Data protection information
DZ BANK AG (also referred to as simply DZ BANK) takes data protection and confidentiality very seriously and adheres to the provisions of the General Data Protection Regulation (GDPR) as well as current national data protection regulations. This data protection information offers you an overview of the processing of your personal data by DZ BANK within the framework of the whistleblowing system and informs you of your rights as a data subject in accordance with data protection law. Please read this data protection information carefully before submitting a report.
Who is responsible for the data processing, and who can you contact?
DZ BANK AG
Deutsche Zentral-Genossenschaftsbank, Frankfurt am Main
Platz der Republik
60325 Frankfurt am Main
Telephone: +49 69 7447-01
Fax: +49 69 7447-1685
Email: mail@dzbank.de
You can reach our company data protection officer at the address above
or by
Telephone: +49 69 7447-94101
Fax: +49 69 427267-0539
Email: datenschutz@dzbank.de
The whistleblowing system is run on behalf of DZ BANK by a specialised company, EQS Group GmbH, Bayreuther Str. 35, 10789 Berlin in Germany.
Personal data and information entered into the whistleblowing system are saved in a database operated by EQS Group GmbH in a high-security data centre. Only expressly authorised persons at DZ BANK can see the data. EQS Group GmbH and other third parties do not have access to the data. This is ensured by extensive technical and organisational measures within the certified process.
All data are encrypted and saved with multi-level password protection according to a permission concept that restricts access to a very small number of explicitly authorised recipients at DZ BANK.
Purpose of the whistleblowing system and legal basis
The purpose of the whistleblowing system is to prevent criminal business activity, protect the assets and reputation of DZ BANK and comply with statutory requirements. The whistleblowing system (BKMS® System) serves for securely and confidentially receiving, processing and managing reports concerning potentially illegal or harmful conduct. The processing of personal data within the framework of the BKMS® System is based on the legitimate interest of DZ BANK in discovering and preventing abuses and thereby averting damage to DZ BANK, its employees and customers.
The legal basis for this processing of personal data is Art. 6(1)(c) and (f) GDPR.
Type of collected personal data
Use of the whistleblowing system takes place on a voluntary basis. When you wish to submit a report using the whistleblowing system, we collect the following personal data and information:
- Your name, if your choose to reveal your identity, as well as other personal data shared by you within the report
- Potentially names of people or other personal data of people mentioned in the report.
Confidential handling of reports
Incoming reports are received and processed in a strictly confidential manner by a small circle of explicitly authorised employees and management staff at DZ BANK. Employees and managers of DZ BANK examine the situation and, if necessary, carry out further case-related fact-finding measures.
In the context of processing of a report, or during a special investigation, it may be necessary to forward reports to other employees of DZ BANK for further investigation insofar as this is required for the investigation.
Every person who receives access to the data is obligated to maintain confidentiality.
Information about the accused
Accused persons will be informed that DZ BANK has received a report about them once this information no longer endangers the investigation of the report. Your identity as whistleblower is not disclosed, as far as legally possible.
Rights of the data subject
Every data subject has the right to access as per Art. 15 GDPR, the right to rectification as per Art. 16 GDPR, the right to erasure ("right to be forgotten") as per Art. 17 GDPR, the right to restriction of processing (blocking) as per Art. 18 GDPR, the right to data portability as per Art. 20 GDPR and the right to object as per Art. 21 GDPR. You also have the right to appeal to a data protection supervisory authority as per Art. 77 GDPR.
Profiling
DZ BANK does not engage in any profiling.
Retention period of personal data
The documentation of the reports is retained for two years if the report was processed within the scope of the whistleblowing system or in the involved departments of DZ BANK. The retention period begins on 1 January of the following year after conclusion of the process. The processing of personal data is required to protect the legitimate interest of DZ BANK.
The documentation of the report will be erased immediately if the process is discontinued after completion of the initial review.
Only in an exceptional case can longer erasure delays arise if longer-term retention is necessary based on legal actions and the data are required as evidence or if statutory regulations require storage of the data beyond the two-year period.
Using the whistleblowing system
The communication between your computer and the whistleblowing system takes place over an encrypted connection (SSL). Your computer IP address will not be stored during your use of the whistleblowing system. In order to maintain the connection between your computer and the BKMS® System, a cookie is stored on your computer that contains only the session ID (a so-called session cookie). This cookie is only valid until the end of your session and expires when you close your browser. The legal basis for the temporary storage of these data and log files is Art. 6(1)(f) GDPR (legitimate interest).
It is possible to set up a postbox within the whistleblowing system that is secured with an individually chosen pseudonym/user name and password. This allows you to send reports to DZ BANK either by name or in an anonymous, safe way. This system only stores data inside the whistleblowing system, which makes it particularly secure. It is not a form of regular e-mail communication.
Note on sending attachments
During the report submission or when submitting additional information, you can send attachments to DZ BANK. If you wish to submit an anonymous report, please take note of the following security advice: Files can contain hidden personal data that could put your anonymity at risk. Remove this data before sending. If you are unable to remove this data or are uncertain about how to do so, copy the text of your attachment into your report text or send the printed document anonymously to the address listed in the footer, citing the reference number received at the end of the reporting process.
Dated: December 2020