Phone numbers, addresses, email and purchase histories can be personal data wherever they are stored. Providing a phone for delivery does not by itself resolve consent for marketing. Identify what is collected, why, who can access it and retention needs before applying PCPD's guidance.
What to have ready
Separate fulfilment from marketing
Collect fields necessary for fulfilment and related purposes and provide an appropriate collection notice about uses and transfers. Direct marketing has separate notification and consent requirements; consent to provide data to another person for direct marketing must be in writing. Payment, prize entry or collection should not be treated as unlimited promotional authority. Build a working process for a request to stop direct marketing, rather than merely displaying an unsubscribe link that staff cannot access or use.
For example, a shop can keep delivery details with the order while recording a clear choice about specified marketing, its date and the accompanying notice. This illustrates a process rather than a ready-made clause guaranteed to comply. Avoid treating a vague partner-offers checkbox as permission for unrestricted sharing. Where a delivery supplier needs an address, share necessary information and confirm responsibilities, protection and retention instead of sending the customer's complete purchase history for convenience.
Manage access even in a small team
Avoid a cloud sheet readable by anyone holding the link. Give access according to work and remove it when employment or a supplier relationship ends. Backups and exports contain data too; a personal phone or public group can introduce further exposure. Before a new CRM, AI tool or overseas cloud, check the supplier and actual processing arrangement. Test with fictional customers rather than uploading the existing customer list to an unfamiliar website to see whether its features are convenient.
Define a retention reason for each record: tax evidence and delivery details need not share a period. Retain legally required material while handling other data according to purpose and applicable requirements, rather than claiming every field may be kept arbitrarily for seven years. Appoint a person to handle access, correction or a suspected breach through the appropriate process and retain the timeline and response. For individual advice, explain the data flow and terms instead of asking only whether an app is safe.
What to do, step by step
- Map data from order entry through payment, support and delivery, then remove unnecessary fields. Do not ask for an identity-document copy without an established need for an ordinary delivery. Distinguish required from voluntary information, explaining what happens if an optional field is left blank.
- Before collection, clearly explain purposes, recipient classes and access/correction channels. Separate membership arrangements from marketing choices and keep evidence of the customer's actual selection and notice version. A hidden preselected box or an internal assumption is a poor basis for explaining what the customer agreed to.
- Give staff access according to their tasks, and address security, retention and deletion with delivery and system providers. Enable strong account protection. Avoid full customer spreadsheets in personal chat groups or unrestricted links. Test whether a support worker can complete a task without seeing unrelated identity or payment details.
- Establish processes for marketing opt-outs, access/correction requests and incidents with a named contact. Review permissions and old data monthly. Assess tax-record retention separately from unnecessary personal details so that a legitimate invoice requirement does not become an excuse to retain every unrelated profile field forever.
A practical example
A florist collects a phone number and address for delivery. The driver receives only the day's required details, which are removed according to the agreed arrangement afterwards. Festival promotions use a separately assessed direct-marketing process, with opt-outs reflected in a suppression list. Invoice retention and promotional lists are managed separately; keeping tax evidence for seven years does not automatically justify retaining every chat attachment.
Clarify purpose and consent, restrict access, and make retention and opt-out procedures work.
Official information and enquiries
These are the reference and service entry points for this guide. Check current fees, eligibility, and schedules with the authority. The preparation date is not each source's official update date.