A customer orders a jacket. By the time it reaches their door, their name and address may have passed through an online store, a shipping platform, a warehouse and a carrier. Someone may also have downloaded a spreadsheet to deal with a delivery problem.
That journey deserves as much attention as the parcel itself. Cloud shipping software can reduce copying between systems, but the business still needs to understand where customer information goes and who can use it.
For businesses subject to GDPR, the practical questions start well before the first label is printed.
Table of Contents
A cloud shipping platform brings shipping tasks into a browser, from preparing labels to checking delivery progress. Rollo Ship is one example of a cloud shipping platform for small businesses.
Before connecting any platform, examine an actual order import. Does it contain only delivery details, or does it also include customer notes, purchase history and information nobody in the packing team needs?
For example, a retailer selling through Shopify and taking some orders by invoice could trace one test order through every connected system. Write down what each service receives. Include exported files and printed labels in that exercise; they are easy to overlook once the online dashboard looks tidy.
GDPR can apply to businesses established in the EEA and to certain processing by businesses elsewhere that target people in the EEA or monitor their behaviour there. A supplier’s location alone does not settle the question. The European Data Protection Board’s explanation of GDPR scope sets out the starting points.
For ordinary retail fulfilment, the merchant will commonly be the controller: it decides why customer information is needed and the essential means of using it. A shipping platform may act as its processor when following the merchant’s instructions.
The role depends on the activity. A provider making its own decisions about separate uses of personal data may be a controller for those uses. Assess carriers separately, too. Calling every supplier a processor can leave responsibilities incorrectly assigned.
Where there is a controller–processor relationship, Article 28 requires a binding processing agreement. It should address instructions, confidentiality, security, subprocessors, assistance with individuals’ rights, incident support, audits and what happens to the data when the service ends. The EDPB’s controller and processor guidance explains these responsibilities.
Ask for that agreement during supplier selection. A privacy page or a reassuring sales email should not be the only document on file.
Using a customer’s address to deliver something they bought can normally be necessary to perform the sales contract. That does not automatically justify using the same information for advertising or an unrelated analytics project. Each purpose needs an appropriate lawful basis. See the EDPB’s guidance on lawful processing.
This is worth checking when a platform adds new automation. Rate comparison and order grouping raise different questions from reusing identifiable purchase histories to develop another product. Ask what information the feature uses, whether it is optional and whether the provider uses that information for its own purposes.
Billing needs the same attention. A business using a Word invoice template from Zintego should consider where completed invoices are saved and who receives them. An invoice may contain personal information even when it never enters the shipping dashboard.
Privacy by default means limiting personal data to what is necessary for the particular purpose. The EDPB includes the amount collected, access and storage duration in its guidance on data protection by design.
Applied to shipping, that suggests a useful review:
Do this before importing the entire order history. It is easier to leave an unnecessary field disconnected than to find every copy after months of shipments.
A temporary packer and the person managing refunds have different jobs. Their accounts should reflect that. Use individual logins, restrict bulk exports to people who need them and remove access when someone leaves. These are practical applications of the EDPB’s security guidance.
Ask the supplier to demonstrate permissions during a trial. Can a warehouse account download the whole customer list? Can it change account settings? Who can see activity logs?
Enable the strongest suitable MFA option available. The NCSC explains why multi-factor authentication matters for account access, including the weaknesses of relying on passwords alone. That guidance supports using MFA; it does not verify which controls a particular shipping provider offers.
Remember the packing bench as well. A discarded label or an unattended shared screen can expose customer details after the software has done its job correctly.
A parcel’s destination and the location of its data are separate questions. Ask where the platform hosts customer records, which other companies process them and whether overseas support teams can access them.
Where a transfer falls under GDPR’s international-transfer rules, an applicable adequacy decision or appropriate safeguards may provide the route. Standard contractual clauses can be relevant, together with a transfer assessment and supplementary measures where needed. The EDPB’s international-transfer guidance explains the options.
Check the specific recipient and processing arrangement. A provider’s US or Canadian address is not enough to establish that every transfer is covered. Nor does a European hosting location answer every question about access by a separate overseas organisation.
UK businesses should also check the separate UK GDPR transfer requirements where those apply.
A successful delivery does not mean every related record should disappear immediately. Tax obligations, returns and disputes can justify keeping particular information. Equally, they do not justify retaining every label, export and delivery note indefinitely.
Set retention periods by purpose, document the reasons and remove or anonymise personal information when it is no longer needed. These duties follow the GDPR principles of storage limitation and accountability.
Before signing up, ask how deletion works in the live system, backups and connected services. Check what you can retrieve when closing the account. A cancellation button tells you little about the customer records left behind.
A customer asking for their information should not trigger a hunt through forgotten accounts. Staff need a way to locate relevant order, invoice and shipping records, correct errors and assess deletion requests.
Under EU GDPR, rights requests generally require a response within one month. A permitted extension requires notice within that first month. Erasure is not absolute; some records may need to remain for legal obligations or claims. The EDPB’s guide to individuals’ rights explains the conditions.
Test the process with a dummy order. Knowing which button exports a customer’s information is more useful than discovering its limitations after a request arrives.
A customer spreadsheet emailed to the wrong person can be a breach, even without a hacker. Have a named contact, an escalation route and a way to preserve the facts.
Processors must notify controllers of personal data breaches without undue delay. Controllers must notify the relevant authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to risk people’s rights and freedoms. High-risk breaches generally also require prompt communication to affected people. All breaches must be documented. See the EDPB’s breach guidance.
Before switching platforms, run one order through checkout, fulfilment, a return and deletion. Ask the people doing the work where they still need spreadsheets or shared passwords. Those answers will show what needs fixing before a busy week puts the new system under pressure.