The following data protection information is intended to explain to you in an understandable, transparent and clear manner how we, PricewaterhouseCoopers GmbH Wirtschaftsprüfungsgesellschaft (hereinafter: "PwC WPG"), process your personal data in connection with your use of our websites, applications ("apps") and online services. However, if you have any questions of understanding or other queries about data protection at PwC, please do not hesitate to contact our data protection officer at DE_Datenschutz@pwc.com or via the alternative channels specified below.
The controller within the meaning of Art. 4 No. 7 Var. 1 EU General Data Protection Regulation (GDPR) for the processing of your personal data is:
60327 Frankfurt am Main
Switchboard: +49 69 9585-0
Fax: +49 69 9585-1000
PwC WPG has appointed a data protection officer in accordance with Art. 37 GDPR. You can contact PwC's data protection officer, Dr Tobias Gräber, via the following channels:
Telephone: +49 69 9585-0
PricewaterhouseCoopers GmbH WPG
Dr. Tobias Gräber, Data Protection Officer
60327 Frankfurt am Main
You have the following rights under applicable data protection law with respect to your personal data.
Right to be informed: You may request information from PwC at any time as to whether PwC has stored your personal data and which personal data it has stored. The provision of information is free of charge for you.
The right of access does not exist or is subject to limitations if and to the extent that confidential information, such as information that is subject to professional secrecy, is disclosed.
Right to rectification: If your personal data stored by us is incorrect or incomplete, you have the right to demand that we rectify this at any time.
Right to erasure: You have the right to demand that we erase your personal data if and to the extent that the data is no longer needed for the purposes for which it was collected or if the data is processed on the basis of your consent and you have withdrawn your consent. In such cases, we must cease processing your personal data and remove that data from our IT systems and databases.
A right to deletion does not exist insofar as
the data may not be deleted due to a statutory obligation or must be processed due to a statutory obligation;
the data processing is necessary for the assertion, exercise or defence of legal claims.
Right to restrict processing: You have the right to request that we restrict the processing of your personal data.
Right to data portability: You have the right to receive from us the data you have provided in a structured, common and machine-readable format, as well as the right to have this data transferred to another controller. This right only exists if
you have provided us with the data on the basis of consent or on the basis of a contract concluded with you;
the processing is carried out with the aid of automated procedures.
Right to object to processing: If the processing of your data is based on Art. 6 (1) (f) GDPR, you may object to the processing at any time.
You can assert all of the data subject rights described above against PwC WPG by addressing your specific request to the following contact details:
By email: DE_Datenschutz@pwc.com
PricewaterhouseCoopers GmbH WPG
Dr. Tobias Gräber, Data Protection Officer
60327 Frankfurt am Main
Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.
Even if an automatic transmission of data takes place in part when you call up our website, you are not legally or contractually obliged to provide data in connection with the use of our homepage.
However, in connection with the ordering of physical items, data is necessary for the conclusion of a contract with us; the provision of this data is also free in this respect, but without the data we cannot conclude a contract with you or send you the physical items.
In connection with the contact form and contacting us by e-mail, you are also free to send us data via these channels, but without contacting us accordingly, we cannot process and answer any enquiries from you in this respect.
Recipients of the data
In order to fulfil the processing purposes listed below, data is also transferred to third parties. This may also include the transfer of personal data to European and non-European countries and the storage of data outside the EU or the European Economic Area (EEA).
Recipients bound by instructions
We share your data with service providers bound by instructions, both within the PwC network and with other third parties, such as IT service providers, who support us in our activities, e.g. as part of the administration and maintenance of the websites and the associated systems and/or for other internal or administrative purposes.
PwC WPG is a member of the global PwC network, which consists of the individual legally independent PwC firms. In the course of our activities, we use other German or foreign PwC network companies as network-internal IT service providers bound by instructions, which provide services for the operation, maintenance and care of the IT systems and applications used by the PwC network companies. This is in particular PwC IT Services Ltd. based in the United Kingdom (UK).
If we pass on data to service providers bound by instructions, we do not require a separate legal basis for this.
In addition, we share your data in individual cases both within the PwC network and with other third parties who use your data on their own responsibility. For example, in individual cases we also transfer personal data to other companies in the PwC network to support and improve the effectiveness of our business processes (including coordinated marketing activities).
In addition, we also pass on your data to other third parties in individual cases, such as authorities, courts or other bodies, if we are obliged by law or by official or court order of an EU member state to hand over personal data to these bodies. These bodies also use the data on their own responsibility.
Insofar as you have explicitly consented, Art. 6 para. 1 lit. a) GDPR is the legal basis for the data transfer. If there is a legal obligation to disclose the data, the legal basis for the data transfer is Art. 6 para. 1 lit. c) GDPR. If, on the other hand, the disclosure is necessary for the fulfilment of a contractual or pre-contractual measure with you as a natural person, Art. 6 (1) (b) GDPR is the legal basis. Otherwise, the transfer is based on our legitimate interests and the legal basis is Art. 6 (1) (f) GDPR; we and the other companies in the PwC network have an interest in making our work processes efficient and in sharing business processes within the PwC network for this purpose.
Data transfer to recipients in third countries outside the EU/EEA
Insofar as one of the above-mentioned data transfers takes place to a recipient outside the European Economic Area, an appropriate level of data protection for the foreign transfer is ensured by means of suitable security measures.
For data transfers within the PwC network, the PwC network companies have, among other things, concluded an internal data protection agreement which provides for compliance with the EU standard contractual clauses of the EU Commission within the meaning of Article 46 (2) c) of the GDPR for the transfer of personal data from EU/EEA countries to PwC network companies outside the EU/EEA.
If you have any questions about such data protection contracts based on the EU standard contractual clauses or if you would like more information about further security mechanisms and security measures for the transfer of data to third countries, please feel free to contact our data protection officer, e.g. at DE_Datenschutz@pwc.com.
Processing of personal data when accessing the website
When you access our website, we collect the data that is technically necessary to display this website to you. This is the following personal data that is automatically transmitted to our server by your browser:
Date and time of your request/website access (the app)
Time zone offset from Greenwich Mean Time (GMT)
Content of the request (information about which specific page you visited)
Access status/http status code
Amount of data transmitted in each case
Website requesting access
Browser (information about your browser)
Operating system and interface (operating system of the computer you used to access the website or the application)
Language and version of the browser software
Processing of such personal data is carried out on the basis of Art. 6 para. 1 lit. f) GDPR. The website cannot be accessed and offered to users without using such data; there is a legitimate interest in making it technically possible to access and use the website.
The above data will be stored for 7 days and then deleted.
This website is hosted by a service provider [Global Headquarters Rackspace, 1 Fanatical Place City of Windcrest, San Antonio, TX 78218], the data collected on our website is therefore stored on the servers of the service provider. The server locations are also located in European and non-European countries.
Data is transferred abroad, including to countries outside the European Union or the European Economic Area. An adequate level of data protection is ensured by using standard contractual clauses laid down by the EU Commission within the meaning of Article 46 (2) (c) GDPR. The EU standard contractual clauses may be viewed at https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2010:039:0005:0018:DE:PDF.
Integration of modules (calculators, surveys)
On our website, interactive modules such as calculators and simple surveys are integrated, with which you can have calculations carried out on the basis of algorithms or participate in the determination of opinion trends by clicking on buttons (such as "Yes"/"No"). If you call up a sub-page of this website in which such a module is integrated, your IP address, date and time of your request/call, time zone, access status/http status code, amount of data, address of the referring page, browser, operating system, language and version of the browser software will be processed by us through an IT service provider so that we can provide you with the module in this form. This processing of your personal data is justified in accordance with Art. 6 Para. 1 lit. f) GDPR. We have an interest in providing you with the functions of this website and in making the integration of the modules technically secure.
The above information is stored for 14 days and then deleted. The storage is necessary for technical security. There is no possibility of linking this data with the data you have entered into the modules.
Ordering physical articles
We occasionally offer the possibility on our website to order physical items (including printed studies, books or other materials). The data you provide in this context via the order form (in particular your first name and surname, your e-mail address, the name and address of your company and, where applicable, other details you have provided on the order form or by e-mail) will be used by us to process and handle your order.
The data accruing within the scope of your order will be stored by us for a period of three years and then deleted, unless you have expressly consented to the further use of your data. Insofar as longer legal storage obligations exist, the data will be stored for the duration of the legally prescribed storage obligation. The legal basis for data processing is Art. 6 para. 1 lit. b) GDPR.
Contact form and contact by e-mail
We provide a contact form on our website so that you can contact us with questions about PwC, our website and other enquiries. You may also contact us by e-mail.
When you contact us via the contact form or by e-mail, the data you provide (in particular your e-mail address, your first and last name and the text of your enquiry as well as any other information you have provided in the contact form or by e-mail) will be stored by us in order to process your enquiry and answer your questions.
The data processing is justified according to Art. 6 para. 1 lit. f) GDPR. We have an interest in contacting you via the website in response to your enquiry. If your request is aimed at the fulfilment of a contractual or pre-contractual measure with you as a natural person, Art. 6 para. 1 lit. b) GDPR is the legal basis for the data processing.
We will delete the data generated in the course of your enquiry/contact as soon as it is no longer required for processing your enquiry. If there are legal storage obligations, the data will be stored for the duration of the legally prescribed storage obligation. The use of the contact form is completely voluntary for you and is not a prerequisite for the use of the website.
Processing operations in marketing and partly joint controllers
PwC WPG determines the means and purposes of some of the data processing operations in the field of marketing described in more detail below, either alone or together with other companies of the German-speaking PwC network named herein (all named companies hereinafter jointly: "PwC DE"). PwC WPG and these other named PwC DE firms of the PwC network therefore process your data as joint controllers within the meaning of Art. 4 No. 7 Var. 2, 26 GDPR.
Individualised electronic approach by PwC DE
PwC DE companies process your personal data and will contact you by email for marketing purposes if you have consented for direct marketing purposes. For this purpose, we process the data provided by you in connection with the consent (in particular your first name and surname, your e-mail address, the name and address of your company, if applicable, and any other information you provided when giving your consent).
This direct mail by PwC DE firms includes PwC DE information on current advisory services and service information, news from your industry, announcements for upcoming events, information on PwC studies (including those of other PwC network firms) and other marketing information.
Based on your consent, PwC DE may tailor and individualise marketing communications to your interests. This is done by PwC DE analysing your interests, which you have explicitly communicated (e.g. via a preference centre on a PwC DE website), and your usage behaviour (e.g. content accessed, opening, clicks and reading time) both with regard to newsletters and similar communications and via linked PwC DE websites using cookies, web beacons and similar technologies and storing this information in a personal profile.
Based on your consent, PwC DE may also add to this profile your personal contact details (e.g. name, title, company and role/position) that you have provided yourself on a PwC DE website and/or that are already stored in the customer relationship management systems operated by PwC DE. Based on your consent, PwC DE may also add public information about the company that employs you to this profile.
The processing is based on your consent, which is a permissible circumstance according to Art. 6 para. 1 lit. a) GDPR. You can revoke your consent at any time with effect for the future at no additional cost, e.g. by email to email@example.com.
Your data will be stored for this purpose as long as it is required for direct advertising and you have not revoked your consent. If there are legal storage obligations, the data will be stored for the duration of the legally prescribed storage obligation.
Organisational management of your consent
PwC DE also processes your personal data to meet organisational requirements with regard to your marketing consent. This includes, for example, the validation of the email address you provided through a so-called double opt-in process and the documentation of the status (granting or withdrawal of your consent and validation of the email address) in a list jointly maintained by PwC DE for this purpose. The data processed for this purpose includes the contact details you provided when granting consent, your IP address, the individual identifier assigned by our IT systems, as well as the status and time of the granting of your consent.
If you withdraw your consent and/or object to the data processing, PwC DE will no longer use your data for marketing purposes. PwC DE will store the data required for the organisational management of your consent beyond the time of your revocation and/or objection in order to fulfil documentation and verification requirements and to ensure that your data is not processed by PwC DE for marketing purposes in the future (so-called blocking list), unless you give new consent. PwC DE will delete your data when these organisational purposes cease to apply, which will generally be after a time lapse of three years at the end of the year following the cessation of marketing activity by PwC DE.
Postal address and existing customer marketing
PwC DE will also use the information you provide (in particular your name and address) to send you marketing information by post about other offers or events.
PwC WPG will use your contact details received in connection with the sale of a service (in particular your first and last name, your e-mail address, if applicable the name and address of your company as well as any other details you may have provided) for the purpose of direct marketing of similar goods and services by electronic mail, unless you have objected to such use. You can object to this use at any time without incurring any costs other than the transmission costs according to the basic rates.
This processing is based on our legitimate interests within the meaning of Art. 6 (1) f) GDPR. There is a legitimate economic interest in informing interested parties, customers and clients about further offers and events of our own in order to establish and maintain a long-term customer relationship.
Your data will be stored for this purpose as long as this is necessary for the postal marketing approach and existing customer marketing and you have not effectively objected to the data processing. Insofar as statutory retention obligations exist, the data will be stored for the duration of the legally prescribed retention obligation.
We use so-called cookies on our website. Cookies are small text files that are sent to your browser by our web servers when you visit our website and stored on your computer for when you re-visit our website at a later time.
Cookies allow our website to access or store information from your browser about you, your settings or your device. They are mainly used to ensure the website's expected functionality. As a rule, cookies do not contain any information that could identify you directly. They do, however, make it possible to offer you a more personalised web experience.
Session cookies (transient cookies)
This website uses session cookies (also referred to as temporary or transient cookies). Session cookies are only stored for the duration of your visit to our website. The session cookies used by us serve solely to identify you for as long as you are logged on to our website and are erased at the end of each session. They are not used for any other purposes.
These cookies are required for the functionality of our website and cannot be disabled on our systems. As a rule, these cookies are only set as a response to an action taken by you constituting a service request, such as setting your privacy preferences, logging in or filling out forms. You can set your browser to block cookies or notify you of them. However, this may impair the functionality of the website in some areas.
The use of these session cookies is based on Art. 6 para. 1 lit. f) GDPR. If we did not use these cookies, you would not be able to technically access or use the website's content and services.
Permanent cookies (persistent cookies)
These cookies are automatically deleted after a specified period, which may vary depending on the cookie. Persistent cookies remain stored on your terminal device until they expire or you delete them.
We use the following categories of cookies:
These cookies allow us to count visits and trace sources of access to measure and improve the performance of our website. They help us determine which pages are most popular, which are least used and how visitors navigate the website. All information collected by these cookies is aggregated and therefore anonymous. If you do not accept these cookies, we have no way of knowing when you visited our website.
Our use of performance cookies is based on a legitimate interest within the meaning of Art. 6 (1) f) GDPR. There is a legitimate interest in analysing the use of our website as a whole by means of aggregated and anonymous data in order to improve our website offering.
We may display ads on other websites to promote relevant services, articles or events. This is made possible by advertising cookies that are used to make ads more relevant to you and your interests. These cookies also have other functions, for example, they prevent the same ad from being displayed repeatedly. The sole purpose of the ads is to call relevant PwC advertising campaigns to your attention. We do not sell your data to third parties.
In some cases, these advertising cookies are personalised and help us track how effective our marketing campaigns are and improve your online experience with us by customising it to you individually.
We only use advertising cookies with your express consent.
Some of the performance and advertising cookies used on our website are so-called third-party cookies. These are cookies from third-party providers/service providers whose tools we use on our website.
These may include, for example, cookies used by the providers of the tracking and analysis tools we use. You can find more information about third-party cookies in the information about tracking and analysis tools and other functionalities in the context of which third-party cookies are used. In addition, you can view a list of all cookies used on this website, their function and their respective storage periods in our Cookie Information.
We only use third-party cookies with your express consent.
Information on the exact validity period of the individual cookies can be found in the list below.
Provider: app.powerbi.com, Name: ai_session, Function: Display of Microsoft Power BI interfaces, Duration: 0 days
Provider: app.powerbi.com, name: ai_user, cookie category: function cookie, function: display of Microsoft Power BI interfaces, duration: 0 days
Provider: pwc.de, Name: pwc_int_usr, Cookie category: Required cookie, Function: Recognition of a visitor coming from the PwC network, Duration: 90 days
Provider: Microsoft, name: ARRAffinity, cookie category: essential cookie, function: display of energy calculators, duration: close browser.
Provider: pwcdeapps.pwc.de, Name: NLSessionSpwcdeapps, Cookie category: Mandatory cookie, Function: Display of event search, Duration: Close browser
Provider: pwcdeapps.pwc.de, Name: WhlWFLB, Cookie category: Mandatory cookie, Function: Display of event search, Duration: Close browser
Provider: pwcdeapps.pwc.de, Name: SPSessionGuid, Cookie category: Mandatory cookie, Function: Display of event search, Duration: Close browser
Provider: apps.pwc-host.de, Name: PHPSESSID, Cookie category: Mandatory cookie, Function: Display of survey, Duration: Close browser
Provider: blogs.pwc.de, Name: borlabsCookie, Cookie category: Mandatory cookie, Function: Storage of cookie preference, Duration: 7 days
Provider: onetrust.com, Name: OptanonConsent, Cookie category: Mandatory cookie, Function: Cookie preference storage, Duration: 362 days
Provider: onetrust.com, Name: OptanonAlertBoxClosed, Cookie category: Mandatory cookie, Function: Cookie preference storage, Duration: 344 days
Provider: Google Analytics, name: _ga, cookie category: performance cookie, function: user tracking: used to distinguish users, duration: 2 years
Provider: Google Analytics, name: _gat, cookie category: performance cookie, function: user tracking: used to throttle the request rate, duration: 1 minute
Provider: Google Analytics, name: _gid, cookie category: performance cookie, function: user tracking: used to distinguish users, duration: 24 hours
Provider: Salesforce, name: Salesforce__s9744cdb192d044faa1bf201d29fafd1e, cookie category: functional cookie, function: store user preferences (if any), duration: close browser.
Provider: Salesforce, name: Salesforcext_0d95e, cookie category: function cookie, function: store user preferences (if any), duration: close browser.
Deactivating the cookie settings
Most browsers are pre-set to accept cookies automatically. You can object to the creation of cookies by disabling cookies in your browser's system settings. However, please note that some cookies are absolutely necessary for the function of our website, otherwise the page cannot be called up and displayed. By deactivating cookies, you will not be able to use parts of the website (without restrictions).
Cookies, which are not strictly necessary for the functionality of our website, are only used with your prior express consent.
You can also control the installation of cookies yourself at any time by changing your browser settings and/or deleting all cookies.
This website uses Google Analytics, a web analytics service provided by Google, Inc. ("Google").
Google Analytics uses "cookies", which are text files placed on the user's computer, to help the website analyze how users use the site. The information generated by the cookie about the use of this website by users is generally transmitted to a Google server in the USA and stored there. IP anonymisation has been activated on this website so that the IP address of Google users within Member States of the European Union or in other Contracting States to the Agreement on the European Economic Area is shortened beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. We would therefore like to point out to you that data processing within the framework of Google Analytics may under certain circumstances also take place outside the scope of EU law.
On behalf of the operator of this website, Google will use this information for the purpose of evaluating the use of the website by users, compiling reports on website activity and providing other services to the website operator relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google.
Google Analytics is only used by us with your consent.
You can also prevent the storage of cookies yourself by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent.
In addition, you can prevent the collection of data generated by the cookie and related to your use of the website (incl. your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plugin available under the following link. The current link is: https://tools.google.com/dlpage/gaoptout?hl=de.
As an alternative you may refuse the use of Google Analytics by setting the performance cookie to inactive in the cookie settings.
Our website currently contains links to the following social media providers: Facebook, Twitter, LinkedIn, YouTube, Pinterest and Instagram by means of corresponding social buttons. To prevent an unwanted transfer of your usage data (e.g. address of the currently visited page) to these services, you can only access the services by clicking on the link. On the service page, these social networks may collect usage data and possibly user data. We have no influence on the collected data and data processing procedures, nor are we aware of the full extent of the data collection, the purposes of the processing, the storage periods. We also have no information on the deletion of the collected data by the plug-in provider.
Therefore, we inform you according to our state of knowledge:
Only when you call up the links does your browser establish a direct connection with the servers of the aforementioned services. In this way, the information that you have visited our website is indirectly (referrer) forwarded to these services. If you are already logged in to the service with your personal user account while visiting our website, you can usually "share" the document (so-called "sharing") or leave a comment etc. after clicking on the social buttons. If you do not wish such data transmission, we advise you not to click on the social buttons.
The purpose and scope of data collection by social media services, as well as the further processing and use of your data there and your rights and options for setting your privacy preferences can be found in the privacy policies for these services.
We have integrated YouTube videos into our online offer, which are stored on https://www.YouTube.com and can be played directly from our website. These are all integrated in "extended data protection mode", which means that no data about you as a user is transmitted to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in paragraph 2 be transmitted. We have no influence on this data transmission.
By visiting the website, YouTube receives the information that you have accessed the corresponding sub-page of our website. In addition, the data listed in the passage "Description of data processing on the website/app and legal basis for processing" is transmitted. This takes place regardless of whether YouTube provides a user account via which you are logged in or whether no user account exists. If you are logged in to Google, your data will be directly assigned to your account. If you do not want your data to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for the purposes of advertising, market research and/or designing its website in line with requirements. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and you must contact YouTube to exercise this right.
On this website we use the "SmartMaps" service of YellowMap AG, CAS-Weg 1-5, 76131 Karlsruhe.
This allows us to show you maps directly in the website and enables you to use the map function conveniently.
In order to be able to show you the maps, SmartMaps uses your IP address when the SmartMaps components are called up by the browser. This is held in the memory of the web server for approx. 5 minutes to prevent DoS attacks, after which it expires and is neither processed nor stored in any other way.
YellowMap AG is therefore a recipient of data. However, YellowMap AG does not process the data for its own purposes, but exclusively on behalf of and on the instructions of PwC. PwC has concluded an agreement on commissioned processing with YellowMap AG in accordance with Art. 28 GDPR.
Our website contains hyperlinks to websites/services of other providers. When you activate these hyperlinks, you will be redirected from our website directly to the website of the other provider. You can recognize this by the change of the URL. We cannot take any responsibility for the confidential handling of your data on these third-party websites, as we have no influence on whether these companies comply with data protection regulations. Please inform yourself directly on these websites about the handling of your personal data by these companies.
Companies of the German-speaking PwC network