Search

How can we help?

Icon

£32.1m fine for employee surveillance

Following an investigation by the Data Protection Authority of Hamburg, fashion retailer H&M has been fined the equivalent of £32.1m for surveillance illegally monitoring of its employees.

The German data protection watchdog discovered that the company was keeping excessive records on hundreds of employees based in their Nuremburg service centre. This included details of holidays, medical symptoms and diagnoses, family issues and religious beliefs. It has also been alleged that these intimate and highly sensitive details were, in some instances, being used by management to evaluate work performance.

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation. Last year, Google was fined by the French data protection regulator for breaching GDPR, Marriot International were fined by our own Information Commissioner’s Office for insufficient data-security systems, and PWC were fined by the Greek data protection authority for unlawful processing of employee data. GDPR is now well into its second year yet many companies continue to give inappropriate weight to data protection and underestimate the significance of the information they process.

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation.

The fine should come as a stark warning. Data Protection regulators are becoming more active and aggressive in their stance against data breaches. Head of the HmbBfDI, the German regulator, hopes that the size of the fine will “scare off companies from violating people’s privacy”.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 06 August 2026
  • Privacy and Data Protection

The rise of the AI-powered individual: Is your business ready?

Artificial intelligence is changing the data protection landscape, but perhaps not in the way many organisations expected. Much of the discussion has centred on businesses adopting AI and ensuring they comply with the UK GDPR.

Pub
  • 06 August 2026
  • Employment

Employment law changes in 2026: What you need to know

With ongoing changes to UK employment law, staying updated is more challenging than ever. Join Monica Atwal and Harry Berryman for a live webinar covering 2026 HR changes and key employment law updates on Thursday 17 September.

Pub
  • 04 August 2026
  • Employment

From Opportunity to Employment: Building Inclusive Workplaces Together | Hosted by Breakthrough Supported Employment

Join Breakthrough Supported Employment for a live seminar on building inclusive workplaces at Malmaison Reading. Clarkslegal’s Lucy White will speak alongside industry experts, sharing insights on fostering diversity and creating equitable opportunities.

art
  • 04 August 2026
  • Litigation and dispute resolution

Advantages of arbitration over litigation

Arbitration is a method of resolving disputes outside the court system, with the dispute being determined by an independent arbitrator or tribunal rather than a judge. Whether a dispute is best resolved through arbitration or litigation will ultimately depend on the particular facts and circumstances of the case.

art
  • 04 August 2026
  • Immigration

Home Office revokes EU Settlement Scheme Status ‘Granted in Error’ – What does This Mean for EU Citizens?

Recent reports that the Home Office has begun revoking the immigration status of some EU nationals on the basis that it was originally “granted in error” have caused understandable concern among immigration practitioners and those with status under the EU Settlement Scheme (EUSS).

art
  • 03 August 2026
  • Corporate and M&A

Shareholders’ Agreements FAQ Guide – SHA Series Part 1 of 5

Shareholders’ agreements are a crucial but often overlooked tool for companies with multiple owners. While many rely solely on standard articles of association, this can leave significant gaps in governance and protection.