Image

Disclaimer:

This register is kept with the utmost care. However, EuroPriSe does NOT guarantee the accuracy of information found on the Site. Your reliance on information found on the Site is at your own risk. For more information please go to EuroPriSe Terms & Conditions.

Image

European Privacy Seal for AMV System

*** SEAL EXPIRED DUE TO WITHDRAWAL BY THE CERTIFICATION AUTHORITY *** 

 

Recertification: 04/2017

AMV Networks GmbH proved that its IT-based service AMV System complies with EU data protection law. Customers of AMV Networks such as insurance companies or providers of traffic information services may use the service in order to receive relevant real time information about a vehicle (e.g., its location, speed or fuel consumption) - provided that the vehicle owner consented to this beforehand. They can be sure that processing of real time vehicle data is in line with the demanding provisions of EU data protection law. Vehicle owners may terminate disclosure of data to customers of AMV Networks at any time via a dedicated web portal.

 

Product/Version

Image

AMV System

Function as provided in February 2017

Qualification: IT-based service

View the AMV System Certificate 

Cert. No.

EP-S-3LF77N

Version of Certification Criteria

11/2011 (95/46/EC)

Validity

*** SEAL EXPIRED *** 

04/04/2017 - 30/04/2019

Initial certification on 30/06/2014

Monitoring

12/2017 !!!OVERDUE!!! [Action by CA in process]

08/2018

Public Report

Recertification 2017: AMV-System Short Public Report Image 

Initial certification 2014: AMV-System Short Public Report Image Image  Image Image 

Manufacturer/Provider

Image

AMV Networks GmbH
Mühlstraße 21
4614 Marchtrenk,
Austria

BEST

The AMV System facilitates the principles of transparency and intervenability: Transparency vis-à-vis the vehicle owners is ensured by means of a dedicated web portal providing access to relevant information (cf. below). Drivers of vehicles who are not owners of those vehicles as well as passengers are informed about the AMV System by means of an information card to be placed in the vehicle. Vehicle owners may stop disclosure of real time information to third parties at any time by means of the above-mentioned web portal.    

ATTENTION:

Vehicle owners who allow other persons to drive their car must inform them about the fact that real time information about the vehicle (including location data) is collected, transmitted and disclosed to third parties. They are contractually obliged to do so and supported by AMV Networks by means of an information card that is to be placed at a visible spot inside of the vehicle.

It is worth noting that no information about location data is dislosed to vehicle owners by means of the web portal mentioned above. This means that vehicle owners may not track routes of other drivers by means of this portal (e.g., an employer does not have the possibility to track employees driving company cars by means of the AMV System). 

Summary

The AMV System consists of two components: A piece of hardware called "ASG device" that is to be installed in cars and other vehicles and the software „TrafficSoft“ that is run on servers that are located in an Austrian data centre. The ASG device transmits real time information about a vehicle such as its location, speed and fuel consumption to the TrafficSoft database. Data may then be accessed by third parties by means of a dedicated web portal - provided that the vehicle owner consented to the disclosure previously. 

Details

Recert 201704

In 2015, AMV Networks GmbH became a subsidiary company of STARLIM Spritzschutz GmbH. In 2016, AMV moved its premises from Ranshofen to the headquarters of STARLIM which are located in Marchtrenk. In this context, AMV rented ressources on virtualisation servers from its parent company to run virtual servers that are used for the further development of the "TrafficSoft" software. These virtualisation servers are operated in a dedicated server room that is located within the headquarters of STARLIM. An agreement between AMV and STARLIM which governs this server hosting is in place and the appropriateness of the respective technical and organisational measures was evaluated by the EuroPriSe Experts in the course of the current recertification project. The experts found that the TOMs do indeed ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected as required by Article 17 of Directive 95/46/EC.

The recent re-evaluation was conducted by the experts from 11/2016 until 02/2017. It showed that AMV System continues to meet all applicable EuroPriSe requirements. Further information can be found in the 2017 version of the Short Public Report

Initial Cert 201406

Two scenarios need to be distinguished:

(1) Data may be disclosed to commercial business partners such as insurance companies offering specific tariffs based on driving behaviour pseudonymously: Each ASG device is allocated a unique identifier called ASG ID. When consenting to the disclosure of data to business partners, vehicle owners reveal their ASG ID. This means that business partners may easily link pseudonymous real time data to the respective vehicle owner.

(2) Data may also be disclosed to third parties without ASG ID and any other unique identifier altogether. E.g., a traffic information service may be interested in analysing aggregated information allowing them to identify traffic congestions etc., but not in tracking a single vehicle and its owner.

It must be stressed that in both cases, information is only disclosed to third parties if the vehicle owner consented to this disclosure beforehand. Furthermore, there are measures in place to ensure that only those pieces of information are disclosed that are relevant for the particular service at hand (e.g., if an insurance company offers a special tariff based on mileage per year, there is no need to disclose information on location, speed, etc.). Likewise, it is ensured that data are only disclosed to third parties at reasonable time intervals. Again, respective decisions are made on a case by case basis.   

Relevant data may be accessed by third parties by means of a dedicated web portal. Certified garages that install the ASG device in vehicles may access a similar web portal in order to verify the functioning of the devices. Finally, another web portal allows vehicle owners to monitor which third parties are entitled to access real time information about their vehicles and what pieces of information exactly are disclosed at what intervals to each of these third parties. What is more, the web portal also provides vehicle owners with an easy means to stop disclosure of real time information to third parties at any time. 

The AMV System lives up to the principle of informational separation of powers: Certified garages who are in direct contact with vehicle owners do know their contact data, but not the unique identifiers (ASG IDs) that have been assigned to them whereas AMV Networks processes the ASG ID, but does not have any information about the vehicle owners' identities.

The ToE includes

  • AMV® On-Board-Unit ASG®
  • AMV® Data Center TrafficSoft®
    (including the web portals for business partners, garages and vehicle owners)
  • Relevant contracts with third parties

Technical Evaluator

Jürgen Stöger
c/o Secur-Data Betriebsberatungs-GmbH
Fischerstiege 9
1010 Vienna
Austria

Legal Evaluator

Prof. Hans-Jürgen Pollirer
c/o Secur-Data Betriebsberatungs-GmbH
Fischerstiege 9
1010 Vienna
Austria

Formerly Certified Versions

n.a.

 

 

© 2008 - 2019 | EuroPriSe GmbH - European Privacy Seal | Handelsregister-Nr. (Commercial Register No.): Bonn HRB 20387

No responsibility for the accuracy of the information. Contact | Privacy Notice | Imprint

Product/Version

REISSWOLF f.i.t.

v1.5; service function as provided in 05/2018

Qualification: IT product and IT-based service (processor service)

View the REISSWOLF f.i.t. certificate

Version of Certification Criteria

11/2011

Cert. No.

EP-S-X5TSCN

Validity

24/05/2018 - 31/05/2020

Monitoring

01/2019

09/2019

Public Report

f.i.t. Short Public Report Image Image 

Manufacturer/Provider

REISSWOLF Systems GmbH

Im Heegen 13
22113 Oststeinbek
Germany

BEST

Access policies can be used to restrict system usage to specific times of the day and/or IP addresses to reduce the attack vector for third-party access. A user session is controlled by means of a cross-tab synchronised session countdown.

ATTENTION

Regarding the processing of personal data on third persons by means of f.i.t., it must be highlighted that the (usually) corporate users of the service qualify as controllers whereas REISSWOLF Systems GmbH acts as a processor on behalf of the users. Customers are advised that the legitimate use of the service may require the collection of the data subject's consent and/or declaration of release from confidentiality.

SUMMARY

REISSWOLF f. i. t. is a web-based archiving system for data storage and access. It serves the purpose of uploading, storing, managing and exchanging data in the sense of a document management system. f.i.t. is a web application that can be used with common internet browsers. 

DETAILS

REISSWOLF f. i. t. is primarily designed for commercial use. It is distributed by REISSWOLF Systems GmbH and operated as Software as a Service (SaaS) in a data center in Germany.

The ToE includes

  • The web-based service REISSWOLF f.i.t. (for details, please cf. the short public report)

It does not include

  • REISSWOLF f.i.t. mobile app
  • REISSWOLF f.i.t. hotfolder
  • Office module
  • Teamviewer
  • Other alternative interfaces to clients

Technical + Legal Evaluator

Ann-Karina Wrede
Innungsstraße 7
21244 Buchholz
Germany

Initial Certification: 05/2018

REISSWOLF f.i.t. provides a web-based service that enables companies to upload, store, manage and exchange data in the sense of a document management system. Users of the service are controllers in respect of personal data on third persons that is processed by means of f.i.t.. The service is designed in a way that facilitates the users' compliance with EU data protection law.

Image

Disclaimer:

This register is kept with the utmost care. However, EuroPriSe does NOT guarantee the accuracy of information found on the Site. Your reliance on information found on the Site is at your own risk.

Image

European Privacy Seal for REISSWOLF f.i.t.