If you need help or are experiencing problems, please contact our support team.
Data Controller
The entity responsible for the processing of personal data within the meaning of the General Data Protection Regulation and other data protection regulations is
Governikus
Hochschulring 4
28359 Bremen
Phone: +49 421 204 95-0
Email: kontakt@governikus.de
Data Protection Officer at Governikus
Christian Drews, Esq., LL.M.Eur.
Director of Legal and Regulatory Affairs
Governikus
Hochschulring 4, D-28359 Bremen
Email
Note: Please do not send support requests to this email address. You can reach our support team at support@ausweisapp.de.
ID Information / “My Data” Service
AusweisApp includes a "My Data" / ID Information function. This function allows the data stored on the national ID card, the electronic residence permit, or the eID card for EU and EEA citizens to be read and displayed.
Once AusweisApp has been launched and a suitable card reader installed or a smartphone connected, this function can be accessed via the "My Data" menu item.
After the PIN is entered and the data transfer is successful, the data is displayed within AusweisApp.
The "My Data" function is strictly a demonstration service. The data retrieved is displayed only and is not passed on to third parties; it is not stored by Governikus. Data verification is performed via the specific eID server used by the service. This eID server manages authorization certificates and maintains revocation lists. The server handles secure communication with AusweisApp and the ID card, passing the retrieved data to the service. It verifies the authenticity and validity of the ID card, checks whether the holder has blocked it, and transmits the results of the online ID function to the service. An internet connection is required for identity verification via the eID server to enable the verification process and the encrypted transmission of data. This connectivity is essential for executing cryptographic protocols with the ID card's chip and for regularly obtaining the necessary authorization certificates and revocation lists. The eID server consistently complies with current BSI technical guidelines, ensuring adherence to the state of the art.
More about the authorization certificate
Access to data from the identity card, electronic residence permit, or eID card (for EU and EEA citizens) is only possible if the service provider wishing to access the data first clearly identifies itself. This is done using what is known as an authorization certificate. The identity of the party wishing to access your data is always displayed. Authorization certificates are issued to service providers upon application and following a review by the Authorization Certificate Issuing Authority at the Federal Office of Administration. An internet connection is essential to display the technical authorization certificate and to perform a validity check on the ID document. For this reason, it is referred to as the "online ID function."
Further details on how the online ID function works can be found here.
The application server, database server, and HSM are located at the following data center:
KDO Service GmbH
Elsässer Str. 66
26121 Oldenburg
General information on the rights of data subjects
If your personal data is processed, you are a "data subject" within the meaning of the GDPR. Provided the respective conditions are met—and subject to any conflicting statutory restrictions or exceptions, particularly under Sections 34–36 of the Federal Data Protection Act (BDSG) or Sections 21–27 of the Federal Office for Information Security Act (BSIG)—you have the following rights vis-à-vis us as the controller:
1. Right of access
You may request confirmation as to whether we are processing your personal data. If this is the case, you have the right to access this personal data and to receive further information related to the processing (Art. 15 GDPR).
2. Right to rectification
You may request the rectification and, where applicable, the completion of your personal data (Art. 16 GDPR).
3. Right to erasure
You may request the erasure of your personal data (Art. 17 GDPR).
4. Right to restriction of processing
You may request the restriction of the processing of your personal data (Art. 18 GDPR).
5. Right to object
You may object to the processing of your personal data by us at any time (Art. 21 GDPR). This right applies if your personal data is processed pursuant to Art. 6(1)(e) or (f) GDPR—for example, for direct marketing, scientific or historical research, or statistical purposes.
6. Right to data portability
Subject to the conditions of Art. 20 GDPR, you are entitled to request that we provide you with the personal data concerning you—which you have provided to us—in a structured, commonly used, and machine-readable format.
7. Right to withdraw consent under data protection law
If you have consented to the processing of your data (Art. 6(1)(a)), you have the right to withdraw your consent at any time. The withdrawal of consent applies only to the future; that is, the withdrawal does not affect the lawfulness of processing carried out based on the consent prior to the withdrawal.
8. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority—particularly in the Member State of your place of residence—if you believe that the processing of your personal data by us violates the GDPR. The supervisory authority for the BSI is:
The Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Str. 153
53117 Bonn
Telephone: +49 (0)228 997799-0
E-mail: poststelle@bfdi.bund.de
Data Protection Officer
Christian Drews, LL.M. Eur. (Attorney)
Director of Legal and Regulatory Affairs
Governikus
Hochschulring 4, D-28359 Bremen
E-Mail
Note: Please do not send support requests to this email address. You can reach our support team at support@ausweisapp.de.
