KfW Privacy Notice
You can rely on the protection and security of your personal data: we consider it our responsibility to protect your privacy when processing your personal data. The following privacy notices provide an overview of the processing of your data and the rights you have under data protection regulations when using the products and services of KfW Group.
1. Who is responsible for data processing and who can I contact?
The following party is responsible:
You can reach our company data protection officer at:
2. What sources and data does KfW use?
We process personal data that we receive from our customers, business partners and website visitors in connection with the use of our website, the use of our portals, subscription to newsletters and in connection with our business relationships with these groups.
Personal data processed by us refers in particular to personal details (such as name, address, telecommunications data, date and place of birth, marital status), identification data (such as ID, residence registration data), contractual data, advertising and sales data, documentation data, registration data and similar information.
3. Why does KfW process your data and what is the legal basis?
We process personal data in accordance with the provisions of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz; BDSG) and other applicable legal regulations.
For technical reasons, it is necessary to collect and store certain personal data when you visit our website, such as the IP address, the date and duration of your visit, the websites used, the identification data of the used browser and operating system type and, if applicable, the website from which you arrived at our site. The legal basis for processing your personal data in this context is Article 6(1)(1)(f) GDPR.
However, the products and services cited as examples below, which you can find on our website, require you to provide personal data in order to use them.
3.1 General communication, use of portals and newsletters – for the purpose of performing contractual obligations and on the basis of your consent:
- General communication, particularly via the contact form,
- Processing other enquiries,
- Use of our portals, for example, our grant portal or online credit portal
The processing of your personal data in this context is generally a prerequisite for concluding and performing a contract with you or entering into a preliminary agreement with you. You are not legally obligated to make your personal data available to us. Without these data, however, we will not be able to perform the relevant contract with you. The legal basis for this processing is Article 6(1)(1)(b) GDPR. This provision permits the processing of personal data if the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps prior to entering into a contract.
If you have given us your consent to process personal data for specific purposes (e.g to send our newsletter), this consent serves as the legal basis for processing the data (Article 6(1)(1)(a) GDPR). Consent which has been granted may be revoked at any time. This also applies to revoking declarations of consent that were issued to us before the GDPR took effect, i.e. before 25 May 2018. If consent is revoked, the legality of data processing carried out before consent was revoked is not affected.
3.2 Analysis of user behaviour and direct marketing – for the purpose of safeguarding legitimate interests:
- Testing and optimising demand analysis procedures for the purpose of directly approaching customers,
- Advertising or market research and polling, insofar as you have not objected to the use of your data
- Measures in relation to business management and the further development of services and products
The legal basis for processing your personal data in this context is Article 6(1)(1)(f) GDPR unless we have, in individual cases, obtained your consent. Pursuant to this provision, processing personal data is permissible if this is necessary for the purposes of legitimate interests except where such interests are overridden by the interests or fundamental rights of the data subject which require that the personal data are not processed. We have a justified interest in aligning our offers with customer behaviour and optimising them. We believe that these interests prevail since, as an international financial institution, we must control and optimise our offers in order to fulfil our promotional mandate. The alignment with our customers allows us to offer and optimise services according to the needs and interests of our customers. We protect the relevant data in such a way that we do not see any overriding disadvantages for you.
3.3 Risk management and compliance – for the purpose of safeguarding justified interests:
- Assertion of legal claims and defence in legal disputes
- Prevention and investigation of criminal activities
- Guarantee of IT security and IT operations at the bank
- Risk management at the KfW Group
The legal basis for processing your personal data in this context is Article 6(1)(1)(f) GDPR. Our justified interest consists of complying with applicable legal provisions, maintaining the security of our IT systems and, in case of non-compliance with legal requirements or violations of security regulations, responding adequately to such circumstances, for instance by asserting legal claims. We believe that these interests prevail since, as a bank, we are subject to a significant number of regulatory requirements and have a responsibility towards our customers to ensure that the corresponding requirements and security regulations are complied with. We protect the relevant data in such a way that we do not see any overriding disadvantages for you.
3.4 Social media
You can access various social media from our website.
Caution: When choosing one of the following links, you will leave our website and be directed to the website of a social media platform. Any information available there was created without any involvement from us and we are therefore not responsible for this content. We do not accept any liability for the information being up-to-date, accurate or complete. Any reference to social media does not imply any approval on our part.
- Facebook Inc., 1601 Willow Road, Menlo Park, California 94025, USA
- Twitter, Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA
- Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- LinkedIn Ireland, 70 Sir John Rogerson’s Quay, Dublin 2, Irland
- XING AG, Dammtorstraße 30, 20354 Hamburg, Deutschland
- Shorthand Pty Ltd.
Particularly for reasons of data protection compliance, the relevant social media cannot be accessed directly. Corresponding notes are therefore displayed. In addition, you may first have to click on integrated buttons, thus giving your express consent to communication with the social media platform. Only after that will the browser connect you by establishing a direct connection with the social media platform’s servers.
Please keep in mind that we are not aware of nor do we influence how and what data find their way to the social media platform.
By activating the button, you will provide the social media platform with the information that you have opened one of the web pages of the platform on the Internet. If you are already registered with the social media platform, it will be able to link your visit with your account on the social media platform. However, even if you have not yet registered with the social media platform, it is not possible to preclude the possibility that it will collect and/or store your IP address after you click on the platform.
3.5 Cookies for website analysis
Data are collected and further processed on this website in order to continually improve and analyse our web content. For this purpose, we use the web analysis tool Mapp Intelligence (Webtrekk Analytics), a product from Mapp c/o Webtrekk GmbH, Robert-Koch-Platz 4, 10115 Berlin, Germany.
As a TÜV-certified service provider, Mapp c/o Webtrekk GmbH uses only servers in Germany
Mapp Intelligence is a statistical program that produces a pseudonymised recording of usage. In this way, we can conduct analyses of user behaviour by collecting and analysing the information communicated by your browser. However, none of these analyses are linked to individual persons. For this purpose, any personal identification characteristics, namely in this case the IP address, are deleted at the moment of processing and replaced by an indicator, which makes it impossible or at least extremely difficult to identify the data subject. This methodology ensures that KfW is routinely unable to establish a concrete link to the particular person.
The following cookies are set on this website:
- wt_r Duration: 5 minutes
- wt_rla Duration: 2 months
- wt_nbg_Q3 Duration: session
- wt3_sid Duration: session
- kfw Duration: session
- Barrierefree Duration: 1 month
Tracking cookie / Persistent cookie for detecting new customers / regular customers:
- wt3_eid Duration: 6 months
Opt-out cookie for guaranteeing your decision against tracking:
- cookieconsent_status Duration: 60 months
Cookies are small text files that are linked with the browser you are using and are stored on your hard drive, sending certain information to the person who set them.
In order to protect our Internet forms, we use the reCAPTCHA service from Google Inc. (‘Google’). ReCAPTCHA collects personal data from users, in order to determine whether the actions on our website are genuinely being performed by persons. The IP address and other data required by Google for the reCAPTCHA service are sent to Google. Here, the IP address is shortened beforehand.
You can use the function of the KfW chatbot on this website. Your IP address is collected during use and retained for three days for technical reasons. We have a legitimate interest in the collection and storage of the IP address (Article 6(1)(f) GDPR). This is necessary for the need-based design of our KfW chatbot and for guaranteeing a problem-free service. The technical operation of the KfW chatbot is carried out by a carefully selected service provider. No personal data are transmitted to any country outside the European Union or the European Economic Area.
If you use the KfW chatbot, please do not enter any personal or confidential data such as your name, address or account number. Our chats are stored for 30 days in anonymised form.
3.8 Authentication procedure for the KfW Foerderassistent funding tool
To enable the use of the KfW Foerderassistent funding tool (https://foerderassistent.kfw.de), your surname, first name, email address and telemetric data are communicated to the Microsoft Corporation in non-EU countries during the registration process. This serves the technically necessary purpose of being able to authenticate your registration process by sending an email. The data processing is based on the performance of tasks carried out in the public interest (Article 6(1)(e) GDPR). The Microsoft Corporation has undertaken to comply with the data protection standards of the EU. Your data are stored by the Microsoft Corporation for a maximum of 30 days and then deleted.
4. Who will have access to my data?
Within the bank, the departments that need your data to fulfil our contractual and legal obligations receive access to your data. Service providers and subcontractors whose services we use may also receive data for these purposes if they observe banking secrecy and data protection. With regard to the transfer of data, we have undertaken to maintain confidentiality concerning all customer-related facts and assessments about which we become aware (banking secrecy).
We may only disclose information about you to third parties if required to do so by law, if you have given your consent or if we are authorised to provide such information for other reasons. Under these conditions, recipients of personal data could include:
- Public bodies and institutions (e.g. the Deutsche Bundesbank, the Federal Financial Supervisory Authority, the Federal Court of Auditors, courts of auditors in the German states, the Federal Parliament including its committees, the European Banking Authority, the European Central Bank (ECB), the European Investment Fund (EIF), the European Investment Bank (EIB), the European Commission, German federal and state ministries, financial authorities and official bodies) in the event of a legal or official obligation.
- Other credit and financial services institutions or similar institutions to which KfW transfers personal data for the purpose of managing its business relationship with you (e.g. commercial banks or credit agencies, depending on the contract)
- Service providers which process data on our behalf (e.g. data centres).
- Specialists and the German Energy Agency (dena), if involved in the promotion.
- Other bodies or service providers, insofar as we refer explicitly to them in these privacy notices or other KfW privacy policies.
Other data recipients may be bodies for which you have given us your consent to transfer data, or for which you have exempted us from banking secrecy by agreement or consent.
If you need further information on individual recipients, please do not hesitate to contact us.
5. Will any data be transferred to a third country or to an international organisation?
Data is not transferred to entities in countries outside of the European Union (known as third countries), except in the cases specified in these privacy notices or other KfW privacy policies.
In the event of a transfer to a third country, this shall be conducted under the application of appropriate guarantees of an adequate level of data protection (Article 44ff GDPR). This may be the case, for example, if the data transfer is necessary for implementing your contractual relationship with us, if it is required by law or if you have given us your consent. Insofar as personal data is transferred by KfW from the European Union/the European Economic Area to its offices abroad, KfW will make use of instruments that are conform with data protection requirements in order to ensure that the local offices process such data with due care in accordance with European standards (EU model clauses and, in the event of legally dependent local offices, a guarantee declaration under data protection laws, the content of which can be accessed electronically via the following link:
6. How long will my data be stored?
How long personal data are stored is based on the respective processing purposes. It is not possible to list the various storage periods in detail in a reasonable format here. The criteria to determine the specific individual storage periods are the following:
- If we process data only for the purpose of executing a contractual relationship, we store the data for the duration of the contractual relationship.
- Where we process data in connection with anticipated legal disputes, we will store the data until the court proceedings have definitively been completed or until the claims at issue have become time-barred in accordance with the applicable civil law provisions. The general limitation period is three years.
- In addition, we are subject to various storage and documentation requirements arising from the German Commercial Code (HGB), the German Fiscal Code (AO), the German Banking Act (KWG), the German Money Laundering Act (GwG) and the German Securities Trading Act (WpHG), among others. The periods for retention and documentation stipulated in these laws range from two to ten years.
- When using the online version of the electronic form archive and the repayment calculator, the entered data are retained in the main memory of our server only for the duration of the use of the applications: the process duration is currently set to one hour from the start of the session. Data are not stored either temporarily or permanently.
7. What are my data protection rights?
If the statutory prerequisites are met, you have the following rights in accordance with Articles 15 to 22 GDPR:
- Right of access in accordance with Article 15 GDPR, i.e. the right to obtain confirmation from us as to whether or not personal data concerning you are being processed and, where that is the case, access to these personal data and other information;
- Right to rectification in accordance with Article 16 GDPR if personal data concerning you are not correct;
- Right to erasure in accordance with Article 17 GDPR, e.g. when the personal data are no longer necessary in relation to the purposes for which they were processed;
- Right to restriction of processing in accordance with Article 18 GDPR and
- Right to data portability in accordance with Article 20 GDPR, i.e. the right to receive your personal data from us in a structured, commonly used and machine-readable format and the right to transmit those data to another controller. However, in accordance with Article 20(3)(2) GDPR, this right shall not apply to processing necessary for the performance of a task carried out in the public interest.
With respect to the right of access and the right to erasure, the restrictions pursuant to Articles 34 and 35 of the German Federal Data Protection Act apply.
In addition, there is a right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
8. Note on data processing for undisclosed assignments and the purchase of claims receivable
In the context of undisclosed assignments for the granting of securities in business transactions, KfW is given the name, address and contractual data of the relevant debtors from the grantor of the collateral or from the seller of the receivables for the purpose of the adequate individualisation of the security collateral required by law. Insofar as the assigned receivables are not liquidated by KfW, the data are collected and stored exclusively for administrative purposes (recording of the receivables assigned as collateral) and they are not processed further in any form. In this situation, KfW is not subject to any notification requirement with regard to the data owners in accordance with Article 14(5)(b) GDPR.
There is no transfer of the data to third parties or to bodies in a third country during the course of such an undisclosed assignment. The data are deleted after the expiry of the statutory storage obligations. There is no automated individual decision-making, including profiling.
Right to revoke your consent
You can revoke consent that you have granted to process data at any time. This does not, however, affect the legality of processing carried out before consent was revoked. If you revoke your consent, we shall no longer process the data for these purposes.
Information about your rights to object
Right to object in individual cases in accordance with Article 21 GDPR
You have the right to object at any time to the processing of your personal data, which is based on the performance of tasks carried out in the public interest or a balancing of interests (Article 6(1)(1)(e) and (f) GDPR), insofar as reasons arise from your particular circumstances which preclude such data processing. This also applies if automated individual decision-making is used (Article 22 GDPR). If you raise an objection, we shall no longer process your personal data for these purposes unless we are able to provide evidence of compelling reasons for the processing which are worthy of protection and which override your interests, rights and freedoms, or unless the processing serves the purpose of establishing, exercising or defending legal claims.
In individual cases, we process your personal data in order to conduct surveys about your satisfaction with KfW products, to inform you about similar promotional products or to initiate or nurture business contacts. You have the right to raise an objection at any time to the processing of your personal data for the purposes of such measures. If you object to data processing for the purpose of direct marketing, we shall no longer process your personal data for such purposes. There is no requirement as to the form of such an objection. Please send your objection to one of the following addresses:
- By mail:
53179 Bonn, Germany
- By e-mail:
Right to object under Section 15 of the German Telemedia Act
Pursuant to Section 15 of the German Telemedia Act (Telemediengesetz; TMG), website visitors may object to the storage of their visitor data collected in anonymised form, so that such data will no longer be collected in the future.
In order to exclude Webtrekk web controlling, a cookie named ‘webtrekkOptOut’ will be set by the domain. This objection will be valid for as long as you do not delete the cookie. In order to complete the objection, please click on the following link:
Status: July 2023