ZPVS Daten bei Ticketkontrolle

Datum: 25.04.2023 | Public Transport Information

What does the ZPVS do?

With the Deutschland-Ticket, there is no issuing transport authority to manage the PV system behind the scenes. That is why we take care of this via the ZPVS.

Normally, a transport authority, acting as the product owner, issues a ticket, sets the price and operates a system for managing the tickets. With the Deutschland-Ticket, this role does not exist in this form. The price, validity and general conditions were determined at a political level.
We have therefore taken on the technical role: we do not deal with fares or prices, but rather ensure that the systems running in the background function smoothly.
On 25 April 2023, we launched the Central Public Transport System (ZPVS) as a new component of the central background systems for ((eTicket Deutschland. The ZPVS forms part of our security management and, amongst other things, can provide important information on the exact number of all D-Tickets to the revenue-sharing system. 


How the ZPVS works technically

The ZPVS is therefore primarily a monitoring system that detects forgeries, copies and compromised keys used for ticket issuance. For each electronic ticket, an issuance transaction with a unique number is generated. Every inspection generates an inspection record, which is also assigned a sequential and unbroken number. The ZPVS receives all issue transaction records and the relevant inspection records for national fare products. This creates a complete history, ensuring that tickets are issued and used correctly. It can
also provide issue and usage data for revenue sharing. Only when it is known how many tickets have been issued and used can revenue be correctly allocated between transport operators and transport associations. The ZPVS provides the technical basis for this whilst also ensuring that the sector’s revenue is protected by detecting and preventing misuse.

Data protection at the ZPVS

All data records sent to the ZPVS are pseudonymised and transmitted in encrypted form via a dedicated, secure network.
Customer data and transaction data are stored separately. This prevents the two from being combined to create a travel profile. The data may only be combined for the purposes of billing or handling complaints by the transport operator or transport association.

The D-Ticket is personalised and non-transferable. It contains the passenger’s data required for validation, such as surname, first name, date of birth and, optionally, gender (although this is generally no longer processed). 

The SCE-ID, a static identifier for the digital user device used for copy protection purposes, is only stored on the user device when using Motics (smartphone tickets with a dynamic barcode). Data processing is carried out in accordance with the GDPR, whilst safeguarding passengers’ rights (Article 6(1)(f) of the General Data Protection Regulation, GDPR).

In addition, the period of validity (currently the relevant month) and the geographical scope of validity (in this case, Germany) are recorded.

The data from the issue and inspection records is stored in the central PV system and by the selling company. It is important to distinguish between the data processed by the transport company issuing the ticket and the system data stored in the ticket and the inspection records for the purposes of monitoring and system security.

Our ZPV system contains only pseudonymised data. The location details of the selling company are entered as the location for the ticket issue transaction.
If the ticket is purchased in Berlin, the location is therefore not the passenger’s place of residence, but Berlin. During ticket inspections, the so-called ‘Germany-wide stop ID’ (DHID) is entered into the inspection record.
 

The transport operators that issue the Deutschland-Ticket store data relevant to the purchase and billing process, such as the passenger’s name, address and bank details. This data is held in separate subscription or customer relationship management systems.

The data relating to a ticket inspection record is deleted from the ZPVS once all checks on the record have been carried out and the result is positive (no irregularities). Only certain basic details of the inspection record remain stored on the user’s medium (chip card). The storage of these inspection transactions on the chip card is necessary for the purposes of consumer protection, so that a passenger can view the most recent transactions carried out using their chip card. 
This data processing, as practised, is accepted by the data protection supervisory authorities. The entries in the application log on the smart card can be deleted at any time at the customer’s request. Only ten transaction records can be stored automatically; these are overwritten as new entries are made (circular storage).

ZPVS Head Office

If you’re having problems with the ZPVS, you can create a ticket here regarding ZPVS Control Centre monitoring.

To the ZPVS headquarters