Logo Allianz Arena

Privacy policy

Privacy policy

This website is operated by FC Bayern München AG. The protection of your personally identifiable data is very important to us. In this privacy policy, you will find information about the handling of your personally identifiable data when you visit the FC Bayern Munich website.

1. Controller and data protection officer

The party responsible for the processing of personally identifiable data on this website (the controller) is:

FC Bayern München AG, Säbener Straße 51-57, D-81547 Munich, Germany
Phone: +49 89 699 31-0
Fax: +49 89 64 41 65

Email: service@fcbayern.com

If you have any questions regarding data protection, you can also contact our data protection officer at datenschutz@fcbayern.com at any time.

2. Collection and use of non-personally identifiable data when using the site

If you use this website without transmitting data to us in any other way (e.g. by registration), we only collect technically necessary data that is automatically transmitted to our server by your browser (e.g. browser type/version, operating system used, referrer URL, pages accessed, length of visit, IP address, date and time of request) or that is required by technically necessary or functional cookies.

As far as personally identifiable data is concerned, we process this on the basis of our legitimate interest in providing you with a functioning, secure website (Art. 6(1)(f) GDPR). There is no merging of data with other data sources. We reserve the right to check this data retrospectively if we become aware of specific indications of illegal use.

More information about cookies and similar technologies can be found here.

3. Collection and use of personally identifiable data

a. Registration (myFCB)

When you register on myFCB, we process the following personally identifiable data relating to you: Place of residence, language of communication, email, password for your login and other information that you voluntarily provide to us, e.g. name, date of birth, information about your favourite player and newsletter preferences.

When you use myFCB, we also process the following information which you make available to us in the registered area at myFCB or which arises during your use. This includes, for example, information about your address, telephone numbers or account or credit card information, information about your membership with FC Bayern München eV, the Kids Club, the Fan Club, the purchase of tickets or products in the Fan Shop, subscriptions to FC Bayern TV as well as top-ups of your ArenaCard. You can always view and change the specific data under myFCB.

We process this data in order to offer you the myFCB area, in particular to provide you with exclusive and personalised content, easy participation in competitions and easy access to offers and services (Art. 6(1)(b) GDPR).

We process your personally identifiable data until you have deleted your myFCB account and as long as it is necessary for the fulfilment of mutual obligations in connection with myFCB. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

For IT security purposes, we also process technical information regarding your use of myFCB, such as your IP address and the time you logged on to myFCB. We process this information on the basis of our legitimate interest. Our legitimate interest is to provide you a secure website (Art. 6(1)(f) GDPR). We delete this information 18 months after the respective registration on myFCB.

b. Ticket/fan article purchase and other contractual relationships

We only process personally identifiable data (e.g. name, delivery and billing address, date of birth, email, content of an order, price) if you have provided it to us in the context of a registration, order of products and services or enquiries, and only insofar as this is necessary for the establishment, execution or termination of the legal relationship.

We process health data that you provide to us (e.g. your certificate of disability) only with your express consent (Art. 6(1)(a) GDPR) and only for the purposes stated in your respective consent declaration (e.g. provision of discounts when purchasing tickets). We will provide you with further information when we obtain this consent from you. To purchase certain tickets (e.g. arena tours) you will be redirected to the offers of our partners. Please also note the corresponding data protection information of these partner websites.

We process your personally identifiable data only as long as it is necessary for the fulfilment of the contract and for the fulfilment of mutual obligations. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

c. Presentation of content on the website

In order to display the website and its essential content such as videos, images or social media posts in your Internet browser, we use various service providers and technologies. In individual cases, it is possible that we process some of your personally identifiable data for this purpose. We do this to deliver the content to your device, to thank you for participating in surveys or to find hashtags from fans' social media posts about FC Bayern on the Internet and to display the respective posts on the website. Our legal basis for processing this data is Art. 6(1)(b) GDPR (contract fulfilment). In this context, your personally identifiable data will only be processed as long as it is necessary for the presentation of the contents.

  • Picture / graphic delivery

If necessary, we process information about your browser, operating system and the URL you previously visited in order to deliver images and graphics optimally to your end device and to ensure the stability of the website. The legal basis for the processing is Art. 6(1)(b) GDPR (contract fulfilment). Images or graphics could otherwise not be displayed on the website. We process your personally identifiable data for this purpose only as long as it is necessary to deliver the images and graphics to you.

  • Surveys

We do not normally process any of your personally identifiable data in the course of surveys on our website. In some cases, such as when you receive a discount code from us in connection with a survey, we may process your email address, name and other information that you provide to us or that we share with you in the course of the survey. We process this personally identifiable data to provide you with the discount code. In case of further data processing, we will inform you separately in advance. The legal basis for the processing is Art. 6(1)(b) GDPR (contract fulfilment). We process your personally identifiable data only as long as it is necessary for the fulfilment of the contract and for the fulfilment of mutual obligations. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

  • Social media hashtags

We process certain social media posts posted by you with an "FC Bayern Munich" hashtag (e.g. #fcb) on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Our legitimate interest is to display and share posts from fans with an FC Bayern Munich hashtag on our website with other fans.

If you or other persons are depicted in your posts, we process the posts only with your prior consent (Art. 6(1)(a) GDPR), which you give by posting with a corresponding hashtag. You can revoke your consent at any time with effect for the future by sending us a message. The legality of the data processing carried out by us before revocation remains unaffected.

We process your personal data only until the above-mentioned purposes are fulfilled.  In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

Further information on the processing of your personal data in this context, in particular also by social networks, can be found below in section 5 b).

  • Cookies and videos

Information on the cookies and similar technologies used by us on the website can be found under section 4 below and here. For more information on embedding videos on our website, see section 6 below.

d. Newsletter service

If you wish, we can process your personally identifiable data to provide you with information on current events and attractive offers from FC Bayern München (FC Bayern München AG, FC Bayern München Merchandising AG & Co. KG, FC Bayern München Service AG & Co. KG, FC Bayern Munich LLC, FC Bayern Munich Shanghai Co. Ltd, FC Bayern Tours GmbH, Allianz Arena München Stadion GmbH, FC Bayern München eV, FC Bayern München Basketball GmbH) and its official partners, which you can find on the website. If you subscribe to the newsletter, we process your email address and information to send the newsletter to you. 

Subscription to the newsletter is only possible with your consent. The legal basis for the processing is Art. 6(1)(a) GDPR. You can unsubscribe from a newsletter at any time via the link at the end of the newsletter or directly via your user profile in myFCB.

We process your personally identifiable data for these purposes as long as you show an interest in our newsletters or until you revoke your consent. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

e. Product recommendations by email

As a customer of our online offer, you will regularly receive product recommendations from us by email. You will receive these product recommendations from us regardless of whether you have subscribed to a newsletter or not. We will use the email address you provide during the purchase process to promote our own goods and/or services similar to those you have purchased from us based on an order you have already placed.

The processing of your personally identifiable data for this purpose takes place on the basis of our legitimate interest in direct advertising to existing customers (Art. 6(1)(f) GDPR). You may object to this product recommendation at any time by writing to FC Bayern München AG, Säbener Str. 51-57, 81547 Munich, Germany, using the link at the end of this product recommendation or by writing to datenschutz@fcbayern.com.

We process your personally identifiable data for this purpose as long as you show an interest in our products or until you object to receiving product recommendations. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

f. Flyers, catalogues and all advertising delivered by post

We process your name, your address data and your interest in FC Bayern for marketing purposes if we are convinced that we have attractive offers ready for you.

The processing of your personally identifiable data for this purpose takes place on the basis of our legitimate interest in advertising by post (Art. 6(1)(f) GDPR). You can object to the receipt of such direct advertising at any time by sending a written message to FC Bayern München AG, Säbener Str. 51-57, 81547 Munich or by email to service@fcbayern.comUpon receipt of your objection, we will immediately cease sending you marketing information and will not pass the data on to third parties for marketing purposes.

We process your personally identifiable data for this purpose as long as you show an interest in our products or until you object to receiving product recommendations. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

g. Contact form

On our website you can enter personally identifiable data via a contact form. If you use the contact form, we process the data you enter in the input mask (e.g. surname, first name, email address, message, time of request and server log data).

The legal basis for the processing is Art. 6(1)(b) GDPR (contract fulfilment).

We use the data exclusively in order to process and answer your enquiry.

We only process the personally identifiable data you provide us to contact you until we have conclusively answered your enquiry. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

h. Special promotions with partners

From time to time, we conduct special promotions together with certain business partners, during which you can also take advantage of attractive offers from our partners ("special promotions"). In order to carry out these special promotions, it may be necessary for us to process your personally identifiable data and pass it on to our partners. We will inform you about the details, in particular the identity of the respective partner and the processed personally identifiable data (e.g. name, address, email address), in each case in connection with your participation in the special promotion.

The processing of your personally identifiable data, including the transmission of your personally identifiable data to the respective partner, will only take place with your consent. The legal basis for the processing is Art. 6(1)(a) GDPR (consent). Our partners then process your personally identifiable data on receipt at their own responsibility. Therefore, please also note the corresponding data protection information of our partners.

We will only process the personally identifiable data you provide you special promotions as long as this is necessary to enable you to participate in the special promotion. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

i. Accreditations

We process personal data in connection with the creation and use of authorization passes ("Accreditations") for specially authorized visitors with a specific work assignment to FCB events (e.g. matches in the Allianz Arena) or appointments ("Accredited Persons"). Registration for an Accreditation can be made by the Accredited Person or by someone else on her/his behalf (e.g. the employer). Our data processing in connection with Accreditations also includes verifying the lawful use of the Accreditation in accordance with the applicable terms and conditions as well as supplementary guidelines, processing reports of loss of the Accreditation and checking Accreditations in and out. 

We process the following data for the above-mentioned purposes, each as required in the individual case: surname, first name, photo, company, position / title, department, address, license plate number, registration data such as e-mail address and password, type of event/appointment and date, barcode on the Accreditation, check-in and check-out times, information on the loss of accreditations (place, time, circumstances) as well as violations of the applicable GTC and related guidelines. If accredited persons are authorized to bring along additional persons, we will process the full name, address, type of event/appointment and date of these persons.

The legal basis for the processing such data is Art. 6(1)(b) GDPR (contract fulfilment).

We process the personal data received from you or from authorized third parties for Accreditations only as long as this is necessary for your Accreditation. In addition, we store your personally identifiable data only for the assertion of or defence against legal claims or as long as legal obligations to store exist.

We reserve the right to conduct a background check via competent authorities as part of the Accreditation process if there are specific indications that such a check is necessary (e.g. relevant past misconduct). We conduct such procedure and transfer the corresponding data to the authority on the basis of our legitimate interests in ensuring that our events run smoothly and safely (Art. 6(1)(f) GDPR). Should we be in individual cases legally obliged to carry out such background check (Art. 6(1)(c) GDPR), we will inform you in advance about such legal obligation, unless prohibited by law.

For further data processing in connection with your visit to the stadium, the following also apply:

4. Cookies and similar technologies

a. What are cookies and similar technologies?

Some of our online services require that we use cookies or similar technologies such as pixels (collectively: "cookies"). Cookies in this sense are small files or other technologies that allow us to learn how you use the site. This enables us, among other things, to offer you our website, to improve our website and to display advertising on the site that is specifically tailored to your interests.

b. What cookies are used on this site and how do I set them with the cookie opt-in solution?

You will find a list of the cookies we use, descriptions of the purposes of the cookies and further information on the respective cookies here in our cookie consent solution.

On your first visit to our website and then at any time in our cookie opt-in solution, you can accept or decline individual cookies or all cookies separately by placing a green tick next to the cookie or removing it and then clicking on "Save settings".

The settings you make in the cookie opt-in solution are stored on your computer or mobile device. You will therefore need to do this again if you delete your browser history or use another device or Internet browser.

c. Further options for setting cookies

Below you will find information on how you can – in addition to or instead of using our cookie opt-in solution – set cookies on the website in a more general way:

Browser settings

Most browsers are set by default to accept cookies, but you can reconfigure your browser so that it rejects cookies or asks you to confirm them beforehand. The help function in the menu bar of most web browsers explains how you can prevent your browser from accepting new cookies, how you can have your browser notify you when you receive a new cookie, or how you can delete all cookies that have already been received and block the browser for all further cookies.

However, if you refuse cookies, some of our website (and the services of other websites) may not be available and so some functions cannot be used. As a rule, cookies must also be activated in order to be able to object to the use of programs/uses (by setting an objection (opt-out) cookie).

Opt-out via www.youronlinechoices.com  

You can also object to some cookies that are loaded on the website centrally at www.youronlinechoices.com. The respective cookie will then no longer collect any data about your future visits to our website. In addition, this prevents the respective cookie from being created again. Please note, however, that this objection sets an opt-out cookie on your device. You may not delete this. If you have deleted all your cookies from your Internet browser, if you are using another Internet browser or another device, you must object to the cookie again using the above link.

5. Integration of social plugins from Facebook and Twitter

On our website we provide social plugins of the social networks Facebook and Twitter. These are offers from the US companies Facebook Inc. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland;  however, personal data may also be processed by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA), and Twitter Inc. (One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; however, personal data may also be processed by Twitter Inc., 1355 Market Street, Suite 900, San Francisco CA 94103, USA). You can recognise the plugins by the respective logos of the companies. You can use these plugins to like, share or otherwise be active directly on the respective network.

Before you click on the Facebook "Share" and Twitter "Tweet" buttons, only the server address is sent to Facebook, Twitter and/or WhatsApp instead of your IP address using the data protection-friendly alternative used (Shariff button). As long as you do not click on the social plugin, you remain invisible to the operators of the respective social network.

We use this data protection-friendly alternative (Shariff button) to prevent social networks from tracking and storing Internet behaviour without the active contribution of the user. Further information on the solution used can be found under the following link: http://www.heise.de/ct/ausgabe/2014-26-Social-Media-Buttons-datenschutzkonform-nutzen-2463330.html 

By using the social plugin, you agree to the collection of your personally identifiable data by the respective network. The respective social network is responsible for the collection and processing of data by the social network, including the use of cookies and similar technologies by the social network. Specifically, information about which of our Internet pages you have visited, and your IP address are then transmitted to the social network, even if you do not have a profile with the respective network or are not logged in there at the time. If you are logged in as a member of the social networks, the network assigns the information to your personal user account.

We therefore recommend that you read the privacy policy of the respective network before using the social plugin:

  • For more information about the processing of your personally identifiable data by Twitter, please refer to the Twitter privacy policy at: https://twitter.com/de/privacy 

6. Data transfer

Insofar as we pass on your personally identifiable data specifically within the framework of the data processing described above, we have described this accordingly in the respective point in this privacy policy. In addition, we pass on your personally identifiable data in general as follows:

a. Processors

All personally identifiable data that we process within the framework of this website is processed by us or our service providers. If necessary, we transmit your personally identifiable data to external service providers, such as IT and website optimisation service providers, advertising agencies or analysis providers, in order to be able to offer you our services. We have carefully selected these service providers and concluded order processing agreements with them.

b. Third parties (so-called transfer recipients)

Contractual partners

We pass on your personally identifiable data to other controllers who process the personally identifiable data for their own purposes, insofar as this is necessary for the execution of the contract or the provision of services, e.g. within the scope of the order to the forwarding agent or the parcel delivery service or in connection with your membership in FC Bayern München e.V. or in connection with ticket purchases for FC Bayern München Basketball GmbH. Our contractual partners may use the data transmitted in this way exclusively for the purpose for which we transmitted it.

The transmission of your personally identifiable data for these purposes takes place for the fulfilment of the contract (Art. 6(1)(b) GDPR), or on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in making our business efficient.

Credit assessment

In justified cases (e.g. direct debit procedures), we exchange address and creditworthiness data with credit service companies for the purpose of a credit assessment. The service providers only receive access to such personally identifiable data as necessary for the performance of the respective activity. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).

Legal obligation or enforcement of legal claims

Otherwise, we will only disclose your personal information to third parties if and to the extent required or permitted by law, to enforce legal rights, or to investigate or prevent suspected or actual illegal activity. In these cases, we will inform you separately about the respective transmission if and to the extent legally required.

Website service provider

Some functionalities on our website require the service providers to process your personally identifiable data on their own responsibility (e.g. for social media interactions; see also the information on social plug-ins under section 5 and for some website optimisation services). Our contractual partners may use the data transmitted in this way exclusively for the purpose for which we transmitted it.

The transmission of your personally identifiable data for these purposes takes place on the basis of our legitimate interest in providing you with the respective functionality. If your consent is required for transmissions to website service providers, we will inform you separately in advance.

c. Transfer to third countries

If we transfer your personal data to processors or other controllers in countries outside the European Economic Area (EEA) (for example, in the USA), we implement the standards and security mechanisms required by law. We achieve this, for example, by transfers under an adequacy decision pursuant to Art. 45 GDPR or by agreeing on the so-called EU standard contract clauses. Please contact us as described in section 1 to learn more about the specific security mechanisms we use.

7. Secure data transfer

All personally identifiable data that you transmit to us during the surfing process in general and during the ordering process in particular are transmitted in encrypted form. We establish a so-called SSL connection for each transaction. SSL (Secure Socket Layer) is a procedure in which your data is encrypted in such a way that it cannot be read by unauthorised persons during transmission on the Internet.

You can recognise the SSL connection by the fact that the Internet address has changed from http:// to https://. In addition, the secure connection is usually indicated by a closed padlock in the status bar of your web browser.

8. Your rights

You have the following legal rights against FC Bayern München AG with regard to your personally identifiable data, provided that the respective requirements are met. You can find further information on your rights and the relevant requirements on the EU Commission's website at https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_de.

a. Right to information

As a data subject, you have the right to request confirmation as to whether we process personally identifiable data that concerns you. If this is the case, you have the right to information about this personally identifiable data, as well as other information, e.g. the processing purposes, the recipients and the planned duration of storage or the criteria for determining the duration.

b. Right to rectification and completion

As a data subject, you have the right to demand the correction of incorrect personally identifiable data without delay. Taking into account the purposes of the processing, you have the right to request the completion of incomplete personally identifiable data.

c. Right to erasure ("right to be forgotten")

As the person concerned, you may have the right to the erasure your personally identifiable data. For example, if your personally identifiable data is no longer necessary for its original purpose, you have revoked your privacy statement, or the personally identifiable data has been improperly processed.

d. Right to restriction of processing

As a data subject, you have the right to restrict the processing in the cases prescribed by law.

e. Right to data portability

As a data subject, you have the right, in the cases prescribed by law, to receive the personally identifiable data concerning you in a structured, common and machine-readable format.

f. Right of objection

As a data subject, you have the right to object at any time to the processing of certain personally identifiable data concerning you for any reason relating to your particular situation.

In the case of direct marketing, as the data subject, you have the right to object at any time to the processing of personally identifiable data concerning you for the purpose of such advertising, including profiling insofar as it is linked to such direct marketing.

g. Right to revoke your consent under data protection law

You may revoke your consent to the processing of your personally identifiable data at any time with effect for the future. However, the lawfulness of the processing carried out before the revocation is not affected.

h. Right of appeal to a data protection authority

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State in which you reside, your place of work or the place where the alleged infringement was committed, if you believe that the processing of your personally identifiable data violates the GDPR.

The responsible supervisory authority for FC Bayern München AG is the Bayerische Landesaufsicht für Datenschutz (https://www.lda.bayern.de/de/kontakt.html).

9. Changes

Our privacy policy and also the descriptions in our cookie consent solution may change from time to time. This also includes further developments due to changes in our business and adjustments due to a changed legal situation and/or due to the implementation of new technologies or services on the website. Any updates to the privacy policy will be published by us on this page. In the event of significant changes, we will point this out accordingly. If you have any further questions that our privacy policy could not answer, please send an email to the following address: datenschutz@fcbayern.com 

Version: September 2020