Data protection declaration in accordance with Art. 12 ff General Data Protection Regulation (GDPR) for Borussia Dortmund GmbH & Co. KGaA and its affiliated companies (BVB Merchandising GmbH, BVB Stadionmanagement GmbH, BVB Event & Catering GmbH, BVB Foundation, besttravel Dortmund GmbH, BVB Fußballakademie GmbH , BVB Asia Pacific Pte. Ltd.) and the BV. Borussia 09 e.V. Dortmund on the handling of personal data

 I. General information

General information on data processing Borussia Dortmund GmbH & Co. KGaA and the companies associated with us (BVB Merchandising GmbH, BVB Stadionmanagement GmbH, BVB Event & Catering GmbH, BVB Foundation, besttravel Dortmund GmbH, BVB Fußballakademie GmbH, BVB Asia Pacific Pte. Ltd.) and the BV. Borussia 09 e.V. Dortmund very important. We process your data exclusively in accordance with the provisions of the General Data Protection Regulation (GDPR) in conjunction with the Federal Data Protection Act (BDSG). Personal data that is required in all areas, i.e. the so-called master data listed under point IV, is available to the entire group. Data that is only required in individual departments to process certain services is only available to the employees there and only to the extent that they are entrusted with completing the task. The special data protection declarations for the respective task groups can be found under the given link:

Technical data protection & social media Borussia 09 e.V. Dortmund (handball, table tennis, old men's football, women's football, blind football, goal ball, integration sports, Borusseum) Fan department/ member service kids club Youth Performance Center Borussia Dortmund GmbH & Co. KGaA share applications BusinessNetwork BVB App BVB TV design competitions eFootball fan shop Fan Shop International Sweepstakes whistleblower system Login (account.bvb.de) Project Panama ticketing Ticketing (eventimsports) Ticketing hospitality (after sales platform) besttravel dortmund GmbH BVB Events & Catering GmbH BVB football academy GmbH BVB Merchandising GmbH BVB Foundation The following explanations generally apply to the entire Group.

II. Name and address of the person responsible

For KGaA and its affiliated companies, the person responsible within the meaning of the European General Data Protection Regulation is Borussia Dortmund GmbH & Co. KGaA Rheinlanddamm 207-209 44137 Dortmund Germany Phone: 02 31 - 90 20 0 Email: datenschutz@bvb.de Website: www.bvb.de

For the club B.V. Borussia 09 eV Dortmund Strobelallee 50 44139 Dortmund Germany Phone: 02 31 - 90 20 0 Email: datenschutz@bvb.de Website: www.bvb.de/Der-Verein

III. Contact details of the data protection officer

You can reach the data protection officer at: Lawyer Ulf Haumann, LL.M. c/o Borussia Dortmund GmbH & Co. KGaA Rheinlanddamm 207-209 44137 Dortmund c/o BV. Borussia 09 eV Dortmund Strobelallee 50 44139 Dortmund Germany Phone: 02 31 - 90 20 0 Email: datenschutz@bvb.de Website: www.bvb.de

IV. Specifics about your data

We collect and use the personal data that is required in the individual business areas of our company. These are essentially the master data:

Salutation, first name, last name Date of birth address E-mail address phone number Payment or billing data

Invoice data is collected when registering for measures that are subject to a fee. They only refer to the information relevant to the invoice. Other data is only collected in accordance with special regulations in individual departments and is only accessible there. You will be specifically informed about this on the respective page. In principle, your data will not be passed on without your express consent. The data is deleted as soon as it is no longer needed, usually when you end the business relationship.

V. Legal basis

We process your personal data to fulfill the contract and for direct advertising, to ensure the security and smooth running of our events.

1.Contract The legal basis for the processing of your personal data by the responsible body is usually Article 6 Paragraph 1 Subsection 1 Letter b) GDPR (performance of contract). Thereafter, your personal data may be processed if and to the extent that this is necessary to fulfill our contractual obligations to you. This also applies to all processing that is necessary in order to be able to carry out pre-contractual measures that are carried out at your request. More details are regulated in the respective departments (e.g. when purchasing tickets, registering for an event, etc.).

2. Legitimate Interest We take all measures within the scope of our possibilities to ensure the safety and smooth running of all BVB events. Among other things, we also have to comply with the guidelines for the uniform treatment of stadium bans of the German Football Association ("DFB") or in an international game of the "UEFA" and ensure safety and order in the stadium by pronouncing house bans under civil law. In this and similar cases, we have a legitimate interest in processing all the information required for this and are therefore entitled to do so in accordance with Art object to data processing by stating your conflicting personal interests. In principle, however, safety aspects take precedence. If applicable, this is explained in detail in the individual departments. If your data is processed on the basis of our legitimate interest (Article 6 paragraph 1 subparagraph 1 lit. f) GDPR), you can object to this in the case of direct advertising without giving reasons, otherwise by stating your conflicting interest in accordance with Article 21 GDPR. In the case of direct advertising, this is in our legitimate interest and is therefore lawful in accordance with Article 6 Paragraph 1 Subparagraph 1 lit. f) GDPR.

Data transfer

3.Data transfer In principle, your data will not be transmitted. In special cases (e.g. to enforce a nationwide stadium ban) this is necessary and contractually regulated in our terms and conditions. However, we transmit data to our service providers (e.g. software companies) on the basis of order processing contracts in accordance with Article 28 GDPR.

Consent

4.Consent If data processing in individual areas is based on your consent (Article 6 paragraph 1 subparagraph 1 lit. a) GDPR), you can revoke this at any time with effect for the future. VI. storage duration We delete your personal data as soon as we no longer need them to fulfill our contractual and/or legal obligations. Invoice data, for example, may only be deleted after 10 years. VII. Your Rights As a data subject, you basically have the right to information about your processed data according to Art. 15 GDPR, the right to have your data corrected in accordance with Art. 16 GDPR if we process incorrect information about you the right to erasure of your data in accordance with Art. 17 GDPR if we no longer need the data and there are no legal storage purposes to the contrary the right to restrict the processing of your data in accordance with Art. 18 GDPR if and for as long as your objections to the data processing (Art. 6 Para. 1 Subparagraph 1 lit. f) GDPR) have not yet been clarified and the right to object to the processing of your data in accordance with Art. 21 GDPR if we process your data in the context of our overriding interest. This is especially the case if, in your case, our and public interests are opposed to overriding personal interests on your part in data processing. You also have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR), i.e. the State Commissioner for Freedom of Information and Data Protection (LDI) (https://www.ldi.nrw.de/). We always comply with all these rights. If you would like more detailed information, we will be happy to provide it to you. To do this, please contact our data protection officer named above. The basic handling of the newsletter, technical data protection & social media or other IT contact is presented in detail at https://www.bvb.de/Datenschutz/BVB-Social-Media and information is provided each time contact is made.

You can find the full text of the GDPR at https://dsgvo-gesetz.de/.