‹ All sectors

Sector reference

DPDP for Ports, Logistics, Transport and Warehousing

What is processed
Driver licences and photographs, vehicle and trip records, gate passes, consignee names, phone numbers and delivery addresses, and the tracking link sent to the person waiting for the consignment.

Why it is allowed, and when

The consignee's details move because the consignment does. Where the sender decides the purpose and the transporter simply carries out the delivery on those instructions, the transporter is a processor and the Act requires a contract between them. Driver records sit under employment, or under the contract with the fleet owner who employs them.

Where the permission stops

A delivery address is given for a delivery. It does not become a marketing database, and it does not stay live once the retention that tax and transport records require has run its course.

Questions people actually ask

Whose data is the consignee's name and address, ours or the sender's?

It is the consignee's data. The question you are really asking is which role you occupy. Where the sender decides why the delivery happens and you carry it out on those instructions, you are its processor and there has to be a contract. Where you decide things for your own purposes, you are a fiduciary.

Either way you hold personal data, so security, breach handling and retention apply to you.

A driver lost a printed manifest with fifty consignee names. Is that reportable?

A purely paper document sits outside the Act, which applies to digital personal data and to non digital data that is digitised subsequently. So the printed sheet alone is not the trigger.

In practice it almost always is digital too, sitting in your system and often photographed on a phone. Once it is, an accidental disclosure or loss of access is a personal data breach, and there is no minimum size below which reporting is excused.

Can we keep delivery history to offer the consignee our own services later?

Not on the delivery basis. Those details reached you so a consignment could arrive, and voluntary provision is limited to the purpose for which the data was provided.

Marketing to that person is a fresh purpose. It needs her consent, obtained for that purpose, and if you are acting as the sender's processor you would also be stepping outside your instructions by doing it.

What people get wrong

The consignee is our customer's customer, so their details are not our problem.

If you hold it, you process it. Whether you are the fiduciary or the processor decides which duties you carry, not whether you carry any at all.

Tracking our drivers needs their permission.

Tracking a driver during work is employment processing, and it is also related to safeguarding the employer from loss. Permission is not the basis, so asking for it and then relying on it leaves you worse off, because it can be taken back.

A lost delivery sheet is not a data breach, it is a piece of paper.

The Act covers digital personal data, so a purely paper record sits outside it. The moment it is scanned, photographed or keyed into a system it is inside, and an accidental disclosure of it is a reportable breach with no minimum size.

We can pass the consignee's number to anyone in the chain.

Only where each hand in the chain has its own basis, and where anyone acting on your behalf is bound by the contract the Act requires. Passing it onward without either is unauthorised processing.

Related questions

This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.