PostNL Privacy Statement

PostNL offers all kinds of services. To perform these services, we collect personal data from you. We believe it is important that we handle these data with due care. We comply with the applicable laws and regulations, such as the General Data Protection Regulation (GDPR). Below we explain what we do with your personal data. 

PostNL is responsible for the processing of all personal data that fall within the scope of this privacy statement. By PostNL we mean all companies and services with a PostNL logo that fall under PostNL Holding B.V.

In this privacy statement you will only find information about the processing of your personal data. If you have any questions or complaints about our services or products, please contact our customer service.

This privacy statement is not about how we handle personal data of job applicants or (former) employees of PostNL. This is covered by a separate privacy statement. Read how we handle personal data of job applicants.

What are personal data and how do we process them?

Personal data are data that say something about you, such as your name, address, email address or telephone number. But also data that we can link to you, such as your IP address or customer number. Some of these data are provided to us by you yourself. Other data are obtained by us if you use our services or products. Data of deceased persons are not personal data.

Special categories of personal data 

Special categories of personal data deserve more protection. This concerns genetic and biometric data, and data about your health, ethnic background, religious and political beliefs, sexual preferences, and trade union membership. Data on criminal offences, such as fraud, are also more sensitive in nature. We may process these special and sensitive personal data if:

  • you have consented to such processing;
  • this is required by law.

In this privacy statement you can read when we process special categories of personal data or sensitive personal data.

Legal bases (reasons) 

We always process personal data for a reason. The legal name for such a reason is a ‘legal basis’. These legal bases are described below. For each legal basis, we also indicate the purpose for which we process personal data and the data concerned. By processing we mean everything we do with your personal data. Such as storing, viewing, analysing, altering, deleting or transmitting them, for example. 

Legal basis: your agreement with us

You may enter into an agreement with us, for example if you buy something in our webshop (purchase agreement). To perform this agreement, we have to process your personal data. This applies to the following purposes: 

Legal basis: our legal obligation

To comply with our legal obligation, we have to process certain personal data. This applies to the following purposes: 

Legal basis: consent that you have given

Sometimes we process your personal data if you have given consent for this yourself. You can withdraw your consent at any time. This will not affect what we have already done with your consent. This applies to the following purposes: 

Legal basis: legitimate interest of PostNL

Certain services and activities are of great importance to us to perform. In that case, we have a legitimate interest in doing so. We can only perform these services and activities if we process certain personal data. This applies to the following purposes:

Who has access to personal data?

We may exchange your personal data with the companies that fall under PostNL Holding B.V. We do this for internal business processes, to perform analyses, and to provide you with services and improve them. PostNL employees only have access to personal data that are necessary for their work.

  • Sometimes it is necessary to share your personal data with other parties (see also the heading below). The main reasons for doing this are:
  • We have to be able to provide the service that is requested from us. For example, our removal service, in which you let us know which companies we have to notify of your change of address.
  • It is required by law. Examples include data from our financial (customer) records that we have to provide to the Tax and Customs Administration. We may also be required to transfer data to supervisory authorities, the police and other investigative services. Before we do this, we always check whether they are allowed to request this information from us.
  • Another company can do some of the work better. For example, a research agency that conducts a customer satisfaction survey for us. We will always make agreements with such an agency on how they are to handle your data.

Who do we share personal data with? 

We share personal data with other parties if this is necessary for the reasons set out above. This concerns two types of parties: 

How long do we retain your personal data?

We will retain your data for as long as necessary for the purpose for which we collected them. We have described this above for each separate purpose. The exact duration of the retention period depends on:

  • the purpose for which we use the data 
  • any legal obligation to retain the data 
  • a balancing between your privacy interest and our legitimate business interest 

If your data are no longer needed for the purpose for which we processed them, we will remove them or render them anonymous.

How do we secure your personal data?

We use various technical and organisational measures to secure your data. For example, we store personal data in encrypted form where possible. And we continuously invest in the security of our systems that process personal data. We also have our security checked regularly by external experts. And we have a dedicated department that monitors the digital security of our data.

Furthermore, employees may only access your personal data if they need them to do their job. All our employees have signed a confidentiality agreement. We also require our suppliers to handle your personal data with the same care and level of security as we do. And we require them to have the appropriate security certificates. 

Where do we process your personal data?

We process personal data mainly within the European Economic Area (EEA).

When sharing your data with countries outside the EEA, we make sure that they are given sufficient protection. We do this in accordance with the rules of the General Data Protection Regulation.

What are your privacy rights?

You have the right to know which personal data we have of you and what we do with those data. Below we explain what rights you have, whether there are exceptions, and how you can use this right.

Do you want to use a right? This is how you can do it:  

  • If you have a PostNL account, you will see many data we have of you. You can often change the data in the account yourself. You can also delete your PostNL account yourself at any time.
  • If you are unable or unwilling to arrange this in your PostNL account, use the access form for personal data. You will then receive a response from our Privacy Office.
  • Do you prefer sending your request by mail? Then send your request to:

    PostNL
    Legal Department, Privacy Office
    Personal data request
    Postbus 30250
    2500 GG Den Haag 

If you make a privacy request, we are obliged to make sure that we give the data to the right person. Do you use the access form? If you have a PostNL account, you do not need to add proof of identity. If you do not have a PostNL account, upload a copy of your identity document, so that we know who you are. You may render your citizen service number (BSN) illegible. Tip: use the KopieID app of the Dutch Central Government. After your request has been dealt with, we will dispose of your copy.

If you send your request by letter, add a copy of your identity document. For example, your passport or driving licence. Please note: render your BSN number invisible on the copy. And write the date on it, and why you are sending us the copy. This helps prevent fraud.

About this Privacy Statement

This privacy statement was last amended on 1 November 2024 and may be amended from time to time.

Do you have any questions about privacy?

There are 2 organisations that monitor how we process personal data: 

  • The Dutch Data Protection Authority (Dutch DPA) checks whether we comply with the General Data Protection Regulation (GDPR)
  • The Netherlands Authority for Consumers & Markets (ACM) checks whether we are handling cookies and direct marketing in a proper manner.

In addition, our own data protection officer checks whether we are handling personal data in a proper manner.

If you have any questions about how we use your personal data, please send an email to our data protection officer via fg@postnl.nl.

If you have any questions or complaints about our services or products, please contact our customer service.

If you are not satisfied with our answers to your privacy questions, you can submit a complaint to the Dutch Data Protection Authority.