Information Management and Data Protection

Information and its management are an important part of our commercial success. Our information comes from a number of different areas – from marketing through to customer services, development and finance. Data security and protection is particularly important for us.

We adhere strictly to the applicable laws governing the protection and security of personal data. We have also developed a number of measures, including a uniform Group-wide rulebook on data protection and privacy, information security and the internal control system, and a cyber security system to protect company-related data. These measures are detailed in corresponding Group guidelines. The comprehensive framework is strengthened by clear responsibilities and contact persons for all relevant areas of the Group. In addition to our data protection officer, we also have data protection coordinators in all departments in Germany and Austria and conduct regular training on data protection and privacy for our employees. All employees are required to complete this training when they joined the company and every year afterwards. Our data protection training was digitalized in 2021 and included in the online training catalog. As a result, employees can complete the training independently from any location. Data protection coordinators track the training on behalf of the employees in their department to ensure that they complete it. Detailed information about our data protection measures is available here:

Uniform Group-wide rule book
on cyber security, information security and the internal control system introduced

Elements of the system for the protection of company-related data:

Due to the extensive measures that we have taken in the area of data protection, we believe that risks related to inadequate IT security or violations of the General Data Protection Regulation only have an extremely low probability of occurrence. Mobile working, which we use far more extensively now than was the case before the coronavirus pandemic, does not involve any significant data protection-related risks.

The Management Board is provided with information about developments in the area of data protection and information security once a year. In Austria, a status report is provided to the management of BUWOG once a year. The Supervisory Board’s audit committee deals with topics related to data security, and is also provided with the data protection report on an annual basis.

