Data protection information for candidates

Preliminary note 

With the following information, we would like to provide you with an overview of how your personal data is processed by us, as well as your rights under data protection law.  

This data protection information describes all data processing procedures carried out by DEKRA SE via the DEKRA candidate portal.  

DEKRA SE (“DEKRA SE,” “DEKRA”, “our,” “us,” or “we”) gathers and processes your personal information in accordance with this privacy notice. This notice provides you with the necessary information regarding your rights and obligations, and explains how, why, and when we collect, process, and use your personal information. 

This Privacy Policy is part of DEKRA’s Terms and Conditions and applies to your use of the DEKRA candidate portal  (the “Portal”), including but not limited to all information, videos, images, tools, applications, fixtures, or other products, goods, or services, and all other services made available by us to Users from time to time, whether through our Portal or through other means (collectively, the “Services”). This Privacy Policy does not apply to the data collection practices of any other DEKRA website that are not owned and operated by DEKRA. 

Please note that this Privacy Policy does not govern the practices of third parties, including our partners, third party service providers, marketing providers, and/or advertisers, even when those services are branded as or provided on behalf of DEKRA. 

By using our Services and/or the Portal you acknowledge that you have read and accepted the terms of this Privacy Policy and our Terms and Conditions, and you are consenting to our collection, protection, use, retention, and disclosure, subject to the terms and conditions set-forth below in this Policy, of your personal information. If you elect to not provide the information we require, we may not be able to provide all of our Services to you. 

If you do not agree to the terms of this Privacy Policy, please do not use the Portal or our other Services. We may make changes to this Privacy Policy from time to time. Your continued use of the Portal and other Services following the posting of any changes to this Privacy Policy will indicate your acceptance to these changes. We will post any Privacy Policy changes on this page. Please check back frequently to see any changes. 

 

Who is responsible for data processing, and whom can I contact? 

The data controller deemed responsible for the processing of your personal data under data protection law is 

DEKRA SE 

with its registered office in Stuttgart, 

and registered in the commercial register 

of the Stuttgart District Court under HRB 734316, 

Handwerkstr. 15, 70565 Stuttgart, Germany 

For any general questions and queries regarding the collection and processing of your personal data, please contact:  

hr.na@dekra.com or +1 770-971-3788 

Should you have any questions about your rights as a data subject, please contact: 

konzerndatenschutz@dekra.com  

 

What data do we collect? 

We collect your information in several ways, including:  

1) Information we collect from you;  

2) Information we collect from when you use the Portal; and  

3) Information we collect from third parties.  

When you use our Services, including the Portal, Portal, we may request and you may provide your personal information to DEKRA. DEKRA collects, uses and processes your personal information to provide the Portal and Services to you, and to meet our legal, statutory and contractual obligations. The specific information we collect depends upon your use of the Portal and our other Services, as described below. 

“Personal information” is information that identifies you as an individual or relates to or is reasonably capable of being associated with an identifiable individual, and includes the data sets referred to below. 

The personal information that we may collect includes the following categories and specifics within said category: 

Identifiers: 

  • Your name; 
  • Your title; 
  • Your email address; 
  • Your unique userID; 
  • Your IP address; 
  • Your mailing address; 
  • Your Telephone Number; 
  • Information about your professional career (e.g. curriculum vitae); 
  • Information about your qualifications (e.g. certifications); and 
  • Documentation data (e.g. interview notes); 

Geo-location: 

  • location of your device or computer, which may in some cases constitute precise geolocation information. 

Internet or other electronic information: 

  • Browser type and browsing history; 
  • Usage data; 
  • Device type and other device information (including host name); 
  • Operating system; 
  • Cookies and tags; 
  • Date and time of access; 
  • Website from which the access is made (referrer URL); and 
  • Information from third parties and other databases. 

What data sources do we use? 

The personal information is collected in several different ways, including: registration forms to sign up for our online and offline Services, billing, surveys, contacting us, different cookies and tracking technologies, and other sources. How we collect information includes the following categories and specifics within said category: 

  • which has been received directly from you as part of the candidate process, or the creation of your account and candidate profile, 
  • Information gathered during the use of our Services; 
  • which we have permissibly collected from public sources or from third parties;  
  • Information collected after consent – in some contexts we may ask your consent before collecting certain information; 
  • or which has been disclosed to us, for example, by public authorities, insurance providers, pension funds, credit institutions, educational and training institutions, other external service providers or by third parties you have named as references.  

Cookies and Ad-Targeting Technologies. 

We and our third-party partners (including service providers and advertising partners) may use cookies, web beacons (“pixels”), mobile ad identifiers, and other similar technologies to facilitate our relevant Services to you, and to provide you with a customized online experience. Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies are also used such as beacons, tags and scripts to collect and track information and to analyze and improve our Service. We use third-party partners to help manage and optimize our Services’ performance and online advertising. 

Please be advised that if you choose to reject all cookies, then certain areas of the Portal might not function properly. 

Examples of cookies we use: 

First Party Cookies. We use first party cookies, including session cookies and preference cookies, to remember your selections, choices, and preferences for when you interact with our Portal. Session cookies are temporary and are automatically deleted once you close your Internet browser. Preference cookies are first party cookies that remain on your device until you delete them or they are otherwise removed upon expiration. 

Third Party Cookies. We permit certain third-party Service Providers, advertisers, and other companies to use cookies or other similar technologies on our Portal. These companies may collect your information, track your behavior on our Portal, and gather information about your use of our Portal and other online Services over time and across different Services. Additionally, some companies may use information collected to deliver targeted ads on behalf of us or other companies, including on other website or online services. We are not responsible for the functioning of cookies and other technologies used and placed by third parties on your device. 

The third-party partners we use who may utilize cookies or other tracking technologies include: 

Google: to provide Google Analytics (as Analytics Cookies) to analyze behavior of your use of our Portal, apps, and other Services, in order to improve our Services and provide you and other users with a better experience; 

Microsoft: to assist with onboarding functionality; 

AppStore Connect: to analyze backend application store data;  

Facebook, Twitter, X (formerly known as Twitter), LinkedIn, and other Social Media Partners (Social Media Cookies): to enable the sharing of content through social media Portal and otherwise allow you to interact or connect with such Portal while using our platforms; 

Sentry: to analyze application crash statistics; 

MixPanel: to analyze performance analytics; and 

Other Technologies: We collect many different types of information from other technologies to improve the quality of our Portal and the Services we provide. For example, we may collect usage data and other information about the device you use to access our Portal, your operating system and/or mobile device type, browser type, domain, and other system settings, as well as the language your system uses and the country and time zone where your device is located. We may record the IP address of the device you use to connect to the Internet. 

These technologies include web beacons and scripts: Web beacons are pieces of code embedded in a website or e-mail to monitor your activity on the website or your opening of the e-mail, and which can pass along information such as the IP address of the computer or device you use to view the website or open the e-mail, the URL page on which the web beacon is located, the type of web browser that was used to access the website, and previously set cookie values. Web beacons are sometimes used to collect advertising data, such as counting page views, promotion views or advertising responses. Disabling your computer’s, device’s or web browser’s cookies may prevent some web beacons from tracking or recording certain information about your activities. Please be advised that if you disable all such cookies, then certain areas of the Portal might not function properly. 

Scripts are pieces of code embedded in a website to define how the website behaves in response to certain key or click requests sent by the user. Scripts are sometimes used to collect information about the user’s interactions with the website, such as the links the user clicks on. Scripts are often temporarily downloaded to the user’s computer or device from the website server, active only while the user is connected to the Portal and deactivated or deleted when the user disconnects from the website. Please be advised that if you disable any scripts through your web browser or other means, then certain areas of the Portal might not function properly. 

This Privacy Policy applies to any personal information collected through our used Cookies and similar technologies. Personal information collected through the third-party partners’ Cookies and similar technologies is subject to the privacy policy of the third party partners respectively, and not to our privacy policy. 

Software Development Kits (“SDKs”): We may use SDKs on our mobile app to collect analytics regarding the use and functionality of our mobile app. Additionally, we may collect mobile ad identifiers on our mobile app for interest-based or cross-application advertising and analytics. To opt-out of the collection of mobile data for cross-application advertising, please contact us utilizing the information in the “Other Questions” Section below. Additionally, if you access our mobile app utilizing an iPhone, you may turn off cross-application tracking in the Privacy section of your phone settings. 

Your Cookie Choices. When it comes to how you want to use or allow cookies to be used on your devices, you are in control. Most internet browsers are initially set to accept cookies. You can set your browser to block or otherwise control what cookies your browser or mobile device accepts via your browser or mobile device settings. Additionally, you can choose to modify your settings and delete cookies that are otherwise stored on your device. Please consult the instructions provided by your browser or your mobile device’s manufacturer to determine how you can limit the placement of and/or remove cookies or other technologies. Please note, however, that limiting or disabling essential cookies and other technologies may impact or adversely affect some portion or functions of our Portal. 

Controlling Cookies and Opt Out Choices. You can visit the following site for comprehensive information on how to manage cookies and how to opt out of cookies used for advertising and marketing purposes: 

For individuals in the United States: 

-The Digital Advertising Alliance’s Consumer Choice tool at https://www.aboutads.info/choices 

-The Digital Advertising Alliance’s AppChoices program at https://www.aboutads.info/appchoices 

-The Network Advertising Initiative’s opt-out program at https://www.optout.networkadvertising.org/ 

We partner with third-party sponsors, affiliates, vendors, and other companies who might have links, content, or applications on the Portal. These third parties might also use tracking tools on our Portal or other Portal to collect information about you when you use the Portal. They may collect information about your online activities over time and across different Portal and other online services. We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about such a link, content, or application, you should contact the third entity directly. We are not responsible for the content or privacy practices on any website, applications, tracking tools, or other technology that are not operated by DEKRA, even though our Portal might link to them or they might link to our Portal. 

We process personal data for the purpose of enabling the use of the DEKRA candidate portal, and for carrying out selection procedures to establish an employment relationship: 

Relevant personal data may include: Personal information (e.g. title, last name, first name), contact information (e.g. e-mail address, postal address, telephone number), information about your career (e.g. curriculum vitae), information about your qualifications (e.g. certificates), documentation data (e.g. interview notes) and other data comparable to the categories mentioned. 

What do we process your data for (purpose of processing), and on what legal basis? 

DEKRA takes your privacy very seriously. We process your personal information in accordance with the provisions of all applicable data protection laws. The purposes and reasons for collecting, processing, and using your personal information are detailed below. The legal basis for such collection processing and use of personal information are found below as well: 

  • to provide you with the products, applications, newsletter, content, and other Services that you seek from us; 
  • to create a user account and candidate profile; 
  • for the inclusion of your information in a candidate pool; 
  • for the purpose of conducting a selection process for possible employment; 
  • to improve the contents of the Portal and apps to serve you, and make them more suitable to your needs and increase their usability; 
  • to analyze how you and other users interact with our Portal; 
  • to provide customer support; 
  • to communicate with you about career opportunities through the job newsletter; 
  • to make your navigation more pleasant and personalized, with our products (such as contents) and Services personalized to you; 
  • to facilitate your experience and social sharing; 
  • to analyze and develop our new products and Services for the interest of users; 
  • to send you offers or other communications about our products and Services, such as special or promotional events, including services, products, or events, or other materials; 
  • to detect, investigate, and prevent activities that may violate our Terms and Conditions or other policies, or which may be fraudulent or illegal; 
  • in specific cases we will be contractually obligated to share your data with one of our third party partners explained above. 

In these instances, we will make it clear that the third party partners, which the data you share will be transferred to, follow applicable privacy and data protection regulations. 

We process your personal data in accordance with the provisions of all applicable data protection laws. 

A. For the purpose of the technical provision of the website  

Insofar as you visit our website, it is necessary for the purpose of the website’s technical provision (and ensuring the requisite system security) that we process certain information automatically transmitted by your browser so that our website can be displayed in your browser and you can use the website. This information is automatically collected each time our website is accessed and automatically stored in so-called server log files; this information essentially comprises:  

IP address of the requesting computer 

Host name of the accessing computer 

Recognition data of the browser and operating system used 

Date and time of access 

Website from which the access is made (referrer URL) 

Our legitimate interest in this regard is that we can make our website and our candidate portal technically available to you.  

LEGAL BASIS 

Art. 6 (1) lit. f of the General Data Protection Regulations of the European Union.  

B. For the purpose of creating a user account and candidate profile  

In the event that you create a user account in our candidate portal, we process your personal data for the purpose of creating and managing the user account for the DEKRA candidate portal. Insofar as you create an candidate profile within your user account and provide us with information about your career and qualifications, we process your personal data for the purpose of enabling the creation and management of your candidate profile.  

This primarily comprises personal information, address data, communication data, access data (e-mail address, password), as well as data pertaining to your professional experience and qualifications. 

LEGAL BASIS 

Art. 6 (1) lit. b GDPR. 

C. For the purpose of communication 

For the purpose of communicating with you, we process personal data, in order to respond to your inquiries or to communicate with you in the context of job recruitment procedures, and to send you pre-contractual documents. 

This may include, in particular, your first name, last name, home address, e-mail address, telephone number and, if applicable, contract data. 

Our legitimate interest here is to be able to stay in touch and communicate with you in the context of inquiries and vacancy procedures. This is to ensure smooth preparation of job placements and support of interested parties. 

LEGAL BASIS 

Art. 88 (1) GDPR; Art. 6 (1) lit. a, b and f GDPR 

For any processing relating to the provision of consent, the legal basis is Art. 6 (1) lit. f GDPR, whereby our legitimate interest is to defend ourselves against possible legal claims. You can withdraw any consent given at any time with effect for the future in any appropriate form. 

D. For the purpose of inclusion in an candidates pool  

In the event that you provide us with your consent to store your personal data for the purpose of worldwide or nationwide matching with future job profiles in the context of selection procedures for possible employment, we will process your personal data in accordance with your selection for the purpose of notifying you by e-mail about jobs that match the requirements and qualifications you have indicated. 

This may include, in particular, your personal information (title, last name, first name), address data (street, house number, postal code, city), contact data (private e-mail address, social media profiles), the preferred language of communication, candidate documents (cover letter, resume, references, salary requirements, notice period, possible start date), individual responses (how did the candidates become aware of the position, is the candidates of legal age, willing to relocate), previous activities, language skills and interests. 

LEGAL BASIS 

Art. 6 (1) lit. a GDPRFor any processing relating to the provision of consent, the legal basis is Art. 6 (1) lit. f GDPR, whereby our legitimate interest is to defend ourselves against possible legal claims. You can withdraw any consent given at any time with effect for the future in any appropriate form. 

E. For the purpose of conducting a selection process for possible employment 

In the event that you apply for a specific position or have given us your consent to store your candidate data in our candidates pool for suitable positions in the future, we process your personal data in the context of job filling procedures for the purpose of conducting a selection process for possible employment. For this purpose, your personal data will be transferred to the DEKRA company that has advertised the vacancy. 

This may include, in particular, your first name, last name, address, country, e-mail address, telephone number, work experience, qualifications, references and language skills. 

LEGAL BASIS 

Art. 88 (1) GDPR; Art. 6 (1) lit. a and b GDPR 

For any processing relating to the provision of consent, the legal basis is Art. 6 (1) lit. f GDPR, whereby our legitimate interest is to defend ourselves against possible legal claims. You can withdraw any consent given at any time with effect for the future in any appropriate form. 

F. For the purpose of sending the newsletter (information about career opportunities) and sending the job newsletter 

In the event that you provide us with your consent to send you regular information about career opportunities by e-mail or to inform you about jobs of interest to you via our job newsletter, we will process your personal data for the purpose of informing you by e-mail. 

This may include, in particular, your first name, last name, e-mail address and your selection based on the filters set in the candidate profile. 

We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an e-mail newsletter once you have expressly confirmed that you consent to receiving newsletters. We will first send you a confirmation e-mail asking you to confirm that you wish to receive future newsletters by clicking on an appropriate link. 

When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP), as well as the date and time of registration, in order to be able to trace any possible misuse of your e-mail address at a later date. We also store your registration to prove that you have registered and agreed. 

You may unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter, or by withdrawing your declaration of consent vis-a-vis the data controller.  

For the purpose of sending the newsletter, we store your data until you withdraw your consent or until the newsletter is permanently discontinued. For the purpose of proving consent, no longer than by the end of the fourth calendar year following the last advertising e-mail dispatch. 

LEGAL BASIS 

Art. 6 (1) lit. a GDPR 

For any processing relating to the provision of consent, the legal basis is Art. 6 (1) lit. f GDPR, whereby our legitimate interest is to defend ourselves against possible legal claims. You can withdraw any consent given at any time with effect for the future in any appropriate form. 

Who receives my data? 

We may share or disclose your personal information to help provide our Services to you. For instance, we may share your information with our affiliated companies and service providers to respond to your requests or process your application. We may also provide your personal information to third party service providers who assist us in providing certain Services.  

With regard to the transfer of data to recipients outside the DEKRA Group, we only pass on information if this is required by law, if the candidate has issued their consent, or if necessary, in order to protect our legitimate interests.  

We may also disclose or share your information for the following purposes: 

To facilitate and improve the quality of our Services. 

b. To protect our users and network against fraud and security threats. 

c. To comply with a legal obligation. 

d. To protect and defend our rights or property. 

e. To prevent or investigate possible wrongdoing in connection with the Services. 

f. To protect the personal safety of individuals or the public. 

g. To protect against legal liability. 

h. When there is a good faith belief that such action is necessary to investigate or protect against harmful activities to our guests, visitors, associates, or property (including the Portal), or to others. This may include disclosures to law enforcement to investigate potential criminal activity or other civil violations. 

We may share your information with the following types of entities and third parties: 

1. Our affiliated companies within the DEKRA family. Within our group of companies, your data will also be transferred to other companies if they have advertised the vacant position or perform data processing tasks centrally for the companies affiliated in the group (e.g. IT services, HR support, disposal of files, etc.). Information on data protection is available on the website of the respective DEKRA company, or on DEKRA’s data protection portal (Data privacy notice).; 

2. Our third-party service providers, such as Google, Sentry, MixPanel, and Microsoft Azure, to analyze how users use our website and apps, track user interests, trends and patterns in order to serve you personalized content which is relevant to your interests; 

DEKRA uses third-party service providers and business partners to provide certain Services and business functions as detailed throughout this Privacy Policy. In those instances, the applicable third-party partners collect and process your data governed by their privacy policy. 

In certain situations, we will only share your information with your consent, as noted below. We may from time to time be required to provide information to law enforcement or other governmental authorities pursuant to a warrant, court order, or other lawful process. 

In order for us to process your data in accordance with the purposes described above, it may also be necessary to provide other recipients with your data for processing. 

Within our group of companies, your data will also be transferred to other companies if they have advertised the vacant position or perform data processing tasks centrally for the companies affiliated in the group (e.g. IT services, HR support, disposal of files, etc.). Information on data protection is available on the website of the respective DEKRA company, or on DEKRA’s data protection portal (Data privacy notice). 

With regard to the transfer of data to recipients outside the DEKRA Group, we only pass on information if this is required by law, if the candidates has issued their consent, or this is necessary, in order to protect our legitimate interests.  

Under these conditions, the recipients of personal data may include, for example, service providers and vicarious agents employed by us who receive data for these purposes, provided they observe confidentiality and data protection requirements, in particular. These can be companies operating within HR and IT services, telecommunications and consulting categories, for example. We ensure that your personal data is used in accordance with your instructions by concluding data processing agreements with commissioned service providers. 

The processing operations described in this data protection notice are processed via the SuccessFactors candidate of SAP Deutschland SE & Co. KG, Hasso-Plattner-Ring 7, 69190 Walldorf. A corresponding data processing agreement has been concluded with SAP to this end, which ensures that your personal data is processed by SAP in accordance with instructions and in compliance with the requirements of data protection law. For more information pertaining to data privacy at SAP, see the SAP Data Protection Declaration and the Data Protection Area of the SAP Trust Center. 

Is data transferred to a third country or to an international organization? 

The Portal is hosted in the United States, and our Services are designed and intended for audiences within the United States and the Americas. If you reside outside of the United States or the Americas and access our Services, you acknowledge that your information will be collected and transmitted to the United States. Please do not use our Services if you do not agree to this transfer. Many of our third-party service providers such as Google, Microsoft Facebook, and Twitter(X) are U.S. companies. Data transmitted to those service providers are done in accordance with their respective privacy policies. 

Data is only transferred to countries outside North America and the European Union (so-called third countries) if you have given us your consent to this end. We would like to expressly point out that your data could also be transferred to third countries that lack the requisite security provisions for which neither an EU adequacy decision nor other suitable data protection guarantees currently apply. The protection of your data may not be guaranteed in the destination country, as in some cases, there is no level of data protection equivalent to that in the EU. Therefore, said data transmission is accompanied by corresponding risks. In particular, there are no guarantees with regard to the prevention of access to your transmitted data by government agencies. In this context, we would like to expressly point out that you, as an Eu or Canadian citizen, may not enjoy any effective legal protection against the processing of your data by authorities in third countries that lack the requisite security provisions. If you nevertheless issue us with your consent with regard to the transfer to third countries, you do so in full knowledge of these risks, which you also consciously accept by doing so. 

Security measures 

DEKRA takes your privacy seriously and we take reasonable measures and precautions to protect and secure your personal information. This includes implementing physical, technical, administrative, and other safeguards to protect you and your information from unauthorized access, alteration, disclosure or destruction. Encryption is our security strategy to ensure the stored personal information can be accessed only by the authorized roles and services with audited access to the encryption keys. 

Personal information is encrypted and stored in a private and isolated environment for extended security. 

Consequences of not providing your data 

You are not obligated to provide your personal information to DEKRA. However, there may be times where your information is required for us to provide you with our Services, deliver requested products, or provide you with the content, feedback, or other materials that you request from us. In certain situations, we will not be able to offer some or all of our products or Services to you without requesting or collecting your personal information. 
Children’s information DEKRA and its Portal and Services provide products and services for general audiences, and are intended for adults over 18 years of age. DEKRA does not intentionally or knowingly collect, use, or process the personal information from children under the age of 18, and such children are not permitted to use our Portal or Services. If you are under 18, do not attempt to register for or use any of our Services, including our Portal, and do not provide us any Personal Information about yourself. By purchasing our products or otherwise using our Services, you acknowledge you are an adult over 18 years of age and are permitted to use our Services in accordance with our Privacy Policy and Terms and Conditions. If you are a parent or guardian and you are aware that your child has violated this Privacy Policy and provided us with Personal Information, please contact us and we will take measures to remove that information from our Services. 

Our policy on “do not track” signals 

We do not support “Do Not Track.” Do Not Track is a preference you can set in your web browser to inform website that you do not want to be tracked. You can enable or disable “Do Not Track” by visiting the “Preferences” or “Settings” page of your web browser. 

We may track users across time and over different website or platforms.How long will my data be stored? 

We generally store your personal data for a period of 4 months after the end of the process. If you have consented to be included in our candidate pool, we will process your data for this purpose for two years. 

Other data processing based on consent shall be carried out at the longest until the time of withdrawal of your consent. We store any consent given to us for a period of four years from the time of its revocation or expiry. 

In addition, we store your data for the purpose of complying with statutory retention periods, and for exercising legal claims or defending against legal claims within the scope of the statutory limitation provisions. 

What data protection rights do I have? 

Individuals may have certain rights over their personal information under particular laws. Please see the following sections regarding the rights you may have over your information: 

1. Your Rights under various United Sates state data privacy laws such as the California Privacy Rights Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, and Virginia Consumer Data Protection Act. 

—For residents from the state of California, Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia this section allows you to exercise your rights under the applicable state law. 

i. Right to Access / Disclosure: The right to have access to your personal data upon simple request – that is, you may receive a copy of such data upon receipt of a verifiable request, along with other information related to the processing of your data. 

ii. Right to Correction/Rectification: The right to correct your personal data if you find it is inaccurate, incomplete or obsolete. 

iii. Right to Deletion: The right to obtain the deletion of your personal data in the situations set forth by applicable data protection law. 

iv. Right to Opt-Out: The right to opt out of the processing of your personal data for targeted advertising, as defined by applicable law. This right also allows you to opt out of the sharing of your personal data for cross-context behavior advertising as defined by the California Privacy Rights Act.  

v. Right to Appeal: You may also have the right to appeal the denial of any of these rights by submitting a form that will be provided to you if we deny a data request. 

 

Your California Privacy Rights Regarding Direct Marketing Information 

California law allows California residents once a year to request information regarding our disclosure of your personal information, if any, to third parties for those third parties’ direct marketing purposes during the preceding calendar year. This information includes: 

a. The categories of information we disclosed to third parties for their direct marketing purposes during the immediately preceding calendar year; 

b. The names and addresses of third parties that received the information; and 

c. If the nature of the third party’s business cannot be determined from their name, to obtain examples of the products or services marketed. 

2. Your Rights Under European Union's (EU) General Data Protection Regulation (GDPR) 

You are entitled to the following statutory data subject rights, provided that their requirements are met: 

Right to the disclosure of information about any data stored by us about you in accordance with Art. 15 GDPR, 

Right to the rectification of inaccurate data pursuant to Art. 16 GDPR, 

Right to erase the data stored by us in accordance with Art. 17 GDPR, 

Right to restrict the processing of data stored by us in accordance with Art. 18 GDPR, 

Right to data portability according to Art. 20 GDPR, 

Right to lodge an objection according to Art. 21 GDPR, 

Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR if you believe that the processing of personal data concerning you violates provisions of the GDPR. 

Is there an obligation for me to provide data? 

You are not obliged to provide us with personal data. In the context of an application procedure, however, you must provide us with the personal data that is required for the procedure itself, in order to participate as an candidate in a selection process. 

To what extent is there automated decision making or profiling? 

DEKRA does not engage in profiling of consumers in furtherance of automated decisions that produce legal or similarly significant effects, as those terms are defined under the Colorado Privacy Act, and in accordance with Article 22 GDPR.  

Exercising your privacy rights / non-discrimination 

We will not discriminate against you if you exercise your privacy rights. If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the relevant request; this is to ensure that your data is protected and kept secure.  

Please bear in mind that if you exercise such rights, this may affect our ability to provide our products and services. 

 As described above, you may have certain rights to access, delete, or otherwise control the use, collection, and/or disclosure of their information. Once DEKRA receives and confirms a verifiable consumer request, we will work to promptly process such request. The need to verify an individual’s identity is critical to protecting your information, and ensuring that your information is not shared with anyone pretending to be you or someone who is not authorized to act as your agent on your behalf. To that end, we must be able to verify your information in order to process your request. 

You may submit a verifiable request via the following: 

By submission portal: Contact Form | DEKRA 

By telephone: +1 770-971-3788 

By email: konzerndatenschutz@dekra.com 

By mail: hr.na@dekra.com 

DEKRA SE 

Handwerkstr. 15, 70565 Stuttgart, Germany 

Please provide sufficient information for us to determine if this applies to you. Please include “Privacy Rights Request” in the Subject line of your email. In the body of your request, please include your full name, year of birth, telephone number, email address, complete mailing address (street name and number, city, state, and zip code) so that we can process your request. 

We will ask you to provide information about yourself so that we can verify your identity as part of this process. This information may include your name, address, account information, and any other information deemed necessary by DEKRA to reasonably verify your identity, to ensure that your information is not shared with anyone impersonating you. Once we have verified your identity, we will work to fulfill your request in a timely manner. Please note there may be some situations in which we are unable to fulfill your request, such as if we cannot find any information about you within our systems. Additionally, we may not be able to honor a deletion request in some situations, such as if your information is necessary to fulfill the Services you requested or meet a legal obligation. We will inform you whether we can fulfill your rights request. 

We may ask for additional information if we have difficulty confirming your identity. We will not share your information or honor other requests in those situations in which we are unable to confirm a request for your information is a “verifiable request.” 

INFORMATION ABOUT YOUR RIGHT TO LODGE AN OBJECTION ACCORDING TO ARTICLE 21 GDPR CASE-BY-CASE RIGHT TO LODGE AN OBJECTION 

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1) lit. f GDPR (data processing on the basis of a balance of interests). This also applies to profiling based on this provision within the meaning of Article 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims. 

Recipient of an objection 

DEKRA only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal information or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with your local supervisory authority. 

If you would like to raise an issue or lodge a complaint directly with DEKRA, please contact us using the information below. 

DEKRA SE 

Data Protection Officer: José E. Soto 
Address: Handwerkstr. 15, 70565 Stuttgart, Germany 

Telephone: +1 770-971-3788 
Email: konzerndatenschutz@dekra.com 

The objection can be made informally with the subject “Objection”, stating your name and any additional authentication features that may become necessary. To do so, please contact the data controller or the data protection officer by e-mail. 

Version and amendment of this data protection declaration 

DEKRA may update this notice from time to time. All changes will be posted and updated here. We will notify you directly by email (if we hold one for you) or by other appropriate means if any significant changes occur. Any changes to the privacy policy will become effective when the updated policy is posted. We advise you to check back here frequently to review the most current version of this notice. 

The further development of our company may also have an impact on the handling of personal data. We, therefore, reserve the right to amend this data protection declaration in the future within the framework of the applicable data protection laws and, if necessary, to adapt it to changed data processing realities. We will notify you separately of any significant changes to the content. 

This statement was last updated on February, 12 2025.