H&M – €50,000 Fine (Italy, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
H&M was fined for using video surveillance in their stores without properly informing employees. The Italian data protection authority found that the company did not follow rules about transparency and employee privacy. This case highlights the importance of clear communication when monitoring employees.
What happened
H&M used video surveillance in their stores and did not adequately inform employees about it.
Who was affected
Employees working at H&M stores who were monitored by the surveillance cameras.
What the authority found
The authority ruled that H&M violated GDPR rules by not being transparent about their video surveillance practices.
Why this matters
This ruling emphasizes that companies must be clear about monitoring practices to protect employee privacy. Other businesses should ensure they comply with transparency requirements when using surveillance.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Following a report by a trade union about video surveillance in multiple companies, in April 2022, the Italian Garante launched an investigation with the company H&M (controller) concerning the video surveillance systems in place at their registered office and in their stores. The investigation service raised multiple points, among others * that all the controller’s shops were equipped with surveillance cameras; * the video surveillance system was active 24 hours a day and that images were kept for 24 hours; * in some of the shops, cameras were placed at employees’ entrance and in other areas reserved to the employees; and * the processing concerned more than 500 employees. The controller argued that the employees were informed of the presence of the cameras through information notices. It relied on a security and protection purpose and referred to an authorization of processing that would have been issued by a territorial Labor Inspectorate. The controller also stated that only 543 employees out of a total of 4,300 were actually monitored and that the cameras were only monitoring an area of passage. The Garante assessed if the processing was lawful within the meaning of Article 5(1)(a) GDPR. According to Article 88 GDPR, the GDPR is applicable without prejudice to more protective national rules. In Italy, a national provision (Article 4 of the Law no. 300 of 1970) is more specific than the GDPR. It requires, in the context of an employment relationship, that the processing should be agreed upon in an agreement with the trade union representatives or authorized by the Labor Inspectorate. Contrary to the controller’s statement, in this case, the Garante found that no agreement nor authorization was in place. The Garante held the fact that the cameras only monitored passage areas is not relevant since the monitoring of video surveillance is subject to the full application of data protection provisions. It added that even if 543 out of a total of 4,300 were con
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for H&M in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
2 March 2023
Authority
Garante per la protezione dei dati personali
Fine Amount
€50,000
GDPRhub ID
gdprhub-6032About this data
Cite as: Cookie Fines. H&M - Italy (2023). Retrieved from cookiefines.eu
Last updated: