GDPR and Corporate Gifting: How to Collect Home Addresses Compliantly
Hybrid and remote work solved one problem and quietly created another: sending someone a branded gift now almost always means sending it to a home address rather than an office. That's a small operational shift with a real compliance dimension attached to it, and it's one that most corporate gifting content skips entirely in favour of product recommendations.
August 13, 2026
5 min

A home address is personal data. Collecting, storing, and sharing it, even for something as well intentioned as a birthday gift or a client thank you, falls squarely within the scope of UK GDPR.
Why This Matters More Than It Used to
A few years ago, most corporate gifts were handed out in an office or shipped in bulk to a single business address, with minimal personal data involved. Distributed teams and remote first client relationships have changed that. A single onboarding or appreciation campaign can now mean collecting dozens or hundreds of individual home addresses, often gathered quickly via a spreadsheet or a scramble of Slack messages, with little thought given to where that data goes afterwards.
What Counts as Personal Data Here
A home address on its own is personal data because it can identify, or help identify, a specific individual. When paired with a name, which it almost always is in a gifting context, there's no ambiguity: this is personal data, and UK GDPR applies to how it's collected, stored, used, and eventually deleted.

Choosing a Lawful Basis
Before collecting any address for a gifting campaign, a business needs a lawful basis under UK GDPR for doing so. For most one off or occasional gifting purposes, the two most relevant options are:
Legitimate interests.
Appropriate for most standard gifting scenarios, provided the processing is necessary, proportionate, and clearly communicated, and doesn't override the individual's own rights and expectations.
Consent.
A valid option, but it must be freely given, specific to the gifting purpose, and easy to withdraw. Consent gathered for an unrelated purpose, such as an employment contract, can't simply be reused.
Whichever basis is used, it should be documented and, for legitimate interests, ideally supported by a brief internal assessment showing the reasoning.
Practical Steps for Compliant Address Collection
1. Collect only what's needed
Data minimisation means resisting the temptation to gather extra fields "just in case." A delivery address, name, and perhaps a size preference (for something like a branded apparel item) is usually sufficient. Additional personal details rarely need to sit in the same spreadsheet.
2. Be transparent about the purpose
A short note explaining why the address is being collected and how long it will be kept builds trust and satisfies the transparency principle at the core of UK GDPR.
3. Limit how long the data is kept
Once a gift has been delivered, there's rarely a reason to retain the address. Under the storage limitation principle, addresses collected for a specific campaign should be deleted once their purpose has been fulfilled, unless there's a separate, clearly stated reason to keep them.
4. Be careful with spreadsheets and shared drives
A spreadsheet of home addresses sitting in a shared drive with broad access permissions is a common, avoidable risk. Restricting access to only those who need it, and removing the file once the campaign concludes, reduces exposure significantly.
5. Consider a self serve collection method
Where possible, having the recipient enter their own delivery address directly into a gifting platform or form, rather than a business collecting and holding it centrally, reduces the amount of personal data the business itself is responsible for managing.
What This Looks Like in Practice
A simple, compliant gifting workflow typically looks like this: a recipient receives a link, enters their own address directly (rather than it being sourced from an HR system or compiled manually), the gift is dispatched, and the address is deleted or automatically purged from the system shortly after delivery is confirmed. This keeps the process both operationally simpler and considerably lower risk from a data protection standpoint.

Frequently Asked Questions
Is a home address personal data under UK GDPR? Yes. A home address is personal data under UK GDPR because it can identify or help identify a specific individual, and businesses must have a lawful basis for collecting and storing it.
What lawful basis applies to collecting addresses for gifting?
Legitimate interests is commonly used for one off gifting purposes, provided the business can show the processing is necessary, proportionate, and does not override the individual's rights, and the address is not retained longer than needed.
How long can a business keep addresses collected for a gifting campaign?
Under the data minimisation and storage limitation principles, addresses should only be kept for as long as needed to fulfil the gift and should be deleted once the delivery is confirmed, unless there is a separate, clearly stated reason to retain them.
Can a gifting platform reduce GDPR risk for a business?
Yes. Platforms where recipients enter their own delivery address directly, rather than the business collecting and storing it internally, can reduce the amount of personal data a business holds and simplify compliance.
Do businesses need consent to collect an employee's home address for gifting?
Consent is one possible lawful basis, but it must be freely given, specific, and easy to withdraw. Many businesses instead rely on legitimate interests for occasional gifting, provided this is clearly communicated to employees in advance.
Final Thought
None of this makes gifting to remote teams and clients complicated. It simply means treating a home address with the same care as any other piece of personal data. A short internal process, a clear lawful basis, and a habit of deleting what's no longer needed goes a long way toward keeping a gifting programme both genuinely thoughtful and properly compliant.
Brandably's commitment
This guide is for general information and does not constitute legal advice. Data protection obligations can be nuanced; consult a qualified professional for advice specific to your organisation.
Share Article