To collect addresses for corporate gifts, first define the delivery purpose and your organisation's lawful basis. Ask only for the fields the carrier and fulfilment partner genuinely need, tell recipients how their data will be used, restrict access, validate the list before dispatch and set a deletion date. Do not start with a spreadsheet and decide the privacy process afterwards.
A home or office address linked to a named person is personal data. The GDPR therefore applies to the collection, sharing, correction, storage and deletion of the list. This checklist helps HR, operations and marketing teams organise that work; it is not legal advice. Your privacy lead or legal adviser should confirm the approach for your organisation and campaign.
The address-collection checklist
- Name the purpose. Write one sentence explaining why the data is needed, such as “to deliver the approved year-end gift to each eligible employee”. Do not reuse the list for marketing or another campaign without assessing that separate purpose.
- Confirm the lawful basis. Do not assume that consent is always required or always suitable. The GDPR provides several lawful bases, and the correct one depends on the relationship and circumstances. Record the basis your organisation has selected and why.
- Define the roles. Identify who decides why and how the campaign runs, who handles data on that organisation's instructions, and which carriers or other sub-processors are involved.
- Collect the minimum. Start with recipient name and the delivery fields required for the destination. Add email or telephone details only when the delivery method genuinely requires them.
- Give clear information. Tell recipients who is using the data, for what purpose, who will receive it, how long it will be kept, how to exercise their rights and where to ask questions.
- Use a controlled collection method. Prefer an approved form or restricted shared file with named access. Avoid sending unprotected address sheets as ordinary email attachments.
- Validate before sharing. Check missing house numbers, postcode formats, country, duplicate recipients and recent moves. Give one named person responsibility for corrections.
- Share only what each party needs. A carrier may need a delivery address and contact detail; a designer does not. Keep message-writing and dietary data separate from the main address list where practical.
- Set retention and deletion dates. Decide how long the working list is needed for delivery, returns and agreed follow-up. Remove access and delete or return temporary copies when that purpose ends, subject to applicable record-keeping duties.
- Prepare for mistakes. Establish who must be contacted if a list goes to the wrong person, a device is lost or an unauthorised person gains access. Do not wait for an incident to decide the route.
Which fields belong in the delivery file?
| Field | Typical decision | Reason |
|---|---|---|
| Recipient name | Usually needed | Identifies the recipient for packing and delivery. |
| Street, house number, addition, postcode, city and country | Needed for individual delivery | Allows the carrier to route the parcel. |
| Company and department | Only for workplace delivery when useful | Helps a reception or mailroom route the parcel. |
| Email or mobile number | Only if the chosen carrier or delivery process needs it | May support delivery notifications or exception handling. |
| Employee number or internal ID | Use a campaign reference where possible | Can support reconciliation without exposing unnecessary HR identifiers. |
| Gift choice | Use only for an approved limited-choice campaign | Directs the correct concept to the recipient. |
| Dietary or allergy information | Handle separately and cautiously | It may reveal health or religious information and can require additional safeguards. |
| Date of birth, salary, job performance or unrelated profile data | Leave out | It is not needed to deliver a gift. |
The European Data Protection Board explains that personal data must be adequate, relevant and limited to what is necessary, accurate, kept only as long as needed and processed securely. Its data-protection basics provide a useful primary reference for these principles.
Do not default to consent
Consent is one possible lawful basis, but it must be freely given, informed, specific and unambiguous, and the person must be able to withdraw it without negative consequences. That can make consent unsuitable where an organisation cannot genuinely offer a choice. The EDPB's lawful-processing guide describes the available bases and their conditions.
Ask the campaign owner to document the chosen basis before collection begins. If addresses come from HR records or a client contact rather than directly from recipients, confirm how the required privacy information will reach the people concerned. Keep the notice short enough to understand, but link to the organisation's complete privacy information.
Map the hand-offs and contracts
A corporate gift campaign often involves the employer or client, a gifting partner and one or more carriers. The party that decides the purpose and essential means is generally the controller; a supplier acting only on its instructions is generally a processor. Roles depend on the actual arrangement, not the labels used in a proposal.
Before sharing the list, confirm the instructions, confidentiality, security, permitted sub-processors, incident notification, assistance with rights requests and what happens to the data after the service. The EDPB's controller and processor guide summarises these responsibilities and the points a processing contract should cover.
A simple hand-off map can make gaps visible:
- HR or the campaign owner approves eligibility.
- Recipients provide or confirm the minimum delivery details.
- One authorised data owner checks and freezes the dispatch version.
- The fulfilment partner receives only the approved fields.
- The carrier receives the subset needed for delivery.
- Corrections, returns and incidents go back through named contacts.
- Working copies are deleted or returned on the agreed date.
For larger campaigns, also separate the data deadline from the production and delivery timeline. Last-minute list changes create both fulfilment errors and uncontrolled copies.
Make the working file safer
For recurring corporate programmes, Coral & Clay recommends a secure shared spreadsheet rather than multiple emailed versions. The right platform and settings are your organisation's decision. At a minimum:
- give named users individual access and remove it when their role ends;
- limit download, forwarding and local copies where the approved tool allows it;
- use one controlled source list and a visible version or freeze date;
- keep the link out of broad channels and meeting notes;
- record who may correct, export and send the dispatch file;
- use multi-factor authentication where available;
- agree how recipients can correct an address quickly;
- delete test exports and superseded lists, not only the final file.
The EDPB recommends risk-appropriate technical and organisational measures, including access control, unique user accounts, review of permissions and encryption where appropriate. See its practical guidance on securing personal data.
Keep preferences out of the address sheet
A delivery list is not a recipient profile. If the campaign offers a small number of approved concepts, store only the choice needed for fulfilment. Avoid free-text notes about health, religion, family circumstances or why somebody chose an option. Dietary and allergy information can reveal special-category data, so involve the privacy lead and collect it only when the campaign genuinely needs it.
If you do not need individual preferences, use one inclusive concept or a small set of neutral alternatives. Our guide to personalising corporate gifts at scale shows how to create useful variation without building unnecessary profiles.
Plan corrections, returns and incidents
Address accuracy is both a delivery issue and a data-protection principle. Validate the list before dispatch, request corrections through the approved channel and record which source is current. If a parcel is returned, notify the campaign contact and avoid keeping the address indefinitely “in case it is useful later”.
If personal data is sent to the wrong recipient, exposed through an open link or lost with a device, follow the organisation's incident process immediately. Controllers must document personal-data breaches and, where a breach is likely to create a risk to people, may need to notify the relevant authority within 72 hours. Processors must notify the controller without undue delay. The EDPB's data-breach guide explains the decision process. Do not delay escalation while trying to solve the delivery problem.
Final campaign check
- The purpose and lawful basis are documented.
- Recipients receive clear privacy information.
- Controller, processor and sub-processor roles are confirmed.
- The file contains only necessary delivery fields.
- Access is limited to named people.
- Addresses are validated before dispatch.
- The supplier and carrier receive only the fields they need.
- Correction, return and incident contacts are named.
- Retention and deletion dates are agreed.
- The privacy or legal owner has reviewed any uncertainty.
Once your internal data process is agreed, Coral & Clay can develop the gift concept, presentation and EU delivery plan around your audience, budget, timing and approved fulfilment instructions. Request a corporate gifting proposal.