1. General Information
The protection of personal data is a key priority for us. The purpose of this privacy policy is to inform you about how Normec VQZ GmbH processes personal data in the context of carrying out customer-related processes.
Processing is carried out in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the applicable legal, contractual, regulatory, and accreditation requirements.
This policy applies both to data we receive directly from data subjects and to data provided to us by customers, applicants, or other parties involved in the process.
2. Data Controller
Normec VQZ GmbH
Schwertberger Str. 14–16
53177 Bonn-Bad Godesberg
Email: info-vqz@normecgroup.com
3. Data Protection Officer
Normec VQZ GmbH
For the attention of the Data Protection Officer
Schwertbergerstraat 14–16
53177 Bonn-Bad Godesberg
Email: datenschutz-vqz@normecgroup.com
4. Purposes of the Processing of Personal Data
We process personal data only to the extent necessary for the performance of our activities as a certification and prequalification body.
This includes, in particular:
- the processing of applications, requests, quotes, and contracts
- the planning, execution, assessment, and documentation of certification procedures in accordance with recognized standards and programs (ISO 9001, ISO 13485, ISO 14001, ISO 45001, ISO 50001, SCC-VAZ, GOI)
- conducting and documenting prequalification procedures
- Planning, conducting, and following up on audits, assessments, and expert evaluations
- Communicating with clients, applicants, stakeholders, and other relevant parties
- Verifying supporting documentation, qualifications, responsibilities, audit findings, and corrective actions
- Preparing, managing, tracking, and ensuring the traceability of certificates, statements, and other outcomes of procedures
- Compliance with legal, regulatory, contractual, and accreditation-related requirements
- Internal quality assurance, management of procedures, review, documentation, and defense in legal proceedings
5. Categories of Personal Data
Depending on the procedure in question, the following categories of personal data, in particular, may be processed:
- name, business contact information, and communication data
- Affiliation with the company, position, professional role, and responsibilities within an organization
- Data relating to contracts, customers, requests, quotes, invoicing, and procedures
- Audit information, assessment documents, findings, actions, responsibilities, and validations
- Supporting documents regarding qualifications, education, skills, training, and professional experience
- Data related to participants in audits, meetings, training sessions, assessments, and other appointments related to procedures
- Signatures, initials, evidence of role and authority, as well as the information contained in validation, control, and documentation records
- Contact information and details related to procedures concerning auditors, experts, service providers, suppliers, authorities, and other relevant entities
- other supporting documents, documents, or documentation content, to the extent that they are necessary for the relevant procedure and contain personal data
In principle, we do not request specific categories of personal data within the meaning of Article 9 of the GDPR. In certain cases, however, such data may be part of the supporting documents provided to us by clients, applicants, or other relevant entities, or consulted in the context of an audit.
This may be particularly relevant in the context of procedures related to the ISO 45001 or ISO 13485 standards, for example, when documents relating to accidents, occupational safety, occupational health, vigilance, complaints, medical devices, or other similar areas contain data pertaining to health or other special categories of personal data.
We therefore request that, to the extent possible, you redact or anonymize this data before providing it, or make it accessible only to the extent necessary for the procedure in question. To the extent that the processing of special categories of personal data is unavoidable in a specific case, it will take place only to the extent necessary and only if a relevant exception exists in accordance with Article 9(2) of the GDPR.
6. Source of the Data
In principle, we receive personal data directly from our clients, applicants, or persons involved in the proceedings.
If the data does not come directly from the data subject, it is generally provided by the client, the applicant, the employer, the contracting party, or another entity involved in the proceedings.
In addition, as part of our activities, personal data may also be transferred to us by other entities involved in the procedure or authorized in this area. This particularly concerns data relating to:
- complaint and appeal procedures,
- cooperation with other certification or prequalification bodies, particularly in the context of transfer processes,
- requests or procedures from competent authorities, accreditation bodies, or regulatory agencies,
- supervisory, reporting, or incident procedures relating to regulated products or services.
In this context, depending on the circumstances, personal data of employees, business partners, involved third parties, or other relevant individuals may also be processed.
In addition, publicly accessible sources, in particular public registers or publicly accessible company information, may be used to the extent necessary to verify the information relating to the procedure.
If the personal data is not collected directly from the data subject, the information referred to in Article 14 of the GDPR will be provided in accordance with the statutory provisions, unless the law provides for an exception.
7. Legal Bases for Processing
The processing of personal data is based, depending on the purpose and context of the procedure, on one or more of the following legal bases:
- Article 6(1)(b) of the GDPR, to the extent that the processing is necessary for taking steps to enter into a contract or for the performance of contractual obligations toward the data subject
- Article 6(1)(c) of the GDPR, to the extent that the processing is necessary to comply with legal obligations, in particular regarding retention and evidence requirements as set forth in commercial, tax, regulatory, or any other law
- Article 6(1)(f) of the GDPR, to the extent that the processing is necessary to protect the legitimate interests of Normec VQZ GmbH, our customers, applicants, or third parties, and there are no overriding interests or fundamental rights or freedoms of the data subject that would prevent this
Our legitimate interests consist, in particular, of the organization, implementation, evaluation, and documentation of certification and prequalification procedures, communication with the relevant authorities, quality assurance, compliance with accreditation and accountability requirements, as well as the assertion, exercise, or defense of legal rights.
To the extent that, in specific cases, special categories of personal data within the meaning of Article 9 of the GDPR are processed, this occurs only if, in addition to a legal basis within the meaning of Article 6 of the GDPR, there is also a relevant exception within the meaning of Article 9(2) of the GDPR.
8. Recipients of Personal Data
The transfer of personal data takes place only to the extent necessary for the stated purposes, where there is a legal or contractual basis, or where disclosure is necessary in the context of legal proceedings.
Recipients or categories of recipients may include, in particular:
- the relevant internal departments of Normec VQZ GmbH
- auditors, inspectors, technical experts, and appointed experts
- service providers in the areas of IT, communications, operations, administration, archiving, and other support activities
- companies within the Normec Group, to the extent necessary for conducting the procedure, management, or quality assurance
- accreditation bodies and assessors
- competent authorities, government agencies, courts, or other bodies prescribed by law
- customers, applicants, or other parties involved in the relevant certification or prequalification procedure, to the extent necessary for the proper conduct of the procedure
Service providers are subject to the obligations set forth in data protection legislation. To the extent that service providers process personal data on behalf of Normec, such processing takes place on the basis of a data processing agreement in accordance with Article 28 of the GDPR.
9. Transfer to Third Countries
In principle, the processing of personal data takes place within the European Union or the European Economic Area.
To the extent that a transfer to a third country or to an international organization takes place in the context of the IT services used, intra-group processes, or other procedure-related activities, we ensure that the requirements of the GDPR regarding international data transfers are complied with.
Such transfers take place, in particular, on the basis of an adequacy decision by the European Commission or appropriate safeguards within the meaning of Article 44 et seq. of the GDPR, to the extent that these are necessary. Information regarding the applicable safeguards can be requested using the contact details provided above.
10. Retention Period
We retain personal data only for as long as necessary for the stated purposes or for as long as legal, contractual, regulatory, accreditation-related, or procedural obligations regarding retention and evidence exist.
The specific retention period depends primarily on the following criteria:
- The duration of the agreement, certification, prequalification, or any other relevant customer procedure
- Legal retention obligations, in particular the provisions of commercial and tax law
- Contractual requirements and statutes of limitations
- Requirements arising from standards, accreditations, certification programs, and other procedural requirements
- Obligations regarding evidence, documentation, auditing, and quality assurance
- The need to assert, exercise, or defend legal rights
Once the purpose of retention no longer exists and the applicable retention obligations have expired, the data will be deleted or, to the extent that deletion is not possible or necessary, blocked, or its processing will be restricted.
11. Obligation to Provide Personal Data
The provision of certain personal data is necessary to enable us to assess, plan, carry out, document, and complete customer procedures.
Depending on the procedure in question, this provision may be contractually required or result from legal, regulatory, normative, accreditation-related, or other procedure-related requirements.
Without the required data, the execution, assessment, or continuation of the relevant procedure may, under certain circumstances, prove impossible or be achievable only to a limited extent.
12. Rights of Data Subjects
Data subjects have the following rights, subject to the statutory conditions:
- Right of access to the processed personal data (Art. 15 of the GDPR)
- Right to rectification of inaccurate personal data (Art. 16 of the GDPR)
- Right to erasure of personal data (Article 17 of the GDPR)
- Right to restriction of processing (Article 18 of the GDPR)
- Right to data portability (Art. 20 of the GDPR)
- Right to object to certain processing activities (Article 21 of the GDPR)
- Right to lodge a complaint with a data protection supervisory authority (Article 77 of the GDPR)
In particular, a complaint may be filed with the supervisory authority with jurisdiction over us: Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, www.ldi.nrw.de.
13. Right to object under Article 21 of the GDPR
To the extent that we process personal data on the basis of legitimate interests pursuant to Article 6(1)(f) of the GDPR, data subjects have the right to object to such processing at any time for reasons related to their specific situation.
In that case, we will no longer process the personal data in question on this basis, unless we can demonstrate that there are compelling legitimate grounds for the processing that override the interests, the rights and freedoms of the data subject, or that the processing is necessary for the establishment, exercise, or defense of legal claims.
14. Automated Decision-Making
No automated decision-making, including profiling, takes place within the meaning of Article 22 of the GDPR.
Updated on: 06/16/2026