Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2014–2019

H&M logged staff's diagnoses and religious beliefs after every absence — fined €35.3M

Managers recorded staff's illnesses, family problems and religion in "welcome back" chats. A server error exposed the files and triggered a record GDPR fine.

H&M · 2020-10-01

What happened

Since at least 2014, managers at H&M's service center in Nuremberg, Germany held informal "Welcome Back Talks" with employees returning from any absence — vacation, sick leave, or otherwise — and recorded far more than the conversation required. Notes captured employees' illness symptoms and diagnoses, family conflicts, religious beliefs and other private details having nothing to do with work performance, and the files were accessible to as many as 50 managers across the company.

The practice ran for years without discovery until October 2019, when a configuration error exposed the entire contents of the shared network drive company-wide for several hours. Employees who saw files about colleagues alerted the works council, and press reports followed, which brought the matter to the Hamburg data protection authority.

Investigators seized and reviewed roughly 60 gigabytes of records covering several hundred employees. In October 2020 the Hamburg Commissioner fined H&M €35,258,707.95 — at the time the largest GDPR fine issued by a German authority — for systematically collecting and retaining sensitive personal data about staff with no legal basis and no need tied to any business purpose.

Why it happened

  • Managers treated informal return-to-work conversations as an opportunity to gather personal information with no connection to job performance or legitimate business need.
  • The records were stored on a shared drive accessible to dozens of managers company-wide, rather than restricted to the individual conducting each conversation.
  • No internal check caught years of accumulating sensitive data — health diagnoses, religion, family matters — despite GDPR's specific rules on that category of information.
  • The practice only surfaced because of an unrelated technical error that exposed the files, not through any internal audit or employee complaint process working as intended.
What it cost€35.3M finecostly

The lesson

Informal data collection accumulates the same legal exposure as a formal database — a filing habit nobody reviews is still a system, and one your own staff can be harmed by if it leaks.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →