Effective Date: January 2026
Approved By: IEL Committee
Next Review Date: January 2027
This policy explains how the Library processes and protects personal data in accordance with the GDPR (DSGVO) and the Bundesdatenschutzgesetz (BDSG).
It applies to all volunteers, board members, and anyone handling personal data on behalf of the Library.
This policy covers all personal data of:
Library users (Mitglieder/Nutzer)
Volunteers and board members (Ehrenamtliche/Vorstand)
Donors and visitors
Contractors or suppliers (if any)
It includes both digital and paper-based data.
The International English Library, officially “Friends of the International Library e.V. in der BRÜCKE” as a non-profit volunteer-run organisation (Verein or community initiative), commits to:
Lawful, fair, transparent data processing
Collecting only the minimum personal data required
Storing data securely
Respecting retention limits according to GDPR and German requirements (e.g., HGB, AO)
Enabling all rights of data subjects under GDPR/BDSG
Processing is conducted under the following bases:
Name, address, email, phone
Borrowing and reservation history
Overdue/lost item information
Nationality (if offered)
Contact details
Emergency contact
Availability and role information
Training/safeguarding certifications (as required)
Registration details
Photos only after signed consent
Data is used for:
Managing loans, reminders, reservations
Contacting users about overdue items
Sending updates and newsletters (only with consent)
Organising volunteer shifts and board duties
Bookkeeping, donations, grant reporting
Ensuring legal compliance (AO, BGB requirements for Vereinsführung)
The Library does not sell or trade personal data.
The Library adheres to GDPR and German statutory retention periods:
Password-protected accounts and devices
Role-based access
European servers preferred for cloud services
Encrypted storage where applicable
No private device usage without permission and security safeguards
Kept in locked cabinets
Access restricted to authorised volunteers
Secure shredding of unneeded documents
Volunteers must follow a “clean desk” approach for records.
Data is not shared unless necessary, including:
Email newsletter services (e.g., German/EU-compliant providers)
Cloud storage or library management software with proper Data Processing Agreements (AV-Verträge) under Art. 28 GDPR
Public authorities when required by law (e.g., safeguarding, police requests)
Funding bodies (usually anonymised reporting)
Data is never shared for marketing.
Where third-party services process data on behalf of the Library (newsletter provider, cloud services, library catalog systems), the Library maintains AV-Verträge to ensure GDPR compliance.
A data breach includes any loss, unauthorised disclosure, or access.
Steps:
Volunteers report breaches immediately to the Data Protection Officer email: data.protecton.officer@international-library.de using the data breach form.
The incident is documented.
If a risk to individuals is likely, the Library reports it to the Landesdatenschutzbehörde within 72 hours under Art. 33 GDPR.
Affected individuals are informed when required by Art. 34.
Individuals have the right to:
Access (Art. 15)
Rectification (Art. 16)
Erasure (Art. 17)
Restrict processing (Art. 18)
Data portability (Art. 20)
Object to processing (Art. 21)
Withdraw consent at any time (Art. 7)
Requests are answered within one month.
Individuals have the right to lodge a complaint with a supervisory authority if they believe the processing of their personal data contravenes the GDPR. The supervisory authority is:
The State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
PO Box 20 04 44
40102 Düsseldorf
Tel.: 0211-38424-0
Email: poststelle@ldi.nrw.de
Not a formal DPO, but responsible for:
Ensuring policy compliance
Managing breaches
Handling rights requests
Maintaining documentation (Verzeichnis der Verarbeitungstätigkeiten)
Only required under §38 BDSG if:
The library regularly engages 20 or more people in data processing or
It processes highly sensitive data or engages in large-scale monitoring.
The Library will maintain:
Register of processing activities (RPA)/Verzeichnis der Verarbeitungstätigkeiten (VVT)
Copies of all AV-Verträge
Records of consent (e.g., photography)
Data breach log
Annual review notes
All volunteers involved in data handling receive basic annual GDPR/BDSG instruction covering:
Data minimisation
Secure handling of records
How to report breaches
How to manage consent (especially photos)
Reviewed annually by the committee.
Changes to data processing activities require immediate review.
When just using the website to obtain information, in other words when you do not register or otherwise provide us with information, we will only collect the personal data that your browser transmits to our server. If you wish to view our website we collect the following data which is technically necessary to display our website to you and to ensure its stability and safety (Legal basis is Art. 6 para. 1 S. 1 lit. f GDPR).
IP address
Date and time of the inquiry
Time zone difference to Greenwich Mean Time (GMT)
Content of the request (precise page)
Access status / HTTP status code
Amount of data transferred in each case
Website from which the request originates
Browser
Operating system and its user interface
Language and version of the browser software
In addition to the aforementioned data, when using our website cookies will be stored on your computer. Cookies are small text files which are recorded and allocated to a specific position on your hard disc by the browser you use. Certain information (in this case provided by us) is passed over to the Cookies. Cookies are not able to execute any programs or transfer viruses to your computer. They serve to make the Internet in general more user friendly and effective.
This website uses the following kinds of cookies whose scope and mode of operation are described as follows:
Transient Cookies (see a)
Persistent Cookies (see b).
(a) Transient Cookies are automatically deleted when you close the browser. Included amongst these are in particular session cookies. They save a so-called Session-ID with which the various requests from your browser can be assigned to the same session. This way your computer can be recognised when you return to our website. Session cookies are deleted when you log out or close your browser.
(b) Persistent Cookies are automatically deleted after a specified period of time, which can differ depending on the cookie. You can delete the cookies at any time using the privacy settings of your browser. In particular they save the chosen language: maximum 2 years.
You can configure your browser settings according to your requirements. For example, you can decline the acceptance of third-party cookies or all cookies. However we would like to point out that it is possible you will not be able to use all the features of the website.