Blog Trust May 2026

GDPR in last-mile delivery: what SMBs need to know

A delivery business handles personal data all day long — names, addresses, phone numbers, photos of doorsteps, live GPS positions. Here is what that means in practice, without the legal fog.

GDPR in last-mile delivery: what SMBs need to know

Delivery data is personal data

Every order in your system contains personal data of at least two people: the sender and the recipient. Address, phone number, sometimes an entrance code and a "leave at the blue door" note. Add proof-of-delivery photos and courier GPS tracks, and a courier company processes more personal data per day than most small businesses do in a month.

GDPR applies if you deliver to anyone in the EU — regardless of where your company is registered. And increasingly, it is not the regulator who asks first: it is your business clients' procurement checklist. "Where is our data hosted?" and "Are you GDPR compliant?" are standard questions in B2B deals now. No answer means no deal.

The questions you need answers for

  • Where is the data hosted? Know which provider and region your platform uses. "On a PC in our office" is an answer that ends conversations.
  • Who can access it? Role separation matters: a courier should see their route — not your entire client base. In RutaLive, couriers see only their assigned orders, and each company's workspace is fully isolated.
  • How long is it kept? Data retention should be defined, not "forever, because nobody ever deleted anything."
  • Can a person get their data deleted? Access, correction, deletion, portability — the four rights you must be able to honor.
  • Is tracking consent-based? Website analytics and pixels should load only after consent. Courier location tracking should run only during active deliveries — and stop after.

Location tracking done right

Courier GPS is the most sensitive data stream in delivery. The compliant pattern is simple: track during work, not around the clock. In RutaLive, tracking starts when the courier taps "Pickup" and stops automatically when the last active delivery is completed. Recipients see the courier's live position only while the courier is actually on the way — and the public tracking link closes itself after delivery.

Proof of delivery and privacy

POD photos are personal data too — they show doorsteps, sometimes faces. Two rules keep you safe: capture only what is needed to prove delivery, and store it in a system with access control rather than in a courier's personal phone gallery. A platform that keeps POD inside the order record — geo-tagged, time-stamped, visible only to the right roles — solves this by design.

What to do this quarter

  • Write down what personal data you collect and where it lives. One page is enough to start.
  • Publish a privacy policy that matches reality — not a template that mentions tools you don't use.
  • Move customer data out of spreadsheets and messenger chats into a system with roles and access control.
  • Ask your software vendor the five questions above. If they can't answer, that is your answer.

This article is practical guidance, not legal advice — for a formal assessment, talk to a data-protection professional.

Try it yourself

See RutaLive on your own scenario

Start free with two couriers, or book a 30-minute walkthrough — live map, dispatch, and proof of delivery on a real route.