"Breach" feels weird in these circumstances, that sounds like they accidentally failed to protect the data of their employees. But it's quite the opposite, they intentionally collected data on their employees that they were not legally allowed to.
Germany fines H&M 35 million euros for data protection breaches
21–30 of 53 posts
Re: Germany fines H&M 35 million euros for data protection breaches
#22Earlier quoted context omitted.
The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.
I think that's actually excellent. It shows that any kind of data collection is subject to the GDPR. This is something I've been warning companies about for a while now, they believe - quite erroneously - that as long as the system isn't automated that they are free and clear but the GDPR doesn't say anything about automation. So even if it is informal and even if you use stone tablets you are still subject to the la…
If it's automated, it's always GDPR.
If it's not automated, it's GDPR under the condition that the data is part of a filing system.
So if you order your stone tablets alphabetically by their title, it's GDPR, but jumble a sufficiently large pile of stone tablets and you're in the clear.
In practice, this means that if you have a warehouse full of unordered boxes full of unordered forms, then somebody exercising their right to be forgotten cannot force you to go through every single box to see if there is data in there.
Conversely and frustratingly, if you have one gigantic folder of digital media, then you are technically required to actually go through that data, although I've heard of cases argued with authorities where this can be forgone in cases where it would be extremely uneconomical.
I'm still anxiously waiting for the first big decision on e-mail, for example. In large-scale corporate environments, good luck identifying every email containing personal data of a particular person, should that person ever exercise their right to be forgotten.
(Edit: no idea why you got downvoted, you raise an important point)
Re: Germany fines H&M 35 million euros for data protection breaches
#23Earlier quoted context omitted.
I think that's actually excellent. It shows that any kind of data collection is subject to the GDPR. This is something I've been warning companies about for a while now, they believe - quite erroneously - that as long as the system isn't automated that they are free and clear but the GDPR doesn't say anything about automation. So even if it is informal and even if you use stone tablets you are still subject to the la…
Well, strictly speaking, automation is a key factor. If it's automated, it's always GDPR. If it's not automated, it's GDPR under the condition that the data is part of a filing system. So if you order your stone tablets alphabetically by their title, it's GDPR, but jumble a sufficiently large pile of stone tablets and you're in the clear. In practice, this means that if you have a warehouse full of unordered boxes fu…
Finding out where that line is is probably going to be an interesting academic exercise which will result in lots of fines that could have been avoided easily: if you don't have a right to process certain data in an automated way pretend you don't have that right at all to stay safe.
After all, once the data is sufficiently disorganized to be searched efficiently it is also sufficiently disorganized to keep it secure and a data leak of disorganized data would be just as big an issue as gathering the data itself.
Re: Germany fines H&M 35 million euros for data protection breaches
#24Earlier quoted context omitted.
The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.
> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…
Re: Germany fines H&M 35 million euros for data protection breaches
#25Earlier quoted context omitted.
The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. Doesn't even look like upper management was involved. Very different from the usual concerns about large-scale, organized collection of data about end users.
> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…
In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) the data leaked because they did not secure it properly.
This sort of files on employees used to be very common. Regulations have made them 'tricky' especially if managed "as it's always been done" without expert, up-to-date, input on what's allowed and acceptable, and how to keep it secure, which seems to have happened at H&M... So definitely a failure of the company management and I'm sure that all managers have been put through compulsory training since with a very clear message that ignoring it means instant dismissal.
Re: Germany fines H&M 35 million euros for data protection breaches
#26Earlier quoted context omitted.
Well, strictly speaking, automation is a key factor. If it's automated, it's always GDPR. If it's not automated, it's GDPR under the condition that the data is part of a filing system. So if you order your stone tablets alphabetically by their title, it's GDPR, but jumble a sufficiently large pile of stone tablets and you're in the clear. In practice, this means that if you have a warehouse full of unordered boxes fu…
That organizational aspect is actually not all that clear cut and I would hold off on making strong statements about what counts as a filing system. A stack of paper might qualify, ordered or not for instance when it pertains to similar data gathered on others, something that can be searched automatically would definitely qualify and so on. Finding out where that line is is probably going to be an interesting academi…
I don't recall the source at the moment, but one convincing argument I've heard was that an amount of disorganized data that you can organize given a few hours time would probably be treated as equivalent to organized data in the eyes of the authorities, otherwise you'd have a trivial loophole.
Re: Germany fines H&M 35 million euros for data protection breaches
#27"Breach" feels weird in these circumstances, that sounds like they accidentally failed to protect the data of their employees. But it's quite the opposite, they intentionally collected data on their employees that they were not legally allowed to.
A breach of contract doesn't imply that the action is accidental. I believe that's the same for breach of data protection regulations.
Re: Germany fines H&M 35 million euros for data protection breaches
#28Earlier quoted context omitted.
> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…
You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…
Re: Germany fines H&M 35 million euros for data protection breaches
#29Earlier quoted context omitted.
> The weird thing about this case is that it was completely informal data collection, about employees by their mid-level managers. The article says that "H&M collected information on illnesses [...]". Data concerning health is among the Article 9 special categories of personal data [1], the processing of which is generally prohibited, with only a few exceptions. I'm all but certain that a mid-level manager collecting…
You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…
Training people in basic IT security is difficult, too, but it's still done. Of course the results aren't going to be perfect, but at least most people will then understand that writing down a password on a post-it under a keyboard is a no-no.