Data protection processes – Handling Data Protection Incidents

Privacy Policy

Processing and Handling of Data Protection Incidents

Controller:

Berlin University of Economics and Law

Badensche Str. 52

10825 Berlin (Germany)

praesident@hwr-berlin.de

Legal representatives:

Prof. Dr. Andrew Zaby

Data Protection Officer:

Vitali Dick (HiSolutions AG)

Badensche Str. 52

10825 Berlin (Germany)

datenschutz@hwr-berlin.de

Information on the processing activity:

Purposes of the processing activity:

Processing, evaluation, treatment and reporting of data protection incidents

Legal basis of the processing activity:

Processing is required to fulfill a legal obligation in accordance with Article 6 (1) (c) GDPR. The legal obligation results from Article 33 GDPR.

Categories of personal data:

  • Data breach content data. These are in the processing directories of the HWR Berlin and may vary from case to case.
  • Master data (surname, first name, business telephone number, business e-mail))

Categories of recipients:

Supervisory authority (supervisory authority)

Processor (processor within the meaning of Art. 4 in conjunction with Art. 28 GDPR)

Data Protection Officer (Data Protection Officer)

Internal (internal departments involved)

Contractor (processor):

Auditis Services GmbH (Herford)

Data transfer to a third country:

There are no planned transfers to third countries.

Additional information obligations:

Duration of storage of personal data:

5 years after the end of the calendar year in which the data protection incident was closed.

Rights of the data subject

The person affected by the processing has rights in accordance with Art. 13 – 23 GDPR, which can be asserted against the HWR Berlin. An overview of the most important rights is listed below:

  • Information obligation when collecting personal data according to Art. 13 DSGVO
  • Information obligation if the personal data was not collected from the person concerned according to Art. 14 DSGVO
  • Right to information about data stored by the person responsible (HWR Berlin) according to Art. 15 DSGVO
  • Right to correction of data stored by the person responsible (HWR Berlin) according to Art. 16 DSGVO
  • Right to erasure of data stored by the person responsible (HWR Berlin) in accordance with Art. 17 GDPR
  • Right to restriction of processing of data stored by the person responsible (HWR Berlin) in accordance with Article 18 GDPR
  • Notification obligation in connection with the correction or deletion of personal data or the restriction of processing according to Art. 19 GDPR
  • Right to data portability according to Art. 20 GDPR
  • Right to object to data processing if processing is required under Art. 6 (1) e GDPR to perform a task that is in the public interest or in the exercise of official authority or processing under Art. 6 (1) f GDPR is necessary to protect the legitimate interests of the person responsible or a third party according to Art. 21 DSGVO.
  • Right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.
  • Right to notification according to Art. 34 GDPR of the person affected by a breach of the protection of personal data.

Exercise of rights

If you would like to exercise your rights, please contact the data protection officer named above or submit the request using the link [1]

Right of appeal 

The person concerned also has the right to complain to a supervisory authority about the HWR Berlin. The competent supervisory authority in the state of Berlin is

Berlin Commissioner for Data Protection and Freedom of Information

Friedrichstr. 219

10969 Berlin

mailbox@datenschutz-berlin.de

 Source of personal data:

Other (usually internal sources)

 Obligation to provide personal data:

You are not obliged to provide the data.

Automated Decision Making:

There is no automated decision-making or profiling.

 

[1] https://dsgvo2.ds – manager.net/jd8g73mg9/frage_meldung.html?key=5oZEoda8bochZmO9  

 

Diese Webseite verwendet ausschließlich technisch notwendige Cookies. Eine Einwilligung des Nutzers ist demnach nicht erforderlich. This website only uses technically necessary cookies. The consent of the user is therefore not required .