Ahenfo Radio Denmark
Danish Data Protection Authority
News

Demand for a million fine is a ‘serious rap over the teddies’ for Netcompany

The Danish Data Protection Authority has reported Netcompany to the police. Reputation is affected, according to the correspondent.

Back in March 2022, a couple of Danes got a bit of a surprise when they logged on to the then new IT solution mit.dk.

Here, they not only had access to their own confidential information, they could also read other citizens’ information.

Specifically, the error on mit.dk meant that information such as e-mail and telephone numbers were shared from between 10 and 50 digital mailboxes.

And that mistake should cost the company behind mit.dk, Netcompany, according to the Danish Data Protection Authority, which supervises whether the rules for data protection are complied with.

Here, Netcompany has been reported to the police for breaching the data protection regulation and a fine of at least DKK 15 million has been proposed.

“Danish society is highly digitized, and therefore it is crucial that citizens can trust that the security of the national critical infrastructure is in order. A case like this can go beyond that trust, and for this reason, the Danish Data Protection Authority is also have to crack down hard,” reads a press release from the Norwegian Data Protection Authority .

Tech correspondent: That shouldn’t be possible

The error occurred because of the coding that was done on mit.dk.

Popularly speaking, the bricks with which the IT solution has been built have not been put together well enough.

And that shouldn’t be possible at all, says DR Nyheder’s tech correspondent, Henrik Moltke.

– What the Danish Data Protection Authority says is that from the start they have not designed the solution in a way that excludes something like this from happening, he says.

According to Netcompany itself, it took about an hour before mit.dk was shut down so that the error could be rectified.

– It is not good enough that you discover it and have it shut down. That shouldn’t be possible at all, says Henrik Moltke.

In the demand from the Danish Data Protection Authority, it is also highlighted that Netcompany “has not ensured an adequate level of security, and an impact analysis should have been prepared”.

Netcompany: One mistake is one too many

In a written response to DR Nyheder, Netcompany director André Rogaczewski says that they are now awaiting a decision in the case.

– The error on the platform was rectified, and a number of measures were introduced to ensure that this type of error could not occur again. Mit.dk has run stably since. We accept that the appropriate authorities make a final decision in the matter, says Netcompany, who emphasizes that they intervened quickly after being informed of the error.

– We have presented everything and explained the error to the Danish Data Protection Authority. The moment the human error was identified back in March 2022, Netcompany shut down the system immediately. This resulted in the error potentially affecting 10-50 citizens’ digital mailboxes on Mit.dk for approximately one hour. This does not change the fact that mistakes with one mailbox are one too many, writes André Rogaczewski.

Not the money that hurts

For years, Netcompany has landed many large contracts for IT solutions with, among others, the Danish state. Therefore, it is unlikely that the 15 million will haunt the company. The recommendation from the Danish Data Protection Authority still hurts, Henrik Moltke assesses.

– Now they get a serious rap over the teddies. DKK 15 million is not an insane amount of money for Netcompany, but for their reputation, it is a reminder that such things must be under control, he says.

How bad the error could potentially have ended up being is unclear to the tech correspondent.

– It is not entirely clear how bad the error is. It didn’t affect very many people because they reacted quickly, but I’m still a little short of being able to say how serious it could have been, says Henrik Moltke.

Related posts

Biden’s pardon of his son pours fuel on Trump’s claims of politicized justice

admin

The government will remove 98 supervisions and give the elderly more freedom to choose their own care

admin

Who is Ryan Wesley Routh, suspect in Trump assassination attempt?

admin

Leave a Comment