{"id":16819,"date":"2020-10-13T20:19:00","date_gmt":"2020-10-13T20:19:00","guid":{"rendered":"https:\/\/businessadapter.es\/hm-penalized-for-data-protection\/"},"modified":"2024-12-11T10:49:27","modified_gmt":"2024-12-11T10:49:27","slug":"hm-penalized-for-data-protection","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/hm-penalized-for-data-protection\/","title":{"rendered":"H&amp;M penalized for data protection"},"content":{"rendered":"\n<h2 style=\"text-align: justify;\"><strong>H&amp;M penalized for data protection<\/strong><\/h2>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www2.hm.com\/es_es\/index.html\" target=\"_blank\" rel=\"noopener\">H&amp;M<\/a> fined \u20ac35 million for <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/proteccion-datos-valencia\">data protection<\/a> breaches.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Hamburg State Commissioner for Data Protection<\/strong><\/h3>\n<p style=\"text-align: justify;\">The State Commissioner for Data Protection in Hamburg (Germany)<a href=\"https:\/\/www2.hm.com\/es_es\/service-clients\/shopping-at-hm\/store-locator.html\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\" wp-image-5719 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/10\/Captura-de-pantalla-2020-10-13-220846-300x214.png\" alt=\"\" width=\"485\" height=\"346\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/10\/Captura-de-pantalla-2020-10-13-220846-300x214.png 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/10\/Captura-de-pantalla-2020-10-13-220846-350x250.png 350w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/10\/Captura-de-pantalla-2020-10-13-220846-255x182.png 255w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/10\/Captura-de-pantalla-2020-10-13-220846.png 727w\" sizes=\"(max-width: 485px) 100vw, 485px\" \/><\/a> penalizes the Swedish multinational Hennes &amp; Mauritz Ab for obtaining personal data of employees with unorthodox tactics, as in some cases private conversations became a mine of information.<\/p>\n<p style=\"text-align: justify;\">This followed an investigation into the events at a Swedish company&#8217;s Nuremberg care center, where it was discovered that there were employee databases containing a multitude of personal data about employees, including those considered sensitive or special category data, such as those related to health.<\/p>\n<h3 style=\"text-align: justify;\"><strong>H&amp;M takes data protection seriously<\/strong><\/h3>\n<p style=\"text-align: justify;\">H&amp;M seems to understand that the problem lay in the lack of knowledge of data protection on the part of employees, forcing itself to implement new internal measures for compliance with the General Data Protection Regulation<a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">(GDPR<\/a>), such as <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/formacion-proteccion-datos-valencia\">data protection training<\/a> for its employees, <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/auditoria-proteccion-datos-valencia\">audits<\/a>, as well as security measures at the IT level.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Data protection consultations in Valencia<\/strong><\/h3>\n<p style=\"text-align: justify;\">Faced with this case, our clients in <a href=\"https:\/\/businessadapter.es\/en\/who-we-are\/\">Valencia<\/a> have expressed some doubts about whether or not they can store personal data of their employees.<\/p>\n<p style=\"text-align: justify;\">The answer is yes, <u>but it is essential to<\/u> rely on a specialized data protection consultancy for proper advice and design of customized measures. Remember that sanctions can be devastating. <\/p>\n<p style=\"text-align: justify;\">Some of the measures to be taken:<\/p>\n<p style=\"text-align: justify;\"><strong>&#8212;<\/strong> Draft specific clauses to obtain the express consent of individuals when their personal data is collected, in accordance with article 6.1 of the <a href=\"https:\/\/www.boe.es\/diario_boe\/txt.php?id=BOE-A-2018-16673\" target=\"_blank\" rel=\"noopener\">LOPD<\/a> GDD.<\/p>\n<p style=\"text-align: justify;\"><strong>&#8212;<\/strong> To elaborate an Impact Assessment<a href=\"https:\/\/businessadapter.es\/evaluacion-de-impacto-de-proteccion-de-datos-eipd-valencia\/\">(EIPD<\/a>) if processing data considered special category data according to the provisions of Article 9.1 of the GDPR,<\/p>\n<p style=\"text-align: justify;\">&#8212; Design technical and organizational measures <strong> to<\/strong> prevent possible leakage, loss or alteration of information, based on Article 28.1 of the LOPD-GDD.<\/p>\n<p style=\"text-align: justify;\">&#8212; Develop an employee <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/formacion-proteccion-datos-valencia\">training<\/a> policy<strong>,<\/strong> as it is extremely important to have basic knowledge (at least) on how to process personal data, to avoid misuse of personal data, based on Article 39.1 b) of the GDPR.<\/p>\n<p style=\"text-align: justify;\">&#8212; Always have at hand all the documentation that supports the due compliance with data protection obligations<strong>,<\/strong> as a result of the principle of proactive responsibility that prevails with this new regulation, and that falls directly on the Data Controller, based on Article 5.2 of the RGPD.<\/p>\n<h3 style=\"text-align: justify;\"><strong>2019 a black year  <\/strong><\/h3>\n<p style=\"text-align: justify;\">2019 was a dismal year in terms of data protection, as large fines were imposed on companies that did not respect the provisions of the legal framework for data protection.<\/p>\n<p style=\"text-align: justify;\">Some of these cases were that of Google, with a fine of 50 million euros for not complying with the right to information regarding the advertising use of users&#8217; personal data.<\/p>\n<p style=\"text-align: justify;\">Another was British Airways, where the origin of its fine was the failure to implement sufficient security measures, with a proposed fine of 182 million pounds. This is not the only shocking case in the United Kingdom, as the Marriott hotel chain also suffered the consequences of a massive information leak, with a proposed penalty of 110 million euros.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Get expert advice and avoid penalties<\/strong><\/h3>\n<p style=\"text-align: justify;\">Put yourself in the hands of a good <strong><a href=\"https:\/\/businessadapter.es\/en\/\">Data Protection Company Valencia<\/a> \/ <a href=\"https:\/\/businessadapter.es\/en\/\">LOPD Valencia<\/a><\/strong>, for a good advice and avoid millionaire fines.<\/p>\n<p> <\/p>\n<p style=\"text-align: center;\"><span style=\"display: inline !important; float: none; background-color: transparent; color: #333333; cursor: text; font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;\">[su_button url=&#8221;https:\/\/businessadapter.es\/contacto&#8221; target=&#8221;blank&#8221; background=&#8221;#f6f903&#8243; color=&#8221;#181818&#8243; size=&#8221;7&#8243; center=&#8221;yes&#8221; icon_color=&#8221;#000000&#8243;]WE HELP YOU[\/su_button]<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>H&amp;M penalized for data protection H&amp;M fined \u20ac35 million for data protection breaches. Hamburg State Commissioner for Data Protection The [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[],"class_list":["post-16819","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16819"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16819\/revisions"}],"predecessor-version":[{"id":16821,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16819\/revisions\/16821"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}