GDPR for tradesman websites — what you actually have to do (and what you can ignore)
Plain English on what UK GDPR means for a small trade firm with a website, a chatbot and a customer list. The five things you must do, the three you should do, and the noise you can ignore.
Every trade firm in the UK with a customer list — i.e. all of them — falls under UK GDPR (formally the UK GDPR + Data Protection Act 2018). The rules sound terrifying when consultants describe them. They're actually pretty manageable when you strip out the fear and look at what the regulator (the ICO) actually expects of small businesses.
This article is plain English from a non-lawyer. If your data setup is unusual — handling health data, working with vulnerable adults, processing for a Tier 1 contractor with their own compliance regime — get proper legal advice. For a standard one-van-to-mid-size trade business with a website and a Klaviyo list, what follows is what you actually need to do.
What 'personal data' covers
Anything that identifies a living person. For a tradesman that's: name, phone number, email, address, postcode, photos of their property (if linked to them), notes about the job. If you've got any of those, you're processing personal data under UK GDPR.
Business-to-business contact info — info@plumbingsupplies.com — is treated more lightly but still personal data if the email belongs to an identifiable person.
Must-do 1 — Lawful basis
You need to know why it's legal for you to hold each piece of customer data. For a trade firm there are usually three lawful bases:
- Contract — you need their address to do the job they hired you for
- Legitimate interest — you keep their contact details for after-care and warranty follow-up
- Consent — they explicitly opted into your marketing list
You don't need to record this for every customer. You need to know it for each category of data you hold. Write it down in your privacy policy.
Must-do 2 — Privacy policy on the website
Every trade website needs a privacy policy explaining what data you collect, why, how long you keep it, and how a customer can get it deleted. The ICO has a free template at ico.org.uk that's specifically designed for small businesses. Copy it, customise the five or six bracketed sections, paste into your website, link from the footer.
Cost: nothing. Time: 45 minutes.
Must-do 3 — Secure storage
Customer data needs to be stored in a way that's reasonably secure. For most trades this means:
- Phone or laptop with a passcode / password
- Email account with two-factor authentication
- Cloud storage (Google Drive, Dropbox) with strong password
- Don't email customer phone numbers in plain text to random suppliers
You don't need ISO 27001. You need basic password hygiene. If you write customer details in a paper notebook, keep the notebook in the van not in the cafe.
Must-do 4 — Delete on request
If a former customer asks you to delete their data, you have to do it within one month. There are limited exceptions — e.g. you can keep an invoice for HMRC purposes for 6 years even if the customer asks — but for marketing data, contact details and chat history, delete on request is the rule.
Practical: have a list of where customer data lives (your phone, your email, your invoicing app, your chatbot platform, your CRM) so when a request comes in, you can hit all of them. Most requests come from customers who never want to hear from you again — usually after an unrelated bad experience. Process them politely and move on.
Must-do 5 — Report breaches
If something goes wrong — laptop nicked, phone lost, email account hacked, supplier list accidentally emailed to the wrong person — and personal data has potentially leaked, you may need to report it to the ICO within 72 hours. The threshold is 'likely to result in risk to people' — most small leaks don't qualify, but the ICO has clear guidance and a self-assessment tool.
Practical: if it happens, don't panic, don't hide it. Check the ICO self-assessment, decide if it's reportable, report if needed.
Should-do 1 — Cookie banner (if your site has analytics)
If your website uses Google Analytics, Facebook Pixel, or any third-party tracking script, you need a cookie banner that lets visitors say yes / no before non-essential cookies are dropped. Most website builders (Wix, Squarespace, Shopify) have a built-in cookie banner — turn it on. WordPress has free plugins (Cookie Notice for GDPR, Complianz) that do the job.
Cost: nothing. Time: 20 minutes.
Should-do 2 — Retention policy
Decide how long you'll keep each category of data and write it down. Typical for a trade:
| Data | Retention |
|---|---|
| Invoice / accounting records | 6 years (HMRC requirement) |
| Customer contact + job history | 3 years after last job |
| Marketing list (opt-ins) | Until they unsubscribe |
| Chatbot transcripts | 12 months |
| Photos of customer's home | 1 year after job complete |
Set up reminders to delete what you're past retention on. Most digital tools (Klaviyo, HubSpot, Voxinly) have built-in retention settings — configure them once.
Should-do 3 — Supplier list
Keep a list of who else processes your customer data on your behalf — your accountant, your CRM provider, your chatbot platform, your invoicing software, your email marketing tool. Each should have its own privacy policy you can point a customer at if they ask. The list goes in (or with) your own privacy policy.
Ignore — the noise
Things you'll be sold that you almost certainly don't need:
- A £2,000 GDPR audit from a consultancy
- A DPO (Data Protection Officer) — only needed for large or sensitive processors
- ISO 27001 certification — only relevant for B2B selling into procurement-heavy organisations
- Bespoke privacy policy drafting — the ICO template is fine for 95% of trades
- Annual GDPR training packages
If a supplier tries to scare you into a five-figure compliance package, walk away. The ICO's whole stance toward small businesses is proportionate. Their guidance is free and clear. Use that first.
What about the chatbot specifically?
A website chatbot collecting names, phone numbers and job details is personal-data processing. Mention it in your privacy policy ('we use a chatbot to handle initial enquiries — [provider name] is our processor'). If the chatbot stores chat transcripts, set the retention period (12 months is typical). Voxinly's privacy controls live in /admin/privacy and let you set retention, customer data export and right-to-delete defaults in one place.
FAQ
Do I need to register with the ICO?
Probably yes — most data-handling businesses pay a small annual fee (£40-£60 for a sole trader, more for larger firms) to register with the ICO. Takes 15 minutes online.
What if I work freelance / I'm a sole trader?
GDPR still applies. Compliance is proportionate — a sole-trader plumber's expected effort is much less than Sainsbury's. The five must-dos above cover it.
What about WhatsApp messages with customers — are those covered?
Yes — same rules apply. Keep your phone passcoded, delete old chats when retention expires, don't share customer numbers with third parties without lawful basis.
Can I keep using my customer list for marketing?
Existing customers — yes under legitimate interest, as long as you offer unsubscribe in every message. Cold prospects — you need explicit opt-in.