Data Protection Academy » Data Protection News » Data breach WeAct Campact
Data breach WeAct Campact
Date: 18.07.2019
Responsible body: Petition platform WeAct of the organisation Campact
Type of data breach: List of petition signatories can be viewed due to technical error
According to the Campact itself, due to a technical error, lists of all petition signatories could be viewed without a password, as long as the person accessing the lists had the exact URL to the respective petition. The technical error occurred because the organisation wanted to ensure a higher level of data protection. So Campact decided to move the WeAct software from Amazon servers to their own servers. The open source software intended for this was not fully suitable for this. Files that were previously marked as private were now publicly accessible. According to the organization, no accesses by third parties were registered.
Categories of data: Address data
Country: Germany
Persons concerned: 2 million WeAct users
Fines: unsettled
Source: City of Bremerhaven
- Internal control system - 10 September 2024
- TISAX requirements: Prepare certification step by step - 8 January 2024
- Audit management: Implementing audits more efficiently - 26 October 2023