2.1 Transparency of Data Processing
(1) DHL Data Controller shall inform the Data Subjects about how their Personal Data is processed. This also includes the publication of the Policy.
(2) DHL Data Controller shall provide the following information to the Data Subjects:
a) the identity and the contact details of the DHL Data Controller ;
b) the contact details of the Data Protection Officer, where applicable;
c) the purpose and scope of Data Processing;
d) the legal basis for the Data Processing:
e) where Data Processing is based on legitimate interests, the legitimate interests pursued by the DHL Data Controller or by a Third Party;
f) the recipients or categories of recipients of the Personal Data;
g) where applicable, the fact that the DHL Data Controller intends to transfer Personal Data to a Third Country or international organization and the existence or absence of an adequacy decision by the EU Commission, reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available;
h) the period for which the Personal Data will be stored, or if that is not possible, the criteria used to determine that period;
i) the existence of the right to request from the DHL Data Controller access to and rectification or erasure of Personal Data or restriction of Data Processing concerning the Data Subject or to object to Data Processing as well as the right to data portability;
j) where the Data Processing is based on consent, the existence of the right to withdraw consent at any time, without affecting the lawfulness of Data Processing based on consent before its withdrawal;
k) the right to lodge a complaint with a Supervisory Authority;
l) whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the Data Subject is obliged to provide the Personal Data and of the possible consequences of failure to provide such data;
m) the existence of automated decision-making, including Profiling and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Data Processing for the Data Subject;
n) where Personal Data have not been obtained from the Data Subject, the categories of Personal Data concerned and from which source the Personal Data originate, and if applicable, whether it came from publicly accessible sources;
o) where it is intended to further process the Personal Data for a purpose other than that for which the Personal Data was collected, the Data Subject shall be provided prior to that further Data Processing with information on that other purpose.
(3) The information may be omitted if the Data Subject already has the information.
In case where Personal Data have not been obtained from the Data Subject the information may be additionally omitted, if
a) the provision of such information proves impossible, or it would entail a disproportionate expense,
b) obtaining or disclosure is expressly laid down by local laws and regulations to which the Controller is subject and which provides appropriate measures to protect the Data Subject's legitimate interests, or
c) Personal Data must remain confidential subject to an obligation of professional secrecy regulated local laws and regulations, including a statutory obligation of secrecy.
(4) DHL Data Controller shall provide the information to the Data Subject at the time when Personal Data is collected. Where Personal Data has not been obtained from the Data Subject, information shall be provided at the latest within one month after obtaining the Personal Data, having regard to the specific circumstances in which Personal Data is processed. In case Personal Data is to be used for communication with the Data Subject, DHL Data Controller shall provide information at the latest at the time of the first communication to that Data Subject. If a disclosure to another recipient is envisaged, DHL Data Controller shall provide information at the latest when the Personal Data is first disclosed.
2.2 Fairness and Lawfulness of Processing
(1) DHL Group Companies shall process Personal Data lawfully, fairly and in a transparent manner in relation to the Data Subject, requiring that one or more of the following conditions are met:
a) The Data Subject has given consent to the processing of his or her Personal Data for one or more specific purposes.
b) The processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, including the contractual information and/or ancillary obligations, or for the implementation of pre- and/or post-contractual measures which are carried out at the request of the Data Subject for the initiation or execution of the contractual relationship.
c) The processing of Personal Data is necessary for compliance with a legal obligation to which the DHL Data Controller is subject.
d) The processing of Personal Data is necessary to protect the vital interests of the Data Subject or of another natural person.
e) The processing of Personal Data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the DHL Data Controller or the Third Party to whom the Personal Data is disclosed.
f) The processing is necessary for the purposes of the legitimate interests pursued by the DHL Data Controller or by a Third Party, except where such interests are overridden by the interests of the Data Subject which require protection.
(2) The processing of Personal Data collected in EEA regarding criminal convictions and offenses, or related security measures, based on section 2.2.1 of this Policy, may only be carried out under the control of official EEA authority or when permitted by EU law or the law of a EU Member State, which provides appropriate safeguards for the rights and freedoms of the affected Data Subjects.
2.3 General Admissibility Requirements for the Processing of Personal Data
DHL Group Companies shall comply with the data protection principles as set out below.
2.3.1 Data Minimization
DHL Group Companies shall take into account the intended purpose of the processing of Personal Data and shall process Personal Data only if it is adequate and relevant and does not go beyond what is necessary in relation to the processing. The principles of Data Processing, including the principle of data minimization, shall also apply to archived Personal Data.
2.3.2 Anonymization and Pseudonymization
Where possible and economically reasonable, DHL Group Companies shall use procedures to remove identification features that can be used to identify individual Data Subjects (Anonymization) or to replace identification features with identifiers (Pseudonymization).
2.3.3 Purpose Limitation
DHL Group Companies shall only collect and process Personal Data for specified, explicit and legitimate purposes. It may only be used for the purpose for which it was originally collected. Changes to the purpose are only admissible with the consent of the Data Subject, if permitted by local Laws and Regulations or where Data Processing for another purpose is compatible with the purpose for which the Personal Data is initially collected.
2.3.4 Consent
(1) DHL Group Companies shall obtain the consent of the Data Subject no later than the date on which the processing of Personal Data begins.
(2) The consent must be freely given, specific, unambiguous and provided on an informed basis, clearly indicating to the Data Subject the scope of Data Processing covered by the consent and the possible consequences of not giving consent. The consent language shall be sufficiently clear and inform the Data Subject of their right to withdraw their consent at any time.
(3) Consent shall be obtained in a form appropriate to the circumstances (in writing or by electronic means). Exceptionally, it may also be provided verbally if the fact that consent has been provided by the Data Subject and the specific circumstances which require that consent is obtained through an oral statement are documented. If the consent is given together with other declarations, it must be clearly highlighted.
2.3.5 Storage Limitation
DHL Group Companies shall keep Personal Data in a form which permits identification of Data Subjects for no longer than necessary for the processing purposes.
2.3.6 Processor
(1) If a DHL Group Company or an external provider process Personal Data on behalf of a DHL Group Company, the obligations of both contractual parties shall be governed by a contract meeting the requirements of applicable Data Protection Laws (Controller-Processor Agreement). The Controller-Processor Agreement shall be concluded in addition to a service agreement which may be concluded in writing or in another equivalent form. It shall stipulate, in particular, that the Processor:
a) processes Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a Third Country, unless required to do so by applicable Laws and Regulations to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless applicable Laws and Regulations prohibit such information on important grounds of public interest;
b) ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality ;
c) takes all technical and organizational measures required pursuant to applicable Laws and Regulations ;
d) respects the conditions for engaging another Processor ;
e) taking into account the nature of the processing, assists the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in section 2.6. ;
f) assists the Controller in ensuring compliance with the obligations pursuant to the applicable Laws and Regulations taking into account the nature of processing and the information available to the Processor ;
g) at the choice of the Controller, deletes or returns all the Personal Data to the Controller after the end of the provision of services relating to processing, and deletes existing copies unless applicable Laws and Regulations require storage of Personal Data ;
h) makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this section and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
(2) Without prior authorization of the DHL Data Controller, the Processor may not process Personal Data, which was passed on to it, for its own or a Third Party's purposes. The obligations set out in the Controller-Processor Agreement for the Processor shall be imposed on any Sub-Processor commissioned by the Processor. The Processor and any Sub-Processor shall be selected on the basis of their ability to comply with the obligations set out in the Controller-Processor Agreement.
(3) If DHL Group Companies enter into contracts with external Processors and/or Sub-Processors in Third Countries, adequate safeguards as stipulated under GDPR, and applicable Data Protection Laws shall be implemented with respect to the rights and freedoms of Data Subjects and the exercise of their rights.
2.3.7 Accountability
(1) Each DHL Group Company shall ensure and be able to demonstrate compliance with applicable requirements under the Policy.
(2) All DHL Group Companies must maintain a record of all categories of Data Processing activities (Data Protection Record, "DPR") carried out under the Policy. The DPR includes, as a minimum:
a) the name and contact details of the DHL Data Controller / Processor (where applicable, the joint controller, the DHL Data Controller's representative and the Data Protection Officer);
b) the purposes of the Data Processing;
c) a description of the categories of Data Subjects and of the categories of Personal Data;
d) the categories of recipients to whom Personal Data have been or will be disclosed;
e) where applicable, transfers of Personal Data to a Third Country or an international organization;
f) where possible, the envisaged time limits for erasure of the different categories of Personal Data;
g) where possible, a general description of the technical and organizational security measures.
DHL Group Companies shall ensure that all DPRs are maintained in writing, including in electronic form. For this purpose, DHL Group Companies are provided with a central documentation tool and platform known as the DHL Group Privacy Portal. DPRs shall be made available to the competent Supervisory Authority upon request.
(3) In order to demonstrate compliance, DHL Group Companies shall ensure that PIAs are conducted for all Data Processing activities involving Personal Data transferred under the Policy. In particular, a PIA shall be carried out for Data Processing operations that are likely to result in a high risk to the rights and freedoms of natural persons. For this purpose, the DHL Group Privacy Portal shall assist DHL Group Companies in fulfilling their documentation and accountability obligations and facilitate the performance of PIAs.
(4) DHL Group Company shall consult the Supervisory Authority prior to Data Processing if a PIA indicates that the Data Processing would result in a high risk in the absence of measures taken by DHL Group Company to mitigate the risk.
(5) DHL Group Companies shall adopt and implement appropriate technical and organizational measures, which are designed to incorporate data protection principles and to support compliance with the requirements outlined in the Policy. These measures should be implemented in practice, to ensure privacy by design and by default.
2.4 Special Data Processing Cases
2.4.1 Special Categories of Personal Data
DHL Group Companies shall only process Special Categories of Personal Data if it is strictly necessary and legally required or if the Data Subject has given explicit consent. DHL Group Companies must implement technical and organizational measures to ensure the security of the Data Processing.
2.4.2 Automated Decisions in Individual Cases
(1) Data Subjects have the right not to be subject to a decision based solely on automated Data Processing, including Profiling, which produces legal effects concerning them or significantly affects them. This right does not apply if the decision is:
a) necessary for entering into, or performance of, a contract between the Data Subject and a DHL Data Controller,
b) authorized by local Laws and Regulations to which DHL Data Controller is subject and which also lays down suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests, or
c) based on the Data Subject's explicit consent.
(2) The DHL Group Company shall inform the Data Subject about the existence of automated decision-making, including Profiling, about the underlying logic involved, as well as the significance and the envisaged consequences of such Data Processing for the Data Subject.
(3) In the cases referred to in paragraph (1)(a) and (c) above, the DHL Data Controller shall implement suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the DHL Data Controller, to express their point of view and to contest the decision.
(4) In the case of automated decisions based on Special Categories of Personal Data, these are only permissible if based on consent of the Data Subject or if necessary for reasons of substantial public interest, based on applicable Data Protection Laws.
2.5 Data Quality/ Security of Data Processing
2.5.1 Data Quality
DHL Group Companies shall comply with the data quality principles, such as accuracy, completeness, and relevance. The Personal Data must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. The DHL Group Companies shall take reasonable steps to ensure that inaccurate or incomplete Personal Data is erased, rectified, supplemented, or updated without delay, considering the intended Data Processing and the interests of the Data Subject.
2.5.2 Confidentiality
Only those employees who are authorized and who have committed themselves to the principles of data protection and confidentiality are permitted to process Personal Data. Any processing of Personal Data for personal benefit, unauthorized disclosure, or making it accessible in any other way which is not in line with Laws and Regulations is strictly prohibited. This includes the transfer of Personal Data to unauthorized parties or making it accessible to them in any other way. In this context, "unauthorized" parties may also include employees of the same or another DHL Group Company if the data is not required and necessary for their field of work or specialist tasks or where the Data Processing is not legitimized by Laws and Regulations.
2.5.3 Technical and Organizational Measures
When processing Personal Data DHL Group Companies shall implement appropriate technical and organizational measures to ensure the security of Personal Data, and to protect Personal Data against unlawful access, loss, destruction, or alteration. To this end and in accordance with the respective internal standards, DHL Group Companies shall implement all necessary measures.
These measures include:
- Denying access to unauthorized persons to data processing facilities where Personal Data is processed or used (entry control).
- Preventing unauthorized persons from using data processing systems (usage control).
- Ensuring that authorized users of a data processing system can access Personal Data only within the scope of their access rights, and that Personal Data stored within the data processing system cannot be read, copied, modified or removed without authorization, either during processing or use or when stored (access control).
- Ensuring that Personal Data cannot be read, copied, modified or removed without authorization during electronic data transfer or in the process of transmission or storage on data media, and that it is possible to verify and establish where the transfer of Personal Data is supported by data transfer facilities (transfer control).
- Ensuring that it can be reviewed and established retrospectively whether, and by whom, Personal Data has been provided, modified or removed from data processing systems (input control).
- Ensuring that Personal Data processed on behalf of the DHL Data Controller can only be processed in accordance with the DHL Data Controller's instructions (process control).
- Ensuring that Personal Data is protected against accidental destruction or loss (availability control).
- Ensuring that items of data collected for different purposes are processed separately (separation requirement).
- Providing possibility of pseudonymization and encryption of Personal Data.
- Providing the ability to ensure the confidentiality, integrity, availability and resilience of processing systems and services, including the ability to restore the availability and access to Personal Data.
- Provide a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures ensuring the security of the Data Processing.
2.5.4 Personal Data Breach
As stated above, confidentiality and data security are key aspects of DHL Group Data Protection Management System. However, in the event of a Personal Data Breach, the respective DHL Group Company shall document the Personal Data Breach in a dedicated register and notify it to the competent management and Data Protection Official, in accordance with the DHL Group Personal Data Breach process. Where the Personal Data Breach is likely to result in a risk to the rights and freedoms of natural persons, the respective DHL Group Company shall notify the competent Supervisory Authority (for EEA within 72 hours after becoming aware, however, might differ for other jurisdictions). When the Personal Data Breach is likely to result in a high risk to the rights and freedoms of natural persons, the respective DHL Group Company shall additionally notify the Data Subject, in accordance with applicable Data Protection Laws. In case the respective DHL Group Company is acting as a Processor it shall notify the DHL Group Company acting as a Controller when it becomes aware of the Personal Data Breach.
2.6 Rights of the Data Subject
2.6.1 General Obligations
(1) DHL Data Controller shall take appropriate measures to provide to the Data Subject information and communication relating to Data Processing in a concise, transparent, intelligible, and easily accessible form. The information shall be provided in writing, or by other means as appropriate.
(2) DHL Data Controller shall provide information or take action upon request pursuant to section 2.6.2 to 2.6.4 without undue delay and in any event within one month of receipt of the request. Where necessary, taking into account the complexity and number of requests, this period may be extended by two further months. The Data Subject shall be informed of any such extension within one month of receipt of the request, together with the reasons for the delay.
2.6.2 Right of Access
(1) Each Data Subject shall have the right to obtain from the DHL Data Controller confirmation as to whether their Personal Data is being processed and, where that is the case, to access their Personal Data and to receive additional information, including its origin, the purpose of the processing, the recipients to which it has been disclosed and where possible, the envisaged period for which the data will be stored, or the criteria to determine that period. In addition, the Data Subject shall receive access to information whether automate decision-making, including Profiling, is performed. Where this is the case, they shall receive further information about the logic involved and the significance and envisaged consequences of such Data Processing. The Data Subject shall also be informed about appropriate safeguards relating to the Data Transfer of Personal Data to a Third Country, where applicable.
(2) Upon request of the Data Subject, DHL Data Controller shall provide a copy of the Personal Data undergoing Data Processing. For any further copies requested by the Data Subject, the Controller may impose a reasonable fee for issuing such information based on administrative costs.
2.6.3 Right of Rectification, Restriction, Erasure (right to Be Forgotten), and Data Portability
(1) The Data Subject has the right to demand rectification if the data stored about the Data Subject is incomplete and/or incorrect.
(2) The Data Subject shall have the right to request from DHL Data Controller the restriction of Data Processing when:
a) the accuracy of Personal Data is contested,
b) the Personal Data is no longer needed by the DHL Data Controller,
c) the Data Processing is unlawful, or
d) where the Data Subject has objected to Data Processing according to section 2.6.4.
(3) Furthermore, the Data Subject shall have the right to request the deletion of their Personal Data if the Data Processing was inadmissible or where the Personal Data is no longer required for the Data Processing purpose, or if any other reason provided for under Laws and Regulations applies.
Where the DHL Data Controller has made the Personal Data public, it shall - taking into account available technology and costs of implementation - take reasonable steps to inform other controllers which are processing the Personal Data that the Data Subject has requested to delete any links to, or copies or replication of those Personal Data (right to be forgotten). The above obligations do not apply where Data Processing is necessary for compliance with legal obligations by Laws and Regulations which require processing.
(4) The Data Subject shall have the right to receive its Personal Data provided to the DHL Data Controller under the conditions mentioned in Laws and Regulations in a structured, commonly used and machine-readable format (data portability).
2.6.4 Right to Object
(1) The Data Subject shall have the right to object at any time to the processing of their Personal Data, which is based on public interest or the exercise of official authority vested in a DHL Data Controller or based on legitimate interests pursued by the DHL Data Controller or by a Third Party. Unless DHL Data Controller demonstrates compelling legitimate grounds for Data Processing which override the interests of the Data Subject or demonstrates necessity for the establishment, exercise, or defense of legal claims, the DHL Data Controller shall no longer process the Personal Data.
(2) Where DHL Group Companies process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to the Data Processing, which includes Profiling, to the extent that it is related to such direct marketing. In case of objection by the Data Subject, DHL Group Companies shall no longer process Personal Data for direct marketing purposes.
2.6.5 Discrimination Ban
DHL Group Companies shall treat Data Subjects fairly and equally when they assert their rights.
2.6.6 Assertion
(1) The Data Subject may at any time contact the Data Protection Official of the respective DHL Data Controller (via the request form under Privacy Notice on dhl.com) regarding the processing of Data Subject's Personal Data or with questions regarding the Policy, including where they wish to complain about the Data Processing.
(2) For inquiries and complaints by mail, Data Subjects can use the following contact address:
Deutsche Post AG Global Data Protection 53250 Bonn
The inquiries and complaints will be forwarded to the respective DHL Group Company.
(3) Data Subjects may lodge their inquiries and complaints directly against the DHL Data Controller. In such cases, the DHL Data Controller, commits to handle such inquiries and complaints without undue delay within one month of receipt of the request. Taking into account the complexity and the number of requests, DHL Group Companies may extend the one-month period at maximum by two further months, in which case the Data Subject shall be informed accordingly within one month of receipt of the request, together with the reasons for the delay.
(4) Data Subjects are duly informed of the complaint handling procedure and how to file a complaint through the Policy and the privacy notices published by DHL Group Companies on the respective websites.
(5) Notwithstanding the foregoing, the Data Subject also has the right to lodge a complaint with the competent Supervisory Authority and/or to take legal action.