Privacy Policy


Information pursuant to Article 13 of the GDPR regarding the processing of personal data at CISPA – Helmholtz Center for Information Security gGmbH (hereinafter referred to as CISPA).

The protection of your personal data is important to us. In this Privacy Policy, we inform you about what personal data we process when you visit our website or use one of our services, for what purposes this is done, and what rights you have.

Part I – Privacy Notice for This Website

1. Data Controller

Responsible for data processing is:
CISPA – Helmholtz-Zentrum für Informationssicherheit gGmbH
Stuhlsatzenhaus 5
66123 Saarbrücken
Germany

Phone: +49 681 87083 1521
Fax: +49 681 87083 8801
Email: info@cispa.de

CISPA is represented by the managing directors Prof. Dr. Dr. h. c. Michael Backes and Chief Operating Officer and Member of the Executive Board Dr. Kevin Streit.

CISPA coordinates the European research and excellence network ELSA (“European Lighthouse on Secure and Safe AI”) and operates this website. ELSA is a consortium of several universities, research institutions, and other partners. To the extent that individual offerings (e.g., events or registrations) are organized or technically handled by other consortium partners, separate data protection responsibilities may apply.

2. Data Protection Officer

You can contact our Data Protection Officer at:

Phone: +49 681 87083 1521
Email: dsb@cispa.de

For general questions regarding data protection, you may also contact our Data Protection Department: datenschutz@cispa.de.

3. General Information on Data Processing on This Website

3.1. Processing

The following data is processed on our website: meta and communication data (e.g., device information, browser information, IP addresses of website users), contact data (e.g., email addresses, phone numbers, fax numbers, mailing addresses), content data (e.g., text entries), and contract data.

Data subjects affected by the processing include all visitors and users of our website as well as communication partners. Data processing depends on these factors and on user behavior. For example, simply by visiting this website, only meta and communication data of website users are processed. If contact is made via email, the user’s personal data transmitted with the email is processed.

3.2. Purpose of Processing

We generally collect and use our users’ data only to the extent necessary to provide a functional and user-friendly website and our content. If contact is made via email, the purpose of the processing is to handle the inquiry.

3.3 Legal Bases for Data Processing

Data processing takes place exclusively on the basis of a legal basis. Such a basis exists if the data subject has given consent (Art. 6(1)(a), Art. 7 GDPR), if we are obligated to fulfill contractual or pre-contractual obligations (Art. 6(1)(b) GDPR), if we must comply with legal obligations (Art. 6(1)(c) GDPR), or if we are safeguarding our legitimate interests (Art. 6(1)(f) GDPR). Special provisions, such as those of the Federal Data Protection Act (BDSG), may also apply.

3.4. Recipients of Data

Your data will not be transferred to processors or other third parties for purposes other than those listed below.

We will only disclose your data to third parties if:

  • you have given your explicit consent pursuant to Article 6(1)(a) of the GDPR,
  • the disclosure is necessary pursuant to Article 6(1)(f) of the GDPR to protect our legitimate interests or those of a third party, and there is no reason to believe that you have an overriding legitimate interest in preventing the disclosure of your data,
  • there is a legal obligation to disclose the data pursuant to Article 6(1)(c) of the GDPR, and
  • this is permitted by law and necessary under Article 6(1), first sentence, (b) of the GDPR for the performance of contractual relationships with you.

We enter into a data processing agreement with data processors in accordance with Article 28 of the GDPR, under which they also commit to complying with data protection requirements.

Transfer to Countries Outside the EU/EEA

Some of the services we or platform operators use may also process personal data outside the European Union or the European Economic Area, particularly in the United States. Countries outside the EU/EEA may not have a level of data protection comparable to that under European law.

To the extent that we carry out such a transfer, we ensure that appropriate safeguards exist in accordance with Articles 44 et seq. of the GDPR, such as an adequacy decision by the European Commission or standard contractual clauses.

3.5. Data Security

In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Furthermore, we take the protection of personal data into account from the very beginning of the development and selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and privacy-friendly default settings (Article 25 of the GDPR).

3.6. Data Retention

The data we process is stored for as long as it is necessary for the purpose of processing. It is deleted as soon as the purpose of processing this data no longer applies or consent has been revoked.

Data may also be stored if this is necessary for other legally permissible purposes. Processing is then limited to these purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary to assert, exercise, or defend legal claims, or to protect the rights of another natural or legal person. Here, too, the data is deleted as soon as the purpose no longer applies.

4. What Data We Process When You Visit Our Website

When you visit our website, data that is technically necessary to display the website to you and to ensure its secure and stable operation is automatically transmitted to our server. In particular, we process:

  • the IP address of your device,
  • the date and time of access,
  • the page or file accessed,
  • information about your browser and operating system,
  • the previously visited page (referrer), if transmitted.

Purpose: To provide the website and ensure its security and stability.

Legal basis: our legitimate interest in a secure and functional website (Art. 6(1)(f) GDPR).

Retention period: The data is stored for 7 days for security reasons (e.g., to investigate cases of misuse). If longer retention is necessary for evidentiary purposes, the data will be deleted once the matter has been fully resolved.

5. Cookies and Similar Technologies

Cookies are small text files that are stored on your device. They help, for example, to technically provide the website and to save your settings.

Cookies/Technologies Requiring Consent

In addition to technically necessary cookies, we use—only with your consent—other technologies, such as those for statistical analysis of our website’s usage. These become active only after you have given your consent via our cookie banner. Your consent is voluntary and may be revoked or adjusted at any time with future effect via the settings in the cookie banner. The legal bases are Section 25(1) of the German Telemedia Act (TDDDG) for storing and retrieving information on your device, and Article 6(1)(a) of the General Data Protection Regulation (GDPR) for the subsequent processing of your data.

In this case, we provide the following information regarding the specific technologies used, their purpose, the retention period, the providers involved, and any transfers to third countries.

6. Web Analytics with Matomo

We use Matomo to statistically analyze the use of our website and to improve our offerings. The data collected helps us optimize the user experience and tailor the content of our website to the needs of our users.

The use of Matomo is limited exclusively to statistical website analysis. We do not create personal user profiles, do not use the data for advertising purposes, and do not combine it with other data sources. The IP address is processed in an anonymized (truncated) form.

In particular, we process the following data:

  • IP address (anonymized/truncated),
  • geographic information (e.g., country, region, city, based on the IP address),
  • device data (e.g., browser type, operating system, device type),
  • screen resolution and browser language settings,
  • User-Agent string (information about the browser and device),
  • pages visited (URL and page titles) as well as the duration of page visits.

Legal basis: Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR

Retention period: The anonymized data collected is stored for a maximum period of 24 months and is subsequently automatically deleted.

7. Newsletter

On our website, you have the option to subscribe to our newsletter. Through the newsletter, we regularly provide information about news, events, research activities, and other offerings related to ELSA.

When you subscribe to the newsletter, we process the personal data you provide, in particular your email address and, if applicable, other voluntary information such as your name or subject-specific interests. Required fields are marked as such.

Your data is processed exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR.

We use the so-called double opt-in procedure for newsletter registration. After you sign up, you will first receive an email containing a confirmation link. Your registration is not complete until you click on this link. This procedure serves to verify that the registration was actually performed by the owner of the provided email address.

In connection with the newsletter subscription, we also store the time of registration, the time of confirmation, and technical log data, to the extent necessary to verify that consent was properly given.

You may revoke your consent at any time with future effect. To do so, you can use the unsubscribe link included in every newsletter email or contact us using the contact information provided in this Privacy Policy.

The data collected in connection with the newsletter will be deleted as soon as it is no longer necessary for the purposes of sending the newsletter or you have revoked your consent, provided that no statutory retention obligations prevent this. Registration is done via an online form provided by Qualtrics.

8. Events, Registrations, and Funding Programs

Through our website, we provide information about events, workshops, research opportunities, and other activities within the ELSA network. For individual events, you can register via registration forms or access further information.

Depending on the event, registration takes place either directly through ELSA or CISPA systems, or via external websites and platforms of individual network partners, research institutions, or other organizers.

If you are redirected to external websites, please note that further processing of personal data from that point onward is the responsibility of the respective external operator. Data processing on external websites is governed exclusively by the privacy notices and terms and conditions provided by the respective providers.

In the context of event registrations, the following personal data in particular may be processed:

  • First and last name,
  • email address,
  • institutional affiliation,
  • Details regarding event participation,
  • other voluntary information related to the respective event or funding program.

Personal data is processed for the purpose of organizing, conducting, and administering the respective event or the respective funding or registration program.

Individual events may also be conducted via external video conferencing and webinar services, in particular Zoom. In such cases, participants’ personal data may be processed, such as registration data, communication content, and video and audio data in connection with participation in virtual events. To the extent that events are conducted through external providers, the data protection provisions of the respective service provider or event organizer apply in addition. A transfer to third countries (e.g., the U.S.) is possible in such cases.

To the extent that ELSA or CISPA processes personal data, such processing is generally based on Article 6(1)(b) of the GDPR, provided that the processing is necessary for the purpose of event registration, or on Article 6(1)(a) of the GDPR, provided that separate consent is obtained.

9. Registration and Login Areas

Certain areas are accessible only after prior registration or after logging in with a user account.

As part of the registration and login process, we process the data you provide, in particular your email address, password, name, and, if applicable, institutional affiliation and other voluntary information. The purpose is to provide and manage the respective restricted area as well as your user account.

Legal basis: Art. 6(1)(b) GDPR (provision of the function you requested or use of the account).

Retention period: for the duration of the existing user account.

In direct connection with the respective registration, we draw your attention to the relevant privacy notices and the respective data controller.

Benchmarks

When you access the https://benchmarks.elsa-ai.eu/ section, you will be redirected to an external website. Please note that from this point on, the further processing of personal data is the responsibility of the external operator. The provider’s privacy policy and terms and conditions, as provided on that site, apply to data processing.

10. Embedded and Linked Third-Party Content (e.g., YouTube, Google Drive, Zoom)

In certain sections—such as “Education & Support” or “Courses and Tutorials”—we embed content from external providers or link to such content, particularly videos on YouTube as well as presentations and documents on Google Drive.

When you access such content or follow the corresponding links, you leave our website and access content from the respective provider. In doing so, personal data (e.g., your IP address) may be transmitted to the respective provider . This may also involve a transfer to third countries, in particular the United States. We have no influence over this processing by the providers; the privacy policies of the respective provider apply.

11. Data Subject Rights

Under the GDPR, you have the following rights in particular with respect to us:

You have the right to request confirmation as to whether data concerning you is being processed, as well as the right to access this data, to receive further information, and to obtain a copy of the data in accordance with Article 15 of the GDPR.

Pursuant to Article 16 of the GDPR, you have the right to request that data concerning you be completed or that inaccurate data concerning you be corrected.

Pursuant to Article 17 of the GDPR, you have the right to request that data concerning you be erased without delay, or, alternatively, pursuant to Article 18 of the GDPR, to request a restriction on the processing of such data.

You have the right to request, in accordance with Article 20 of the GDPR, to receive the data concerning you that you have provided to us and to request that it be transmitted to other data controllers.

You have the right to withdraw any consent you have given in accordance with Article 7(3) of the GDPR with future effect.

Right to Object: You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR (see below).

Pursuant to Article 77 of the GDPR, you may lodge a complaint with the supervisory authority responsible for data protection. As a rule, you may contact the supervisory authority in your place of residence or the Independent Data Protection Center of Saarland:

Independent Data Protection Center of Saarland

The State Commissioner for Data Protection and Freedom of Information

Fritz-Dobisch-Straße 12

66111 Saarbrücken

Phone: (0681) 94781-0

Fax: (0681) 94781-29

Email: poststelle@datenschutz.saarland.de

 

Right to Object

If your personal data is processed on the basis of legitimate interests pursuant to Article 6(1)(f) of the GDPR, you have the right, pursuant to Article 21 of the GDPR, to object to the processing of your personal data, provided there are grounds arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will honor without requiring you to specify a particular situation.

If you wish to exercise your data subject rights, you may also contact us by email at dsb@cispa.de.


Part II – Privacy Notice for Our Social Media Presence

Social Media Links on Our Website

Our website includes links to external social media platforms, in particular to profiles on LinkedIn, X, Bluesky, and YouTube.

The embedded social media buttons are purely external links and not so-called social plug-ins. This means that simply visiting our website does not, in principle, result in the automatic transmission of personal data to the respective platform operators.

The respective platform operators generally do not process personal data until you actively click on the corresponding link and access the respective social media platform. From that point on, data processing is the sole responsibility of the respective platform operator.

Please note that when using the respective platforms, personal data may also be processed outside the European Union or the European Economic Area. We have no complete control over the data processing carried out by the respective platform operators.

For more information on the processing of personal data, please refer to the privacy policies of the respective platform operators:

YouTube (Google): https://policies.google.com/privacy

LinkedIn: https://www.linkedin.com/legal/privacy-policy

X: https://x.com/de/privacy

Bluesky: https://bsky.social/about/support/privacy-policy

Data Processing on Our Social Media Channels

As the coordinator of ELSA, we maintain a presence on social media platforms, particularly on X, LinkedIn, Bluesky, and YouTube. There, we provide information about the ELSA network and engage with users.

When you visit one of our social media profiles or interact with us (e.g., through comments, direct messages, or by following our profile), the respective platform operators process your data under their own responsibility. For some of this processing (in particular, statistics on site usage), we may be jointly responsible with the respective provider (joint controllership under Art. 26 GDPR).

Purpose: Public relations, providing information about ELSA, and communicating with interested parties.

Legal basis: our legitimate interest in maintaining a modern public image and communication (Article 6(1)(f) of the GDPR); if you actively contact us, to process your inquiry.

Platform operators may also process personal data outside the EU/EEA (e.g., in the U.S.). Please also note that, according to their own statements, certain platform operators (in particular LinkedIn and Meta) may also use their users’ personal data to train AI models. We have no influence over this processing. For details and information on your options for setting preferences and exercising your right to object, please refer to the linked privacy policies of the respective providers.


Date of this Privacy Policy: May 2026