Datenschutzerklärung
Privacy Policy for the Sustainability Reporting Navigator (SRN)
Last updated: May 2025
I. Overview
The Sustainability Reporting Navigator (SRN) is a research project jointly conducted by:
- Ludwig-Maximilians-Universität München (LMU Munich)
- University of Cologne
- Goethe University Frankfurt
The SRN is part of and funded by the DFG Collaborative Research Center TRR 266 "Accounting for Transparency."
The SRN Panel is an independent web-based research infrastructure that collects data for academic purposes. It is not hosted on an official LMU university domain but is administered by researchers at LMU Munich.
II. Who is responsible for data processing?
Unless otherwise stated, the controller under Article 4(7) GDPR is:
Ludwig-Maximilians-Universität München (LMU Munich)
Represented by the President
80539 Munich, Germany
Phone: +49 89 2180-0
Email: info@lmu.de no
Website: https://www.lmu.de
Scientific and operational contact:
Institute of Accounting and Auditing (Institut für Rechnungswesen und Wirtschaftsprüfung)
LMU Munich School of Management
Ludwigstraße 28 RG/IV
80539 Munich, Germany
Email: rwp@som.lmu.de
Data Protection Officer of LMU Munich:
https://www.lmu.de/de/die-lmu/struktur/organisation/vertretungen-und-beauftragte/datenschutzbeauftragte.html
III. Purpose and Legal Basis of Processing
We process personal data exclusively for academic research purposes within the meaning of Article 89(1) GDPR. The SRN Panel collects and analyzes user data to study digital behavior, sustainability reporting, and transparency-related decision-making.
Legal bases include:
- Article 6(1)(e) GDPR in conjunction with Article 4(1) BayDSG: processing in the public interest (scientific research)
- Article 6(1)(a) GDPR: where you provide voluntary consent (e.g. for participation in surveys)
- Article 9(2)(j) GDPR in conjunction with § 27 BDSG: processing of special categories of data for scientific research (if applicable)
IV. Categories of Data Processed
We process the following categories of data:
1. Basic and technical identifiers
- IP address, device information, browser type and version, screen resolution
- Referrer URLs, location (based on IP), language settings
- Date, time, and duration of visits
2. Behavioral data (scientific tracking)
We collect extensive and detailed user interaction data, including:
- Clicks and click paths
- Scrolling behavior
- Mouse movements and hovers
- Time on page and navigation sequences
- Interaction with dynamic elements (e.g., dropdowns, filters)
This tracking is used exclusively for scientific research and not for advertising or commercial profiling.
3. Questionnaire and survey data
We conduct voluntary online questionnaires as part of our research. When participating, we may collect:
- Demographic data (e.g. age range, gender, education level, professional background)
- Attitudes, perceptions, or preferences (based on survey content)
- Free-text responses
- Technical metadata associated with the response (e.g. response duration, completion status)
Participation is always voluntary. Depending on the study design, data may be pseudonymized, anonymized, or—where consent is given—linked to other session data.
V. Use of Tracking and Analysis Tools
To support research on user behavior, we use tracking technologies such as:
- Logfiles on secure servers
- Local storage (e.g. sessionStorage, cookies)
- Server-side analytics tools (e.g. Matomo in anonymized mode)
- JavaScript-based interaction logging
Tracking is conducted either without consent under the scientific exemption in Art. 89(1) GDPR and Art. 25 BayDSG, or—if personal identifiers are used—only with explicit consent.
All data are evaluated exclusively for scientific purposes and in accordance with the principle of data minimization.
VI. Data Transfers and Hosting
The SRN Panel is hosted on servers located within the European Union. Technical services are provided by academic or certified providers under data processing agreements in accordance with Article 28 GDPR.
Personal data are not transferred to third parties unless:
- required by law,
- explicitly permitted by the data subject, or
- fully anonymized for academic publication or scientific reuse.
VII. Data Retention
We store personal data only as long as needed for the specific research project.
Where possible, personal identifiers are removed early in the processing chain and replaced with pseudonyms. Fully anonymized data may be stored for long-term academic use.
Participation data (e.g. questionnaires) are retained only for the duration of the research project and then deleted or anonymized, unless longer storage is required by law or justified by scientific purposes.
VIII. Your Rights under the GDPR
You have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restrict processing (Art. 18 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with a data protection authority (Art. 77 GDPR), such as:
Bavarian State Commissioner for Data Protection – www.datenschutz-bayern.de
Please note: Some rights (e.g. erasure or objection) may be restricted under Article 89(2) GDPR if exercising them would seriously impair or render impossible the achievement of research purposes.
IX. Updates and Applicability
This Privacy Policy applies to the SRN Panel as operated by the Sustainability Reporting Navigator. It does not apply to other university websites of LMU, Cologne, or Frankfurt.
We may update this notice in line with legal or methodological changes.
Last updated: May 2025