Data Protection and GDPR Compliance
We are committed to protecting personal data and respecting the privacy of all project participants, partners, employees, trainers, young people, stakeholders, and website visitors.
All personal data is processed in accordance with the General Data Protection Regulation - GDPR, Regulation (EU) 2016/679 - as well as applicable national data protection legislation.
Our data protection principles
When collecting and processing personal data,
we follow the key principles established by the GDPR:
Lawfulness, fairness and transparency: Personal data is processed on a valid legal basis and individuals are clearly informed about how their data is used.
Purpose limitation: Data is collected only for clearly defined and legitimate project-related purposes.
Data minimisation: We collect only the information that is necessary for the implementation, administration, documentation and evaluation of our activities.
Accuracy: We take reasonable steps to ensure that personal data is correct and kept up to date.
Storage limitation: Personal data is retained only for as long as required by the project, funding agreement, legal obligations or applicable retention rules.
Integrity and confidentiality: Appropriate technical and organisational measures are used to protect data against unauthorised access, loss, alteration or disclosure.
Accountability: We document our data-processing activities and are able to demonstrate compliance with applicable data protection requirements.
Data processing within European projects
Personal data may be processed for purposes such as:
participant registration and communication;
implementation of workshops, training courses, events and mobility activities;
project management and cooperation between partner organisations;
attendance records, reporting and financial documentation;
evaluation, quality assurance and impact measurement;
dissemination and communication activities;
photographs, videos or testimonials where appropriate consent or another valid legal basis has been obtained.
Where children, young people or vulnerable participants are involved, additional safeguards and age-appropriate information are applied.
Personal information is not sold or used for unrelated commercial purposes.
Cooperation with project partners
and service providers
Personal data is shared only where necessary for the implementation of a project or where required by law, funding rules or contractual obligations.
Project partners, external service providers and processors are expected to comply with the GDPR and to apply appropriate data protection and security standards. Where required, data-processing agreements or joint-controller arrangements are established.
Transfers of personal data outside the European Economic Area are carried out only where an appropriate legal basis and recognised safeguards are in place.
Rights of individuals
Individuals whose personal data we process may have the right to:
request access to their personal data;
request correction of inaccurate information;
request deletion or restriction of processing;
object to certain processing activities;
withdraw consent at any time where processing is based on consent;
request data portability where applicable;
submit a complaint to the competent national data protection authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Documentation and compliance evidence
For European projects, we maintain appropriate documentation to demonstrate responsible data processing. Depending on the project and activity, this may include:
privacy notices and participant information;
consent and media-release forms;
records of processing activities;
data-processing agreements;
access and security procedures;
data-retention and deletion rules;
risk assessments and, where necessary, Data Protection Impact Assessments;
procedures for handling data-subject requests and potential data breaches.
Data protection contact
Questions concerning privacy or the processing of personal data may be directed to:
Organisation: BildungsLAB
Contact person or Data Protection Coordinator: Juergen Schroeder
Email: juergen.schroeder@bildungslab.com
Further information about individual processing activities is provided in the relevant privacy notices, registration forms or project documentation.