GeoBusinessIQGeoBusinessIQ

Data protection in logistics: personal data hidden inside freight records

What this answers

Which parts of a logistics operation involve personal data, and what does that require of the operator?

Logistics companies rarely think of themselves as data-heavy businesses, yet they hold consignee names and addresses, delivery signatures and photographs, driver location histories, camera footage, biometric access records and customs filings identifying individuals. Each of those attracts obligations, and the awkward ones concern employees rather than customers. Getting the roles and the retention right is most of the work. What follows is an educational overview and not advice on any jurisdiction's data protection law.

Written for: logistics compliance and legal teams, fleet and telematics managers, last-mile delivery operators.

Where the personal data actually is

Four pools dominate. Consignment records hold consignee and contact details for home deliveries and for business contacts. Delivery evidence holds signatures, photographs of doorsteps and parcels, and sometimes recipient names captured on a device. Workforce systems hold driver hours, tachograph records, telematics traces, in-cab camera footage and site access logs. Cross-border filings hold identifying details of individuals in customs and security declarations. The risk profile differs sharply between them. Consignment data is high volume and comparatively low sensitivity; workforce monitoring data is lower volume and far more sensitive, both legally and industrially, because it concerns people who did not choose to be observed.

Controller, processor and why the label matters

In European Union data protection law, the party determining the purposes and means of processing is the controller and carries the primary obligations, while a party processing on its behalf is a processor bound by a written contract with prescribed terms. A logistics provider is typically a processor for the consignment data it handles on a customer's instruction, and a controller for its own workforce data, its access control and its telematics. Companies get into difficulty when the same dataset is used for both. Using customer consignment data to build a proprietary analytics product, for example, is a purpose the provider has determined for itself, which changes the role and the obligations. Being explicit about that in the contract is far easier than resolving it after the fact.

Lawful basis, transparency and minimisation

Processing needs a lawful basis, and in a logistics setting it is usually necessity for the performance of a contract, compliance with a legal obligation such as customs or driver hours rules, or the legitimate interests of the business balanced against the rights of the individuals concerned. Consent is a poor fit for employment monitoring because it is difficult to treat as freely given. Transparency follows: individuals need clear information about what is collected and why, and workforce monitoring generally requires consultation with employee representatives where they exist. Minimisation is the practical control that reduces everything else. Collecting a signature rather than a signature plus a photograph plus a name, or setting telematics to record what is needed for safety and compliance rather than everything the device can produce, shrinks the exposure at source.

Retention, access and international transfers

Retention should be defined per dataset against the reason it exists: delivery evidence retained long enough to answer disputes and claims under the applicable time bars, customs records for the period the law prescribes, camera footage for a short defined window unless preserved for an incident, and telematics for as long as the safety or compliance purpose requires. Indefinite retention is the default failure, and it multiplies the cost of any breach. Access control matters equally: not everyone in an operation needs to see recipient addresses or a driver's location history. Where data moves outside the region, transfer mechanisms apply, which is a live issue for global logistics platforms and for cloud-hosted transport management systems with support teams in multiple countries.

Requests, incidents and vehicle cameras

Operators should have a route for handling individual rights requests, including a driver asking for their telematics or camera data, and a breach process capable of assessing and notifying within the short deadlines such laws impose. Both are easier when the data map exists in advance. Vehicle camera systems deserve their own assessment. They can be justified for safety, incident evidence and insurance defence, but forward-facing and driver-facing cameras raise different questions, continuous recording is harder to justify than event-triggered capture, and audio recording harder still. A documented assessment, a clear policy and consultation are the recognised route through. Because the requirements vary by jurisdiction, take specialist advice before deploying monitoring.

Frequently asked questions

Is a logistics provider a controller or a processor?
Commonly both, in different respects: a processor for consignment data handled on a customer's instruction, and a controller for its own workforce, telematics and access data. Problems arise when consignment data is reused for the provider's own purposes without that being addressed contractually.
Can we record drivers with in-cab cameras?
Monitoring can be lawful where there is a proper basis and it is proportionate, but driver-facing cameras, continuous recording and audio each raise the bar. A documented assessment, transparency to drivers and consultation with representatives are the expected route, and rules differ by country.
How long should delivery photographs be kept?
For as long as they serve the purpose that justified capturing them, typically the window in which delivery disputes and claims can arise under the applicable time bars, and then deleted on a schedule. Keeping them indefinitely is the most common failure and the most expensive one in a breach.

Data limitations

  • Carrier and forwarder liability depends on the contract, the mode, the applicable convention, and the jurisdiction hearing a claim. Material here is educational and is not legal or insurance advice; check your own contract terms and cover.
  • Logistics figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no freight rates, transit times, capacity, or throughput data and does not estimate them — every result reflects only the figures you enter.

Explore the graph

Sources

  • European Commission European Commission — policy and country information (accessed ; reviewed )
    Covers: EU policy framework including the VAT One-Stop-Shop and single-market rules.
    Does not cover: Member-state-specific reduced rates, national thresholds, or non-EU jurisdictions.
    Why it matters: Used for EU/EEA market-access and VAT-OSS framing referenced across rankings and guides.
    Review cadence: On policy change; re-checked each data review.

Educational and operational information only — not legal, customs, tax, insurance, or financial advice. Requirements vary by jurisdiction, commodity, and contract; confirm with the relevant authority or a qualified adviser before acting.

Last updated: