Live data from Hacker News

Germany fines H&M 35 million euros for data protection breaches

marketscreener.com

31–40 of 53 posts

Re: Germany fines H&M 35 million euros for data protection breaches

#31
post #5

Very little money. If companies can screw up their customers that cheap, they would rather not do data protection at all.

That's only a warning shot. If they are found to violate it again it will be much higher. Last year HN was complaining that GDPR made high fines possible that would sink any company. Now it's not enough.

Just wish the UK's ICO were as strict at enforcing GDPR breaches. Most of the time the ICO will do nothing or issue laughably small fines.

Re: Germany fines H&M 35 million euros for data protection breaches

#32

Very little money. If companies can screw up their customers that cheap, they would rather not do data protection at all.

It's about 2% of their annual profit. That seems not-unreasonable for a first offense. Most companies don't want to incur a 35 million euro cost if they can help it, so it should hopefully improve compliance.

Now, if you want a truly pointless fine, look no further than: https://www.wsj.com/articles/u-s-regulators-fine-pork-giant-... . A whole $13,494!

As a general rule, once the penalties are seen as both likely and as more expensive than doing things properly, compliance will improve.

Re: Germany fines H&M 35 million euros for data protection breaches

#33

Earlier quoted context omitted.

That organizational aspect is actually not all that clear cut and I would hold off on making strong statements about what counts as a filing system. A stack of paper might qualify, ordered or not for instance when it pertains to similar data gathered on others, something that can be searched automatically would definitely qualify and so on. Finding out where that line is is probably going to be an interesting academi…

I agree; what counts as a filing system remains to be seen. Hence why I used a "sufficiently large" pile of stone tablets, to put it beyond doubt that it's not organized regardless of how strict or relaxed the interpretation. I don't recall the source at the moment, but one convincing argument I've heard was that an amount of disorganized data that you can organize given a few hours time would probably be treated as…

There is that and there are multiple cases where a single individual affected by a transgression already led to fines as well as the fairly low count that is used to determine if a transgression is a significant one (10!).

Re: Germany fines H&M 35 million euros for data protection breaches

#34
post #9

Good first step. Hope it leads to less data collection to be honest.

The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.

There is nothing weird about this. If you are not allowed to collect/archive certain data, you are not allowed to do so. This is not limited to customers. And that is good.

Re: Germany fines H&M 35 million euros for data protection breaches

#35

Earlier quoted context omitted.

> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…

And the first of these exceptions is employment. That's quite reasonable because an employer keeps track of employees' absence for health reasons and will come to know some details in case of serious health problems/long absences. In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) t…

an employer keeps track of employees' absence for health reasons

That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer.

Speaking only for NL here, but I think the regulation is the same EU-wide. When you call in sick, you are not obligated to answer any questions from your employer except:

- whether the cause of the illness is (or might be) work-related

- how much time you expect to be out

- discuss a next moment of contact (phone appointment or presence in the office)

Any data regarding the illness itself is off-limits for the employer, you are allowed to volunteer the information but the employer strictly isn't even allowed to ask.

Re: Germany fines H&M 35 million euros for data protection breaches

#36
post #24

Earlier quoted context omitted.

> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…

You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…

Awareness program and an annual refresher aimed at H&M middle management level imminent. That's a lot cheaper than these fines would be.

Re: Germany fines H&M 35 million euros for data protection breaches

#37
post #24

Earlier quoted context omitted.

You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…

Awareness program and an annual refresher aimed at H&M middle management level imminent. That's a lot cheaper than these fines would be.

Well, the problem is that to be consistent (and safe), you'd have to do a similar training for every possible offense. GDPR is top-of-mind for HN readers, but any large company is likely constantly violating at least dozens, if not hundreds or thousands of regulations. Ask any corporate lawyer how you could avoid violating any regulation or law, and they will just give you a blank stare, or tell you it's impossible.

Re: Germany fines H&M 35 million euros for data protection breaches

#38
I wonder if the huge, scaled violations (when web sites violate the privacy of millions of visitors through "consent" dialogs that require dozens of clicks or by claiming legitimate interest where it has already been decided that's not OK) will receive penalties scaled accordingly to their scale of the violation, and it's just taking time, or if the DPAs are just continuing their pattern of bringing the hammer down on randomly picked small-scale violations while ignoring the stuff that actually affects all of us.

Re: Germany fines H&M 35 million euros for data protection breaches

#39
post #35

Earlier quoted context omitted.

And the first of these exceptions is employment. That's quite reasonable because an employer keeps track of employees' absence for health reasons and will come to know some details in case of serious health problems/long absences. In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) t…

an employer keeps track of employees' absence for health reasons That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer. Spea…

I am writing from Europe.

I am not suggesting that an employer has access to employees' medical records. However, the fact is that employers will reasonably keep track of sicks leave and will in practice (and quite reasonably) have knowledge of health information very often including the illness.

Personally, I think things start to go too far. Saying that "employee health is a personal matter" is going too far. Intimate details are of course personal and people may not want to share too much (and that's fine) but an employee's health insofar it impacts their job very much concerns the employer, but it must be handled lawfully, reasonably, and tactfully by them. If the employer has a clear picture it is not necessarily negative for the employee as it means that the employer can adapt and take the appropriate supportive action. I think that the legislator recognises this, seeing that employment is an exception to the GDPR's ban on health information processing (obviously without reason).

Post reply on HN