Privacy Notice pursuant to Articles 13 and 14 of the EU General Data Protection Regulation (GDPR)

This privacy notice is intended for our clients and customers, our points of contact at clients and customers, our service providers and points of contact at our service providers, as well as other business contacts of PwC.

You have a business relationship with PwC because either you yourself or your employer is a client or prospective client of PwC Certification Services GmbH (hereinafter: “PwC Cert”), or because you have had business contact with PwC Cert or PwC Cert personnel—for example, at events, during proposal presentations, or in other ways—and we have obtained your contact information from you in this manner.

This privacy notice describes how PwC Cert processes your personal data in connection with the provision of audit, review, and certification services, particularly in the areas of services and management systems or other engagements. In addition, we inform you about how PwC Cert processes the personal contact data of clients, contacts, and other business contacts for the purpose of establishing, maintaining, and ensuring continuity in business relationships.

“Personal data” in this document refers to personal data as defined in Article 4(1) of the GDPR. This includes all information relating to a person (a natural person) that can be used to identify that person directly or indirectly.
The following privacy notice is intended to explain in a clear, transparent, and concise manner how we process your data. If you still have any questions or other inquiries regarding data protection at PwC Cert, please feel free to contact our Data Protection Officer, Dr. Tobias Gräber, at DE_Datenschutz@pwc.com or using the contact information provided below.

Data Controller

The controller, as defined in Article 4(7) of the EU General Data Protection Regulation (GDPR), for the processing of your personal data is:
PwC Certification Services GmbH
Friedrich-Ebert-Anlage 35-37
60327 Frankfurt am Main, Germany
Main Switchboard: +49 69 9585-0
Fax: +49 69 9585-1000

Data Protection Officer

PwC WPG has appointed a Data Protection Officer in accordance with Article 37 of the GDPR. You can contact PwC WPG’s Data Protection Officer using the following contact information:

Email:DE_Datenschutz@pwc.com
Phone: +49 69 9585-0

Mailing Address:
PricewaterhouseCoopers GmbH WPG
Data Protection Officer
Friedrich-Ebert-Anlage 35-37
60327 Frankfurt am Main, Germany

Purposes of Processing and Legal Basis for Processing

PwC Cert processes your personal data for the following purposes.

Data Processing for the Purpose of Contract Initiation and Performance

PwC Cert processes your personal data to carry out pre-contractual measures (such as preparing quotes, conducting internal pre-contractual compliance reviews, or drafting contracts) as well as to provide the contractually agreed-upon services, including the administrative execution and billing of the engagement. The legal basis for the processing is Article 6(1)(b) of the GDPR. In this context, your contact information—such as your name, address, phone number, and email address—is processed in particular.

PwC Cert uses IT systems to process engagement inquiries and engagements, in which your personal data is stored and managed.

No automated decision-making or profiling takes place.

The duration of the storage of personal data is determined by the data processing described below for the purposes of record-keeping, documentation, and archiving.

If you have not personally engaged PwC Cert, we have generally received your contact information from your employer, our client, who has designated you as a point of contact within the company. In this case, the processing of your personal data is based on Article 6(1)(f) of the GDPR, as there is a legitimate interest in the processing. PwC Cert is obligated under a contract with its client to provide the commissioned service. In order to provide this service, it is necessary to process the data of the contact persons at the client’s organization. This constitutes a legitimate interest on the part of PwC Cert in processing this data. The same applies accordingly in the context of preparing a proposal.

If you yourself, as an individual, are a client of PwC Cert, additional personal data about you will also be processed in the course of order fulfillment, to the extent that such data is necessary for the provision of the services agreed upon with you. This may include, in particular, bank and payment details, as well as, where applicable, further information regarding your personal, professional, and financial circumstances, to the extent that such information is relevant to PwC Cert’s fulfillment of the engagement and you provide this information to us in accordance with the engagement agreement concluded with PwC Cert.

This processing of your data by PwC Cert is based on Article 6(1)(b) of the GDPR, as the data processing is necessary for the performance of the contract concluded between you and PwC Cert.

Please note that, in accordance with PwC Cert’s General Terms and Conditions, the client is obligated to cooperate by providing PwC Cert with all documents and information necessary for the execution of the engagement. If and to the extent that the necessary information is not provided, PwC Cert will be unable to process your engagement or fulfill the agreed-upon services, or will only be able to do so to a limited extent.

Data Processing for the Purpose of Collaborating with Clients and Mandants via Digital Applications

PwC Cert offers you the opportunity to collaborate directly with PwC Cert personnel on tools and documents via digital collaboration tools and their sharing functions, allowing you, among other things, to work on a document simultaneously with multiple users. If your company has been authorized to use this functionality, a PwC Cert personnel member can grant you permission for such collaboration and invite you via email as a visitor. After completing a confirmation and authentication process, you will be granted access to collaborate on one or more documents. You can then, depending on the document settings, add comments and suggest changes directly within the document.

As part of this processing, the following personal data in particular will be processed:

The legal basis for the processing is Article 6(1)(f) of the GDPR. PwC Cert has a legitimate interest in improving its collaboration with its clients and customers, including in the digital sphere, by offering sharing settings in collaboration tools.

However, as a company accredited by the German Accreditation Body (DAkkS), PwC Cert is also subject to extensive documentation and due diligence requirements. When multiple authors collaborate on a document, we must be able to permanently trace the document’s creation and the decisions underlying that process. All documents we archive to comply with legal retention requirements or accreditation standards therefore always include a revision history that transparently shows the timing and content of the changes. As a general rule, contributions made by authors who were authorized to access the document as “Visitors” are no longer listed by name once their authorization expires. However, if in individual cases a formerly authorized visitor is still listed by name—for example, in the revision history—the archiving of this information, beyond the fulfillment of statutory retention and archiving obligations, is also carried out with regard to this author data in order to safeguard our legitimate interests as described above. The legal basis is therefore Article 6(1)(f) of the GDPR.

The personal data processed in the context of collaboration on a document is generally subject to the same retention and documentation obligations as the edited documents themselves. This means that, for example, the personal data in the document history—to the extent that it is still contained in the document after the authorization has expired—as well as the content of the comments are subject to a retention obligation of up to ten years. 2.3.3 Data Processing for the Purpose of Purchasing and Utilizing Services If you or your employer are service providers to PwC Cert, we process your personal data (in particular your contact information, such as your name, address, phone number, and email address) for the purpose of initiating, concluding, and performing services that PwC Cert obtains from you or your employer. The processing of your contact information is based on Article 6(1)(b) of the GDPR to fulfill a contract concluded with you, provided that you are personally a service provider for PwC Cert, or on the basis of a legitimate interest within the meaning of Article 6(1)(f) of the GDPR if your employer provides services to us.

Data Processing for the Purposes of Record Keeping, Documentation, and Archiving

PwC Cert is legally required to maintain proper records and comprehensive documentation of its client engagements and assignments. These records and documentation must be retained and stored for retention periods specified by law, even after the completion of an assignment or client engagement. In addition, PwC Cert is subject to further legal documentation and retention obligations based, among other things, on tax, accounting, and commercial and corporate law requirements for companies.

The documents, work products, and related client-specific correspondence that must be documented also contain personal data, which means that this data is likewise part of the record-keeping and archiving process.

The record-keeping, documentation, and archiving of client documents at PwC Cert take place in PwC Cert’s IT systems and, in some cases, also in the form of paper files.

This processing is carried out on the basis of Article 6(1)(c) of the GDPR; through record-keeping, documentation, and archiving, PwC Cert fulfills legal obligations arising from, among other things, professional law, tax law, and commercial and corporate law.

Data Processing for Marketing and Advertising Purposes

PwC Cert also uses your contact information (in particular, your name, address, and email address) to solicit client feedback or to provide you with information about other PwC Cert offerings or PwC Cert events.

This processing is based on PwC Cert’s legitimate interest within the meaning of Article 6(1)(f) of the GDPR. There is a legitimate business interest in informing PwC Cert’s clients about its other offerings and events in order to establish and maintain a long-term customer relationship.

Data Processing for the Purpose of Maintaining Business Contacts

If PwC Cert has received your contact information in connection with a PwC Cert business event or another event, during a business meeting (e.g., through the exchange of business cards), or in connection with an engagement, we use your contact information (in particular, name, address, email address) to maintain our business contacts; for this purpose, we transfer your contact information to the CRM system (Customer Relationship Management system) we use. This processing is based on PwC Cert’s legitimate interest within the meaning of Article 6(1)(f) of the GDPR. PwC Cert has a legitimate business interest in maintaining contacts established in the course of business beyond the initial contact, using them to build a business relationship, and remaining in contact with the PII principals for this purpose.

Categories of Data Recipients and Transfers to Third Countries

In connection with the provision of the services you have commissioned, data is transferred to third parties; this may also include the transfer of personal data to countries within and outside Europe and the storage of data outside the EU. Specifically, data is transferred to the following categories of recipients.

Data transfers to government agencies, courts, or other bodies

Depending on the nature of the specific engagement, PwC Cert’s provision of the service may also require the transmission of information, work products, and documents to government agencies, courts, or other public or private entities in order to process the engagement. To the extent that the commissioned service has an international component, this may also include entities located abroad.

In addition, PwC Cert will transfer personal data to government agencies, courts, or other entities to the extent that PwC Cert is required by law or by an official or court order to disclose personal data to such entities.

Engagement-Related Collaboration with Other PwC Network Firms or Other Appropriate Subcontractors

PwC Cert is a member of the global PwC network, which consists of individual, legally separate, and independent PwC firms.

To the extent necessary to provide the commissioned service, collaboration takes place with other firms within the global PwC network or other suitable subcontractors. This may be the case if the engagement has an international component or if, for other reasons, it requires the expertise of a colleague from another (foreign) PwC network firm. To the extent that this transfer is made to a network firm outside the European Economic Area, an adequate level of data protection is ensured through the use of the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR. The PwC network firms have entered into an internal data protection agreement that ensures compliance with the European Commission’s EU Standard Contractual Clauses for the transfer of personal data from EU/EEA countries to other firms.

You can access the modular EU Standard Contractual Clauses at https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_de.

Data Transfer to Service Providers Within the PwC Network

As part of its operations, PwC Cert utilizes other German or foreign PwC network firms as internal network IT service providers that provide services for the operation, maintenance, and support of the IT systems and applications used by the PwC network firms. These are primarily PwC IT Services Ltd., based in the UK. In addition, PwC uses network-internal Service Delivery Centers (SDCs) that provide support to other PwC firms in the administrative organization and processing of client orders and engagements. These services include, for example, the preparation and review of invoices, layout and design, proofreading, translation services, and other engagement-related services. SDCs are located in Germany, Poland, and Argentina, among other places.

To the extent that this transfer is made to a network company outside the European Economic Area, an adequate level of data protection is ensured through the use of the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR. The PwC network firms have entered into an internal data protection agreement that requires compliance with the European Commission’s EU Standard Contractual Clauses for the transfer of personal data from EU/EEA countries to other firms.

Data Transfer to External IT Service Providers

In addition, PwC Cert also uses external IT service providers.

To the extent that the IT service providers are foreign cloud service providers, data is stored in the service provider’s data centers both within and outside the EU. The adequate level of data protection required under EU data protection law is contractually guaranteed through the adoption of the EU Standard Contractual Clauses (EU Model Clauses). You can find more detailed information about the cloud service providers used by PwC Cert at the following link: www.pwc.de/externe-dienstleister.

If an adequate level of data protection comparable to that within the EU under the EU GDPR cannot be guaranteed in a specific case, a transfer is permitted only with your express consent.

Use of Cookies

To make your visit to our website more engaging and to enable the use of certain features, we and certain third parties use cookies on our website. These are small text files that are stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e., when you close your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies to recognize your browser the next time you visit (so-called persistent cookies).

We use the following categories of cookies:

Cookies that are technically necessary for the operation of our website:

These cookies are technically necessary for the operation and functionality of the website. They make the website technically accessible, secure, and usable, and provide essential and basic functionalities, such as navigation on the website, the correct display of the website in the web browser, or consent management.

Analytics Cookies:

Analytics cookies allow us to collect data in an aggregated form about our website visitors and their experiences on our website. We use this data to fix errors and improve the experience for all visitors.

Integration of SmartMaps

On this website, we use the “SmartMaps” service provided by YellowMap AG, CAS-Weg 1-5, 76131 Karlsruhe.

This allows us to display maps directly on the website and enables you to conveniently use the map feature. In order to display the maps to you, SmartMaps uses your IP address when the browser retrieves the SmartMaps components. This IP address is stored on the web server for approximately 5 minutes to prevent DoS attacks; after that, it expires and is neither further processed nor stored.

YellowMap AG is therefore a recipient of data. However, it does not process the data for its own purposes, but exclusively on behalf of and at the direction of PwC. PwC has entered into a data processing agreement with YellowMap AG in accordance with Article 28 of the GDPR.

Data Subject Rights/Your Rights Under Data Protection Law

You have the following rights under applicable data protection law with respect to your personal data held by PwC Cert.

Right of Access: You may at any time request information from PwC Cert regarding whether and what personal data PwC Cert has stored about you. PwC Cert will provide this information free of charge.

The right to access does not apply, or applies only to a limited extent, if and to the extent that providing the information would disclose information subject to confidentiality, such as information covered by professional secrecy.

Right to Rectification: If your personal data stored by PwC Cert is inaccurate or incomplete, you have the right to request that PwC Cert rectify this data at any time.

Right to erasure: You have the right to request that PwC Cert erase your personal data if and to the extent that the data is no longer necessary for the purposes for which it was collected or, if the processing is based on your consent, you have withdrawn your consent. In this case, PwC Cert must cease processing your personal data and remove it from its IT systems and databases.

There is no right to erasure to the extent that

Right to Restriction of Processing: You have the right to request that PwC Cert restrict the processing of your personal data.

Right to data portability: You have the right to receive from PwC Cert the data you have provided in a structured, commonly used, and machine-readable format , as well as the right to have this data transmitted to another data controller. This right applies only if

Right to Withdraw Your Consent: If PwC Cert processes your data based on your consent, you may withdraw your consent at any time with future effect. Withdrawing your consent does not affect the lawfulness of processing carried out on the basis of your consent prior to its withdrawal.

Right to object to processing: If PwC Cert processes your data on the basis of Article 6(1)(f) of the GDPR, you may object to such processing by PwC Cert at any time.

Processing based on Article 6(1)(f) of the GDPR occurs, for example, if your employer is a client of PwC Cert and has provided us with your data as a contact person at your company, or if PwC Cert uses your contact information to send you information about PwC Cert’s offers and events.

You may exercise all of the data subject rights described above by contacting PwC Cert with your specific request using the following contact information:

By email: DE_Datenschutz@pwc.com.

By mail:
PwC Certification Services GmbH
Dr. Tobias Gräber, Data Protection Officer
Friedrich-Ebert-Anlage 35-37
60327 Frankfurt am Main, Germany

Right to File a Complaint with a Data Protection Supervisory Authority

Pursuant to Article 77 of the GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.

Data Retention Period

PwC Cert will store and process your personal data for as long as necessary to fulfill the processing purposes described in this Privacy Notice. To the extent that your personal data is subject to statutory retention obligations or forms part of records subject to such obligations, PwC Cert will store this data for the duration of the retention period specified by law. The retention periods to which PwC Cert is subject vary in length and typically cover a period of 6 to 10 years. The key statutory retention obligations to which PwC Cert is subject include, among others, the following periods:

If PII data is subject to different retention periods, the longest retention period applies in each case. In individual cases, the legally prescribed retention period may be extended further if, for example, the information is needed to assert, exercise, or defend legal claims even after the retention period has expired.

Supplementary Data Protection Notice for the Processing of Special Categories of Personal Data

If you yourself have commissioned PwC Cert to provide a service, PwC Cert will process, in addition to your personal contact information, other personal data regarding your personal, financial, and/or professional circumstances that you provide to us for the purpose of fulfilling the engagement.

Depending on the nature of the specific engagement, this personal data may also include special categories of personal data as defined in Article 9 of the GDPR. This data is subject to special protection under data protection law, and the processing of such data is permitted only under specific conditions.

The following information provides additional details regarding PwC Cert’s processing of special categories of personal data.

Special Categories of Personal Data

Special categories of personal data are personal data that reveal information about the following characteristics:

Purposes of Processing and Legal Basis for Processing

PwC Cert will process such special categories of personal data exclusively to fulfill the engagement entered into with you, provided that you provide us with such data within the scope of the engagement and its processing is necessary for the fulfillment of the engagement.

This information is particularly sensitive and is subject to a higher level of protection than other personal data. We require your consent to process such data relating to you.

The processing is therefore based on your consent within the meaning of Article 6(1)(a) in conjunction with Article 7 of the GDPR:

By signing the engagement letter and providing such sensitive personal data to PwC Cert, you are expressing your consent to the processing of your data by PwC Cert for the purpose of fulfilling the specific engagement and are thereby granting your consent under data protection law.

Withdrawal of Consent to Data Processing

Consent to data processing is voluntary and may be revoked by you at any time with future effect.

If you wish to withdraw your consent to the processing of special categories of personal data by PwC Cert, you may do so by simply sending your withdrawal to the following contact information:

By email: DE_Datenschutz@pwc.com.

By mail:
PwC Certification Services GmbH
Dr. Tobias Gräber, Data Protection Officer
Friedrich-Ebert-Anlage 35-37
60327 Frankfurt am Main, Germany

Please note, however, that if you withdraw your consent, PwC Cert will be unable to process your request or provide the agreed-upon service, or will only be able to do so to a limited extent.