Advisory policy
Data protection & privacy
GDPR-aligned handling of client data, mandate materials, and communications.
Updated September 2025
Data protection & privacy
GDPR-aligned handling of client data, mandate materials, and communications.
Data controller
Consultinghouse GWB is the data controller for personal data processed in connection with advisory mandates, business relationships, and compliance obligations.
This policy supplements our website Privacy Policy and applies specifically to client and counterparty data handled in the course of professional advisory services.
Data protection contact (Datenschutzbeauftragter): [email protected] (Consultinghouse GWB, Maximilianstraße 13, 80539 München, Germany).
Data processing
We process personal data lawfully under the GDPR — including contract performance, legitimate interests in operating our advisory business, legal obligations, and consent where required.
- Contact and identity data for client representatives and project stakeholders
- Professional information required for due diligence, KYC, and mandate delivery
- Communications, meeting records, and document metadata necessary for advisory work
- Technical logs for secure collaboration platforms used in mandates
Retention periods
Data is retained only as long as necessary for the mandate, statutory limitation periods, regulatory record-keeping, or legitimate business needs such as dispute resolution.
Typical advisory records are retained for a minimum of six years after mandate completion unless a longer period is required by law or contract. Secure deletion or anonymisation follows approved schedules.
Third-party processors
We use vetted processors for cloud storage, communications, and professional services. Data processing agreements are in place requiring GDPR-equivalent protections, sub-processor controls, and breach notification.
Cross-border transfers outside the EEA rely on Standard Contractual Clauses, adequacy decisions, or other approved mechanisms. Clients are informed where mandate delivery requires transfer to specific jurisdictions.
Client rights
Data subjects may request access, rectification, erasure, restriction, portability, or objection in accordance with GDPR. Requests are handled within statutory timelines via [email protected].
Clients may also contact the Bavarian Data Protection Authority (BayLDA) regarding unresolved concerns. Security incidents affecting personal data are assessed and reported as required by Articles 33 and 34 GDPR.