesn't say anything about automation. So even if it is informal and even if you use stone tablets you are still subject to the law.

Re: Germany fines H&M 35 million euros for data protection breaches

#15
post #8
post #5

Earlier quoted context omitted.

That's only a warning shot. If they are found to violate it again it will be much higher. Last year HN was complaining that GDPR made high fines possible that would sink any company. Now it's not enough.

The fine will certainly hurt, it's not exactly a small fine you can just book as part of your coffee budget. But it's not going to sink the company. If they do it again the fine will certainly be higher and sting a lot more. Possibly sink them. It's certainly a shot before the bow, close enough to do some damage to the ship but not sink it quite yet.

They don't want to sink the company. They want them to stop doing this, and send a message to other companies who are also doing things like this.

Re: Germany fines H&M 35 million euros for data protection breaches

#16
post #8

Earlier quoted context omitted.

The fine will certainly hurt, it's not exactly a small fine you can just book as part of your coffee budget. But it's not going to sink the company. If they do it again the fine will certainly be higher and sting a lot more. Possibly sink them. It's certainly a shot before the bow, close enough to do some damage to the ship but not sink it quite yet.

They don't want to sink the company. They want them to stop doing this, and send a message to other companies who are also doing things like this.

Well, no, if the company doesn't stop and doesn't seem to stop the fines can be high enough to sink a company and I don't doubt that if it comes to it, the agencies involved are ready to sink a company over data protection.

Re: Germany fines H&M 35 million euros for data protection breaches

#17

revenue was $24.3 billion in 2019.

In 2018 they had about 1.1 billion € profit after tax.

35 million € of that isn't quite a small number and that is basically a warning shot to stop. The maximum fine would be 720 million €, which would eat into the years profit quite a lot (and in turn, the shareholder's dividends).

Re: Germany fines H&M 35 million euros for data protection breaches

#18
post #9

Good first step. Hope it leads to less data collection to be honest.

The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.

> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers.

The article says that "H&M collected information on illnesses [...]".

Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting this data does not fall under any of the exceptions.

[1] https://gdpr.eu/article-9-processing-special-categories-of-p...

Re: Germany fines H&M 35 million euros for data protection breaches

#19
post #16

Earlier quoted context omitted.

They don't want to sink the company. They want them to stop doing this, and send a message to other companies who are also doing things like this.

Well, no, if the company doesn't stop and doesn't seem to stop the fines can be high enough to sink a company and I don't doubt that if it comes to it, the agencies involved are ready to sink a company over data protection.

Trust me on this: no company is going to take a 3% hit to their net profits after taxes as a happy event.

The agencies are quite ready but it would take a pretty stupid management to step in front of that train willingly. Note that H&M was adamant that they would cease to collect this data (as they should be).

The only case I know of where there was a multiple-repeat-offender the eventual fine was 250K for a violation involving a single individual (hospital employees in NL thought it was 'fun' to peek on the records of a minor celebrity).

Re: Germany fines H&M 35 million euros for data protection breaches

#20
post #9

Earlier quoted context omitted.

The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.

> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…

It's pretty much an as open-and-shut of a clear violation of having consent and a right to process that data as you could come up with. They got off light in my view but then again, it is a first time offense so maybe not all that light.
Post reply on HN