¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
631.284 Berlin Commissioner for
535.1963 Data Protection and
Freedom of Information
A56ID 161003
CR 169740 Friedrichstr. 219
10969 Berlin
DD 175403
Visitors’ entrance:
Puttkamer Str. 16-18
The building is fully accessible to
Final Decision disabled members of the public.
The Berlin DPA closes the case. Contact us
Phone: +49 (0)30 13889-0
1. Facts concerning the data breach Fax: +49 (0)30 215 50 50
Controller: Springer Nature AG & Co KgaA
Use our encrypted contact form
Incident: 411 author data (names, partly also e-mail addresses) for registering data protection
complaints:
were inadvertently forwarded to the platform Research Square with- www.datenschutz-berlin.de/be-
out the consent of the data subjects and partly published there. The schwerde.html
author data of 36 of 76 research papers were published for 25 days. For all other enquiries, please
Date of occurrence: 11 July 2020 send an e-mail to:
[email protected]
Date of acknowledgement of the incident: 4 August 2020
EU/EEA Member States concerned, with the number of data Fingerprint of our
PGP-Key:
subjects concerned: Austria, United Kingdom, Germany, France,
D3C9 AEEA B403 7F96 7EF6
Italy, Estonia, Belgium, Netherlands, Sweden, Finland. The exact C77F B607 1D0F B27C 29A7
number of affected persons per country would require a recreation
of the breach. For this reason, it was decided not to do so. Please Office hours
find a list of the institutions concerned attached.
Category of data subjects: 411 author names of scientific papers Daily from 10 am to 3 pm,
Thursdays from 10 am to 6 pm
and e-mail addresses in some cases. (or by appointment)
Category of the data types/data records concerned: 80 datasets
with bibliographic data of scientific papers. How to find us
Likely consequences of the violation of the protection of per- The underground line U6 to
Kochstraße / Bus number M29
sonal data: almost none since the controller also published the and 248
data in their scientific journals that are available digitally (partly for
free) and on paper for free for the scientific community through (uni-
Visit our Website
versity) libraries.
https://privacy.de
2. Description of the data breach from a technical-organizational per-
spective
Due to an administrative error (a faulty system configuration), 411 author
data (names, partly also e-mail addresses) were forwarded to the platform
Research Square and partly published there.
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
The controller has taken the following measures:
corrected incorrect system configuration;
-2-
deactivated the publication of the data on the Research Square plat-
form and erased all data transmitted to the platform without authori-
sation (the platform has an access point where controllers such as
Springer can edit the data you have entered);
developed a concept to minimize the risk of data transmissions be-
ing influenced by system configurations;
revised quality assurance, especially for updates.
The Berlin DPA assess the measures as sufficient and effective.
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
Notification of the data subjects is not mandatory, as there is no high risk.
No sensitive data have been published. In addition, the names of the au-
thors were and are intended for publication in the journals "Breast Cancer
Research" and “Critical Care”.
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
Not applicable.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
See 3.
7. Taken measures by the LSA Berlin DPA
In the light of the above-mentioned considerations, the Berlin DPA closes
the case as only a limited amount of uncritical data was affected. This data
was meant to be published in another place and has been published there
by now.