Privacy Policy
Thank you for your interest in our work and for visiting our website. The protection of personal data is a top priority for us. In general, this website can be used without providing any personal data. However, the use of certain features or services on our website may require the processing of personal data. Where this is necessary, and no legal basis exists for such processing, consent will generally be obtained in advance. Personal data is always processed in compliance with the General Data Protection Regulation (GDPR). The following page explains which personal data is collected when visiting this website and how it is used. This privacy policy is available for access at any time on this page and may be saved or printed for reference.
Legislative changes or updates to internal processes may require this privacy policy to be amended. It is therefore recommended to review this notice regularly.
The IQB privacy policy is based on the terminology used by the European legislator when adopting the GDPR. The terms used are defined in a glossary at the end of this page.
1. Name and Contact Details of the Controller 🔗
The controller within the meaning of the General Data Protection Regulation is the IQB board of directors: Institut zur Qualitätsentwicklung im Bildungswesen – Wissenschaftliche Einrichtung der Länder an der Humboldt-Universität zu Berlin e.V.
Prof. Dr Petra Stanat (Academic Director)
Dr Anne Jostkleigrewe-Paulus (Executive Director)
Unter den Linden 6
10099 Berlin
Phone: +49 (30) 2093-46500
Email: iqboffice@iqb.hu-berlin.de
2. Name and Contact Details of the Data Protection Officer 🔗
The data protection officer of the IQB is:
Gesine Hoffmann-Holland
Phone: +49 (30) 2093-20020
Email: datenschutz@uv.hu-berlin.de
www.hu-berlin.de/de/datenschutz
3. Scope 🔗
This privacy policy applies to the internet presence of the Institute for Educational Quality Improvement, Unter den Linden 6, 10099 Berlin, which is accessible via the websites available under the domain „www.iqb.hu-berlin.de" (hereinafter referred to as "our website").
4. What is Personal Data? 🔗
Personal data refers to any information that can be used to identify you or to determine details about your personal circumstances (e.g. name, address, telephone number, date of birth, or email address). Information that cannot be linked to you, or can only be linked with disproportionate effort (e.g., because it has been anonymised), does not constitute personal data.
5. Data Processing and Purposes of Processing 🔗
Our website collects a series of general data and information whenever the website is accessed by a data subject or an automated system. This general data and information are stored in the server log files. The legal basis for processing the data is our legitimate interest pursuant to Article 6(1)(f) GDPR in ensuring the operational security of the website.
The following data may be collected:
1. The type and version of browser used
2. The operating system used by the accessing device
3. The website from which access was made (referrer URL)
4. The subpages accessed on this website
5. The date and time of access
6. The IP address in anonymised form (with the last segment removed)
7. Other similar data and information required to ensure security in the event of attacks on the IT systems
When using this general data and information, the IQB does not draw any conclusions about the data subject.This information is needed to
1. Ensure that the content of this website is delivered correctly
2. Improve and optimise the website content
3. Maintain the long-term functionality and security of the IT systems and website infrastructure
4. provide law enforcement authorities with any necessary information in case of a cyber attack. This anonymously collected data and information are statistically evaluated by the IQB to enhance data protection and security within our institution, ultimately ensuring an optimal level of protection for the personal data we process. The anonymous data contained in server log files is stored separately from any personal data provided by users.
If a data subject contacts the controller by email or via contact form, the personal data transmitted will be stored automatically. Any personal data voluntarily provided is stored for the purpose of handling the enquiry and, where necessary, responding to the data subject concerned. This personal data is not disclosed to third parties.
6. Erasure and Restriction of Personal Data 🔗
Any personal data collected is processed and stored only for as long as necessary to fulfil the relevant purpose, or as required by applicable laws or regulations. The log data referred to under Section 5 are deleted after one week.
7. Rights of the Data Subject (Withdrawal, Access, Rectification, Erasure) 🔗
In accordance with applicable legal provisions, any data subject affected by the processing of personal data has the right to request, free of charge, information or confirmation from the responsible entity about the personal data stored about them. In addition, data subjects have the right to request the rectification of inaccurate personal data without undue delay, as well as the erasure of such data, the restriction of processing, or to object to the processing of their data. Consent to the processing of personal data may be withdrawn at any time. The withdrawal does not affect the lawfulness of any processing carried out on the basis of that consent prior to its withdrawal.
Data subjects have the right to receive the personal data they have provided in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
In addition, without prejudice to any other administrative or judicial remedy, a complaint may be lodged with a supervisory authority in a member state if there are concerns regarding the lawfulness of the processing of personal data relating to the data subject.
8. Cookies 🔗
The IQB website uses cookies. Cookies are text files that are stored on a computer system via a web browser. Many websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a character string that allows websites and servers to be assigned to the specific web browser in which the cookie was stored. This enables the websites and servers visited to distinguish the individual browser of the data subject from other web browsers that contain other cookies. A specific web browser can be recognised and identified via the unique cookie ID.
Using cookies enables the IQB to provide a more user-friendly service on this website. For example, you do not have to select your preferred language setting every time you visit our website. The legal basis for the processing of cookies is Article 6(1)(f) GDPR.
You can prevent the setting of cookies by our website at any time by means of a corresponding setting of the web browser used and thus permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via a web browser or other software programmes. This is possible in all common web browsers.
9. Hyperlinks to External Websites 🔗
This website contains hyperlinks to websites operated by other providers. When a hyperlink is activated, you are redirected directly to the website of the respective provider. This can be identified, for example, by the change in the URL displayed in your browser. We do not take responsibility for the confidential handling of your data on third-party websites, as we have no control over other providers’ compliance with data protection requirements. For further information on how these providers process personal data, please refer to their privacy notices directly on the respective websites.
10. Legal Basis for Processing 🔗
Article 6(1)(a) GDPR serves as the legal basis for processing operations for which consent is obtained for a specific purpose. If the processing of personal data is necessary, for example for processing operations required to send university publications, the processing is based on Article 6(1)(b) GDPR. Where the institution is subject to a legal obligation requiring the processing of personal data, such processing is carried out on the basis of Article 6(1)(c) GDPR. In rare cases, processing personal data may be necessary in order to protect the vital interests of the data subject or another natural person.
11. Glossary 🔗
The privacy policy of Humboldt-Universität zu Berlin is based on terms used by the European legislator when adopting the GDPR. This privacy policy is intended to be clear and easy to understand. To support this, the key terms used are explained below.
This privacy policy uses the following terms:
a) Personal data
Personal data refers to any information relating to an identified or identifiable natural person (“data subject”). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an ID, location data, an online ID, or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.
b) Data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing
Processing refers to any automated operation or set of operations in relation to personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing refers to the marking of stored personal data with the aim of limiting its future processing.
e) Profiling
Profiling means any type of automated processing of personal data in which such data is used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
f) Pseudonymisation
Pseudonymisation means the processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to appropriate technical and organisational measures to ensure that the personal data is not attributed to any identified or identifiable person.
g) Controller
The controller is the natural or legal person, authority, institution, or other body that, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union law or the law of the Member States, the controller, or the specific criteria for its designation, may be provided for by Union law or by the law of the Member States.
h) Data processor
The data processor is a natural or legal person, authority, institution, or other body which processes personal data on behalf of the controller.
i) Recipient
The recipient is a natural or legal person, authority, institution, or other body to whom personal data is disclosed, whether or not that entity is a third party. However, public authorities which may receive personal data in the context of a specific investigative mandate under Union law or the law of the Member States are not regarded as recipients.
j) Third party
A third party is a natural or legal person, authority, institution, or other body other than the data subject, the controller, the data processor, or the persons authorised to process the personal data.
k) Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, given by a statement or by a clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to them.