Lidl Connect - Privacy Policy

Last update: 29-09-2026
At 1GLOBAL, we are committed to protecting your privacy and ensuring the security of the personal data we process. All personal data collected by 1GLOBAL in connection with our services is processed in compliance with the General Data Protection Regulation (EU GDPR) 2016/679.
This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our services, including any data you may provide us when you purchase and use our mobile communication services, and informs you about your privacy rights and how the law protects you. For the purposes of this Privacy Policy, TP Ireland Operations Ltd, a company registered at Riverside One, Sir John Rogerson's Quay, Dublin 2, D02 X576, Ireland, is the data controller of your personal data and is referred to in this Privacy Policy as “1GLOBAL”, “we”, “us” or “our”.
1. IMPORTANT INFORMATION AND WHO WE ARE
Purpose of this privacy policy
This privacy policy aims to provide you with information on how 1GLOBAL collects and processes your personal data and applies to the services we provide to you, namely our data and connectivity services and associated products.
It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when collecting or processing your personal data. This ensures you are fully aware of how and why we use your data.
Contact details
If you have any questions about this privacy policy or our privacy practices, please reach out to our Data Protection Officer (DPO) via the following e-mail address: dpo@1GLOBAL.COM.
Changes to the privacy policy and your duty to inform us of changes
We regularly review and update our privacy policy. Any modifications will be posted on our websites and in the Lidl Connect section of the Lidl Plus App, as will be reflected in the “Last update” heading, and where applicable (for material changes), communicated to you. It is essential to ensure that the personal data we hold about you is accurate and up to date. Please inform us if your personal data changes during your relationship with us.
Third-party links
Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When leaving our website, we recommend reviewing the privacy policy of every website you visit.
2. THE DATA WE PROCESS ABOUT YOU
We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:
● Technical Data identifiers of your SIM/eSIM, device and mobile subscription (for example, your mobile number, your SIM/eSIM serial number and your device model).
● Usage and Connection Data means how you use our services, including the call date, times and lengths, metadata related to SMS sent/received, network usage made, information about the port-in progress of your telephone number and routing. In case you decide to transfer your number to another network, the name of your new service provider
● Identity Data This category may include name, surname, username, customer number, billing address, email address, telephone number, date of birth or similar identifier, tax ID, and identity document’s number if required for regulatory purposes.
● Payment Data information necessary to process the payment, including details of services you have purchased from us, amount/unit price paid, method of payment used during the purchase, payer ID and e-mail address, details of issued invoices, discounts and applicable taxes as well as possible refunds. We do not store credit card numbers as payments are processed securely through third-party PCI payment providers.
We also collect and use aggregated data, such as statistical or demographic data. Aggregated data could be derived from your personal data but will not directly or indirectly reveal your identity. For example, we may aggregate your Usage and Connection Data to calculate the percentage of users accessing a specific website feature.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
Direct interactions. You provide us with personal data when you:
● Purchase a Lidl Connect plan through the Lidl Plus App
● Activate your eSIM or physical SIM through the Lidl Plus App
● Use the Lidl Connect service, including making calls, sending SMS and using mobile data
● Contact Lidl Connect customer service by email or phone
● Submit a complaint or provide feedback about the service
Lidl Plus App: Additionally, when you contract the Lidl Connect service, we may receive certain personal data from your Lidl Plus account that you have previously provided to Lidl Plus. This may include, for example, your customer number, first and last name, date of birth, billing address and, where applicable, the telephone number you wish to port to Lidl Connect, as well as other information necessary to provide and manage the Lidl Connect service.
Automated technologies or interactions. We also collect certain data automatically when you use the Lidl Connect service, including through your use of calls, SMS and mobile data, and your interactions with the Lidl Plus App.
4. PURPOSES FOR WHICH WE WILL USE YOUR PERSONAL DATA AND LAWFUL BASIS
We have set out below, in a table format, a description of the personal data we collect. We rely on different legal bases to process your personal data and for each legal basis set out below, we have set out the purpose for each processing operation and the categories of personal data which is processed in respect of same.
Sometimes, these activities are carried out by third parties, including other members of the 1Global Group (see “Disclosure of your Personal Data ” section below).
Legal Basis: Necessary for the performance of the contract with you or to take steps for entering into a contract with you | ||
Purpose of Processing | Processing Operation | Categories of Personal Data |
To allow you to use our services, website and APP including establishing a technical connection between your devices and our server infrastructure | The collection, storage, analysis and disclosure of personal data | Technical Data Usage and Connection Data |
To process and deliver your purchase order including managing payments, fees and charges | The collection, storage, analysis and disclosure of personal data | Identity data Payment data Usage and Connection Data |
To manage our relationship with you which will include: (I) Notifying you about changes to our terms (II) Customer support | The collection, storage, analysis and disclosure of personal data | Identity data Technical Data Usage and Connection Data Payment Data |
Legal Basis: Legitimate Interests | |||
Purpose of Processing | Legitimate Interests | Processing Operation | Categories of Personal Data |
To collect and recover money owed to us | Our legitimate interests in efficiently running our business | The collection, storage, and analysis of personal data | Identity data Technical Data Usage and Connection Data Payment Data |
To administer and protect our business, the website and applications (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data, service improvement) | Our legitimate interests in running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise | The collection, storage, and analysis of personal data | Technical Data Usage and Connection Data |
To make suggestions and recommendations to you about goods or services that may be of interest to you. To develop our services and grow our business | Our legitimate interest in communicating with existing customers who have previously purchased or engaged in negotiations to acquire a similar service from us | The collection, storage, and analysis of personal data | Identity Data Technical Data Usage and Connection data |
Where this processing involves monitoring of Usage and Connection Data for network security or fraud-prevention purposes, it is carried out in accordance with the ePrivacy Regulations (S.I. No. 336 of 2011) governing the confidentiality of communications.
Legal Basis: Legal Obligations | ||
Purpose of Processing | Processing Operation | Categories of Personal Data |
To notify you of changes to our privacy policy or terms where required by law (e.g., Art. 13/14 GDPR, EECC-derived notice obligations) | The collection, storage, analysis and disclosure of personal data to ensure compliance with Art. 6(1)(c) GDPR; S.I. 444/2022 (EECC Regulations); Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023; Communications Regulation Act 2002, s.45; Consumer Rights Act 2022 | Identity data |
Based on an official request, if we are legally required to transmit data about your use of telecommunications services, such as telephony and the internet, to the competent authority | The collection, storage, analysis and disclosure of personal data to ensure compliance with Communications (Retention of Data) Act 2011 (as amended by Act 25/2022); Interception of Postal Packets and Telecommunications Messages (Regulation) Act 1993; Postal and Telecommunications Services Act 1983, ss.98 & 110; Policing, Security and Community Safety Act 2024; S.I. 336/2011 (ePrivacy Regulations); Data Protection Act 2018. | Technical Data Usage and Connection Data
|
To ensure regulatory compliance. | The collection, storage, analysis and disclosure of personal data to ensure compliance with identity verification and the Communications Regulation Acts 2002–2023; S.I. 444/2022 (EECC Regulations); Communications Regulation and Digital Hub Development Agency (Amendment) Act 2023; S.I. 360/2018 (NIS Regulations); Data Protection Act 2018. | Identity data |
5. AUTOMATED INDIVIDUAL DECISION-MAKING
1GLOBAL does not currently carry out any processing that involves decisions made solely by automated means (including profiling) that have legal or similarly significant effects on individuals, within the meaning of applicable data protection laws.
6. DISCLOSURE OF YOUR PERSONAL DATA
1GLOBAL takes care to allow access to personal data only to those who require such access. Whenever we permit a third party to access personal data, we will require those third parties to ensure that the confidentiality and integrity of the information is maintained and require that they have in place and maintain appropriate technical and organisational security measures.
1GLOBAL group of companies: We share your personal data among the 1GLOBAL Group companies as necessary for legitimate business purpose (such as data processing and storage; providing you with access to our services; providing customer support; making decisions about service improvements and for other purposes described in this Privacy Policy. Your personal data will in particular be shared with:
● 1GLOBAL TECHNOLOGIES (ASIA) LIMITED - Philippine Branch, having its registered office at 17F i-Square Building, #15 Meralco Avenue, Pasig City 1600, Philippines.
● 1GLOBAL Operations (UK) Ltd, 109 Farringdon Road, London, EC1R 3BW, United Kingdom.
● Other 1GLOBAL Group entities providing technical support and infrastructure services.
Third Party Service Providers: We may use third party service providers to perform services on our behalf or to assist us with the provision of services to you. In the course of providing such services, these third-party service providers may have access to your personal data or other information. We do not authorize them to use or disclose your personal information except in connection with providing their services to us. Third party service providers have a data processing agreement enforced by 1GLOBAL, thus cascading to them the security and privacy requirements we uphold with you.
We may make certain personal data available to these third parties (as further described in the table below) where these services are provided to us.
Service Providers | Purpose | Categories of Personal Data |
IT support provider | support and maintenance of our IT and communications infrastructure | Technical Data; Usage and Connection Data; Identity Data; Payment Data |
Business continuity provider | hosting | Technical Data; Usage and Connection Data; Identity Data; Payment Data |
Identity verification provider
| KYC verification | Identity Data |
Email and messaging service provider
| Delivering operational and transactional communications, notifications and contractual documents | Identity Data, Payment Data, Usage and Connection Data |
Marketing provider | insert e.g. to support our advertising and communications strategy and provide analytics about user interactions with our services and administer consumer surveys | Identity Data; Technical Data; Usage and Connection Data |
Payment service provider | to support our payment processes (i.e. processing credit card transactions and other payment methods | Identity Data; Payment Data; Technical Data |
Customer service provider | to support our response to customer queries (e.g. providing balance information) | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Other Transfers to Third Parties: We may also disclose and / or be obliged to disclose personal data to third parties in a manner that is consistent with our Privacy Policy including:
Third Parties | Purpose | Categories of Personal Data |
Our legal advisers | For advice and interpretation of law and regulations in connection with (i) the provision of our services (ii) the sale, assignment or other transfer of all or part of our business and (iii) as necessary to establish, exercise or defend against potential, threatened or actual litigation | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
External professional advisors including insurers | For the purposes of obtaining insurance cover and performing “due diligence” on our service providers (with your knowledge) | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Administrative authorities (tax or social security authorities) | To comply with legal requirements including tax related purposes | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Auditors | To ensure compliance with legal requirements and to comply with audit requests | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Financial institutions | For valuations of our assets and liabilities, and regulatory reporting as required by law | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Government bodies and law enforcement organisations | For the purposes of crime prevention and compliance with regulatory requirements and applicable laws | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Relevant industry bodies and regulatory authorities (e.g. the Data Protection Commission) | For the purposes of compliance with regulatory requirements and applicable laws | Identity Data; Technical Data; Usage and Connection Data; Payment Data |
Lidl Stiftung & Co. KG | Distribution of Lidl Connect plans, customer account management, payment processing through the Lidl Plus App, and customer service | Identity Data; Technical Data; Payment Data; Usage and Connection Data |
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
7. INTERNATIONAL TRANSFER
Whenever we transfer personal data outside the European Economic Area (EEA), we ensure that such transfers comply with GDPR requirements.
When transferring personal data outside of the EEA, we rely on the following transfer mechanisms in accordance with the GDPR:
Categories of Personal Data | Destination | Transfer Mechanism |
Identity Data; Technical Data; Usage and Connection Data; Payment Data | United Kingdom | Adequacy decision |
Identity Data; Technical Data; Usage and Connection Data; Payment Data | Philippines | EU Standard Contractual Clauses and supplementary measures |
Where applicable, you may request a copy of the transfer mechanism specified by using the contact details set out in the ‘contact details’ section above.
8. DATA SECURITY
1GLOBAL implements technical measures to ensure the confidentiality of communications content across its services and complies with all applicable legal obligations and exceptions under relevant legislation.
9. DATA RETENTION
How long will you use my personal data for?
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal, regulatory, tax, accounting, or reporting obligations. We ensure that personal data is securely deleted or anonymised when no longer needed, in compliance with Article 5(1)(e) GDPR. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
10. YOUR LEGAL RIGHTS
You can request from 1GLOBAL access to your personal data and also the rectification, deletion, restriction of processing, or transfer of your personal data. In certain circumstances you also have the right to object to the processing of your personal data. If we have collected and processed your personal information based on your consent, then you can withdraw your consent at any time; withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
These rights are not absolute and may be subject to applicable laws and our own legitimate interests. If you want to contact us about any of your rights or complain about how we use your information, please contact us at dpo@1global.com.
You have the right to file a complaint with the Data Protection Commission (DPC), the supervisory authority in Ireland, at www.dataprotection.ie. You also have the right to lodge a complaint with the competent data protection authority in your country of residence or place of work. Of course, we value the opportunity to deal with any concerns directly before they are shared externally and would encourage you to raise them using the contact details above as a first step.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you informed of the progress, including providing an estimated timeframe for our response, in accordance with Article 12(3) GDPR.
1GLOBAL is a trading name of 1GLOBAL Holdings B.V.