Skip to content

Logistics and distribution

Shipper data processing addendums: what 3PLs signed and what it means now

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A 3PL data processing addendum makes the 3PL a processor or service provider for the shipper's personal data, usually consumer names, addresses and contact details on orders. Its core promise, to process only on the shipper's documented instructions, generally rules out reusing that personal data for the 3PL's own purposes, including licensing, unless the shipper authorizes it in writing.

Key takeaways

  • A DPA covers the personal data a 3PL handles for a shipper, not every operational record.
  • Processing only on instructions generally excludes the 3PL's own purposes, including analytics licensed to others.
  • Whether de-identifying data is itself a permitted use depends on the DPA and the privacy laws that may apply.
  • Written authorization from the shipper is the usual route when reuse touches personal data.
  • Return-or-delete clauses may already require deleting former clients' personal data.

Why did shippers ask 3PLs to sign DPAs?#

Shippers asked 3PLs to sign data processing addendums because a 3PL fulfilling direct-to-consumer orders handles personal data on the shipper's behalf: names, delivery addresses, phone numbers, email addresses and sometimes order contents. Privacy laws such as GDPR and state laws such as the CCPA expect a business that shares personal data with a vendor to bind that vendor by contract.

Many 3PLs signed these addendums during onboarding with little negotiation, often on the shipper's paper and alongside a security questionnaire. They now sit next to the warehousing agreement and can decide the answer when someone asks whether order, fulfillment and returns history can be reused.

What does processing only on instructions mean?#

Processing only on instructions means the 3PL may handle the shipper's personal data solely to perform the services the shipper engaged it for, as documented in the agreement and the DPA. Processing for the 3PL's own purposes, such as building products, benchmarking for other clients or licensing to third parties, falls outside those instructions unless they expressly cover it.

Many DPAs add specific prohibitions: no selling or sharing personal data, no combining it with other clients' data, no use for the 3PL's own commercial purposes, and sometimes no use to train AI models. State privacy laws such as the CCPA generally expect service provider contracts to confine personal information to the contracted business purpose, with narrow allowances such as improving the service itself, and many DPAs track that language closely.

The instruction limit applies to personal data. Operational records with no personal data in them, such as dock-to-stock times, pick exceptions by SKU or carrier damage codes, are more often governed by the warehousing agreement's confidentiality terms than by the DPA.

Clause by clause: what the DPA says and what follows for reuse#

Seven DPA clauses decide what a 3PL may do with shipper data now: scope, processing on instructions, use restrictions, de-identification, subprocessors, return or deletion, and audit. Wording differs between shippers, and many 3PLs hold DPAs on several different templates.

Finding the DPAs is often the first real task. They may sit in the sales team's contract folder, a shipper's vendor portal, a security questionnaire attachment or an email thread from onboarding. Build a simple register with the shipper, the template used, the signature date, any AI or de-identification language and the deletion terms, so the analysis can run client by client.

Clause by clause: what the DPA says and what follows for reuse
ClauseWhat the 3PL signedWhat it means for reuse now
Scope and data categoriesA list of personal data categories and data subjectsDefines which records the DPA reaches; check whether order contents are listed
Processing on instructionsProcess only to provide the servicesThe 3PL's own uses of personal data generally need new authorization
Restrictions on useNo sale, sharing or combination with other dataLicensing personal data is generally excluded; de-identified use needs review
De-identificationSometimes expressly permitted, often silentFollow any stated conditions; where silent, counsel assesses whether creating de-identified data is permitted
SubprocessorsPrior notice or approval for subprocessorsSending data to an outside preparation vendor may count as engaging one
Return or deletionDelete or return personal data when services endFormer clients' personal data may already be due for deletion
Audit and cooperationShipper may audit complianceReuse decisions should be documented for a possible audit

Separate consent from the shipper is usually needed when the intended reuse involves the shipper's personal data and the DPA's instructions do not cover it. In practice that means a written amendment or authorization from the shipper, as the controller or business, rather than consent collected from consumers by the 3PL.

Records stripped of personal data before reuse need consent less often, but the stripping itself is generally treated as processing. Some DPAs permit de-identification expressly; others are silent or prohibit any processing beyond the services. Counsel decides which applies, and the main agreement's confidentiality terms still protect the shipper's business information either way. A written authorization usually covers these points:

  • Which records and fields are covered, and which are excluded.
  • That personal data is removed before any use outside the services.
  • The de-identification method and who performs it.
  • Permitted purposes for the resulting records, including any third-party license.
  • Whether the shipper's identity may appear, which is usually no.
  • How the shipper can withdraw the authorization for future records.

Former clients and old DPAs#

Former clients raise a specific problem: return-or-delete clauses may have required the 3PL to delete or return personal data when services ended, sometimes with a written certification. A 3PL that still holds years of consumer order data for departed clients should first check whether those duties were met, before considering any reuse.

Where retention was required by law or allowed by the DPA, the retained data is usually limited to that purpose. Reusing it for something else would generally need a fresh basis, which can be hard to obtain from a client who has moved on. Many 3PLs simply exclude former clients' personal data from any scope and fix their deletion process instead.

Illustrative: a fulfillment 3PL reviews its shipper DPAs#

Illustrative: a fictional fulfillment 3PL serves direct-to-consumer apparel and home goods brands. Its WMS holds order lines with consumer names and addresses, and its returns module holds return reasons and disposition decisions. Leadership asks whether pick, pack and returns exception records could be licensed.

Counsel finds most DPAs on the brands' paper with standard instruction limits. Two expressly bar AI training on brand data; a handful permit de-identified, aggregated use for service improvement only. Several former clients' consumer data was never deleted.

The 3PL excludes the brands with AI prohibitions and all former clients, starts deletion for departed clients, and asks the brands whose records matter most for written authorization. The candidate scope is built from operational events with consumer data removed at the source.

How SourceX approaches DPA-bound records#

When a 3PL reaches Rights, the second stage of the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery), its DPAs are read alongside the warehousing agreements they attach to. Records whose DPAs do not allow the intended use are excluded or held until the shipper authorizes it.

Personal data is removed in Preparation, and the privacy record and permitted use in the SourceX Evidence Packet show what was done under which authorization. A template outline of DPA terms for AI licenses helps when a shipper asks what it would be agreeing to.

Frequently asked questions

Is a B2B 3PL without consumer orders affected by DPAs?

Less, but often still. B2B warehouses also handle personal data: buyer contact names, receiver names, driver details and staff records. If a shipper sent a DPA, read its scope. Many B2B operational records carry little personal data, so the confidentiality terms may matter more than the DPA.

Does aggregated data fall outside the DPA?

Data that is truly aggregated, with no way to identify a person, is treated differently from personal data under many privacy laws. But the DPA may still limit creating it, and the shipper's confidentiality terms may still protect the business information it reveals. Check both before relying on aggregation.

What if we used our own DPA template with shippers?

Then your own drafting governs, which can help. Read what your template says about de-identified data, service improvement and analytics. If it already permits de-identified use for defined purposes, the remaining question is whether licensing to a third party falls within them.

Who at the shipper should sign an authorization?

Usually the person or function that signed the DPA or warehousing agreement, often with privacy or legal review on the shipper's side. An email from an operations contact is unlikely to be enough. Ask for a short written amendment that refers to the original agreement.

Do DPAs cover our warehouse staff data?

No. A shipper DPA covers personal data the 3PL processes for that shipper. Records about the 3PL's own employees, such as scan logs tied to picker IDs, fall under the 3PL's own employment notices and the privacy laws that may apply. Treat them as a separate review with its own decisions.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify