jumpToMain
199187

Data Protection at Rheinmetall

The protection of personal data is a priority for Rheinmetall AG and its group companies. Rheinmetall is committed to handling the personal data of all individuals who come into contact with our company—whether they are customers, business partners, visitors to our websites, or employees—in a responsible, transparent, and legally compliant manner. On this page, we provide information about the principles and measures we use to ensure the protection of your data.

1. Our Commitment to Data Protection

Rheinmetall is committed to complying with the European Union’s General Data Protection Regulation (GDPR) as well as all other applicable national and international data protection regulations worldwide. This commitment applies across the entire Group—to all business activities, locations, and subsidiaries.

We see the protection of personal data not only as a legal obligation, but also as an essential component of our corporate responsibility and our commitment to sustainable and ethical business practices. The careful and data-protection-compliant handling of personal data fosters trust and security for our employees and business partners. Our Data Protection Management System (DPMS) is regularly reviewed and adapted to new legal requirements and technological developments. The Rheinmetall Group is committed to the following strategic data protection goal:

We ensure the protection of the personal data of our customers, employees, and business partners.

2. Data Protection Governance

Responsibility for data protection at Rheinmetall is anchored at the highest corporate level. The Executive Board of Rheinmetall AG bears overall responsibility for establishing and implementing an effective Group-wide DPMS.

Organizational implementation takes place through a multi-tiered structure:

  • At the Group level, the data protection organization—as a department within the compliance organization—is entrusted with the overarching coordination and strategic management of data protection.
  • At the division and individual company levels, dedicated roles ensure compliance with data protection requirements within their respective business units.
  • Our Group Data Protection Officer monitors compliance with the GDPR and other relevant regulations, reports directly to top management, and acts independently and free from instructions.
  • Responsibilities are organized according to the principle of separation of duties to avoid conflicts of interest.
3. Data Protection Organization

The Executive Board of Rheinmetall AG bears overall responsibility for data protection within the Group. It has established a Group-wide Data Protection Management System (DPMS) and delegated its operational implementation to the data protection organization. This ensures that data protection is anchored at the highest management level and has clearly defined responsibilities.

The practical implementation of data protection is carried out by a network—in some cases multi-tiered—of specialized contacts within the Group’s divisions and companies. This decentralized structure ensures that compliance with data protection requirements at every location and in every business unit is guaranteed by individuals with direct knowledge of the respective processes. The contact persons work closely with the Group Data Protection Officer, thereby ensuring the uniform application of data protection law throughout the Group.

Our Group Data Protection Officer independently monitors—without receiving instructions—compliance with data protection requirements in the Group companies under his supervision, as well as the adequacy of the Data Protection Management System (DPMS). Furthermore, as part of his data protection mandates and in fulfillment of his legal duties, he is available at all times and directly to data subjects and data protection supervisory authorities as a point of contact. He advises the business units and, when necessary, the data protection organization on data protection issues, supports new projects from a data protection perspective, and reports directly to the company’s senior management.

4. Data Protection Management System (DPMS)

Rheinmetall operates a comprehensive DPMS that encompasses processes and organizational structures to ensure compliance with all statutory data protection requirements during the planning, establishment, operation, and decommissioning of personal data processing activities.

In addition to the data protection organization described in Section 3, our DPMS is characterized in particular by the following features:

  • Establishing processes, guidelines, and measures to ensure that business processes comply with data protection regulations
  • Maintaining a comprehensive record of processing activities
  • Documentation of data protection-related measures to fulfill accountability requirements
  • Conducting data protection risk assessments and data protection impact assessments (DPIAs) for high-risk processing operations
  • Regular audits and operational reviews of data protection-related business processes
  • Continuous improvement process based on the Plan-Do-Check-Act (PDCA) cycle
  • Regular review and updating—at least every three years and as needed

 

In conjunction with the Information Security Management System (ISMS), we ensure that personal data is protected at all times through appropriate technical and organizational measures.

To effectively embed data protection into day-to-day business operations, the data protection organization is integrated into core business processes as a permanent review and liaison body. This applies in particular to the introduction of new IT applications, the engagement of external service providers, and the design of new business processes. This ensures that data protection requirements are taken into account at an early stage and consistently adhered to.

5. Handling of Sensitive Data and Data Minimization

Rheinmetall always processes personal data in accordance with the principle of data minimization: We collect and process only the data that is actually necessary for the respective purpose.

Our core principles for handling personal data:

  • Data minimization: Collecting only the data necessary for the specific purpose
  • Need-to-know principle: Access to personal data is restricted to individuals who require it for their work
  • Storage limitation: Deletion or anonymization of personal data as soon as the purpose of processing no longer applies
  • Privacy by Design: Designing technology with privacy in mind from the outset
  • Privacy by Default: Data protection-friendly default settings in all systems and processes

 

The processing of special categories of personal data—such as health data—is carried out in accordance with specific legal requirements (in particular Article 9 of the GDPR) and is subject to enhanced safeguards.

6. International Data Transfers

As a globally active corporation, Rheinmetall places particular emphasis on the protection of personal data in cross-border data transfers. As a general rule, the processing of personal data takes place within the European Union or the European Economic Area (EU/EEA).

To the extent that a transfer of personal data to third countries outside the EU/EEA is necessary, we ensure an adequate level of data protection through appropriate safeguards. To this end, we rely in particular on:

  • EU Standard Data Protection Clauses (Standard Contractual Clauses) as a contractual basis
  • Additional technical and organizational measures to ensure an adequate level of protection

 

This practice is consistent with internationally recognized principles for cross-border data flows, as set forth in particular in the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. The principles enshrined therein—namely accountability, purpose limitation, security, and ensuring an adequate level of protection—are an integral part of our approach to international data transfers.

7. Rights of Data Subjects

Rheinmetall respects and guarantees the rights of all individuals whose data we process. Under the GDPR, data subjects have the following rights in particular:

  • The right to access the data stored about them (including a copy)
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing, particularly in the case of direct marketing (in this case, the objection takes effect immediately and without the need to provide a reason)
  • Right to withdraw consent with future effect
  • Right to lodge a complaint with a competent data protection supervisory authority

 

Requests from data subjects are generally processed within one month. We try to ensure  wherever possible that exercising these rights is simple and accessible.

8. Training and Awareness

Effective data protection requires informed and aware employees. Rheinmetall therefore relies on a comprehensive training and awareness program:

  • Mandatory data protection training for all new employees
  • Regular refresher training sessions to refresh and deepen knowledge of data protection
  • E-learning modules for flexible, cross-location training
  • Training tailored to specific target groups for areas particularly relevant to data protection (e.g., human resources, marketing)
  • Supplementary awareness-raising measures such as information campaigns, flyers, posters, videos, and internal communications

 

Through these measures, we ensure that data protection is practiced throughout the entire company and that all stakeholders are aware of and fulfill their responsibilities.

9. Handling Data Protection Incidents

Rheinmetall has an established procedure for detecting, assessing, and handling data protection incidents. In the event of a data protection incident:

  • An immediate internal assessment of the risk to the affected individuals is conducted
  • If the risk warrants it, the competent data protection supervisory authority is notified within 72 hours
  • Data subjects are informed if there is a high risk to their rights and freedoms
  • Measures are taken to contain the incident and prevent future incidents
  • Reports are also received and processed via Rheinmetall’s whistleblower system, the EQS Integrity Line (EQS Integrity Line)
10. Contact Information and Points of Contact

Accessibility is important to us. Our contact persons are happy to assist you with any questions regarding data protection, the exercise of your rights as a data subject, or other data protection concerns.

Further information and contact details can be found in Section 3 of our Privacy Policy.

Rheinmetall Platz 1

40476 Dusseldorf

Germany

Contact us

© 2026 Rheinmetall AG