GDPR for Construction and Trades Businesses UK

A practical guide to GDPR for construction businesses UK, covering customer records, subcontractor data, site access information, mobile devices, job-management apps and data security. Learn how builders, tradespeople and small contractors can apply proportionate UK GDPR controls, manage personal data securely and reduce compliance risks on-site and in the office
Aug 11, 2026
8 min read
GDPR for construction businesses UK banner showing a construction professional using a tablet, with a security shield, customer data, invoices, subcontractors and secure cloud access.

Construction companies and trades businesses handle more personal information than they may realise. A typical job can involve customer names, home addresses, access instructions, invoices, subcontractor records, site induction details and information stored in mobile apps.

For GDPR for construction businesses UK, compliance is not limited to large contractors. The UK GDPR and Data Protection Act 2018 apply when a business processes personal data, including many sole traders and small firms. The practical goal is proportionate compliance: know what information you hold, why you need it, who can access it, how long it should be kept and how it is protected. For a broader foundation, see our UK GDPR overview.

Does GDPR apply to small construction and trades businesses?

Yes. Business size does not remove data protection responsibilities. The ICO recognises that sole traders, self-employed people and businesses of any size can act as data controllers when they decide how and why personal information is used.

This matters for data protection for tradespeople because information is often collected through phone calls, text messages, email, paper diaries or job-management apps.

Common examples include:

  • Customer names, telephone numbers and email addresses
  • Home or site addresses
  • Quotes, invoices and payment records
  • Photographs that identify a person or their property
  • Access instructions and appointment notes
  • Subcontractor contact and payment information
  • Emergency contacts and health details collected for site purposes

The UK GDPR requires a lawful basis for each purpose for which personal data is used. Depending on the situation, this may include contract, legal obligation or legitimate interests; consent is not automatically required for routine business processing. Businesses should also be transparent about how information is used.

Small operators can also read our guide to GDPR for freelancers and sole traders.

Customer data from quotes to invoices

Customer information follows the lifecycle of a job. An enquiry may begin with a name and mobile number, then develop into a quote containing an address, photographs, access information and pricing. Once work starts, the business may add appointment notes, invoices and warranty records.

For GDPR for builders UK, collect only information genuinely needed for the job. Avoid unnecessary personal comments in customer notes and do not keep copies of identification documents without a clear reason.

A simple job lifecycle can follow these steps:

  1. Collect only the details needed to respond to the enquiry or prepare the quote.
  2. Explain how customer information will be used through a concise privacy notice.
  3. Restrict access to staff or subcontractors who need the information.
  4. Keep financial or contractual records only for a justified business or legal period.
  5. Delete or anonymise personal information when there is no longer a valid reason to retain it.

The UK GDPR does not prescribe one universal retention period for customer data. ICO guidance says businesses should keep personal data no longer than necessary and be able to justify their retention periods. Legal, tax, warranty or dispute-related requirements may justify keeping some records longer.

Subcontractor and supplier data

Construction businesses frequently process information about subcontractors and sole-trader suppliers, including names, contact details, payment information and records connected with the Construction Industry Scheme.

Subcontractor data GDPR responsibilities sit alongside HMRC record-keeping rules. Contractors operating CIS must maintain required records, and HMRC guidance states that relevant CIS records must generally be kept for at least three years after the end of the tax year to which they relate.

Useful controls include:

  • Limiting payroll, CIS and banking information to authorised people
  • Avoiding unnecessary copies of identity or tax documents
  • Sending payment records through secure systems rather than open group chats
  • Keeping supplier and subcontractor records accurate
  • Removing obsolete details when there is no reason to retain them

If an accountant, payroll provider or software platform processes personal data on the business’s behalf, confirm whether it acts as a processor and ensure appropriate contractual safeguards are in place.

Site access, ID checks and health records

Construction site data protection becomes more sensitive during inductions and access control. Site managers may collect identity information, competency details, emergency contacts, accident information and medical information relevant to safe working.

Health information is special category data under the UK GDPR. Where a business processes it, it must identify an Article 6 lawful basis and an appropriate Article 9 condition; depending on the condition relied upon, the Data Protection Act 2018 may also require a relevant Schedule 1 condition.

Site managers should not collect broad health details “just in case”. Data minimisation is particularly important for special category data, and the ICO advises collecting and retaining only what is necessary with stronger safeguards for sensitive information.

Emergency contact details are also personal data and should be available only to people who need them for operational or safety purposes.

Using mobile apps and job management software

Scheduling platforms, cloud invoicing tools and job-management apps can make a trades business more efficient, but they can also centralise customer and workforce data.

An app is not automatically “GDPR compliant” because it is popular or cloud-based. Where a supplier acts as a processor, the business should assess its safeguards and ensure appropriate UK GDPR contractual terms are in place. Article 28 covers matters such as instructions, confidentiality, security, sub-processors, assistance with data-subject rights and deletion or return of data at the end of the service.

Before adopting a platform, check:

  • What personal data the app stores
  • Where the data is hosted and whether it leaves the UK
  • What security controls and multifactor authentication are available
  • How user permissions are managed
  • Whether data can be exported or deleted
  • What the provider says about processors and sub-processors

For a small firm, this can be a short supplier check rather than a complex procurement exercise.

Data security when working away from the office

Tradespeople often work from vans, temporary site offices and customer homes. That makes mobile security central to trades business compliance UK.

Personal devices can mix business information with private photos, personal cloud backups or family access. The ICO’s bring-your-own-device guidance notes that company-issued devices are generally the most secure option, while BYOD arrangements need appropriate controls.

Use strong screen locks, multifactor authentication, automatic updates and encrypted storage. Control who can download customer information, avoid leaving paperwork visible in vehicles, and remove access promptly when a worker leaves.

Job photos also need care. Images taken in a customer’s home may capture people, documents or vehicle registrations, so staff should know when photos are necessary, where to store them and whether they can be reused for marketing.

If a phone, laptop or file containing personal information is lost, stolen or sent to the wrong person, treat it as a potential personal data breach. Where the reporting threshold is met, the ICO must be notified without undue delay and within 72 hours of awareness.

Simple compliance steps for trades businesses

A small contractor does not need an enterprise-sized compliance programme.

Teal and gold GDPR compliance flowchart for construction and trades businesses, showing eight steps—data map, lawful basis, privacy notice, retention, access control, secure devices, review apps and staff training—set against a construction-site background with a hard hat and scaffolding.


Effective 
GDPR compliance small business practices should be proportionate to the information and risks involved.

  1. List the personal data you collect from customers, workers, subcontractors and suppliers.
  2. Record why you use each type of data and identify the appropriate lawful basis.
  3. Create a short privacy notice and provide it when you collect personal information.
  4. Set sensible retention periods for quotes, customer records, site records and subcontractor files.
  5. Restrict access to people who genuinely need the information.
  6. Secure phones, laptops, email accounts and cloud services.
  7. Review job-management apps and other processors before using them.
  8. Train staff on data handling, site photos, lost devices and suspected breaches.

Protecting personal data on-site and in the office

  • Keep customer and subcontractor records in approved systems
  • Use strong passwords and multifactor authentication
  • Lock phones, tablets and laptops when unattended
  • Avoid storing work data indefinitely on personal devices
  • Limit health and induction data to what is necessary
  • Review access when staff or subcontractors leave
  • Securely delete records when retention is no longer justified
  • Train anyone who handles personal information

For a structured next step, GDPR Essentials for UK Businesses can build practical knowledge around lawful processing and everyday compliance. Cybersecurity training for small businesses supports safer devices, accounts and cloud tools, while data protection training for employees helps staff apply consistent handling practices.

For businesses asking how to comply with GDPR as a small business, a simple data map, privacy notice, sensible retention rules, security controls and basic SME data protection training are a practical starting point. For firms looking for affordable GDPR training in the UK, focusing first on these everyday controls can make compliance more manageable without creating unnecessary bureaucracy.

Frequently Asked Questions

Do sole trader builders need to comply with GDPR?

Yes, where they process personal data for business purposes. A sole trader who stores customer names, addresses, invoices or subcontractor information can be a data controller and must follow applicable data protection requirements.

What customer data can a tradesperson keep and for how long?

A tradesperson can keep information necessary for legitimate business purposes and supported by an appropriate lawful basis. There is no single UK GDPR retention period for all customer data, so retention should be justified by the purpose and any legal, tax, contractual, warranty or dispute requirements.

Is health information collected at site induction special category data?

Yes. Information about physical or mental health is special category data under the UK GDPR. Businesses should collect only what is necessary, identify the relevant Article 6 basis and Article 9 condition, and apply stronger security controls.

Are job management apps GDPR compliant?

No app is automatically compliant for every business or use case. Assess the provider’s security, data location, processor terms, sub-processors, access controls and deletion arrangements, then configure the platform appropriately.

What's the simplest way for a small trades business to become compliant?

Start with a practical GDPR checklist for small businesses by identifying the personal data you hold, documenting why you need it, providing privacy information, securing your systems, setting retention periods and training anyone who handles the data. Keep the approach proportionate to the business and its risks.

Take the Next Step

Get compliant on-site and in the office without unnecessary jargon. Build practical knowledge of customer data, subcontractor records, privacy notices, lawful processing and everyday security with our GDPR Essentials for UK Businesses course, designed to help smaller organisations apply data protection requirements confidently in real working situations.

CTA button: View Course

Article by:

Professional portrait of a cybersecurity awareness and organisational risk writer.

Maya Fletcher

Maya Fletcher is a cybersecurity awareness and organisational risk writer who helps businesses understand digital threats, strengthen staff awareness and adopt practical measures to protect information, systems and day-to-day operations.

Start Building Your Data Protection Skills Today

Explore flexible online courses designed to help you learn, apply, and strengthen data protection knowledge at your own pace.

Browse Courses