Hamburger Verkehrsverbund GmbH (HVV GmbH)

€20,000

Insufficient fulfilment of data breach notification obligations

Date de décision

1 janvier 2019

Autorité

Data Protection Authority of Hamburg

DE

Secteur

Transportation and Energy

Pays

DE

Droit

GDPR

Statut

FINAL

Description

On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called Customer E-Service (CES). The security gap consisted in the fact that customers logged in to the CES who had an HVV Card and linked their CES customer account to at least one active contractual relationship in background systems could, by changing the URL, display data of other customers who had an HVV Card. This data breach was not reported to the data protection authority in a timely manner.

Citations légales

Art. 33Art. 34

Questions et violations

Insufficient fulfilment of data breach notification obligations

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.