e-Boks – Violation Found (Denmark, 2022)

Violation Found
Datatilsynet (Denmark)4 March 2022Denmark
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

e-Boks, a digital platform, faced a security breach that allowed users to access other people's profiles. The Danish DPA found that e-Boks did not test all scenarios that could lead to such errors, violating GDPR's security requirements. This highlights the need for thorough security testing in digital services.

What happened

e-Boks had a security breach that allowed unauthorized access to user profiles.

Who was affected

Users of e-Boks Express who could access other people's profiles due to a technical error.

What the authority found

The Danish DPA concluded that e-Boks failed to ensure adequate security measures, as required by GDPR, by not testing all possible error scenarios.

Why this matters

This case highlights the critical need for comprehensive security testing in digital platforms to prevent unauthorized access. Companies should regularly review and test their systems to ensure they meet GDPR's security standards.

GDPR Articles Cited

Art. 32(1) GDPR
Art. 4(12) GDPR
Full Legal Summary
Detailed

The controller is e-Boks, a digital platform for dialogue, shipping and storage of documents. The controller also manages e-Boks Express, a self-service portal where companies can send messages and documents. In March 2021, the Danish DPA carried out an investigation after it became aware that it was possible to access someone else’s user profile when logged in to e-Boks Express. According to the controller, the problem was not caused by them. Their procedure requires the user to access the portal via a NemID Erhverv/NemID signature (which is a key file, key card or key app). According to the controller, the fact that a user, after signing in with a NemID keycard, was signed in to another user account, was caused by a technical error by Nets Danmark A/S (which manages the NemID Erhverv/NemID signatures). Nets confirmed this, and stated that the error only existed when a user signed in to e-Boks Express with a NemID key card (and not with a key file or key app). Moreover, they argued that it is clear from the log-files that ‘only’ 304 people could potentially have exploited the bug, and that the security breach ‘only’ lasted from 4 March 2021 to 27 April 2021. First, the DPA noted that the unauthorised access to user profiles, meant that there was a personal data breach pursuant to Article 4(12) GDPR. Moreover, it stated that Article 32(1) GDPR obliges controllers to take appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the controller’s processing of personal data. In this regard, it noted that this obligation normally implies that changes to existing IT platforms, and developments of new IT platforms, can only take place if security can be ensured. The DPA noted also that the controller did not carry out tests of all possible scenarios in which errors could occur. After all, it was not aware of the error that users were signed into the wrong account when they used a NemID key card as authent

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for e-Boks in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

4 March 2022

Authority

Datatilsynet (Denmark)

GDPRhub ID

gdprhub-4789

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. e-Boks - Denmark (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: