Data protection information & Information Security guideines for visitors
Purpose of this Document
Welcome to DEKRA!
To ensure the protection of personal data, confidential business information, employees, customers, business partners and DEKRA facilities, visitors are required to comply with both the applicable data protection requirements and the information security requirements while visiting DEKRA premises.
This document therefore provides in:
- Part A: Information regarding the processing of personal data as part of visitor registration.
- Part B: Information security and physical security requirements applicable to all visitors while on DEKRA premises.
Applicbility and Status
Applicable to: All visitors, customers, business partners, contractors, auditors, consultants and other external persons entering DEKRA premises.
Status: September 2026.
Acknowledgement
By entering DEKRA premises, visitors acknowledge that they have been informed about:
- The processing of their personal data for visitor registration purposes.
- Their obligations regarding information security, physical security and confidentiality while on DEKRA premises.
- Visitors are required to comply with these requirements throughout the duration of their visit.
Part A - Data Protection Information for Visitor Registration
Preface
With the following information, we would like to give you an overview of the processing of your personal data by us and your rights under data protection law.
Who is responsible for Data Processing and who can I Contact?
The person responsible for your personal data in terms of data protection law is:
DEKRA SE,
Handwerkstraße 15
70565 Stuttgart
What Sources and Data do we use?
We process personal data that we receive from you as part of the visitor registration process at the reception desk of the head office.
Relevant personal data may be: personal data (e.g. title, surname, first name), business contact details (e.g. e-mail address, address, telephone number), information about your employment relationship (e.g. employer, position in the company).
What do we process your Data for (Purpose of Processing) and on what legal Basis?
We process your personal data in accordance with the provisions of the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and all other relevant laws.
Irrespective of this, there may always be constellations in which we process your personal data that is not mentioned here. In these cases, you will receive separate information on data protection related to the respective occasion, insofar as this is required by law.
We process your personal data for the purpose of access control for visitors and in order to be able to issue you with a visitor badge and/or a visitor access card as part of the visitor registration process at the reception of the head office, as well as to be able to ensure the return of these.
This primarily includes personal data, business address data, business communication data as well as information about your employment relationship and position in your company.
The collection and recording of your data takes place on the basis of our legitimate interest. Our legitimate interest lies in the documentation of your visit as well as the creation, provision, assurance and traceability of the handing over of the visitor badge and/or visitor access card as well as their return. This serves to ensure smooth visitor access support.
The legal basis for the processing is Art. 6 (1) (f) GDPR.
Who gets my Data?
In order for us to be able to process your data in accordance with the purposes described above, it may be necessary to transmit your data to other recipients for processing.
Within our company group, your data may also be transmitted to other companies if they perform data processing tasks centrally for the companies affiliated to the group (e.g. IT services).
With regard to the transfer of data to recipients outside the DEKRA Group, we only pass on information if this is required by law, if we obtain your consent or if this is necessary and permissible to safeguard our legitimate interests.
Under these conditions, recipients of personal data may be, for example, service providers and vicarious agents employed by us, who receive data for these purposes, insofar as they comply in particular with confidentiality and data protection requirements. These can be, for example, companies in the IT services category. We ensure that your personal data is used in accordance with instructions by concluding processing contracts with commissioned service providers.
The processing described in this privacy notice are processed via the Microsoft M365 – Sharepoint application by our service provider Microsoft Ireland Operations Limited One Microsoft Court, South County Business Park, Leopardstown, Dublin 18, D18 DH6k. For this purpose, a corresponding data processing agreement has been concluded with Microsoft, which ensures that your personal data is processed in accordance with instructions in accordance with the requirements of European data protection law. For more information about privacy at Microsoft, see the Microsoft Privacy Statement (https://privacy.microsoft.com/de-de/privacystatement).
How long will my Data be stored?
We process your personal data for as long as this is necessary for the fulfilment of our contractual and legal obligations or for as long as we can justify a legitimate interest in the processing. If you have given us your consent, we will process your data until you withdraw your consent at the latest.
Your data will be automatically deleted 6 months after the end of your stay.
What data Protection rights do I have?
You are entitled to the following statutory rights as a data subject, provided that their requirements are met:
- Right of access about your data processed by us in accordance with Art. 15 GDPR,
- Right to rectification of inaccurate data in accordance with Art. 16 GDPR,
- Right to erasure of the data stored by us in accordance with Art. 17 GDPR,
- Right to restriction of the processing of data stored by us in accordance with Art. 18 GDPR,
- Right to data portability in accordance with Art. 20 GDPR,
- Right to object pursuant to Art. 21 GDPR,
- If you have given us your consent to data processing, you can revoke this consent at any time with effect for the future Art. 7 para. 3 GDPR,
- Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR if you believe that the processing of your personal data violates the provisions of the GDPR.
Is there an obligation for me to provide Data?
As part of the visitor registration process, you must provide the personal data that is necessary for the provision of the visitor badge and/or visitor access card or that we are legally obliged to collect. Without this information, we may not be able to provide you with appropriate access to DEKRA's business premises.
To what exitent is there automated Decision-Making or Profiling?
As a matter of principle, we do not use fully automated decision-making in accordance with Article 22 of the GDPR. If we use these procedures in individual cases, we will inform you separately about this and your rights in this regard, if required by law.
Information about your right to Object in Accordance with Article 21 of the GDPR
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is carried out on the basis of Article 6 (1) (e) of the GDPR (data processing in the public interest) and Article 6 (1) (f) of the GDPR (data processing on the basis of a balancing of interests). This also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Recipient of an Objection or Revocation
The objection or revocation can be addressed to the controller in any form.
Status and Changes to this Privacy Policy
This Privacy Policy is as of October 2023.
We reserve the right to amend this privacy policy in the future within the framework of the applicable data protection laws and, if necessary, to adapt it to changed data processing realities. We will inform you separately of any significant changes to the content.
Part B - Information Security Guidelines for Visitors
The following requirements apply for the duration of the visit and support the protection of DEKRA information, systems, facilities, employees, customers and business partners.
General Security Principles
Visitors are expected to support DEKRA’s commitment to protecting the confidentiality, integrity and availability of information and services. Any information observed, received, discussed or made available during a visit shall be treated appropriately and used only for legitimate business purposes.
Visitor Registration and Identification
Visitors must:
- Register at reception before entering DEKRA facilities.
- Provide identification where required.
- Receive a visitor badge or access credential.
- Wear the visitor badge visibly while on DEKRA premises.
- Return all visitor badges, visitor cards and temporary credentials when leaving.
Visitor Escort and Access Restrictions
Visitors may only access areas explicitly authorized for the purpose of their visit.
Visitors must:
- comply with directions given by DEKRA personnel.
- remain accompanied where required.
- be accompanied at all times when entering restricted areas.
- not enter restricted, confidential or high-security areas without authorization.
- not follow authorized personnel through secured entrances or allow other persons to enter behind them without completing the required access procedure.
- immediately notify their DEKRA host or reception if they encounter an open security door, an unescorted visitor, suspicious activity, or a security weakness.
Confidentiality Requirements
During a visit, visitors may become aware of business information belonging to DEKRA, its customers, suppliers, employees or business partners.
Visitors must:
- Treat all non-public information as confidential.
- Comply with any applicable confidentiality agreement or Non-Disclosure Agreement (NDA).
- Not disclose information obtained during their visit to unauthorized persons.
- Not copy, reproduce, publish, transmit or distribute information unless explicitly authorized.
- Only access or use information where this is explicitly authorized and necessary for the agreed business purpose.
Applicable confidentiality obligations continue after completion of the visit.
Protection of Information and Documents
Visitors shall ensure that:
- Documents and information entrusted to them are protected against unauthorized access, disclosure, modification, loss or destruction.
- Confidential, strictly confidential or classified information is never left unattended.
- Information is accessed only on a need-to-know basis.
- DEKRA information provided during meetings, workshops or site visits is protected against unauthorized viewing, overhearing or recording.
- Documents, data carriers or other information are returned or securely disposed of only as instructed by DEKRA personnel.
Photography, Video and Audio Recording
Unless explicitly authorized by the responsible DEKRA representative:
- Photography, video recording and audio recording are prohibited in restricted areas.
- Screens, documents, whiteboards, technical installations, customer information and other non-public information must not be photographed or recorded.
- Private recording devices must not be used in restricted or high-risk zones.
- Any permitted recording must be limited to the approved purpose and area.
Use of it Systems, Network and Devices
Visitors may not:
- Connect personal or external devices to DEKRA networks, systems or equipment without authorization.
- Use DEKRA information systems without an approved, personalized user account.
- Share accounts, passwords, PINs, access cards or other credentials.
- Use DEKRA resources for unauthorized or personal activities.
- Transfer DEKRA information to unauthorized systems, services or data carriers.
- Where temporary access is granted, it must be used solely for the approved business purpose and in accordance with the security instructions provided by DEKRA.
Emergency and Safety Instructions
Visitors must:
- Follow site-specific emergency and evacuation procedures.
- Follow instructions given by DEKRA employees, reception, security personnel and emergency services.
- Use emergency exits only during emergencies or when instructed.
- Immediately report safety or security concerns to their DEKRA host.
- Visitors will be informed about applicable emergency procedures as part of the local visitor management process.
Reporting Security Incidents
Visitors must immediately notify their DEKRA host or reception if they become aware of:
- A lost or stolen visitor badge, access card, device, document or data carrier.
- An unauthorized access attempt or the presence of an unauthorized person.
- The accidental or unauthorized disclosure, alteration or loss of information.
- A suspected cybersecurity incident, personal data breach or policy violation.
- Any other event that could affect DEKRA information, systems, facilities or business operations.
- Confirmed or suspected security incidents may also be reported to Information.security@dekra.com. Incidents involving personal data must additionally be reported immediately to the responsible Data Protection Officer of the relevant DEKRA legal entity.
Consequences of Non-Compliance
Failure to comply with these Information Security Guidelines may result in:
- Immediate withdrawal of visitor authorization.
- Removal from DEKRA premises.
- Restriction of future access.
- Contractual consequences for the visitor or sponsoring organization, where applicable.
- Further legal or regulatory action where justified.