PROTECTION OF PRIVACY AND STATE TRANSPARENCY
FOR INTERNAL USE
Holder of information: Data Protection Inspectorate
Notation made: 2023.
The access restriction shall be valid until: 2028.
Legal ground: Sections 35(1)(18) (2), 35(1)(2) and
35(1)(9) of the Public Information Act
Ours: 2023 nr
ARTICLE 60 FINAL DECISION
Reprimand and notice of termination of proceedings concerning the protection of
personal data
On , submitted an initial notification of the personal data
breach to The Data Protection Inspectorate. On personal data breach notification
was updated. According to notification a cyber incident had occurred on in
a .
explained that a brute-force cyber-attack took place on
against the website , during which the
attacker tried to get access to the information of , including the
and . Information of those was used to
. The incident was detected on and it concerned
approximately via the
. The concerned categories of data subjects related to were: first name, last
name, e-mail address, telephone number.
The to prevent unauthorised access to data was carried
out on . In the , the following changes were made
to prevent the
On , submitted new initial notification of the personal data
breach and on a final notification according to which
on . Interested parties were offered the
opportunity to buy information on how data can be obtained from the
from , and The number of data subjects
concerned ranged from persons . The following data could
potentially be leaked: first name and surname, e-mail and, in the case of , also
the telephone number if this optional field was filled in by the client. In cooperation with
website developer of the
. As a way forward, a was developed that minimises the risk and
prevents brute-force or similar unauthorised access data. In addition,
were further implemented and
.A to prevent unauthorised access to
data was installed on , and on
.
Tatari tn 39/10134 Tallinn/627 4135/ [email protected] / www.aki.ee
Register code 70004235
According to the , the attacker found a new weakness in the incident
detected on . had reasonable grounds to believe that there
were two separate incidents. Explaining the reasons for the second data leak,
pointed out that it was not possible for them and the development partner to proactively
take action against an incident that had not yet occurred. IT and cybersecurity are constantly
evolving, sometimes attackers find weaknesses that were not known at the time of the building
up the system, also in this case.
explained that have the same
and the same . In theory, getting access to data was
possible by the same method. In fact, however, no similar cases have been detected
so far. The described above were also taken .
After the second data leak, has published information on
data leaks in the printed press, on social media accounts and homepage. Regarding
leaked data, is a controller.
In cooperation with senior developers of (working according to ISO 27001
certification) the security risks of the existing were
analyzed. It was found that the developments and changes made by the in
the period from in the current system, including
and the protection of data, were
sufficient. It was decided that in the commissioning of an
would be addressed.
On , the confirmed that a new
would be developed in cooperation with . The timetable for the
development of the is as follows: On , the
introduced a ,
operating both on the new and the old one. At the same time, all data relating
to and are protected . A new and a
will be in place in , including
without . By , all online data, will
be modified via the , as well as
. As of , a new professional
will be in place.
has submitted a separate to the
Supervision Authority. In addition, has confirmed that similar personal data
breach cases (including successful attacks) have no longer taken place and that the security
measures taken, and the have been effective.
Position of the Data Protection Inspectorate
Under Article 24(1) of the Regulation (EU) 2016/679 of the European Parliament and of the
Council (General Data Protection Regulation), the controller shall implement appropriate
technical and organisational measures to ensure a level of security appropriate to the risk, taking
into account the nature, scope, context and purposes of the processing of personal data, as well
as the risks of varying likelihood and severity for the rights and freedoms of natural persons.
Under Article 32(1), the controller must implement appropriate technical and organisational
measures to ensure a level of security appropriate to the risk, including ensuring the continued
confidentiality, integrity, availability and resilience of systems and services processing personal
data.
2 (3)
The same obligation arises from the principles governing the processing of personal data,
namely Article 5(1)(f) of the GDPR, according to which personal data must be processed in a
manner that ensures appropriate security and protects against unauthorised or unlawful
processing.
had not implemented adequate safeguards for
, as the unauthorised person(s) had the possibility to access
data relating to them.
In order to ensure security and prevent processing carried out in breach of GDPR, the controller
should assess the risks associated with the processing and implement measures to mitigate those
risks, such as encryption. Those measures should ensure an appropriate level of security,
including confidentiality, taking into account the state of the art and the costs of implementation
in relation to the risks and the nature of the personal data to be protected. In assessing data
security risk, consideration should be given to the risks that are presented by personal data
processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure
of, or access to, personal data transmitted, stored or otherwise processed which may in
particular lead to physical, material or non-material damage.
No one is protected from a cyberattack, but in order to prevent it, the controller needs to ensure
the security of and systems need to be regularly monitored to identify risks
that may have arisen. In the case of this incident, it would have been possible to prevent data
leakage .
has taken additional measures to ensure the protection of personal data laid
down in the GDPR. In addition, has confirmed that no further such attacks
and personal data leaks have taken place. Since
, which further reduces the risks associated with cyber-attacks. the Data
Protection Inspectorate terminates the supervision proceedings.
The Data Protection Inspectorate makes a reprimand to on the basis of
Article 58(2)(b) of the GDPR because the processing operations of personal data have violated
the requirements of the General Data Protection Regulation (Article 5(1)(f), Article 32).
Best regards,
lawyer
authorised by Director General
3 (3)