Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update 'ABIS GmbH' (community contribution) #812

Conversation

datenanfragen-community-edits
Copy link
Collaborator

This suggestion was submitted through the website.

Edit

@mal-tee
Copy link
Member

mal-tee commented Nov 1, 2020

When I made a request via email in 2020-05 the wrote back "Gerne beantworten wir Ihnen Ihre Anfrage. Bitte haben Sie jedoch Verständnis dafür, dass wir eine Auskunft gem. Art. 15 DS-GVO nur dann erteilen können, wenn uns die im beigefügten Schreiben genannten Angaben in schriftlicher Form vorliegen.", so I guess fax makes sense?

@mal-tee
Copy link
Member

mal-tee commented Nov 1, 2020

I can also confirm the comment on the company that they want an "eigenhändige Unterschrift", so i guess we should make a comment in the record?

@baltpeter
Copy link
Member

This seems to depend on whether they have data on you. I got the (written) confirmation that they don't have any data on me by simply sending an email (in September 2020), without having to submit any additional requirements.

As such, I don't think changing the record to 'fax' is a good idea. The signature isn't necessary in all cases, most users don't have access to a fax machine and according to the comment they also accept the signature via email.
I think it's best if we simply add a comment explaining that to the record. Users probably won't know beforehand whether Abis has data on them, so it doesn't make sense to voluntarily submit a signature in all cases.

@baltpeter
Copy link
Member

Only slightly related: It would be great to have a supervisory authority decide whether the practice of requiring the signature is even lawful. The GDPR doesn't specify any "Formerfordernisse" and a signature obviously cannot be used for identification purposes.

Unfortunately I cannot submit a complaint as they didn't want a signature for my request. :D

@rugk
Copy link
Contributor

rugk commented Nov 2, 2020

Ok, I'll do.

@rugk
Copy link
Contributor

rugk commented Nov 10, 2020

Sent. I'll keep you up-to-date.

@mal-tee
Copy link
Member

mal-tee commented Nov 10, 2020

Great! Thanks.

Copy link
Member

@mal-tee mal-tee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So, should we update the record like this for the time being?

companies/abis.json Outdated Show resolved Hide resolved
companies/abis.json Outdated Show resolved Hide resolved
Copy link
Member

@mal-tee mal-tee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

Should we create an issue for the discussion regarding @rugk 's complaint or do we just use this PR? :D

@mal-tee mal-tee merged commit 5652f0a into datenanfragen:master Nov 10, 2020
@baltpeter baltpeter deleted the suggest_abis_1604245775667 branch November 13, 2020 21:01
@rugk
Copy link
Contributor

rugk commented Nov 20, 2020

Problem solved.

LDI Hessen:

Die ABIS GmbH hat mir nunmehr bestätigt, dass der Prozess zur Auskunftserteilung den datenschutzrechtlichen Maßgaben angepasst worden ist.

Die Betroffenenrechte erfordern keine bestimmte Form, insbesondere keine Unterschrift der betroffenen Person. Eine eindeutige Identifikation des Betroffenen ist mit einer Unterschrift auch gar nicht möglich. Nach Art. 12 Abs. 6 DS-GVO kann der Verantwortliche lediglich dann zusätzliche Informationen anfordern, welche zur Bestätigung der Identität der betroffenen Person erforderlich sind, wenn er begründete Zweifel an der Identität der natürlichen Person hat. Ein voraussetzungsloses Anfordern weiterer Daten ist damit nicht vereinbar. Eine Unterschrift der betroffenen Person wird zukünftig von der ABIS GmbH nicht mehr verlangt.

Die Erteilung von Auskunftsersuchen muss zudem auf verschiedenen Kommunikationskanälen geschehen. Entsprechend erfolgt eine Auskunftserteilung durch die ABIS GmbH künftig nicht mehr nur mittels Briefpost.

Ich bedanke mich für Ihren Hinweis auf das nicht datenschutzkonforme Verhalten der ABIS GmbH, welcher zu einer Optimierung des Datenschutzes beigetragen hat, und verbleibe[…]

@mal-tee
Copy link
Member

mal-tee commented Nov 20, 2020

Wow, that is great!

baltpeter added a commit that referenced this pull request Dec 1, 2020
@baltpeter
Copy link
Member

@rugk I'm a little late to the party but that is indeed great. Thanks for submitting the complaint!

I think it would be good to have a blog post on this for our website (this PR is kind of hard to find). That post could serve two important purposes: a) document that requiring signatures for requests is not OK and b) be an awesome (and unfortunately quite rare, thus far) example of a successful complaint that actually changed the situation for the better for everyone.

Would you be OK with sharing a redacted copy of your correspondence with the LDI Hessen with me? That would make writing the post a lot easier. You can reach me via email (PGP key) or Matrix).

But if you don't want that, that's obviously totally OK as well.

@rugk
Copy link
Contributor

rugk commented Dec 19, 2020

Done. (ID: GqLAkqcDekj,iH6,3oCx)

@rugk
Copy link
Contributor

rugk commented Dec 19, 2020

Or, of course you can FOI-request that communication from the LfDI Hessen.
Agency reference: AZ 90.20.77:0245

@baltpeter
Copy link
Member

Thank you! I have opened #524 for the post.

Or, of course you can FOI-request that communication from the LfDI Hessen.

Good point! As someone from Lower Saxony that isn't a right I am used to having. :D

@mal-tee
Copy link
Member

mal-tee commented Dec 19, 2020

https://www.datenanfragen.de/blog/abis-unterschrift-dsgvo-anfragen/
The article is live 🥳

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
record Issue related to the JSON records via-suggest-api
Development

Successfully merging this pull request may close these issues.

None yet

4 participants