Data Protection Information
We want to protect you, as a whistleblower, effectively and offer you a secured communication platform for submitting reports. Reports can be submitted with disclosure of your name, under a pseudonym, or anonymously.
The responsible party for the purposes of the German Federal Data Protection Act (BDSG) is ECE Projektmanagement G.m.b.H. & Co. KG, Heegbarg 30 22391, Hamburg.
Personal data entered into the BKMS® whistleblowing system will be stored on our behalf in a database operated by EQS Group GmbH, Bayreuther Str. 35, 10789 Berlin, externally to the database operated by ECE. Only explicitly authorised employees of the Compliance and Data Protection Department of ECE have access to the submitted reports. Third parties, in particular EQS Group GmbH, are excluded from access. All data are stored with encryption and password protection in a safe location in Germany, externally to ECE. The communication relating to submitted reports is carried out with strict confidentiality.
Only those employees of the Compliance and Data Protection Department of ECE who have been explicitly authorised by ECE will have access to the submitted reports. If necessary for the investigation in exceptional cases, the Chief Compliance Officer of ECE will include other internal and/or external parties, such as the group auditing department, in the process. Further details are specified in an internal process description of ECE pertaining to “procedures for dealing with suspected compliance violations”.
Type of personal data collected
Use of the BKMS® whistleblowing system takes place on a voluntary basis. If you submit a report via the whistleblowing system, we collect the following personal data and information:
- your name, if you choose to reveal your identity,
- whether you are employed at ECE, and
- the names and other personal data of persons whom you list in your report, if applicable.
Legal basis
ECE makes confidential use of the personal data, such as name and other communication data and content, exclusively for the purpose of receiving and processing reports on specific criminal acts as well as serious legal violations, such as white-collar crime, corruption and human rights and data protection violations, via a secure and confidential channel.
Insofar as we obtain your consent for the processing of personal data, this serves as the legal basis according to Article 6 paragraph 1 point a of the General Data Protection Regulation (GDPR). In other cases, the processing serves in accordance with Article 6 paragraph 1 point f GDPR for pursuing the predominant legitimate interests of ECE in investigating criminal acts as well as statutory violations in connection with the ECE group and thereby protecting the group and its employees from possible damages, and this predominant legitimate interest is the legal basis.
Sharing of data
Only ECE is able to view these data. Access to the data is restricted to a very small set of explicitly authorized and specially trained persons of the ECE compliance organisation or the group data protection organisation. Depending on the content of the report and the progress of the investigation, a very restricted number of additional authorized persons, in particular within the compliance and security organisations of the respectively involved subsidiaries of ECE, may receive access to these data, for example if the reports refer to activities within the subsidiaries. The latter may be based in countries outside the European Union or the European Economic Area.
All persons who receive access to the data are obligated to maintain confidentiality. Within the scope of criminal proceedings, personal data may have to be disclosed to governmental investigation authorities in accordance with statutory obligations.
Retention period of personal data
Personal data are only retained for as long as necessary to clarify the situation and perform a concluding evaluation of the case. After the report processing is concluded, the data are deleted in accordance with the statutory requirements.
Use of the BKMS® whistleblowing system
Communication between your computer or smartphone and the BKMS® whistleblowing system takes place over an encrypted connection (SSL). The IP address of your computer or smartphone will not be stored during your use of the whistleblowing system. In order to maintain the connection between your computer or smartphone and the BKMS® whistleblowing system, a cookie is stored on your computer that merely contains the session ID (a so-called session cookie). This cookie is only valid until the end of your session and expires when you close your browser.
It is possible to set up a postbox within the BKMS® whistleblowing system that is secured with an individually chosen pseudonym/user name and password. The postbox allows you to submit reports under your name or anonymously and communicate with employees of the ECE Compliance and Data Protection Department. This system only stores data inside the BKMS® whistleblowing system, which makes it particularly secure. It is not a form of regular e-mail communication.
Note on sending attachments
During the submission of your report or an addition, you can send attachments to the employees of the ECE Compliance and Data Protection Department. If you wish to submit an anonymous report, please take note of the following security advice:
files can contain hidden personal data that could put your anonymity at risk. Remove these data before sending messages. If it is not possible to remove these data or you are uncertain about how to do so, copy the text of your attachment into your report text or send the printed document anonymously to the address listed in the footer, citing the reference number received at the end of the report submission process.
You as whistleblower and the persons named in the report have a right of access, rectification, erasure and restriction of processing (blocking) regarding your personal data as well as a right to object to the processing of your personal data.
Data protection rights
According to the applicable laws and the information below, you have the right to access your personal data and to request the correction, erasure or portability (e.g. transfer of your personal data to another service provider) of your personal data processed by us as well as to demand the restriction of the processing.
You have the right to submit a complaint regarding our data processing. Please submit this to:
Hamburg Representative for Data Protection and Freedom of Information
Klosterwall 6
20095 Hamburg
To exercise your rights, it is also sufficient to send a letter or email to the controller at the following address:
ECE Projektmanagement G.m.b.H. & Co. KG
-CDS Whistleblowing System-
Heegbarg 30
22391 Hamburg, Germany
or
compliance@ece.com
Additional information on data protection at ECE can be obtained here:
https://www.ece.com/en/data-protection/
(Privacy statement of ECE)