Blog » HOW NOT TO USE CCTV AT WORKPLACE? – 15 MILLION FINE FOR AUCHAN HUNGARY
HOW NOT TO USE CCTV AT WORKPLACE? – 15 MILLION FINE FOR AUCHAN HUNGARY
09 April 2018
Auchan Hungary started this year with a HUF 15 Million data breach fine for operating CCTV at workplace in breach of data protection principles. Given that CCTV lies in the heart of GDPR entering into force in May 2018, it is worth to learn from the Auchan case so that you can avoid a similar penalty in Hungary.
A freely-given consent?
One of the key-questions of the Auchan case was the CCTV monitoring of employees. This was based on the written consent of employees, that the latter gave when signing the labour contract.
In this regard the Data Protection Authority stressed that those clauses of the labour contract in which the employee gave his consent to the monitoring by CCTV can not be considered as valid under data protection laws.
In the world of work we can not speak about “freely-given” consent, because it is called into question by the hierarchy between the parties. In addition, the employee can not withdraw unilaterally his consent, which is doubtful from data protection point of view.
Based on the above, instead employee consent, Auchan should have based the legal basis of CCTV monitoring of employees on a “legitimate interest assessment test”. In the test he should have assessed employee’s interest on the one hand and the employer’s on the other, and then decide, whether CCTV is necessary, and to what extent.
The Data Protection Authority has also established that the setting of cameras was not appropriate, since those were “zoomed” to one employee. This is only possible in very limited circumstances, when it is necessary by reason of a direct and real danger to life or health of the employee or to property security.
The eventual irregular handling of money by the cashier or mixing up items by the colleague responsible for vending is only a potential risk to property security, which can not justify the direct monitoring of the employee all day. Instead, it is better to direct the camera to the asset to be defended.
Lack of notification
Last but not least, the Data Protection Authority put Auchan in the wrong for informing only in a general manner the employees about the use of CCTV, but not providing detailed information about the following:
- the setting of the cameras, the territory monitored, and the goal of monitoring;
- whether the monitoring is recoded or not by the employer;
- the data security measures executed;
- about the fact that who, when, how long, and for what purposes can watch the recordings;
- finally, about the rights of data subjects.
About the amount of penalty
When determining the amount of the penalty the Data Protection Authority has taken into account that Auchan used the CCTV illegally in all of its 20 shopping malls, thereby more than 6.500 employees were concerned, let alone customers.
The significant market role of Auchan and the fact that it breached more data protection principles were also aggravating factors.
When using CCTV at workplace, you have to carefully comply with data protection laws.
It is not sufficient if you do the paperwork by get labour contract signed by the employee in which he gives his consent to monitoring. Instead of this, you should rely on your legitimate interest and conduct a legitimate interest assessment test which will be the basis of using CCTV. In addition, the proper setting of cameras and the notification of employees is crucial if you want to avoid a huge data protection fine in Hungary
HOW NOT TO CONCLUDE AN INTERNATIONAL SALES CONTRACT? – OUR CLIENT’S CASE IN FRONT OF THE CURIA
Can the raw material supplier be liable for defects, if the specification is incomplete, but he knows what the end-product is? Who has to prove this under the Vienna Convention on the International sale of goods? These questions were decided by the Hungarian Supreme Court in the case of our Italian client, against a Hungarian company.Read more »
GDPR PENALTY FORECAST – OUR PRESENTATION AT BELGABIZ
How often did the Hungarian Data Protection Authority impose penalties in the last five years? What was the average amount of penalties? Will be there any change after 25th May 2018, when the GDPR comes into force? We addressed these questions in our presentation made at BELGABIZ.Read more »
DATA BREACH – NOTIFY OR NOT, THAT IS THE QUESTION
If data leakage, data theft or other breach happens at your company and it is likely to result in a risk to the data subjects’ rights, you have to report it to the supervisory authority. If this risk is likely to be high you shall as well inform the affected persons. In this article we mention 5 things that you need to consider when you decide about whether you should notify the authority or the data subjects.Read more »