← All enforcement actions
GDPREmployee MonitoringRetail / HR

H&M€35.3M GDPR fine (2020)

Secret employee profiling — managers logged personal details after 1:1s

Penalty
€35.3M
Regulator
Hamburg DPA (Germany)
Jurisdiction
European Union

What happened

Hamburg's data-protection authority fined H&M €35.3M after a misconfigured network drive exposed years of detailed records on hundreds of Nuremberg service-center employees — including health conditions, family issues, religion, and vacation experiences captured by managers after 'welcome-back' chats.

Root cause

What every team should do

  1. Employee monitoring requires explicit, narrow legal basis and documented DPIA
  2. Sensitive-category data (health, religion) needs Art. 9 condition + heightened safeguards
  3. Audit fileshare ACLs quarterly — exposed shares are the most common GDPR breach vector
Source: Hamburg DPA press release (Oct 1, 2020).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Meta Platforms
€1.2B
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
Amazon Europe Core
€746M
Largest GDPR fine at the time — behavioural ad targeting without valid consent
TikTok
€345M
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
Meta / Instagram
€405M
Children's business-account email + phone exposed publicly