Live data from Hacker News

Germany fines H&M 35 million euros for data protection breaches

marketscreener.com

41–50 of 53 posts

Re: Germany fines H&M 35 million euros for data protection breaches

#41

I wonder if the huge, scaled violations (when web sites violate the privacy of millions of visitors through "consent" dialogs that require dozens of clicks or by claiming legitimate interest where it has already been decided that's not OK) will receive penalties scaled accordingly to their scale of the violation, and it's just taking time, or if the DPAs are just continuing their pattern of bringing the hammer down o…

DPA's don't go on fishing expeditions, if you want them to do something you have to inform them.

Re: Germany fines H&M 35 million euros for data protection breaches

#42
post #37

Earlier quoted context omitted.

Awareness program and an annual refresher aimed at H&M middle management level imminent. That's a lot cheaper than these fines would be.

Well, the problem is that to be consistent (and safe), you'd have to do a similar training for every possible offense. GDPR is top-of-mind for HN readers, but any large company is likely constantly violating at least dozens, if not hundreds or thousands of regulations. Ask any corporate lawyer how you could avoid violating any regulation or law, and they will just give you a blank stare, or tell you it's impossible.

Very few laws have as many teeth in them for corporations as the GDPR does, it was designed with that particular aspect in mind. The EU bureaucrats have a personal stake in the outcome so that definitely helped to focus them.

Re: Germany fines H&M 35 million euros for data protection breaches

#43
post #37

Earlier quoted context omitted.

Well, the problem is that to be consistent (and safe), you'd have to do a similar training for every possible offense. GDPR is top-of-mind for HN readers, but any large company is likely constantly violating at least dozens, if not hundreds or thousands of regulations. Ask any corporate lawyer how you could avoid violating any regulation or law, and they will just give you a blank stare, or tell you it's impossible.

Very few laws have as many teeth in them for corporations as the GDPR does, it was designed with that particular aspect in mind. The EU bureaucrats have a personal stake in the outcome so that definitely helped to focus them.

I suppose you're right that companies should weigh their efforts in favor of complying with laws that bureaucrats are personally invested in. That said, I see this as a rather sad state of affairs.

Re: Germany fines H&M 35 million euros for data protection breaches

#44

Is it related to GDPR? At least the linked article doesn't mention it is. It looks like it is related to health data which is anyways illegal in most countries before GDPR.

"The fashion company with seat in Hamburg operates a service center in Nuremberg. Here, according to the findings of the Hamburg data protection officer, since at least 2014 private life circumstances of some of the employees have been comprehensively recorded and this information stored on a network drive. For example, the company conducted a "Welcome Back Talk" after employees returned to work after vacation or illness. The information that became known in this context - including information on the symptoms of illness and diagnoses of the employees - was recorded and stored. In addition, according to the Hamburg data protection authority, some supervisors also used the "Flurfunk" [meaning to hear something through the grapevine] to acquire a broad knowledge of individual employees, for example about family problems and religious beliefs. The information stored on the network drive was accessible to up to 50 managers of the company and was used, among other things, to evaluate the work performance of the employees and to make employment decisions.The data collection became known due to a technical configuration error in October 2019, according to which the data stored on the network drive was accessible company-wide for several hours. After the violation became known, the management apologized to the employees and offered monetary compensation. In addition, also further protective measures were introduced together with the data protection authority. [Note: Concrete legal basis of the fine not yet published - we assume this will mainly be Art. 5 and 6 GDPR]"

From the GDPR enforcement tracker.

Re: Germany fines H&M 35 million euros for data protection breaches

#47
post #35

Earlier quoted context omitted.

And the first of these exceptions is employment. That's quite reasonable because an employer keeps track of employees' absence for health reasons and will come to know some details in case of serious health problems/long absences. In this case they collected data after sick leaves, but (a) it seems they collected quite a bit of information regarding private life, perhaps more than could be deemed reasonable and (b) t…

an employer keeps track of employees' absence for health reasons That works differently in Europe. Employee health is a personal matter, and the employer does not get automatic access to that information. The employer can get a dedicated physician (affiliated but not employed by your employer) to assess your illness and guide you back to work, but even then the physician's records are off-limits to the employer. Spea…

> Speaking only for NL here, but I think the regulation is the same EU-wide.

In Germany the doctor only certifies that the employee is unable to carry out their work duties. The reason why is a secret between doctor and patient.

In Finland the doctor sends the ICD code to the employer.

So there is no EU-wide regulation. IIRC GDPR says that data is protected unless the exchange is regulated by a law or the subject has consented. (It's been a while I read it...) Laws are national.

Re: Germany fines H&M 35 million euros for data protection breaches

#48

Earlier quoted context omitted.

I think that's actually excellent. It shows that any kind of data collection is subject to the GDPR. This is something I've been warning companies about for a while now, they believe - quite erroneously - that as long as the system isn't automated that they are free and clear but the GDPR doesn't say anything about automation. So even if it is informal and even if you use stone tablets you are still subject to the la…

Well, strictly speaking, automation is a key factor. If it's automated, it's always GDPR. If it's not automated, it's GDPR under the condition that the data is part of a filing system. So if you order your stone tablets alphabetically by their title, it's GDPR, but jumble a sufficiently large pile of stone tablets and you're in the clear. In practice, this means that if you have a warehouse full of unordered boxes fu…

If that was true, it would be hilarious. The law does only apply if the defendant keeps his records in order :D. Normally, you get fined extra. Like you get fined for not keeping order, then for being late at producing said document (first you need to find it in your mess after all) and then fined for the document being what it is.

Re: Germany fines H&M 35 million euros for data protection breaches

#49
post #24

Earlier quoted context omitted.

You are most certainly right. But I think parent's point was that informal data gathering on mid manager level is a difficult thing to protect yourself from, as a large corporation. Any clueless manager can open an Excel file and type in personal information about their reports. Training and policies can help, but not completely prevent. When you build larger software systems you can have audit processes in place etc…

In this case they seem to have collected 60 GB data shared among 50 managers. It's interesting that no one raised an issue. It only became known after the network share was made visible to more people by mistake.

That clearly rises well above the level of “someone entered personal data into a spreadsheet”. At that level it is absolutely a negligent failure of the company to A. train and educate its managers, and B. audit operations to shut down activities like this.

Re: Germany fines H&M 35 million euros for data protection breaches

#50
post #16

Earlier quoted context omitted.

Well, no, if the company doesn't stop and doesn't seem to stop the fines can be high enough to sink a company and I don't doubt that if it comes to it, the agencies involved are ready to sink a company over data protection.

Trust me on this: no company is going to take a 3% hit to their net profits after taxes as a happy event. The agencies are quite ready but it would take a pretty stupid management to step in front of that train willingly. Note that H&M was adamant that they would cease to collect this data (as they should be). The only case I know of where there was a multiple-repeat-offender the eventual fine was 250K for a violatio…

A hit of 3% of their revenue on their profits. If your profit margin is 10% then that turns into a 30% profit hit and the board will be unhappy.
Post reply on HN