Aftersales Online System


Notifications about data protection

The high standard of the properties of our products and services, is for us the guiding principle for the handling of your data. It is our endeavour to create and safeguard the basis for a trusting business relationship with our customers and prospective customers. The confidentiality and integrity of your personal data is of paramount concern to us.

Who is responsible for data processing?

Die Bayerische Motoren Werke Aktiengesellschaft, Petuelring 130, D-80788 Munich, Headquarters and registry court: Munich HRB 42243 (hereinafter "BMW") provides the customer via the "Aftersales Online System AOS" (hereinafter "Portal") certain technical information, especially information and applications (hereinafter referred to as "Content") for professional maintenance and repair of vehicles and motorcycles manufactured by the operator and/or distributed under the brands of the operator, and is responsible for data processing in this context.

What data do we process about you and for what purposes?

Data collected in connection with the conclusion of the contract or the provision of the services will be processed for the following purposes:

A. Entrance Examination prior to conclusion of the contract (Article 6, paragraph 1 lit. b) Data Protection Regulation)

In the framework of the accreditation examination prior to conclusion of the contract, the following data categories will be processed:

  • Contact details (surname, first name, address, e-mail address, etc.)


B. The conclusion of the contract and fulfilment of contractual obligations (Article 6, paragraph 1 lit. b) Data Protection Regulation)

In the context of the conclusion of the contract the following data categories will be processed:

  • Contact details (surname, first name, address, e-mail address, etc.)

The contract data will be automatically deleted 1 year after expiry of the contract, financial transactions will be deleted within the framework of the statutory provisions after 10 years.

For the purpose of fulfilment of the contract concluded between you and BMW, BMW provides various services such as Technical Help Desk, Change Requests, user administration.

For the provision of these services, the following, where appropriate personal information is processed by BMW or service providers commissioned by BMW in order to provide the services:

  • Vehicle identification number (VIN)
  • Contact details (surname, first name, address, e-mail address, etc.)

The provision of this data is not required for the conclusion of the contract. However, without the data provided by you and processed by BMW, BMW is unable to render respective service to you.

The processed personal data will be deleted automatically if it is no longer needed for the provision of the particular service.

As part of the order, the specified personal payment details (credit card number, card expiry date, card verification number, card holder name) are processed by the payment service provider SIX Payment Services (Germany) GmbH, Langenhorner Chaussee 92-94, 22415 Hamburg („SIX"). The payment details are neither saved on BMW servers or stored temporarily. You can find more information about data protection using SIX on the SIX website under


C. Product quality assurance and development of new products (type. 6 paragraph 1 lit. f) Data Protection Regulation)

Above and beyond the mere provision of services, the data collected is also processed by BMW to ensure the quality of products and services provided by the BMW Group and the development of new products and services. This processing is used to protect the legitimate interest of BMW, the high customer demands on the already existing products and services, and to be able to meet future needs of our customers through new products and services to be developed. The processing will be carried out to protect the privacy of our customers exclusively to the customer in a form that cannot be directly traced back to the customer.

C. Fulfilment of the sales, service and management processes at BMW AG (type. 6 paragraph 1 lit. f) Data Protection Regulation)

BMW AG is a company of the BMW Group. We may use your personal data in some cases to make the management of the various companies within the BMW Group as efficient and successful as possible. This applies, for example, to the joint consolidated financial statements in accordance with international accounting rules for companies (such as the International Financial Reporting Standards (IFRS).

E. Customer Care (type. 6 para. 1 lit. b, g, f) Data Protection Regulation)

BMW uses your personal data to address the contract processing see above (for example editing the registration) or for handling a concern expressed by you (e.g. inquiries and complaints to support). In relation to all aspects of the contract or the settlement of an issue , we will address you without any special consent for example, in writing, by telephone, by E-mail, depending on which contact media you specified.


F. Fulfilment of legal obligations to which BMW is subject (Art. 13 Abs. 1 lit. c, 6 para. 1 lit. c) Data protection regulation)

Collected data is also used in the context of ensuring the operation of IT systems.

Collected data is also used in the context of ensuring the operation of IT systems. By ensuring, inter alia, the following activities:

  • Backup and recovery of data processed in IT systems
  • Logging and monitoring of transactions, in order to verify correct operation of IT systems
  • Detection and prevention of unauthorized access to personal data
  • Incident and Problem Management for rectification of faults in IT systems

Data collected will be processed in the framework of the internal compliance management, for example, we check whether you were sufficiently advised in the context of a contract conclusion and whether the dealer has complied with all statutory obligations.

BMW is subject to a variety of other statutory obligations. In order to comply with these obligations, we process your data to the extent necessary and pass it on where appropriate within the framework of statutory reporting obligations to the responsible authorities.


How long do we store your data?

We store your personal data only as long as the respective purpose requires. Data will be processed for several purposes, the data will be automatically deleted or saved in a not directly traceable form as soon as the last specified purpose has been fulfilled.

How is your data backed up?

We protect your data in accordance with the current state of technology.  As an example, the following security measures are implemented to protect your personal data against misuse or other unauthorized processing:

  • Access to personal data is restricted to only a limited number of authorised persons for the specified purposes.
  • Collected data will only be transmitted in encrypted form.
  • Sensitive data will be stored only in encrypted form.
  • The IT systems for the processing of data are technically sealed off from other systems to prevent unauthorized access, for example, by hacking.
  • In addition, access to these IT systems is monitored constantly, in order to prevent and ward off abuse at an early stage.

To whom do we collect information and how we protect you?

BMW is a globally active company. Personal data is used by BMW employees, and commissioned by our preferred service providers within the EU.

Should data be processed in countries outside the EU, BMW ensures by means of EU-standard contracts including appropriate technical and organizational measures that your personal data will be processed in accordance with the European data protection level. If you would like to view the specific safeguards for the transfer of data in other countries, please contact us via the above-mentioned communication channels.

For some countries outside the EU, such as Canada and Switzerland, the EU has already ascertained a comparable level of data protection. As a result of the comparable level of data protection required, the data transmission in these countries does not required any special approval or agreement.

Contact details, your affected rights and your right to complain to a supervisory authority.

For questions on the use of your personal data by us, please contact AOS support – either by e-mail at or via the contact form

In addition, you can contact the competent data protection officer:

Stefan Winkler
Petuelring 130
D-80788 Munich


As a person affected by the processing of your data, you can make use of certain rights against us according to the data protection foundation and other relevant data protection provisions. The following section contains explanations about your affected rights in accordance with the data protection regulation.

Rights of affected parties

According to the data protection regulation, you have the following rights in particular with respect to BMW and as an affected person:

Right to information (art. 15 Data Protection Regulation): You can request from us at any time information about your data we are holding on you. This information relates among other things to the categories of data processed by us, the purposes for which we process it, the origin of the data, if we have not collected it directly from you, and, where applicable, the recipients to whom we have submitted your data. You can receive a free copy of your data. If you are interested in more copies, we reserve the right to send you further copies for a charge.

Right to correction (art. 16 Data Protection Regulation): You can request the correction of your data. We will take reasonable measures to keep the information we are holding on you correct, complete and up to date, based on the most up-to-date information available to us.

Right to deletion (Art. 17 Data Protection Regulation): You can request the deletion of your data by us, insofar as the legal conditions are met. This can be according to art. 17 Data Protection Regulation in the following cases:

  • The data is no longer required for the purposes for which it was collected or processed in any other way.
  • You revoke your consent, which is the basis of the data processing, and there is a lack of any other legal basis for the processing.
  • You object to the processing of your data and there are no legitimate reasons for processing or you object to the data processing for the purposes of direct advertising.
  • The data has been processed unlawfully.

Exceptions are in the following cases:

  • The storage is necessary for compliance with a legal obligation, which requires of us the processing of your data.
  • The storage is necessary for compliance with statutory retention periods.
  • The storage is a necessary step to ensure, pursue or defend legal claims.

Right to limitation of processing (art. 18 Data Protection Regulation): You can request the restriction of the processing of your data in the following cases:

  • You deny the accuracy of the data for the period that we need in order to verify the accuracy of the data.
  • The processing is unlawful and you reject the deletion of your data and instead require the restriction of the use.
  • We no longer require your data, but need it to make, pursue or defend legal claims.
  • You have objected to the processing, as long as it is not clear whether our legitimate reasons predominate yours.

Right to data transfer (art. 20 Data Protection Regulation): At your request, we will transfer your data - as far as is technically possible - to another responsible. However, this right is available only if the data processing is based on your consent, or is required to carry out a contract. Instead of receiving a copy of your data, you can also ask us that we provide the data directly to another responsible person specified by you.

Right of Appeal (Art. 21 Data Protection Regulation): You can at any time object to the processing of your data for reasons of your specific situation, to the extent that the data processing rests on your consent or on our legitimate interests or those of a third. In this case, we will not disclose your data for a longer time. The latter does not apply if we can prove compelling legitimate grounds for processing that outweigh your interests or if we require your data to make, exercise or defend legal claims.

Deadlines for the fulfilment of the affected person's rights

Basically, we strive to comply with all requests within 30 days. However, this period can be extended if necessary, for reasons that relate to the specific affected person's right or the complexity of your request.

Information restriction in the fulfilment of the right

In certain situations, we might not be able to provide any information about any of your data due to legal requirements. If we must reject your request for information in such a case, we will inform you about the reasons for the rejection at the same time.

Complaint with supervisory authorities

BMW takes your concerns and rights very seriously. But if you are of the opinion that we have not sufficiently complied with your complaints or concerns, you have the right to file a complaint with a competent data protection authority.