From ad95dfd52b497f1aa072bc707dacd2787936dbeb Mon Sep 17 00:00:00 2001
From: Felix Schmidt
your random IDs from the last 14 days) as well as optional information you provide about the
onset of your symptoms and event IDs will be forwarded to the server system and then to users of
the Corona-Warn-App as part of the positive lists.
+
The RKI has commissioned T-Systems International GmbH and SAP Deutschland SE & Co. KG to operate and maintain part of the technical infrastructure of the app (e.g. server system, hotline), meaning that these two companies are processors under data protection law and acting on the @@ -1552,9 +1554,13 @@
If, in the situations where it is required by law, you present a COVID Certificate to other persons or entities (for example, European border authorities or service providers), they will become aware of all the data contained in the certificate. +
+You can prevent this by only presenting the QR code of the COVID Certificate in the app, so that it can be scanned using a verification app (e.g. as proof of your vaccination status and entitlement to certain exemptions under coronavirus restrictions). Then, only the data contained @@ -1566,6 +1572,8 @@
During certificate verification for ticket bookings, your COVID certificates and booking information are transmitted to a verification partner used by the provider. The specific verification partner is displayed in the app before transmitting the information. To retrieve @@ -1579,6 +1587,8 @@
Users of the Corona-Warn-App can retrieve the latest positive lists regardless of where they are (even if they are abroad on holiday or on a business trip, for example). +
+In addition, the confirmation of the authenticity of your app may involve the transfer of data to a country outside the EU. The identifier generated by your smartphone, which contains information about the version of your smartphone and the app, will be transmitted to the @@ -1589,6 +1599,8 @@
Otherwise, the data transmitted by the app is processed exclusively on servers in Germany or in another country in the EU (or the European Economic Area), which are therefore subject to the strict requirements of the General Data Protection Regulation (GDPR). @@ -1743,7 +1755,7 @@
- If the hash value of the electronic signature is temporarily stored when a digital COVID - certificate is updated, this does not enable the RKI to determine the identity of certificate - holders (see Section 6 o.). -
If the hash values of the electronic signatures are temporarily stored when a digital COVID certificate is updated, this does not enable the RKI to determine the identity of certificate @@ -1783,5 +1790,6 @@