Our privacy policy

At SNCF Group, we’re committed to maintaining the highest ethical standards, in particular when it comes to protecting personal data.

In the course of our business, we collect and process personal data concerning our customers, our employees, and our partners, such as suppliers and service providers.

In an effort to promote innovation while at the same time building strong, lasting relationships based on mutual respect and shared, socially responsible values, we use technical and organizational measures to protect the personal data we process.

This policy describes SNCF Group’s commitments concerning the protection of personal data.

1. Fair, transparent collection

We inform our customers, employees, and partners of the processing of their data.

Our aim in collecting personal data is to optimize management of our relationships with our customers, employees, and partners.

2. Lawful and proportionate data processing

When we process data, we do so for specific purposes. Whenever we process data, there is a legitimate, defined, and explicit purpose.

We ensure that the data are retained in a form that permits identification of the data subjects for no longer than is necessary to accomplish the purpose of the processing.

3. Data minimization and accuracy

Whenever we process data, we undertake to collect and use only such data as are adequate, relevant, and limited to what is necessary for the purposes for which the data are processed.

4. Data protection

Each SNCF Group company has a designated Data Protection Officer (DPO).

At SNCF Group, we take technical and organizational measures to ensure that data are processed in a manner that ensures protection against accidental loss, destruction, or damage that could undermine their confidentiality or integrity.

When developing, designing, selecting, and using tools for the processing of personal data, we ensure (where applicable, working with the tools’ publishers) that they provide an optimal level of protection for processed data.

We take measures that comply with the principles of data protection by design and data protection by default. To that end, when possible and/or necessary, we use the techniques of pseudonymizing and encrypting data.

When using a service provider, we communicate personal data only after obtaining the provider’s commitment to comply with our own security rules.

We conduct audits of our own departments and of our service providers to verify compliance with data security rules.

5. Restricted access to data

SNCF Group follows strict authorization policies to ensure that the data we process are transmitted only to persons who are authorized to have access to them.

When we need to transfer data to a location outside the European Union, we do so only in accordance with specific contractual provisions and in compliance with the requirements of the competent supervisory authorities.

6. Respect for personal rights

We are particularly careful to respect the rights of data subjects:

  • the right to be informed;
  • the right to access;
  • the right to rectification;
  • the right to erasure (the “right to be forgotten”);
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object; and
  • the right to issue directives regarding the retention, erasure, and communication of personal data after the data subject is deceased.

7. Contacting us

SNCF Group handles requests from individuals wishing to exercise their data protection rights throughout the period in which their data is processed, subject to the procedures and time limits set out in applicable regulations.

Individuals may submit these requests online and/or by post, using the contact details provided in the relevant documents. These may include specific data processing notices, the terms and conditions for apps and websites, data collection forms, and similar materials.

If no specific instructions or contact details are provided, you may exercise your rights by using SNCF Group’s online rights request platform, which will direct your request to the Data Protection Officer of the relevant SNCF Group entity.

Details of how the platform processes the personal data needed to handle your request are provided in the relevant privacy notice.

Individuals must clearly state their first name(s) and surname, together with the address to which the response should be sent. If necessary to verify their identity, they may also be asked to provide a copy of an identity document.

SNCF Group will inform any individual exercising their rights if it is unable to comply with their request.