¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
Berlin Commissioner for
Berlin, 24 March 2021 Data Protection and
Freedom of Information
535.1660 Friedrichstr. 219
10969 Berlin
631.257
Visitors’ entrance:
CR 126887 Puttkamer Str. 16-18
DD 156313
The building is fully accessible to
FD 188955 disabled members of the public.
Contact us
Final Decision
Phone: +49 (0)30 13889-0
Fax: +49 (0)30 215 50 50
The Berlin DPA closes the case.
Use our encrypted contact form
for registering data protection
1. Facts concerning the data breach complaints:
www.datenschutz-berlin.de/be-
- Controller: AWIN AG (www.awin.com) schwerde.html
- Incident: vulnerability in API interface For all other enquiries, please
- Date of occurrence: unknown (at the earliest in 2017) send an e-mail to:
[email protected]
- Date of acknowledgement of the incident: 20 March 2020
- EU/EEA Member States concerned, with the number of data Fingerprint of our
PGP-Key:
subjects concerned: total of 309
o Austria: 2 D3C9 AEEA B403 7F96 7EF6
C77F B607 1D0F B27C 29A7
o Belgium: 4
o Denmark: 4
Office hours
o France: 17
o Germany: 106 Daily from 10 am to 3 pm,
Thursdays from 10 am to 6 pm
o Hungary: 2 (or by appointment)
o Ireland: 3
o Italy: 7 How to find us
o Netherlands: 22
The underground line U6 to
o Norway: 2 Kochstraße / Bus number M29
o Poland: 5 and 248
o Portugal: 2
o Spain: 7 Visit our Website
o Sweden: 7 https://privacy.de
o UK: 119
- Category of data subjects: customers
- Category of the data types/data records concerned: email ad-
dresses (no passwords)
- Likely consequences of the violation of the protection of per-
sonal data: misuse
2. Description of the data breach from a technical-organizational per-
spective
Via an API interface, the above-mentioned personal data could be retrieved
for a part of the customer data records. By repeatedly calling up the inter-
face with different search parameters, it was possible to retrieve the per-
sonal data of all customer accounts.
-2-
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
Immediately after the data leak became known, the corresponding API in-
terface was restricted in such a way that the aforementioned personal data
could no longer be retrieved. The data leak was thus permanently closed.
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
All data subjects were informed of the incident by e-mail.
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
Not relevant. However, access to the API interface was also previously
transport-encrypted.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
See point 3
7. Measures taken by the LSA Berlin DPA
7.1 Measures taken regarding Articles 33, 34 GDPR
In the light of the above-mentioned considerations regarding Articles 33,
34 GDPR, the Berlin DPA closes the case.
7.2 Measures taken regarding data protection violations beyond Ar-
ticles 33, 34 GDPR
As regards this point as well, the Berlin DPA closes the case, since the
data was mainly not sensitive and the underlying technical problem has
been solved.