Very little money. If companies can screw up their customers that cheap, they would rather not do data protection at all.
That's only a warning shot. If they are found to violate it again it will be much higher. Last year HN was complaining that GDPR made high fines possible that would sink any company. Now it's not enough.
Germany fines H&M 35 million euros for data protection breaches
31–40 of 53 posts
Re: Germany fines H&M 35 million euros for data protection breaches
#32Very little money. If companies can screw up their customers that cheap, they would rather not do data protection at all.
Now, if you want a truly pointless fine, look no further than: https://www.wsj.com/articles/u-s-regulators-fine-pork-giant-... . A whole $13,494!
As a general rule, once the penalties are seen as both likely and as more expensive than doing things properly, compliance will improve.
Re: Germany fines H&M 35 million euros for data protection breaches
#33Earlier quoted context omitted.
That organizational aspect is actually not all that clear cut and I would hold off on making strong statements about what counts as a filing system. A stack of paper might qualify, ordered or not for instance when it pertains to similar data gathered on others, something that can be searched automatically would definitely qualify and so on. Finding out where that line is is probably going to be an interesting academi…
I agree; what counts as a filing system remains to be seen. Hence why I used a "sufficiently large" pile of stone tablets, to put it beyond doubt that it's not organized regardless of how strict or relaxed the interpretation. I don't recall the source at the moment, but one convincing argument I've heard was that an amount of disorganized data that you can organize given a few hours time would probably be treated as…
Re: Germany fines H&M 35 million euros for data protection breaches
#34Good first step. Hope it leads to less data collection to be honest.
The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.
Re: Germany fines H&M 35 million euros for data protection breaches
#35Earlier quoted context omitted.
> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…
And the first of these exceptions is employment. That's quite reasonable because an employer keeps track of employees' absence for health reasons and will come to know some details in case of serious health problems/long absences. In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) t…
That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer.
Speaking only for NL here, but I think the regulation is the same EU-wide. When you call in sick, you are not obligated to answer any questions from your employer except:
- whether the cause of the illness is (or might be) work-related
- how much time you expect to be out
- discuss a next moment of contact (phone appointment or presence in the office)
Any data regarding the illness itself is off-limits for the employer, you are allowed to volunteer the information but the employer strictly isn't even allowed to ask.
Re: Germany fines H&M 35 million euros for data protection breaches
#36Earlier quoted context omitted.
> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…
You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…
Re: Germany fines H&M 35 million euros for data protection breaches
#37Earlier quoted context omitted.
You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…
Awareness program and an annual refresher aimed at H&M middle management level imminent. That's a lot cheaper than these fines would be.
Re: Germany fines H&M 35 million euros for data protection breaches
#38Re: Germany fines H&M 35 million euros for data protection breaches
#39Earlier quoted context omitted.
And the first of these exceptions is employment. That's quite reasonable because an employer keeps track of employees' absence for health reasons and will come to know some details in case of serious health problems/long absences. In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) t…
an employer keeps track of employees' absence for health reasons That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer. Spea…
I am not suggesting that an employer has access to employees' medical records. However, the fact is that employers will reasonably keep track of sicks leave and will in practice (and quite reasonably) have knowledge of health information very often including the illness.
Personally, I think things start to go too far. Saying that "employee health is a personal matter" is going too far. Intimate details are of course personal and people may not want to share too much (and that's fine) but an employee's health insofar it impacts their job very much concerns the employer, but it must be handled lawfully, reasonably, and tactfully by them. If the employer has a clear picture it is not necessarily negative for the employee as it means that the employer can adapt and take the appropriate supportive action. I think that the legislator recognises this, seeing that employment is an exception to the GDPR's ban on health information processing (obviously without reason).