Send email Copy Email Address

Privacy Notice for Events Pursuant to Article 13 of the GDPR

This Privacy Notice informs you about the processing of your personal data in connection with the registration, organization, conduct, and follow-up of events held by CISPA.

This Privacy Notice applies to all types of events hosted or organized by CISPA, including, in particular, in-person events, hybrid events, and online events. These include, for example, conferences, workshops, lectures, informational events, networking events, research and educational formats, and comparable events.

Where additional privacy notices apply to specific digital services, video conferencing systems, or event platforms, these will be provided separately to participants or linked in the respective invitation.

Protecting your personal data is important to us. We process your data exclusively in accordance with applicable data protection laws. The information below fulfills our obligation to inform you about the nature, scope, and purposes of the processing of your personal data. If you have any questions regarding the processing of your personal data, you may contact us at any time.

 

I. Controller

The data controller responsible for the processing of personal data within the scope of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:

CISPA - Helmholtz Center for Information Security gGmbH
Stuhlsatzenhaus 5
66123 Saarbrücken
Germany
Tel.: + 49681 87083 1001
Fax: + 49 681 87083 8801

E-Mail: info@cispa.de

Managing Directors:
CISPA is represented by the Managing Directors Prof. Dr. Dr. h. c. mult. Michael Backes and Dr. Kevin Streit.

II. Data protection officer

You can contact our Data Protection Officer at: dsb@cispa.de.

III.    Processing of Personal Data in Connection with Events

1.     Registration and Organization of Events

Where registration is required to participate in an event, we process the personal data you provide as part of the registration process or subsequently in the course of organizing the event.
In connection with the registration, organization, conduct, and follow-up of events, we may process the following categories of personal data in particular:

  • Basic personal information (e.g., name, title, organization, role, or job title)
  • Contact information (e.g., address, email address, or phone number)
  • Event and registration information (e.g., registration status, participation information, event preferences, or information about events attended)
  • Communications data (e.g., correspondence relating to an event)

 The processing is carried out primarily for the planning, organization, conduct, and follow-up of the respective event. This includes, in particular, managing registrations, communicating with participants, preparing participant lists, name tags, access documents, and coordinating organizational procedures. 

Where necessary, we also process the data provided to accommodate individual organizational requirements relating to the event.

The processing is based on Article 6(1)(b) GDPR insofar as it is necessary for conducting the event and fulfilling the participation arrangement with you.

2.     Conduct of Events

As part of conducting events, we process personal data insofar as this is necessary to conduct the respective event, ensure its orderly operation, and maintain the security of our events.

In particular, we may process the following categories of personal data:

  • Basic personal information (e.g., name, title, organization, or role)
  • Participation data (e.g., attendance, on-site registration, or access authorizations)
  • Communications data (e.g., comments, questions, or other interactions during the event)
  • Data generated through participation in online or hybrid events (e.g., display name, chat messages, audio and video contributions, technical connection data, and log data)

When video conferencing systems are used, additional technical connection, usage, and log data may also be processed. Further information is provided in the applicable privacy notices for the system being used.

If online or hybrid events are recorded, participants will be informed separately before the recording begins. In such cases, audio, video, chat, and presentation content, as well as other communications captured as part of the recording, may be processed. Further information will be provided to participants before the recording begins.

The processing of this personal data is carried out primarily for conducting the event, managing participation, providing event-related content, facilitating interactions between participants and speakers, and ensuring the technical functionality and security of the event.

Where necessary, we also process personal data to exercise and enforce our property and premises rights, ensure the safety of participants and employees, and prevent and investigate cases of misuse or security incidents. 

In these cases, the processing is based on Article 6(1)(b) GDPR insofar as it is necessary for conducting the event and fulfilling the participation arrangement with you.

 Where the processing serves to ensure the orderly operation of the event, IT security, the exercise and enforcement of our property and premises rights, or other security purposes, it is based on Article 6(1)(f) GDPR. Our legitimate interests are the secure, uninterrupted, and efficient conduct of our events; the exercise and enforcement of our property and premises rights; and the protection of participants, employees, facilities, and IT systems.

3.     Photos and Video Recordings

Photos and video recordings may be taken during our events.

In particular, we may process the following categories of personal data:

  • Photos
  • Video recordings
  • Where applicable, other personal data associated with the recordings (e.g., name, position, or organization, if such information is mentioned in connection with publication in an individual case)

The taking and publication of photographs and video recordings serve, in particular, to document our events and to support the public relations and science communication activities of CISPA. The recordings may be published, in particular, on our websites, on social media, in press releases, in print and online publications, and in other communication and information materials.

The focus is generally on showcasing events, research activities, and the event activities as a whole. Wherever possible, we primarily use photographs and recordings showing situations and groups of people. The recordings are subject to editorial review before publication.

As a general rule, the processing of photographs and video recordings is based on Art. 6(1)(f) of the GDPR. 

Our legitimate interests include, in particular:

  • Public relations and science communication, especially providing the public with information about our research activities, research findings, and events
  • Fulfilling our public information obligations and, where applicable, existing documentation and reporting obligations toward funding organizations
  • Presenting our activities, expertise, and research priorities to the public, scientific institutions, cooperation partners, and funding organizations
  • Promoting transparency, visibility, and public dialogue in the field of cybersecurity research
  • Building our reputation and trust, as well as recruiting scientific professionals, cooperation partners, and obtaining research funding
  • Internal communication, documenting projects and events, and fostering a sense of community within CISPA

Where consent is obtained for specific recordings or purposes of use, the processing is based on Art. 6(1)(a) of the GDPR. Consent that has been given may be withdrawn at any time, with effect for the future.

Where photographs or video recordings are created and used on the basis of a separate agreement or contract with the individual concerned, the processing is based on Art. 6(1)(b) of the GDPR.

If you do not wish to be photographed or recorded, you may inform the photography or video team at any time while on site. You may also contact us at any time at:pr@cispa.de.

4.     Compliance with Legal Obligations

 Where necessary to comply with legal obligations, we may also process personal data independently of the actual conduct of the event.

Depending on the circumstances and the applicable legal obligation, the following categories of personal data may be processed in particular:

  • Basic personal data (e.g., name, organization, or position)
  • Attendance information
  • Billing and documentation data
  • Other information required to fulfill statutory documentation, evidentiary, or retention obligations

The processing is carried out in particular to fulfill statutory documentation, evidentiary, retention, and accountability obligations.

This may include, for example, documenting hospitality expenses, complying with tax and budgetary requirements, processing event-related billing, and fulfilling documentation and reporting obligations toward funding organizations or supervisory authorities.

The processing is based on Art. 6(1)(c) of the GDPR insofar as it is necessary to comply with a legal obligation to which CISPA is subject.

IV.    Recipients of Personal Data

Within CISPA, access to your personal data is limited to those departments and individuals who require it to perform their respective duties.

In addition, we may transfer personal data to external recipients where this is necessary for the organization, conduct, or follow-up of events, or where we are legally required to do so.

Recipients may include, in particular:

  • service providers involved in organizing and conducting events,
  • IT and hosting service providers,
  • providers of conferencing, communication, and collaboration platforms,
  • service providers responsible for admission, attendee, and registration management,
  • catering, event, and security service providers,
  • photographers, videographers, and service providers involved in media production and public relations,
  • printing and mailing service providers,
  • public authorities, government agencies, courts, or other public institutions, where there is a legal obligation to do so,
  • funding organizations or other grant providers, where this is necessary to fulfill documentation or reporting obligations.

Where external service providers process personal data on our behalf, this is carried out on the basis of a data processing agreement pursuant to Art. 28 of the GDPR.

V. Transfer of Personal Data to Third Countries 

To the extent that we use service providers or platforms in connection with the organization, conduct, or follow-up of events whose processing of personal data takes place outside the European Union (EU) or the European Economic Area (EEA), personal data may be transferred to so-called third countries. 

Such a transfer takes place only to the extent that the specific requirements of Articles 44 et seq. of the GDPR are met. This may be the case, in particular, if there is an adequacy decision by the European Commission for the third country in question or if appropriate safeguards—in particular, the Standard Data Protection Clauses adopted by the European Commission—are in place.

We will be happy to provide you with further information regarding specific transfers to third countries and the service providers used in each case upon request.  

VI.    Retention Period

As a general rule, we retain your personal data only for as long as is necessary for the respective purposes of processing. 

Data that we process in connection with the registration, organization, conduct, and follow-up of events is deleted as soon as it is no longer necessary for these purposes and provided that no legal retention obligations preclude such deletion.

Photographs and video recordings may be stored and published for the duration of their use for the purposes of public relations, science communication, documentation, and reporting. The necessity of continued storage and publication is reviewed on a regular basis. 

To the extent that personal data is processed to fulfill statutory retention, verification, or documentation obligations, it will be stored for the duration of the applicable statutory retention periods. Upon expiration of these periods, the relevant data will be deleted unless there is another legal basis for processing.

VII.    Obligation to Provide Personal Data

The provision of personal data is generally voluntary.

To the extent that the processing of personal data is necessary for the registration, organization, or conduct of an event, you must provide the personal data required to establish and carry out the participation arrangement.

Without providing this data, registration for or participation in the respective event may not be possible or may be limited.

 The provision of additional personal data is voluntary. If we ask for your consent, failure to grant or the revocation of consent generally has no adverse consequences for your participation in the event, unless the respective processing is, in exceptional cases, necessary for the conduct of the event.

VIII.    Your Rights as a Data Subject

Subject to the statutory requirements, you have the following rights:

  • right of access to personal data processed about you pursuant to Art. 15 of the GDPR,
  • right to rectification of inaccurate data or completion of incomplete data pursuant to Art. 16 of the GDPR,
  • right to erasure of your personal data pursuant to Article 17 of the GDPR,
  • right to restriction of processing pursuant to Article 18 of the GDPR,
  • right to data portability pursuant to Article 20 of the GDPR,
  • right to object to the processing of your personal data pursuant to Article 21 of the GDPR.

To exercise your rights, you may contact us or our Data Protection Officer at any time. 

To the extent that the processing of your personal data is based on your consent, you may withdraw this consent at any time with future effect. The lawfulness of the processing carried out on the basis of your consent up until the time of withdrawal remains unaffected.

You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. This right applies in particular to the data protection supervisory authority of the Member State where you habitually reside, where you work, or where the alleged infringement occurred. 

Notwithstanding the foregoing, you may also contact the data protection supervisory authority responsible for CISPA:

Unabhängiges Datenschutzzentrum Saarland (UDZ)
Fritz-Dobisch-Straße 12
66111 Saarbrücken
Email: poststelle@datenschutz.saarland.de 

Or you can use the complaint form available at
https://www.datenschutz.saarland.de/online-dienste/beschwerde-kontrollanregung/beschwerdeformular.

IX.    Automated Decision-Making

Automated decision-making, including profiling as defined in Article 22 of the GDPR, does not take place.

Actuality and change of this privacy policy

This data protection notice is currently valid and has the status September 2026. Due to changes in legal or regulatory requirements, it may be necessary to amend this data protection notice.