Search

How can we help?

Icon

£32.1m fine for employee surveillance

Following an investigation by the Data Protection Authority of Hamburg, fashion retailer H&M has been fined the equivalent of £32.1m for surveillance illegally monitoring of its employees.

The German data protection watchdog discovered that the company was keeping excessive records on hundreds of employees based in their Nuremburg service centre. This included details of holidays, medical symptoms and diagnoses, family issues and religious beliefs. It has also been alleged that these intimate and highly sensitive details were, in some instances, being used by management to evaluate work performance.

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation. Last year, Google was fined by the French data protection regulator for breaching GDPR, Marriot International were fined by our own Information Commissioner’s Office for insufficient data-security systems, and PWC were fined by the Greek data protection authority for unlawful processing of employee data. GDPR is now well into its second year yet many companies continue to give inappropriate weight to data protection and underestimate the significance of the information they process.

Jacob Montague

Senior Solicitor

View profile

+44 118 960 4613

In the last 12 months there have been a string of high-profile fines against companies for breaches of the legislation.

The fine should come as a stark warning. Data Protection regulators are becoming more active and aggressive in their stance against data breaches. Head of the HmbBfDI, the German regulator, hopes that the size of the fine will “scare off companies from violating people’s privacy”.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Jacob Montague

Senior Solicitor

View profile

+44 118 960 4613

About this article

Read, listen and watch our latest insights

art
  • 04 July 2025
  • Employment

Update: The ‘Employment Rights Bill Implementation Roadmap’

The Employment Rights Bill is a draft law which is poised to expand the rights of employees, signifying a major overhaul in employment law. The ERB has already been passed by the House of Commons and is currently at the ‘Report Stage’ in the House of Lords.

Pub
  • 03 July 2025
  • Corporate and M&A

Get your tech business market ready for sale

In our latest podcast, join Stuart Mullins and Nicky Goringe Larkin to learn how to maximise your tech business value and get your tech business market ready for sale.

art
  • 03 July 2025
  • Immigration

Major Changes to the Immigration Rules from 1 July 2025: What Employers and Visa Holders Need to Know

We outline the key updates, how they affect employers and visa holders—particularly those on the Skilled Worker and Global Business Mobility (GBM) routes—and how our team can assist you in staying compliant and ahead of policy changes.

art
  • 02 July 2025
  • Employment

Day One Rights: What the New UK Employment Bill Means for You and Your Workplace

Let’s unpack what’s changing in the UK Employments Rights Bill, and why it matters, and what both employees and employers should expect.

art
  • 01 July 2025
  • Privacy and Data Protection

Data protection compliance: tricky issues for employers

This article highlights key issues organisations may face when processing personal data and stresses the importance of a proactive approach. It also outlines tailored training packages to support compliance and build internal expertise.

art
  • 26 June 2025
  • Employment

A shift in EHRC guidance on single sex spaces in the workplace

In a recent significant shift, the Equality and Human Rights Commission (“the EHRC”) has quietly amended its guidance on single sex spaces in the workplace.