Information on data protection at Stromnetz Berlin GmbH

compliant to Art. 13 and 14 of the General Data Protection Regulation (GDPR)

Update from 28.10.2020

Protecting your personal data is important to us. We therefore process personal data with the utmost care in accordance with the relevant regulations, such as the General Data Protection Regulation (GDPR).

Below, you will find all of the information relevant to data protection for our end customers, prospective customers, service providers and other business partners, divided as follows:

A) General data protection information at Stromnetz Berlin GmbH

B) Specific information for the use of Stromnetz Berlin GmbH websites

C) Specific information for the use of Stromnetz Berlin GmbH apps

A) General data protection information at Stromnetz Berlin GmbH

to the top

1. Entity responsible and data protection officer

The entity responsible for processing your personal data is:

Stromnetz Berlin GmbH
Eichenstrasse 3 A
12435 Berlin

represented by:

Thomas Schäfer
Dr. Erik Landeck

You can get in touch with our data protection officer at:

Stromnetz Berlin GmbH
Data Protection Officer
Chausseestraße 23
10115 Berlin
email: datenschutz@stromnetz-berlin.de

2. Data categories

The data of our end customers, prospective end customers, service providers and other business partners are processed if these data are required to fulfil the purposes specified under Section 3. This specifically refers to the following people:

End customers

  • Connection users (end consumers)
  • Meter operations customers
  • Power recipients
  • Producers
  • Other customers


Prospective customers (e.g. those requesting information, making complaints or reporting a fault)
Service providers
IT users

  • Other business partners
  • Visitors to Stromnetz Berlin GmbH premises/buildings
  • Electricity supplier employees
  • Damaging parties
  • Damaged parties
  • Premises owners
  • People requesting cable information
  • Public authority employees
  • Further business partners

Data processing includes the following categories of personal data if they are required for the purposes stated in Section 3:

  • Master data (e.g. name, private or business contact details such as address, e-mail address, phone number, employee of company, etc.)
  • Consumption, producer and meter data (e.g. meter number, meter reading, electricity consumption, address of the point of consumption, position data of the meter, meter alarms)
  • Contract data (e.g. subject matter of the contract, customer number, prices, grid usage fees, electricity supplier, "system not blocked/is blocked" status, usage rights)
  • Billing data (e.g. payment information and bank details, e.g. for producers)
  • Electricity grid fault data
  • Process data (e.g. complaint, power request, report of a fault in the electricity grid)
  • Order data (e.g. orders to service providers) and associated data basis for an order (e.g. certificates)
  • Photos, voice recordings (e.g. for incident management) and video recordings (e.g. for securing operating sites)
  • IT user data (with use of Stromnetz Berlin GmbH IT systems, e.g. the service provider portal, access data to smart measuring portal)

and

  • Comparable data.

3. Purpose and legal basis for the processing of personal data

Stromnetz Berlin GmbH, a Vattenfall Group company and network operator, is responsible for Berlin's distribution network. The company distributes electricity to grid users and operates meters.

Data processing is carried out:

3a. For the fulfilment of contractual obligations (Art. 6(1)(b) GDPR)

Data processing is necessary for the initiation, execution and billing of the contract (e.g. network connection contract). In this case, data are collected at the time the contract is concluded and during the term of the contract. Among other data, master data (e.g. name, address, e-mail address), contract data (e.g. contract duration, price) and billing data (e.g. bank details) are collected.

3b. On the basis of consent (Art. 6(1)(a) GDPR)

If we have obtained your consent to process personal data for specific purposes, processing is legitimate on this basis. SEPA direct debit mandates are also consents that we use within the scope of the agreed contract. Other examples are "Consent to receive information about potential job offers" or "Consent to use data for Gateway Administration test customers".

You may withdraw your consent at any time without stating the reason with effect for the future. Any withdrawal of consent applies with future effect and does not affect the legitimacy of the data processed until the withdrawal.

3c. On the basis of a legitimate interest (Art. 6(1)(f) GDPR)

This includes the use of your data for the following purposes (among others):

  • To ensure the general electricity supply
  • Admission and access data, among other things to safeguard our domiciliary rights, occupational health and safety, protection against damage to Stromnetz Berlin GmbH property, prevention and investigation of criminal offences
  • Prevention of manipulation of measuring equipment
  • Data relating claims for the assertion, exercise or defence of civil law claims
  • Optimisation of business processes (e.g. optimised route planning for meter replacements)
  • Creation of anonymised time-lapse films e.g. of Stromnetz Berlin GmbH construction sites

3d. On the basis of legal obligation (Art. 6(1)(c) GDPR)

As an energy supply company, Stromnetz Berlin GmbH is obliged to supply electricity in accordance with Section 1 of the German Energy Act, i.e. the aim is "to provide the general public with a grid-bound supply of electricity that is as secure, cost-effective, consumer-friendly, efficient and environmentally compatible as possible".

As a company we are also subject to various legal obligations (e.g. Energy Industry Act regarding data processing for market processes such as changing electricity suppliers), Metering Point Operation Act (e.g. consumption data), metering and calibration laws (e.g. meter data), tax laws, the German Commercial Code, the German Civil Code (e.g. compensation for damages), the German Fiscal Code (e.g. invoice data), the European General Data Protection Regulation (e.g. data required to answer a data subject's request for information), the German Renewable Energies Act and the German Combined Heat and Power Act (e.g. for producer data), which make it necessary to process your data in order to comply with the law.

4. Recipient/transfer of personal data/third country

Within Stromnetz Berlin GmbH, only units requiring access to your personal data for fulfilling the purposes stated in Section 3 are granted access to it. This also applies to service providers engaged by Stromnetz Berlin GmbH, in other words processors, in accordance with Art. 28 GDPR. Examples of these are meter reading or meter replacement service providers, IT service providers, call centres or debt collection agencies.

We only transfer personal data to third parties if this is necessary for fulfilling the above-stated purposes (e.g. your electricity provider or third-party metering point operators, insurance companies) or if you have previously given us your consent to do so.

The data is also transferred on the basis of legal obligations to public authorities where overriding legislation exists.

Currently, personal data are not generally transferred to third countries (i.e. countries outside the EU/EER). Exceptions to this are:

  • Sub-processes for the processing of supplier data (master data, contact data and bank details) are carried out with the participation of service providers in the USA and India. Insofar as the EU Commission has not issued an adequacy decision for these countries, compliance with the legal level of data protection pursuant to the GDPR is ensured by the conclusion of standard EU contractual clauses.
  • Transfer of data during the use of Google Recapchta during the use of our web portal (see Chapter "B) Specific information for the use of Stromnetz Berlin GmbH websites")

Furthermore, it is not planned to transfer personal data to third countries.

5. Retention period for personal data

We store your personal data for the purposes stated in Section 3. We delete your personal data once the contractual relationship with you has expired, all mutual claims have been fulfilled and there are no other statutory retention periods or legal reasons for the storage of the data. These include statutory retention periods as stipulated in the German Commercial Code (Handelsgesetzbuch - HGB) and the German Tax Code (Abgabenordnung - AO). Your personal data is deleted once the purposes stated in Section 3 and/or the statutory retention periods have expired.

6. Rights of affected parties – your rights

If you have any questions about the processing of your personal data, you can contact our data protection officer directly. They and their team are also available for requests for information, applications and complaints. Please send all inquiries regarding stored personal data in accordance with Art. 15 GDPR to:

Stromnetz Berlin GmbH
Data Protection Officer
Chausseestraße 23
10115 Berlin
email: datenschutz@stromnetz-berlin.de

The data protection officer is also your contact person for exercising your rights to rectification in the event of errors in the storage and processing of your data (Art. 16 GDPR), deletion of your data, for example in the event of discontinuation of purpose or withdrawal of issued consent (Art. 17 and 18 GDPR), restriction of processing, for example due to a dispute regarding the correctness of personal data or for the protection of possible existing claims (Art. 18 GDPR), opposition to processing on the basis of legitimate interest (Art. 21 GDPR), and portability of data provided by you in a machine-readable format (Art. 20 GDPR).

6a. Withdrawal of consent

If consent forms the legal basis for the processing of your data, you have the right to withdraw this consent at any time in the future. Please contact the above-mentioned data protection officer to do this.

6b. Objection pursuant to Art. 21 GDPR

If data processing takes place on the basis of a balance of interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to this processing at any time due to reasons arising from your particular situation. Please contact the above-mentioned data protection officer to do this.

6c. Right to lodge a complaint

In addition, you have the right to lodge a complaint with a responsible data protection supervisory authority (Art. 77 GDPR). The data protection supervisory authority responsible for Stromnetz Berlin GmbH can be reached at:

Berliner Beauftragte für Datenschutz und Informationsfreiheit [Berlin Commissioner for Data Protection and Freedom of Information]
Friedrichstr. 219
10969 Berlin.

7. Provision of personal data

We ask for and process only personal data that we absolutely need to deal with and fulfil the above-mentioned purposes and obligations (e.g. contract execution or to respond to questions). Without these data, no services can be carried out.

8. Data sources

We process personal data that we have received from our business partners (e.g. from your electricity supplier) within the scope of our business relationship. We also process personal data that we are permitted to collect from public sources, such as land registers. We also process personal data which we legitimately receive from our own group companies or third parties, such as electricity suppliers.

9. Automated decision-making

No automated decision-making process, including profiling (i.e. creating an overall picture of someone) is used for the justification and execution of agreements.

B) Specific information for the use of Stromnetz Berlin GmbH websites

to the top

Stromnetz Berlin GmbH provides different websites online for targeted communication with its business partners.

Storing IP addresses

Stromnetz Berlin GmbH temporarily stores log data of access to its websites for reasons of data security to ensure that its system is stable and operates securely. Log data include user IP address, browser type, length of stay on the sites, for example. To clarify: Every device requires a unique IP address for transferring data via the Internet. No personal data is analysed in this process. Data records are anonymised or deleted after two weeks at the latest.

Basis for the use of cookies

A cookies is a text information file that can be stored in the browser on the user's computer for each website visited.

On Stromnetz Berlin GmbH websites, all cookies used are assigned to one of the following three categories:

  • Cookies required for technical purposes
  • Cookies for statistics
  • Cookies for convenience

Cookies required for technical purpose are absolutely necessary for the proper and safe functioning of the website. Without these cookies, our websites could not be used as intended. These cookies are activated by default and cannot be deactivated in the consent management. Deactivating them in your browser may lead to the website not functioning properly. Data is processed on the basis of Art. 6(1)(b) and (f) GDPR.

Cookies for statistics are used to perform statistical analyses on the use of our website and for perception of web presence. For this purpose, statistics are generated that give an overview of the visits to the websites. On the basis of the collected statistical data, weak points are analysed and optimisation measures are worked out to improve the functionality, content and attractiveness of the websites. The stored statistical data are anonymised and are therefore not personal data.

Cookies for convenience are used by Stromnetz Berlin to make your visit as convenient as possible. This includes cookies in particular when using forms.

Data from cookies for statistics and convenience is processed on the basis of Art. 6(1)(a) GDPR. Before cookies for statistics or convenience are stored, you will be asked for consent. The websites also function without these cookies. Consent can be withdrawn at any time.

Links to other websites

Our websites sometimes contain links to websites of third parties. If you use these links, you will leave the Stromnetz Berlin GmbH websites and therefore also the scope of this data protection policy. The respective operators, but not Stromnetz Berlin GmbH, are responsible for compliance with the legal provisions on the target pages of the links.

Specific privacy policies for each website are set out below.

B1) Stromnetz Berlin GmbH website

Stromnetz Berlin GmbH's website can be found at www.stromnetz.berlin.

Use of cookies

Stromnetz Berlin GmbH's website uses different categories of cookies. These are:

  • Cookies required for technical purposes
  • Cookies for statistics
  • Cookies for convenience

The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
__cfduidThis cookie stores a unique number (ID) for the user's computer. This cookie is used to identify individual computers behind a shared IP address (e.g. in an Internet cafe) and to apply IT security settings for each individual computer to protect the website.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third parties1 year
ai_userThis is a cookie that can be used to count the number of users who have accessed the application over time. These cookies do not collect any information that identifies a user. All information these cookies collect is aggregated and therefore anonymous. The data is only used to improve the functionality of a website.
ARRAffinityThis cookie creates a unique connection between the user's computer and the website's IT infrastructure. This cookie enables the website to function even if many users access it.For each session
ASP.NET_
SessionId
This cookie is necessary in order to identify requests from a web browser during a limited session window while surfing the website.
ai_sessionThese cookies collect information about how users use a website, for example which pages users visit most often and whether they receive error messages from websites. These cookies do not collect any information that identifies a user. All information these cookies collect is aggregated and therefore anonymous. The data is only used to improve the functionality of a website.
accepted
cookies
The cookie categories of the cookie consent management confirmed by the user are documented in this cookie.

Cookies for statistics

NameDescriptionRecipientStorage period
_pk_idThis cookie stores a user ID and is used to fill in statistics for Stromnetz Berlin GmbH. The statistics serve as a basis for analyzing visitor behavior and making improvements. The statistics themselves are anonymized.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third parties13 month
_pk_sesThis cookie stores visitor behavior for a short time and is used to fill statistics for the Stromnetz Berlin GmbH. The statistics serve as a basis for analyzing visitor behavior and making improvements. The statistics themselves are anonymized.30 minutes
_pk_
testcookie
This cookie enables the website to test whether cookies can be set at all. It does not contain any further data.For each session

Cookies for convenience

NameDescriptionRecipientStorage period
.EPiForm_
BID
With this cookie, entries made once in forms are saved and made available to the user again when the form is used again.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third parties90 days
.EPiForm_
Visitor
Identifier
With this cookie, the user is identified when the website www.stromnetz.berlin is called up again using a unique character string (ID) contained in the cookie, in order to enable him to provide support when using forms

Use of the Matomo web analysis service

To allow us to keep improving our web pages for our end customers, we collect general information on how our website is used (page visited, browser used, length of time spent on the page, etc.).

We only collect this information if you have consented to the use of cookies for statistics.

We use the PiwikPro tool from Matomo to analyse usage of our web pages. The data is transferred to our web analysis service in encrypted form using an SSL encryption protocol. The collected data also includes the IP address of your computer. We use the full IP address exclusively for temporary determination of the probable location of use of our website, with the aid of an internal service. The IP address is anonymised on entry to the web analysis service by deleting the last two of the four bytes. This means that the full IP address is not stored in the web analysis service. Other unambiguous identifiers or references to the user, such as the MAC address, are not transferred. More information about the Matomo web analysis service is available at https://piwik.pro/privacy-policy/.

Use of a link on YouTube

By integrating YouTube videos, no cookies are set.

B2) Mein Stromnetz Berlin

"Mein Stromnetz Berlin" can be found at https://mein.stromnetz.berlin/ including from various applications such as i.e. a customer contact form https://mein.stromnetz.berlin/Kundenanfrage or entering meter readings https://mein.stromnetz.berlin/zaehlerstand.

Use of cookies

Stromnetz Berlin GmbH's website uses only cookies required for technical purposes.

The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
__cfduidThis cookie stores a unique number (ID) for the user's computer. This cookie is used to identify individual computers behind a shared IP address (e.g. in an Internet cafe) and to apply IT security settings for each individual computer to protect the website.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third parties1 year
XSRF-TOKENThis is an IT security cookie that prevents third-party websites from exerting undesired influence on this website (attack scenario: so-called Cross-Site-Request-Forgery (CSRF)). This cookie does not contain any personal data.For each session
various cookies of GoogleThese cookies are stored as part of reCAPTCHA. reCAPTCHA is used to protect our website from malicious attacks and misuse and thus also to protect the personal data that is processed in our systems. reCAPTCHA collects personal data from users in order to determine whether the actions on our website really originate from humans (and not from machines). So the IP address and other data that Google needs for the reCAPTCHA service can be sent to Google.Google Ireland Limitedvarious

Use of Google reCAPTCHA

For protection of data transfer from entry forms, such as contact or registration forms, in specific cases we use the Invisible reCAPTCHA service from Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, hereafter referred to as "Google". Data is processed on the basis of Article 6(1)(f) GDPR. Using Google reCAPTCHA enables us to protect our website against mass improper use and spam. The use of Google reCAPTCHA may also involve the sending of personal data to the servers of Google LLC, Mountain View, California, USA.

As part of this service, the page that integrates reCAPTCHA and your IP address are sent to Google. Google additionally acquires further data that is necessary for the provision and performance of this service, such as the behaviour of the website visitor, information about the operating system, browser and length of visit, cookies, display instructions and scripts, the user's entry behaviour, and mouse motions in the vicinity of the reCAPTCHA checkbox.

The IP address transferred in the framework of reCAPTCHA is not combined with other data from Google unless you are logged in to your Google account at the time when you use the reCAPTCHA plug-in. If you wish to prevent this transfer and storage by Google of data about you and your behaviour on our website, you must log out from your Google account before visiting our site or using the reCAPTCHA plug-in.

The deviating data protection provisions of Google apply to all transferred data. For information regarding the purpose and scope of data collection and further processing and use of the data by the service provider, as well as your related rights and setting options for the protection of your privacy, please consult Google's privacy policy at https://policies.google.com/privacy.

B3) Customer triggered meter assemblies [Kunden ausgelöste Zählermontagen] (ZMP)

„Kunden ausgelöste Zählermontagen“ of Stromnetz Berlin GmbH can be found at https://zaehlermontage.stromnetz.berlin/.

Use of cookies

„Kunden ausgelöste Zählermontagen“ uses only cookies required for technical purposes.

The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
__cfduidThis cookie stores a unique number (ID) for the user's computer. This cookie is used to identify individual computers behind a shared IP address (e.g. in an Internet cafe) and to apply IT security settings for each individual computer to protect the website.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third parties1 year
XSRF-TokenThis is an IT security cookie that prevents third-party websites from exerting undesired influence on this website (attack scenario: so-called Cross-Site-Request-Forgery (CSRF)). This cookie does not contain any personal data.For each session
VATTENPUBThis cookie is used to identify the session and to store the login in the IT infrastructure of the Stromnetz Berlin GmbH as well as for load distribution. Note: "VATTENPUB" is only a proper name for the classic JSESSONID cookie.
JSESSIONIDThis cookie is used to identify the session and to save the login in the IT infrastructure of this website and to distribute the load.

B4) Service provider portal [Dienstleister Portal (DLP)]

"Dienstleisterportal" of Stromnetz Berlin GmbH can be found at https://dienstleister.stromnetz.berlin/ih-portal-neu/.

Use of cookies

„Dienstleisterportal“ uses only cookies required for technical purposes.

The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
JSESSIONIDThis cookie is used to identify the session and to save the login in the IT infrastructure of this website and to distribute the load.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third partiesFor each session
DLPPROUTEIDThis cookie creates a unique connection between the user's computer and the website's IT infrastructure.

B5) Legally triggered meter assemblies [Gesetzlich ausgelöste Zählermontagen (PMR)]

„Gesetzlich ausgelöste Zählermontagen“ of Stromnetz Berlin GmbH can be found at https://mein.stromnetz.berlin/web/zaehlermontage/login.

Use of cookies

„Gesetzlich ausgelöste Zählermontagen“ uses only cookies required for technical purposes.

The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
__cfduidThis cookie stores a unique number (ID) for the user's computer. This cookie is used to identify individual computers behind a shared IP address (e.g. in an Internet cafe) and to apply IT security settings for each individual computer to protect the website.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third parties1 year
VATTENPUBThis cookie is used to identify the session and to store the login in the IT infrastructure of the Stromnetz Berlin GmbH as well as for load distribution. Note: "VATTENPUB" is only a proper name for the classic JSESSONID cookie.For each session
XSRF-TokenThis is an IT security cookie that prevents third-party websites from exerting undesired influence on this website (attack scenario: so-called Cross-Site-Request-Forgery (CSRF)). This cookie does not contain any personal data.

B6) Load profile online [Lastgang Online]

„Lastgang Online“ of Stromnetz Berlin GmbH can be found at https://lastgang-online.stromnetz.berlin/.

Use of cookies

„Lastgang Online“ uses only cookies required for technical purposes.

The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
PHPSESSIDThe cookie is used to maintain the user's personalized registration when navigating the website.Stromnetz Berlin GmbH as well as selected IT service providers commissioned by it, that means no transfer to third partiesFor each session
ROUTEIDThis cookie creates a unique connection between the user's computer and the website's IT infrastructure.
TestCookieThis cookie enables the website to test whether cookies can be set at all. It does not contain any further data.

C) Specific information for the use of Stromnetz Berlin GmbH apps

to the top

Stromnetz Berlin GmbH provides different apps for mobile devices for targeted communication with its business partners.

Basis for the use of cookies

A cookies is a text information file that can be stored in the browser on the user's mobile device for each website visited.

On Stromnetz Berlin GmbH apps uses only cookies cookies that are necessary for technical purposes.

Cookies required for technical purpose are absolutely necessary for the proper and safe functioning of the website. Without these cookies, our websites could not be used as intended. These cookies are activated by default and cannot be deactivated in the consent management. Deactivating them in your browser may lead to the website not functioning properly. Data is processed on the basis of Art. 6(1)(b) and (f) GDPR.

Specific privacy policies for each app are set out below.

C1) StromTracker Berlin

The app "StromTracker Berlin" is available for the operating systems Android (Google Play Store) and iOS (Apple App Store).

Use of cookies

This app does not create any cookies.

C2) Stromnetz Berlin Lichtstörung

The app "Lichtstörung" is available for the operating systems Android (Google Play Store) and iOS (Apple App Store).

Use of cookies

The app „Stromnetz Berlin Lichtstörung“ only uses cookies that are necessary for technical purposes. The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
SameSiteThis is an IT security cookie that prevents external websites from exerting unwanted influence on this website (attack scenario: so-called Cross-Site Request Forgery (CSRF)). All users receive the same/identical cookies, so the cookie does not contain any personal data.Stromnetz Berlin GmbH and its selected IT service providers commissioned by it, i.e. no disclosure to third partiesFor each session
SecureThis is an IT security cookie that prevents external websites from exerting unwanted influence on this website (attack scenario: so-called XSS attacks). All users receive the same/identical cookies, so the cookie does not contain any personal data.
i18nextThis cookie is used so that the app can be used internationally. All users receive the same/identical cookies, so the cookie does not contain any personal data.

C3) Stromnetz Berlin StörMeldung

The app "StörMeldung" is available for the operating systems Android (Google Play Store) and iOS (Apple App Store).

Use of cookies

The app „StörMeldung“ only uses cookies that are necessary for technical purposes. The cookies are described in detail below:

Cookies required for technical purposes

NameDescriptionRecipientStorage period
SameSiteThis is an IT security cookie that prevents external websites from exerting unwanted influence on this website (attack scenario: so-called Cross-Site Request Forgery (CSRF)). All users receive the same/identical cookies, so the cookie does not contain any personal data.Stromnetz Berlin GmbH and its selected IT service providers commissioned by it, i.e. no disclosure to third partiesFor each session
SecureThis is an IT security cookie that prevents external websites from exerting unwanted influence on this website (attack scenario: so-called XSS attacks). All users receive the same/identical cookies, so the cookie does not contain any personal data.
i18nextThis cookie is used so that the app can be used internationally. All users receive the same/identical cookies, so the cookie does not contain any personal data.