Data Protection and Data Processing PolicyVersion: 1.1
Date: 23 April 2026
Document owner: Management
Approved by: Management1. PurposeThis policy defines the organisational and technical principles for protecting personal data within the organisation.The aims are:ensuring compliance with the GDPR and applicable international data protection lawsimplementing relevant requirements of ISO/IEC 27001reducing risks for data subjects and for the organisationintegrating data protection requirements into the information security management system (ISMS)This policy is a binding part of the ISMS.2. ScopeThis policy applies to:all business unitsall employees and managersexternal service providers with access to personal dataall IT systems, applications, infrastructure and processesIt covers all processing of personal data, regardless of storage location or technical platform.3. Embedding in the ISMS and risk managementThe protection of personal data is an integral part of information security risk management.Risks relating to personal data are identified and assessed as part of the general risk analysis.Protective measures are defined on a risk basis and reviewed regularly.Data protection requirements feed into the selection and implementation of security controls.Implementation follows the continuous improvement process (plan-do-check-act).4. Principles of data processingPersonal data are processed according to the following principles:lawfulness, fairness and transparencypurpose limitationdata minimisationaccuracystorage limitationintegrity and confidentialityThese principles follow Art. 5 GDPR and are implemented through appropriate organisational and technical measures.5. Roles and responsibilitiesManagement bears overall responsibility for compliance with this policy.System and process owners are responsible for implementing technical and organisational measures.Employees are obliged to comply with data protection requirements.External service providers are contractually bound to comply with corresponding data protection standards.Responsibilities are documented and reviewed at least annually.6. Technical and organisational measures (TOMs)The following measures in particular are implemented to ensure an appropriate level of protection:role-based access controlmulti-factor authentication for privileged accessencryption of data in transitencryption of stored data (risk-based)logging of security-relevant eventsbackup and restore proceduresregular security updatesnetwork segmentation (where required)physical access controls at relevant sitesThe effectiveness of the measures is reviewed regularly.7. Data protection by design and by defaultData protection requirements are taken into account as early as the planning phase of new systems and processes.The following applies:processing only the data that is necessaryintegrating protective measures into the system architectureprivacy-friendly default settingsdocumenting the basis for decisions8. Data classificationPersonal data are assessed within the general information classification.Possible protection levels:publicinternalconfidentialparticularly sensitiveThe classification affects the choice and intensity of protective measures.9. Record of processing activitiesA documented record is kept for relevant processing activities.It contains at least:the purpose of processingcategories of data subjectscategories of personal datarecipients or categories of recipientsretention periodstechnical and organisational measuresThe record is updated regularly.10. Retention periods and deletion conceptDefined retention and deletion periods apply to personal data.Principles:deletion once the purpose no longer appliesdeletion at the end of a contracttaking statutory retention obligations into accountdocumented deletion proceduresCompliance with deletion periods is reviewed regularly.When a contractual relationship ends, all personal customer data are deleted within a defined period, unless statutory retention obligations prevent this.Backups are subject to a rotating deletion concept and are overwritten automatically.
Complete deletion is documented.11. Data subject rightsThe organisation ensures that statutory data subject rights are upheld:accessrectificationerasurerestriction of processingdata portabilityobjectionRequests are documented, assessed and handled within statutory deadlines.A defined process for handling data subject requests is in place.
Requests from data subjects or clients are received through defined support or communication channels, documented and handled on time.The organisation supports clients and platform partners in implementing deletion, rectification and access requests.12. Processing on behalf and third partiesWhere personal data are processed by external service providers:this takes place solely on the basis of a data processing agreementappropriate technical and organisational measures are reviewedservice providers are assessed on a risk basisan up-to-date list of the processors used is maintainedInternational data transfers take place only in compliance with statutory requirements.13. Data protection incidentsPersonal data breaches are handled in accordance with the incident management policy.This covers:identification and assessmentdocumentationrisk-based decisions on notification obligationsnotification of the competent authorities within statutory deadlines (where required)notification of affected individuals (where prescribed)14. Training and awarenessEmployees receive regular awareness training on data protection and information security requirements.Training is documented.15. Monitoring and internal reviewCompliance with this policy is reviewed as part of internal controls.Deviations identified are documented and handled within the continuous improvement process.16. Review and updatingThis policy is reviewed and updated where necessary:at least once a yearin the event of significant organisational or technical changesin the event of changes in the law.Changes are documented with version control.17. Entry into forceThis policy takes effect on publication and is binding for all persons concerned. This English text is a convenience translation; the German version is the authoritative one.