FOR DATA PRIVACY AND FREEDOM OF INFORMATION
Your: 12.11.2021
Management board member
Our: 28.02.2022 nr 2.1.-1/21/3286
Notice of termination of the proceeding in regard to the protection of personal data
The proceeding of the Estonian Data Protection Inspectorate concerned the claim of a Lithuan ia
citizen (complainant) in regard to the fact that the
violated the requirements of GDPR.
Given the above, we initiated a supervision proceeding on the basis of clause 56 (3) 8) of the
Personal Data Protection Act.
During the proceeding, stated the following:
Our position is that in the case that was detailed in the inquiry, which includes a breach in
security regarding the processing of personal data, is not at fault.
has not processed the personal data of in their system in
relation to the described case because the services described in the case were n ot ordered in
the systems of nor according to ’s guidelines. The
application does not allow the commencement of ordering the services described in
the inquiry and the application does not have the functionality to do such things. The
is a tool for authentication and electronic signing which is meant for signing documents
electronically and logging in to different environments. We stress that does
not and has never taken payments from users.
It is true that on 23 March 2021 we requested on the website that users update the
Android system components of their phones in the Google Play Store. The reason for this was
that Google had released a broken update for Google Chrome and Android System Webview
which was causing errors in different applications, including the application. The
problem was also confirmed by Google themselves. Google then released an update which fixed
the issues that were caused by the previous update and the new update was required for not
only the seamless operation of but also other applications. More information
regarding Google’s problem can be found here.
Through the website, we directed the users of the service to apply the fixed update in
order for the service to function properly once again. Please note that there were no links, QR-
codes, or telephone numbers in the message we published on the website. We simply
requested our clients to update their Google Chrome and Android System Webview in the
Google Play Store. The message reads as follows:
FOR DATA PRIVACY AND FREEDOM OF INFORMATION
application started crashing? Please update Google Chrome and Android System
Webview in Google Play Store. Google released a broken update that causes applications to
crash and they have now also released fix for it. If that does not help, please call our helpline
or contact us through the e-mail form.
In the message, did not request clients to scan a single QR-code, and
furthermore, the short number 1394 is not used by us nor is it under our control.
Therefore, does not know where the person could have received the QR-
code for scanning or what exactly could have happened. does not have any
connections to the case besides requesting on our website that users update their
Android components, as was described above.
has no knowledge of the services provided by or the
details connected to the order that was described in the inquiry. Furthermore,
does not have a contractual or any other kind of relationship with
.
Based on the above, the Estonian Data Protection Inspectorate did not identify any violation of
the GDPR. For this reason, we are terminating the supervision proceedings.
This decision may be challenged within 30 days by submitting one of the two:
- A challenge to the Director General of the Estonian Data Protection Inspectorate
pursuant to the Administrative Procedure Act1, or
- An appeal to an administrative court under the Code of Administrative Court Procedure 2
(in this case, the challenge in the same matter can no longer be reviewed).
Respectfully
Lawyer
Authorised by the Director General
1
https://www riigiteataja.ee/en/eli/527032019002/consolide
2
https://www riigiteataja.ee/en/eli/512122019007/consolide