Vogon Today

Selected News from the Galaxy

StartMag

App IO, this is how the Guarantor folded PagoPa

App IO, this is how the Guarantor folded PagoPa

How the dispute between the Privacy Guarantor and the state company PagoPa over the IO app ended

PagoPA collects the blow inflicted by the Guarantor for the Protection of Personal Data on the Io App and adapts it to the required confidentiality standards. 

Only a few days ago the Authority for the protection of personal data had given the green light to the issue of the green pass and, at the same time, had ordered the blocking of the IO App because it was responsible for transferring citizens' data to three companies: Google, Instabug and Mixpanel . 

PagoPA welcomes the findings of the Guarantor 

The Guarantor retraces his steps in consideration of the "efforts undertaken by PagoPA to remedy the remarks formulated by the Guarantor" and unlocks the App Io . PagoPA "has provided for the App IO a series of technical measures to protect the privacy of users, which will be made effective with the imminent release of a new version of the app". In short, it accepted the remarks about the privacy protection risks raised by the Guarantor. 

The Guarantor unlocks the App Io

The Guarantor therefore considered that "the reasons for the blocking of the treatments carried out by the App that involve interaction with Google and Mixpanel no longer exist ". The decision came because PagoPA " promptly remedied the remarks made by the Guarantor ". The processing block will remain, however, "for the data collected and archived by Mixpanel, which can no longer be used, but exclusively stored until the end of the investigation by the Authority". In the report of the Guarantor there are PagoPA's commitments in relation to the data transmitted to Mixpanel and Google but there are no indications on the data processed by Instabug .

What PagoPA is committed to doing with Google LLC

As stated in the decision of the Guarantor of 16 June, the company of the Ministry of Finance has decided to accept and follow up on the findings highlighted by the Guarantor for the protection of personal data. PagoPA has deactivated unnecessary Google services and has "taken measures to ensure that the content of the notices to citizens is no longer known by Google ". Furthermore, in relation to interactions with Google LLC services, PagoPA has guaranteed that "services other than those used for sending push notifications" have been deactivated and " push notifications with generic content have been introduced (ie without any indication of the sender, the object or its content) ". 

Minimize interactions with Mixpanel 

As regards the transmission of data to Mixpanel, PagoPA ensures that the " modification of the current unique identifier of the user , present within the set of data sent to Mixpanel " and the "minimization of the data sent to Mixpanel has been prepared. , disabling the tracking of some events relating to the holiday bonus and cashback and eliminating some information from the set of data transmitted ". In this way, the user's tax number and other unnecessary information relating to the holiday bonus and cashback will no longer be transferred to the US company. Furthermore, the “Geolocation Tracking functionality” was deactivated and an “opt-in mechanism for the use of the tracking libraries offered by Mixpanel was introduced, adequately informing users and requesting the consent required by art. 122 of the Code ". In short, a victory across the board for the Guarantor and for the protection of citizens' data. 

The news starting from 9 July 2021 

From 9 July 2021, users will be able to choose which services to activate on the IO App among the more than 12 thousand available . Currently, all of them have been activated by default so far. In addition, "the forwarding to one's email of all messages received on the app must be requested by citizens". 


This is a machine translation from Italian language of a post published on Start Magazine at the URL https://www.startmag.it/innovazione/app-io-ecco-come-il-garante-ha-piegato-pagopa/ on Thu, 17 Jun 2021 11:57:02 +0000.