I wonder if the huge, scaled violations (when web sites violate the privacy of millions of visitors through "consent" dialogs that require dozens of clicks or by claiming legitimate interest where it has already been decided that's not OK) will receive penalties scaled accordingly to their scale of the violation, and it's just taking time, or if the DPAs are just continuing their pattern of bringing the hammer down o…
Germany fines H&M 35 million euros for data protection breaches
41–50 of 53 posts
Re: Germany fines H&M 35 million euros for data protection breaches
#42Earlier quoted context omitted.
Awareness program and an annual refresher aimed at H&M middle management level imminent. That's a lot cheaper than these fines would be.
Well, the problem is that to be consistent (and safe), you'd have to do a similar training for every possible offense. GDPR is top-of-mind for HN readers, but any large company is likely constantly violating at least dozens, if not hundreds or thousands of regulations. Ask any corporate lawyer how you could avoid violating any regulation or law, and they will just give you a blank stare, or tell you it's impossible.
Re: Germany fines H&M 35 million euros for data protection breaches
#43Earlier quoted context omitted.
Well, the problem is that to be consistent (and safe), you'd have to do a similar training for every possible offense. GDPR is top-of-mind for HN readers, but any large company is likely constantly violating at least dozens, if not hundreds or thousands of regulations. Ask any corporate lawyer how you could avoid violating any regulation or law, and they will just give you a blank stare, or tell you it's impossible.
Very few laws have as many teeth in them for corporations as the GDPR does, it was designed with that particular aspect in mind. The EU bureaucrats have a personal stake in the outcome so that definitely helped to focus them.
Re: Germany fines H&M 35 million euros for data protection breaches
#44Is it related to GDPR? At least the linked article doesn't mention it is. It looks like it is related to health data which is anyways illegal in most countries before GDPR.
From the GDPR enforcement tracker.
Re: Germany fines H&M 35 million euros for data protection breaches
#45Money goes to the state cofins, not to the victims.
Re: Germany fines H&M 35 million euros for data protection breaches
#46Money goes to the state cofins, not to the victims.
Re: Germany fines H&M 35 million euros for data protection breaches
#47Earlier quoted context omitted.
And the first of these exceptions is employment. That's quite reasonable because an employer keeps track of employees' absence for health reasons and will come to know some details in case of serious health problems/long absences. In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) t…
an employer keeps track of employees' absence for health reasons That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer. Spea…
In Germany the doctor only certifies that the employee is unable to carry out their work duties. The reason why is a secret between doctor and patient.
In Finland the doctor sends the ICD code to the employer.
So there is no EU-wide regulation. IIRC GDPR says that data is protected unless the exchange is regulated by a law or the subject has consented. (It's been a while I read it...) Laws are national.
Re: Germany fines H&M 35 million euros for data protection breaches
#48Earlier quoted context omitted.
I think that's actually excellent. It shows that any kind of data collection is subject to the GDPR. This is something I've been warning companies about for a while now, they believe - quite erroneously - that as long as the system isn't automated that they are free and clear but the GDPR doesn't say anything about automation. So even if it is informal and even if you use stone tablets you are still subject to the la…
Well, strictly speaking, automation is a key factor. If it's automated, it's always GDPR. If it's not automated, it's GDPR under the condition that the data is part of a filing system. So if you order your stone tablets alphabetically by their title, it's GDPR, but jumble a sufficiently large pile of stone tablets and you're in the clear. In practice, this means that if you have a warehouse full of unordered boxes fu…
Re: Germany fines H&M 35 million euros for data protection breaches
#49Earlier quoted context omitted.
You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…
In this case they seem to have collected 60 GB data shared among 50 managers. It's interesting that no one raised an issue. It only became known after the network share was made visible to more people by mistake.
Re: Germany fines H&M 35 million euros for data protection breaches
#50Earlier quoted context omitted.
Well, no, if the company doesn't stop and doesn't seem to stop the fines can be high enough to sink a company and I don't doubt that if it comes to it, the agencies involved are ready to sink a company over data protection.
Trust me on this: no company is going to take a 3% hit to their net profits after taxes as a happy event. The agencies are quite ready but it would take a pretty stupid management to step in front of that train willingly. Note that H&M was adamant that they would cease to collect this data (as they should be). The only case I know of where there was a multiple-repeat-offender the eventual fine was 250K for a violatio…