Information on data processing by the Shibboleth service
In the following we inform you in accordance with Art. 14 of the General Data Protection Regulation (GDPR) about the collection of personal data as part of the data processing of the Shibboleth service provided via the Technical University of Munich via the Leibniz Supercomputing Center.
Shibboleth implements single sign-on for logging in to internal services as well as external services that are part of a federation, such as the DFN or eduGain.
Responsible body
Leibniz Institute for Food Systems Biology
at the Technical University of Munich
(Leibniz-LSB@TUM)
Lise-Meitner-Str. 34
85354 Freising
E-Mail: contact.leibniz-lsb@tum.de
Phone: +49 8161 71-2928
Order processing by
Leibniz Supercomputing Center (LRZ)
of the Bavarian Academy of Sciences and Humanities
Boltzmannstraße 1
D-85748 Garching near Munich
Phone: (089) 35831 8000
Fax: (089) 35831 9700
E-Mail: lrzpost@lrz.de
Internet: www.lrz.de
Our data protection officer
External data protection officer:
Prof. Dr. Uwe Baumgarten
E-Mail: beauftragter@datenschutz.tum.de
Phone: +49 89 289-17052
Postal address:
Computer Science F13 - Chair/Department of Operating Systems
Faculty of Computer Science
Technical University of Munich
Boltzmannstr. 3
85748 Garching
Germany
Visitor address:
Computer Science F13 - Chair/Department of Operating Systems
Faculty of Computer Science
Technical University of Munich
Parkring 37
85748 Garching
Germany
Data processing
PROCESSING PURPOSE
Shibboleth is used to provide a single sign-on for the registration and use of services of the research information system operated by the Leibniz Institute for Food Systems Biology at the Technical University of Munich (Leibniz-LSB@TUM).
The data is processed for the purpose of authenticating and authorizing users of the research information system in order to enable secure and personalized access to protected information and functions within the system. In addition, the data can be processed to manage user rights, to log access and to improve and secure IT services.
Further information on data processing when using the research information system can be found in the corresponding data protection information.
LEGAL BASIS OF THIS PROCESSING
Your data is processed on the basis of Art. 6 para. 1 letter e GDPR, Art. 4 para. 1 BayDSG, Art. 2 para. 2, 7, 11 para. 3 sentence 6 BayHIG and on the basis of Art. 6 para. 1 letter b GDPR in conjunction with the company agreement.
DATA HERITAGE
The data originates from the central directory service of the Technical University of Munich
DATA CATEGORIES
We process the following categories of personal data in this context:
- Master data (e.g. name, gender, user name)
- Contact details (e.g. e-mail, telephone number)
- Data in connection with the activity (e.g. employment relationship, student status, group membership)
- Metadata and database IDs (e.g. eduPersonTargetedID (a unique characteristic per user that remains the same in the long term but does not allow any conclusions to be drawn about the user's personal data), eduPersonEntitlement (a unique value that authorizes certain applications))
- Data and metadata relating to visits to the website (e.g. IP address, data from cookies, log data, control data, traffic data)
RECIPIENTS AND INTERNATIONAL DATA TRANSFER
The data will be passed on to internal institute services, service providers and vicarious agents (e.g. technical service providers, hosting providers, disposal companies, service providers from other federations, service providers in the DFN-AAI) and consultants (e.g. tax or legal advisors). In particular, your data will be passed on to the operator of the Shibboleth service, the Leibniz Supercomputing Center (LRZ) of the Bavarian Academy of Sciences and Humanities, Boltzmannstraße 1, 85748 Garching near Munich.
Our service providers, vicarious agents and consultants usually act as our processors in accordance with our instructions under an order processing contract pursuant to Art. 28 GDPR.
Your personal data is processed in a member state of the European Union, in another state party to the Agreement on the European Economic Area or in a third country with an adequacy decision. Any further transfer of data processing to a third country without an adequacy decision requires the special conditions of Art. 44 et seq. GDPR.
Duration of storage
The data is processed for the period required to achieve the purpose of processing or for as long as a legal obligation exists.
Rights of data subjects
With regard to this processing of your personal data, you as a data subject have the following rights in accordance with Art. 15 et seq. GDPR:
- You can request information about whether we process your personal data. If this is the case, you have a right of access to this personal data and to further information related to the processing (Art. 15 GDPR). Please note that this right to information may be restricted or excluded in certain cases (see in particular Art. 10 BayDSG). See also www.datenschutz.tum.de/datenschutz/was-weiss-die-tum-ueber-mich/auskunft/.
- In the event that personal data about you is not (or no longer) accurate or incomplete, you may request that this data be corrected and, if necessary, completed (Art. 16 GDPR).
- If the legal requirements are met, you can request the erasure of your personal data (Art. 17 GDPR) or the restriction of the processing of this data (Art. 18 GDPR). However, the right to erasure pursuant to Art. 17 (1) and (2) GDPR does not apply if, among other things, the processing of personal data is necessary for the performance of a task which is in the public interest or in the exercise of official authority (Art. 17 para. 3 letter b GDPR).
- You also have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit those data to another controller without hindrance from us (Art. 20 GDPR).
- You have the right to complain to a supervisory authority within the meaning of Art. 51 GDPR about the processing of your personal data. The competent supervisory authority for Bavarian public bodies is the Bavarian State Commissioner for Data Protection, Wagmüllerstraße 18, 80538 Munich.
We will inform you separately about your right to object.
RIGHT OF OBJECTION
For reasons arising from your particular situation, you can also object to the processing of your personal data by us at any time (Art. 21 GDPR). If the legal requirements are met, we will then no longer process your personal data.
Contact: contact.leibniz-lsb@tum.de