Data Protection Principles of NORD/LB

Below you will find NORD/LB’s data protection notices. These include information about your visit and use of our website, as well as general information and our current privacy notices for various topics.

Controller

Norddeutsche Landesbank - Girozentrale -
Friedrichswall 10
30159 Hanover

For general inquiries, please use the following contact options to reach our customer service:

For questions specifically related to data protection, please contact our Data Protection Officer.

Data Protection Officer

Norddeutsche Landesbank - Girozentrale -
Data Protection Officer
Friedrichswall 10
30159 Hanover

E-mail: datenschutz@nordlb.de 

Principles for Processing Your Personal Data

As the controller responsible for processing your personal data, NORD/LB takes the protection of your data and your privacy very seriously. Safeguarding your personal information is a key concern for us.

Personal data includes all information relating to an identifiable natural person, such as your name, address, e-mail address, and telephone number.

We process your personal data exclusively on a legal basis in accordance with Art. 6 GDPR. Compliance with data protection requirements is regularly reviewed internally by our internal audit department and externally by the competent supervisory authorities.

In the following privacy notices, you will find detailed information on the processing of your personal data in connection with our various activities.

NORD/LB stores and processes your personal data for as long as you maintain a business relationship with us, are in business contact with us, or are authorized to represent us. Once the data is no longer required to fulfill contractual or legal obligations and no other lawful reason for processing exists, it will be regularly deleted. Exceptions apply in the following cases where temporary storage is necessary:

  1. Compliance with commercial and tax retention periods arising from the German Commercial Code (HGB), the Fiscal Code (AO), the German Banking Act (KWG), the Anti-Money Laundering Act (GwG), and foreign trade regulations. These periods may range from two to ten years.
  2. Preservation of evidence under statutory limitation periods. According to Sections 195 et seq. of the German Civil Code (BGB), these periods may be up to 30 years, although the regular limitation period is three years. If you have objected to or revoked the processing of your data for contact purposes, we will no longer store your data unless the above-mentioned statutory retention or documentation obligations take precedence.

Your Data Protection Rights

You have the following rights regarding your personal data vis-à-vis NORD/LB:

  • Right of access (Art. 15 GDPR)
  • Right to rectification or erasure (Art. 16 and 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

Please note that withdrawal only applies for the future. Processing carried out before the withdrawal remains unaffected.

Security

We place great importance on a high level of security in the collection and processing of your data. NORD/LB implements effective technical and organizational measures to protect your data against manipulation, loss, destruction, and unauthorized access. Our security measures are continuously optimized and adapted to the latest technological developments. In addition, we have established a reliable internal incident process to respond appropriately in the event of security incidents.

When processing your personal data, we also work with carefully selected service providers who must meet NORD/LB’s requirements. To ensure continuous compliance with data protection regulations, we conclude the necessary data protection agreements, such as data processing agreements, with these partners. We only receive personal data from third parties or transfer it to third parties if there is a legal basis for processing. Furthermore, we do not sell personal data to third parties for advertising purposes.

The security and integrity of your personal data is extremely important to us. Therefore, our employees are regularly trained and sensitized on data protection issues.

Transfers to Third Countries

We generally process your personal data within the European Economic Area (EEA). Transfers to countries outside the EEA only occur if necessary to fulfill your orders, provide our services, or in connection with an existing, potential, or former employment relationship, if legally required, or if you have given your consent. When we use service providers in third countries, they are required to comply with EU Standard Contractual Clauses or be located in a country recognized by the EU as providing an adequate level of data protection.

The following countries are considered by the EU to provide an adequate level of protection for the processing of personal data (adequacy decision):
Andorra, Argentina, Canada (limited), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, and Uruguay.

For recipients in other countries, we conclude agreements on the application of EU Standard Contractual Clauses or binding corporate rules to ensure an adequate level of protection in accordance with legal requirements.

Updates and Amendments to This Privacy Notice

This privacy notice is currently valid as of January 2026.

Due to the further development of our website and services or changes in legal or regulatory requirements, it may become necessary to update this privacy notice.

 

Privacy Notices of the NORD/LB homepage

Privacy Regarding Cookies

Privacy Notices for NORD/LB social media channels

Privacy Notice