Privacy policy
Data protection information pursuant to Art. 13, 14 DSGVO for the M-Login
Status: 11.08.2026
1. Responsible entity
The service provider of the M-Login (login.muenchen.de) and the party responsible under data protection law is Stadtwerke München GmbH, Emmy-Noether-Straße 2, 80992 Munich, datenschutz.stadtwerke@swm.de („SWM“). For further so-called joint controllers according to Art. 26 GDPR, see section 4.2. M-Login is offered as a website (login.muenchen.de).
2. Contact details of the data protection officer
Stadtwerke München GmbH
Data Protection Officer
Emmy-Noether-Straße 2
80992 München
E-Mail: datenschutz@swm.de
3. Processing purposes
3.1. Access to and informational use of the website
Each time you visit this website, your browser automatically sends the following data to our website server: IP address of your requesting internet-capable device; date and time of your access to the website; website/application from which the access was made (referrer URL); your browser type with version and language; operating system of your internet-capable computer; your internet service provider; the sub-websites you are visiting; files downloaded from our website (e.g. PDF or Word documents); website accessed; website previously visited.
The temporary storage of the IP address for the duration of the use of our website is necessary to provide you with our website and its contents.
In addition, the further processing of the data described in 3.1. (1. paragraph) is performed in order to optimize our website, to ensure the long-term functionality, security and stability of our website and connected IT systems and to provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack.
The legal foundation for this data processing is Art. 6 para. 1 lit. f DSGVO. The legitimate interest derives from the above-mentioned purposes of providing the content of the website accessed by the user, optimization of the website and system security and stability, as well as procedures in the event of cyber attacks.
The above data will be deleted as soon as the use of the service (use of the website) ends.
3.2 Registration for and use of M-Login
The M-Login is a single sign-on service of SWM, which provides you with clear and central user profile management as well as secure and central login (single sign-on) for connected services of the service companies ("connected services" such as HandyParken München, MVGO etc.). For details, see item 6.
In order to use the M-Login, you must register.
We process the personal data you provide during registration to fulfill the contract for the use of our single sign-on service and, upon your approval, to perform pre-contractual measures for the use of the connected services. We will check if your given address exists. The legal foundation for this is Art. 6 para. 1 sentence 1 lit. b DSGVO.
SWM will process your above-mentioned data for as long as it is necessary for the aforementioned purposes.
3.3 Payment data
You have the option to store payment details on the website. You can share these details with connected services to pay for paid services. Your approval gives the respective connected service access to the payment data listed in detail below. Processing by the respective affiliated service is governed by its privacy and data protection policy.
3.3.1 SEPA Direct Debit
If you wish to deposit a SEPA direct debit as a means of payment, we will ask you to enter the following personal data: IBAN, account holder. This data is transmitted to the payment service provider Novalnet AG, which handles the payment processing. To reduce the risk of non-payment, Novalnet AG performs a credit check. For this purpose, we transmit the following information from your profile: Surname and first name, address and date of birth. In order to be able to pay by SEPA direct debit in the respective affiliated service, you must give Novalnet AG a direct debit authorization for your account, which we also store. In addition, we process the information about the decision as to whether Novalnet AG acquires or does not acquire the claim of the affiliated service. We store this data for as long as you have deposited the SEPA direct debit as a means of payment with us.
We process the above data to fulfill the contract with you on the use of the M-Login. The legal foundation for this is Art. 6 para. 1 sentence 1 lit. b DSGVO.
You can access the data protection information of Novalnet AG here.
3.3.2 Credit card
If you wish to deposit a credit card as a means of payment, we will ask you to enter the following personal data: Card number, expiration date, cardholder if applicable, and security code. Your card type (e.g. VISA, Mastercard, American Express) is determined from the card number. This data is received directly from the payment service provider First Data GmbH. We do not have access to this data and do not store this data. As part of the strong customer authentication according to PSD2, the bank that issued your credit card may ask you for additional information that you have agreed with it. We do not have access to this data either.
After successful validation, First Data GmbH transmits the following personal data to us: a credit card replacement number, the card type, the last four end digits of the credit card number and the expiration date. We store this data as long as you have deposited the credit card as a means of payment with us.
We process the above data to fulfill the contract with you on the use of the M-Login. The legal basis for this is Art. 6 para. 1 sentence 1 lit. b DSGVO.
You can access the data protection information of First Data GmbH here.
3.4 Additions to the profile and verifications
3.4.1 Driver's license data
You have the option to store information about your driver's license on the website.
To do this, you must have us verify your driver's license. For verification, we capture and analyze photos of the front and back of your driver's license. We delete the photos no later than 90 days after the verification is completed.
After successful verification of your driver's license, we store the following personal data from this:
- Validity of the driver's license
- Driver's license number
- Place and authority of issue
- Date of issue
- Vehicle classes
- Date of birth
- Verification status
- Verification date
You can share this information with connected services if a driver's license is required to use them (e.g., car rental). Processing by the respective affiliated service is governed by its privacy policy.
We store this data for as long as you have the information on your driver's license on file with us.
We process the above data to fulfill the contract with you on the use of the M-Login. The legal foundation for this is Art. 6 para. 1 sentence 1 lit. b DSGVO.
3.4.3 Portrait Photo
You have the option to upload your portrait photo to your M-Login account if necessary.
For this, we use the service provider Visible Solutions AG. After successfully uploading your portrait photo, we store your portrait photo and the date of the upload.
You can share this portrait photo along with the upload date for connected services if required (e.g., personalization). The processing by the respective connected service is subject to its privacy notices.
We store this data as long as you have the portrait photo stored with us.
We process the aforementioned data to fulfill the contract with you regarding the use of M-Login. The legal basis for this is Art. 6 para. 1 sentence 1 lit. b GDPR.
3.4.4 Identity card data
You have the option to additionally verify your M-Login account. For verification, our service provider IDnow takes a photo of the ID card, captures it and analyses it. All photos will be deleted no later than 14 days after the successful completion of the verification.
During verification, we collect and process the following personal data from your ID card with your consent (Art. 6 para. 1 sentence 1 lit. a GDPR in conjunction with § 20 para. 2 PAuswG):
- Given name
- Surname
If available on the card, additionally:
- Address, Postal Code, City, Country
- Date of birth
- Title
- Type of ID
- ID-Number
- Issuing authority and country
- Date of issue
- Date of expiry
- Nationality
Once verification has been completed, the data will be deleted no later than 14 days after completion. This does not include given name, surname, address and date of birth, which will be stored for up to 90 days after completion of the verification.
In addition, we store the time and status of the verification. You can share this information (time and status of verification) with connected services if verification is required for their use (e.g. purchase of the Deutschlandticket). The processing by the respective affiliated service is based on its privacy policy. We will store the time and status of the verification for as long as you have stored this information with us. We process the above-mentioned data to fulfil the contract with you regarding the use of the M-Login. The legal basis for this is Art. 6 para. 1 sentence 1 lit. b GDPR.
We also process the data to prevent fraud (multiple use of ID cards, comparison with input data, detection of fake accounts). To detect multiple use of ID cards, among other things an identifier (hash value of nationality and ID number) is created and stored. The legal basis for this data processing is our legitimate interest in fraud prevention, Art. 6 para. 1 sentence 1 lit. f GDPR.
3.4.5 Family Members
You have the option of creating one or more family members in your M-Login account, including their last name, first name, date of birth, and portrait photo. To do so, you must either be the legal guardian for underage family members, or the adult family member must consent to the collection of their data.
You can share these family member profiles with connected services if they are required for their use (e.g., purchasing a ticket for a different user in the MVG customer portal). Processing by the respective connected service is governed by its privacy policy.
We store the family member profiles for as long as you have stored the information in your profile.
We process the above-mentioned data to fulfill the contract with you regarding the use of M-Login. The legal basis for this is Art. 6 (1) (b) GDPR.
3.5 Anonymization and statistical analysis
Beyond the actual performance of the contract, we process your personal data in a permissible manner in order to anonymize it for analysis purposes.
The legal foundation for this is Art. 6 Para. 1 Sentence 1 lit. b in conjunction with. Art. 5 para. 1 lit. b, Art. 89 para. 1 DSGVO.
3.6 Consents ("approvals")
3.6.1 Consents in connection with market research and advertising
During the registration process, we ask you whether you
- wish to subscribe to our emails for advertising purposes;
- consent to the processing of your data for the purpose of creating personalised offers by email.
You may also grant these consents after completing the registration process. If you give your consent (activate one or more “Consents”) on the “My Consents” page at login.muenchen.de (by activating one or more “Consents”), we will process your personal data as specified in the relevant consent form for the respective purpose (e.g. emails for advertising purposes, data matching, advertising selection, analyses, and sending offers optimally tailored to you).
Specific information regarding consent to the processing of your data for the purpose of creating and sending offers tailored specifically to you: You are free to decide whether your data may be processed for the purpose of providing personalised offers. If you give your consent to this, a data comparison will be carried out with the companies named in the consent form to ensure unambiguous identification. Provided the data comparison is successful, the companies named may analyse and select your data according to specific advertising criteria (based, for example, on contract information, order and usage history, registration and login details, interests and customer profiles, where available) and transmit the master data to us, together with information on the relevant selection criteria and your membership of specific advertising target groups. We consolidate the personal data and analyse it. The same applies to any connected services that you use via M-Login (“activated services”). An overview of the services connected to M-Login can be found here in section 6 of this privacy notice. If you are registered with M-Login, you can see on the website under “Services” which of these connected services you are currently using and which you are not. The services you use are covered by your consent.
For this purpose, we may also supplement your user profile with microgeographic data at address level where appropriate. Examples of such aggregated data, information and characteristics – some of which are estimated or calculated – include demographic information, affinities, socio-demographic and household information, building information, etc., which we derive, for example, from the most recent census published by the Federal Statistical Office. This allows us to draw conclusions, such as whether a particular address is likely to be a detached house or a block of flats, or whether there is presumably an above-average affinity for electric cars.
3.6.2 Legal basis and revocation
Where you have given your consent, the legal basis for data processing is Article 6(1), first sentence, point (a) of the GDPR.
Your consent is voluntary. You may refuse to give your consent without any adverse consequences for you or withdraw it at any time with future effect without giving reasons, either by logging in to our website and deactivating the relevant consent under “Permissions”, or by clicking the unsubscribe link contained in every newsletter, every email sent with offers tailored specifically to you, and every contact email sent for market research purposes.
By withdrawing your consent in this way, you are simultaneously withdrawing your consent to the transmission of usage data by the services you use.
3.7 Cookies
We use cookies on our website. Cookies are small text files and contain a characteristic string that enables identification of the browser when the website is accessed again.
In our Cookie Banner you can make detailed cookie settings for this website and for example, you can allow only required cookies.
3.7.1 Use of required cookies
We use technically required cookies that ensure smooth use of the website and enable numerous basic functions. You can find more information about these cookies in the data protection settings (cookie symbol) at login.muenchen.de. In addition, the following cookies are technically required for login and registration:
- MLOGIN_SESSION: expires after approx. 1 year, required for session management
- mlogin: expires after the session ends, required for session management
- mlogin-persistent: expires after approx. 6 months, required for session management
The legal foundation for the data processing is Art. 6 para. 1 lit. f DSGVO, § 25 para. 2 TDDDG. The legitimate interest to collect data derives from the purpose of providing the informational function of the website called up by the user and the simplification of the website.
You can also visit our website without cookies. If you do not want to use cookies, you can deactivate or restrict them completely in your browser. This may, however, lead to functional restrictions of our website. If you want to log in, cookies are required.
The following list provides more information on how to deactivate or manage your cookie settings in the browser you use:
3.7.2 Analysis of e-mail usage
In order to better tailor the content of our emails for advertising purposes to the interests and preferences of our subscribers and to optimise the promotional email service, we collect and analyse your use of promotional emails as follows, with your consent:
Opening the email: When and how often the email is opened is determined by a so-called tracking pixel, which is contained in the email and stored on your device along with the email. The download of the tracking pixel is counted.
Clicks: The click-through rate is determined by setting up links in the email as tracking links. This ensures that every click is recorded.
Bounces: A bounce occurs when delivery to an email address was not possible.
Unsubscriptions: Unsubscriptions via the unsubscribe link in the email are counted.
Your consent to the sending of emails for advertising purposes also covers the collection and analysis of usage behaviour (opening and clicking behaviour) as described above in connection with the newsletter (Section 25(1) TDDDG, Article 6(1), first sentence, point (a) of the GDPR). If you do not wish your usage behaviour to be analysed, you may unsubscribe from promotional emails at any time with future effect. You will find an unsubscribe link at the bottom of every promotional email.
Provided that you have given your consent as part of our bespoke offers, we analyse your usage behaviour (opening and clicking behaviour) on an individual basis in order to optimise the promotional email service for you (for example, personalisation and the implementation of follow-up campaigns) and pass this information on to the companies and activated services specified in your consent for the purposes of direct marketing activities.
The legal basis for the processing of your personal data and the analysis of the newsletter is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Unsubscribing: Your consent to the sending and analysis of emails for advertising purposes is voluntary and may be withdrawn at any time with future effect without giving reasons. You may withdraw your consent by clicking on the link provided in every promotional email or by emailing datenschutz.stadtwerke@swm.de.
3.8 Captcha
Captcha (a service of Captcha GmbH, Muthgasse 2, 1190 Vienna, Austria, acting as a processor for M-Login) helps M-Login verify whether a request is sent by a bot or a human. This detection is necessary to prevent abuse and protect the data stored in M-Login. We use Captcha to ensure the secure use of M-Login. The legal basis for this type of data processing is our legitimate interest in the secure operation of M-Login, Article 6(1)(f) GDPR.
Captcha processes your IP address during this verification, where the last 4 digits of the IP address are deleted prior to storage. Additionally, the type and model of the device, type and model of the browser, and the referrer website are recorded. A cookie or local storage value is stored in the browser. There is no further processing of the values; the value remains on the user's device at all times. Mouse movements and timing intervals of keystrokes are processed, but not keyboard inputs, multiple-choice form inputs, or user selections. Processed data are stored for a maximum of 6 months, but no personal data are stored, as the data are anonymized.
Further information on data protection from Captcha can be found at the following website: https://www.captcha.eu/dsgvo-user__de/
3.9 Compliance with legal requirements
We also process your personal data to fulfill other legal obligations. We may encounter these, among other things, in connection with the processing of a chargeable service or business communication. This includes, in particular, retention periods under commercial, trade or tax law.
We process your personal data for the fulfillment of a legal obligation to which we are subject pursuant to Art. 6 para. 1 lit. c DSGVO in connection with commercial, trade or tax law, insofar as we are obliged to record and store your data.
3.10 Enforcement of rights
We also process your personal data in order to be able to assert our rights and enforce our legal claims. We also process your personal data in order to be able to defend ourselves against legal claims. Finally, we process your personal data insofar as this is necessary to prevent or prosecute criminal offenses.
In this context, we process your personal data to protect our legitimate interests pursuant to Art. 6 (1) lit. f DSGVO, insofar as we assert legal claims or defend ourselves in legal disputes or we prevent or investigate criminal acts.
4. Recipient categories
4.1. Processor
We have carefully selected the service providers who process data for us on behalf of our instructions as processors and are thereby recipients of personal data, provide sufficient guarantees for suitable technical and organizational measures and are contractually obligated by us in accordance with Art. 28 DSGVO.
SWM regularly transfers your personal data in particular to the following order processors:
Type of processing activity: Call Center Services
Processor: SWM Kundenservice GmbH, Emmy-Noether-Strasse 2, 80992 Munich
Registered office of the service provider: Germany
Type of processing activity: E-mail dispatch, e-mail analysis
Order processor: DYMATRIX CONSULTING GROUP GmbH, Lautenschlagerstraße 2, 70173 Stuttgart
Location of the service provider: Germany
Type of processing activity: Verification of ID and driver's license data
Processor: IDnow GmbH, Auenstraße 100, 80469 Munich
Registered office of the service provider: Germany
Type of processing activity: Upload-Service Portrail Photo
Processor: Visible Solutions AG, Viaduktstrasse 93, 8005 Zürich
Registered office of the service provider: Switzerland
Type of processing activity: Bot defense, prevention of abuse, data security
Processor: Captcha GmbH, Muthgasse 2, 1190 Vienna (see 3.9)
Registered office of the service provider: Austria
If necessary, further processors are used who are not evident from the above list (e.g. for market research projects).
4.2. Jointly responsible entities
SWM will transfer your personal data – provided you have given your consent and wish to use the relevant connected services (see section 6) via M-Login – to the following “joint controllers”:
- Münchner Verkehrsgesellschaft mbH (MVG)
- SWM Versorgungs GmbH
- Heyroom Limited (Ltd.)
In connection with the bespoke offers, we are also joint controllers with the following companies:
- SWM Versorgungs GmbH
- Munich Transport Company (MVG)
- M-net Telekommunikations GmbH
SWM will be happy to provide you with the key details of the joint responsibility agreements with the above-mentioned companies. To obtain these, please use the contact details provided in section 1.
4.3. Further recipients
Within SWM, access to your data is granted to those offices that need it for the purposes described. To the extent permitted by law (for example, as part of a contract processing), we may disclose personal data to third parties in the following categories:
- (IT) service provider
- Customer service provider
- Logistics
- Print service provider
- Sales partner
- Payment service provider
- Collection service providers and lawyers
- Public bodies and institutions (e.g. social insurance entities, financial authorities, police, public prosecutor's office, supervisory authorities) if there is a corresponding obligation/authorization
5. Transmission to third countries
For certain tasks, we use (IT) service providers who also use (IT) service providers who may have their headquarters, parent company or data center headquarters in a third country (outside the European Union and the European Economic Area).
The following must be given: The transfer is permissible because there is a legal authorisation or you have expressly consented to the transfer and the special requirements for a transfer to a third country are met. This means, in particular, that the European Commission has decided that there is an adequate level of data protection in the third country (Art. 45 GDPR) or that appropriate safeguards (e.g. through so-called EU standard contractual clauses specified by the European Commission or the supervisory authority) and that enforceable rights and effective remedies are provided.
6. Separate data protection information when using the connected services
In order for you to use the services connected to M-Login and offered by the service companies (selected service apps and websites), in the case of service apps it is necessary that you download the app for the respective service beforehand. When using the connected services, their data protection information must be observed. You can find this information at:
HandyParken München App (handyparken-muenchen.de)
Provider (service company): Münchner Verkehrsgesellschaft mbH (MVG)
Offer: Purchase of parking tickets
Privacy information
M-Bäder Webshop (m-baedershop.swm.de)
Provider (service company): Stadtwerke München GmbH
Offer: M Baths Gift Certificate
Privacy information
Meine SWM (meine.swm.de)
Provider (service company): SWM Versorgungs GmbH
Offer: SWM Versorgungs GmbH Customer portal
Privacy information
MVG Abo Kundenportal (mvg.de)
Provider (service company): Münchner Verkehrsgesellschaft mbH (MVG)
Offer: Public transport
Privacy information
SWM more (more.swm.de)
Provider (service company): Stadtwerke München GmbH
Offer: digital management of the products M-Ladelösung, M-Partnerkraft, M-Solar Sonnenbausteine and C/sells
Privacy information
MVGO (mvg.de/mvgo)
Provider (service company): Münchner Verkehrsgesellschaft mbH (MVG)
Offer: Mobility
Privacy information
heyroom (https://www.heyroom.app/)
Provider (service company): HEYROOM LIMITED
Angebot: Studenten WG's
Privacy information
SWM Energiepilot App (swm.de/m-energiepilot)
Provider (service company): SWM Versorgungs GmbH
Angebot: Home-Energiemanagement-App der SWM Versorgungs GmbH
Privacy information
7. Storage duration
Unless otherwise specified, we delete your personal data after storage is no longer necessary (e.g. after final response to your request, for the duration of the contractual relationship with you until its final termination), or - in the case of statutory retention obligations - restrict processing. Please note that further processing is required in particular for:
- Fulfillment of statutory retention obligations, which may arise from the German Commercial Code (HGB) and the German Fiscal Code (AO), for example. The periods specified therein are up to ten years.
- Preservation of evidence under statutory limitation provisions. According to Sections 195 et seq. of the German Civil Code (BGB), these limitation periods can extend up to 30 years, with the regular limitation period being 3 years.
8. Your rights
According to Art. 15 DSGVO, you have the right to request information at any time about which personal data we have stored about you. This also concerns the recipients or categories of recipients to whom this data is passed on and the purpose of the storage. You can at any time, under the conditions of Art. 16 DSGVO demand the correction and/or under the conditions of Art. 17 DSGVO demand the deletion and/or - under the conditions of Art. 18 DSGVO – request the restriction of processing. Furthermore, you can request data transmission at any time in accordance with Art. 20 DSGVO.
You have the right to object to the processing of your personal data if the conditions specified in Art. 21 DSGVO apply.
You can exercise your data protection rights vis-à-vis: Stadtwerke München GmbH, Emmy-Noether-Strasse 2, 80992 Munich, datenschutz.stadtwerke@swm.de. Alternatively, you can also use our login-protected information service at https://login.muenchen.de/ui/portal/secure/dsgvo for your data information regarding M-Login.
In addition, according to Art. 77 DSGVO, you have the possibility to lodge a complaint with a data protection supervisory authority.
Right to withdraw consent: You can revoke your consent to the processing of your data at any time for the future. This also applies to declarations of consent that were issued before the DSGVO came into force, i.e. before 25.05.2018. Please send your revocation to: Stadtwerke München GmbH, Emmy-Noether-Strasse 2, 80992 Munich, datenschutz.stadtwerke@swm.de
9. Automated decision making
As a matter of principle, we do not use automated decision-making pursuant to Art. 22 DSGVO. Should we use these procedures in individual cases, we will inform you of this separately within the framework of the legal provisions.
10. Modification clause
As our data processing is subject to change, we will adjust our privacy notice from time to time. Amended privacy notices will be published on our website. Unless otherwise specified, such amendments shall take effect immediately. Therefore, please check this privacy notices regularly to view the most current version.