The Danish authority closes the investigation on the Rejsekort app without issuing criticisms
The Danish Data Protection Authority (Datatilsynet) has closed its own-initiative investigation into the transport application "Rejsekort." The decision thoroughly analyzes the ongoing collection of location data when users forget to log out at the end of their journey, in light of the principles of data minimization and data protection by design, without however finding any infringement.
Facts and context
The Danish Data Protection Authority published a closure decision concerning the company Rejsekort & Rejseplan A/S, regarding the collection of location data by its mobile application.
The case began with an own-initiative investigation by the supervisory authority, focusing on the compliance of the "Rejsekort" application which replaces the physical transport card. The application uses the phone's GPS to track the user's journey, calculate the price, and distribute revenues among carriers. The central point of the investigation concerned the collection of location data that continues if a user forgets to finalize their journey ("check-out") in the application, thus collecting data unrelated to the service provided.
Reasons for the decision
The authority focused its analysis on two fundamental principles, without concluding a manifest violation, after balancing the arguments.
Data minimization obligation (Article 5(1)(c) of the GDPR): The authority examined whether the collection of location data after the actual end of the journey, in case of the user's failure to log out, was excessive. Such collection could potentially include sensitive data about places visited by the person. In its assessment, the authority weighed the fact that, according to the company, only a small proportion of users forget to log out. It also took into account measures implemented to limit this risk, such as user guides, reminder alerts, an optional "smart logout" function, and a forced automatic logout for inactive journeys once per day. However, the authority noted that several of these aids required activation by the user.
Data protection by design obligation (Article 25 of the GDPR): The authority assessed whether the design of the application, which allows this ongoing data collection by default in the absence of user action, complied with this principle. The question was whether the system should have been designed differently to inherently prevent such collection. The authority acknowledged that the user has the obligation to finalize their journey but also considered the technical safeguards implemented. After unsuccessfully seeking a clear position from other European authorities and the European Data Protection Board (EDPB) on this principle question, the authority proceeded with its own balancing.
Authority's decision
Consequently, the authority concluded that there was no sufficient basis to issue a criticism against Rejsekort & Rejseplan A/S and closed the case.
Lessons learned
This decision clarifies that:
The compliance of continuous location data processing, notably in case of the user's failure to log out, is assessed through a detailed balancing of risks and mitigation measures implemented.
The implementation of mitigating measures (such as reminder notifications, a smart logout option, and periodic forced logout) is a key factor in assessing respect for the principles of minimization and data protection by design.
Although the user has the obligation to complete their journey in the application, the service design must include safeguards to limit the consequences of a failure to log out, even if some of these safeguards require user action.
The lack of consensus at the European level on the interpretation of the principles of minimization and data protection by design in the context of similar applications may lead a national authority to a more lenient assessment in the absence of clear guidelines.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire