DATA PROTECTION GUIDELINES
Introduction and terms (> Deutsche Fassung)
With the operation of our website www.fsk-freigaben.de (hereinafter referred to as "website") we process personal data. These will be treated confidentially by us and processed in accordance with the applicable laws - in particular the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). With our data protection regulations we want to inform you which personal data we collect from you, for which purposes and on which legal basis we use it and, if applicable, to whom we disclose it. In addition, we will explain to you which rights you have to protect and enforce your data protection.
Our data protection regulations contain technical terms which are defined in the GDPR and the BDSG. For your better understanding we would like to explain these terms in simple words in advance:
2.1 Personal Data
"Personal data" means any information relating to an identified or identifiable person (Art. 4 No. 1 GDPR). Information of an identified person can be e.g. the name or the e-mail address. However, personal data also includes data in which the identity is not immediately apparent but can be determined by combining one's own or third-party information and thus finding out who it is. A person becomes identifiable, for example, by providing his/her address or bank details, date of birth or user name, IP addresses and/or location data. Relevant here is all information that in any way allows conclusions to be drawn about a person.
Art. 4 No. 2 GDPR defines "processing" as any operation or set of operations performed on personal data. This concerns in particular the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, transmission, dissemination or any other form of supply, comparison or association, limitation, erasure or destruction of personal data.
Responsible company ("Controller") and Data Protection Officer
Responsible for data processing:
Company: Freiwillige Selbstkontrolle der Filmwirtschaft GmbH ("we")
Legal representative: Stefan Linz and Helmut Possmann (Managing Directors)
Address: Murnaustraße 6, 65189 Wiesbaden
Phon: +49 611 77891-0
Fax: +49 611 7789-139
4. DATA PROTECTION OFFICER
We have appointed an external data protection officer for our company. You can reach him at :
Name: Reinher Karl
Address: HABEWI GmbH & Co KG, Palmaille 96, 22767 Hamburg
Phone: 040/ 18189800
Fax: 040/ 181898099
5. PROCESSING PARAMETERS: WEBSITE
On our website www.fsk-freigaben.de, we process your personal data listed in detail below under numbers 6-9. We only process data from you which you actively enter on our website (e.g. by completing forms) or that you automatically provide when using our services.
Your data will only be processed by us and will not be sold, leased or provided to third parties. If we use the help of external service providers to process your personal data, this is done in our contractual relationship with our data processors. We as the controller are authorised to give instructions to our data processors. For the operation of our website we use external service providers for hosting as well as for maintenance, care and further development. Should further external service providers be used for individual processing operations listed in points 6-9, they shall be named there.
Data transfer to third countries does not take place and is not planned. We will inform you about exceptions to this principle in the processing operations described below.
The processing operations in detail
6. PROVISION OF THE WEBSITE AND LOG FILES
6.1 Description of processing
Each time you visit our website, we automatically collect information that your browser sends to our server. These are also stored in the so-called log files of our system. This is the following data:
- Browser software used, as well as their version and language
parts of the sent forms are not stored personalized, i.e. only with reference to the application number.
The processing is carried out in order to enable access to the website and to guarantee its stability and security. In addition, the processing serves the statistical evaluation and functionality of our online offer.
6.3 Legal basis
Processing is necessary to safeguard the overriding legitimate interests of the data controller (Art. 6 para. 1 lit. f GDPR). Our legitimate interest lies in the purpose stated in Section 6.2. Insofar as a contract exists between the registered user and us, the processing is based on the consent of the user (Art. 6 para. 1 lit. b GDPR).
6.4 Storage duration
The data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected. In the case of the collection of data to provide the website, this is the case when the respective session is terminated.
7.1 Description of processing
Access to the application form for the FSK examination is only available to registered users. With the registration you conclude a free user contract with us. By registering, you will receive your own user account on our website. You can register by filling out the registration form on https://www.fsk-freigaben.de/registrieren and sending it to us electronically. To register, you must provide your company, street, postal code, city, country, first name, last name, telephone number, e-mail address and your member association. By clicking the button "Register" you send us the form. You will then receive an automatic welcome e-mail. This will contain a link to confirm your email address. Only after successful verification of your e-mail address by clicking on the confirmation link your account is being activated on our website.
The processing takes place in order to provide you with the functions of our website for registered users.
7.3 Legal basis
The processing is necessary for the conclusion and fulfilment of the user contract (Art. 6 para. 1 lit. b GDPR). We will not be able to perform our contractual services without providing your personal data as part of the registration process.
7.4 Storage duration
The data will be automatically deleted by us upon termination of your user contract. You can terminate the user contract yourself by sending an e-mail to firstname.lastname@example.org, by post to FSK GmbH, Murnaustraße 6, 65189 Wiesbaden, Germany, stating that you no longer wish to be a registered user of our website. We will then delete your user account immediately.
8. CONTACT BY E-MAIL
8.1 Description of processing
You can contact us via the e-mail addresses provided on the website. In this case, the personal data transmitted by e-mail will be processed by us.
The data transmitted with the contact form or your e-mail will be used exclusively for the purpose of processing and answering your request.
8.3 Legal basis
Processing is necessary to safeguard the overriding legitimate interests of the data controller (Art. 6 para. 1 lit. f GDPR). Our legitimate interest lies in the purpose specified in Section 8.2. If the e-mail contact is aimed at concluding or fulfilling a contract, data processing is carried out to fulfil the contract (Art. 6 para. 1 lit. b GDPR).
8.4 Storage duration
The data is deleted by us as soon as it is no longer required for the purpose of its collection. This is usually the case when the respective communication with you is finished. Communication is terminated when it can be inferred from the circumstances that your request has been conclusively clarified. If legal retention periods prevent deletion, deletion shall take place immediately after expiry of the statutory retention period.
10. Security Measures
In order to protect your personal data from unauthorized access, we have provided our website with an SSL or TLS certificate. SSL stands for "Secure Sockets Layer" and TLS for "Transport Layer Security" and encrypts the communication of data between a website and the user's terminal device. You can recognize the active SSL or TLS encryption by a small lock logo, which is displayed on the far left in the address bar of the browser.
11. RIGHTS AFFECTED
With regard to the data processing described above by our company, you are entitled to the following data subject rights:
11.1 Right of Access (Art. 15 GDPR)
You have the right to be informed by us if we are processing your personal data. If we are processing it, you have the right under Art. 15 of the GDPR to be informed as to what data we are processing and the right to additional information as specified in Art. 15 of the GDPR..
11.2 Rectification (Art. 16 GDPR)
You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you and, where applicable, to have incomplete personal data completed, including by means of providing a supplementary statement.
11.3 Erasure (Art. 17 GDPR)
You have the right to obtain from us the erasure of your personal data without undue delay, and we shall have the obligation to erase your personal data without undue delay where one of the following grounds under Art. 17 of the GDPR applies (e.g. if your data is no longer required for the purpose for which we were using it).
11.4 Restriction of data processing (Art. 18 GDPR)
You have the right to demand that we restrict the processing of your personal data, provided that one of the criteria specified under Art. 18 of the GDPR is met (e.g. if you dispute the accuracy of your personal data, its processing will be restricted for the period necessary for us to check its accuracy).
11.5 Data portability (Art. 20 GDPR)
Subject to the criteria specified under Art. 20 of the GDPR, you have the right to be given your data in a structured, commonly used and machine-readable format.
11.6 Withdrawal of consents (Art. 7 para. 3 GDPR)
You have the right to withdraw your previously provided consent for data processing. The withdrawal will take effect from the time you request it (i.e. it will have future effect but no retrospective affect).
11.7 Complaints (Art. 77 GDPR)
If you believe that the processing of your personal data is in breach of the GDPR, you can complain to a supervisory authority. You can submit your complaint to a supervisory authority in the EU member state where you are habitually resident or work, or where the alleged breach took place.
11.8 Restraint on automated decision-making/ profiling (Art. 22 GDPR)
Decisions that have legal consequences for you or that could have a significant detrimental affect on you must not be based solely on the automated processing of personal data, including profiling. We do not apply any such processing or profiling to your personal data.
11.9 Objection (Art. 21 GDPR)
Where we process your personal data on the basis of Art. 6 Par. 1 f of the GDPR in pursuit of our overriding legitimate interests, you have the right subject to Art. 21 of the GDPR to object, provided your objection is based on grounds relating to your specific situation. Once you have objected, we will no longer process your personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims. Regardless of the aforementioned restrictions, and regardless of whether any special circumstances apply, you have the right to object at any time to the processing of your personal data for direct marketing purposes.
Status: Februar 2019