Website

www.vbl.de

Function as provided in February 2018

View the www.vbl.de certificate

Version of Certification Criteria

Criteria Catalogue for Website Certification v1.1 (04/2016)

based on Directive 95/46/EC and Directive 2002/58/EC as amended by Directive 2009/136/EC

An overview of the certification criteria is available here.

Cert. No.

EP-W-TWX1KG

Validity

06/02/2018 - 29/02/2020

Monitoring

08/2018 (O.K.)

02/2019

08/2019

Website Owner

Bild

VBL. Versorgungsanstalt des Bundes und der Länder
Hans-Thoma-Straße 19
76133 Karlsruhe
Germany

Scope

Website certification covers the publicly available parts of a website. It focuses on the interaction between a visitor of a website and the website when the visitor browses the publicly available parts of the website. By contrast, it does not cover data protection issues related to website content (e.g., published pictures, videos and personal data in textual format).

Access restricted parts of a website are out of scope, but may be certified as an IT-based service according to the respective EuroPriSe requirements. The same holds true for other website offerings that qualify as an IT-based service (e.g., web shops).

In the case at hand, it must be stressed that the customer portal "Meine VBL" is out of scope of the EuroPriSe website certification.

Target of Evaluation

Applicable packages as addressed by the EuroPriSe certification criteria for website certification:

  • Basic package
  • Web  hosting
  • Web analytics
  • Forms on a website
  • Newsletter

More precisely, the target of evaluation of the website certification project www.vbl.de includes:

  • All information (DE+EN) on the website that ensures transparency towards website visitors as far as data protection issues are concerned, namely
    • the imprint,
    • the privacy policy,
    • the information that is provided via the cookie banner and
    • the cookie policy;
  • Processing of visitors' IP addresses;
  • Use of browser cookies;
  • Processing of personal data submitted by means of forms; 
  • Processing of personal data upon subscription to VBL's newsletter.

The ToE does not include:

  • Hosting of the webserver by a third party (contract + TOMs);
  • Customer portal "Meine VBL".

Evaluation Result

The legal and technical evaluation by the EuroPriSe Experts confirmed that visitors of the publicly available parts of the website www.vbl.de can be sure that VBL complies with all relevant requirements of the General Data Protection Directive (95/46/EC) and of the Directive on Privacy and Electronic Communications (2002/58/EC) as amended by Directive 2009/136/EC as far as interaction between website visitors' browsers and the webserver is concerned. 

Technical Evaluator

Alexey Testsov
datenschutz cert GmbH
Konsul-Smidt-Str. 88a
28217 Bremen
Germany

Legal Evaluator

Dr. Irene Karper, LL.M. Eur.
datenschutz cert GmbH
Konsul-Smidt-Str. 88a
28217 Bremen
Germany

Image

European Privacy Seal for www.vbl.de (Website Pilot)

Image

Disclaimer:

This register is kept with the utmost care. However, EuroPriSe does NOT guarantee the accuracy of information found on the Site. Your reliance on information found on the Site is at your own risk. For more information please go to EuroPriSe Terms & Conditions.

Initital Certification: 02/2018

VBL. Versorgungsanstalt des Bundes und der Länder proved that the publicly available parts of the website www.vbl.de comply with EU data protection law. Visitors of www.vbl.de can be sure that processing of personal data that results from the interaction between their browsers and VBL's webserver is in line with EU data protection law. 

Note: Information on the previous pilot certification of www.vbl.de (2015/08) is available at https://www.european-privacy-seal.eu/EPS-en/vbl-wwwvblde-pilot.

  

© 2008 - 2019 | EuroPriSe GmbH - European Privacy Seal | Handelsregister-Nr. (Commercial Register No.): Bonn HRB 20387

No responsibility for the accuracy of the information. Contact | Privacy Notice | Imprint

Product/Version

REISSWOLF f.i.t.

v1.5; service function as provided in 05/2018

Qualification: IT product and IT-based service (processor service)

View the REISSWOLF f.i.t. certificate

Version of Certification Criteria

11/2011

Cert. No.

EP-S-X5TSCN

Validity

24/05/2018 - 31/05/2020

Monitoring

01/2019

09/2019

Public Report

f.i.t. Short Public Report Image Image 

Manufacturer/Provider

REISSWOLF Systems GmbH

Im Heegen 13
22113 Oststeinbek
Germany

BEST

Access policies can be used to restrict system usage to specific times of the day and/or IP addresses to reduce the attack vector for third-party access. A user session is controlled by means of a cross-tab synchronised session countdown.

ATTENTION

Regarding the processing of personal data on third persons by means of f.i.t., it must be highlighted that the (usually) corporate users of the service qualify as controllers whereas REISSWOLF Systems GmbH acts as a processor on behalf of the users. Customers are advised that the legitimate use of the service may require the collection of the data subject's consent and/or declaration of release from confidentiality.

SUMMARY

REISSWOLF f. i. t. is a web-based archiving system for data storage and access. It serves the purpose of uploading, storing, managing and exchanging data in the sense of a document management system. f.i.t. is a web application that can be used with common internet browsers. 

DETAILS

REISSWOLF f. i. t. is primarily designed for commercial use. It is distributed by REISSWOLF Systems GmbH and operated as Software as a Service (SaaS) in a data center in Germany.

The ToE includes

  • The web-based service REISSWOLF f.i.t. (for details, please cf. the short public report)

It does not include

  • REISSWOLF f.i.t. mobile app
  • REISSWOLF f.i.t. hotfolder
  • Office module
  • Teamviewer
  • Other alternative interfaces to clients

Technical + Legal Evaluator

Ann-Karina Wrede
Innungsstraße 7
21244 Buchholz
Germany

Initial Certification: 05/2018

REISSWOLF f.i.t. provides a web-based service that enables companies to upload, store, manage and exchange data in the sense of a document management system. Users of the service are controllers in respect of personal data on third persons that is processed by means of f.i.t.. The service is designed in a way that facilitates the users' compliance with EU data protection law.

Image

Disclaimer:

This register is kept with the utmost care. However, EuroPriSe does NOT guarantee the accuracy of information found on the Site. Your reliance on information found on the Site is at your own risk.

Image

European Privacy Seal for REISSWOLF f.i.t.