Data Protection
Data protection information
1. Who is responsible and whom can you contact?
The controller responsible for processing your personal data is me, Notary Grischa Franke, with my official seat in Berlin. For all data protection enquiries you can contact me or my data protection officer as follows:
Controller | Data protection officer | |
Address | Grischa Sebastian Franke Nithackstraße 18-20 10585 Berlin | Rolf Jürgen Franke Nithackstraße 18-20 10585 Berlin |
Phone | +49 30 – 2000 70 900 | +49 30 – 2000 70 900 |
Fax | ||
2. Which data do I process and where does it come from?
I process personal data that I receive from you or from third parties acting on your behalf (e.g. lawyer, tax adviser, estate agent, bank), such as:
- personal details, e.g. first name and surname, date and place of birth, nationality, marital status; in individual cases your birth register number;
- contact details, e.g. postal address, phone and fax numbers, email address;
- for real estate contracts, your tax identification number;
- in certain cases, e.g. marriage contracts, wills, inheritance contracts or adoptions, also data on your family situation and your assets and, where applicable, information on your health or other sensitive data, e.g. because it serves to document your legal capacity;
- in certain cases also data from your legal relationships with third parties, e.g. file references or loan or account numbers at banks.
I also process data from public registers, e.g. the land register, the commercial register and the register of associations.
3. For what purposes and on what legal basis is the data processed?
As a notary, I hold a public office. I perform my official duties in carrying out a task that serves the general interest in an orderly system of preventive justice, and is therefore in the public interest, and in the exercise of official authority (Art. 6(1) sentence 1 point (e) of the General Data Protection Regulation (GDPR)).
Your data is processed solely to carry out the notarial work requested by you and, where applicable, by other persons involved in a transaction, in accordance with my official duties. This includes preparing draft deeds, notarising and executing deeds, and providing advice. Personal data is therefore only ever processed on the basis of the professional and procedural rules that apply to me, which derive mainly from the Federal Notarial Code (Bundesnotarordnung) and the Notarisation Act (Beurkundungsgesetz). These rules also give rise to my legal obligation to process the required data (Art. 6(1) sentence 1 point (c) GDPR). If you do not provide the data I request from you, I would therefore have to refuse to carry out or continue the official act.
4. To whom do I pass on data?
As a notary, I am subject to a statutory duty of confidentiality. This duty also applies to all my staff and to anyone else I engage.
I may therefore pass on your data only if and to the extent that I am obliged to do so in the individual case, e.g. because of reporting obligations towards the tax authorities, or to public registers such as the land registry, the commercial register or the register of associations, the Central Register of Wills, the register of lasting powers of attorney, courts such as the probate, guardianship or family court, or public authorities. As part of professional and official supervision, I may also be obliged to provide information to the Chamber of Notaries or my supervisory authority, which in turn are subject to an official duty of confidentiality. Possible recipients acting as processors are our external IT service provider, notarial software providers, our web host and NotarNet GmbH.
Otherwise, your data is passed on only if I am obliged to do so because of declarations you have made, or if you have requested that it be passed on.
5. Is data transferred to third countries?
Your personal data is transferred to third countries only at your specific request, or if and to the extent that a party to a deed is based in a third country.
6. How long is your data stored?
I process and store your personal data in line with my statutory retention obligations.
Under section 50(1) of the Ordinance on the Keeping of Notarial Files and Registers (NotAktVV), the following retention periods apply to notarial records:
- register of deeds, electronic collection of deeds, collection of inheritance contracts and special collection: 100 years,
- paper-based collection of deeds, custody register and general files: 30 years,
- collective file for protests of bills of exchange and cheques, and ancillary files: 7 years; the notary may specify a longer retention period in writing, at the latest when the ancillary file is last worked on, e.g. for testamentary dispositions or where there is a risk of recourse claims; this may also be specified generally for individual types of legal transaction, e.g. for testamentary dispositions.
Once the retention periods have expired, your data is deleted and paper records are destroyed, unless I am obliged to store it for longer under Art. 6(1) sentence 1 point (c) GDPR because of retention and documentation obligations under tax and commercial law (from the Commercial Code, the Criminal Code, the Money Laundering Act or the Fiscal Code) or because of professional rules on checking for conflicts of interest.
7. What rights do you have?
You have the right:
- to request information on whether I process personal data about you and, if so, for what purposes, which categories of personal data I process, to whom the data may have been passed on, how long the data is to be stored and which rights you have (Art. 15 GDPR).
- to have inaccurate personal data about you that is stored by me corrected. You also have the right to have an incomplete data record stored by me completed (Art. 16 GDPR).
- to request the erasure of personal data about you, provided that there is a statutory ground for erasure (see Art. 17 GDPR) and the processing of your data is not required to comply with a legal obligation or for other overriding reasons within the meaning of the GDPR.
- to require me to process your data only to a restricted extent, e.g. for asserting legal claims or for reasons of important public interest, while I examine, for example, your claim to rectification or your objection, or where I refuse your request for erasure (see Art. 18 GDPR).
- to object to the processing where it is necessary for me to perform my tasks in the public interest or to exercise my public office, if there are grounds for the objection that arise from your particular situation (Art. 21 GDPR).
- to lodge a data protection complaint with the supervisory authorities. The supervisory authority responsible for me is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
You can lodge the complaint with any supervisory authority, regardless of which one is responsible.