Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Outdated DSFA (Datenschutz-Folgenabschätzung) at CWA 2.15 level #2821

Closed
MikeMcC399 opened this issue Apr 28, 2022 · 7 comments
Closed

Outdated DSFA (Datenschutz-Folgenabschätzung) at CWA 2.15 level #2821

MikeMcC399 opened this issue Apr 28, 2022 · 7 comments

Comments

@MikeMcC399
Copy link
Contributor

MikeMcC399 commented Apr 28, 2022

Issue

The "Bericht zur Datenschutz-Folgenabschätzung für die Corona-Warn-App der Bundesrepublik Deutschland, Öffentliche Version, Version 1.20, 09.12.2021" covers CWA versions up to and including CWA 2.15, which was released on Dec 20, 2021.

In the meantime CWA 2.16, 2.17, 2.18, 2.19, 2.20, 2.21, 2.22, 2.23 and 2.24 have been released. Version 2.24 was released on June 29, 2022.

The current DSFA document is available from https://www.coronawarn.app/. See Data Protection Impact Assessment, and the corresponding annexes 1a, 1b, 1c, 2, 3, 4, 5, 6, 7 and 8.

Requested change

Publish an updated DSFA (Datenschutz-Folgenabschätzung) for CWA to the website https://www.coronawarn.app/ which covers all released versions including Version 2.24.


Internal Tracking ID: EXPOSUREAPP-12963

@larswmh
Copy link
Member

larswmh commented Apr 29, 2022

Thanks for your report @MikeMcC399. We have created an internal ticket for it and will raise this topic internally.
Internal Tracking ID: EXPOSUREAPP-12963


Corona-Warn-App Open Source Team

@MikeMcC399
Copy link
Contributor Author

What are the plans for publishing an up-to-date version of the Datenschutz-Folgenabschätzung? The document is at the 2.15 level whereas the app has been released as 2.24. This is a big gap.

@GisoSchroederSAP
Copy link
Contributor

At least internally, I checked the updated document. Is this already officially in place (I did not check yet) and acceptable?

@MikeMcC399
Copy link
Contributor Author

@GisoSchroederSAP

At least internally, I checked the updated document. Is this already officially in place (I did not check yet) and acceptable?

You need to check what is published on https://www.coronawarn.app/assets/documents/cwa-datenschutz-folgenabschaetzung.pdf which has not changed yet.

If a new approved document is available internally, then perhaps somebody from the Open Source Team could provide a PR to upload it to the src/assets/documents directory?

@GisoSchroederSAP
Copy link
Contributor

Renewed request at the lawers office about date of release for the updated DSFA

@MikeMcC399
Copy link
Contributor Author

  • PR Update Datenschutz-Folgenabschätzung (DSFA) #3268 which publishes Version 2.00, 10.10.2022 of the "Datenschutz-Folgenabschätzung" goes some way to resolving this issue, however the document is already more than two months old and covers CWA versions up to 2.25. Therefore 2.26, 2.27 and the current 2.28 are not covered.

@MikeMcC399
Copy link
Contributor Author

The original issue that the DSFA was still at CWA 2.15 has been resolved in that the document now covers up to CWA 2.25.

Considering that the later versions 2.26, 2.27 and 2.28 did not introduce new functionality which could affect data protection, I am closing this issue.

From a formal standpoint it would still be good if the DSFA document could be updated and republished for the current version. Perhaps this could be a target again for the CWA version 3.0 currently in development?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants