Search

How can we help?

Icon

£32.1m fine for employee surveillance

Following an investigation by the Data Protection Authority of Hamburg, fashion retailer H&M has been fined the equivalent of £32.1m for surveillance illegally monitoring of its employees.

The German data protection watchdog discovered that the company was keeping excessive records on hundreds of employees based in their Nuremburg service centre. This included details of holidays, medical symptoms and diagnoses, family issues and religious beliefs. It has also been alleged that these intimate and highly sensitive details were, in some instances, being used by management to evaluate work performance.

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation. Last year, Google was fined by the French data protection regulator for breaching GDPR, Marriot International were fined by our own Information Commissioner’s Office for insufficient data-security systems, and PWC were fined by the Greek data protection authority for unlawful processing of employee data. GDPR is now well into its second year yet many companies continue to give inappropriate weight to data protection and underestimate the significance of the information they process.

Jacob Montague

Senior Solicitor

View profile

+44 118 960 4613

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation.

The fine should come as a stark warning. Data Protection regulators are becoming more active and aggressive in their stance against data breaches. Head of the HmbBfDI, the German regulator, hopes that the size of the fine will “scare off companies from violating people’s privacy”.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Jacob Montague

Senior Solicitor

View profile

+44 118 960 4613

About this article

Read, listen and watch our latest insights

art
  • Employment
  • 11 June 2025

Employment Contracts and Specific Performance

‘Specific performance’ is a type of equitable remedy available, in some circumstances, and at the court’s discretion, for breach of contract; it entails an order by the court which legally compels a party to a contract to fulfil its contractual obligations.

art
  • Commercial Real Estate
  • 10 June 2025

Taking a commercial lease: The main points to negotiate when agreeing the Heads of Terms

What are the key areas tenants may want to pay particular attention to when agreeing to the Heads of Terms (HoTs).

art
  • Employment
  • 09 June 2025

Clarkslegal representing UK employers at the International Labour Conference

I am writing this from Geneva, where I once again have the honour of attending the International Labour Organisation’s International Labour Conference.

art
  • Immigration
  • 06 June 2025

MAC Report: Immigration Support for IT and Engineering Professionals

On 29 May 2025, the Migration Advisory Committee (MAC) published its much-anticipated review on the use of the UK immigration system by professionals in IT and engineering.

art
  • Corporate and M&A
  • 04 June 2025

Authorised Corporate Service Providers – what you need to know!

The Economic Crime and Corporate Transparency Act 2023 (ECCTA 2023) intends to enhance the transparency of corporate structures with an aim to reduce economic crime.

art
  • Privacy and Data Protection
  • 04 June 2025

Decrypting the ICO’s Draft Updated Guidance On Encryption

Where data breaches are easily achieved by human error, encryption not only offers a secure way of sending personal data, but also provides another layer of protection if a data breach was to occur.