Djøfs privacy policy
Learn how Djøf processes, uses and protects your personal data to tailor and improve your user experience.
The General Privacy Policy
This Privacy Policy covers the general data processing activities (processing of personal data) carried out by Djøf in connection with membership administration and services, insurance distribution, marketing, union representative roles and other activities.
This Privacy Policy explains how Djøf processes your personal data, for what purposes and on what legal bases. It also explains your rights and how you can exercise them.
Separate, specific privacy policies apply to certain data processing activities carried out by Djøf:
- Privacy Policy for Djøf’s data processing activities relating to the use of social media.
- Privacy Policy for Djøf’s data processing activities relating to Djøf’s whistleblower scheme
- Privacy Policy for Djøf’s data processing activities relating to Djøf’s mentoring program
Data Controller and Contact Details
Djøf is the data controller for the personal data we process about you.
If you have any questions about the processing of your personal data, you are always welcome to contact Djøf’s Data Protection Officer (DPO) at dpo@djoef.dk.
Personal Data
Categories of Personal Data
Djøf only processes personal data about you that is necessary for the purposes described in this Privacy Policy. This may include general personal data, confidential personal data and sensitive personal data within the following categories:
a) Contact details, including, for example, your name, address, telephone number, email address and similar information.
b) Your Danish civil registration (CPR) number.
c) Trade union membership.
d) Employment-related information, including, for example, employment status, employer, education, job title and similar information.
e) Health data, including, for example, information about occupational diseases, work-related injuries and similar matters.
f) Other information we receive from you in connection with our advisory services, including, for example, information about social and family circumstances, sexual orientation, race, ethnic origin, political opinions, criminal offences and similar matters.
g) Information about the use of digital services and participation in networks, education programs, courses and events, including, for example, your username, access code, activity history, image and – where participation takes place online via video meetings and collaboration platforms – video footage of you and recordings of your voice.
h) Relevant information in connection with Djøf awards where you submit a nomination, are nominated or are selected as a winner.
i) Payment information.
j) Information about your use of Djøf’s websites.
k) Responses to satisfaction surveys and market surveys.
Sources of Personal Data
Djøf obtains most of the personal data we process about you directly from you, for example when you join Djøf or use our services and offers. In some cases, Djøf may also obtain personal data about you from public authorities or your trade union representative. Djøf may also obtain personal data about you from third parties, such as your colleagues in connection with Djøf awards.
We retain your personal data for as long as necessary to fulfil the purposes for which it was originally collected. This means that we retain the data for as long as a claim may be brought against us, we are required to do so by law or we have another legitimate reason for retaining it. Further information about retention periods is provided under each of the purposes set out below.
Purposes, Legal Bases and Retention Periods
Djøf processes personal data for several different purposes, including as part of its activities as a trade union, the provision of courses, education programs and events, insurance distribution and marketing. Below, you can read about the individual purposes of processing, the legal bases relied on for the specific processing activities and the periods for which the personal data is retained.
Membership Administration
Djøf processes personal data about its members for membership administration purposes, including ensuring unique identification, registering new members, updating membership information, terminating memberships and reporting information for tax purposes.
For these purposes, Djøf processes personal data based on Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in administering its membership – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
For membership administration purposes, Djøf also processes civil registration (CPR) numbers on the basis of section 11(2), paragraph 4, of the Danish Data Protection Act – as the conditions set out in section 7 of the Danish Data Protection Act are met in relation to the processing of civil registration (CPR) numbers by private-sector organizations – and section 11(2), paragraph 1, of the Danish Data Protection Act, as Djøf is legally required to report information for tax purposes.
Generally, Djøf retains personal data processed for membership administration purposes for the duration of your membership of Djøf and for five full calendar years after your membership ends.
My Djøf
Djøf members have access to My Djøf (www.djoef.dk/mitdjoef), where they can, among other things, update their basic membership information and communicate directly with Djøf.
The personal data entered in the membership portal is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in providing a membership service, including ensuring data quality by giving members easy access to update their basic membership information and providing an easily accessible and secure means of communication – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
Djøf retains personal data from its membership portal for the duration of your membership of Djøf and for five years after your membership ends.
MitID
Djøf uses MitID for secure login and validation in connection with member-facing services and services for people holding union representative roles. In this regard, we process personal data about you, including your civil registration (CPR) number.
When establishing access to services via MitID, Djøf discloses your civil registration (CPR) number to our MitID provider. The disclosure is based on Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in ensuring access to My Djøf – and section 11(2), paragraph 3, of the Danish Data Protection Act – as the disclosure is of decisive importance for ensuring the unique identification of the data subject.
Following establishment of the MitID services, Djøf process the personal data based on of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in ensuring unique identification and access to Djøf services for members and persons holding union representative roles; Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union; and section 11(2), paragraph 4, of the Danish Data Protection Act – as the conditions set out in section 7 of the Danish Data Protection Act are met in relation to the processing of civil registration (CPR) numbers by private-sector organizations.
Djøf retains personal data collected in connection with access to My Djøf via MitID for six months after your membership ends. If you access My Djøf in your capacity as a union representative without being a member, the data is retained for six months after you cease to be a union representative.
Djøf's Member Benefits and Services
Djøf members have access to a range of membership services, including, for example, career consultations and CV guidance, legal advice, participation in events, networks and affiliated associations, as well as member benefits and discounts.
The personal data Djøf receives in connection with providing member benefits and services is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in providing membership services – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union. Where relevant to the provision of a benefit or service, Djøf’s disclosure of information concerning trade union membership to Djøf’s partners, event organisers and other participating Djøf members is based on Article 6(1)(a) of the GDPR – consent – and Article 9(2)(a) of the GDPR – explicit consent.
Djøf retains personal data received in connection with the provision of membership services for the duration of your membership of Djøf and for five years after your membership ends.
Insurance distribution - Djøf Forsikring
Djøf offers its members access to personal insurance products through its insurance partner, Købstædernes Forsikring. In this connection – when specifically relevant – members’ basic details and information about their membership of Djøf are disclosed to Købstædernes Forsikring.
Djøf’s disclosure of members basic details to Købstædernes Forsikring is based on Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in facilitating access to favourable personal insurance products for its members.
Djøf’s disclosure of information concerning trade union membership to Købstædernes Forsikring is based on Article 9(2)(a) of the GDPR – explicit consent.
Djøf retains a record of the disclosure of your personal data to Djøf’s insurance partner for the duration of your membership of Djøf and for five years after your membership ends.
Djøf's Websites
When you visit Djøf’s websites, we process information about your user behavior in order to tailor and improve the user experience, including adapting articles, advertisements and other content to match your preferences as closely as possible. This information is collected using cookies.
Djøf processes personal data collected through necessary cookies based on Article 6(1)(f) of the GDPR – Djøf’s legitimate interest in supporting the technical operation and functionality of its websites.
Djøf processes personal data collected through other cookies based on Article 6(1)(a) of the GDPR – consent.
See Djøf’s Cookie Policy for further information about the processing of personal data in connection with visits to our websites, including information about retention periods.
Djøf Awards
Djøf processes personal data in connection with Djøf awards, including where you submit a nomination, are nominated or are selected as a winner.
The personal data Djøf processes in connection with its awards is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest in using awards to highlight and recognise the contributions made by members and third parties in their fields and professions – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
The public announcement of award winners is based on Article 6(1)(a) of the GDPR – consent – and Article 9(2)(a) of the GDPR – explicit consent.
Generally, Djøf retains personal data about nominees for three months after the award process and personal data about winners until their consent to publication is withdrawn.
Marketing
Djøf processes personal data about you for targeted marketing purposes, including sending newsletters containing information about Djøf’s offers and services and targeting advertisements and campaigns on social media.
Djøf processes personal data for targeted marketing purposes based on Article 6(1)(a) of the GDPR – consent – and Article 6(1)(f) of the GDPR – Djøf’s legitimate interest in targeting its marketing at members and potential members.
Djøf processes personal data for the telephone marketing of insurance products on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in facilitating access to favourable personal insurance products for its members – and section 4(2), paragraph 3, of the Danish Consumer Contracts Act – the exception to the general prohibition on unsolicited telephone calls made for the purpose of entering into agreements concerning insurance mediation.
If you attend one of Djøf’s events, we may also process personal data about you for marketing purposes in the form of photographs and video footage taken at the event. Photographs and video footage from Djøf member events are used for marketing on www.djoef.dk, in Djøfbladet and on social media.
Personal data in the form of photographs and video footage from Djøf’s members-only events (attended exclusively by Djøf members) is processed based on Article 6(1)(a) of the GDPR – consent – and Article 9(2)(a) of the GDPR – explicit consent. Personal data in the form of photographs and video footage from open Djøf events (where participation is not conditional on Djøf membership) is processed based on Article 6(1)(a) of the GDPR – consent.
Djøf retains personal data for marketing purposes until you withdraw your consent or for a period of up to three years from the date on which the data was collected.
Focus Groups and Member Surveys
Djøf conducts member surveys, focus groups and similar activities to gain insight into members’ views on themes and issues of interest to Djøf. Surveys and focus groups are conducted either through questionnaires or as in-person or online interviews. In this connection, Djøf may process personal data concerning individuals’ opinions and views, as well as audio and video recordings from interviews.
The personal data Djøf processes in connection with focus groups and member surveys is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in gaining insight into members’ opinions and views on broader themes; Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
Djøf retains personal data collected in connection with focus groups and member surveys for six months from the date of collection.
Participation in User Testing
Djøf conducts user testing of existing and future services to understand their usability, relevance and quality from a member perspective. User tests are conducted by telephone or through invitations to participate voluntarily via our digital usability testing platform. In this connection, Djøf may process personal data about individual members when selecting participants and as part of the specific user test.
The personal data Djøf processes in connection with invitations to and the conduct of user tests is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in evaluating and ensuring the relevance and quality of digital member benefits and services – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
Djøf retains personal data collected through participation in a user test for the duration of the specific test.
Anonymization for Statistical Purposes
Djøf processes personal data for internal, external and member-facing statistical purposes. This is done, among other things, to continuously tailor Djøf’s services based on user behavior and to provide insight into and an overview of members’ circumstances in specific areas, such as parental leave conditions or salary trends broken down by segment and geographical area.
The personal data Djøf uses for statistical purposes is anonymised before being included in statistical calculations and materials.
Djøf’s processing of personal data for anonymization for statistical purposes is based on Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in obtaining statistical insight into members’ behavior, circumstances and needs – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
The retention period for personal data anonymized by Djøf for statistical purposes corresponds to the retention period applicable to the specific purpose for which the data was originally collected and processed.
Purchase and Delivery of Djøf Courses and Training Programs
Djøf processes personal data about you in connection with your participation in courses and training programs for purposes including registering your enrolment, invoicing, checking attendance, carrying out access control, recording dietary preferences, preparing participant lists and name badges, facilitating participation in online meetings and discussion forums, conducting evaluations and issuing course certificates.
The personal data Djøf processes in connection with offering and delivering courses and training programs is processed on the basis of Article 6(1)(b) of the GDPR – performance of a contract; Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in providing membership services; and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
Where relevant to the provision of a course or training program, Djøf’s disclosure of information concerning trade union membership to organizers and other participating Djøf members is based on Article 6(1)(a) of the GDPR – consent – and Article 9(2)(a) of the GDPR – explicit consent.
Djøf retains personal data collected in connection with offering and delivering courses and training programs for five full calendar years following its collection.
Union Representative Roles
Djøf processes personal data about you if you are elected as a Djøf union representative at your workplace. We do so to maintain contact between you and Djøf and to enable us to provide your contact details to the members and job applicants you represent.
The personal data Djøf processes about its union representatives is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in facilitating and coordinating local union representation – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
Djøf retains personal data about your union representative role for the duration of your term as a union representative and for six months after your term ends.
Job Alert Service – Jobuniverset.dk
When you sign up for our job alert service on Jobuniverset.dk, we collect your email address and job preferences so that we can send you relevant job postings.
The personal data Djøf receives when job alerts are set up is processed based on Article 6(1)(f) of the GDPR – Djøf’s legitimate interest in providing users of Jobuniverset with a relevant and personalised job-matching service that supports their career development.
Djøf retains the personal data received in connection with providing the job alert service for as long as you subscribe to the service.
Testing to Ensure Data Protection and the Security of Processing
In exceptional circumstances, Djøf may process a limited amount of personal data in connection with the development and testing of core systems where this is critical to ensuring data protection and the security of processing.
The personal data Djøf processes in connection with testing and ensuring the security of processing is processed on the basis of Article 6(1)(f) of the GDPR – Djøf’s legitimate interest, as a trade union, in ensuring the security of its processing of personal data – and Article 9(2)(d) of the GDPR – processing carried out as part of Djøf’s legitimate activities as a trade union.
Djøf retains personal data processed as part of testing to ensure data protection and the security of processing for the duration of the test.
Automated Individual Decision-Making and Profiling
Djøf does not process personal data for the purpose of making automated individual decisions.
If you are a Djøf member, Djøf uses profiling to generate and continuously update your Djøf member profile. The purpose is to improve Djøf’s offers and services and your overall user experience when interacting with Djøf. The profiling is based on information we collect when you visit Djøf’s websites, communicate with us, and register for and use Djøf’s services.
Recipients of Personal Data
To the extent necessary, Djøf discloses personal data about you to, or makes it available for processing by, a number of recipients. We do so to provide you with the services described in the section “Purposes, Legal Bases and Retention Periods”.
The recipients of your personal data will either be independent data controllers (“third parties”) or data processors acting on behalf of Djøf.
The third parties to whom we disclose your personal data are:
Public authorities:
- Location/country: Denmark.
- Sector/industry: Varies depending on the purpose (e.g. the Danish Data Protection Agency, courts and arbitration tribunals, and the Danish Tax Agency).
- Purpose of disclosure: Compliance with legal obligations.
Insurance company:
- Location/country: Denmark.
- Sector/industry: Insurance.
- Purpose of disclosure: Insurance mediation for members through Djøf’s insurance partner, Købstædernes Forsikring.
Employers:
- Location/country: Denmark.
- Sector/industry: Varies depending on the employer.
- Purpose of disclosure: The performance of trade union activities by Djøf or Djøf’s union representatives in dealings with third parties, including counterparties and employers.
External partners:
- Location/country: Denmark.
- Sector/industry: Varies depending on the supplier or partner (e.g. banking, insurance, publishing, e-commerce or telecommunications).
- Purpose of disclosure: Provision of member benefits and discount schemes through partners.
In addition to the recipients listed above, your personal data will be shared with the following categories of data processors and sub-processors:
IT suppliers:
- Location/country: The EU, India, the United States and other locations.
- Sector/industry: IT.
- Industry: IT operations, IT support, systems development and cloud service providers.
- This category includes the following processing chains: Djøf to Microsoft; Djøf to TOPdesk to Microsoft; Djøf to DB Job; Djøf to PushFar; Djøf to Planorama; Djøf to Zoom; Djøf to Mentimeter; and Djøf to Miro.
- Purpose of processing: IT support, systems development, server hosting, database support, provision of network infrastructure and IT operations, as well as the operation and support of activity and event administration, digital meetings, webinars and video conferences, presentations, polls and digital collaboration.
- Basis for transfers to third countries: Transfers are based on the European Commission’s Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
See further information about the European Commission’s Standard Contractual Clauses used to transfer personal data to third countries.
Website tracking, statistics and analytics:
- Location/country: The EU, India, the United States and other locations.
- Sector/industry: IT.
- Industry: Statistics and analytics.
- This category includes the following processing chains: Djøf to Google Analytics; and Djøf to Mouseflow.
- Purpose of processing: Collection of data about user behavior in order to tailor and improve the user experience, including adapting articles, advertisements and other content.
- Basis for transfers to third countries: Transfers are based on the European Commission’s Standard Contractual Clauses.
See further information about the European Commission’s Standard Contractual Clauses used to transfer personal data to third countries and the EU-U.S. Data Privacy Framework.
User testing via a digital usability testing platform:
- Location/country: The EU, India, the United States and other locations.
- Sector/industry: IT.
- Industry: Digital usability testing.
- This category includes the following processing chain: Djøf to Peerly.
- Purpose of processing: User testing of existing and future digital services to understand their usability, relevance and quality from a member perspective.
- Basis for transfers to third countries: Transfers are based on the European Commission’s Standard Contractual Clauses.
Contract review and analysis:
- Location/country: Denmark.
- Sector/industry: Legal advice.
- Industry: Statistics and analytics.
- This category includes the following processing chain: Djøf to Deep Lex.
- Purpose of processing: As part of providing contract review services, employment contracts are reviewed and analysed using automated means.
Your Rights
Under the GDPR, you have several rights in relation to Djøf’s processing of your personal data. You can read more about these rights below.
If you wish to exercise your rights, please contact us using the contact details provided in the section “Data Controller and Contact Details”.
Right to Withdraw Consent
Right of Access
Right to Rectification
Right to Erasure
You have the right to request the erasure of the personal data we process about you.
However, the right to erasure may be restricted under applicable law where we have a legal basis that justifies the continued processing of your personal data.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances. This may apply if you contest the accuracy of the personal data, the processing is unlawful and you request restriction instead of erasure, we no longer need the personal data but you require it for the establishment, exercise or defense of legal claims, or while we assess an objection you have made to the processing.
Where processing has been restricted, we will generally only retain personal data. Apart from storage, the data may only be processed with your consent, for the establishment, exercise or defense of legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest.
Right to Object
In certain circumstances, you have the right to object to our processing of your personal data where the processing is based on Djøf’s legitimate interest. We will then stop the processing unless we can demonstrate compelling legitimate grounds for continuing it or the processing is necessary for the establishment, exercise or defense of legal claims.
You may object to direct marketing at any time, after which we will stop processing your personal data for this purpose.
Right to Data Portability
Right to Lodge a Complaint with the Danish Data Protection Agency
In addition to the rights described above, you have the right to lodge a complaint with the Danish Data Protection Agency regarding Djøf’s processing of your personal data. The Agency’s contact details are available on its website.
Changes and Version History
Djøf may amend this Privacy Policy at any time and without prior notice to reflect changes in Djøf’s processing activities. Any amendments will apply prospectively. Depending on their nature, changes to this Privacy Policy will be communicated through Djøf’s websites and services.
The version history of this Privacy Policy is set out below:
Version 1.0
- Date: 28 May 2018.
- Change: Privacy Policy prepared and implemented.
Version 1.1
- Date: 19 December 2022.
- Change: General update to the structure of the Privacy Policy. Djøf Forsikring added.
Version 1.2
- Date: 10 March 2023.
- Change: Djøf user testing added.
Version 1.3
- Date: 3 September 2024.
- Change: Addition of a processing purpose relating to necessary system testing.
Version 1.4
- Date: 10 January 2025.
- Change: Addition of a processing purpose relating to Djøf awards. “Member Login Using MitID” replaced by “My Djøf Login Using MitID”.
Version 1.5
- Date: 9 April 2025.
- Change: Update of the categories of personal data relating to the processing of images, voice and video in connection with participation in courses, and the legal bases relating to marketing activities.
Version 1.6
- Date: 29 April 2025.
- Change: Addition of a processing purpose relating to subscription to the job alert service on Jobuniverset.dk.
Version 1.7:
- Date: 18. September 2026
- Change: Clarification and expansion of the categories of personal data, purposes of processing and legal bases, including in relation to digital services, membership administration, member benefits, courses and events, as well as updates to recipients, data processors and data subjects’ rights.