Privacy Policy
Who should I contact if I have questions about data protection?
We are happy to assist you to the best of our ability with any questions regarding personal data, as well as copyright, usage rights, and licenses. Please note that we cannot provide legal advice. If in doubt, please contact the Legal Office in Department 1.
If you have questions regarding the protection of research data, please first contact us at the following email address:
fdm[at]uni-hildesheim.de
Your questions regarding data protection will be forwarded to the Data Protection Officer at the University of Hildesheim. For questions regarding IT security, please contact the IT Security Officer.
Further information on legal aspects such as copyright or licenses can be found in the Legal Aspects section. Additionally, questions regarding research ethics may need to be considered.
When do I need to comply with data protection regulations?
The General Data Protection Regulation (GDPR), the Lower Saxony Data Protection Act (NDSG), and, where applicable, the Federal Data Protection Act (BDSG) must be observed whenever personal data or data that can be linked to an individual is processed, regardless of whether it was collected by the organization itself or is being reused. Before you are permitted to work with such data, a data protection plan must be submitted to the data protection officer.
What is personal data?
Personal data refers to any information relating to an identified or identifiable natural person. This includes, among other things, names, contact details, genetic or biometric data, and online identifiers such as IP addresses (Art. 4(1) GDPR). Personal data is often derived when non-personal information is combined.
What is sensitive data?
Sensitive data is not intended for public disclosure and may only be used for scientific purposes under specific conditions. It is subject to special protection because it may include information regarding, among other things, a person’s ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, and sex life. For this reason, it is classified as a special category of personal data and is subject to stricter rules (Art. 9 GDPR, § 27 BDSG).
Does my research data constitute personal data under the GDPR?
It is not always easy to determine whether data is subject to the GDPR. The interactive virtual assistants iVA 1 and iVA 2 serve as helpful tools. iVA 1 uses a questionnaire to determine whether the GDPR applies and which regulations must be observed. iVA 2 explains what is required for legally valid consent to data processing. The results should be discussed with the data protection officer, as iVA 1 and iVA 2 are intended solely for informational purposes.
What should be taken into account when processing personal data?
In general, the processing of personal data is subject to a "presumption of prohibition with exceptions," meaning that processing is permitted only
- if it is permitted or required by law or other legal provisions (e.g., Section 13 NDSG, Article 5(1)(b) GDPR, or Article 6(1)(e) GDPR).
- if the data subject in question has given their consent (informed consent).
The following principles apply (including Art. 5 GDPR):
- Fairness and Lawfulness
- Purpose limitation
- Data minimization (“as much as necessary, as little as possible”)
- Limited storage period
- Transparency
- Data accuracy
- Confidentiality
- Data security
We recommend obtaining informed consent from all data subjects or some other form of authorization before beginning research involving personal data. Clarifying authorization for data processing after the fact will cost you time above all else.
How do I write a privacy policy?
A data protection plan must be developed as soon as personal data is to be processed for research purposes. In doing so, it is particularly important to distinguish between research data and contact information. Ensure that all required use cases (including teaching) are specified. The plan consists of several parts:
- Privacy policy with an overview of the measures taken during the collection, processing, and use of data, including storage, backup, and deletion (information sheet)
- Informed consent
- “Record of Processing Activities” in collaboration with the Data Protection Officer
- Data Protection Impact Assessment, if applicable, especially for special categories of personal data
- If applicable, user agreements with the users
- If applicable, declarations regarding the maintenance of data confidentiality by project staff
Further guidance is provided by, among others, Per Holderberg, Marie Meyer, & Johanna Nowakowski (2025): Data Protection in Online Surveys: A Practical Research Guide with Handouts, Checklists, and Best Practice Examples. In: Hildesheim Contributions to Methodological Research, No. 2025-1. https://doi.org/10.18442/hilme-2025-1
The Technical University of Munich offers eTIC—electronic Tool for the compilation of Informed Consent documents—a tool for creating data protection concepts.
What is informed consent?
In most cases, the consent of the data subjects (in writing) must be obtained for the processing of personal data, e.g., for interviews or video recordings. If you wish to develop your own consent form for your project, the legally reviewed consent form templates provided by the Qualiservice Research Data Center can offer additional guidance.
Do I have to delete personal data?
Personal data must generally be deleted as soon as the purpose for which it was collected has been fulfilled, but no later than the end of the research project, or if the right to erasure (Art. 17 GDPR) is exercised. Whenever possible, personal data should be anonymized immediately after collection, and only the anonymized data should be used thereafter.
How do I anonymize my research data?
Anonymization ensures that all personally identifiable characteristics are removed from the data, making it impossible to identify individual persons. An alternative is pseudonymization. Methods and tools such as Amnesia or QualiAnon are available for this purpose. The Research Data Education Network (FDB) provides an overview of the topic: https://www.forschungsdaten-bildung.de/anonymisieren-pseudonymisieren.
Who is responsible for technical security measures?
The person responsible for data protection in the research project is also responsible for technical and organizational security measures (TOMs) (Art. 32 GDPR). These should be determined prior to data collection and agreed upon with the data protection officer.
Am I allowed to share personal data with third parties?
This is only possible if you have explicit permission to do so, such as informed consent. It is recommended that the transfer take place behind closed doors and with access controls in place. Whenever possible, personal data should remain at the institution that collected it, and only anonymized data should be shared. Special caution is required when transferring data to other EU countries. Please contact the Data Protection Officer regarding this matter.
Am I allowed to publish personal information?
Personal data may only be published in anonymized form, unless the data subject gives explicit consent or there is a corresponding legal provision. The Technical University of Dresden provides a decision-making guide to help determine whether research data may be published:
- Paul Baumann, Philipp Krahn & Anne Lauber-Rönsberg (2019): Decision Tree for the Publication of Research Data. As of 12/2020, p. 2. https://nbn-resolving.org/urn:nbn:de:bsz:14-qucosa2-731105
Where can I find more information? (Selected links)
- Overview of data protection for research data: https://forschungsdaten.info/themen/rechte-und-pflichten/datenschutzrecht/
- Kreutzer, Till & Henning Lahmann (2021) Legal Issues in Open Science: A Guide. Hamburg University Press. https://doi.org/10.15460/HUP.211, esp. Ch. IV
- Kuschel, Linda (2018) Who “owns” research data? On the legal situation under copyright and data protection law. In: Forschung & Lehre 2 (2018), 9, pp. 764–766. https://www.forschung-und-lehre.de/forschung/wem-gehoeren-forschungsdaten-1013
- Leibniz University Hannover & Technical Information Library (2018) FAQs on Legal Aspects of Handling Research Data (Version 180215). https://doi.org/10.5281/zenodo.3233508
Contact
Please send us any questions by email.