¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
Berlin, 16 November 2021
Berlin Commissioner for
Data Protection and
535.2907 / 631.447 Freedom of Information
Friedrichstr. 219
10969 Berlin
Final Decision Visitors’ entrance:
Puttkamer Str. 16-18
The Berlin DPA closes the case. The building is fully accessible to
disabled members of the public.
1. Facts concerning the data breach Contact us
- Controller: Delivery Hero SE Phone: +49 (0)30 13889-0
- Incident: Due to a manual configuration error at the food delivery Fax: +49 (0)30 215 50 50
service Delivery Hero, stored photos of rejected orders were pub- Use our encrypted contact form
licly accessible; on 19,000 photos, the invoice was also displayed. for registering data protection
complaints:
In about 400 of the photos with invoices, the name and telephone www.datenschutz-berlin.de/be-
schwerde.html
number of the person placing the order were also visible. A break-
down by country was not provided. For all other enquiries, please
- Date of occurrence: 4 March 2021 – 20 July 2021 send an e-mail to:
[email protected]
- Date of acknowledgement of the incident: 20 July 2021
Fingerprint of our
- EU/EEA Member States concerned, with the number of data PGP-Key:
subjects concerned: Bulgaria, Croatia, Cyprus, Czech Republic, D3C9 AEEA B403 7F96 7EF6
Finland, Greece, Hungary, Norway, Sweden, Romania C77F B607 1D0F B27C 29A7
- Category of data subjects: Customers
- Category of the data types/data records concerned: Pictures of Office hours
delivered dishes, partly with customer data (name, phone number,
Daily from 10 am to 3 pm,
NO delivery addresses) Thursdays from 10 am to 6 pm
- Likely consequences of the violation of the protection of per- (or by appointment)
sonal data: Probably little or no consequences, as no unusual ac-
cesses and especially no accesses on a large scale to the cloud How to find us
storage were detected. In addition, only relatively uncritical personal The underground line U6 to
data was affected, in the majority even only images without any per- Kochstraße / Bus number M29
and 248
sonal reference. Possible consequences: Identity theft, unwanted
calls
Visit our Website
2. Description of the data breach from a technical-organizational per- https://privacy.de
spective
Due to a manual configuration error, between 4.3.2021 and 20.7.2021,
170,000 photos of rejected orders stored in a cloud bucket were publicly
accessible, on 19,000 of which the receipt was also shown. About 2% of
the photos with receipts also showed the name and telephone number of
the person placing the order. There are therefore about 400 data subjects.
There was no breakdown by country. Retrieving the photos also required
knowledge and manipulation of the corresponding URLs.
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
-2-
Erasure of the cloud bucket, moving the data to a storage that can-
not be accessed without authentication.
Checking all other buckets for faulty configuration
4-eyes principle for the configuration of access rights has been im-
plemented
Automated analysis of the photos to see whether the photos contain
a receipt and whether personal data can be read on the receipt.
In the future, the company will draw customers' attention to the fact
that such receipts should not contain any personal data when using
the app function for uploading pictures.
We consider the measures to be sufficient and effective.
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
Notification of the data subjects is not mandatory, as there is no high risk
due to the non-critical data and it is unlikely that unauthorised access to
personal data has occurred.
No read logging was (inadvertently) set up on the bucket (cloud storage
area), so no object-level analysis is possible. However, coarser data traffic
analyses did not show any anomalies such as large-scale data retrievals.
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
For services and other storage, automated erasure rules generally apply for
erasure after 6 months. In the present case, however, this functionality had
not been activated by mistake.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
See point 3.
7. Intended measures by the LSA Berlin DPA
In the light of the above-mentioned considerations, the Berlin DPA closes
the case.