¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
631.183.3
Berlin Commissioner for
Berlin, 5 August 2020 Data Protection and
Freedom of Information
535.1479 Friedrichstr. 219
10969 Berlin
A56ID 109234
CR 129278 Visitors’ entrance:
Puttkamer Str. 16-18
DD 129284
FD 142719 The building is fully accessible to
disabled members of the public.
Final Decision
Contact us
1. Facts concerning the data breach Phone: +49 (0)30 13889-0
Fax: +49 (0)30 215 50 50
- Controller: Applause GmbH Use our encrypted contact form
for registering data protection
- Incident: Publication of a document on the online platform Trello complaints:
- Date of occurrence: unknown www.datenschutz-berlin.de/be-
schwerde.html
- Date of acknowledgement of the incident: 16 January 2020
For all other enquiries, please
- EU/EEA Member States concerned, with the number of affected send an e-mail to:
data subjects: 257 affected data subjects in 27 Member States and [email protected]
Gibraltar Fingerprint of our
o Austria: 3 PGP-Key:
o Belgium: 2 D3C9 AEEA B403 7F96 7EF6
o Bulgaria: 2 C77F B607 1D0F B27C 29A7
o Croatia: 2
o Czech Republic: 5 Office hours
o Denmark: 3 Daily from 10 am to 3 pm,
o Finland: 8 Thursdays from 10 am to 6 pm
(or by appointment)
o France: 23
o Germany: 26
How to find us
o Gibraltar: 1
o Greece: 11 The underground line U6 to
Kochstraße / Bus number M29
o Hungary: 2 and 248
o Ireland: 6
o Italy: 22 Visit our Website
o Lithuania: 1
https://privacy.de
o Luxembourg: 1
o Latvia: 1
o Netherlands: 9
o Norway: 1
o Poland: 17
o Portugal: 6
o Romania: 3
o Slovenia: 2
o Slovakia: 1
o Spain: 29
o Sweden: 2
o United Kingdom: 68
- Category of data subjects: people participating in a company pro-
ject as testers
-2-
- Category of the data types/data records concerned: first name,
last name, e-mail addresses
- Likely consequences of the violation of the protection of per-
sonal data: misuse of data
2. Description of the data breach from a technical-organizational per-
spective
Due to human error, a document with personal data was published on a
digital platform (Trello). In addition, the entry was made publicly accessible
on the web by the responsible user (set to public instead of private, which
probably means restricted to a certain user group).
This was not a technical error.
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
Both the document and the entry were deleted. Employees were once
again reminded that the use of this online platform is not permitted within
the company.
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
The data subjects concerned were informed in writing on 21 January 2020
(in German, English and French).
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
This was not a technical error.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
This does not constitute a technical error. For organisational measures, see
point 3 above.
7. Intended measures by the LSA Berlin DPA
In the light of the above-mentioned considerations regarding Articles 33, 34
GDPR, the Berlin DPA closes the case.
Furthermore, the Berlin DPA has not identified any data protection viola-
tions.