IMY (Sweden) - 2024-2347
| IMY - 2024-2347 | |
|---|---|
| Authority: | IMY (Sweden) |
| Jurisdiction: | Sweden |
| Relevant Law: | Article 28(1) GDPR Article 32(1) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 06.05.2025 |
| Published: | |
| Fine: | n/a |
| Parties: | Consulate General of Sweden in Istanbul |
| National Case Number/Name: | 2024-2347 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Swedish |
| Original Source: | IMY (in SV) |
| Initial Contributor: | cci |
The DPA audited the Consulate General of Sweden in Istanbul and ordered it to address security issues related to the processing of physical documents and the verification of the identify of authorized personnel.
English Summary
Facts
The DPA carried out an ex officio investigation of the Consulate General of Sweden in Istanbul (the controller)[1] in order to assess its compliance with the GDPR and other Regulations (the VIS Regulation and the Borders Regulation).
During the investigation, the DPA carried out an on-site inspection of the Consulate. The DPA also assessed the operations of VSF Global (the processor), an external provider responsible for transmitting most of the VISA applications received by the Consulate. Applications were collected on the processor’s premises, which included an area reserved for the personnel of the Swedish mission. This area was secured via a biometric locking system that recognized the fingerprints of authorized personnel.
Holding
The DPA found that access to the reserved area of VSF’s center, was not properly secured. When the biometric system repeatedly failed to capture a high-quality fingerprint image, an officer could override the system and allow the image despite its insufficient quality. In practice, the override window of the system was always open and the officer would allow access without checking why the override was needed in the first place. The DPA held the system to be unsecure.
Furthermore, the DPA found that the passports of VISA applicants[2] were stored in boxes and placed on the floor. The DPA held that this practice was also insecure and unappropriate, as it would be easy to lose documents.
On these grounds, the DPA concluded that the controller violated Articles 28(1) and 32(1) GDPR and ordered the controller to address the shortcomings it found.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.
1(7) Consulate General of Sweden in Istanbul Sent only by email generalkonsulat.istanbul@gov.se File number: Decision after supervision according to VIS, SIS- IMY-2024-2347 and the Data Protection Regulation – Date: Consulate General of Sweden in Istanbul 2025-05-06 1. Decision of the Privacy Protection Authority The Privacy Protection Authority (IMY) finds that the Consulate General of Sweden in Istanbul processes personal data in violation of - Article 28(1) and Article 32(1) by not ensuring that the external service provider maintains sufficient security around the collection of biometric data and when handling physical documents. The Swedish Data Protection Authority, based on Article 58(2)(d) of the Data Protection Regulation, orders the Consulate General of Sweden in Istanbul to submit a written report to the Swedish Data Protection Authority with a description of the measures that the Consulate General has taken or intends to take to remedy the identified shortcomings. The action plan must be received by the Swedish Data Protection Authority no later than three months after this decision has entered into force. 2. Report on the inspection case 2.1 Purpose and method of the inspection The Swedish Data Protection Authority has initiated an inspection of the Consulate General of Sweden in Istanbul (hereinafter referred to as the Consulate General) with the aim of investigating the Consulate General's processing of personal data in connection with visas in accordance with the VIS Regulation, the Border Regulation and the Data Protection Regulation. The inspection has also covered the Consulate General's use of an external service provider, VFS Global, for the processing of visa applications. IMY is required by the VIS Regulation and the Borders Regulation to regularly audit how so-called end-users handle personal data in VIS and SIS. The Consulate General in Postal address: Istanbul has been selected for audit primarily due to the high percentage Box 8114 104 20 Stockholm 1Regulation (EC) No 767/2008 of the European Parliament and of the Council of 9 July 2008 concerning the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas. www.imy.se 2Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and Email: use of the Schengen Information System (SIS) in the field of entry and exit checks, amending the Convention implementing the Schengen Agreement and amending and repealing Regulation (EC) No 1987/2006. imy@imy.se 3Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC Page 1 of 7Integrity Protection Authority Case number: Consulate General of Sweden Istanbul 2(7) Date: 2025-05-06 visa applications that go through Turkey. The Consulate General is an end user of both the VIS and SIS systems and a user of the Swedish Migration Board's case management systems Wilma and W2. IMY has reviewed the processing of personal data during an on-site inspection of the embassy in Istanbul in March 2024. During the review, IMY has asked employees at the migration unit questions and observed when the employees were handling visa cases. The site inspection also included an inspection of the external service provider. IMY has asked questions to representatives of the service provider and observed the employees' work with receiving visa applications, valuable documents, and recording alphanumeric data and biometrics. IMY has also inspected VFS Global's handling of the documents submitted by the applicant. In addition, a questionnaire and supplementary questions have been sent to the Consulate General, which has received supplementary statements. 2.2 About the Consulate General's handling of personal data in visa applications During the inspection, the following has mainly emerged. Processing of visa applications The migration unit at the Consulate General handles visa cases. Each year, the unit processes approx. 16,000 visa applications. The unit employs both seconded from the Migration Board and local employees. It is the Migration Board's secondees who are the decision-makers in visa cases. The processing takes place in the Migration Board's Wilma and W2 systems, which the caseworkers access via UM Net, the missions' intranet. UM Net is in turn accessed via the Government Offices' intranet. VIS is built into W2 and can only be accessed through that system. The Consulate General has two biometric stations on site for recording the biometrics required for visa applications, but the absolute majority of applicants submit their data to the external service provider VFS Global, which has four visa centers in Turkey. The biometric and alphanumeric data collected by VFS Global is sent electronically to the Consulate General, while the physical documents, such as passports and certificates, etc., are sent in locked mail. Training and security Local employees and those seconded have different access rights to Wilma and W2. Local employees only have viewing access to Wilma and no decision-making ability in W2. Only decision-makers can search SIS and see more detailed information about so-called VIS blocks etc. Before an employee is granted authorization, he or she must undergo a number of training courses, including data protection, which are carried out online. The biometrics and alphanumeric data collected by VFS Global are sent electronically to the Consulate General; VFS Global has no access to Wilma or W2. The Consulate General, in cooperation with other Nordic countries, carries out inspections at VFS 4Schengen Information System Page 2 of 7Integrity Protection Authority Filing number: Consulate General of Sweden Istanbul 3(7) Date: 2025-05-06 Global every nine months according to a rotating schedule to check that, among other things, the personal data processing carried out is correct. 2.3 VFS Global's handling of personal data as a data processor During the inspection, IMY also inspected the external service provider's visa center in Istanbul, which receives visa applicants on behalf of the Consulate General. Between the Government Offices and VFS Global, a framework agreement has been established with an attached data processor agreement between the Swedish Migration Board and VFS Global, which regulates the personal data processing VFS Global performs in connection with visa applications to Sweden. In addition, there is a local agreement between VFS Global's Turkish company and the Swedish Consulate General in Istanbul / the Swedish Migration Board. During the inspection of VFS Global's center in Istanbul, the following mainly emerged. VFS Global receives the applicant at the center, where they carry out an initial check to see whether the applicant is the same as the passport states. The center has written information about the rights of the data subjects in English and Turkish. All applicants sign a consent to the processing of personal data in connection with their application. Access to the part of the premises where the staff are located requires biometric unlocking. As a rule, only staff trained for the Swedish mission should work on applications to Sweden. Employees at the centre undergo mandatory training in, among other things, data protection and information security. VFS Global's biometric stations have a built-in quality system and capture biometrics when the images have reached a certain quality standard. After a number of attempts, the system informs you of which fingers are not approved or of lower quality. The officer then tries to take new images of the fingers that were not approved. If this fails, the officer can make a so-called override but then needs to write the reason for this. During the inspection, IMY was given the opportunity to observe how the capture of biometrics is carried out. IMY then observed two officers taking the applicant's fingerprints. These were not approved by the biometric station and several attempts were made. IMY noted that an officer on a couple of occasions made a so-called supervision override, which means that another colleague needed to approve an action taken by the case officer. However, the approval was made without reviewing what had been done because the box where the person would fill in their details to approve was already up. During the inspection, IMY also noted that the applicants' passports were in boxes on the floor behind the employees who were working. The majority of the boxes belonging to the missions of different Member States were behind the employees who worked with the recording of biometrics. Page 3 of 7Integrity Protection Authority Case number: Consulate General of Sweden Istanbul 4(7) Date: 2025-05-06 3. Justification of the decision 3.1 Applicable legislation The rules on the Member States' handling of visa applications to the Schengen area are set out in the VIS Regulation and the so-called Visa Code. In the case of 5 visa applications, the applicant is checked against the Schengen Information System (SIS) to check whether there are any records relating to the person in the system. The processing of personal data in SIS by the visa authorities is primarily regulated in the so-called Borders Regulation. It follows from Article 51 of the Borders Regulation that the Data Protection Regulation shall apply to the processing of personal data carried out by 7 competent authorities in accordance with the Borders Regulation. It is clear from recital 17 of the VIS Regulation and from Article 94 of the Data Protection Regulation that the provisions of the Data Protection Regulation apply to the processing of personal data by the Member States in accordance with the VIS Regulation. The processing of personal data by the Swedish Migration Board and foreign missions is also regulated by supplementary legislation in the Aliens Data Protection Act (2016:27). IMY's corrective powers follow from the Data Protection Regulation. 3.2 Scope of the audit and IMY's assessment During the audit, IMY has checked whether the Consulate General's personal data processing complies with the legislation described above under 3.1. During the inspection, IMY has particularly focused on the rights of individuals, the security of the personal data that is processed and that employees have the required training. During the inspection, IMY has noted shortcomings in the security of the processing of personal data and the responsibility that the Consulate General has to ensure that the personal data processor VFS Global handles personal data in a manner that is compatible with the Data Protection Regulation, the VIS Regulation and the Border Regulation. IMY's assessments in these parts are set out below. Otherwise, IMY has no comments on the processing. 3.3 Security of the processing of personal data Article 32(1) of the GDPR requires the controller to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk represented by the processing. This, according to the same provision, must take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons. According to Article 28(1) of the GDPR, the controller must only use processors who provide sufficient guarantees to implement appropriate 5Regulation (EC) No 810/2009 of the European Parliament and of the Council of 13 July 2009 establishing a Community Code on Visas (Visa Code). 6Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of entry and exit checks, amending the Convention implementing the Schengen Agreement and amending and repealing Regulation (EC) No 1987/2006. 7See also recital 36 of the Borders Regulation. Page 4 of 7Integrity Protection Authority Filing number: Consulate General of Sweden Istanbul 5(7) Date: 2025-05-06 technical and organisational measures in such a way that the processing meets the requirements of the Data Protection Regulation. Article 28(3) states that the processor may only process personal data on documented instructions from the controller (point a) and that the processor shall take all the measures required by Article 32 (point c) of the Data Protection Regulation. During the inspection of the external service provider, VFS Global, which is the personal data processor of the Consulate General, IMY noted two different deficiencies. Firstly, it was noted that the documents submitted by the visa applicant, such as valuable documents in the form of passports and the like, were stored in plastic bins on the floor of the staff. The space was limited and biometrics capture for several different countries' missions took place next to each other. Given the high number of personnel involved and the space where the bins were stored was open to the staff, it can be questioned how appropriate it is to store the documents in this way. It seems relatively easy to mix up or lose documents in the way that the documents were handled. The handling also makes it more difficult to track the document and ensure its security from external influences. Secondly, it was noted that the security measures for approving fingerprints, which do not reach a sufficiently good quality at the biometric station, were waived when taking biometrics from applicants. The built-in security feature that another employee must approve a so-called override of a non-approved fingerprint requires that the employee who approves makes an actual check of the quality of the fingerprint and does not approve the fingerprint in the way that was noted during the inspection. In order to ensure that the fingerprints that are taken are of sufficiently good quality throughout the process and that the information taken is correct, measures should be taken to prevent a so-called override from being made without the necessary control. In light of the two identified deficiencies in VFS Global's handling, IMY finds that the Consulate General of Sweden in Istanbul processed personal data in violation of Articles 28(1) and 32(1) of the General Data Protection Regulation by failing to ensure that VFS Global's collection of biometric data complies with built-in security measures and by failing to ensure that applicants' documents are handled in a sufficiently secure manner by VFS Global. 3.4 Choice of intervention It is clear from Article 58(2) and Article 83(2) of the GDPR that the IMY has the power to impose an administrative fine. Depending on the circumstances of the individual case, an administrative fine shall be imposed in addition to or instead of the other measures referred to in Article 58(2), such as an injunction or a ban. Furthermore, Article 83(2) sets out the factors to be taken into account when deciding whether to impose an administrative fine and when determining the amount of the fine. In the case of a minor infringement, the IMY may, as set out in recital 148, instead of imposing a fine, issue a reprimand pursuant to Article 58(2)(b). Aggravating and mitigating circumstances in the case shall be taken into account, such as the nature, severity and duration of the violation and previous violations of relevance. IMY has observed the following relevant circumstances in its assessment. VFS Global is a personal data processor for the Consulate General. As explained above, the personal data controller is obliged to ensure that it only engages Page 5 of 7Integrity Protection Authority Filing number: Consulate General of Sweden Istanbul 6(7) Date: 2025-05-06 personal data processors who, when processing personal data, meet the requirements of the General Data Protection Regulation. The Consulate General receives a large number of visa applications annually through VFS Global, which handles large amounts of documents and applications on a daily basis. With this extensive processing of personal data comes a special responsibility to ensure that the data is processed correctly. During the inspection, IMY noted that many good examples of protective measures were in place. However, with regard to the handling of biometric data and physical documents at the external service provider, it is noted that measures need to be taken to ensure that data of insufficient quality is not collected or that individuals' valuable documents are lost. Given the extensive processing of data, a deficiency could have major consequences. However, it has not emerged during the inspection that such incidents have occurred. In summary, none of the deficiencies that IMY has identified are considered so serious that a penalty fee would be applicable. However, it is important that the deficiencies are addressed. IMY notes that there are grounds to, in accordance with Article 58(2) of the Data Protection Regulation, order the Consulate General to, in dialogue with the external service provider, provide IMY with an action plan to address the deficiencies that were identified during the inspection. The Consulate General shall report the action plan to IMY no later than three months after this decision has entered into force. __________________________ This decision has been made by the Head of Unit Jonas Agnvall after a presentation by the lawyer Elena Mazzotti Pallard. Jonas Agnvall Copy to the Swedish Migration Board's Data Protection Officer, dataskyddsombud@migrationsverket.se 8See recital 148 of the Data Protection Regulation. Page 6 of 7Integrity Protection Authority Case number: Consulate General of Sweden Istanbul 7(7) Date: 2025-05-06 How to appeal If you wish to appeal the decision, you must write to IMY. Indicate in the letter which decision you are appealing and the change you request. The appeal must have reached IMY within three weeks of the day you received the decision. If you are a party representing the public, the appeal must be received within three weeks of the date on which the decision was announced. If the appeal has been received in good time, IMY will forward it to the Administrative Court in Stockholm for review. You can e-mail the appeal to IMY if it does not contain any privacy-sensitive personal data or information that may be subject to confidentiality. The authority's contact details are provided on the first page of the decision. Page 7 of 7
- ↑ See Article 3(3) GDPR: "This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law".
- ↑ See Article 2(1) GDPR: "This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system".




