Privacy Policy

Privacy information pursuant to Art. 13 and Art. 14 GDPR for the website and the research project “Datenspende”

This English text is a convenience translation. The German version is the authoritative and legally binding version of this privacy policy; in case of doubt or discrepancies, the German text prevails.

Protecting your personal data is important to us. Below we explain which personal data we process in connection with this website (Part A) and in the context of the voluntary donation of energy data for the research project “Datenspende” (Part B), for which purposes and on which legal basis, and which rights you have (Part C).

1. Controller

The controller within the meaning of the GDPR is the:

Rector of RWTH Aachen University
Templergraben 55, 52062 Aachen, Germany
E-mail: rektorat@rwth-aachen.de

Responsible for the content of this website and the research project “Datenspende”:

RWTH Aachen University
Chair of Communication and Distributed Systems (COMSYS, Informatik 4)
Head: Prof. Dr.-Ing. Klaus Wehrle
Ahornstraße 55, 52074 Aachen, Germany
E-mail: datenspende@comsys.rwth-aachen.de

Project lead / contact person: Johannes Lohmöller, COMSYS – Informatik 4, lohmoeller@comsys.rwth-aachen.de, +49 241 80 21421

The research project “Datenspende” is part of the ERC-funded project SAFEr Grid (ERC Synergy Grant, EU Horizon Europe, grant no. 101166783).

2. Data Protection Officer

Data Protection Office (Stabsstelle Datenschutz) of RWTH Aachen University
Templergraben 83, 52062 Aachen, Germany
Phone: +49 241 80 94114, e-mail: dsb@rwth-aachen.de

Part A – This Website

3. Provision of the website and log files

This is a static website (built with Hugo) hosted within the infrastructure of RWTH Aachen University in Germany. Each access is temporarily recorded in server log files, which may include: date and time of access, IP address, requested URL and file, transferred data volume, success status, browser type and version (user agent), and operating system.

Log data is processed to operate the website properly (detecting and fixing faults) and for technical security, in particular protection against cyber attacks. Legal basis: Art. 6(1)(e), (3) GDPR in conjunction with § 3(1) DSG NRW and § 3 HG NRW, as well as Art. 6(1)(f), Art. 32(1) GDPR. Logs are deleted when no longer required, generally after at most seven days; where kept longer, IP addresses are deleted or obfuscated.

4. Cookies and storage on your device

On this website we set no cookies and use no tracking or analytics methods of any kind.

The data portal referred to in Section 6 is a web application. To ensure its functionality, it stores information in the local storage of the browser you use. No cookies are set there either. The following data is stored:

EntryPurposeStorage period
safergrid.tokenSession token with which the portal identifies itself to the project server after you sign inuntil sign-out
safergrid.userId, safergrid.householdIdIdentifiers of your account and your household, which the portal uses to retrieve the corresponding datauntil sign-out
safergrid.username, safergrid.emailDisplay of your account details in the interface, the e-mail address only if you have provided oneuntil sign-out
safergrid.themeAppearance you selected (light or dark)until changed by you
safergrid.localeInterface language you selecteduntil changed by you

As an installable web application (progressive web app), the portal also stores its program components in a browser cache. This keeps it usable during short interruptions of the connection.

These entries are strictly necessary for the signed-in use of the data portal. Their storage requires no consent under § 25(2) no. 2 TDDDG.

Legal basis for the processing of personal data using these storage techniques: Art. 6(1)(e), (3) GDPR in conjunction with § 3(1) DSG NRW and § 3 HG NRW, as well as Art. 6(1)(f), Art. 32(1) GDPR. Where the processing concerns the data donation, Art. 6(1)(a) GDPR applies (Part B).

The account-related entries are deleted when you sign out of the data portal. The remaining entries persist until changed by you. You can delete all entries at any time through your browser settings. Signing in again is then required.

5. No third-party services

This website embeds no third-party content (no CDNs, fonts, maps, videos, or social media plugins). No data is transferred to third parties when you visit it.

This website links to an external data portal operated within the same research project. Further personal data is only processed there once you follow the link and sign in. That processing is covered by Part B and the notices provided in the portal itself. For storage on your device, see Section 4.

7. Contacting us

If you contact COMSYS by e-mail or post, the data you voluntarily provide is processed solely to handle your request and deleted when no longer required.

Part B – The Voluntary Data Donation (Research Project)

8. Description of the research project

In the research project “Datenspende”, the COMSYS chair at RWTH Aachen University researches the power grids of the future. For this purpose, we collect electrical time-series data (measurements of electricity consumption and production) donated voluntarily by citizens from their smart home platforms, at the level of individual devices and of the household. The data is used to simulate and research future energy grids. Participation is entirely voluntary; not participating has no disadvantages for you.

9. How the donation works and purposes of processing

  1. You install our integration in your smart home platform (currently Home Assistant; support for openHAB, OpenEMS, evcc, and openWB is planned).
  2. Before any transmission, you review which entities/devices to release and give targeted consent. You stay in control of what you share.
  3. The selected time series are transmitted to servers operated by COMSYS within RWTH infrastructure in Germany.
  4. You receive a pseudonymous identifier. Through a data portal, you can view your own data, label it, delete it, and revoke your consent.

Purposes: answering the research questions on future power grids; analyzing the donated energy time series; publishing anonymized datasets as an open research resource; providing pseudonymized data to the SAFEr Grid consortium partners and, where applicable, to verified researchers under controlled access, in each case under data use agreements (see Section 12); using exclusively anonymized data and examples derived from it in teaching; and contacting you about your donation (e.g. questions about your devices, major project changes) if you have voluntarily provided an e-mail address and separately consented to this.

10. Categories of personal data

  • Energy time-series data: consumption and production measurements at device and household level (power, energy, and where available voltage and current), with timestamps;
  • Metadata on released entities/devices (entity names from your smart home platform, vendor and model details (nameplate), device type, labels you assign);
  • Pseudonymous participation identifier and technical data required for transmission and portal access (e.g. credentials, type of smart home platform); the time and chosen scope of your consent are also recorded electronically;
  • Voluntary household details, if you provide them: postcode, country, number of people living in the household, the living area in square metres, a freely chosen household name, and the construction year of the building (if known; entered in the data portal). These are optional and serve the scientific contextualization of the measurements;
  • Optionally an e-mail address, if you have consented to being contacted. It is stored linked to your pseudonymous identifier so we can reach you about your donation; it is never published, not shared with third parties, and not used for any other purpose. Note that in this case your donation becomes linkable to you via the e-mail address; the address is stored separately from the measurement data and can be removed at any time.

Note on identifiability: household energy data can constitute personal data, since consumption patterns may allow inferences about daily routines or presence at home. We therefore treat all donated data as personal data. Special categories of data (Art. 9 GDPR) are not deliberately collected; residual risks are minimized through pseudonymization and anonymization.

11. Data minimization, pseudonymization, and safeguards

We process only the data required for the stated research purposes (Art. 5(1)(c) GDPR); you decide which entities/devices to release. Your donation is processed under a pseudonymous identifier from the moment of transmission. Data is stored on RWTH systems in Germany and protected by appropriate technical and organizational measures (Art. 32 GDPR), in particular: TLS encryption for all transmissions; access restricted to project staff who need it for their tasks (need-to-know, personal accounts); separate, specially protected storage of optional contact data and the pseudonym mapping; regular static vulnerability analysis of the deployed software; operation exclusively within RWTH infrastructure in Germany; and strictly one-way communication (the integration only sends measurements; there is no channel back into your smart home).

12. Recipients and publication

The donated data is processed by project staff of the COMSYS chair. Anonymized time-series datasets are published and continuously updated as an open research resource. The measurements themselves are not summarized, because their resolution is required for the research purposes. Anonymization is applied to the accompanying metadata.

All metadata, in particular postcode, country, number of people in the household, living area, construction year of the building, device type, and vendor and model details, is treated as quasi-identifiers. Before every publication it is generalized until every combination that occurs is shared by a defined minimum number of households (k-anonymity). Pseudonymous identifiers and self-assigned device names are removed. Through the published metadata, attribution to individual persons or households is no longer possible. The procedure and the chosen parameters are documented together with the dataset.

Residual risk: the time course of consumption and generation still contains patterns that reveal habits (see Section 10). Removing them would require a coarsening that would considerably limit the scientific value of the data for the stated research purposes. Attributing a published load profile to a particular household would require a third party to already know that household’s electricity consumption in detail. A residual risk of recognition from the load profile itself cannot be fully excluded.

Finer-grained, pseudonymized data (without contact data, credentials, or the pseudonym mapping) may be made available to the partners of the SAFEr Grid consortium (two further RWTH Aachen institutes and Aalborg University, Denmark) for the joint research purposes, exclusively under data use agreements with purpose limitation and no right of onward transfer; transfers take place only within the EU. In addition, we plan to make pseudonymized data available to verified researchers under a controlled-access procedure and data use agreements. [TODO: specify conditions and application process once defined.] No other disclosure to third parties takes place.

13. Transfers to third countries

Your personal data is not transferred to countries outside the EU/EEA or to international organizations. Processing and storage take place exclusively on RWTH infrastructure in Germany.

Processing in connection with the voluntary data donation is based on your consent pursuant to Art. 6(1)(a) GDPR. You give consent informed and without obligation by selecting and confirming the entities/devices to be transmitted during setup or in the data portal.

15. Storage period and deletion

Your pseudonymized personal data is processed as long as required for the research purposes, at the longest until you revoke your consent. Upon revocation, data linked to your pseudonymous identifier that has not yet been anonymized is deleted or blocked. You can also delete your data yourself in the data portal at any time. Identifying data is deleted, and research data anonymized, as soon as the research purpose permits (§ 17(3) DSG NRW). Pseudonymized raw data is retained, in line with the principles of good scientific practice (including the DFG guidelines), for up to ten years after the end of the project and then deleted or fully anonymized. The mapping between the pseudonymous identifier and optional contact data is deleted as soon as it is no longer required, at the latest at the end of this retention period.

16. Voluntariness, revocation, and its limits

Participation is voluntary. You can revoke your consent at any time with effect for the future, without affecting the lawfulness of processing before revocation, via the data portal or by informal message to the project contact address. Limits of revocation: once data has been anonymized and published, removal from the already published datasets is technically no longer possible, because this data can no longer be attributed to any person. Revocation therefore stops all future processing of your identifiable data and its inclusion in future publications.

Part C – Your Rights

17. Rights of the data subject

You have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and revocation of consent with effect for the future (Art. 7(3) GDPR). Under § 17(5) DSG NRW, some of these rights may be restricted where their exercise would make achieving the research purposes impossible or seriously impair them. Rights can no longer be exercised regarding anonymized data, which has no link to your person. To exercise your rights, contact: datenspende@comsys.rwth-aachen.de or the RWTH Data Protection Officer (dsb@rwth-aachen.de).

18. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Competent for RWTH Aachen University:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de


Version: 21 July 2026