PRIVACY INFORMATION
Public employer and job sources
Information under Article 14 GDPR · Version 1.6 · 15 August 2026
This information covers limited measurement of publicly accessible job sources and a time-limited depth analysis. Applicant and user data are not part of this processing.
1. Controller and privacy contact
Stephan Popp, sole proprietor (ADE), Peterssteinweg 14–16, 04107 Leipzig, Germany
Email for data-protection rights and objections: optout@ade.international
Data protection officer – functional contact: data@ade.international
Current online version: https://datenschutz.ade.international
2. Processing covered by this information
ADE conducts limited source measurement on publicly accessible employer and job sources. The purposes are to discover and perform technical and legal pre-checks on eligible sources, count publicly offered jobs, and measure coverage and data quality. A separately approved, time-limited depth analysis may also structure published information about work, requirements and working conditions.
This information applies only where processed information may relate to a natural person, particularly sole traders, self-employed professionals or person-linked business names. Information concerning legal persons is generally not personal data as such. Application forms, CVs, applicant profiles and applicant contact data are not collected in this source measurement.
3. Purposes and legal basis
Where personal data are involved, processing is based on Article 6(1)(f) GDPR. ADE's legitimate interests are to:
- discover, check and measure publicly accessible job sources in a data-minimising manner;
- avoid duplicate access, prohibited access and renewed processing of blocked sources;
- assess coverage, quality, representativeness, effort and economic viability in aggregated form;
- ensure data quality, accountability, security and effective rectification, objection and erasure processes.
ADE limits processing to the publicly apparent business and job context. Personal designations are detected only transiently and then suppressed where they are not necessary. Private characteristics are not evaluated and no personal profile is created.
4. Sources and categories of data
The data originate from publicly accessible sources, including:
- employer career sites and recruiting systems operated or commissioned by employers;
- public job and employment portals and official or openly provided employment channels;
- feeds, listings, directories and structured interfaces published by their operators;
- public registers, reference data and metadata sources, where their use is permitted for the relevant purpose.
Depending on the measurement stage, the following categories are processed:
- technical source and route identifiers and publicly apparent source attributes;
- published business, location, language, industry, activity and legal-form classifications with minimal provenance and currency information;
- review, blocking, objection, rectification and accountability status and aggregated technical metrics;
- during the time-limited depth analysis: structured information on work and requirements, employment and working conditions, remuneration and benefits, and publicly stated workplace or employer characteristics.
Applicant documents, private contact details and additional information about owners, partners, employees or contact persons are neither intentionally extracted nor stored in structured form. Information carried incidentally in job text is not enriched and is removed no later than that text under section 6; uncertain classifications remain open.
5. Recipients and transfers
Access is limited to authorised internal roles and contractually bound service providers for hosting, database operation, backups, technical administration, email and domain operation, insofar as required for the stated purposes. These service providers are selected and controlled by function, safeguards and processing location within Germany or the EU/EEA.
Personal data covered by this information are not transferred to recipients outside the EU or EEA in the described measurement path and are not published as a public source or person directory. On request, the actual relevant recipients are provided to the data subject in accordance with Article 15 GDPR.
6. Retention
| Data category | Period / criterion |
|---|---|
| Source, route and classification data | no more than 12 months from creation or the most recent documented review; earlier where the purpose ends or a prevailing rectification, erasure, restriction or objection ground applies |
| Transient job text | without undue delay after analysis and no later than 72 hours after completion of the relevant analysis pass |
| Job-level depth-analysis results | 30 days after sample review and no later than 90 days after the relevant pass begins |
| Technical security logs | normally 7 days; justified incident extracts for no more than 30 days |
| Minimal blocking or objection record | for as long as needed to honour an effective block or objection, subject to periodic necessity review |
Only demonstrably non-personal, sufficiently aggregated measurement results may be used for business assessment and expansion planning beyond these periods. Low counts and the risk of re-identification are taken into account.
7. Automated decisions
Source measurement does not make a solely automated decision producing legal or similarly significant effects on natural persons (Article 22 GDPR) and does not create a profile of natural persons.
8. Your rights
Where data can be linked to you, you may request access, rectification, erasure and restriction subject to the statutory conditions. You may also object under Article 21(1) GDPR on grounds relating to your particular situation. You do not need to provide a special justification for an access request. Data portability applies only where its statutory conditions are met.
A domain, host name, public URL, job reference or another plausible link will normally be sufficient to locate a record. Additional identity evidence is requested only where there are reasonable doubts about identity. In response to an access request we provide the personal data actually concerned and the required information on their source and recipients; unrelated internal system knowledge or the complete general data schema is not part of an individual access response.
Separately from the rights of natural persons, source operators may use the same contact route for technical, licensing or organisational review, blocking and removal requests.
You may lodge a complaint with a data protection supervisory authority. In Saxony, this is the Saxon Commissioner for Data Protection and Transparency; you may also contact any other competent supervisory authority.
9. Public information instead of collecting additional contact data
ADE generally does not hold separate contact data for potentially affected sole traders or self-employed professionals in the measurement path. Individual notice would therefore often require collecting additional personal contact data solely for notification. ADE records separately for each affected processing class whether the conditions of Article 14(5)(b) GDPR are met. Where they are met, this continuously accessible notice is one safeguard. Where the exception does not apply, the timing requirements of Article 14(3) GDPR apply.
10. Security, language and updates
ADE applies appropriate technical and organisational measures, including role-based access, data minimisation, separation of review and content data, erasure and blocking processes, and periodic controls. The German version is the controlling master; this English version is intended to be substantively equivalent. Material changes to purposes, categories of data, recipients, transfers or retention are reflected in this information before activation.