Compliance & Safety

GDPR for Tradespeople: What You Must Do With Customer Data

The Gaffer Team··6 min read

You quote a job, take a name, an address, a phone number and maybe a few photos of someone's boiler. The moment you do that, you are handling personal data — and the rules that cover it apply to a one-van plumber just as much as a high-street bank. The good news is that compliance for a typical trade business is mostly common sense, not a legal degree.

This is the plain-English version. It is general guidance, not legal advice, so for anything you are unsure about, check the current official guidance from the Information Commissioner's Office (ICO) rather than treating any rule here as fixed.

Does GDPR Actually Apply to a One-Van Trade Business?

Short answer: yes, almost certainly. UK GDPR and the Data Protection Act apply to anyone who processes personal data about living people in connection with a business — and there is no "too small to bother" exemption.

"Personal data" is anything that identifies a person. For a trade business that usually means:

  • Customer names, addresses, phone numbers and emails
  • Job notes, quotes, invoices and payment details
  • Photos of a property or job that show whose it is
  • Staff and subcontractor records if you employ people

You do not need a fancy database to be caught by this. A WhatsApp thread full of customer addresses, a notebook on the dashboard, or a spreadsheet of leads all count.

What You Must Actually Do

You do not need to drown in paperwork. For most sole traders and small firms, the practical core comes down to a handful of habits.

  • Only collect what you need. You need a homeowner's address to do the job. You probably do not need their date of birth.
  • Tell people how you use their data. A short, honest privacy notice on your website or quote is enough for most trades.
  • Keep it secure. Lock your phone, use strong passwords, and do not leave customer lists in an unlocked van.
  • Do not keep it forever. Hold records for as long as you genuinely need them (tax, warranty, certification) then delete them.
  • Let people see or delete their data. If a customer asks what you hold about them, you generally have to tell them, usually within a month.

Quick tip: write down, in a few lines, what data you hold, why, where it lives and how long you keep it. That single note is most of your "compliance" sorted and is exactly what you would show if anyone ever asked.

Do You Need to Pay the ICO Fee?

Most businesses that process personal data electronically must pay the ICO an annual data protection fee. As a rough guide it sits in the tens of pounds for a small business, but the bands and exemptions change, so check the current fee and the self-assessment tool on the ICO website rather than guessing.

There is an important split here that trips people up.

Doing the job rarely needs explicit consent. If someone asks you to fix their heating, you have a lawful reason to hold their details to carry out that work and invoice for it.

Marketing is different. Sending "service due" texts, newsletters or special offers is covered by separate rules (PECR) as well as GDPR. As a general rule:

  • Get clear permission before adding someone to a marketing list.
  • Always include an easy way to opt out.
  • Keep a record of who agreed and when.

This is where reminders get nuanced. A genuine safety or service reminder to an existing customer — like a gas safety check or an annual boiler service — is usually fine and welcomed. If you want to automate those properly, see how to automate annual gas service reminders, and keep the messaging useful rather than salesy.

Keeping Customer Data Secure (the Bit That Bites)

The single most common cause of a data problem in a small business is not a hacker — it is a lost phone, a shared password, or a spreadsheet emailed to the wrong person. Security does not have to be expensive.

  • Put a PIN or biometric lock on every phone and tablet that touches customer data.
  • Use a different, strong password for each important account, ideally with a password manager.
  • Turn on two-factor authentication for email and any software holding customer records.
  • Be careful with shared inboxes and group chats — old messages pile up with personal data in them.

This is one of the strongest arguments for getting customer details out of scattered notebooks and chat apps. Running everything through one secure system means data is encrypted, access-controlled and backed up, instead of sitting on a cracked phone screen or in a years-old message thread. If you are still co-ordinating jobs over chat, it is worth reading why you should stop running your business on WhatsApp.

A platform like Gaffer keeps customer records, quotes, certificates and payment details in one access-controlled place, so you are not duplicating data across half a dozen apps — which is both more secure and a lot less admin.

Handling Photos, Certificates and Old Records

Two areas catch trades out specifically.

Job photos. Pictures of a property, a meter cupboard or a damaged ceiling can be personal data, especially with an address attached. Take what you need for the job, store it securely, and do not post identifiable photos publicly without permission.

Certificates and compliance documents. EICRs, gas safety records and installation certificates contain names and addresses, and you often have to keep them for years. That is a legitimate reason to hold the data — just store them properly and securely rather than in a pile in the van. A tidy, searchable store also makes you audit-ready, which is covered in how to store certificates and stay audit-ready.

When records are no longer needed for tax, warranty or legal reasons, delete them. Holding data "just in case" forever is the opposite of what the rules want.

What Happens If You Get It Wrong

The headlines about huge GDPR fines almost always involve large companies and serious, deliberate failures. A small trade business that makes a genuine mistake and acts quickly is in a very different position.

If you do have a data breach — say a laptop full of customer details is stolen — you may need to report it to the ICO, generally within 72 hours if there is a real risk to the people involved. The ICO's own guidance is the place to check what counts and what to do. Acting fast and honestly matters far more than pretending it did not happen.

FAQs

Do sole traders need to comply with GDPR?

Yes. If you process personal data about living people for your business — names, addresses, phone numbers, job records — UK GDPR applies regardless of your size. There is no exemption for being a one-person operation.

Do tradespeople have to pay the ICO data protection fee?

Most businesses that process personal data electronically must pay an annual fee, which for a small business is usually in the tens of pounds. The bands and exemptions change, so use the ICO's self-assessment tool to check your exact position.

Can I text customers reminders about their next service?

Usually yes for genuine service or safety reminders to existing customers, but pure marketing messages need clear permission and an easy opt-out under the PECR and GDPR rules. Keep reminders useful and always let people unsubscribe.

How long should I keep customer records?

Keep them only as long as you have a genuine reason — typically tax, warranty or certification requirements — then delete them securely. Holding data indefinitely "just in case" is not compliant.

Run your trade business on Gaffer

Jobs, quotes, invoices, scheduling and customer messaging in one place — built for UK trades. Start free, no card needed.

Start your 14-day free trial