Does GDPR Really Apply to Me?
Short answer: yes. If you hold any information about living, identifiable people — customers' names, addresses, phone numbers, email addresses — the UK General Data Protection Regulation (UK GDPR) applies to your business. That includes sole traders working alone, not just limited companies with HR departments.
The good news is that the law scales with you. As a small trade business, your obligations are proportionate to your size and the data you actually hold. You are not expected to hire a Data Protection Officer or write a 40-page policy. But you do need to take a few concrete steps — and ignoring the rules entirely can result in fines from the Information Commissioner's Office (ICO) or, more likely, a serious loss of customer trust.
What Counts as Personal Data?
Personal data is any information that can identify a living person, directly or in combination with other details. For a tradesman, this typically includes:
- Customer names and addresses (including job-site addresses)
- Phone numbers and email addresses
- Photographs taken inside or outside a customer's home
- Payment details and bank account information
- Signed certificates and job reports that reference a named customer
- CCTV footage if you operate a van or workshop with cameras
Business names and general company addresses on their own are not personal data — but the name of a sole trader running that business is. If your customer is a self-employed person or a landlord you deal with personally, treat all their details as personal data.
Your Lawful Basis for Holding Data
UK GDPR requires you to have a valid reason — a "lawful basis" — for processing personal data. For most tradesmen, two bases cover nearly everything:
- Contract performance: You need the customer's name and address to carry out the job and issue an invoice. This is your primary lawful basis for almost all data you collect.
- Legitimate interests: Keeping records of past jobs for warranty purposes, or following up on a quote, can fall under this basis — provided the interest is genuine and doesn't override the customer's privacy rights.
You generally do not need to ask customers to tick a consent box just to hold their contact details for a job you're doing for them. Consent is required for things like adding them to a marketing mailing list — which is a separate matter entirely.
Site Photos and Customer Premises
Taking photos on a job is standard practice — for your own records, to document completed work, or for insurance purposes. Under UK GDPR, photographs of the inside of someone's home can constitute personal data, particularly if they show recognisable personal belongings, family photos on walls, or information that identifies the property.
Here's a practical approach:
- Before the job: Mention to the customer that you take photos for your records. A brief verbal note or a line in your quote documents is sufficient — you don't need a signed form for routine job photography.
- For social media or marketing: You do need explicit permission before posting customer property photos online. Get this in writing — a WhatsApp reply is far better than nothing, but keep your request specific so it is obvious exactly what was agreed to.
- Storage: Don't leave customer site photos in a publicly accessible cloud folder or on your personal social media. Store them in a dedicated business folder, preferably password-protected.
Digital Certificates and Job Records
Completion certificates — gas safety records (CP12), electrical installation condition reports (EICRs), minor works certificates, and similar documents — contain personal data: the customer's name, address, and details of their property's systems. This makes them subject to UK GDPR requirements on storage, retention, and sharing.
How Long Should You Keep Records?
Different regulations set different minimum retention periods, and you must meet both the trade standard and data protection principles:
- Gas safety records (Landlord CP12): Landlords must keep records for two years under the Gas Safety (Installation and Use) Regulations 1998. As the engineer, keeping your copy for the same period is reasonable.
- Electrical certificates: No single statutory minimum, but industry guidance from the IET and NICEIC recommends keeping records for at least six years — aligning with standard limitation periods for civil claims.
- General job records and invoices: HMRC requires you to keep financial records for at least five years after the 31 January tax return deadline. This often drives your minimum retention period in practice.
UK GDPR's "storage limitation" principle says you shouldn't keep personal data longer than necessary. For certificates, "necessary" is determined by those regulatory and tax requirements above — so keeping them for six years is a defensible policy. After that, delete or securely destroy them.
Sharing Certificates with Third Parties
Landlords often ask you to send a certificate directly to a tenant, letting agent, or mortgage company. This is fine — it falls within the original purpose of issuing the certificate — but make sure you only share it with parties the customer has authorised. Don't forward a customer's records to an unknown third party without their say-so.
Do You Need to Register with the ICO?
Most businesses that process personal data must pay the ICO's data protection fee — this is separate from, and often confused with, "registering under GDPR." The fee is £52 a year for most small organisations (Tier 1), or £47 if you pay by Direct Debit. You can check whether you need to pay and register at the ICO website.
Exemptions exist for some sole traders, including those who only process data for personal, family, or household purposes — but if you hold customer data for business purposes (which you do), you almost certainly need to pay the fee. Failure to do so can result in a penalty of up to £4,350.
Practical Steps to Get Compliant
You don't need a solicitor or a consultant to get the basics right. Work through this checklist:
- Audit what you hold: Go through your phone, laptop, paper files, and email. List every place customer data lives.
- Secure it: Enable a PIN or biometric lock on your phone. Use a password on your laptop. Don't leave paper job sheets in an unlocked van.
- Register with the ICO if you haven't already, and pay the annual fee. Takes 10 minutes at ico.org.uk/registration.
- Write a brief privacy notice: One paragraph on your website or quote template explaining what data you collect, why, and who to contact with questions. The ICO provides free templates.
- Set a deletion policy: Decide how long you'll keep records (six years covers most scenarios) and actually delete old files when the time comes.
- Train yourself on breaches: If customer data is lost, stolen, or accidentally sent to the wrong person, assess whether it needs reporting. The ICO's self-assessment tool takes five minutes.
Responding to Customer Requests
Under UK GDPR, individuals have rights over their data, including the right to access it, correct it, or request deletion. In practice, most customers will never exercise these rights — but you need to know what to do if they do.
- Subject Access Request (SAR): A customer asks to see all the data you hold on them. You must respond within one calendar month, free of charge. Simply compile any records — job sheets, certificates, emails — that reference them, and send it.
- Right to erasure: A customer asks you to delete their data. You can comply, but you're entitled to refuse if you need the data to meet a legal obligation (e.g., tax records). Explain this clearly.
These requests are rare for tradespeople, but handling them calmly and promptly if they do arise demonstrates professionalism and avoids formal complaints to the ICO.
The Bottom Line
GDPR compliance for a sole trader or small trade business is not complicated. It comes down to: know what data you hold, keep it secure, don't keep it longer than you need to, don't share it without good reason, and register with the ICO. A few hours of organisation now means you can answer any customer query or regulatory question with confidence — and that's good for business as well as being the law.
Create compliant certificates in minutes
CertBox helps tradespeople produce professional, regulation-compliant certificates on any device.
Start freeFree to start. No card required.
Free weekly trade guides
Regulation updates and practical guides, straight to your inbox every Monday.
Subscribe to the newsletterPublished 2026-07-27. This article is for general guidance only and does not constitute legal or professional advice. Always refer to the relevant standards and consult qualified professionals for definitive requirements.