H&M's announcement of up to 250 UK office redundancies on 7 August 2026 has dominated retail headlines. But while employment lawyers fielded calls from anxious staff at Oxford Street, Regent Street, and stores across Manchester, Cardiff, Glasgow, and Birmingham, a quieter story was building for the millions of British consumers on the other side of the H&M brand relationship: the company's H&M Club loyalty app has spent years accumulating detailed digital profiles of UK shoppers — and a landmark new British data law has just materially changed the rules of that relationship.
H&M's Digital Restructuring Goes Beyond Headcount
The job cuts are part of a wider strategic pivot. H&M Group has been consolidating its European operations throughout 2026, eliminating 250 positions at its Netherlands customer service centre in June, shutting a distribution centre in Belgium with 440 redundancies, and now notifying 250 UK office employees of potential roles at risk. The stated rationale — "overlapping responsibilities and decision-making processes disconnected from customers" — points unmistakably toward greater automation and digital centralisation.
That shift concentrates more of H&M's UK business inside its app and e-commerce platform. H&M's digital operations now account for over 30% of global sales, and the company has explicitly signalled that growth will come through personalisation — meaning algorithmic systems that analyse customer behaviour to serve targeted offers, recommend products, and adjust the shopping experience in real time.
The engine behind that personalisation is your data.
What H&M Club Knows About You
H&M's UK privacy notice is candid about the scope of data collection. When you join H&M Club — the loyalty programme available via app or in-store — H&M collects:
- Your full name, email address, date of birth, and telephone number
- Your complete purchase history, both in-store and online
- Your IP address and device identifiers
- Your browsing behaviour across the H&M website and app, including items viewed and time spent
- Stored payment information and transaction records
- Your geolocation data, if location services are enabled on your device
That data is used to "provide a tailor-made experience," which in practice means algorithmic profiling that determines which products appear in your app feed, which promotional emails arrive in your inbox, and — critics argue — potentially which price tiers you are shown for comparable items.
H&M also shares data with unnamed third-party partners to deliver loyalty programme benefits. The privacy notice does not identify these partners, which privacy specialists note sits in a grey zone under UK GDPR's transparency requirements.
The €35.3 Million Warning Signal
H&M's relationship with data regulation carries a notable precedent. In October 2020, the Hamburg Data Protection Authority imposed a €35.3 million fine — one of the largest GDPR penalties in European history — after H&M was found to have systematically recorded private information about employees without lawful basis. The violations included logging staff members' medical conditions, family situations, religious beliefs, and personal life events through an internal "people analytics" practice that operated for years before detection.
The fine applied to employee data, not customer data. But the underlying failure — data collected beyond necessity, retained beyond justification, processed without adequate transparency or lawful consent — is precisely the standard now applied to H&M's customer data practices under UK law. For the millions of UK shoppers with active H&M Club accounts, that history is worth understanding.
What the Data (Use and Access) Act 2025 Changes
The Data (Use and Access) Act 2025 — which began coming into force from February 2026 and reached its most significant consumer-facing provisions on 19 June 2026 — represents the most substantial overhaul of UK data protection law since the post-Brexit transition.
For H&M shoppers, three changes are particularly significant.
Mandatory complaint handling. Organisations that process UK residents' personal data — including H&M — must now have a formal complaints mechanism in place. H&M is required to acknowledge any data protection complaint within 30 days and provide a substantive outcome. This is no longer a discretionary best practice; it is a statutory obligation.
Stronger automated decision-making rights. H&M's personalisation algorithms — which decide what appears in your app and which offers you receive — now fall under tighter rules. If a material decision about your shopping experience is made solely by automated processing, you have a strengthened right to know, to contest, and to request human review of that decision.
Updated tracking consent rules. The Act tightens the framework for consent to online behavioural tracking, making it harder for retailers to bury opt-out mechanisms in lengthy privacy notices or treat passive browsing as implied consent to profiling.
Enforcement is handled by the Information Commissioner's Office (ICO), whose powers have been expanded under the Act. The ICO's official guidance on the Data (Use and Access) Act confirms that the maximum fine is now £17.5 million or 4% of global annual turnover — whichever is higher. For H&M Group, with global revenues of approximately SEK 236 billion (around £17 billion) in 2025, a worst-case penalty could approach £680 million.
What Actually Changes for an H&M Shopper: A Concrete Scenario
Consider a specific situation. Priya is a 33-year-old secondary school teacher in Birmingham who joined H&M Club in 2020. By August 2026, H&M holds six years of her shopping data: 127 purchase transactions, 640 browsing sessions on the H&M app, stored payment card details linked to two bank accounts, and geolocation records from nine occasions when she used the app near an H&M store.
In July 2026, Priya notices that her H&M app has stopped surfacing sale items — which she had reliably browsed and purchased — and is now predominantly showing full-price "premium" ranges. She suspects the recommendation algorithm has reclassified her based on a recent higher-value purchase and is now targeting her differently.
Before 19 June 2026, Priya's practical options were limited. She could submit a Subject Access Request under UK GDPR, but H&M faced no statutory deadline on handling a related complaint, and challenging an algorithmic recommendation required navigating a less clearly defined process.
After 19 June 2026, the picture changes in three concrete ways:
- H&M must acknowledge Priya's complaint within 30 days and provide a substantive outcome — failure to do so is itself an ICO-reportable breach
- If H&M's system made the recommendation shift based solely on automated profiling, Priya can invoke her right to human review of that automated decision — H&M cannot refuse
- If H&M's response is inadequate or incomplete, Priya can escalate to the ICO, which now has the authority to investigate and fine H&M up to 4% of its global revenues, a figure in the hundreds of millions of pounds
An IT consultant or data protection specialist can help Priya draft a Subject Access Request that compels H&M to disclose the full extent of her data — including third-party recipients — and assess whether any processing step falls outside the lawful bases H&M has disclosed in its UK privacy notice. Given the complexity of H&M's loyalty programme architecture and its history of data violations, professional guidance is not excessive caution — it is informed risk management.
Your Rights as an H&M Club Member in 2026
Under UK GDPR and the Data (Use and Access) Act 2025, every H&M Club member holds six enforceable rights:
- Right of access — Request a copy of all personal data H&M holds on you. H&M must respond within one calendar month, free of charge, via its My Privacy Portal at privacy.hmgroup.com.
- Right to rectification — Require H&M to correct inaccurate or incomplete data.
- Right to erasure — Request full deletion. H&M's own UK privacy notice confirms that closing your H&M Club account triggers deletion of your associated personal data.
- Right to restriction — Instruct H&M to pause processing your data while accuracy is being disputed.
- Right to data portability — Obtain your data in a structured, machine-readable format for transfer to another service.
- Right to object — Object to direct marketing based on profiling. H&M must stop immediately, with no justification required from you.
For shoppers concerned about how H&M's third-party data sharing operates — or who want to understand whether H&M's cookie practices comply with the updated consent rules — an IT specialist can decode the technical detail that privacy notices rarely make accessible. Our guide to cookie tracking and retail data rights covers how major retailers use behavioural data and what the new Act means in practice.
What to Do Now
If you are an H&M Club member, these five steps are worth taking before the end of August 2026:
- Review your consent settings. Log into your H&M account and audit which data uses you have authorised — particularly behavioural profiling for marketing. Withdraw consent for any use you no longer agree with.
- Submit a Subject Access Request. Use H&M's My Privacy Portal (privacy.hmgroup.com) or email privacy@hm.com. H&M must reply within 30 days.
- Check third-party sharing. When H&M's response arrives, look specifically for references to third-party partners. If the disclosure is vague or appears incomplete, note this for escalation.
- Delete your account if you no longer shop there. Account closure triggers data deletion under H&M's own stated policy — do not leave a data profile active unnecessarily.
- Escalate to the ICO if H&M's response is inadequate. The ICO accepts complaints at ico.org.uk and has actively signalled its intent to enforce the new Act. If you believe H&M has processed your data unlawfully, ExpertZoom connects you with verified IT and data protection consultants across the UK who can assess your case and guide your complaint.

Rhys Morgan