Voxinly
Compliance

GDPR for tradesman websites — what you actually have to do (and what you can ignore)

Plain English on what UK GDPR means for a small trade firm with a website, a chatbot and a customer list. The five things you must do, the three you should do, and the noise you can ignore.

1 June 2026·8 min read·Sally / Voxinly team
A British high-street office desk with paperwork and a laptop

Every trade firm in the UK with a customer list — i.e. all of them — falls under UK GDPR (formally the UK GDPR + Data Protection Act 2018). The rules sound terrifying when consultants describe them. They're actually pretty manageable when you strip out the fear and look at what the regulator (the ICO) actually expects of small businesses.

This article is plain English from a non-lawyer. If your data setup is unusual — handling health data, working with vulnerable adults, processing for a Tier 1 contractor with their own compliance regime — get proper legal advice. For a standard one-van-to-mid-size trade business with a website and a Klaviyo list, what follows is what you actually need to do.

What 'personal data' covers

Anything that identifies a living person. For a tradesman that's: name, phone number, email, address, postcode, photos of their property (if linked to them), notes about the job. If you've got any of those, you're processing personal data under UK GDPR.

Business-to-business contact info — info@plumbingsupplies.com — is treated more lightly but still personal data if the email belongs to an identifiable person.

Must-do 1 — Lawful basis

You need to know why it's legal for you to hold each piece of customer data. For a trade firm there are usually three lawful bases:

  • Contract — you need their address to do the job they hired you for
  • Legitimate interest — you keep their contact details for after-care and warranty follow-up
  • Consent — they explicitly opted into your marketing list

You don't need to record this for every customer. You need to know it for each category of data you hold. Write it down in your privacy policy.

Must-do 2 — Privacy policy on the website

Every trade website needs a privacy policy explaining what data you collect, why, how long you keep it, and how a customer can get it deleted. The ICO has a free template at ico.org.uk that's specifically designed for small businesses. Copy it, customise the five or six bracketed sections, paste into your website, link from the footer.

Cost: nothing. Time: 45 minutes.

Must-do 3 — Secure storage

Customer data needs to be stored in a way that's reasonably secure. For most trades this means:

  • Phone or laptop with a passcode / password
  • Email account with two-factor authentication
  • Cloud storage (Google Drive, Dropbox) with strong password
  • Don't email customer phone numbers in plain text to random suppliers

You don't need ISO 27001. You need basic password hygiene. If you write customer details in a paper notebook, keep the notebook in the van not in the cafe.

Must-do 4 — Delete on request

If a former customer asks you to delete their data, you have to do it within one month. There are limited exceptions — e.g. you can keep an invoice for HMRC purposes for 6 years even if the customer asks — but for marketing data, contact details and chat history, delete on request is the rule.

Practical: have a list of where customer data lives (your phone, your email, your invoicing app, your chatbot platform, your CRM) so when a request comes in, you can hit all of them. Most requests come from customers who never want to hear from you again — usually after an unrelated bad experience. Process them politely and move on.

Must-do 5 — Report breaches

If something goes wrong — laptop nicked, phone lost, email account hacked, supplier list accidentally emailed to the wrong person — and personal data has potentially leaked, you may need to report it to the ICO within 72 hours. The threshold is 'likely to result in risk to people' — most small leaks don't qualify, but the ICO has clear guidance and a self-assessment tool.

Practical: if it happens, don't panic, don't hide it. Check the ICO self-assessment, decide if it's reportable, report if needed.

Should-do 1 — Cookie banner (if your site has analytics)

If your website uses Google Analytics, Facebook Pixel, or any third-party tracking script, you need a cookie banner that lets visitors say yes / no before non-essential cookies are dropped. Most website builders (Wix, Squarespace, Shopify) have a built-in cookie banner — turn it on. WordPress has free plugins (Cookie Notice for GDPR, Complianz) that do the job.

Cost: nothing. Time: 20 minutes.

Should-do 2 — Retention policy

Decide how long you'll keep each category of data and write it down. Typical for a trade:

DataRetention
Invoice / accounting records6 years (HMRC requirement)
Customer contact + job history3 years after last job
Marketing list (opt-ins)Until they unsubscribe
Chatbot transcripts12 months
Photos of customer's home1 year after job complete

Set up reminders to delete what you're past retention on. Most digital tools (Klaviyo, HubSpot, Voxinly) have built-in retention settings — configure them once.

Should-do 3 — Supplier list

Keep a list of who else processes your customer data on your behalf — your accountant, your CRM provider, your chatbot platform, your invoicing software, your email marketing tool. Each should have its own privacy policy you can point a customer at if they ask. The list goes in (or with) your own privacy policy.

Ignore — the noise

Things you'll be sold that you almost certainly don't need:

  • A £2,000 GDPR audit from a consultancy
  • A DPO (Data Protection Officer) — only needed for large or sensitive processors
  • ISO 27001 certification — only relevant for B2B selling into procurement-heavy organisations
  • Bespoke privacy policy drafting — the ICO template is fine for 95% of trades
  • Annual GDPR training packages

If a supplier tries to scare you into a five-figure compliance package, walk away. The ICO's whole stance toward small businesses is proportionate. Their guidance is free and clear. Use that first.

What about the chatbot specifically?

A website chatbot collecting names, phone numbers and job details is personal-data processing. Mention it in your privacy policy ('we use a chatbot to handle initial enquiries — [provider name] is our processor'). If the chatbot stores chat transcripts, set the retention period (12 months is typical). Voxinly's privacy controls live in /admin/privacy and let you set retention, customer data export and right-to-delete defaults in one place.

FAQ

Do I need to register with the ICO?

Probably yes — most data-handling businesses pay a small annual fee (£40-£60 for a sole trader, more for larger firms) to register with the ICO. Takes 15 minutes online.

What if I work freelance / I'm a sole trader?

GDPR still applies. Compliance is proportionate — a sole-trader plumber's expected effort is much less than Sainsbury's. The five must-dos above cover it.

What about WhatsApp messages with customers — are those covered?

Yes — same rules apply. Keep your phone passcoded, delete old chats when retention expires, don't share customer numbers with third parties without lawful basis.

Can I keep using my customer list for marketing?

Existing customers — yes under legitimate interest, as long as you offer unsubscribe in every message. Cold prospects — you need explicit opt-in.