Data protection information in accordance with Articles 13, 14 EU General Data Protection Regulation (GDPR) |
The data protection statement below is intended to provide you with a clear, transparent and concise explanation of how your personal data is processed by us. If, having read it, you require further clarification or have other queries on data protection at PwC, please contact our data protection officer at DE_Datenschutz@pwc.com or by using the additional contact details provided below. |
1. Controller
The controller within the meaning of Art 4 no 7 GDPR for the processing of your personal data is: |
2. Data Protection Officer
PwC WPG has appointed a data protection officer in accordance with Art 37 GDPR. You can reach the Data Protection Officer of PwC WPG, Dr Tobias Gräber, at the following contact details: Address for postal contact:
PricewaterhouseCoopers GmbH Wirtschaftsprüfungsgesellschaft |
3. Rights of the data subject/your rights under data protection lawYou have the following rights under applicable data protection law with respect to personal data concerning you: Right of access
You can request information from us at any time about whether and which personal data we store about you. The provision of information is free of charge for you. Right to rectification If your personal data stored by us is inaccurate or incomplete, you have the right to obtain rectification of this data from us at any time. Right to erasure You have the right to request that we erase your personal data if and to the extent that the data is no longer needed for the purposes for which it was collected or, if the processing is based on your consent, you have withdrawn your consent. In this case, we must stop processing your personal data and remove it from our IT systems and databases. A right to erasure does not exist insofar as
Right to restrict processing You have the right to request that we restrict the processing of your personal data. Right to data portability You have the right to receive from us the data you have provided in a structured, common and machine-readable format, as well as the right to have this data transferred to another controller. This right only exists if
Right to object to processing If the processing of your data is based on Art 6 para 1 lit f) GDPR, you may object to the processing at any time. You may assert all of the data subject rights described above against PwC WPG by addressing your specific request to the following contact details:
PwC WPG has appointed a data protection officer in accordance with Art 37 GDPR. You can reach the Data Protection Officer of PwC WPG, Dr Tobias Gräber, at the following contact details: By mail:
PricewaterhouseCoopers GmbH WPG |
4. Right to lodge a complaint with a supervisory authorityIn accordance with Art 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data by PwC infringes data protection law. |
5. Provision of dataAlthough some data is automatically transferred when you visit our homepage, you are not under any statutory or contractual obligation to provide data relating to your use of our homepage. However, data is required in order to conclude a contract with us when you book an event. You can still choose not to provide this data, but we cannot conclude a contract without it. With respect to the contact form and contacting us by e-mail, here again you are free to choose whether or not to send us data using these channels, but we cannot process or answer any of your inquiries if you do not use them to contact us. |
6. Description of the data processing on the website/app and legal basis for the processing6.1 Recipient of the dataIn order to fulfil the processing purposes listed below, data is also transferred to third parties. This may also include the transfer of personal data to European and non-European countries and the storage of data outside the EU or the European Economic Area (EEA).
Recipients bound by instructions PwC is a member of the global PwC network, which consists of the individual legally independent and independent PwC firms. In the course of our activities, we use other German or foreign PwC network companies as network-internal IT service providers bound by instructions, which provide services for the operation, maintenance and care of the IT systems and applications used by the PwC network companies. This is in particular PwC IT Services Ltd. based in the United Kingdom (UK). If we pass on data to service providers bound by instructions, we do not require a separate legal basis for this.
Independent recipients In addition, in individual cases, we also pass on your data to other third parties, such as public authorities, courts or other bodies, if we are required by law or by official or court order of an EU member state to disclose personal data to these bodies. These bodies also use the data on their own responsibility. Insofar as you have explicitly consented, Art 6 para 1 lit a) GDPR is the legal basis for the data transfer. If there is a legal obligation to disclose the data, the legal basis for the data transfer is Art 6 para 1 lit c) GDPR. If, on the other hand, the disclosure is necessary for the fulfilment of a contractual or pre-contractual measure with you as a natural person, Art 6 para 1 lit b) GDPR is the legal basis. Otherwise, the transfer is based on our legitimate interests and the legal basis is Art 6 para 1 lit f) GDPR. We and the other companies in the PwC network have an interest in making our work processes efficient and in sharing business processes within the PwC network for this purpose.
Data transfer to recipients in third countries outside the EU/EEA
For data transfers within the PwC network, the PwC network companies have, among other things, concluded an internal data protection agreement which provides for compliance with the EU standard contractual clauses of the EU Commission within the meaning of Art 46 para 2 lit c) GDPR for the transfer of personal data from EU/EEA countries to PwC network companies outside the EU/EEA. 6.2 Processing of personal data when accessing the websiteWhen you visit our website, we collect the data that is technically necessary to display this website to you. This involves the following personal data which is automatically transmitted to our server by your browser:
The processing of this personal data is based on Art 6 para 1 lit f) GDPR. The website cannot be accessed and offered to users without using such data; there is a legitimate interest in making the call-up and use of the website technically possible. The aforementioned data will be stored for 7 days and then deleted. This website is hosted by a service provider [SFDC Germany Data Centre GmbH, München, Clemensstr. 30, c/o Dr. Samara, Chryssanthe, 80803 München], the data collected on our website is therefore stored on the service provider's servers. The server locations are also located in European and non-European countries. Data is transferred abroad, including to countries outside the European Union or the European Economic Area. An adequate level of data protection is ensured by the use of standard contractual clauses of the EU Commission within the meaning of Art 46 para 2 lit c) GDPR. 6.3 Contact by emailYou can find the email addresses of contact persons on the event page. You can also contact us by email. If you contact us, the data communicated by you (in particular your email address, your first and last name, and the text of your enquiry, as well as any additional information you may have provided in the contact form or by email) will be stored by us in order to process your enquiry and answer your questions. Data processing is justified in accordance with Art 6 para 1 lit f) GDPR. We have an interest in contacting you via the website in response to your request. If your request is aimed at fulfilling a contractual or pre-contractual measure with you as a natural person, the legal basis for the data processing is Art 6 para 1 lit b) GDPR. The data provided when you contact us or make an enquiry is erased by us once it is no longer necessary for processing your enquiry. Insofar as there is a legal obligation to retain data, the data will be stored for the duration of the legally required retention period. 6.4 Provision of high-quality eventsIf you wish to register for a high-quality event that can be booked on our website, you give us marketing consent in return and we process the data provided by you in connection with the consent (in particular your first and last name, your email address, the name and address of your company, if applicable, and any other information you provided when giving your consent). We validate the email address you provide using the double opt-in procedure. Further information on this can be found in the section "Organisational management of your consent". The data processing for booking the respective event is based on a contract with you (Art 6 para 1 lit b) GDPR). The subsequent marketing communication, on the other hand, is based on your consent (Art 6 para 1 lit a) GDPR). Further information regarding the processing of your data in the context of marketing communication can be found in the section "Individualised electronic contact by PwC DE". 6.5 Processing operations in marketing and partly joint controllersPwC WPG determines the means and purposes of some of the marketing data processing operations described in more detail below, either alone or together with other companies of the German-speaking PwC network named here (all named companies hereinafter jointly: "PwC DE"). PwC WPG and these other named PwC DE firms of the PwC network therefore process your data as joint controllers within the meaning of Art 4 no 7, 26 GDPR. 6.5.1 Individualised electronic approach by PwC DE PwC DE companies process your personal data and will contact you by email for marketing purposes if you have provided consent for direct marketing purposes. For this purpose, we process the data provided by you in connection with the consent (in particular your first and last name, your email address, the name and address of your company, if applicable, and any other information you provided when giving your consent). This direct marketing by PwC DE companies includes PwC DE information on current advisory services and service information, news from your industry, announcements for upcoming events, information on PwC studies (including those of other PwC network companies) and other marketing information. Based on your consent, PwC DE may tailor and individualise marketing communications to your interests. PwC DE does this by analysing your interests, which you have explicitly communicated (e.g. via a preference centre on a PwC DE website), and your usage behaviour (e.g. content accessed, opening, clicks and reading time) both with regard to newsletters and similar communications and via linked PwC DE websites using cookies, web beacons and similar technologies and storing this information in a personal profile. Based on your consent, PwC DE may also add your personal contact details (e.g. name, title, company and role/position) that you have provided yourself on a PwC DE website and/or that are already stored in the customer relationship management systems operated by PwC DE to this profile created in this way. Based on your consent, PwC DE may also add public information about the company you work for to this profile. The processing is carried out on the basis of your consent, which constitutes a legal permission according to Art 6 para 1 lit a) GDPR. You can withdraw your consent at any time with effect for the future at no additional cost, e.g. by email to DE_Datenschutz@pwc.com. Your data will be stored for this purpose as long as it is required for direct marketing and you have not revoked your consent. Insofar as there is a legal obligation to retain data, the data will be stored for the duration of the legally required retention period. 6.5.2 Organisational management of your consent PwC DE also processes your personal data to meet organisational requirements with regard to your marketing consent. This includes, for example, the validation of the email address you provided through a so-called double opt-in process and documenting the status (granting or revoking your consent and validating your email address) in a list jointly maintained by PwC DE for this purpose. The data processed for this purpose includes the contact details you provided when granting consent, your IP address, the individual identifier assigned by our IT systems, as well as the status and time of the granting of your consent. If you withdraw your consent and/or object to the data processing, PwC DE will no longer use your data for marketing purposes. PwC DE will store the data required for the organisational management of your consent beyond the time of your revocation and/or objection in order to fulfil documentation and verification requirements and to ensure that your data is not processed by PwC DE for marketing purposes in the future (so-called blocking list), unless you provide new consent. PwC DE will delete your data when these organisational purposes cease to apply, which will generally be after a period of three years at the end of the year following the cessation of marketing activity by PwC DE. 6.5.3 Postal address and existing customer marketing PwC DE will also use the information you provide (in particular your name and address) to send you marketing information by post about other offers or events. PwC WPG will use your contact details received in connection with the sale of a service (in particular your first and last name, your email address, the name and address of your company, if applicable, as well as any other details you may have provided) for the purpose of direct marketing of similar goods and services by electronic mail, unless you have objected to such use. You can object to this use at any time without incurring any costs other than the transmission costs according to the basic rates. This processing is based on our legitimate interests within the meaning of Art 6 para 1 lit f) GDPR. There is a legitimate economic interest in informing interested parties, customers and clients about further offers and events of our own in order to establish and maintain a long-term customer relationship. Your data will be stored for this purpose as long as this is necessary for the postal marketing approach and existing customer marketing and you have not effectively objected to the data processing. Insofar as there is a legal obligation to retain data, the data will be stored for the duration of the legally required retention period. |
7. Use of cookiesIn order to make visiting our website attractive and to enable the use of certain functions, we and certain third parties use cookies on our website. These are small text files that are stored on your terminal device. Some of the cookies we use are deleted after the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your terminal device and enable us or our partner companies to recognise your browser the next time you visit us (so-called persistent cookies). The following cookie categories are used: 7.1 Cookies technically required for the operation of our website:These cookies are technically required for the operation and functionality of the website. They make the website technically accessible, secure and usable and provide essential and basic functionalities, such as navigation on the website, correct display of the website in the internet browser or consent management.
7.2 Analytics/Analysis cookies:The analysis cookies enable us to collect data in an aggregated form about our website visitors and their experiences on our website. We use this data to fix bugs and improve the experience for all visitors.
The legal basis for the use of technically required cookies is § 25 para 2 no 2 Telecommunications-Telemedia Data Protection Act (TTDSG) or on the basis of Art 6 para 1 lit f) GDPR to protect our legitimate interests. In particular, our legitimate interests lie in being able to provide you with a technically optimised website that is user-friendly and tailored to your needs, and to ensure the security of our systems. The legal basis for consent with regard to the storage and reading of information is § 25 para 1 TTDSG and, with regard to the processing of personal data, Art 6 para 1 lit a GDPR. The consent includes all cookies selected by you and the storage of information associated with them on your terminal device, as well as their subsequent reading and subsequent processing of personal data. Insofar as we use cookies on the basis of your consent, you can revoke your consent at any time with effect for the future, e.g. by adjusting your cookie settings here. Your revocation does not affect the lawfulness of the processing carried out until revocation. 7.3 Marketing cookies:These cookies enable us to alert you to relevant PwC advertising campaigns and to show you personalised PwC content based on your interests, including on third-party websites. In addition, we can use so-called targeting to limit the frequency of appearance of an advertisement and reduce the display of advertising for you.
7.4 Disabling cookie settingsMost browsers are pre-set to accept cookies automatically. You can object to the creation of cookies by disabling cookies in your browser's system settings. Please note, however, that some of the cookies are technically required for the functionality of our website, as otherwise the page cannot be accessed and displayed. By disabling cookies, you will not be able to use parts of the website (without restrictions). We only use cookies that are not technically required for the functionality of our website with your prior express consent. In addition, you can also control the installation of cookies yourself at any time by changing your browser settings and/or deleting all cookies. Cookie settings |
8. Links to social mediaOur website currently contains links to the following social media providers: Twitter, LinkedIn, YouTube and Instagram by means of corresponding social media buttons. In order to prevent any unwanted transfer of your usage data (e.g. address of the currently visited page) to these services, you only access the services by clicking on the link. On the service page, these social networks mentioned may collect usage data and possibly user data. We have no influence on the collected data and data processing procedures, nor are we aware of the full extent of the data collection, the purposes of the processing or the storage periods. We also have no information on the deletion of the collected data by the plug-in provider. Therefore, we inform you according to our current knowledge: Only when you access the links does your browser possibly establish a direct connection with the servers of the aforementioned services. In this way, the information that you have visited our website is forwarded indirectly (referrer) to these services. If you are already logged in to the service with your personal user account while visiting our website, you can usually "share" the document (so-called "sharing") or leave a comment etc. after clicking on the social media buttons. If you do not wish such data transmission, we advise you not to click on the social media buttons. The purpose and scope of the data collection by the social services, as well as the further processing and use of your data there, as well as your rights in this regard and setting options for protecting your privacy, can be found in the data protection notices of these services. |
9. Integration of MediasiteWhen you view a video that is displayed with a thumbnail on the website (not just a link to another platform with a video), we collect the necessary data to show you the video. The following personal data is required for this purpose:
The processing of this personal data is based on Art. 6 para. 1 lit. f) DSGVO. This is necessary, since the communication runs via internet/intranet and is established on the basis of the Internet Protocol (IP). Furthermore, the use of the stream is determined on the basis of the IP communication. The video cannot be called up and provided without the use of this data; there is a legitimate interest in making the call-up and making the use of the video technically possible. The data stated above is stored for the duration of viewing/streaming and then deleted. If there are legal storage obligations, the data will be stored for the duration of the legally prescribed storage obligation. |
10. Integration of SmartMapsOn this website we use the "SmartMaps" service of YellowMap AG, CAS-Weg 1-5, 76131 Karlsruhe. This allows us to show you maps directly on the website and enables you to use the map function conveniently. In order to be able to show you the maps, SmartMaps uses your IP address when the SmartMaps components are called up by the browser. This is held in the memory of the web server for approx. 5 minutes to prevent DoS attacks, after which it expires and is neither processed nor stored in any other way. YellowMap AG is therefore a recipient of data. However, YellowMap AG does not process the data for its own purposes, but exclusively on behalf of and on the instructions of PwC. PwC has concluded a data processing agreement with YellowMap AG in accordance with Art 28 GDPR. |
11. Use of Friendly CaptchaFor certain online services on our website we use the "Friendly Captcha" solution provided by Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany. Friendly Captcha blocks non-human and automated entries and protects our website against spam-bots and abuse. The following personal data is transmitted in the process:
Processing of such personal data is carried out on the basis of Article 6(1)(f) GDPR. There is a legitimate interest in the functioning and secure operation of our website. To the extent personal data is processed, it is stored for 30 days and then deleted. Friendly Captcha GmbH is thus the recipient of data. However, it does not process the data for its own purposes, but solely on behalf of and on the instructions of PwC. PwC has entered into a commissioned data processing agreement with Friendly Captcha GmbH in accordance with Article 28 GDPR. |
12. LinksOur website contains hyperlinks to websites/services of other providers. When activating these hyperlinks, you will be redirected from our website directly to the website of the other provider. You will recognise this by the change of URL, among other things. We cannot accept any responsibility for the confidential handling of your data on these third-party websites, as we have no influence on whether these companies comply with data protection regulations. Please inform yourself about the handling of your personal data by these companies directly on these websites. |