¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
535.2009 / 631.442 Berlin Commissioner for
Data Protection and
Freedom of Information
13 March 2022
Friedrichstr. 219
10969 Berlin
Final Decision
Visitors’ entrance:
Puttkamer Str. 16-18
The Berlin DPA closes the case.
The building is fully accessible to
disabled members of the public.
1. Facts concerning the data breach
Controller: Fabletics GmbH (ehemals Just Fabulous GmbH), Fa- Contact us
bletics.de, Schlesische Straße 38, 10997 Berlin
Incident: Data of Fabletics users (fabletics.de, fabletics.co.uk, fa-
Phone: +49 (0)30 13889-0
Fax: +49 (0)30 215 50 50
bletics.es, fabletics.fr, fabletics.nl) were temporarily visible to other Use our encrypted contact form
users due to a technical misconfiguration of the server for registering data protection
Date of occurrence: 26 August 2020, 18:13 - 21:01 o’clock complaints:
www.datenschutz-berlin.de/be-
Date of acknowledgement of the incident: 26 August 2020, 20:04 schwerde.html
o’clock For all other enquiries, please
EU/EEA Member States concerned, with the number of data send an e-mail to:
[email protected]
subjects concerned:
Fingerprint of our
Germany: 283 PGP-Key:
Spain: 35
D3C9 AEEA B403 7F96 7EF6
France: 144 C77F B607 1D0F B27C 29A7
Netherlands: 28
UK: 577 Office hours
Category of data subjects: customers of the online shops
Daily from 10 am to 3 pm,
Category of the data types/data records concerned: Name, ad- Thursdays from 10 am to 6 pm
dress, email address, phone number and account history (or by appointment)
Likely consequences of the violation of the protection of per-
sonal data: possible misuse of address data (e.g. data trading or How to find us
for abusive transactions) The underground line U6 to
Kochstraße / Bus number M29
and 248
2. Description of the data breach from a technical-organizational per-
spective
Visit our Website
Data of Fabletics users (fabletics.de, fabletics.co.uk, fabletics.es, fablet- https://privacy.de
ics.fr, fabletics.nl) was temporarily visible to other users due to a technical
misconfiguration of the server (incorrect configuration of a code in the load
balancer to address Google Chrome "samesite" cookie policy).
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
The faulty code has been removed in the load balancer, so the problem
should not occur again (the controller also writes in the data breach notifi-
cation that they do not want to use the faulty code again in a context that
could affect the personal data of the customers.
-2-
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
Yes, the affected customers were informed of the data breach by e-mail on
1 September 2020.
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
Deactivation of the faulty code and logout of all customers from the web
shop so that they had to log in again and, if possible, no more customer
data could be viewed through "open" logins.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
Permanent deactivation of the faulty software code
7. Intended measures by the LSA Berlin DPA
7.1. Intended measures regarding Articles 33, 34 GDPR
In the light of the above-mentioned considerations, the Berlin DPA closes
the case.
7.2. Examination of the intended measures with regard to the possible
underlying data protection violation by the specialist unit.
In the light of the above-mentioned considerations, the Berlin DPA closes
the case.