Search

How can we help?

Icon

£32.1m fine for employee surveillance

Following an investigation by the Data Protection Authority of Hamburg, fashion retailer H&M has been fined the equivalent of £32.1m for surveillance illegally monitoring of its employees.

The German data protection watchdog discovered that the company was keeping excessive records on hundreds of employees based in their Nuremburg service centre. This included details of holidays, medical symptoms and diagnoses, family issues and religious beliefs. It has also been alleged that these intimate and highly sensitive details were, in some instances, being used by management to evaluate work performance.

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation. Last year, Google was fined by the French data protection regulator for breaching GDPR, Marriot International were fined by our own Information Commissioner’s Office for insufficient data-security systems, and PWC were fined by the Greek data protection authority for unlawful processing of employee data. GDPR is now well into its second year yet many companies continue to give inappropriate weight to data protection and underestimate the significance of the information they process.

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation.

The fine should come as a stark warning. Data Protection regulators are becoming more active and aggressive in their stance against data breaches. Head of the HmbBfDI, the German regulator, hopes that the size of the fine will “scare off companies from violating people’s privacy”.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 03 June 2026
  • Employment

Holiday Pay Record Keeping – What this new duty means for employers

The Employment Rights Act 2025 made certain changes to the rules around holiday records, which came into effect on 6th April 2026.

art
  • 03 June 2026
  • Corporate and M&A

Is your Company’s Register of Members accurate? The hidden risks of getting it wrong

Ensure your company’s Register of Members is accurate and compliant. Learn the legal risks, common mistakes, and how to protect your business from penalties.

art
  • 02 June 2026
  • Corporate and M&A

Clarkslegal welcomes leading Corporate Law expert Mark Ridley as Partner

Clarkslegal is delighted to announce the appointment of Mark Ridley as a new Partner in the Corporate and Commercial team.

art
  • 28 May 2026

Newly rebranded legal services group Orwins makes investment in Clarkslegal

Orwins, the law firm for ambitious businesses and high net worth individuals, has today, 27 May 2026, announced a significant investment in Reading-based commercial law firm Clarkslegal.

art
  • 20 May 2026
  • Immigration

AI vs Home Office approved Translations – why migrants are paying the price

AI is transforming almost every professional sector. Law firms now use AI-assisted drafting, businesses rely on automated translation software, and governments increasingly use digital systems for decision-making.

art
  • 20 May 2026
  • Employment

Trade Unions Right of Access from October – What you need to know

Under the Employment Rights Act 2025, independent Trade Unions (i.e. those with a certificate of independence) will have a right to access workplaces (physically and digitally) from October 2026.