The browser is not supported
To display the website correctly, please use one of the following browsers.CautionPlease update your browser, if you proceed with this browser, your shopping experience might not be successful!

    Privacy Notice for Business Partners and Stakeholders

    Last revised October 2026


    1. Scope

    This privacy notice applies if you are a Lidl business partner, or if you are a representative, employee, shareholder, or beneficial owner of one.

    Business partners include any person or company in negotiations with Lidl or with an existing business relationship. (Note: This does not apply to employment or apprenticeship contracts.)

    Additionally, we process personal data for stakeholder management, which covers stakeholders and regional representatives from authorities, associations, and interest groups.


    2. Purposes of Data Processing and Legal Basis

    We process your data on the basis of the following legal grounds and for the purposes stated below:

    Based on consent

    If you voluntarily provide us with information or if you expressly give us your consent to data processing, the processing is carried out accordingly

    To fulfill contractual obligations We process personal data in connection with pre-contractual measures, in particular contract negotiations, as well as for the fulfillment of existing contractual obligations.

    To fulfill a legal obligation We process your data to comply with legal requirements related to our business relationship, such as anti-money laundering checks or identity verification. Sometimes, we receive this data from external sources like government authorities, rather than directly from you. For information on how we handle reports regarding compliance violations - where you or your employees might be suspects, witnesses, or victims - please see our whistleblower system documentation.

    To fulfill legitimate interests

    In the context of business relationships, we process personal data based on our legitimate business interests. These include:

    • Selecting business partners: To avoid economic risks, we may research reliability, suitability, and creditworthiness, as well as ensure compliance with environmental and social standards.
    • Maintaining relationships: We keep contact lists to facilitate communication and perform activities like sending greetings or conducting satisfaction surveys.
    • Facilitating cooperation: We process data to manage IT infrastructure and system access, ensuring our processes remain secure.
    • Improving efficiency: We use digital tools, such as electronic signatures, to streamline our collaboration.
    • Ensuring compliance: We process data to prevent and investigate potential legal violations and to protect our legal standing.
    • Protecting corporate interests: We may process data for public relations and to document company history.
    • If you have an accident on Lidl premises, we process personal data to investigate the incident, prevent future occurrences, and defend potential legal claims.

    For stakeholder management, we process data to maintain regional networks, exchange information regarding construction, real estate, and location projects, and keep stakeholders updated on company news. This supports our goals of efficient communication and effective site development.

    When we collect this data from public sources, such as websites, we do so based on these same legitimate interests.


    3. Categories of Data

    We process personal data as needed for our business operations. This typically includes your name, contact information, and job title.

    Depending on the situation, we may also collect additional information, such as:

    • Financial and tax records
    • Company structure and ownership details
    • Identification and authentication information
    • Data from electronic contracts
    • Photo and video recordings
    • Information regarding insolvencies or compliance-related matters

    Please note: We may collect this additional information from third-party sources (like credit agencies or authorities) if it isn't provided directly by you or if necessary.

    For stakeholder management, we specifically process:

    • Name and job title
    • Business address and contact details (phone, email)
    • Publicly known responsibilities for specific topics
    • Accident-related information, including incident description, nature of the event, and health data where relevant.

    4. Recipients and Categories of Recipients

    Recipients within the Lidl companies

    Within the Lidl organisation you work with, only the specific departments that need your information for the purposes mentioned above will have access to it. This typically includes our purchasing teams and departments receiving your services.

    Your data may also be shared with Lidl Stiftung & Co. KG when they assist us in supporting the relevant national Lidl organisation. When you use our supplier contact form, Lidl Stiftung & Co. KG and your local Lidl organisation work as joint controllers to manage your inquiries.

    For stakeholder management, access is restricted to the specific departments involved in those projects, such as our real estate team.


    Recipients within the Lidl and Schwarz corporate groups

    For the purposes outlined in section 2, or if you have a framework agreement with the entire Lidl or Schwarz Group, data relevant to those purposes is accessible to the procurement and purchasing teams of the Lidl or Schwarz Group (including Schwarz Beschaffung GmbH). Additionally, the national compliance departments within the Schwarz companies have access to data related to business partner compliance checks. In these instances, the companies work together as joint controllers to manage your data. If you have an accident on Lidl premises, we may share your personal data relating to this accident to investigate the incident, prevent future occurrences, and defend potential legal claims.


    External recipients

    We may share your personal data with external service providers or public authorities when it is necessary for our business operations. We ensure your data is kept secure by requiring these parties to sign data protection agreements or by verifying that they strictly follow all relevant legal requirements.

    Where necessary for claims handling or legal obligations, we may share accident data with insurers or relevant public authorities.


    5. Storage Duration and Criteria for Determining Storage Duration

    We keep your data only for as long as necessary.

    Business Relationships: Depending on the type of document, we are legally required to retain certain records for up to 12 years.

    General Purposes: Data is stored as long as necessary to fulfill the purposes mentioned in this notice.

    Historical Documentation: If data is used to document our company's history, it may be kept permanently or for as long as it remains relevant.

    Accident records are typically retained for five years, though this period may be extended where necessary for the establishment, exercise, or defence of legal claims.


    6. Obligation to Provide the Data

    Depending on your relationship with us, you may be required by law or contract to provide certain personal information. While providing this data is optional if no such obligation exists, please note that we generally cannot work with you if this information is not provided.


    7. International Data Transfers

    If we transfer your data to countries outside the European Economic Area (EEA), we ensure it remains protected.

    Adequacy Decisions: The European Commission has recognized some countries as having data protection standards comparable to those within the EEA. You can view the list of these countries [here].

    Additional Safeguards: If we transfer data to a country without an adequacy decision, we protect your information using additional measures, such as the European Commission's Standard Contractual Clauses.


    For more information about these transfers or the safeguards we use, please contact the Data Protection Officer listed in section 2.


    8. Name and Contact Details of the Controller and Data Protection Officer

    Lidl Great Britain Limited

    Lidl House

    14 Kingston Road

    Surbiton

    KT5 9NU

    Telephone: +44 (0)203 966 556


    Registered in England and Wales under company number 02816429 with the ICO registration number Z6682144.


    Lidl GB Ltd is considered the data controller and responsible for fulfilling the obligations under the UK GDPR, in particular for responding to requests for information, answering your questions regarding the collection, processing, and use of your personal data, and providing you with further information in cases of joint controllership.


    For any data protection concerns, please contact the Data Protection Officer at dataprotection@lidl.co.uk.