Analysis and Constructive Criticism of the Official Data Protection Impact Assessment of the German Corona-Warn-App
Rainer Rehak, Christian R. K\"uhne, Kirsten Bock

TL;DR
This paper critically analyzes the initial German Corona-Warn-App DPIA, highlighting its weaknesses and documenting improvements over time to enhance data protection practices and academic understanding.
Contribution
It provides a detailed critique of the initial DPIA's shortcomings and tracks subsequent improvements, offering insights into effective DPIA practices for health apps.
Findings
Initial DPIA focused narrowly on the app, neglecting infrastructure and processing procedures.
Subsequent revisions addressed some weaknesses, improving comprehensiveness.
Remaining gaps include insufficient safeguards discussion for third-party risks.
Abstract
On June 15, 2020, the official data protection impact assessment (DPIA) for the German Corona-Warn-App (CWA) was made publicly available. Shortly thereafter, the app was made available for download in the app stores. However, the first version of the DPIA had significant weaknesses, as this paper argues. However since then, the quality of the official DPIA increased immensely due to interventions and interactions such as an alternative DPIA produced by external experts and extensive public discussions. To illustrate the development and improvement, the initial weaknesses of the official DPIA are documented and analyzed here. For this paper to meaningfully do this, first the purpose of a DPIA is briefly summarized. According to Article 35 of the GDPR, it consists primarily of identifying the risks to the fundamental rights and freedoms of natural persons. This paper documents at least…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
