
BERLIN (Reuters) - Germany’s data protection and privacy commissioner said on Thursday it was imposing a hefty fine on giant clothing following an investigation earlier this year into systematic surveillance of employees in Germany. The fine is 35.3 million euros ($41 million).
Hamburg's data protection commissioner had said in a statement that the Swedish company was collecting personal information about its employees, which could be considered harmless but could even include details about family matters and religious beliefs.
The information was stored on a network that was accessible to up to 50 administrators. This data essentially created a detailed profile of the employees.
According to the data, Johannes Caspar, “the collection of information about their private lives and the recording of their activities led to a particularly intensive violation of workers’ civil rights.”

As mentioned above, the commissioner has been aware of the incident since the beginning of the year and has launched an investigation. The breach was discovered when employee data became visible to everyone in the H&M network
H&M said in a statement that the practices in Nuremberg (where the breach occurred) did not correspond to the company's guidelines. However, it said it takes full responsibility for the incident and has already apologized to the employees affected. The company said it would review the fine issued.
Casper is pleased with H&M’s decision to compensate employees at the Nuremberg service center. Also, according to Security Week, the company has taken steps to prevent future privacy breaches. H&M “shows its intention to give employees the respect and appreciation they deserve for their daily work at the company.”
