Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
SWISS SUPERVISORY AUTHORITY: concludes preliminary investigation into Mitto AG

SWISS SUPERVISORY AUTHORITY: concludes preliminary investigation into Mitto AG

In December 2021, international media coverage drew the FDPIC’s attention to allegations of unlawful data processing by an employee of the Zug-based company Mitto AG. A preliminary investigation found no evidence of a breach of data protection regulations. The FDPIC has concluded his preliminary investigation with a final report, without issuing any recommendations.

In December 2021, following media coverage, the Federal Data Protection and Information Commissioner was alerted by an article published by the Bureau of Investigative Journalism and Bloomberg News to allegations of unlawful data processing by an employee of the Zug-based company Mitto AG. The article alleged that the employee in question had abused the access granted by mobile phone operators to their networks for the purpose of sending text messages to obtain information for other purposes. In particular, the employee allegedly used access to the signalling system (SS7) to enable the unauthorised surveillance of individuals in return for payment.

The FDPIC demanded detailed information from Mitto AG in several stages on the technical and organisational safeguards in place at the company. Mitto AG complied with all of the FDPIC’s requests and conducted its own external investigations, the results of which were shared with the FDPIC.

Mitto AG produced documentation on the organisational framework of its operations and described the measures in place to prevent and detect unauthorised changes to the software. According to Mitto AG, the logging data showed no evidence to suggest that the systems had been abused in the manner alleged.

According to Mitto AG, and confirmed by mobile operators in Switzerland, who were also invited to comment, it is impossible for Mitto AG employees to access the location data of SMS recipients without modifying the systems or software.

The FDPIC has carried out all the necessary inspections that were possible with the resources available to him but no evidence has come to light confirming that a breach of data protection regulations has taken place.

In view of the foregoing, the FDPIC has decided to conclude the preliminary investigation into Mitto AG without making any recommendations.

https://www.edoeb.admin.ch/edoeb/en/home/kurzmeldungen/nsb_mm.msg-id-93802.html

Recommended to you

Advanced Research