berlin.de privacy policy — score 65/100 (medium risk)
Ultima analiză
Acest raport are mai mult de 28 de zile. Afișează ultima analiză salvată pentru această politică — actualizează pentru a reîncărca pagina live și a reînnoi scorul.
Conținutul raportului (rezumat, constatări, citate) a fost generat în engleză și nu este localizat.
Detalii raport
medium riscThe Senatskanzlei’s privacy notice mixes solid safeguards for basic logging but relies heavily on consent and US‑based third‑party services, leaving several GDPR gaps.
The policy provides detailed descriptions for many processing activities (browser logs, analytics, contact forms, newsletters, event registrations) and lists legal bases. It uses legitimate interest for technical logs and consent for newsletters and embedded media. However, it transfers personal data to several US‑based providers (Google, Vimeo, movingimage, Datawrapper) with only generic references to Standard Contractual Clauses, lacks explicit DPIA references, does not address AI/model training, and offers vague retention periods for some categories. Overall compliance is mixed.
Evaluare pe categorii
Defalcare a politicii pe domenii cheie de conformitate. Bun = solid, rezonabil = mixt, slab = îngrijorător.
Collects extensive technical data (IP, OS, referrer) even when only minimal data may be needed for page rendering.
Provides separate sections for each service with clear legal bases, but some processing (e.g., AI use) is omitted.
Shares data with many third parties (Google, Vimeo, movingimage, Datawrapper, Mapp) and only sometimes mentions that data are not passed on further.
Transfers to US providers are disclosed, but safeguards (SCCs, adequacy) are only mentioned in passing.
No information on whether collected data are used for profiling or training AI models.
Rights are listed comprehensively, though procedural details per service are limited.
Constatări cheie
Clauze notabile, probleme sau practici pozitive identificate (critice primele)
Legitimate interest used for extensive technical logging
The policy relies on Art. 6 (1) f DSGVO for browser logs that include IP address, OS, referrer, and user‑agent, which may exceed what is strictly necessary for security.
US‑based third‑party services with limited transfer safeguards
Google Maps, YouTube, Vimeo, movingimage and Datawrapper are US‑based; the notice only generically states that SCCs are in place for movingimage and Datawrapper, leaving the legal basis for other transfers unclear.
No mention of AI or profiling
The document does not address whether any collected data (e.g., search terms in Mapp Intelligence) are used for automated decision‑making or model training, which is required under Art. 22 DSGVO if applicable.
Consent mechanisms lack clear withdrawal process
Two‑click opt‑in for embedded media and double‑opt‑in for newsletters are described, but the policy does not explain how consent is recorded, audited, or withdrawn across devices.
Vague data retention for contact‑form and event data
The notice says data are deleted "sobald sie für die Erreichung des Zweckes nicht mehr erforderlich sind" without concrete timeframes, unlike the precise 14‑day or 4‑year periods for other logs.
Rezumat pentru utilizator
You can use the site, but be aware that personal data (IP, browsing details) may be sent to US services and the notice does not fully explain how you can control that.
Postură de conformitate
mixed
Transferuri UE
The notice acknowledges transfers to the US (Google, Vimeo, movingimage, Datawrapper) and claims SCCs for some, but does not provide concrete evidence or detail for all, making the assessment incomplete.
Semnale detectate
Date și practici specifice identificate în text
Fragmente probatorii
Citate directe din politică care susțin aceste constatări
Die Daten werden nach 14 Tagen gelöscht.
Der Webanalysedienst verwendet temporäre Sessioncookies, mit einer auf den Besuch begrenzten Laufzeit.
Die IP‑Adresse wird vor jeglicher Verarbeitung gekürzt und in anonymisierter Form zur Session‑Erkennung … verwendet.
Sobald Sie durch Anklicken des Buttons „Akzeptieren und Anzeigen“ der Anzeige von Inhalten zugestimmt haben, willigen Sie gemäß Art. 6 Abs. 1 S. 1 lit. a DSGVO darin ein, dass Ihre Daten an Google übertragen werden.
movingimage hat uns im Auftragsverarbeitungsvertrag zugesichert, dass mit diesen Unterauftragsverarbeitern Standardvertragsklauseln abgeschlossen wurden.
Lipsă sau neclar
- No explicit statement on whether data are used for AI model training or profiling.
- No reference to a Data Protection Impact Assessment (DPIA) for high‑risk processing (e.g., US transfers, analytics).
- No detailed procedure for how users can withdraw consent for embedded media across devices.
Întrebări de pus
- Haben Sie für alle US‑basierten Dienste (Google, Vimeo, movingimage, Datawrapper) ein dokumentiertes DPIA vorliegen?
- Wie wird das Opt‑out‑Cookie für Mapp Intelligence technisch umgesetzt und wird es in allen gängigen Browsern respektiert?
- Welche konkreten Aufbewahrungsfristen gelten für die Daten, die über Kontakt‑ und Veranstaltungsformulare erhoben werden?
- Werden die gesammelten Suchbegriffe aus Mapp Intelligence für maschinelles Lernen oder Profiling verwendet?
- Können Sie Nachweise über die abgeschlossenen Standardvertragsklauseln für alle Drittland‑Transfers erbringen?
Distribuie această analiză
Oricine are acest link poate vedea rezultatul de mai sus.
Creat de DentroChat
Chat AI 100% european pentru toți
Discută cu AI, lucrează cu fișiere, generează imagini și caută pe web. Datele rămân în Europa.