Designbysi – Violation Found (Denmark, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Designbysi, a Danish fashion brand, faced a security breach that exposed customers' payment data. Hackers inserted malicious code on their website, prompting customers to re-enter card details. The Danish DPA reprimanded the company for not having strong security measures.
What happened
Hackers exploited a security flaw on Designbysi's website to collect customers' payment card information.
Who was affected
Customers who attempted to make purchases on Designbysi's website during the breach period.
What the authority found
The Danish DPA reprimanded Designbysi for inadequate security measures, specifically the lack of two-factor authentication.
Why this matters
This incident highlights the importance of robust security practices, like two-factor authentication, to protect customer data. Businesses should regularly review and update their security measures to prevent breaches.
GDPR Articles Cited
The controller is Designbysi, a Danish fashion brand. Due to a security issue, hackers were able to implement a JavaScript code on Designbysi's website. Subsequently, customers saw an error message during their purchase with a request to re-enter their card information before purchasing an item. This enabled the hackers to collect the customers' payment card information. The hackers' attack could have potentially affected anyone purchasing items on the website between 26 April 2021 and 22 June 2021. It was not possible to identify exactly how many and which cards had been affected. As soon as Designbysi noticed the problem, the JavaScript code was removed and the personal data breach was reported to the DPA. Designbysi also sent a mail to all customers informing them about the breach and recommending them to contact their bank. Designbysi has also fixed the technical issue that made the attack possible. The Danish DPA issued a reprimand against Designbysi for violating Article 32(1) GDPR by not implementing sufficient technical and organisational measures to ensure an appropriate security level for the clients' accounts. In particular, Designbysi should have implemented two-factor authentication for persons who could change the website script.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Designbysi in DK
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Designbysi - Denmark (2022). Retrieved from cookiefines.eu
Last updated: