The French data protection authority, the CNIL, has issued a €32 million fine to Amazon France Logistique for implementing an overly intrusive employee monitoring system, which constitutes a data minimisation violation under Article 5(1)(c) of the EU General Data Protection Regulation (GDPR).
Following an investigation, the CNIL found that the system for monitoring employee activity and performance was excessive, leading to the implementation of indicators measuring the inactivity time of employee scanners and the speed of scanner use when storing items. The CNIL also deemed it excessive to keep all the data collected by the system and the resulting employee statistical indicators for 31 days. However, the CNIL acknowledged that the scanner system was justified for the management of Amazon's activity, considering the company's strong constraints and high-performance objectives.
Amazon was also penalised for video surveillance without proper information and security measures, an infringement of Articles 12-13 and 32 of the GDPR.
In a statement to BBC News, an Amazon spokesperson said: "We strongly disagree with the CNIL's conclusions which are factually incorrect and we reserve the right to file an appeal."
(Translate to English: Google Chrome, Mozilla Firefox, or Microsoft Edge)
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 4,350 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.