My Lidl Account Privacy Notice
As of: July 2023
Version: 1.5.1
My Lidl Account is a service (hereinafter "My Lidl Account" or "the Service") of the Lidl group of companies (hereinafter referred to as " group of companies" operated by Lidl Stiftung & Co. KG, Stiftsbergstraße 1, 74167 Neckarsulm ("Lidl Stiftung", "we", "us"). The password-protected My Lidl Account enables you to view, access, manage and edit your data in a central location (hereinafter "Portal"). Furthermore, it also offers you a single sign-on service (hereinafter "SSO"), through which you can use various digital offers of the group of companies with a one-off registration. You can access My Lidl Account terms of use here.
Lidl Stiftung processes the data required for the purposes of the Service as the responsible party insofar as it collects, aggregates, evaluates and transmits the data to other companies of the Lidl group of companies for the performance of the Service.
The list contains only the relevant and current Lidl companies. In the future, other companies may also be added to this list if SB Lidl KG directly or indirectly owns shares in the respective company and they participate in the Service. This data transfer is limited to constellations in which the respective Lidl company requires your data to be able to offer the respective target service or to support us as a service provider within the scope of My Lidl Account (see below for details).
This data protection information applies to the processing activities of Lidl Stiftung as the data controller. For data protection-related inquiries and the exercise of your data subject rights, please feel free to contact us, for example at: customercare@lidl.co.uk The data protection officer of the Lidl Stiftung can be reached at the above postal address.
SSO enables you, after one-time registration with an online service of the group of companies (e.g., online shops, click and collect service, apps, etc., hereinafter referred to as "target service"), to use this target service with the same username and password, provided that SSO is implemented in the respective target service.
The Portal allows you to view, access, manage and display the information stored in your My Lidl Account in one central place, if the Portal is implemented in the respective target service. The Service displays the customer master data and information described in section 1 (About me, Family Club, payment history).
1 What personal data do we collect?
Registration for My Lidl Account
If you register with the target service without having previously registered with another target service and thus set up the My Lidl Account for the first time, we ask for at least your e-mail address and a password as part of the registration process. Depending on the target service, additional customer master data is also collected: First name, last name, date of birth, mobile phone number and preferred Lidl store. Optionally, salutation, gender, and address (street, house number, postal code, city, and country) can be specified. You can find out which of the data we collect is specifically passed on to the respective target service in the data protection information of the relevant target service. When you register for a new target service with an existing My Lidl Account, we will only ask for the above-mentioned customer master data that you have not already provided and that is required for the use of this target service.
We also collect data such as: Your IP address, your mouse movements, the duration of your stay on the My Lidl Account registration website, online identifiers such as device ID, browser details, i.e., browser name and version, name and version of the operating system of the device on which the browser is installed and network-based location data of your device when logging in.
Furthermore, we also store and process certain data in so-called log files if you have visited the registration page. In particular, a log file provides information about the date and time of the registration/login attempt and whether it was successful, the e-mail address provided and the IP address.
Use of the About me function
If you voluntarily enter certain information about your circumstances and interests as well as the birth date of your child in the "About Me" section of the Portal, we will also store this data for your overview.
Linking with Lidl Liddle Club
If you have also registered with our Family Club, we store information on the benefits granted and display this in the Portal.
Payment history
In addition to the data mentioned above, we may also receive information from the target service you use about the payment methods stored there and the history of your purchases and orders. We display this data to you in the Portal. You can find out which target services transfer their payment history to the My Lidl Account in the data protection information of the respective target service.
Analysis of user behaviour / cookies
Lidl Stiftung & Co. KG, Stiftbergstraße 1, 74167 Neckarsulm, Germany, is the data controller in connection with the use of cookies and other similar technologies for processing usage data on the My Lidl Account website accounts.lidl.com and in the portal.
When cookies and similar technologies are used to process usage data (in particular local storage), files are stored locally on your end device (laptop, tablet, smartphone or similar) when you use our Service. These files do not cause any damage to your end device and do not contain any viruses, Trojans or other malware. Information is stored in them in connection with the end devices you use and the actions you take when using them. However, this does not mean that we gain direct knowledge of your identity. Cookies send different information, e.g., the IP address of your device, to a web server.
You can find an overview of the cookies used together with the respective processing purposes, the storage periods and any integrated third-party providers here. (without the cookies for convenience and marketing purposes also listed there).
Customer Service
When you contact Lidl Customer Service, they can access the information from your My Lidl Account to help you as efficiently as possible.
2 For what purposes and on what legal basis do we process your personal data?
Purpose of registration, login, and account management
In order to provide you with the greatest possible convenience in your user experience, we process your personal data in My Lidl Account, to enable you to avoid having to re-enter your personal data for the usage of the Service.
From now on, your My Lidl Account can rather be used for the use of all connected target services without the need for a separate, complete registration or a renewed entry of detailed user data in each case, as provided for and agreed in the terms of use.
The legal basis for data processing is thus Art. 6 para 1 lit b UK GDPR, i.e., you provide us with the data on the basis of the contractual relationship between you and us.
This also applies to any additional personal data we receive from target services in connection with the use of your My Lidl Account.
Should you voluntarily store certain information about your circumstances and interests in the "About Me" area, we will also display this data for your overview in your My Lidl Account, as provided in the terms of use. Thus, the legal basis is also Art. 6 para 1 lit b UK GDPR.
Purpose of securing your customer profile
In the context of registration and/or login, we use Google reCaptcha, a service provided by Google. Our legitimate interest here lies in the protection of your data and our systems. In this context, an analysis of various information is used to determine whether the data entry is made by a human or by an automated program. This analysis begins automatically as soon as you open the My Lidl Account registration website. For the analysis, Google reCaptcha evaluates various information (e.g., IP address, your time spent on the page or mouse movements made by the user). The information generated is transferred to a Google server in the USA and processed there. The collection and analysis do not enable us or Google to identify you. In particular, the information will not be merged by Google with personal data of you. For more information on Google reCaptcha, please visit https://policies.google.com/privacy?hl=en or https://policies.google.com/terms?hl=en. The legal basis for this is Art. 6 para 1 lit f UK GDPR.
Purpose of the processing of your technical user data for abuse prevention
We use your IP address as well as the online identifiers described above, logfiles and your network-based location to prevent abuse and prevent and detect any security breaches and other prohibited or unlawful activities. For example, if you login from a new/unknown device, we may notify you of such a login attempt. The processing of this data is based on our legitimate interest in monitoring and improving the information security of our service (Art. 6 para 1 lit f UK GDPR).
Purpose of the data overview and management in the Portal
SSO provides you with a cross-portal identity that is recognised and verified by the connected target services. In this way, your master data and information from the "About me" and "Lidl Liddle Club" functions mentioned in section 1 can also be viewed by you from the connected target services in the Portal and can be used for the respective target services within the scope of what is required for the respective purpose. The Portal also allows you to easily and centrally manage the data you have stored there and your My Lidl Account. For example, you can correct and partially delete your master data, change your password, and view some information about your purchases and orders made via the respective target services. Furthermore, the Portal offers you the possibility to use the stored data when using the respective target service. For example, during the checkout process in the Lidl Online Shop, you can automatically use your address stored in the Portal without having to enter it again.
Purpose of the processing of "About me" to determine your product interests and the optimisation of our online offers
Should you voluntarily store certain information about your circumstances and interests in the "About Me" area, we will also display this data for your overview in your My Lidl Account.
If you have registered to use the Lidl Plus service, we will also use your information in "About me" for the purpose of personalised advertising targeting as part of the Lidl Plus service, as provided for in the usage agreement for the Lidl Plus service. Thus, the legal basis for this is Art. 6 para 1 lit b UK GDPR, i.e., you provide us with the data on the basis of the contractual relationship with the use of Lidl Plus between you and us.
Purpose of processing customer requests
If you contact our customer service to process any problems with this area of the My Lidl Account, we will use your data stored there to process your respective request. The legal basis for this is Art. 6 para 1 lit b UK GDPR, as the processing is necessary to provide you with the agreed Service, or to restore a contractual condition in accordance with the usage agreement.
If you contact Lidl customer service regarding concerns with target services, we will give your data stored in My Lidl Account to the respective target service so that they can process your concern as efficiently as possible. The legal basis for this is Art. 6 para 1 lit b UK GDPR, i.e., we thereby fulfil our contract with you.
Use of cookies
The use of cookies and the other technologies for processing usage data serves the following purposes, depending on the category of the cookie or the other technology:
- Technically necessary: These are cookies and similar methods without which you cannot use our services (for example, to display our website correctly, including the font and colour/, to provide the functions you want and to take account of your settings, such as the choices you have made about cookies and similar technologies, to save your registration in the login area, etc.).
- Statistics: These techniques enable us to compile anonymous statistics of the use of our services. This enables us, for example, to determine how we can adapt our website even better to the habits of users.
The legal basis for the use of technically necessary cookies is Art. 6 para 1 lit b UK GDPR. In addition, you have the option to voluntarily consent to the use of "analytical cookies" (and to revoke this consent later). The legal basis for this is your consent pursuant to Art. 6 para 1 lit a UK GDPR. You can find more detailed information in our Cookie Policy.
3 To whom do we disclose your personal data?
Transfer to operators of the target services
If you use your My Lidl Account to use a target service, we will pass on your data on to the operator of the respective target service for the purpose of processing purchase contracts or other services that have been ordered via the target services covered by My Lidl Account. The latter receives those data that are required for the provision of the service ordered, insofar as these have been stored by you or displayed in the Portal by another target service, i.e., depending on the offer:
- Verification of log-in data (e-mail address, password, telephone number if applicable).
- Master data (name, address, date of birth)
- Stored payment methods
- Information about your participation in the Family Club program
- Information stored in the "About Me" section about your circumstances and interests
We also pass on your customer master data to those companies of the group of companies whom you contacted in the context of customer service inquiries regarding target services connected to My Lidl Account.
If you use the Google Assistant as part of our target services, please note that Google obtains access to your customer ID for this purpose in order to establish a connection with the respective target service. Your data processing by Google (as far as we know, the recording and conversion of voice commands) is the sole responsibility of Google. For more information, please refer to Google's separate privacy policy ( https://policies.google.com/privacy?hl=en).
Transfer to service providers
In addition, we use service providers to process your data. The companies acting on our behalf are carefully selected and commissioned in writing. They are bound by our instructions and are inspected by us before the start of data processing and regularly thereafter. These companies never pursue their own purposes with your personal data. In this context, we forward your data to recipients who provide us with
- storage capacity, database systems or similar,
- fraud prevention services,
- technical support and
- provide us with marketing advice.
We exclude any further transfer of your data to third parties.
Transfer to third countries
If we transfer personal data to recipients in third countries (countries outside the European Economic Area), you can infer this from the information on data processing by our service providers described in this data protection information. By adopting adequacy decisions, the European Commission has determined whether such a third country provides an adequate level of data protection. The exact list of countries with an adequacy decision can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en. If an adequate level of protection has not been determined by the European Commission for a third country, we will ensure that the adequate level of data protection is provided through other measures, such as: binding internal data protection rules, standard contractual clauses, certification mechanisms or recognised codes of conduct. Please contact our Data Protection Officer (see above) if you would like more information.
4. How do we ensure the confidentiality of your personal data?
To ensure the confidentiality of your personal data, our employees involved in data processing are prohibited from collecting, processing or using personal data without authorisation. Our carefully selected employees, who are sensitive to data protection law, are contractually obligated to maintain data secrecy at the beginning of their employment. This obligation continues after termination of the employment relationship.
5. How long do we store your personal data?
We generally store your data for as long as you are a registered user of the My Lidl Account.
If you have only registered with the target service via My Lidl Account, your data will be deleted accordingly as soon as you request the deletion of your account with the target service. Please note, however, that if you have registered with several target services via My Lidl Account, your My Lidl Account and all personal data stored by us will only be deleted once all target services linked to the My Lidl Account have been deleted. The retention periods described in the data protection information of the target service apply accordingly.
The processing and storage of data is the responsibility of the respective operator of the service used, who uses the data required to provide the service ordered for this purpose and then archives it in accordance with the statutory retention periods (the retention periods described in the data protection information of the target service apply accordingly).
6. What rights do you have with regard to the processing of your data?
Of course, upon request, we will provide you with the information pursuant to Art. 15 UK GDPR (in particular, the data stored about you, the recipient or categories of recipients to whom data are disclosed, the purpose of storage, etc.). We will provide this information free of charge. In addition, you have the right, under the respective legal conditions, to have incorrect data corrected as well as to have your personal data deleted, restricted from processing and transferred. Furthermore, you have a right to lodge a complaint with the competent supervisory authority.
In cases where the data processing is based on Art. 6 para 1 lit f UK GDPR or is carried out for the purpose of direct marketing, you have the right to object to the processing.
Insofar as the processing is based on your consent, you have the right to revoke this at any time with effect for the future.
7. No obligation to provide data
If you provide this data yourself, you are not obliged to provide the above voluntary information. Without this data, however, we are not able to fully provide you with the My Lidl account service and to fully provide you with the target services based on it. Only optional data fields are marked as such in the My Lidl Account.
8. Can we change the data protection information?
An amendment of this data protection information may be necessary due to changes in the legal situation or the circumstances of the data processing of the My Lidl Account. If the circumstances or the scope of the processing of your personal data change, we will inform you of this and, if necessary, ask for your consent.
Data protection information for download
You can find the data protection information for download as a PDF version here:
Lidl Plus Data Protection Notice
Last revised: August 2025
Version: 2.1
Contents
1. Overview
2. Contact details of the controller and the data protection officer
3. Processing purposes, legal basis and recipients
3.1 Registration for Lidl Plus and account management
3.2 Store visits
3.3 Determining your product interests and personalised advertising approach
3.4 Advertising optimisation measures, the store network and store design
3.5 Google reCaptcha
3.6 Provision of the Self Scanning function
3.7 Competitions
3.8 Reservation of products
3.9 Partner offers
3.10 E-mobility (EV Charging)
3.11 Lidl Pay
3.12 Map Services
4. To which other recipients do we pass on your personal data?
4.1 Overview
4.2 Transfer within the Lidl Group companies
4.3 Transfers to recipients in third countries
5. How long do we store your personal data?
6. What rights do you have with regard to the processing of your data?
1. Overview
Lidl Plus is a loyalty programme (hereinafter referred to as "Service" or "Lidl Plus") that offers you deals and discounts tailored to your interests from the Lidl Group companies and selected partners.
You can use Lidl Plus by registering for selected online services of the Lidl Group ("Online Ser-vices", e.g. online shop, click and collect service, apps). Please note that some functionalities are only available via the Lidl App. For example, you must identify yourself with the Lidl App at the till so that your purchases in Lidl stores are assigned to your Lidl Plus profile.
2. Contact details of the controller and the data protection officer
Unless otherwise stated below, Lidl Stiftung & Co. KG, Stiftsbergstraße 1, 74172 Neckarsulm ("Lidl Stiftung", "we", "us") is responsible for the processing of your data in the context of Lidl Plus.
The data protection officer of Lidl Stiftung can be contacted at the above postal address or at data.protection@lidl.co.uk.
3. Processing purposes, legal basis and recipients
3.1 Registration for Lidl Plus and account management
Purposes of data processing/legal basis
Once you have registered, you can use Lidl Plus in all connected Online Services with the same username and password and access your customer registration data, shopping history and Lidl Plus functions in your Lidl Plus account.
The following data is processed when registering for Lidl Plus:
- First name,
- Date of birth,
- E-mail address,
- Mobile phone number,
- Password,
- Title (optional),
- Gender (optional).
We need your date of birth, as participation in Lidl Plus requires a minimum age of 18 years (see section 2 of the Terms and Conditions) and for certain products (e.g. alcoholic beverages) age limits under youth protection laws must be taken into account.
You can also optionally enter your address and surname in your Lidl Plus account. However, this data will be mandatory for certain functions.
If you have registered for Lidl Plus in the Lidl App, we will also process the store you have se-lected there. In addition to the above-mentioned data, we receive information from the Online Service you use – if available – about the payment methods stored there and your purchase and order history. You can access this data in your Lidl Plus account. You can find out which Online Services transfer your payment history to your Lidl Plus account in the data protection notices of the Online Services.
We process the data collected during registration for the following specific purposes:
- Communicating with you,
- Verifying your identity as the account holder (e.g. when resetting the password),
- Uniquely assigning your purchase and usage behaviour to your customer profile.
We also use your e-mail address to send you a notification when your account is accessed via a new device.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
The following data is processed to secure the registration/login procedure:
- E-mail address or mobile phone number,
- IP address,
- Mouse movements,
- Duration of your visit to the registration page,
- Online identifiers such as device ID,
- Browser details (browser name and version),
- Name and version of the operating system of the device on which the browser is in-stalled,
- Network-based location of your device when you log in,
- Date and time of the registration/login attempt,
- Information on whether registration/login attempts were successful.
The legal basis for the above-mentioned Personal Data processing is our legitimate interest in efficiently operating our Lidl Plus service (Article 6 1.f. UK GDPR).
Recipients/categories of recipients
If you log in to Online Services as a Lidl Plus user, we pass on to the respective operator of the Online Service the data required to provide the Service you have requested. The data varies depending on the offer and can include:
- Verified login data (e.g. e-mail address, password, mobile phone number),
- Master data (e.g. name, address, date of birth),
- Stored payment methods,
- Information stored in the "About me" section.
We also pass your customer registration data to those companies within the Lidl Group that you contact in the context of customer service enquiries.
3.2 Store visits
Purposes of data processing/legal basis
If you use Lidl Plus, you can provide your loyalty account information at the self-checkout or at the till when you visit a store. In this case, we collect the following data:
- The store you have visited,
- The products you have purchased or returned by type, quantity and price,
- The coupons and vouchers you have redeemed,
- The purchase receipt amount,
- The time of the payment transaction and which means of payment you used.
The legal basis for processing your Personal Data is our contractual relationship with you (Art 6 1. b. UK GDPR).
For fraud prevention, we analyse your purchasing behaviour. For example, we analyse whether and how often items are returned. The legal basis for this our legitimate interest in protecting our business from fraudulent activities (Article 6 1.f. UK GDPR).
In the event of product recalls, we will check whether you have purchased the affected product so that we can inform you of the recall. This processing is carried out to protect you from health concerns relating to the product (Article 6 1.d. UK GDPR) and because we have a legitimate in-terest in informing you of any product recalls (Article 6 1.f. UK GDPR).
3.3 Determining your product interests and personalised advertising approach
Purposes of data processing/legal basis
In Lidl Plus, we determine which products, promotions and services could potentially be of in-terest and relevance to you. This is done in particular based on the following data:
- Store purchases (e.g. products purchased or returned by type, quantity and price),
- Demographic information (e.g. age, gender, place of residence),
- Data stored in the Lidl Plus account,
- Information about life circumstances and interests, which are stored in the "About me" section,
- Activated and/or redeemed coupons
- Participation in competitions and promotions,
- Reservations,
- Use of our Partner offers (e.g. which Offers you have chosen),
- Use of the Digital Services (e.g. information about your access authorisation to services of our partners, length of use of the services, termination date of the free month, activa-tion and use of the discount collector for Digital Services),
- Use of functions in Lidl Plus (e.g., Shopping List),
- Use of our Lidl Pay payment service.
In addition, the following information from Online Services is processed to determine your in-terests:
- Usage data of the Lidl App, e.g.
o Visited app sections,
o Viewed articles,
o Version of the operating system,
o Device labelling,
o System language and selected country,
o Lidl App version used,
- Tracking data, e.g.
o advertising identifiers (iOS IDFA, Android advertising ID or Huawei ID, e-mail ad-dress, address, mobile phone number),
o IP/MAC address,
o HTTP header,
o Fingerprint of your end device,
o Information about the use of apps and websites (links clicked on, areas visited, duration and frequency of use, number of clicks and scrolls),
o App and event tokens.
- nformation from the Online Service of the Lidl Group companies, e.g.
o Products purchased/reserved in Online Services by type, quantity and price,
o Receipt amount and time of payment,
o Payment method used,
o Selected delivery method,
o Participation in surveys and competitions,
o Products stored in the shopping cart,
o Frequency of purchase transactions,
o Web tracking data of the Online Services.
Your usage behaviour in relation to marketing communication of Online Services, e.g.
o Time of opening the newsletter,
o Links or areas clicked on,
o Duration and frequency of use.
We use mathematical-statistical methods to determine your interests. For this purpose, your personal data is also compared with the data of other customers. Based on this comparison, we can deduce which products and campaigns are relevant for customers with similar interests.
We use this information to provide you and other customers of the Online Services with per-sonalised advertising tailored to your interests and to offer you the best possible individual of-fers and discounts. Where possible, you will also receive personalised information about prod-ucts, promotions, competitions, new services, customer surveys, the Store and travel offers. We also use these findings to optimise the Lidl Plus programme.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
Recipients/categories of recipients
In addition, we may transfer the data described in this paragraph to other Lidl Group companies or other third parties if there is a legal basis for this (in particular your consent to the use of tracking technologies in our Online Services).
3.4 Advertising optimisation measures, the store network and store design
Purposes of data processing/legal basis
If you provide us with your address as part of the registration process or at a later date in your Lidl Plus account, we use it to optimise our advertising e.g. leaflet distribution and poster ad-vertising.
This data is processed on the basis of our legitimate business interest in optimising sales chan-nels (Article 6 1.f UK GDPR).
3.5 Google reCaptcha
Purposes of data processing/legal basis
We use Google reCaptcha to protect our registration/login process from attacks or misuse by automated programs (so-called bots). Bots are used, for example, to try to obtain passwords for customer accounts or to restrict the functionality of the website through mass data transfers.
Google reCaptcha determines whether the interaction with the website is by a human user or a bot. For this purpose, usage behaviour (time spent on the page or mouse movements made) is analysed and the IP address is read by Google and checked to see whether it could have been assigned to a bot in the past. If the IP address has already been assigned to a bot, Google trans-mits this information to us. We then store these IP addresses for defence against future attacks. This analysis starts automatically as soon as you open the registration page.
The legal basis for this data processing is based on our legitimate interest in operating a secure service (Article 6 1.f. UK GDPR).
Recipients/categories of recipients
When using Google reCaptcha, the above-mentioned data is also processed by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA to provide the Service. We have no influence over the processing and use of data by Google. Further information on data pro-cessing by Google can be found here: https://policies.google.com/privacy.
3.6 Provision of the Self Scanning function
Purposes of data processing/legal basis
You can use the Self Scanning function in selected Lidl stores. To do so, you must check in at your chosen Store either by enabling the geo-location feature on your mobile device or by scanning the Store’s check-in QR code. Once checked in, Store-specific information (such as item prices) will be downloaded to your mobile device.
You can then use your mobile device’s camera to scan items, which will be added to your virtual shopping basket. This basket is stored locally on your device until you tap the ’Checkout’ button. After identification at the checkout, the contents of your basket are transferred to the self checkout system to initiate the payment process.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
3.7 Competitions
Purposes of data processing/legal basis
As a Lidl Plus user, you can take part in various competitions. Unless otherwise specified in the respective competition, your data will be used in the context of your participation in the com-petition in order to run the competition (e.g. determining the winner, notifying the winner, sending the prize) and for the purposes described under Section 3.3 to determine your inter-ests..
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
Recipients/categories of recipients
A transfer to the Lidl group of companies or third parties will only take place outside the above-mentioned determination of your interests and the personalised advertising approach, insofar as this is necessary for the processing of the competition (e.g. sending the prize via a third-party Company). The legal basis for this transfer is our legitimate business interest in managing Com-petitions (Article 1.f. UK GPDR).
3.8 Reservation of products
Purposes of data processing/legal basis
If you reserve products via Lidl Plus and purchase them in the Store at a later date, we process this information in order to
- enable you to make a subsequent purchase in a Lidl store,
- to display a history of reservations,
- to offer you special offers tailored to your preferences and interests and to enable you to participate in activities.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
Recipients/categories of recipients
3.9 We will send a list of the reserved products and your order number to the relevant Lidl Group company. The Lidl company uses this data under its own responsibility for the subsequent processing of the purchase. Partner offers
Purposes of data processing/legal basis
Lidl Plus gives you the opportunity to take advantage of discounted offers from selected part-ners. Some of these offers require you to identify yourself as a Lidl Plus customer with your digi-tal customer card. In this case, the partner informs us about your use of the special offer includ-ing the associated information (e.g. time, quantity, location).
If special offers are offered within Lidl Plus for contracts concluded with our partners, we will receive your contact details (e.g. e-mail address and mobile phone number) from them so that we can correctly assign the special offer to your account.
We use the information on the use of the partner offers to determine your interests as de-scribed above and to display personalised advertising.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
Recipients/categories of recipients
If you make use of partner offers via Lidl Plus, we only send the partner the information that you are a Lidl Plus user so that the partner can assign the corresponding offer to you.
3.10 E-mobility (EV Charging)
Purposes of data processing/legal basis
To start the charging process at a Lidl charging station, you must first provide your Lidl Plus ac-count information. If you have not yet entered an address in Lidl Plus, you will be asked for a billing address so that payment can be made. During the charging process, we process the fol-lowing data with reference to your customer number:
- Date of the charging process,
- Charging quantity (kWh),
- Charging power (kW),
- Start and end of the charging process (time),
- Type of charging plug used.
We use the information on the use of the charging stations to determine your interests as de-scribed above and to display personalised advertising.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
Recipients/categories of recipients
If you select a charging station and a plug in Lidl Plus as part of the EV Charging Service, we will transmit the Personal Data, which you submitted during the registration of your Lidl Plus ac-count to Lidl GB. In addition, the following data is also shared: Customer Account data, which is for the purpose of carrying out the charging process to Lidl Great Britain Limited. The processing is based on our legitimate interests in ensuring correct accounting (Article 6 1.f. UK GDPR).
3.11 Lidl Pay
Purposes of data processing/legal basis
As a Lidl Plus user, you can choose to register your credit or debit card with our mobile pay-ment Service "Lidl Pay" and make payments (e.g. in Lidl stores) conveniently using your mobile device. The registration and use of Lidl Pay requires the provision of data, such as your first and last name, the credit or debit card number, CVV/CSV code and the card's expiration date. This data is entered and stored in encrypted form directly in the PCI-DSS & PCI 3DS-certified systems of our payment platform. To ensure that you are indeed the holder of the credit/debit card, your data will be compared with the information of the card-issuing company.
If the registration for Lidl Pay is successful, the payment platform sends us a token as confirma-tion. We then associate this token with your customer account.
The legal basis for processing your Personal Data is our contractual relationship with you (Article 6 1.b. UK GDPR).
Recipients/categories of recipients
Once you use Lidl Pay in a Lidl store, your credit or debit card data will be forwarded to the respective Lidl Group company for payment processing, which will process the data for its own purposes (e.g. for tax verification obligations).
In order to carry out the payment process in accordance with the statutory provisions of Di-rective (EU) 2015/2366 ("PSD 2"), the Payment Services Regulations 2017, Delegated Regulation (EU) 2018/389 and the Financial Conduct Authority's Strong Customer Authentication and Com-mon and Secure Methods of Communication technical standards, we also exchange specific in-formation (e.g. data about you, the transaction and your payment behaviour) with your credit institution or the issuer of your means of payment (e.g. your debit or credit card) with the help of our service providers.
These processing operations are carried out based on our contractual relationship with you (Ar-ticle 6 1.b. UK GDPR) and the fulfilment of the legal obligations mentioned above (Article 6 1.c. UK GDPR).
To prevent fraud, we process your mobile phone number in the registration, pre-authentication and payment process and transmit it to the payment service provider. The legal basis for this is our legitimate interests in the prevention of fraud (Article 6 1.f. UK GDPR).
3.12 Map Services
Purpose of Data Processing and Legal Basis
If, as part of your use of the Lidl App or through the settings on your mobile device, you have consented to geolocation via the "Allow Permission" dialog, we use this function to provide you with location-based, personalized services and marketing communication. Specifically, we pro-cess your location via GPS and network-based data as part of features like "Store Search," "Coun-try Switch," "Charging Station Search," and "Self Scanning" to display the nearest stores or ser-vices related to your current location.
To use the map services, it is necessary to process your IP address as part of internet communi-cation. This is usually processed on a server of the respective operating system provider. We do not have control over this specific data processing. For more information on the purpose and scope of data processing, please refer to the privacy notices of the respective provider. There, you will also find further information on your rights and settings regarding the protection of your privacy.
Provider Addresses and Privacy Policies:
• Google Maps
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy Policy: https://policies.google.com/privacy?hl=en-uk
Terms of Service: https://policies.google.com/terms?hl=en-uk
• Apple Maps
Apple Inc, One Apple Park Way, Cupertino, California, USA
Privacy Policy: https://www.apple.com/legal/privacy/en-ww/
Terms of Service: https://www.apple.com/legal/internet-services/maps/terms-en.html
Terms of Service:
• Huawei Maps Kit
Huawei Aspiegel SE, 1F, Simmonscourt House, Ballsbridge, Dublin D04 W9H6, Ireland
Privacy Policy: https://www.huawei.com/en/privacy-policy
Terms of Service: https://developer.huawei.com/consumer/en/hms/huawei-MapKit/
Terms of Service:
The use of map services is based on our contractual relationship with you, Article 6 .1.b. UK GDPR as well as our legitimate interest, Article 6 1.f. UK GDPR in presenting our offerings attrac-tively and ensuring the easy location of the stores listed in the app.
4. To which other recipients do we pass on your personal data?
4.1 Overview
Your personal data will only be passed on without your prior consent in the cases mentioned in Sections 3.1 - 3.12 if this is permitted by law. This is the case, for example, if:
- we have a legitimate interest in sharing your personal data for administrative purposes within the Lidl Group and your rights and interests in protecting your personal data as outlined in Article 6 1.f. UK GDPR do not outweigh this interest
or
- we use third parties as data processors, who we have carefully selected and contractual-ly obliged to process your personal data exclusively in accordance with our instructions.
4.2 Transfer within the Lidl Group companies
The data provided during registration will be shared within the Lidl Group companies internal administrative purposes, including joint customer support.
Any disclosure of personal data is justified by our legitimate interest in disclosing the data for administrative purposes within our Group (Article 6 1.f. UK GDPR).
4.3 Transfers to recipients in third countries
In some cases, it may be necessary for us to transfer your personal data to Recipients in one or more third Countries outside the UK and the European Union (EU)/the European Economic Area (EEA).
The UK Government and European Commission has certified some third Countries have a level of data protection comparable to the UK and EU by means of an adequacy decision. You can find an overview of third countries with an adequacy decision by the EU Commission here.
In the event that we transfer data to Countries with no adequacy decision, we ensure safeguards are in place by adopting an appropriate transfer mechanism. This may include Binding Corporate Rules or Contractual Standard Contractual Standard Data Protection Clauses.
If you have any questions, you can contact our Data Protection Officer (Section 2).
5. How long do we store your personal data?
We delete or anonymise your personal data as soon as it is no longer required for the stated purposes. In general, we store your personal data for the duration of your participation in Lidl Plus. If you remain inactive for 24 months or actively delete your Lidl Plus account, we will noti-fy you of the pending cancellation. Within 72 hours, you can cancel the deletion by logging in again. If your data needs to be retained for legal retention periods or to secure, assert, or en-force legal claims, we will retain your data beyond account deletion. The data will be stored only as long as retention is legally permissible.
If you use the Self Scanning function, your shopping basket will be saved for 72 hours and then deleted.
If you do not use Lidl Pay for 24 months, the data collected within this function and the func-tion itself will be deleted. You can then re-register for Lidl Pay at any time.
All Personal Data that you provide to us during customer service enquiries will be deleted or anonymised by us no later than 95 days after the final response. Experience has shown that there are usually no more queries after 95 days. If Customers exercise their Data Subject Rights, Personal Data will be stored for three years after the final response to evidence that a compre-hensive response has been provided and our legal obligations have been met.
The log files in which we record your interactions with Lidl Plus (e.g., your login, password reset, etc.) are stored for a period of up to 90 days.
6. What rights do you have with regard to the processing of your data?
You have the right, under Article 15 1. UK GDPR, to request free information about the personal data stored about you.
If the legal requirements are met, you also have the right to rectification (Article 16 UK GDPR), deletion (Article 17 UK GDPR) and restriction of processing (Article 18 UK GDPR). If you have provided us with the processed data, you have a right to data portability in accordance with Article 20 UK GDPR.
If data processing is carried out based on Article 6 1.e. or f. UK GDPR, you have the right to ob-ject in accordance with Article 21 UK GDPR. If you object to data processing, it will only be con-tinued if we can demonstrate compelling legitimate grounds for further processing that out-weigh your interest in objecting. You can send your objection at any time to Custom-er.Care@lidl.co.uk.
If the data processing is based on consent in accordance with Article 6 1.a Article 9 2.a. UK GDPR you may withdraw your consent at any time with future effects without affecting the law-fulness of the processing carried out prior to the withdrawal.
You also have the right to file a complaint with a data protection supervisory authority. The data protection supervisory authority of the country in which you live or in which the controller has its registered office is responsible.
Data protection notice on download
You can download the Lidl Plus data protection information as a PDF version at the top of this page.