Our privacy policy
German is the authoritative version.
This English version of the Privacy Policy is provided for convenience and informational purposes only. In the event of any discrepancies or inconsistencies between the German and English versions, the German version shall prevail.
GI maintains its website to support the pursuit of its charitable objectives. The website serves, in particular, to present GI’s objectives, work and activities, as well as to facilitate communication with members and non-members from the field of computer science.
Privacy Notice for Members and Prospective Members
Privacy Notice regarding our data processing in accordance with Articles 13, 14, and 21 of the General Data Protection Regulation (GDPR). We take data protection seriously and hereby inform you about how we process your data and what claims and rights you are entitled to under data protection regulations. Effective as of May 25, 2018.
Data controller as defined by data protection law
Gesellschaft für Informatik e.V.
Ahrstraße 45
53175 Bonn
Email: info@gi.de
Contact information for our Data Protection Officer:
HEC Harald Eul Consulting GmbH
Datenschutzbeauftragter Gesellschaft für Informatik
Auf der Höhe 34
50321 Brühl
E-Mail: datenschutzbeauftragter@gi.de
We process personal data in accordance with the provisions of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and other applicable data protection regulations (details below). The specific data that may be processed—including through the use of artificial intelligence (AI)—and the manner in which it is used depend largely on the services requested or agreed upon in each case. Further details or additional information regarding the purposes of data processing can be found in the respective contractual documents, forms, a declaration of consent, and/or other information provided to you (e.g., in connection with the use of our website or our terms and conditions). In addition, this privacy notice may be updated from time to time, as you can see on our website at https://gi.de/datenschutz.
We process personal data to fulfill our contracts with you and carry out your orders, as well as to implement measures and activities within the framework of pre-contractual relationships, e.g., with prospective customers. In particular, this processing serves to provide membership services in accordance with your orders and requests and includes the services, measures, and activities necessary for this purpose. This essentially includes contract-related communication with you, the ability to verify transactions, orders, and other agreements, as well as quality control through appropriate documentation, goodwill procedures, measures to manage and optimize business processes, and the fulfillment of general due diligence obligations; statistical analyses for corporate management, cost tracking and controlling, reporting, internal and external communication, emergency management, billing and tax assessment of business services, risk management, the assertion of legal claims, and defense in legal disputes; Ensuring IT security (including system and plausibility tests) and general security, such as building and facility security, and ensuring and enforcing the right of access (e.g., through access controls); Ensuring the integrity, authenticity, and availability of data; preventing and investigating criminal offenses; oversight by supervisory bodies or audit authorities (e.g., internal audit).
Beyond the actual performance of the contract or preliminary agreement, we may process your data if necessary to protect our legitimate interests or those of third parties, in particular for the following purposes:
- advertising or market and opinion research, provided you have not objected to the use of your data;
- the review and optimization of procedures for needs analysis;
- the further development of services and products as well as existing systems and processes;
- the enrichment of our data, including through the use or research of publicly available data;
- statistical evaluations or market analysis;
- asserting legal claims and defending against legal disputes that are not directly attributable to the contractual relationship;
- restricted storage of data if deletion is not possible or is only possible with disproportionately high effort due to the specific nature of the storage;
- the prevention and investigation of criminal offenses, unless done exclusively to comply with legal requirements;
- internal and external investigations, security reviews;
- the obtaining and maintenance of certifications under private law or issued by public authorities;
- the training and (further) development of AI applications;
The processing of your personal data for specific purposes (e.g., using your email address for member information or newsletters) may also be based on your consent. As a general rule, you may revoke this consent at any time. This also applies to the revocation of consent given to us prior to the effective date of the GDPR, i.e., before May 25, 2018. You will be informed separately in the relevant consent text about the purposes and the consequences of withdrawing or refusing to give consent.
As a general rule, the withdrawal of consent takes effect only for the future. Processing that took place before the withdrawal is not affected and remains lawful.
Like anyone involved in business activities, we are also subject to a wide range of legal obligations. These primarily consist of statutory requirements (e.g., commercial and tax laws), but may also include regulatory or other governmental requirements. The purposes of processing may include identity and age verification, compliance with tax-related audit and reporting obligations, and the archiving of data for data protection and data security purposes, as well as for audits by tax and other authorities. In addition, the disclosure of personal data may be required in the context of administrative or judicial proceedings for the purposes of gathering evidence, criminal prosecution, or the enforcement of civil claims.
To the extent necessary for the provision of our services, we process personal data lawfully obtained from other companies or other third parties (e.g., credit bureaus). In addition, we process personal data that we have lawfully obtained, received, or acquired from publicly available sources (such as telephone directories, commercial and association registries, the press, the Internet, and other media) and are permitted to process.
Relevant categories of personal data may include, in particular:
- Personal details (name, occupation/industry, and similar data)
- Contact information (address, email address, phone number, and similar data)
- Address data (registration data and similar data)
- Payment/funds confirmation for bank and credit cards
- Membership history
- Data regarding your use of the telemedia we offer (e.g., time of access to our websites, apps, or newsletters; pages/links clicked on our sites or entries, and similar data)
Within our company, your data is shared with those internal departments or organizational units that require it to fulfill our contractual and legal obligations or in connection with the processing and implementation of our legitimate interests. Your data will be disclosed to external parties exclusively
- in connection with the fulfillment of the contract;
- for the purpose of complying with legal requirements under which we are obligated to provide information, report, or disclose data, or where the disclosure of data is in the public interest (see Section 2.4);
- to the extent that external service providers process data on our behalf as data processors or functional successors (e.g., external data centers, support/maintenance of computer/IT applications, archiving, document processing, data destruction, purchasing/procurement, membership administration, direct mail services, marketing, billing, telephony, website management, auditing services, financial institutions, printing companies, data disposal companies, courier services, and logistics);
- based on our legitimate interest or the legitimate interest of the third party for the purposes specified under “Purposes Based on Our Legitimate Interest or That of Third Parties” (e.g., to government agencies, credit bureaus, debt collection agencies, attorneys, courts, experts, group companies, committees, and supervisory bodies);
- if you have given us your consent to transfer your data to third parties.
We will not disclose your data to third parties beyond this. To the extent that we engage service providers under a data processing agreement, your data is subject to the same security standards there as it is with us. In all other cases, recipients may use the data only for the purposes for which it was transferred to them.
We process and store your data for the duration of our business relationship. This also includes the initiation of a contract (pre-contractual legal relationship) and the fulfillment of a contract.
In addition, we are subject to various retention and documentation requirements arising, among other things, from the German Commercial Code (HGB) and the German Fiscal Code (AO). The retention and documentation periods specified therein extend up to ten years beyond the end of the business relationship or the pre-contractual legal relationship.
Furthermore, specific statutory provisions may require a longer retention period, such as the preservation of evidence within the framework of statutory statutes of limitations. According to Sections 195 et seq. of the German Civil Code (BGB), the standard statute of limitations is three years; however, statutes of limitations of up to 30 years may also apply.
If the data is no longer necessary for the fulfillment of contractual or statutory obligations and rights, it is routinely deleted, unless its—temporary—further processing is necessary to fulfill the stated purposes based on an overriding legitimate interest. Such an overriding legitimate interest also exists, for example, if deletion is not possible—or is possible only with disproportionately high effort—due to the specific nature of the storage, and if processing for other purposes is prevented by appropriate technical and organizational measures.
Data may be transferred to entities in countries outside the European Union (EU) or the European Economic Area (EEA) (so-called third countries) where this is necessary for the performance of an order or contract from or with you, it is required by law (e.g. tax reporting obligations), it is necessary to pursue a legitimate interest of ours or of a third party, or you have given us your consent.
In this context, the processing of your data in a third country may also take place in connection with the engagement of service providers acting as data processors. Where no decision by the European Commission exists regarding an adequate level of data protection in the country in question or for specific sectors within a third country, appropriate contracts (such as EU Standard Contractual Clauses) and additional measures may be used as the basis for the transfer. Information on the appropriate or adequate safeguards and on how to obtain a copy of these may be requested from the company’s data protection officer.
Under certain conditions, you may exercise your data protection rights with us.
- You have the right to receive information from us regarding the data we have stored about you in accordance with the provisions of Article 15 of the GDPR (subject to any restrictions under Section 34 of the BDSG, if applicable).
- Upon your request, we will rectify the data we have stored about you in accordance with Article 16 of the GDPR if it is inaccurate or incorrect.
- If you wish, we will erase your data in accordance with the principles of Article 17 of the GDPR, provided that no other legal provisions (e.g., statutory retention obligations or the restrictions under Section 35 of the BDSG) or an overriding interest on our part (e.g., to defend our rights and claims) preclude this.
- Subject to the conditions set forth in Article 18 of the GDPR, you may request that we restrict the processing of your data.
- Furthermore, you may object to the processing of your data pursuant to Article 21 of the GDPR, in which case we must cease processing your data. However, this right to object applies only under very specific circumstances related to your personal situation, and our company’s rights may, in some cases, override your right to object.
- You also have the right, under the conditions set forth in Article 20 of the GDPR, to receive your data in a structured, commonly used, and machine-readable format or to have it transmitted to a third party.
- In addition, you have the right to withdraw your consent to the processing of personal data at any time, effective for the future (see Section 2.3).
- You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 of the GDPR). However, we recommend that you always direct any complaint to our Data Protection Officer first.
Your requests to exercise your rights should, if possible, be submitted in writing to the address provided above or directly to our Data Protection Officer.
You only need to provide the data that is necessary for the establishment and performance of a business relationship or for a pre-contractual relationship with us, or which we are legally obliged to collect. Without this data, we will generally not be able to conclude or fulfil the contract. This may also apply to data required later on in the course of the business relationship. Should we request any further data from you, you will be specifically informed that the provision of such information is voluntary.
We do not use fully automated decision-making processes as defined in Article 22 of the GDPR. Should we nevertheless use such a process in individual cases in the future, we will inform you separately, provided this is required by law. In some cases, we may process your data in part for the purpose of evaluating certain personal aspects (profiling). In order to provide you with targeted information and advice about our services, we may use analytical tools. These enable us to tailor our services, communications, and advertising to your needs, including market and opinion research.
1. You have the right to object at any time to the processing of your data that is carried out pursuant to Article 6(1)(f) of the GDPR (data processing based on a balancing of interests) or Article 6(1)(e) of the GDPR (data processing in the public interest), if there are grounds for doing so arising from your particular situation. This also applies to profiling based on this provision within the meaning of Article 4(4) of the GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
2. We may also process your personal data for direct marketing purposes. If you do not wish to receive advertising, you have the right to object to it at any time; this also applies to profiling to the extent that it is related to such direct marketing. We will honor this objection going forward.
We will no longer process your data for direct marketing purposes if you object to such processing.
The objection may be submitted in any form and should, if possible, be addressed to
Gesellschaft für Informatik e.V.
Ahrstraße 45, 53175 Bonn
Supplementary Privacy Policy for our website
This Privacy Policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within our web portal and its associated websites, features, and content, as well as external online presences, such as our social media profiles. (Hereinafter collectively referred to as the “web portal”). With regard to the terms used, such as “personal data” or its “processing,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Cookies are pieces of information that are transmitted from our web server to users’ web browsers and stored there for later retrieval. Cookies may be small files or other forms of information storage. We use temporary and permanent cookies. Some cookies serve security purposes or are necessary for the operation of our online services (e.g., for logging into the members’ area at https://meine.gi.de) or to save the user’s decision when confirming the cookie banner. In addition, we use cookies to measure reach, as explained in the Privacy Policy.
If users do not wish to have cookies stored on their computer, they are asked to disable the corresponding option in their browser’s settings. Stored cookies can be deleted in the browser’s settings. Disabling cookies may result in limited functionality of this website.
Based on our legitimate interests within the meaning of Article 6(1)(f) of the GDPR, we collect data regarding every access to the server on which this service is hosted (so-called server log files). Access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.
Log file information is stored for a maximum of seven days for security reasons (e.g., to investigate cases of misuse or fraud) and is deleted thereafter. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.
Matomo collects and stores the following data: the type and version of the browser you use, the operating system you use, your country of origin, the date and time of the server request, the number of visits, the length of time you spend on the website, and the external links you click on. Users’ IP addresses are anonymized before being stored.
Matomo uses cookies that are stored on users’ computers and enable an analysis of how users interact with our online service. Pseudonymous user profiles may be created from the processed data. The cookies are stored for one week. The information generated by the cookie regarding your use of this website is stored only on our server and is not shared with third parties.
The legal basis for the processing is your consent pursuant to Article 6(1)(a) of the GDPR.
The following information explains the content of our mailings, as well as our registration, mailing, and statistical analysis procedures, and your rights to object. By subscribing to our mailings, you agree to receive them and to the procedures described herein.
Content of the mailings:
We send out member information and other electronic notifications containing promotional content only with the recipients’ consent or when permitted by law. If the content of promotional materials is specifically described as part of a registration process to receive such materials, that description is decisive for the user’s consent. In addition, we send out the GI-Radar every 14 days, which contains specialized information as well as details about our services, offers, promotions, and our organization.
Mailing Service Provider:
Newsletters are sent via Maijlet (website: www.mailjet.de), hereinafter referred to as the “mailing service provider.” You can view the mailing service provider’s privacy policy here: www.mailjet.de/privacy-policy/. Furthermore, according to the mailing service provider’s own information, it may use this data in pseudonymous form—i.e., without linking it to a specific user—to optimize or improve its own services, e.g., for technical optimization of the newsletter’s delivery and presentation, or for statistical purposes to determine the countries from which recipients originate. However, the mailing service provider does not use the data of our newsletter recipients to contact them directly or to pass it on to third parties.
Cancellation/Withdrawal
You can cancel your subscription to the GI-Radar and other mailings at any time, i.e., withdraw your consent. A link to unsubscribe from the newsletter can be found at the end of every newsletter. In addition, you can manage your subscriptions under “Master Data” in the member area (https://meine.gi.de). If users have signed up for the GI-Radar trial subscription and have canceled that subscription, their personal data will be deleted.
Registration Information
To register for GI-Radar, simply provide your email address. Optionally, we ask that you provide a name so we can address you personally in GI-Radar.
Double Opt-In and Logging
Registration for GI-Radar takes place via a so-called double opt-in process. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to ensure that no one can register using someone else’s email address. Newsletter subscriptions are logged to provide evidence of the registration process in accordance with legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Changes to your data stored with the email service provider are also logged.
The logging of the registration process is based on our legitimate interests pursuant to Art. 6(1)(f) of the GDPR and serves to document consent to receive the GI Radar.
Performance Measurement
The GI Radar is delivered in both an HTML version and a plain-text version. The plain-text version does not load any content. When viewing the HTML version of the GI-Radar, HTTP requests are sent to the server gi-radar.de operated by GI, provided your email program is configured to automatically load images. No cookies are set, and no third-party content is embedded. The IP addresses of users accessing the site are not permanently stored.
The HTML version of the GI Radar includes a tracking pixel that is retrieved from gi-radar.de. This allows the GI office to estimate how many recipients have opened the GI Radar. However, a personalized analysis is technically impossible, as all readers send requests for the same tracking pixel URL. Therefore, we do not know whether you have opened the GI Radar or not.
The links contained in the GI-Radar (gi-radar.de/index.php?id or gi-radar.de/tl/) automatically redirect to the respective landing pages. The GI office can determine how often each link was clicked. However, a personalized analysis of click behavior is technically impossible, as all readers receive the same URLs. We therefore do not know which links you clicked on.
The distribution of the GI-Radar and the measurement of its effectiveness are based on the recipients’ consent pursuant to Art. 6(1)(a) and Art. 7 of the GDPR in conjunction with § 7(2)(3) of the UWG, or on the basis of statutory authorization pursuant to § 7(3) of the UWG.
On our website (https://lists.gi.de), we offer users the option to register by providing personal data. The data is entered into a form, transmitted to us, and stored. The data is not shared with third parties.
The following data is collected as part of the registration process: email address, username, first and last name (optional), and password. At the time of registration, the following data is also stored: the user’s IP address, and the date and time of registration. Registration for the mailing lists is necessary so that you can receive emails and post to the list. The data will be deleted as soon as you unsubscribe from the last list and close your user account. This applies to all data collected during the registration process as well as to data collected when subscribing to individual mailing lists, provided that your registration on our website is canceled or modified.
As a user, you have the option to cancel your registration at any time. You can have the data stored about you modified at any time. To unsubscribe from a mailing list or change your data, go to the information page for the corresponding list (https://lists.gi.de).
Use of YouTube Videos
This website occasionally uses the YouTube service to embed videos. YouTube is operated by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland. The “enhanced privacy mode” is used to embed YouTube videos, which ensures that a cookie is stored on the user’s computer only when the respective YouTube video is played. YouTube states that no personally identifiable cookie information is stored when embedded videos are played in enhanced privacy mode.
For more information on data processing and privacy policies by YouTube (Google), please visit www.google.de/intl/de/policies/privacy/. If you wish to ensure that YouTube does not receive any data from you, please do not click on the embedded YouTube videos.
Use of Vimeo Videos
This website occasionally uses the Vimeo service to embed videos. Vimeo is operated by Vimeo, LLC, 555 West 18th Street, New York, New York 10011.
When you visit subpages of our website that include a Vimeo plugin, a connection is established with the Vimeo servers, and the plugin is displayed. This transmits information to the Vimeo server about which of our subpages or web pages you have visited. If you are logged in as a Vimeo member at that time, Vimeo will associate this information with your personal user account. When you use the Vimeo plugin—for example, by clicking the play button on a video—this information is also associated with your user account. To prevent this association, log out of your Vimeo user account before using our website and delete the corresponding Vimeo cookies.
For more information on data processing and Vimeo’s privacy policy, please visit www.vimeo.com/privacy.
Our Privacy Policy and the information regarding data protection related to our data processing pursuant to Articles 13, 14, and 21 of the GDPR may change from time to time. We will publish all changes on this page. We make older versions available for your review in an archive (only available in german).
As of May 8, 2025
German is the authoritative version.
This English version of the Privacy Policy is provided for convenience and informational purposes only. In the event of any discrepancies or inconsistencies between the German and English versions, the German version shall prevail.

