Skip to main content Skip to page footer

Data Protection

MVV GmbH would like to thank you for visiting our website. We take the protection of your personal data very seriously. We comply with the applicable data protection regulations and guarantee the security of the data you provide to us in accordance with the relevant data protection laws. 

We only collect personal data if you actively and voluntarily provide it to us (e.g. when using mobile or online ticketing, ordering a loyalty card, entering a competition or placing an order in our MVV online shop) – otherwise, we do not process any personal data via the MVV website. Personal data includes, in particular, email addresses, names, addresses and telephone numbers. The personal data provided will not be passed on to third parties, unless this is necessary to fulfil the purpose for which it was provided. It will be used exclusively for the purpose for which it was collected, unless otherwise specified below. We guarantee that your personal data will not be used for advertising purposes. Nor is any automated decision-making, including profiling, carried out in accordance with Article 22(1) and (4) of the GDPR.

Where the processing of personal data is based on your consent (Article 6(1)(a) or Article 9(2)(a) of the GDPR), you have the right to withdraw your consent at any time, without this affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal, in accordance with the statutory provisions on data protection (Article 7 of the GDPR, Section 51 of the Federal Data Protection Act (BDSG)).

You have the right to access the personal data in question (Article 15 of the GDPR), as well as the right to rectification (Article 16 of the GDPR), erasure (Article 17 of the GDPR) or restriction of processing (Article 18 of the GDPR) or to object to the processing (Article 21 of the GDPR), as well as a right to data portability (Article 20 of the GDPR), in accordance with the statutory provisions on data protection.

For some of the services and offers provided by MVV GmbH, specific provisions are set out below. If you make use of these services or offers, or by ticking the relevant box (opt-in), you, as a user, expressly consent to the use of your data as follows:

MVV GmbH processes the data provided by the customer in connection with an order for the purposes of fulfilling that order. The legal basis for this is Article 6(1)(b) of the GDPR. The recipients of this data are the employees of MVV GmbH responsible for processing the order. The data will be deleted after ten years in accordance with commercial law requirements. No contract can be concluded without the provision of this data.

The special terms and conditions for mobile and online ticketing apply, as set out at 

Terms and Conditions for Mobile and Online Tickets, Section 12

To issue the customer card, the data provided by the customer in the online application form is processed. This data (where marked with *) is required to issue the customer card, which in turn is essential for using the student fare. Without this data, the service cannot be used.

The personal data required when completing the application form for a customer card under the student fare scheme is processed solely by employees of MVV GmbH – and, in the case of orders placed via the S-Bahn München website, also by employees of DB Vertrieb GmbH – for the purposes of verifying, creation, printing and dispatch of customer cards under the student fare scheme, as well as for the settlement of corresponding state compensation payments and for sales statistics (quantities only). The legal basis for the processing is Article 6(1)(b) of the GDPR; the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.

The data will be stored for as long as is necessary for the purposes stated; as a rule, it is deleted two years after the card is issued.

Data provided to MVV GmbH in connection with a suggestion or complaint is stored and analysed in anonymised form for the purpose of dealing with the matter and improving quality. The data is processed by employees of MVV GmbH; where the suggestion or complaint is forwarded to the relevant transport company for a response or to clarify the facts of the matter, the personal data provided will also be forwarded. The user expressly consents to this. The legal basis for the processing is Article 6(1)(a) of the GDPR (consent). Without the provision of the data, the complaint or enquiry cannot be processed.

To protect against spam, MVV GmbH uses the reCAPTCHA service provided by Google Inc. (“Google”). This service involves the transmission of your IP address and, where applicable, other data required by Google for the reCAPTCHA service to Google. Google’s separate data protection provisions apply to this data. Further information on Google reCAPTCHA’s privacy policy can be found at policies.google.com/privacy.

Enquiries submitted outside the contact form will also be forwarded to the relevant transport operator where necessary to respond to them or clarify the facts; in such cases, the personal data provided will also be forwarded.

The data is generally deleted twelve months after processing.

When ordering MVV brochures online, the data provided by the customer is processed by employees of MVV GmbH for the purpose of fulfilling the order. The legal basis for this processing is Article 6(1)(f) of the GDPR. The legitimate interest of MVV GmbH, the transport operators and the funding authorities lies in the (free) distribution of information material to encourage more people to switch to public transport. It is not possible to place an order without providing the data. The data will be deleted two months after dispatch.

The MVV Partner Area serves as a data exchange platform for employees of transport companies and transport authorities. The data provided during registration is used by MVV GmbH staff to verify the user’s identity upon login and for functions related to the MVV platform. It is not processed for any other purposes. This data is not disclosed to third parties, unless this is necessary to fulfil the purpose of the disclosure. The legal basis for the processing is Article 6(1)(f) of the GDPR. The legitimate interest of MVV GmbH, the transport authorities and the transport operators lies in the smooth transmission of information required by the employees of transport operators, transport authorities and MVV GmbH for their day-to-day work. The registered person’s personal data will be deleted once they have deregistered or are deregistered. Registration is not possible without providing the data.

When making enquiries via the MVV Enquiry Service and the MVV Cycle Route Planner – apart from brief, technically necessary temporary storage in connection with IP-based communication and when using one of the ticket shops on offer to purchase MVV OnlineTickets – no personal data is processed. When using one of the ticket shops offered to purchase MVV OnlineTickets, personal data is processed in accordance with the data protection provisions applicable to the respective ticket shop. The regulations governing the sale of mobile and online tickets via the MVV GmbH ticket shop can be found in Section 12 of the General Terms and Conditions and Data Protection Principles.

When accessing timetable enquiries, the following data is stored on the end device: history of the most recently used locations, connections and routes, settings applied, downloads (e.g. orientation maps, displayed timetables and timetable book pages), server content received (map extracts, journey information) and technically necessary cookies, as described in more detail below.

To ensure secure operation, calculations carried out by the electronic timetable enquiry service (departures, journey information, etc.) are logged on the timetable enquiry servers. The logs relate exclusively to the calculations carried out and comply with the data protection principles of MVV GmbH. No personal data is transmitted or stored in the process; it is not possible to draw any conclusions about the user or their query patterns.

Where the user provides an email address, this is also stored temporarily for technical reasons only and is automatically deleted once the information has been sent; it is not used for any other purpose. The legal basis for the processing is Article 6(1)(f) of the GDPR, in order to provide you, the user, with better access to public transport.

MVV Information and the MVV Cycle Route Planner use so-called functional cookies, i.e. those that are technically necessary. These cookies enable us to recognise and temporarily store information, such as language settings or your preferred method of accessing our mobile information portal. In addition, the cookies set optimise the processing of your connection requests on our server infrastructure (so-called session cookies). No personal data is collected or passed on in the process.

To improve the quality of timetable information, MVV GmbH and/or IT service providers also compile anonymised usage statistics based on server requests. These are used solely for product improvement and do not contain any personal information. We do not use any tracking or advertising cookies in the MVV timetable enquiry service or the MVV cycle route planner.

The MVV mobile information portal allows location data to be used for timetable enquiries. To use this function, you must explicitly consent to the use of location information in your browser. This data is used to determine waypoints in route planning, as well as nearby stops and departures. Location data is not stored permanently or passed on to third parties.

A code will be generated based on the details you provide to integrate the MVV timetable information into your website. This code is not stored permanently but is deleted once your enquiry has been processed. No personal data is collected, as, in particular, no IP address is stored.

Any documents you send us as part of a job application will be reviewed by us to assess their potential use. The legal basis for the processing is Article 6(1)(b) of the GDPR; the processing is necessary for the implementation of pre-contractual measures. Your documents will be deleted six months after a rejection (paper applications will be shredded), unless otherwise agreed.

The data you provide will be used solely for the purposes of the project. The data will not be passed on to third parties and will only be processed anonymously; we are unable to establish any link to specific individuals. Once the project has been completed, the raw data will be deleted, meaning that it will no longer be possible to establish any link to specific individuals.

As part of our prize draws, we process personal data that you voluntarily provide to us (e.g. name, email address). This data is used exclusively for the purpose of running the prize draw and notifying the winners. For any differing provisions, please refer to the terms and conditions of the respective promotion.

Purpose and legal basis for processing:

The processing of your personal data is based on your consent in accordance with Article 6(1)(a) of the GDPR. Your data will only be stored for the duration of the competition and for the subsequent notification of winners. The data will then be deleted, unless statutory retention obligations prevent this.

Data disclosure:

Your data will not be disclosed to third parties and will not be used for advertising purposes.

Withdrawal of consent:

You have the right to withdraw your consent to data processing at any time with future effect. You may withdraw your consent by emailing datenschutz(at)mvv-muenchen.de. Following withdrawal, your data will be deleted unless there are statutory retention obligations.

Prohibition on linking:

You are not required to consent to the anonymous statistical analysis of app data in order to take part in the prize draw.

MVV GmbH uses the data you provide solely for the purpose of sending the newsletter. The data will not be passed on to third parties. The data is used in anonymised form by MVV GmbH staff solely for the statistical analysis of newsletter distribution. The legal basis for the processing is Article 6(1)(a) of the GDPR (consent). Your data will be deleted when you unsubscribe from the newsletter. The newsletter cannot be sent without you providing this data.

To book on-demand services (MVV Ruftaxi, FLEX) online or by telephone, you must register by providing your name, telephone number and email address (this may not be required if you book by telephone). This data is used exclusively for the organisation, scheduling and provision of the journeys you have booked, as well as for contacting you in connection with the journeys you have booked (e.g. changes to journey times, enquiries regarding space requirements) and, for the same purpose, passed on electronically via encrypted transmission systems to the call-a-taxi centre and the relevant transport operator. The legal basis for the processing is Article 6(1)(b) – the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures – and (f) of the GDPR. The legitimate interests of MVV GmbH, the transport operators and the public transport authorities lie in providing you, as a user of the MVV app, with better access to public transport and in facilitating timetable enquiries and the purchase of MVV Mobile Tickets. Without providing the data, no booking can be made via the booking tool.

The data will be deleted no later than two years after the last use or booking. Furthermore, the data will be deleted within 30 days upon the customer’s express request sent by email to kundendialog@mvv-muenchen.de, provided that no statutory retention obligations prevent this.

The protection of your personal data is important to Münchner Verkehrs- und Tarifverbund GmbH (MVV, hereinafter referred to as MVV GmbH), Thierschstraße 2, 80538 Munich (hereinafter referred to as ‘we’). Alongside the so-called customer contract partners (MVG, Munich S-Bahn), we also process personal data in compliance with the EU General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Bavarian Data Protection Act (BayDSG) and all other relevant data protection legislation.

Below, we explain how we, as MVV GmbH, process your personal data in connection with the use of electronic tickets (e-tickets) on smart cards and what rights you have. In addition, our general data protection notice applies. You can find this at https://www.mvv-muenchen.de/footer/datenschutz/index.html. To find out how our customer contract partners process your personal data, please visit

MVG: https://www.mvg.de/datenschutz-eticket.html

DB Vertrieb: https://www.bahn.de/p/view/home/datenschutz/schutz.shtml

1. Data controller

The entity responsible for the protection of your data entering and leaving the MVV GmbH back-end system, in accordance with Article 4(7) of the GDPR, is Münchner Verkehrs- und Tarifverbund GmbH (MVV), Thierschstraße 2, 80538 Munich, email: info@mvv-muenchen.de. For further information on so-called joint controllers under Article 26 of the GDPR, see section 5.2.

MVV GmbH has an external data protection officer. You can contact them by email at Datenschutz@mvv-muenchen.de or by post at DSBOK, Data Protection Officer for MVV GmbH, Untergasse 2, 65474 Bischofsheim.

2. Categories of data, as well as the purpose and legal basis of data processing

The partners in the Munich Transport and Fare Association (MVV) are gradually switching their season tickets from paper tickets to electronic tickets (eTickets for short). You can find out exactly which season ticket products this applies to in our FAQs on the chip card at https://www.mvv-muenchen.de/tickets/zeitkarten-abos/isarcard-chipkarte/index.html. In this process, the booked electronic ticket (the travel authorisation or ticket) is stored on a chip card.

Your personal data is processed in the back-end systems of the customer contract partners, as this is necessary for the performance of the season ticket contract with you. This processing is described in the privacy policy of the respective customer contract partner with whom you have concluded your contract.

Making changes via the online procedure

One advantage of the e-ticket on a chip card is that no customer data is printed on the chip card itself (as was the case with paper tickets), furthermore, the card can be blocked in the event of loss or theft, and you can request changes (e.g. adding or reducing zones) yourself online, with the changes being applied directly to your chip card. The previous process of exchanging tokens is no longer necessary. If you do not make a change to your ticket at the customer centre using your chip card, but instead do so by telephone via the hotline of your contract partner (MVG or S-Bahn München) or online, the following procedure must be followed to ensure your change is stored on your chip card:

To ensure that your (amended) ticket is accepted as a valid travel document by all partners within the MVV – even though the partners within the MVV do not have access to each other’s back-end systems – it must be ensured that all partners within the MVV are informed of the change. The partners listed in section 5.2 have therefore opted for the Germany-wide ‘(((eTicket Deutschland’ standard as so-called joint controllers for the chip card. This standard is considered particularly secure with regard to misuse, tampering or forgery. The standard was developed in close cooperation with the Conference of Federal and State Data Protection Commissioners. In the “(((eTicket Deutschland” standard (known as the VDV core application), particular emphasis was placed on data protection, data minimisation and consumer protection. Under the “(((eTicket Deutschland” standard, the change you have made is stored in a so-called action list at MVV GmbH. In this process, only the change request (e.g. extension of the ticket’s geographical validity) is processed in conjunction with the smartcard number and the travel authorisation number. Only pseudonymised data is therefore exchanged between the partners; no other personal data relating to you is shared with the partners within the MVV network. It makes no difference which MVV partner you are a customer of; the personal data required to fulfil your season ticket contract is held solely by your direct contractual partner. All partners within the MVV can access the action list, thereby ensuring that your chip card is automatically updated the next time it interacts with a ticket inspection device (e.g. during a ticket inspection), a ticket machine with (((e-Logo) or a till terminal in the customer centre, and that, for example, the new travel authorisation is stored on the chip card. Once the update is complete, your change is deleted from the action list.

Data in/on the chip card

The following data is stored on the chip card itself with access protection: ticket number, number of the issuing transport operator, geographical and temporal validity, and – only in the case of a personalised season ticket – the cardholder’s first name and surname in an anonymised form (e.g. Max Mustermann becomes M1x@M8n), as well as date of birth and gender.

No personal data is printed on the smartcard. There is a note field which you can fill in yourself – e.g. to distinguish between cards within the family – (however, we recommend that you do not enter your full name here, but rather ‘Mum’ or similar). The only information printed on the chip card is the chip card number and the expiry date of the chip card (you will automatically be sent a new chip card when this date expires). The chip card number printed in the bottom right-hand corner can also be read electronically via the printed barcode.

In addition to the electronic ticket, there are ten memory slots on the chip card for so-called transaction entries (logbook). A transaction occurs when data is exchanged between the chip card and a terminal, for example during a ticket inspection. The transaction is stored as an entry in the logbook. From the eleventh logbook entry onwards, the old entries are overwritten by the new subsequent entries, so that only the last ten entries are ever stored on the chip card.

Ticket inspection

During a ticket inspection by inspection staff, the data stored on the smartcard is read out and the electronic ticket, along with its temporal and geographical validity, is automatically checked. The inspection result is displayed to the inspector (ticket valid or invalid in terms of its time and geographical validity). In addition, the ticket holder’s anonymised name, date of birth and gender are displayed on the ticket inspection device (only for personal season tickets, not for transferable ones). This data is necessary to enable ticket inspectors to make an initial assessment, based on age and gender, as to whether the person being checked may be the rightful ticket holder. Unlike with a paper ticket, however, ticket inspectors cannot see the unmasked (i.e. fully legible) name. As before, holders of a personalised season ticket must carry photo ID and present it if required. The data read from the chip card by the ticket validator is temporarily stored on the device solely for the purpose of the inspection and is automatically deleted by the ticket validator immediately after the inspection is completed.

Proof of inspection

MVV GmbH is responsible, within the framework of (((eTicket Deutschland, for the fare products issued by MVV as electronic tickets. Against this background, transaction records (e.g. so-called inspection records) are transmitted to MVV GmbH’s back-end system, which checks the data record as part of a fraud analysis for tampering, i.e. the authenticity and integrity of the electronic ticket. A transaction record contains details of the time, location and type of transaction (e.g. zone change or ticket inspection), as well as the terminal number (e.g. validator) and the product number, but no other personal data.

Further information / Legal basis / Anonymous tickets

Further information on data processing can be found in the FAQs on the chip card at www.mvv-muenchen.de/tickets/zeitkarten-abos/isarcard-chipkarte/index.html.

The legal basis for data processing by MVV GmbH is Article 6(1)(b) of the GDPR in conjunction with your contractual relationship regarding your IsarCard subscription with a customer contract partner (MVG or S-Bahn München) and Article 6(1)(c) and/or (f) of the General Data Protection Regulation (GDPR).

It is still possible to use transport services within the MVV network without an e-ticket by purchasing a ticket from the cash fare scheme (e.g. monthly and weekly passes), which are issued on paper.

3. Data sources

We process pseudonymised personal data that is lawfully transferred to us by joint controllers (your customer contract partner) (e.g. smart card number).

4. Necessity of providing personal data

Unless expressly stated otherwise, the provision of the data referred to in section 2 is already necessary for the conclusion or performance of the contract between you and your customer contract partner, as the contract cannot be performed without this personal data. No additional personal data is collected for the specific data processing described in section 2 relating to e-tickets on chip cards; however, additional pseudonymised personal data (primarily the chip card number) is stored and processed.

5. Categories of data recipients

5.1 Internal departments and data processors

Within MVV GmbH, only staff members in operational management who require your data for the purposes described in section 2 are granted access to it. Where permitted by law (for example, in the context of data processing on behalf of a client), we may disclose personal data to third parties in the following categories:

  • (IT) service providers
  • Public authorities and institutions (e.g. social security bodies, tax authorities, the police, the public prosecutor’s office, supervisory authorities) where there is a corresponding obligation or authorisation.

5.2 Joint controllers

To ensure that the eTicket can be used throughout the MVV fare zone, it is necessary for transaction records to be transmitted to the MVV GmbH back-end system, which checks the data record as part of a fraud analysis for tampering, i.e. the authenticity and integrity of the electronic ticket. Furthermore, for checks carried out by the various transport operators within the MVV network, pseudonymised personal data must be exchanged via the action list, as described in section 2. No other personal data is transmitted in this process.

As the transport operators within the MVV area jointly determine the purposes and means of data processing, they act as so-called joint controllers in accordance with Article 26 of the GDPR. The following transport operators have therefore concluded a corresponding agreement on joint controllership:

  • Münchner Verkehrs- und Tarifverbund GmbH (MVV)
  • DB Regio AG – Munich S-Bahn
  • Münchner Verkehrsgesellschaft mbH (MVG)

MVV GmbH will be happy to provide you with the key details of the joint controller agreements with the above-mentioned companies. To do so, please use the contact details provided in section 1.

6. Data transfers to a third country or to an international organisation

There are currently no plans to transfer data to a third country or to an international organisation in relation to the chip card. Should we, in future, use (IT) service providers for certain tasks who in turn use (IT) service providers that may have their registered office, parent company or data centre in a third country (outside the European Union and the European Economic Area), the following conditions must be met: The transfer is permitted because there is a legal basis for it, or you have expressly consented to the transfer, and the specific conditions for a transfer to a third country are met. In particular, this means that the European Commission has determined that an adequate level of data protection exists in the third country (Article 45 of the GDPR) or that suitable safeguards (e.g. through so-called EU Standard Contractual Clauses prescribed by the European Commission or the supervisory authority) and enforceable rights and effective legal remedies are in place.

7. Retention period

The chip card is valid for a maximum of approximately five years; after this period, it is replaced by a new card with a new chip card number. Transactions that are (directly or indirectly) personal in nature are archived for a maximum of 180 days after receipt/creation and deleted after a further 365 days; the associated authorisations are archived 270 days after the expiry of the validity period and, if there are no longer any references to the authorisation, are deleted after a further 540 days.

With regard to other data, we will delete your personal data as soon as it is no longer required for the purposes for which it was collected, unless its – temporary – further processing is necessary to:

  • comply with statutory retention obligations, which may arise, for example, from the German Commercial Code (HGB) and the German Fiscal Code (AO). The time limits specified therein are up to ten years.
  • Preserving evidence within the framework of statutory limitation periods. Under Sections 195 et seq. of the German Civil Code (BGB), these limitation periods may be up to 30 years, although the standard limitation period is three years.

8. Data subjects’ rights

You can find detailed information about your rights as a data subject on our website in the data protection section: https://www.mvv-muenchen.de/datenschutz

9. Automated decision-making

As a general rule, we do not use automated decision-making in accordance with Article 22 of the GDPR. Should we use such procedures in individual cases, we will inform you of this separately in accordance with the statutory provisions.

10. Amendment clause

As our data processing is subject to change and the legal situation may evolve, we will also update our privacy notice from time to time.

Date of this privacy notice: 1 April 2020

As a rule, the data collected by passenger counting devices does not constitute personal data within the meaning of the GDPR.

Video-based passenger counting is only activated when necessary to verify the plausibility of counting results by an authorised MVV employee. Personal video data is only generated once the video recording function has been activated. Following the verification, the relevant video data is deleted within 48 hours.

The legal basis for this processing is Article 6(1), first sentence, point (e) of the GDPR, as the processing is necessary for the performance of a task carried out in the public interest, as well as Section 4(1), first sentence, No. 1 and No. 3 of the BDSG. Furthermore, in accordance with Article 24(3) of the Bavarian Data Protection Act (BayDSG), the identification of individuals by security authorities for the purpose of investigating crimes on the basis of objects, clothing or similar items would be permissible. However, this would be subject to the condition that the video function had happened to be activated in that particular vehicle at that precise time and that the video recordings had not yet been deleted or overwritten.

Following explicit consent (‘opt-in’), anonymised mobility data may be collected from app users who have purchased a Deutschland-Ticket via the MVV Ticket Shop during the pilot period from September to November 2024. The aim is to investigate the use of the Deutschland-Ticket on different routes and services. To this end, the following data will be collected and analysed: anonymous user IDs (randomised at least once a month), timestamps, geolocation, recording accuracy and compass direction, speed of movement, time intervals per mobility segment (including classification reliability for transport mode identification), smartphone model name, and the version of the operating system and the MVV app. The legal basis is Article 6(1)(a) of the GDPR. No conclusions regarding individual persons can be drawn from the data analysis. In the MVV app settings, consent to data collection can be withdrawn at any time and data that has been transmitted can be deleted at any time.

As at October 2024

1. General

(1) MVV GmbH offers a check-in/check-out system (hereinafter referred to as the InOut system or MVVswipe) via the MVV app. This is a smartphone-based ticketing system with automatic ex-post fare calculation. Using location data (GPS), the smartphone detects a CheckIn actively triggered by the customer, the route travelled within the MVV network via local public transport (ÖPNV), and the CheckOut triggered by the customer. The system then calculates the correct fare for the journey in the background based on this location data. If several journeys are made in a single day, the maximum charge will be the applicable daily fare (depending on the zone and number of passengers). Depending on the number of journeys per day, the customer’s previously registered payment method will be debited.

(2) To process the e-payment service (e.g. the InOut system), MVV GmbH utilises the IT service provider Mentz GmbH (hereinafter referred to as MENTZ), Grillparzerstraße 18, 81675 Munich, and the financial services company LOGPAY Financial Services GmbH (hereinafter referred to as ‘LOGPAY’), Schwalbacher Straße 72, 65760 Eschborn. MENTZ is responsible for the technical operation of the software components. The infrastructure is located in certified data centres in Germany. As part of commissioned data processing, the service providers utilise software instances hosted by the data centre operator Amazon Web Services (AWS). These components are operated exclusively in the eu-central-1 region (Frankfurt am Main).

(3) The data controller within the meaning of data protection law is MVV GmbH, represented by its management. It can be contacted by email at info@mvv-muenchen.de or by post at MVV GmbH, Management, Thierschstraße 2, 80538 Munich. MVV GmbH has an external data protection officer. The data protection officer can be contacted by email at datenschutz@mvv-muenchen.de or by post at DSBOK, Data Protection Officer for MVV GmbH, Untergasse 2, 65474 Bischofsheim. If the customer wishes to have their personal data deleted, they must submit a request by email to datenloeschung@mvv-muenchen.de.

(4) The German version of the General Terms and Conditions and the Privacy Policy shall apply. In the event of any discrepancy between the German and English versions, the German version shall take precedence.

 

2. Data required for the use of the InOut system

(1) In order to perform the functions of the InOut system as set out in clause 1(2), the InOut system or the MVV app requires access to the following data and services:

  • Location data (GPS): Following the customer’s explicit authorisation, the InOut system accesses the location data (GPS) of the mobile device in order to determine the customer’s current location, the starting point, transfer points and destination stops, as well as the customer’s journey route and duration.
  • Mobile internet: The InOut system requires internet access to exchange necessary information between the app and the back-end system (e.g. for the purposes of journey recognition and fare calculation).
  • Motion sensors (motion data): The InOut system utilises the device’s motion sensors to improve journey recognition. This makes it possible, for example, to distinguish whether the customer is travelling on public transport or walking.
  • Wi-Fi and Bluetooth: To improve location accuracy for determining the stops relevant for billing during the customer’s journey, the InOut system can process existing Wi-Fi or Bluetooth signals. Bluetooth signals are generated by so-called Bluetooth beacons. This can significantly improve location tracking, for example in underground stops or on board vehicles.

(2) The data mentioned above is required by the InOut system to ensure the public transport journey is correctly identified. No personal movement profiles are created in the process. The recording of the journey only begins once the CheckIn has been successfully completed. The MVV app does not need to be open continuously for the journey to be recorded. The recording ends when the customer successfully completes the CheckOut. The system services mentioned in paragraph (1) above can be deactivated at any time outside an active InOut journey via the settings on the mobile device; however, they must be reactivated before starting a new journey with MVVswipe. The customer will receive a corresponding system message. The customer explicitly consents to the InOut system or the MVV app accessing their personal data (see clauses 3, 4 and 5), including the data mentioned above (see paragraph 2) – including for the purpose of resolving customer enquiries. Otherwise, it will not be possible to use the InOut function.

The MVV app is available via the relevant app stores. For data protection within these stores or in areas directly related to them, please refer to their privacy policies:

 

3. Registration for MVVswipe

(1) To use the InOut system, the customer must register. Upon registration, the customer must agree to the General Terms and Conditions (GTC) and the privacy policy relating to the InOut function, as well as the MVV’s Conditions of Carriage and Fare Regulations.

(2) The following data is collected for registration:

  • First name and surname
  • Date of birth
  • Address or billing address
  • Email address
  • Password
  • Valid payment method (SEPA direct debit, credit card, PayPal, Apple Pay or Google Pay)

(3) Data processing is carried out on the basis of Article 6(1), first sentence, point (b) of the GDPR. 

(4) During the registration process, the customer may voluntarily consent to the use of personal data for market research purposes (optional tick box; see section 7).

 

4. Use of the InOut system and price calculation

(1) The basic structure of the InOut system was explained in Section 1(1). In order to track the customer’s journey continuously and subsequently calculate the fare correctly, the InOut system must access and process the following data (see also clause 1(2)):

  • Location data (GPS)
  • Mobile internet
  • Motion sensors
  • Wi-Fi and Bluetooth
  • Individual ticket settings before the journey begins (passengers)

(2) Each time the service is used, a journey authorisation is purchased by the customer, assigned to the relevant customer account and displayed there. In this context, the following data is processed:

  • First name and surname
  • Date of birth
  • Validity of the journey authorisation, including time period and ID
  • Date and time
  • Location data for the entire journey
  • Passengers, daily limit
  • Device information (operating software (version), terminal model and app version)

(3) The journey route, determined on the basis of the journey data, comprises the first boarding stop after check-in, the stops passed through and transfer stops, the final alighting stop before check-out, as well as the modes of transport and routes used. The fare is calculated by assigning the calculated journey route to the applicable fare regulations in the MVV. When calculating the fare, the data provided by the customer during registration and the payment methods on file are used (see clauses 3 and 5).

(4) Data processing is carried out on the basis of Article 6(1), first sentence, point (b) of the GDPR. 

 

5. Billing via LOGPAY

(1) The personal data provided by the customer (first name and surname, date of birth, address, email address, telephone number where applicable, and details of their respective purchases) and any changes thereto are passed on to LOGPAY Financial Services GmbH for the purpose of the sale and assignment of MVV GmbH’s claims against the customer arising in connection with their purchase, hire or booking. This is carried out on the basis of Article 6(1), first sentence, point (f) of the GDPR. The legitimate interest on the part of MVV GmbH lies in the outsourcing of payment processing and receivables management. The legitimate interest on the part of LOGPAY Financial Services GmbH lies in the processing of data for the purposes of payment processing, receivables management, assessing the validity of payment methods and preventing payment defaults.

(2) The offer to conclude a contract of sale for a ticket will only be accepted if LOGPAY Financial Services GmbH acquires the resulting claim arising from the ticket sale. If LOGPAY Financial Services GmbH refuses to acquire the claim, the customer’s offer to conclude a contract of sale will be rejected.

(3) The customer may object to the transfer of this data to LOGPAY Financial Services GmbH at any time; however, in that case, it will no longer be possible to place an order via the electronic sales channel.

(4) The customer may access LOGPAY Financial Services’ data protection information at documents.logpay.de/de/datenschutzinformationen.pdf.

(5) In addition, MVV GmbH processes the customer’s personal data which MVV GmbH receives from LOGPAY Financial Services GmbH (information regarding the decision as to whether or not the claim will be acquired).

(6) Where personal data is processed for the performance of tasks carried out in the public interest (Article 6(1), first sentence, point (e) of the GDPR) or for the purposes of legitimate interests (Article 6(1), first sentence, point (f) of the GDPR), the customer may object to the processing of their personal data at any time with effect for the future. In the event of an objection, MVV GmbH must cease any further processing of the customer’s data for the aforementioned purposes, unless

  • there are compelling legitimate grounds for processing which override the interests, rights and freedoms of the customer, or
  • the processing is necessary for the establishment, exercise or defence of legal claims.

(7) As part of the registration process for the SEPA Direct Debit payment method and/or in the event of changes to the customer’s details in connection with the switch to the SEPA Direct Debit payment method, the financial services company LOGPAY Financial Services GmbH may carry out a check of the customer’s details and creditworthiness. This is carried out by cross-referencing the customer’s personal data against the database of SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden.

(8) In order to verify the credit card details provided by the customer and to process payments via the credit card scheme, the financial services company LOGPAY Financial Services GmbH will pass on the credit card and payment details to a credit card acquirer. 

(9) In the event that the customer fails to meet their payment obligations, their personal data will be passed on to a debt collection agency for the purpose of recovering the debts (e.g. through payment reminders/reminders) and the enforcement of claims (for example, as part of court-ordered debt collection proceedings or in cooperation with a law firm in the event of legal enforcement through court proceedings) to a debt collection agency.

 

6. Customer Support

(1) Any queries or complaints raised by the customer regarding the accuracy of journey recording will be handled and processed on behalf of MVV GmbH by the customer support team of the technical service provider MENTZ. All other enquiries (e.g. regarding fares or registration) are handled and processed by MVV GmbH’s customer support team. Customer enquiries sent directly via the MVV app are forwarded, depending on the subject line provided, either directly to MENTZ (journey and stop recording) or to MVV GmbH. General enquiries sent by email are first reviewed by MVV GmbH and, where appropriate, forwarded to MENTZ.

(2) MVV GmbH may use and store the personal data of customers registered with it for the purposes of customer service and may also pass this data on to its service providers to clarify any queries; it will not be used for advertising or other purposes without the customer’s prior express consent.

(3) The processing of this personal data is based on the legal basis of Article 6(1)(b) of the GDPR, provided that the communication relates to the completion of a ticket purchase. Processing for other communications is carried out on the basis of a legitimate interest (on the part of MVV GmbH) in accordance with Article 6(1)(f) of the GDPR, namely to handle the customer’s contact enquiry in a manner appropriate to their needs. An InOut ticket cannot be used without providing the data.

 

7. Market research

(1) The InOut system implements a new technology for recording journey data for the purpose of ex-post fare calculation. To ensure the continuous improvement and further development of the system, as well as its user-friendliness, MVV GmbH may carry out (or commission) market analyses (market research). To this end, the customer may be sent a request to take part in market research via the app or via the email address voluntarily provided during registration for market research purposes. Participation in this is voluntary. By taking part in the market research, the following information is transmitted to the market research organisation:

  • First name and surname
  • Email address
  • Age
  • Postcode

Consent may be withdrawn at any time in writing and will apply prospectively. The processing of this personal data is based on the legal basis of Article 6(1)(a) of the GDPR, namely the customer’s consent.

 

8. Journey history

(1) The journey history is created in the back-end system. In order to display the history of journeys made by the customer in the MVV app, some personal data is stored locally within the app. This includes: the history of journeys made and the resulting tickets, the user’s settings, and certain states of the MVV app.

(2) The processing of the locally stored data is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR, namely to provide the customer with a functional and user-friendly app.

 

9. Checking InOut journeys

(1) To ensure revenue collection, the transport operators participating in the network may, where necessary during ticket inspections, view the ticket data, the information stored in the barcode (first name and surname (masked where applicable, depending on the inspection device), as well as date of birth and, where applicable, title, first name and surname of the ticket holder) and the ticket presented by the customer. This is carried out on the basis of Article 6(1)(f) of the GDPR. The legitimate interest of MVV GmbH and the transport operators carrying out ticket inspections lies in safeguarding fare revenue. Personal data is not stored in the inspection device, but is merely displayed. In the event of a dispute, personal data may be forwarded to the transport operator that carried out the inspection for further processing. An InOut ticket cannot be used unless the data is provided.

 

10. Storage period and retention periods

(1) The personal data stored by MVV GmbH or by service providers shall be deleted once it is no longer required for the purpose for which it was collected (the sale of InOut tickets) and the statutory retention obligations (a maximum of ten years in accordance with Section 147(3) of the German Fiscal Code (AO)) no longer preclude this. The data associated with a registered customer account that has been inactive for two years will be deleted from the relevant register after two years at the latest. Data relating to active customer accounts will be deleted from the relevant register ten years after the booking date. Order data is to be treated as a booking receipt and will be retained in accordance with the statutory retention periods; it will then be deleted. Furthermore, data will be deleted at the customer’s express request by email to kundendialog-swipe@mvv-muenchen.de, provided that no statutory retention obligations prevent this. In this case, deletion will take place within 30 days at the latest. 

(2) Information relevant to technical testing and analysis, i.e. operating system (version), device model and app version, is stored temporarily and automatically deleted after six months.

 

11. Disclosure of data

(1) In the course of using the service and fulfilling the contract, it is generally necessary to engage data processors. These include:

  • Technical service providers for the operation and maintenance of IT systems and server infrastructure, e.g. for the InOut system
  • Customer support
  • Payment service providers
  • Other parties involved in the performance of the contract
  • External service providers for market research purposes (see clause 7)
  • Public authorities or other state bodies, where MVV GmbH is legally obliged to do so

All data processors and external service providers have been or will be carefully selected and are subject to strict data protection agreements. Compliance with these is ensured through contractual provisions, technical and organisational measures, and supplementary controls.

Where necessary for the aforementioned purposes, MVV GmbH also transfers customer data to recipients outside the European Economic Area (EEA), provided that

  • it is necessary for the performance of a contract,
  • statutory requirements must be complied with, or
  • the customer has given their consent to MVV GmbH.

In addition, MVV GmbH transfers the customer’s personal data to the technical service providers engaged by MVV GmbH, which support MVV GmbH in its operations and maintenance and are based in the USA. Although the customer’s personal data is stored exclusively on servers within the EU/EEA, However, it cannot be entirely ruled out that the customer’s personal data may be transferred to the USA (for example, in the case of support enquiries). To this end, MVV GmbH and the technical service providers it engages have taken appropriate measures to ensure an adequate level of protection for the customer’s personal data. In addition to the conclusion of the European Commission’s Standard Contractual Clauses, this includes the implementation of additional technical, organisational and contractual safeguards. The customer’s other personal data is not transferred to countries outside the EEA.

 

12. Further information on data protection

(1) Where the processing of personal data is based on the customer’s consent, the customer has the right to withdraw that consent at any time, without this affecting the lawfulness of the processing carried out on the basis of the consent prior to its withdrawal, in accordance with the statutory provisions on data protection (Art. 7 GDPR, Section 51 of the BDSG). 

In the event that personal data is processed for the performance of tasks carried out in the public interest (Article 6(1), first sentence, point (e) of the GDPR) or for the purposes of legitimate interests (Article 6(1), first sentence, point (f) of the GDPR), the customer may object to the processing of their personal data at any time with effect for the future. In the event of an objection, MVV GmbH must cease any further processing of the data in question for the aforementioned purposes, unless

  • there are compelling legitimate grounds for processing which override the interests, rights and freedoms of the customer, or
  • the processing is necessary for the establishment, exercise or defence of legal claims.

There is a right to access the personal data in question (Art. 15 GDPR) as well as a right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR) or restriction of processing (Art. 18 GDPR) or a right to object to the processing (Art. 21 GDPR), as well as a right to data portability (Art. 20 GDPR) in accordance with the statutory provisions on data protection. The customer may exercise these rights by sending an email to kundendialog-swipe@mvv-muenchen.de.

(2) In addition to the aforementioned processing purposes, the customer’s personal data will also be processed for the following purposes:

  • To comply with MVV GmbH’s statutory retention obligations or data protection obligations. This processing is based on the legal basis of Article 6(1)(c) of the GDPR.
  • To exercise any legal claims or to defend MVV GmbH against claims. This processing is based on the legal basis of Article 6(1)(f) of the GDPR.
  • To respond to and comply with requests from public authorities. This processing is based on the legal basis of Article 6(1)(c) of the GDPR.

(3) Pursuant to Article 77 of the GDPR, the customer has the right to lodge a complaint with a supervisory authority, without prejudice to any other administrative or judicial remedy, in particular in the Member State of their place of residence, their place of work or the place where the alleged infringement occurred, if they consider that the processing of personal data relating to them infringes the General Data Protection Regulation.

(4) The competent supervisory authority for MVV GmbH is the Bavarian State Commissioner for Data Protection, PO Box 22 12 19, 80502 Munich, www.datenschutz-bayern.de.

Prior registration is required to use the “OpenService” service. Personal data will only be stored and processed once you have successfully registered and on the basis of your explicit consent.

As part of the registration process, at least the following personal data is collected:

  • First name
  • Surname
  • Email address
  • Telephone number
  • Address (street, house number, postcode, town)

This data is processed solely for the purpose of providing and operating the OpenService offering, as well as for communication relating to the use of the service.

The legal basis for the processing of your personal data is your consent in accordance with Article 6(1)(a) of the GDPR. Your consent applies prospectively and may be withdrawn at any time.

The provision of the aforementioned data is necessary for the use of the service. Without this information, OpenService cannot be used.

You may at any time delete your account – and thereby all personal data stored about you – yourself via the login area. In this case, your personal data will be deleted immediately, provided that there are no statutory retention obligations to the contrary.

This privacy policy applies to the following social media channels


https://www.facebook.com/deinmvv

https://www.instagram.com/dein.mvv/

https://www.linkedin.com/company/muenchner-verkehrsverbund-mvv

https://www.youtube.com/@deinMVV


Data processing by social networks


We maintain publicly accessible profiles on social media platforms. You can find a list of the specific social media platforms we use below.
Social media platforms such as Facebook, X, etc. can generally analyse your user behaviour in detail when you visit their website or a website featuring integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data-processing operations relevant to data protection. Specifically:

If you are logged into your social media account and visit our social media presence, the operator of the social media portal may associate this visit with your user account. However, your personal data may also be collected even if you are not logged in or do not have an account with the relevant social media platform. In this case, data is collected, for example, via cookies stored on your device or by recording your IP address. 

Using the data collected in this way, the operators of the social media platforms can create user profiles that record your preferences and interests. In this way, interest-based advertising may be displayed to you both on and off the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are logged in or have previously been logged in. Please also note that we are not able to track all data processing activities on the social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For details, please refer to the terms of use and privacy policies of the respective social media platforms.

 

Legal basis


Our social media presence is intended to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analysis processes initiated by the social networks may be based on different legal grounds, which must be specified by the operators of the social networks (e.g. consent within the meaning of Article 6(1)(a) of the GDPR). 

 

Data controller and exercising your rights


When you visit one of our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both against us and against the operator of the relevant social media platform (e.g. against Facebook). Please note that, despite our joint responsibility with the social media platform operators, we do not have full control over the data processing operations carried out by the social media platforms. Our options depend largely on the corporate policy of the respective provider. 

 

Retention period


Data collected directly by us via our social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected. We have no influence over the retention period of your data stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below). 

 

Your rights


You have the right at any time to obtain, free of charge, information about the origin, recipients and purpose of your stored personal data. You also have the right to object, the right to data portability and the right to lodge a complaint with the relevant supervisory authority. Furthermore, you may request the rectification, restriction, erasure and, under certain circumstances, the restriction of the processing of your personal data. 

 

Social media platforms in detail


Facebook

We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries. 

We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we or Meta are responsible for when you visit our Facebook page. You can view this agreement via the following link:
https://www.facebook.com/legal/terms/page_controller_addendum

You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

Please refer to Facebook’s privacy policy for further details:
https://www.facebook.com/about/privacy/

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: https://www.dataprivacyframework.gov/participant/4452 

 

Instagram


We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

For details on how Instagram handles your personal data, please refer to Instagram’s Privacy Policy: https://privacycenter.instagram.com/policy/.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: https://www.dataprivacyframework.gov/participant/4452 

 

LinkedIn


We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.

For details on how LinkedIn handles your personal data, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: https://www.dataprivacyframework.gov/participant/5448 

 

YouTube


We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For details on how they handle your personal data, please refer to YouTube’s privacy policy:
https://policies.google.com/privacy?hl=de.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every organisation certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: Data Privacy Framework
 

Data Controller and Data Protection Officer

The data controller within the meaning of data protection law is MVV GmbH, represented by its management. It can be contacted by email at kundendialog@mvv-muenchen.de or by post at MVV GmbH, Management, Thierschstraße 2, 80538 Munich.

MVV GmbH has an external Data Protection Officer. You can contact them by email at Datenschutz@mvv-muenchen.de or by post at DSBOK, Data Protection Officer for MVV GmbH, Untergasse 2, 65474 Bischofsheim.

Data erasure

If you wish to have your personal data erased (e.g. in connection with mobile phone/online ticketing, registration for a call-a-taxi service, etc.) or have any questions regarding your personal data processed by us, please send an email to datenloeschung@mvv-muenchen.de. If possible, please specify in your enquiry the service (e.g. ticket shop, RufTaxi, newsletter, etc.) with which you have registered.

Right to lodge a complaint

In accordance with Article 77 of the GDPR, without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your usual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the General Data Protection Regulation.

The competent supervisory authority for MVV GmbH is the Bavarian State Commissioner for Data Protection, PO Box 22 12 19, 80502 Munich, www.datenschutz-bayern.de.

 

Munich, October 2025