Privacy Policy for Applicants

Data protection information for applicants

Booth: 05.07.2018

We are pleased that you are interested in us and are applying or have applied for a position in our company. In the following we would like to provide you with information on the processing of your personal data in connection with your application. This data protection information applies in addition to our general data protection notice.

1. Who is responsible for data processing?

Responsible in the sense of data protection law is

Utimaco Management GmbH
Germanusstraße 4
52080 Aachen


You will find the contact information of our data protection officer in section 9.

You will find further information about our company, details of the authorized representatives and other contact details in our imprint on our website:

2. Which of your data will be processed by us? And for what purposes?

We process data you have sent us in connection with your application in order to check your suitability for the position (or any other open positions in our company) and to carry out the application procedure.

If you have also provided us with special categories of personal data (e.g. religious affiliation, health data, degree of disability) within the scope of your application, we will process these on the basis of your consent. In this case, the processing only takes place in order to take your application into account in the application process. The data of special data categories are generally not taken into account by us in the selection decision, unless the consideration results from a legal obligation. We therefore ask you to refrain from communicating this data to us in principle.

You can use the button "Use LinkedIn Profile" to have certain data from your LinkedIn profile transferred directly to the application form by entering your LinkedIn login data. If you decide to use this function within the application process, you will be redirected to the LinkedIn network website after clicking. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. These data are automatically entered into the application form after you have entered your login data and given your consent to the transfer. The data is transferred once. There is no permanent connection to LinkedIn. However, you can delete this data in the respective text field. Only after sending the application form we receive the data selected and indicated by you. Through the use of LinkedIn the following data can be collected from us:

  • Name
  • Profile picture
  • Slogan
  • Current positions
  • Place
  • Link to your LinkedIn profile

When using LinkedIn services, LinkedIn processes data. This includes login data, device type information, page visits and IP addresses. In addition, LinkedIn uses cookies, i.e. small text files which are stored on your computer and which, for example, allow recognition when you visit the site again.

The data will be stored by LinkedIn in compliance with the "EU-U.S.-Privacy Shield". LinkedIn Corporation is certified according to the Privacy Shield ( According to the EU Commission, a company on the "Privacy Shield List" can in principle be assumed to offer an adequate level of data protection.

Further information on data protection at LinkedIn can be found at

3. What is the legal basis for this?

The legal basis for processing your personal data in this application procedure is primarily § 26 Federal Data Protection Act (German Bundesdatenschutzgesetz, BDSG) in conjunction with Art. 6 Para. 1 lit. b) GDPR. It allows the processing of data required in connection with the decision to establish an employment relationship.

In individual cases, we process your data to protect the legitimate interests of the controller or third parties (e.g. German subsidiaries of Utimaco GmbH). Such a justified interest exists in particular in the processing of your data for group-internal data exchange for administrative purposes (legal basis Art. 6 para. 1 lit. f) GDPR).

Insofar as special categories of personal data pursuant to Art. 9 para. 1 GDPR are processed, this serves the exercise of rights or the fulfilment of legal obligations under labour law and social law within the scope of the application procedure. Legal basis is Art. 9 para. 2 lit. b) GDPR in conjunction with § 26 para. 3 BDSG new version.

In addition, the processing of special categories of personal data may be subject to consent pursuant to Art. 6 para. 1 lit. a) GDPR or Art. 9 para. 2 lit. a), Art. 88 para. 1, 2 GDPR in conjunction with § 26 para. 3 sentence 2, para. 2 BDSG.

Should data be necessary for legal prosecution after completion of the application procedure, data may be processed based on the requirements of Art. 6 GDPR, in particular to safeguard legitimate interests pursuant to Art. 6 para. 1 lit. f) GDPR. We are then interested in asserting or defending claims.

As far as it comes to an employment relationship between us, we process personal data already received from you for the purpose of the employment relationship in accordance with § 26 para. 1 BDSG. This is the case if the processing is necessary for the performance or termination of the employment relationship or for the exercise or fulfilment of rights and obligations of the employees' representation of interests resulting from a law, a company agreement or an employment agreement (collective agreement).

4. How long is the data stored?

In the event of rejection, candidate data will be deleted after 6 months.

If you have agreed to further storage of your personal data, we will add your data to our applicant pool. These data will be deleted after two years.

Data of applicants who have taken part in an interview at our company will be stored for reasons of processing any travel reimbursements. The storage is limited to the data necessary for this purpose. The deadline is three years and begins at the end of the year in which the claim arose.

If you got the job after the application process, your data from the applicant data system will be transferred to our personnel information system.

5. To which recipients is the data passed on?

We use a specialized software provider for the application process. He will act as a service provider for us and may also gain knowledge of your personal data in connection with the maintenance and care of the systems. We have concluded a so-called data processing agreement with this provider, which ensures that data processing is carried out in a lawful manner.

Your application data will be reviewed by the personnel department after receipt of your application. Suitable applications are then forwarded internally to the department heads for the respective open position. Then the further procedure is coordinated.

Your data is collected for filling positions in our entire group of companies (Utimaco GmbH, Utimaco Management GmbH, Utimaco IS GmbH, Utimaco TS GmbH). Your data will be made available to the responsible decision-makers of the respective corporate affiliate for further implementation of the application process.

Within the group of companies, your data will be transferred to other corporate affiliates if they perform data processing tasks for the group's affiliated companies (e.g. IT services, recruiting etc.).

In the company, only those persons have access to your data who need to for the proper course of our application procedure.

6. Where are the data processed?

Data are processed exclusively in data centers of the Federal Republic of Germany.

7. Your rights as "data subject”

You have the right to information about the personal data processed by us. In case of an information request which is not made in writing, we ask for your understanding that we may then require proof of identity.

Furthermore, you have a right to correction, deletion or to restriction of the processing, as far as you are legally entitled to.

If we process your data pursuant to Art. 6 para. 1 lit. e or f GDPR, for example if the data processing does not serve to establish the employment relationship but to safeguard our legitimate interests, you can object to this processing at any time for reasons arising from your particular situation. We will then no longer process your personal data unless we can prove compelling reasons for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

The same applies to the right to data transferability.

To assert your rights, you can contact us at any time at the address given in section 9.

8. Withdraw Consent

In the event that we process your personal data on the basis of your consent, you can withdraw your consent at any time and without giving reasons for the future. Please use the contact data under section 9.

9. Our data protection officer

We have appointed a data protection officer, who you can reach under the following contact options:

Utimaco Management GmbH
- Data Protection Officer -
Germanusstraße 4
52080 Aachen

10. Right of appeal

You have the right to complain about our processing of personal data to a data protection supervisory authority of your choice. The data protection authority responsible for us is the

State Commissioner for Data Protection and Freedom of Information
in North Rhine-Westphalia (NRW)
[German Landesbeauftragte für den Datenschutz und Informationsfreiheit
in Nordrhein-Westfalen (LDI NRW)]

Kavalleriestraße 2-4
40213 Düsseldorf


How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.

      Your collection of download requests is empty. Visit our Downloads section and select from resources such as data sheets, white papers, webinar recordings and much more.