Continue reading on DataGuidance with:
Free Member
Limited ArticlesCreate an account to continue accessing select articles, resources, and guidance notes.
Already have an account? Log in
Italy: Garante imposes €50,000 fine on H&M for unlawfully processing personal data via video surveillance systems
On May 26, 2023, the Italian data protection authority (Garante) announced in its monthly newsletter, issued on the same date, its decision No. 58, in which it imposed a fine of €50,000 on H&M Hennes & Mauritz s.r.l. (H&M), for violation of Articles 5(1)(a) and 88 of the General Data Protection Regulation (GDPR) and Article 114 of the Personal Data Protection Code, Containing Provisions to Adapt the National Legislation to the GDPR (the Code), following the receipt of a report from a trade union.
Background to the decision
The report related to the allegedly unlawful use of video surveillance systems by H&M in its stores. The investigation carried out by the Garante revealed that all H&M's shops were equipped with at least three video cameras, up to a number of 27, active 24 hours a day, seven days a week, in the areas reserved for workers. The Garante stated that H&M justified the installation of the equipment with the need to defend against theft and to ensure the safety of employees and corporate assets.
Findings of the Garante
Further to the above, at the end of its investigation, the Garante found that such installation of video surveillance systems did not comply with the applicable legislation on remote monitoring. On this, the Garante noted that it is not enough to simply inform the interested parties of the usage of video surveillance systems via information notices posted in the areas adjacent to those subject to monitoring. The applicable legislation requires that the installation of video surveillance systems cannot take place in the absence of an agreement with the workers' representatives or authorization from the Labor Inspectorate. As such, the Garante held that H&M processed data in violation of the aforementioned articles, and in particular of the principle of lawfulness under Article 5 of the GDPR, on the basis of which the processing can be considered lawful only if it complies with all applicable sectoral regulations.
Outcomes
In light of the aforementioned violations, the Garante imposed a fine of €50,000 on H&M.
You can read the newsletter here and the decision here, both only available in Italian.