Designbysi – Violation Found (Denmark, 2022)

Violation Found
Datatilsynet (Norway)22 June 2022Denmark
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Designbysi, a Danish fashion brand, faced a security breach that exposed customers' payment data. Hackers inserted malicious code on their website, prompting customers to re-enter card details. The Danish DPA reprimanded the company for not having strong security measures.

What happened

Hackers exploited a security flaw on Designbysi's website to collect customers' payment card information.

Who was affected

Customers who attempted to make purchases on Designbysi's website during the breach period.

What the authority found

The Danish DPA reprimanded Designbysi for inadequate security measures, specifically the lack of two-factor authentication.

Why this matters

This incident highlights the importance of robust security practices, like two-factor authentication, to protect customer data. Businesses should regularly review and update their security measures to prevent breaches.

GDPR Articles Cited

Art. 32(1) GDPR
Full Legal Summary
Detailed

The controller is Designbysi, a Danish fashion brand. Due to a security issue, hackers were able to implement a JavaScript code on Designbysi's website. Subsequently, customers saw an error message during their purchase with a request to re-enter their card information before purchasing an item. This enabled the hackers to collect the customers' payment card information. The hackers' attack could have potentially affected anyone purchasing items on the website between 26 April 2021 and 22 June 2021. It was not possible to identify exactly how many and which cards had been affected. As soon as Designbysi noticed the problem, the JavaScript code was removed and the personal data breach was reported to the DPA. Designbysi also sent a mail to all customers informing them about the breach and recommending them to contact their bank. Designbysi has also fixed the technical issue that made the attack possible. The Danish DPA issued a reprimand against Designbysi for violating Article 32(1) GDPR by not implementing sufficient technical and organisational measures to ensure an appropriate security level for the clients' accounts. In particular, Designbysi should have implemented two-factor authentication for persons who could change the website script.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Designbysi in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

22 June 2022

Authority

Datatilsynet (Norway)

GDPRhub ID

gdprhub-5038

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Designbysi - Denmark (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: