Blog » HOW NOT TO USE CCTV AT WORKPLACE? – 15 MILLION FINE FOR AUCHAN HUNGARY
HOW NOT TO USE CCTV AT WORKPLACE? – 15 MILLION FINE FOR AUCHAN HUNGARY
09 April 2018
Auchan Hungary started this year with a HUF 15 Million data breach fine for operating CCTV at workplace in breach of data protection principles. Given that CCTV lies in the heart of GDPR entering into force in May 2018, it is worth to learn from the Auchan case so that you can avoid a similar penalty in Hungary.
A freely-given consent?
One of the key-questions of the Auchan case was the CCTV monitoring of employees. This was based on the written consent of employees, that the latter gave when signing the labour contract.
In this regard the Data Protection Authority stressed that those clauses of the labour contract in which the employee gave his consent to the monitoring by CCTV can not be considered as valid under data protection laws.
In the world of work we can not speak about “freely-given” consent, because it is called into question by the hierarchy between the parties. In addition, the employee can not withdraw unilaterally his consent, which is doubtful from data protection point of view.
Based on the above, instead employee consent, Auchan should have based the legal basis of CCTV monitoring of employees on a “legitimate interest assessment test”. In the test he should have assessed employee’s interest on the one hand and the employer’s on the other, and then decide, whether CCTV is necessary, and to what extent.
The Data Protection Authority has also established that the setting of cameras was not appropriate, since those were “zoomed” to one employee. This is only possible in very limited circumstances, when it is necessary by reason of a direct and real danger to life or health of the employee or to property security.
The eventual irregular handling of money by the cashier or mixing up items by the colleague responsible for vending is only a potential risk to property security, which can not justify the direct monitoring of the employee all day. Instead, it is better to direct the camera to the asset to be defended.
Lack of notification
Last but not least, the Data Protection Authority put Auchan in the wrong for informing only in a general manner the employees about the use of CCTV, but not providing detailed information about the following:
- the setting of the cameras, the territory monitored, and the goal of monitoring;
- whether the monitoring is recoded or not by the employer;
- the data security measures executed;
- about the fact that who, when, how long, and for what purposes can watch the recordings;
- finally, about the rights of data subjects.
About the amount of penalty
When determining the amount of the penalty the Data Protection Authority has taken into account that Auchan used the CCTV illegally in all of its 20 shopping malls, thereby more than 6.500 employees were concerned, let alone customers.
The significant market role of Auchan and the fact that it breached more data protection principles were also aggravating factors.
When using CCTV at workplace, you have to carefully comply with data protection laws.
It is not sufficient if you do the paperwork by get labour contract signed by the employee in which he gives his consent to monitoring. Instead of this, you should rely on your legitimate interest and conduct a legitimate interest assessment test which will be the basis of using CCTV. In addition, the proper setting of cameras and the notification of employees is crucial if you want to avoid a huge data protection fine in Hungary
WHY SHOULD YOU ENTRUST A LAWYER WITH YOUR GDPR COMPLIANCE PROJECT?
In the last months preceding the entering into force of GDPR, the market was inundated with various service providers promising data protection compliance: data protection experts, counsels, IT experts, etc. Besides these providers, lawyers and law firms, experienced in the field of data protection also provide GDPR compliance services. We summarize the reason why you should involve them in your GDPR compliance project.Read more »
I GET “ONLY” STATISTICAL DATA FROM FACEBOOK – AM I DATA CONTROLLER UNDER GDPR?
Besides having a website, vast majority of businesses have company pages on the social networks like Facebook, Linkedin, etc. Do you become a data controller, being primarily responsible for data processing, if you get “only” statistical information of your visitors? The Court of Justice of the European Union addressed this question in its recent ruling.Read more »
HOW NOT TO DO DIRECT MARKETING? LEARN FROM THE MISTAKES OF TELEKOM!
In the recent past the Hungarian Data Protection Authority imposed a fine of 2 Million Hungarian Forints against Telekom, a major Hungarian telecommunication company, because of his unlawful direct marketing activity. Although the decision has been made before the entering into force of the GDPR, it is worth to examine the mistakes of Telekom. Indeed, the fine would have been much higher if it was imposed after the GDPR.Read more »