Privacy notice for the OPAC Library Catalogue in Accordance with Article 14 of the General Data Protection Regulation (GDPR)
The Max Planck Society for the Advancement of Science e.V. (MPG) takes the protection of your personal data very seriously. We process personal data that is collected when you visit our library catalogue in accordance with the applicable data protection regulations and, as a general rule, only to the extent necessary to provide a fully functional website and to maintain our content and services. We will never publish your data or disclose it to third parties without authorization. Below, we explain what data we collect during your visit to our websites and exactly how it is used.
A. Making the website available for use
1. Accessing the website
a. Type of data
Each time our website is accessed, our servers and applications automatically collect data and information from the system of the device used to access the site, e.g. the IP address.
The data is stored in our systems’ log files. This data is not stored together with any other personal data of the data subject.
b. Legal basis
The legal basis for the temporary storage of the data and log files is Article 6(1)(f) of the GDPR. The data is stored in log files to ensure the website functions properly. Furthermore, the data is used to optimize the website, to troubleshoot errors, and to ensure the security of our IT systems. These purposes also constitute our legitimate interest in data processing pursuant to Article 6(1)(f) of the GDPR.
The collection of data for the provision of the website and the storage of data in log files is strictly necessary for the operation of the website. Consequently, data subjects have no right to object.
c. Deletion of data
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. This is the case after seven days.
2. User-friendly design of the website
a. Type of data
Our website uses cookies. Cookies are text files that are stored in the web browser or by the web browser of the data subject. When a person visits a website, a cookie is stored on that person’s device. The cookies contain a distinctive string of characters that enables the browser to be uniquely identified when the website is visited again.
We use cookies to make our website more user-friendly. Some elements of our website require, for technical reasons, that the browser used to access the site can be identified even after a page has been changed. The following data is stored and transmitted via the cookies:
- KohaOpacLanguage: Storage of the language setting in the form of language codes (e.g. en, de-DE)
- CGISESSID: session data in the form of a session ID
- form_serialized and form_serialized_limits: search terms and restrictions used
- search_path_code: information on whether the ‘more options’ content in Advanced Search is enabled or disabled (e.g. ‘true’ or ‘false’, or ‘0’ or ‘1’)
- num_paragraph: Number of additional search fields used in Advanced Search, as a numerical value
- bib_list: Record numbers of the titles saved in the “basket”, in the form of a list
Cookies are stored on your device and transmitted from your device to our website. As a user, you therefore have full control over the use of cookies. By changing the settings in your web browser, you can disable or restrict the transmission of cookies. This can also be done automatically. If cookies are disabled for our website, it may no longer be possible to make full use of all the website’s functions.
b. Legal basis
The legal basis for the processing of personal data using cookies is Article 6(1)(f) of the GDPR and Section 25(2)(2) of the Telecommunications Digital Services Data Protection Act (TDDDG). Some functions of our website cannot be provided without the use of cookies. For these functions, it is absolutely essential that the browser is recognized even after changing pages.
c. Deletion of data
A language cookie (KohaOpacLanguage) is stored for three years after the language has been selected, so that the desired language can be used the next time the catalogue is accessed. All other cookies are deleted at the end of the session at the latest. Finally, the bib_list cookie is deleted upon using the ‘Empty basket’ function, and the session cookie (CGISESSID) is delated upon logging out.
B. Acquisition suggestions
1. Type of data
Our library catalogue features a contact form for acquisition suggestions, which can be used to contact us electronically. If you use this option, the data entered in the form will be transmitted to the library team and stored. This includes your name and your user account ID. We will inform you about the specific processing of the data as part of the usage process. Reference is also made to this privacy policy. The data will be used exclusively for the purpose of managing the communication. You may withdraw your consent to the processing of personal data at any time by contacting the listed points of contact.
2. Legal basis
The legal basis for processing the data when using the contact form is your consent in accordance with Article 6(1)(a) of the GDPR. We process the personal data from the input form solely for the purpose of handling your enquiry.
3. Deletion of data
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. This is the case once the relevant communication with you has ended or the matter has been conclusively resolved. The communication is deemed to have ended when it is clear from the circumstances that the matter in question has been conclusively resolved. If the enquiry results in the use of a library service (e.g. borrowing an item or placing an inter-library loan request), this will be stored in your library account (see Section C).
C. User accounts in the Koha library system
1. Type of data
Creating a user account is essential for using the library catalogue’s borrowing function and personalized services. When you create an account, we store your name, address details, the registration date, and the date upon which it is expected that you will no longer be using the system. We will inform you about the specific processing of your data as part of the registration process. Reference is also made to this privacy policy.
Each time you use your account, the time of a successful or failed login is recorded in the library system.
2. Legal basis
The legal basis for processing data in connection with the library account is Article 6(1)(b) of the GDPR (the performance of a contract or the implementation of pre-contractual measures as requested by the data subject). Registration is required in order to provide certain content and services on our website (such as self-service borrowing or online renewals), or to fulfil a contract with you or to implement pre-contractual measures.
The storage of logins and login attempts serves to resolve technical issues and to ensure the security of our IT systems. These purposes also constitute our legitimate interest in data processing pursuant to Article 6(1)(f) of the GDPR.
3. Deletion of data
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. This applies to data that has been collected in the library account when the library account is deleted. Deletion usually takes place within four weeks of the end of your stay or upon request, provided that all borrowed items have been returned beforehand. When the library account is deleted, your personal data will also be removed from the library system’s logs. Even after the contract has ended, it may still be necessary to store the contractual partner’s personal data in order to comply with contractual or legal obligations.
D. Data transfer
Your personal data is managed and stored as an element of commissioned data processing on systems operated by GWDG (Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen, Burckhardtweg 4, 37077 Göttingen).
Your personal data will only be transferred to state institutions and authorities in cases required by law or for the purposes of criminal prosecution following attacks on our network infrastructure.
No data is disclosed to third parties for any other purposes.
E. General Information
1. Contact details of the data controller
The data controller within the meaning of the General Data Protection Regulation and other national data protection laws, as well as other data protection provisions, is the
Max Planck Society for the Advancement of Science e.V. (MPG)
Hofgartenstraße 8
D-80539 Munich
Telephone: +49 (89) 2108-0
Contact form: https://www.mpg.de/kontakt/anfragen
Website: https://www.mpg.de
2. Contact details of the Data Protection Officer
The data protection officer of the data controller can be contacted as follows:
Data Protection Officer of the MPG
Hofgartenstraße 8
D-80539 München
Telephone: +49 (89) 2108-1554
datenschutz@mpg.de
F. Rights of data subjects
As a data subject whose personal data is collected in connection with the above-mentioned services, you generally have the following rights, provided that no statutory exceptions apply in your individual case:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17(1) GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to objection to processing (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with the supervisory authority (Art. 77 GDPR). For the MPG, this is the Bavarian State Office for Data Protection Supervision, PO Box 1349, 91504 Ansbach.
G. Web analytics
1. Type of data
We use the web analytics programme Matomo to collect statistical data on usage behaviour; this programme uses cookies and JavaScript to collect various pieces of information from your computer and automatically transmits them to us. Each time our websites are accessed, our system records the following data and information from the computer system of the accessing device:
- IP address, anonymized by truncation
- Two cookies to distinguish between different visitors: pk_id and pk_sess
- Previously visited URL (referrer), if transmitted by the browser
- Name and version of the operating system
- Name, version, and language setting of the browser.
In addition, provided JavaScript is enabled:
- URLs visited on this website
- Times at which pages were accessed
- Type of HTML requests
- Screen resolution and colour depth
- Technologies and formats supported by the browser (e.g. cookies, Java, Flash, PDF, Windows Media, QuickTime, RealPlayer, Director, Silverlight, Google Gears).
The data is stored and analysed exclusively on a central server operated by the MPG.
You are, of course, entitled to object to the collection of data. You have the following independent options for objecting to data collection by the central server:
- Enable the ‘Do Not Track’ setting in your browser. As long as this setting is active, our central server will not store any data relating to you. Important: The ‘Do Not Track’ setting generally applies only to the specific device and browser in which you enable it. If you use multiple devices or browsers, you must enable ‘Do Not Track’ separately in each case.
- Use our opt-out function. Tick the selection box at https://www.mpg.de/privacy-policy/data-collection-opt-out to stop or reactivate data collection. As long as the selection box is deactivated, our central server will not store any data about you. Important: To opt out, we need to store a special tracking cookie in your browser. If you delete this cookie or use a different computer or browser, you will need to opt out of data collection again on this page.
This data is not stored together with any other personal data relating to users.
2. Legal basis
The legal basis for the processing of users’ personal data is Article 6(1)(a) of the GDPR and Sections 25(1) and 26 of the TDDDG. The processing of users’ personal data enables us to analyse our users’ behaviour. By evaluating the data collected, we are able to compile information on the use of the individual components of our websites. This helps us to continuously improve our websites and their user-friendliness. You can optionally enable or disable this analysis in the cookie banner.
3. Deletion of data
The data is deleted once the final annual totals for the access statistics have been compiled or once the stated purposes have been achieved.