GDPR applies to any organisation processing personal data of EU and UK residents, regardless of sector. Logistics organisations face a specific configuration of obligations shaped by the personal data they collect, the regulatory environment they operate in, and the systems they use to do it.
This page covers the GDPR obligations specific to Logistics, the lawful bases that apply, and the implementation approach that survives supervisory authority scrutiny.
Regulatory context
Supervisory authority: National supervisory authorities
Key personal data categories: driver location data, recipient delivery addresses, shipment manifests, customer contact data, B2C recipient personal data
Special category data present: Typically no — standard Article 6 lawful bases apply
Primary lawful bases: Contract (with retail clients), Legitimate Interests (delivery optimisation, fraud prevention)
Last-mile delivery services increasingly use subcontracted couriers or gig-economy drivers. Where the driver is an independent contractor rather than an employee, the processor chain includes an additional party — the delivery platform or agency — and an additional Article 28 agreement is required. Many logistics GDPR audits find this sub-processor layer is not covered by a written agreement.
The hard part
B2C delivery data is collected on behalf of the retailer (the controller), making the logistics company a processor. The data subject exercises rights against the controller (retailer), who must forward the request to the logistics processor within the required timeframe. The Article 28 agreement and DSAR workflow must be designed for this three-party structure.
This is the implementation decision that most Logistics GDPR programmes get wrong. It is also the issue most likely to appear in a supervisory authority audit or a data subject complaint.
Required controls
- Article 28 agreements with retail clients covering DSAR forwarding obligations and response timelines
- Driver location data minimisation: aggregate after delivery confirmation
- Recipient data retention limited to delivery confirmation window plus returns period
- DSAR workflow with retailer-forwarding mechanism and tracked response deadlines
- Cross-border transfer mechanisms for international shipment data
GDPR gap assessment framework for Logistics
A gap assessment for a Logistics organisation covers five areas:
1. Data inventory and ROPA
Map every system that holds personal data specific to Logistics operations: driver location data, recipient delivery addresses, shipment manifests, customer contact data, B2C recipient personal data. Document the purpose, lawful basis, retention period, and third-party recipients for each. The ROPA must be current — a snapshot taken at implementation and not updated is not compliant.
2. Lawful basis audit
For each processing activity, confirm the lawful basis is documented and appropriate. Logistics organisations frequently find that processing that was assumed to be covered by legitimate interests has not had a Legitimate Interests Assessment completed. Where special category data is present, Article 9 requires a separate documented basis.
3. Consent management
Where consent is the lawful basis, verify that consent records meet GDPR Article 7 requirements: freely given, specific, informed, unambiguous, and withdrawable. Legacy consent from before the current privacy notice version should be assessed for adequacy.
4. DSAR readiness
Test the DSAR workflow with a synthetic request. The test should cover: intake, identity verification, data discovery across all systems identified in the data inventory, response assembly, and delivery within the 30-day deadline. Most Logistics DSAR gaps are discovered at the data discovery stage — systems that hold personal data but are not connected to the DSAR workflow.
5. Breach preparedness
Verify the incident log, the severity classification matrix, and the 72-hour notification workflow. The Logistics-specific question is: which data categories, if breached, trigger notification to individuals (not just to the supervisory authority)? Notification to individuals is required where the breach is likely to result in high risk to their rights and freedoms.
Implementation priority order
For Logistics organisations starting a GDPR programme:
- Data inventory — identify all systems holding personal data before configuring any controls
- Lawful basis documentation — stop processing for which there is no documented basis
- DSAR workflow — rights requests can arrive at any time; the workflow must be operational before launch
- Consent remediation — address legacy consent before running any marketing to the affected population
- ROPA — live, connected to source systems, reviewed quarterly
- Breach procedure — tested annually; DPO and legal team both trained on the 72-hour obligation