The following entities are responsible for data collection and processing:
These entities are responsible towards their respective business partners (clients, prospective clients and suppliers), employees and website visitors. The information set out below applies equally to these companies, which are collectively referred to as 'BDO' for simplicity.
You can contact our Data Protection Officer as follows:
Peter Suhren
FIRST PRIVACY GmbH
Konsul-Smidt-Str. 88
28217 Bremen
Telephone: +49 421 69 66 32 80
office@first-privacy.com
The reporting centre has been established in accordance with the applicable legal provisions, particularly Section 14(2) of the HinSchG, Section 8 of the LkSG, Section 6(5) of the GwG, and Section 55b (2)(7) of the WPO.
When using the digital whistleblowing system, personal data may be processed, and we take the protection of such data very seriously. We therefore treat personal data confidentially and comply with the statutory provisions on data protection, particularly the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
This privacy policy is intended to inform you about the nature, scope and purpose of the collection and use of personal data by us, the data controller referred to above.
As a general rule, we only collect personal data if its processing is required by law or contract, is necessary for concluding or performing a contract, or is voluntarily provided to us on the basis of consent.
We only process personal data based on consent in accordance with Article 6(1)(a) of the GDPR if we decide – with your prior express consent – to record a telephone call in an individual case.
We process personal data in accordance with Article 6(1)(f) of the GDPR to safeguard legitimate interests, such as the interest in investigating breaches of rules and conducting enquiries. This is provided that the other conditions set out in Article 6(1)(f) of the GDPR are met; specifically, where our interests, or the interests of a third party, in processing the data outweigh the interests, fundamental rights and freedoms of the data subject(s).
Furthermore, we use personal data where and to the extent necessary to safeguard legitimate legal interests, for example to defend against and enforce claims. In this respect, too, the data processing is based on Article 6(1)(f) of the GDPR.
Where necessary, we also process personal data to detect criminal offences committed by employees where there are factual indications of such offences (Article 6(1)(f) of the GDPR and Section 26(1), second sentence, of the BDSG).
Where necessary, we process personal data to comply with legal obligations. In this case, data processing is carried out on the basis of Article 6(1)(c) of the GDPR. These obligations may arise from Section 10 of the HinSchG, Section 8 of the LkSG, Section 6(5) of the GwG and Section 55b(2)(7) of the WPO, where the relevant scope of application applies.
If processing personal data is necessary to protect your vital interests or those of another natural person, Article 6(1)(d) of the GDPR serves as the legal basis.
Within the digital whistleblowing system, the report and associated correspondence are deleted three months after the conclusion of the proceedings. Notwithstanding this, the internal reporting office documents the case elsewhere in a read- and access-protected manner for two years following the conclusion of the proceedings. This retention period is required by law.
A different retention period applies to the deletion of log files relating to visits to the digital whistleblowing system.
We use the latest secure technologies, particularly 'Transport Layer Security' (TLS) (previously also known as 'Secure Socket Layer' (SSL)). All information and data transmitted using these secure methods is encrypted before being sent to us. Please note that this only works if the relevant technical settings have also been configured on your end.
The digital whistleblowing system is provided by BDO Denmark on a contractual basis and is based on the open-source software 'GlobaLeaks'. BDO Denmark provides technical support for the system. Even BDO Denmark colleagues have no access whatsoever to the content of actual reports or their senders.
Data processing takes place exclusively within the territory of the Federal Republic of Germany, a Member State of the European Union (EU), or a signatory state to the Agreement on the European Economic Area (EEA).
As a user of the digital whistleblowing system, you can choose to:
If you submit an anonymous report, simply state which company the report concerns and describe its content. In this case, we do not collect any personal data relating to you, such as your name, telephone number or email address.
In addition to the above information, you may provide us with your name, position within the company, email address and telephone number, so that we can contact you if we have any questions about your report. The provision of this personal data is voluntary.
We will only collect and store this personal data if you give us your consent in accordance with Article 6(1)(a) of the GDPR when you provide the relevant details in your report.
If your data is transferred to a company outside the European Union (EU) or the European Economic Area (EEA), and if the European Commission has not made an adequacy decision pursuant to Article 45(1) of the GDPR for the relevant third country, you also consent, in accordance with Article 49(1)(a) of the GDPR, to the transfer of your personal data to that third country. We would like to point out in this context that the level of data protection in some third countries (e.g. India and China) is not comparable to that in the EU. In particular, your data may be subject to access by public authorities and intelligence services in these countries.
You may withdraw your consent at any time. To do so, please email Menschenrechtsbeauftragter@bdo.de. Please note, however, that the lawfulness of the data processing prior to receipt of the withdrawal remains unaffected.
You may also name other individuals who are aware of the incident to be reported, as well as listing those involved and witnesses. Depending on the scope of the information you provide, the following will be stored and transferred: their names; their companies; their relationship to the company; and their contact and address details.
The processing and transfer of personal data relating to those individuals is carried out on the basis of Article 6(1)(c) of the GDPR. Companies are legally obliged under the HinSchG, the LkSG, the GwG and the WPO to establish reporting offices. Pursuant to Sections 10 of the HinSchG, 8 of the LkSG, 6(5) of the GwG and 55b(2)(7) of the WPO, the processing of personal data is permitted insofar as it is necessary to fulfil the reporting offices' tasks. As a reporting office, our duties include examining reports, assessing them, and making subsequent recommendations to the company we represent. This may require the processing of personal data relating to other parties and witnesses involved.
Data processing by the company we represent, and where applicable the data subject, is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in avoiding legal consequences (e.g. criminal prosecution), claims for damages, and other harm, including reputational damage.
In the event of an imminent breach of internal company policies, data processing on the basis of Article 6(1)(f) of the GDPR shall only take place if such a breach is likely to result in harm.
We will only transfer the personal data of those involved and/or witnesses to organisations outside the EU/EEA if we are authorised to do so under Articles 44 et seq. of the GDPR. In all other cases, we will not pass this data on to organisations in third countries.
Documents that you upload to the portal may contain personal data. This may include your own personal data, as well as that of other parties or witnesses involved.
If you wish to submit an anonymous report, we recommend that you redact any personal data contained in uploaded documents in advance (e.g. by blacking it out). Please note that personal data includes not only data that directly identifies a natural person (e.g. by name), but also data that makes a natural person identifiable when combined with other information which does not necessarily have to be personal data.
If you have also provided additional personal details and consented to the processing and disclosure of data, the processing and disclosure of your personal data, which may be included in the uploaded documents, is covered by Article 6(1)(a) of the GDPR. Where uploaded documents contain the personal data of involved parties and/or witnesses, processing and disclosure of data is carried out on the basis of Articles 6(1)(c) and 6(1)(f) of the GDPR.
In addition to companies to which you have consented to disclose your personal data, your data may also be transferred to external service providers (e.g. companies that destroy or archive data, cloud service providers). We only transfer your data to third parties where there is a legal basis for such transfer under data protection law.
Data transfer to third parties is based on either the fulfilment of legal obligations, legitimate interests or any consent given. Where an external service provider acts as a data processor, the data transfer takes place within the framework of a data processing agreement.
Should it ever be necessary to transfer data to processors in countries outside the EU/EEA, this will be done either on the basis of the EU Standard Contractual Clauses or to countries for which an EU adequacy decision has been issued.
As a data subject, you have the right to obtain information from any controller regarding your personal data, as well as the right to have inaccurate data rectified or erased, provided that one of the conditions set out in Article 17 of the GDPR applies. For example, this could be if the data is no longer necessary for the purposes for which it was collected. Data subjects also have the right to restrict processing if one of the conditions set out in Article 18 of the GDPR applies. In cases covered by Article 20 of the GDPR, data subjects have the right to data portability. Where data is collected on the basis of Article 6(1)(f) (data processing to safeguard legitimate interests), the data subject has the right to object to the processing at any time on grounds relating to their particular situation. In this case, we will no longer process the personal data unless there are compelling legitimate grounds for processing that override the interests, rights and freedoms of the data subject or unless the processing is necessary for the establishment, exercise or defence of legal claims. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out prior to withdrawal. If consent is withdrawn, we will cease the relevant data processing.
Every data subject has the right to lodge a complaint with a supervisory authority if they believe that the processing of their data infringes data protection regulations. This right may be exercised with a supervisory authority in the Member State where the data subject is resident, or where the alleged infringement took place. In Hamburg, this is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg.
As at: July 2026