Data Protection

KfW Privacy Notice

You can rely on the protection and security of your personal data: we consider it our responsibility to protect your privacy when processing your personal data. The following privacy notices provide an overview of the processing of your data and the rights you have under data protection regulations when using the products and services of KfW Group.

1. Who is responsible for data processing and whom can I contact?

The following party is responsible:

  • KfW Group (hereinafter referred to as ‘we’ or ‘us’)
    Palmengartenstrasse 5-9
    60325 Frankfurt, Germany
    Tel: +49 (0)69 74 31-0
    Fax: +49 (0)69 74 31-29 44

You can reach our company data protection officer at:

  • KfW Group
    Data protection officer
    Palmengartenstrasse 5-9
    60325 Frankfurt, Germany

2. Which sources and data does KfW use?

We process personal data that we receive from our customers, business partners and website visitors in connection with the use of our website, the use of our portals, subscription to newsletters and in connection with our business relationships with these groups.

Personal data processed by us refers in particular to personal details (such as name, address, telecommunications data, date and place of birth, marital status), identification data (such as ID, residence registration data), contractual data, advertising and sales data, documentation data, registration data and similar information.

3. For what purpose does KfW process your data and on what legal basis?

We process personal data in accordance with the provisions of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz; BDSG) and other applicable legal regulations.

For technical reasons, it is necessary to collect and store certain personal data when you visit our website, such as the IP address, the date and duration of your visit, the websites used, the identification data of the used browser and operating system type and, if applicable, the website from which you arrived at our site. The legal basis for processing your personal data in this context is Article 6(1)(1)(f) GDPR.

However, the products and services cited as examples below, which you can find on our website, require you to provide personal data in order to use them.

3.1 1 General communications, use of the portals and newsletters for the purpose of fulfilling contractual obligations, the purposes of legitimate interests and on the basis of your consent:

  • General communications, particularly via the contact form
  • Processing other enquiries
  • Use of our portals, for example, our grant portal or online credit portal
  • Newsletters

The processing of your personal data in this context is generally a prerequisite for concluding and performing a contract with you or entering into a preliminary agreement with you. You are not legally obligated to make your personal data available to us. Without these data, however, we will not be able to perform the relevant contract with you. The legal basis for this processing is Article 6(1)(1)(b) GDPR. This provision permits the processing of personal data if the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps prior to entering into a contract.

Moreover, we store and process your data for inquiries for the purpose of customer information and support. You can object to this type of processing at any time. Any further use and disclosure of your data does not take place. The basis for the processing of your personal data in this context is Article 6 Paragraph 1 Subparagraph 1 lit. f GDPR. According to this, the processing of personal data is permitted if this is necessary to purpose legitimate interests, except where such interests are overridden by the interests of the data subject which require protection of personal data. We have a legitimate interest in optimizing prospect/customer support. We protect the data concerned in such a way that we do not see any major disadvantages for you.

Selected KfW portals include, as part of the contractual services provided by KfW, the option for the user to design the content of the portal according to their personal needs for permanent use. Any necessary processing of personal data in this regard shall be used exclusively for the purposes mentioned above.

If you have given us your consent to process personal data for specific purposes (e.g to send our newsletter), this consent serves as the legal basis for processing the data (Article 6(1)(1)(a) GDPR). Consent which has been granted may be revoked at any time. This also applies to revoking declarations of consent that were issued to us before the GDPR took effect, i.e. before 25 May 2018. If consent is revoked, the legality of data processing carried out before consent was revoked is not affected.

3.2 Analysis of user behaviour and direct marketing – for the purpose of safeguarding legitimate interests:

  • Testing and optimising demand analysis procedures for the purpose of directly approaching customers
  • Advertising or market research and polling, insofar as you have not objected to the use of your data
  • Measures in relation to business management and the further development of services and products

The legal basis for processing your personal data in this context is Article 6(1)(1)(f) GDPR unless we have, in individual cases, obtained your consent. Pursuant to this provision, processing personal data is permissible if this is necessary for the purposes of legitimate interests except where such interests are overridden by the interests or fundamental rights of the data subject which require that the personal data are not processed. We have a justified interest in aligning our offers with customer behaviour and optimising them. We believe that these interests prevail since, as an international financial institution, we must control and optimise our offers in order to fulfil our promotional mandate. The alignment with our customers allows us to offer and optimise services according to the needs and interests of our customers. We protect the relevant data in such a way that we do not see any overriding disadvantages for you.

3.3 Risk management and compliance – for the purpose of safeguarding justified interests:

  • Assertion of legal claims and defence in legal disputes
  • Prevention and investigation of criminal activities
  • Guarantee of IT security and IT operations at the bank
  • Risk management at the KfW Group

The legal basis for processing your personal data in this context is Article 6(1)(1)(f) GDPR. Our justified interest consists of complying with applicable legal provisions, maintaining the security of our IT systems and, in case of non-compliance with legal requirements or violations of security regulations, responding adequately to such circumstances, for instance by asserting legal claims. We believe that these interests prevail since, as a bank, we are subject to a significant number of regulatory requirements and have a responsibility towards our customers to ensure that the corresponding requirements and security regulations are complied with. We protect the relevant data in such a way that we do not see any overriding disadvantages for you.

3.4 Social media

You can access various social media from our website.

Caution: When choosing one of the following links, you will leave our website and be directed to the website of a social media platform. Any information available there was created without any involvement from us and we are therefore not responsible for this content. We do not accept any liability for the information being up-to-date, accurate or complete. Any reference to social media does not imply any approval on our part.

Particularly for reasons of data protection compliance, the relevant social media cannot be accessed directly. Corresponding notes are therefore displayed. In addition, you may first have to click on integrated buttons, thus giving your express consent to communication with the social media platform. Only after that will the browser connect you by establishing a direct connection with the social media platform’s servers.

Please keep in mind that we are not aware of nor do we influence how and what data find their way to the social media platform.

By activating the button, you will provide the social media platform with the information that you have opened one of the web pages of the platform on the Internet. If you are already registered with the social media platform, it will be able to link your visit with your account on the social media platform. However, even if you have not yet registered with the social media platform, it is not possible to preclude the possibility that it will collect and/or store your IP address after you click on the platform.

3.5 Cookies and other technologies for website analysis

We use cookies and other technologies for the operation of our website, as well as for a pseudonymised recording of its usage. In this way, we can conduct analyses of user behaviour by collecting and analysing the information communicated by your browser. However, none of these analyses are linked to individual persons. Any personal identification characteristics, namely in this case the IP address, are deleted at the moment of processing and replaced by an indicator, which makes it impossible or at least extremely difficult to identify the data subject. This methodology ensures that KfW is routinely unable to establish a concrete link to particular persons.

In our cookie notes you can find detailed information on which cookies and other technologies are used for which concrete purposes and on which legal basis this is done. You can also find opt out-options there.

You can access the cookie notes by clicking on the blue circular icon with the fingerprint at the bottom left of this page.

3.6 Chatbot

You can use the function of the KfW chatbot on this website. Your IP address is collected during use and retained for three days for technical reasons. We have a legitimate interest in the collection and storage of the IP address (Article 6(1)(f) GDPR). This is necessary for the need-based design of our KfW chatbot and for guaranteeing a problem-free service. The technical operation of the KfW chatbot is carried out by a carefully selected service provider. No personal data are transmitted to any country outside the European Union or the European Economic Area.

If you use the KfW chatbot, please do not enter any personal or confidential data such as your name, address or account number. Our chats are stored for 30 days in anonymised form.

3.7 Authentication procedure for the KfW Förderassistent funding tool

To enable the use of the KfW Förderassistent funding tool (https://foerderassistent.kfw.de), your surname, first name, email address and telemetric data are communicated to the Microsoft Corporation in non-EU countries during the registration process. This serves the technically necessary purpose of being able to authenticate your registration process by sending an email. The data processing is based on the performance of tasks carried out in the public interest (Article 6(1)(e) GDPR). The Microsoft Corporation has undertaken to comply with the data protection standards of the EU. Your data are stored by the Microsoft Corporation for a maximum of 30 days and then deleted.

4. Who will have access to my data?

Within the bank, the departments that need your data to fulfil our contractual and legal obligations receive access to your data. Service providers and subcontractors whose services we use may also receive data for these purposes if they observe banking secrecy and data protection. With regard to the transfer of data, we have undertaken to maintain confidentiality concerning all customer-related facts and assessments about which we become aware (banking secrecy).

We may only disclose information about you to third parties if required to do so by law, if you have given your consent or if we are authorised to provide such information for other reasons. Under these conditions, recipients of personal data could include:

  • Public bodies and institutions (e.g. the Deutsche Bundesbank, the Federal Financial Supervisory Authority, the Federal Court of Auditors, courts of auditors in the German states, the Federal Parliament including its committees, the European Banking Authority, the European Central Bank (ECB), the European Investment Fund (EIF), the European Investment Bank (EIB), the European Commission, German federal and state ministries, financial authorities and official bodies) in the event of a legal or official obligation.
  • Other credit and financial services institutions or similar institutions to which KfW transfers personal data for the purpose of managing its business relationship with you (e.g. commercial banks or credit agencies, depending on the contract).
  • Service providers which process data on our behalf (e.g. data centres).
  • Specialists and the German Energy Agency (dena), if involved in the promotion.
  • Other bodies or service providers, insofar as we refer explicitly to them in these privacy notices or other KfW privacy policies.

Other data recipients may be bodies for which you have given us your consent to transfer data, or for which you have exempted us from banking secrecy by agreement or consent.

If you need further information on individual recipients, please do not hesitate to contact us.

5. Will any data be transferred to a third country or to an international organisation?

Data are not transferred to entities in countries outside of the European Union (known as third countries), with the exception of the cases specified in these privacy notices or other KfW privacy policies.

In the event of a transfer to a third country, this shall be conducted under the application of appropriate guarantees of an adequate level of data protection (Article 44ff GDPR).

6. How long will my data be stored?

How long personal data are stored is based on the respective processing purposes. It is not possible to list the various storage periods in detail in a reasonable format here. The criteria to determine the specific individual storage periods are the following:

  • If we process data only for the purpose of executing a contractual relationship, we store the data for the duration of the contractual relationship.
  • Where we process data in connection with anticipated legal disputes, we will store the data until the court proceedings have definitively been completed or until the claims at issue have become time-barred in accordance with the applicable civil law provisions. The general limitation period is three years.
  • In addition, we are subject to various storage and documentation requirements arising from the German Commercial Code (HGB), the German Fiscal Code (AO), the German Banking Act (KWG), the German Money Laundering Act (GwG) and the German Securities Trading Act (WpHG), among others. The periods for retention and documentation stipulated in these laws range from two to ten years.
  • When using the online version of the electronic form archive and the repayment calculator, the entered data are retained in the main memory of our server only for the duration of the use of the applications: the process duration is currently set to one hour from the start of the session. Data are not stored either temporarily or permanently.

7. What are my data protection rights?

If the statutory prerequisites are met, you have the following rights in accordance with Articles 15 to 22 GDPR:

  • Right of access in accordance with Article 15 GDPR, i.e. the right to obtain confirmation from us as to whether or not personal data concerning you are being processed and, where that is the case, access to these personal data and other information;
  • Right to rectification in accordance with Article 16 GDPR if personal data concerning you are not correct;
  • Right to erasure in accordance with Article 17 GDPR, e.g. when the personal data are no longer necessary in relation to the purposes for which they were processed;
  • Right to restriction of processing in accordance with Article 18 GDPR and
  • Right to data portability in accordance with Article 20 GDPR, i.e. the right to receive your personal data from us in a structured, commonly used and machine-readable format and the right to transmit those data to another controller. However, in accordance with Article 20(3)(2) GDPR, this right shall not apply to processing necessary for the performance of a task carried out in the public interest

With respect to the right of access and the right to erasure, the restrictions pursuant to Articles 34 and 35 of the German Federal Data Protection Act apply.

In addition, there is a right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).

8. Note on data processing for undisclosed assignments and the purchase of claims receivable

In the context of undisclosed assignments for the granting of securities in business transactions, KfW is given the name, address and contractual data of the relevant debtors from the grantor of the collateral or from the seller of the receivables for the purpose of the adequate individualisation of the security collateral required by law. Insofar as the assigned receivables are not liquidated by KfW, the data are collected and stored exclusively for administrative purposes (recording of the receivables assigned as collateral) and they are not processed further in any form. In this situation, KfW is not subject to any notification requirement with regard to the data owners in accordance with Article 14(5)(b) GDPR.

There is no transfer of the data to third parties or to bodies in a third country during the course of such an undisclosed assignment. The data are deleted after the expiry of the statutory storage obligations. There is no automated individual decision-making, including profiling.

Right to revoke your consent

You can revoke consent that you have granted to process data at any time. This does not, however, affect the legality of processing carried out before consent was revoked. If you revoke your consent, we shall no longer process the data for these purposes.

Information about your rights to object

Right to object in individual cases in accordance with Article 21 GDPR

You have the right to object at any time to the processing of your personal data, which is based on the performance of tasks carried out in the public interest or a balancing of interests (Article 6(1)(1)(e) and (f) GDPR), insofar as reasons arise from your particular circumstances which preclude such data processing. This also applies if automated individual decision-making is used (Article 22 GDPR). If you raise an objection, we shall no longer process your personal data for these purposes unless we are able to provide evidence of compelling reasons for the processing which are worthy of protection and which override your interests, rights and freedoms, or unless the processing serves the purpose of establishing, exercising or defending legal claims.

In individual cases, we process your personal data in order to conduct surveys about your satisfaction with KfW products, to inform you about similar promotional products or to initiate or nurture business contacts. You have the right to raise an objection at any time to the processing of your personal data for the purposes of such measures. If you object to data processing for the purpose of direct marketing, we shall no longer process your personal data for such purposes. There is no requirement as to the form of such an objection. Please send your objection to one of the following addresses:

  • By post:
    KfW Group
    c/o Widerspruchsstelle
    Ludwig-Erhard-Platz 1-3
    53179 Bonn, Germany
  • By e-mail:

Status: July 2021

Contact

Data Protection Officer