BETA nonprofit public democratic european moderated

Search

#ochronadanych

The ruling of the Supreme Administrative Court states that housing cooperatives that violate GDPR regulations should be treated like enterprises and may be fined up to 20 million euros, instead of the 100,000 PLN limit that applies to public administration. (translated)

Spółdzielcy łamiący RODO bez taryfy ulgowej przy naliczaniu kar

The Dutch Data Protection Authority (AP) fined Uber 825 million euros for violating drivers' rights by automatically blocking their accounts. (translated)

The Dutch Data Protection Authority (AP) imposed a fine of 825 million euros on Uber for violating drivers' rights by automatically blocking their accounts. Reuters reported on the decision. The company announced it would appeal. (translated)

Child's grades for a fee? Advertisements in the online journal? It's time to end this ❌. @RozwojPlus is submitting a bill proposal: free access for parents, no ads for children, and full protection of their data. 🔒 The online journal is a tool for families, not a business model. (translated)

We are introducing Cyber Friday, which means five changes that will better protect the data of Polish women and men. Medical data cannot be treated like ordinary goods that can be passed on to other companies without responsibility. That is why we are strengthening the rules for their protection and will introduce the following. (translated)

The Dutch Data Protection Authority (AP) imposed a fine of 825 million euros on Uber for violating drivers' rights by automatically blocking their accounts. Reuters reported the decision. The company announced it would appeal. (translated)

The Polish government, in response to a record leak of medical data, is introducing Gawkowski's Cyber Friday - a package of legislative changes aimed at tightening the personal data protection system, including mandatory certification for entities processing this data. (translated)

Cyberpiątka Gawkowskiego. Wiemy, jak rząd chce zatamować wycieki

Karol Nawrocki today again vetoed in defense of the interests of toxic Big Tech companies, this time stealing and trading the data of Polish children. I don't know if it is possible to do more harm than what the current president is doing. (translated)

Leaks of confidential information in the GameDev industry, illustrated by the case of Epic Games against a former employee, reveal serious business consequences and highlight the importance of protecting trade secrets. (translated)

Tajemnica przedsiębiorstwa w branży GameDev. Lekcje ze sprawy Epic Games

The police are securing data, and the UODO is conducting an inspection in the private company MyDr. The systemic conclusions after the incident are clear - increasing the accountability of entities that process data and expanding the obligations of those that handle large amounts of data - regardless of how they are... (translated)

Po wycieku blisko 20 mln danych osobowych i medycznych Polaków, puszczana była w obieg informacja, że na stronie rządowej bezpiecznedane_gov_pl można sprawdzić czy Twoje dane wyciekły. Teraz okazuje się, że na tej stronie rządowej nie było i do dziś nie ma danych osobowych, które wyciekły, więc tak naprawdę nikt nie może już być pewien czy jego dane są bezpieczne i nie trafiły w ręce oszustów. Dziś potwierdziło to Centralne Biuro Zwalczania Cyberprzestępczości: "Na tym etapie nie jest zasadnym publikowanie numerów PESEL pacjentów obsługiwanych przez system MyDr na stronie bezpiecznedane .gov pl Publikowanie takich danych mogłoby utrudnić prowadzone działania." Zdjęcie: Komunikat na stronie bezpiecznedane_gov_pl #Cyberbezpieczeństwo #OchronaDanych #BezpieczeństwoInformacji

The German organization HateAid is demanding a ban on the sale of Ray-Ban Meta smart glasses, arguing that their hidden camera and microphones violate data protection regulations, and that the LED signal indicating recording is not sufficiently visible to bystanders, which creates a risk of covert filming in public places. (translated)

Kamera ukryta w oprawkach. Niemiecka organizacja domaga się zakazu popularnych okularów

The President of the Personal Data Protection Office, Mirosław Wróblewski, emphasizes that Poland is one of the most attacked countries in the world in terms of cybersecurity, pointing out the need for systemic changes in security following a serious data leak involving 19 million Poles from the MyDr service. (translated)

Prezes UODO: Jesteśmy jednym z najbardziej atakowanych państw na świecie

Due to the data leak from the private company MyDr, further state institutions are taking action to protect patients and doctors. The e-Health Center has started a preventive and gradual update of the certificates used for communication with the P1 system. What are they for? (translated)

Onet.pl 3w

The leaked data from the MyDr platform indicates that 12,000 Polish clinics that entrusted it with processing patient data may face consequences, as the responsibility for data security rests with the administrators, which could affect nearly 19 million people due to the theft of their sensitive information. (translated)

Wyciek z MyDr. Tysiące przychodni mogą ponieść konsekwencje

It's embarrassing how the state tries to shift the responsibility onto citizens for the unlawful use of their data by appealing for the protection of PESEL. Is the government incapable of doing more? Of course, it is worth doing as a precaution and to avoid having to explain ourselves if someone misuses our data. (translated)

Skala wycieku jest katastrofalna. Jak to możliwe, że prywatny procesor zgromadził dane zdrowotne blisko 19 mln ludzi i stał się ogólnokrajowym punktem koncentracji ryzyka, a żaden z systemów nadzoru nie uruchomił wcześniej wymogów, audytu ani mechanizmu monitorowania koncentracji? #RODO nie tworzy centralnego rejestru koncentracji danych. Nie ma mechanizmu: „hej, jeden procesor właśnie przekroczył 5, 10 czy 15 mln kartotek zdrowotnych i traktujemy go od tej chwili jak systemowo istotny podmiot wymagający szczególnego nadzoru”. Oceny ryzyka i dokumentacja pozostają zasadniczo u poszczególnych administratorów i procesorów. Komunikat UODO może brzmieć dziś dość absurdalnie z perspektywy obywatela (prawnie jest poprawny). Urząd mówi tysiącom placówek korzystających z MyDr, że każda jako administrator ma przeanalizować ryzyko, zgłosić naruszenie i zawiadomić pacjentów. To ujawnia słabość zasad ochrony danych i cyberbezpieczeństwa państwa. Z punktu widzenia zarządzania kryzysowego sensowniejsze byłoby równoległe centralne ustalenie zakresu poszkodowanych i jeden komunikat odgórny. Tu ważna uwaga, "stary" NIS/KSC miał poważny brak dotyczącą łańcucha dostaw. W sektorze zdrowia dostarczanie oprogramowania czy usług tysiącom placówek nie oznaczało, że firma stawała się operatorem usługi kluczowej sektora zdrowia. NIS2 miał zaradzić temu problemowi, ale w Polsce nie wdrożono go na czas. Jest BARDZO DUŻE OPÓŹNIENIE. Nowy Krajowy System Cyberbezpieczeństwa (ustawa) jest w okresie wdrożeniowym. Podmioty mają czas na wpis do wykazu do 3 października 2026 r., na wdrożenie obowiązków do 3 kwietnia 2027 r., a pierwsze obowiązkowe audyty podmiotów kluczowych mogą przypadać dopiero na 3 kwietnia 2028 r. #OchronaDanych #Cyberbezpieczeństwo #Nadzór

Posłuchajcie rady wicepremiera @KGawkowski i zastrzeżcie sobie PESEL. Chociaż pewnie większość z Was ma go już zastrzeżonego od dawna. Niestwty nic więcej sensownego nie da się zrobić w Polsce, kiedy wyciekną wasze dane medyczne (albo inne, które PESEL zawierają) Jeśli przed kwietniem 2024 byliście u lekarza, to przypomnijcie sobie u którego. Możecie zapytać go czy korzystał z systemu MyDr. A jeśli tak, to przypomnijcie sobie jakie dane mu podawaliście. To nie oznacza, że lekarz faktycznie wpisał te wszystkie dane (np. niektórzy nie wpisują adresu) no ale to jest wasz "worst case scenario". Na koniec trzymajcie kciuki, żeby być w tej części pacjentów, do której atakujący nie uzyskał dostępu. #PESEL #BezpieczeństwoDanych #OchronaDanych

In Krakow, there was a huge data leak from MyDr, where 19 million records related to information about prescriptions, visits, and medications were stolen, confirming the interest of authorities and specialists in cybersecurity issues. (translated)

Ogromny wyciek danych z MyDr. Chodzi o nawet 19 mln osób

Dr n. med. @JacekGMadej wysyła do @NawrockiKn petycje w sprawie @RzeczPacjenta "Działanie RPP stanowiło świadomą i celową zemstę urzędniczą, podjętą z premedytacją w celu całkowitego zniszczenia mojej reputacji zawodowej i dobrego imienia. Skala tego czynu jest tak rażąca, że sprawa ta skutkuje skierowaniem przeze mnie stosownego zawiadomienia do Prokuratury na podstawie art. 231 K.k., wytoczeniem powództwa cywilnego o ochronę dóbr osobistych i zadośćuczynienie przeciwko Skarbowi Państwa, a także złożeniem oficjalnej skargi na rażące naruszenie przepisów RODO do Prezesa Urzędu Ochrony Danych Osobowych" https://t.co/BCUYwdIdfe #prawo #ochronadanych #reputacja