Are my data secure?
Personal data and COVID certificates are not stored on any central federal government systems
The federal government is responsible for data security when generating COVID certificates within the federal system.
When checking the COVID certificate using the verifier app provided by the federal government, only the information required to check and relate to a specific person is displayed.
Holders of a COVID certificate are responsible for keeping the certificate safe. They themselves decide who they present the COVID certificate to and what personal data they disclose.
If you use the dedicated COVID Certificate app, the COVID certificate is only stored locally on your mobile device.
Even when checking the COVID certificate, it is technically impossible for personal data to be stored – either on the Federal Administration’s servers or by third parties in the verifier app.
The COVID certificate contains a digital signature, which makes it forgery-proof. Access to the certificate on the mobile device can also be protected using Face ID, Touch ID or a PIN.
If you lose your COVID certificate, you can request another one from the issuer. You can read more on this here.
How the security of the certificate system is being tested
The COVID Certificate system – the system for generating and issuing COVID certificates – is open source and the software’s source code is publicly accessible.
Even before the system was rolled out a comprehensive public security test was conducted under the supervision of the National Cybersecurity Centre NCSC. IT and security specialists outside of the project team and the Federal Administration reviewed the source code as part of the test and reported their findings and observations to the NCSC.