Chiltern Railways Privacy Notice

Last update: June 2026

At Chiltern Railways we understand the importance of handling personal data in ways that are fair, legal and transparent. 

This policy explains how and why we process your personal data whenever you interact with us, be it via our website, in person or through our app.

If you don’t want to read all of the detail, here are the points we think you’re most likely to want to know;

  • We are The Chiltern Railway Company Limited, trading as Chiltern Railways.  We make the decisions about how and why your personal data is processed.
  • We do, where necessary, share information about you with our third-party organisations who process your data on our behalf
  • You have a number of rights over your personal data. How you can exercise these rights is set out in this notice.
  • We do send direct marketing where are legally allowed to. You have the right to opt out of our marketing at any time.  The ‘Contact us’ section below tells you how you can do this.

 

About us

We are The Chiltern Railway Company Limited, trading as Chiltern Railways.  We are currently part of the Arriva Group and our registered office address is;

Arriva Plc, 1 Admiral Way, 
Doxford International Business Park, 
Sunderland, 
SR3 3XP

We are registered with the Information Commissioner’s Office as a ‘Data Controller’ which means we are a legal entity that makes decisions about how your personal data is processed.
 

Contents

What sorts of personal data do we process?

Personal data is defined as any information that either by itself, or put together with other information, can identify a living individual.

Type of DataExamples

Account data

 

This is personal data such as your name, home address, date of birth, email, and payment card details.

 

Transaction data

 

Information about your travel history, the tickets that you buy from us, when and where you bought them and how much you paid.

 

Interaction data

 

These include your calls and correspondence with our Customer Relations Team and any feedback you provide or research you participate in. 

 

CCTV data

 

If you commit, are suspected of committing, or are a victim of fraud or another crime, we process data related to this. This could include information from ticket inspections, delay repay claims, or incidents on our trains or at stations.

 

Incident/investigation data

 

If you commit, are suspected of committing, or are a victim of fraud or another crime, we process data related to this. This could include information from ticket inspections, delay repay claims, or incidents on our trains or at stations.

 

Device data

 

This is information from devices you use to access our on-train and station Wi-Fi.  This could include information such as IP addresses, MAC addresses, information about your browser, your name and your email address.

 

Preference Data

 

Information about whether or not you want to receive marketing, and details of the emails and other electronic communications you receive from us, and how you interact with them. For example, whether the communication has been opened, if you have clicked on any links within that communication and the device you used.

 

 

Our legal bases for processing your personal data

Whenever we process your personal information we have to have something called a “legal basis” (a legal reason) for what we do. The different legal bases we rely on are:

  • •    Consent: You have told us you are happy for us to process your personal information for a specific purpose (s);
  • •    Legitimate interest/recognised legitimate interests: The processing is necessary for us to conduct our services, but not where our interests are overridden by your interests or rights.
  • •    Performance of a contract: We must process your personal information in order to be able to provide you, or a third party with one of our products or services;
  • •    Vital interests: The processing of your personal information is necessary to protect you or someone else’s life;
  • •    Legal obligation: We are required to process your personal information by law.
     

In the limited circumstances that we need to process your special category data (personal data that is considered sensitive and requires extra protections in place), we’re legally required to have at least one additional legal basis in place.  This will most likely be one of the following;

  • •    Explicit consent: This is where you have explicitly provided your consent for us to process your data. An example of this is the health information you provide to Passenger Assist.
  • •    Legal claims and judicial acts: Where Chiltern Railways need to process your special category data to create, exercise or defend legal claims.
  • •    Substantial public interest: This is when Chiltern Railways need to process your special category data for reasons of substantial public interest (e.g. regulatory requirements, preventing or detecting unlawful acts).

     

How we use your personal data and our legal bases for doing so

Purpose of processingLegal basis for processing

Provision of your tickets (including, renewals, and cancellations) to use our services.
Responding to your enquiries and complaints.
Handling the administration of your payment, issuing tickets/products, or confirming orders.
Providing access to our wi-fi.

Data types: Account data, transaction data

 

Performance of a contract

 

Sending you marketing communications, travel rewards & promotions.
Our use of web analytics via cookies to customise you’re your website visits
Storing credit/debit card information on Chiltern website or app

Data types: Account data, transaction data, preference data

 

Consent

 

Our use of CCTV/BWC to prevent, deter and detect crime.
Complying with requests from law enforcement agencies, courts, or regulators
Managing a sale, restructuring, or merger of our business
Publishing the names of our competition prize draw winners

Data Types: CCTV data, account data, transaction data, incident/investigation data

 

Legal obligation

 

Analysis & modelling for marketing campaigns 
Surveys
Competition entries
Providing passenger assistance

Data types: Preference data, account data, transaction data, interaction data

 

Legitimate interest/Consent/Explicit consent

 

Undertaking law enforcement activities including;
•    the detecting, investigating, and preventing of fare evasion or other fraudulent offences
•    Execution of criminal penalties
•    Safeguarding against and preventing threats to public security

Data types: CCTV data, account data, transaction data, interaction data, incident/investigation data

 

Performance of a contract/Public Task

 

Maintaining the safety and security of;
•    The public
•    Our property
•    Our colleagues
Facilitating the return of lost property
Issuing Authority to Travel (ATT) permits

Data types: CCTV data, account data, transaction data, interaction data, incident/investigation data

 

Legitimate interest 

 

Sharing your personal data

We will share your personal data with the following third parties as part of the purposes set out above:

The Arriva Group

Third parties we partner with – we work with different third parties to ensure we deliver the best possible service to our customer. These third parties include:

  • •    Legal, regulatory, and insurance-related third parties
  • •    Marketing and advertising partners
  • •    IT support, data hosting, and system administrators
  • •    Ticketing and payment service providers
  • •    Mailing houses sending pre-booked tickets and marketing materials
  • •    Website developers and hosting providers managing website content and personalised messaging
  • •    Wi-Fi providers supporting onboard internet services
  • •    Website analytics and customer research agencies


Other organisations and individuals - we may share your personal information in certain scenarios. For example, we may disclose your personal data to any competent law enforcement body, regulator, government agency or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation; (ii) to exercise, establish or defend or legal rights; or (iii) to protect your vital interests or those of any other person.

We may also transfer your personal data to a buyer or potential buyer (and its agents and advisers) in connection with any reorganisation, restructuring, merger or sale, or other transferring of assets.

We operate the Chiltern Railways franchise under arrangements with the Secretary of State for Transport and the franchise operations may pass to a successor operator. We may disclose your personal data to the relevant franchising authority and/or any successor operator, who will use your personal information only for the purposes disclosed in this Privacy Notice.
 

Transferring your data internationally

Some of our third-party partners are based outside of the United Kingdom and we do occasionally transfer your personal data to them.  When we do this we ensure that there are one or more appropriate safeguards in place ensuring your data is kept protected in line with data protection legislation.

Your rights

You have a number of rights under data protection legislation which, in certain circumstances, you may be able to exercise in relation to the personal information we process about you. These include:

  • •    the right to access a copy of the personal information we hold about you;
  • •    the right to correction of inaccurate personal information we hold about you;
  • •    the right to restrict our use of your personal information;
  • •    the right to be forgotten;
  • •    the right of data portability; and
  • •    the right to object to our use of your personal information.

From the 19th of June 2026 individuals have a new statutory "right to complain".  This allows you to complain directly to us if you’re unhappy about how we have handled your personal data.  

If you are seeking to exercise any of these rights, please contact us using the details in the "Contact Us" section below. Please note that we will need to verify your identity before we can fulfil any of your rights under data protection law. This helps us to protect your personal data against fraudulent requests.
 

How long do we keep your personal data for?

We will keep your personal information for the purposes set out in this privacy policy and in accordance with the law and only for as long as is necessary. In most cases, our retention period will come to an end 7 years after the end of your relationship with us.

Contact us

If you would like to exercise one of your rights as set out in the "Your rights" section above, or you have a question or a complaint about this policy, or the way your personal information is processed, please contact us by one of the following means:

By email: [email protected] 

By post: Data Protection Officer, The Chiltern Railway Company Limited, Great Central House, Marylebone Station, Melcombe Place, London, NW1 6JJ

You also have the right to lodge a complaint with the UK regulator, the Information Commissioner. Please visit ico.org.uk/concerns to find out more.
 

Privacy notice change:

This notice was last updated in June 2026. Our previous privacy notice can be found on the following link: chilternrailways.co.uk/privacy