Skip to content

We use optional analytics to understand how the site is used and improve it. See our Cookie Policy.

Loomwork AI
How it worksROIServicesWorkGuidesFind a tradeContact Web Design Programs Book audit
How it worksROIServicesWorkGuidesFind a tradeContact Web Design Programs Book audit
← Back to Guides

Compliance

GDPR and Your Customer List: What Small Trade Businesses Must Know

Published 11 September 2026 · Sources checked 11 September 2026

A spreadsheet of names, addresses and mobile numbers looks like nothing more than a job list — until you remember that every row is somebody’s personal data. It’s easy to assume GDPR is something only big companies with dedicated compliance teams need to think about, but that’s not what the law or the regulator that enforces it actually says. Here’s what applies to a trade business running quotes and callouts off a spreadsheet, sourced from gov.uk and the underlying regulations.

Yes, UK GDPR applies to your customer list

Everyone responsible for using personal data has to follow the data protection principles, unless a specific exemption applies [1]. That covers any trade business keeping a record of customer names, addresses or phone numbers on a computer, phone or app — a spreadsheet, a diary app, or a job-management tool all count. The principles require that personal information is used fairly, lawfully and transparently, collected for specified purposes, kept accurate and up to date, held for no longer than necessary, and secured appropriately [1]. There’s no size or turnover threshold built into that list — a sole trader working alone is bound by the same principles as a business running a full office of staff.

Do you need to register with the ICO and pay a fee?

Separately from following the principles, a business, organisation or sole trader that processes personal data must generally tell the Information Commissioner’s Office (ICO) how it uses that data and pay a data protection fee, unless it’s exempt [2][3]. The fee is tiered: £52 or £78 covers most small and medium-sized businesses and charities, rising to as much as £3,763 for organisations with a high turnover and many staff [3]. Which of those tiers a business falls into is set by turnover and staff numbers under regulations that took effect on 17 February 2025 [4]. Gov.uk is explicit that not paying the fee when it’s owed can lead to a fine from the ICO [3]. The precise exemptions available to very small operations — for example, whether keeping records only on paper, or processing data solely for something like staff administration, takes a business out of scope entirely — sit in the ICO’s own self-assessment process rather than in a page this guide could independently confirm, so treat that as something to check directly rather than assume.

Picking a lawful basis for the data you already hold

Before processing any personal data, a business needs a lawful basis for doing so. UK GDPR sets out six: consent, performance of a contract, compliance with a legal obligation, protecting someone’s vital interests, performing a public task, and the legitimate interests pursued by the business [5]. For a trade business, the names, addresses and phone numbers needed to quote a job, get access to a property, and invoice for the work will typically sit under “contract” or “legitimate interests” rather than consent — there’s no requirement to get a customer to tick a box before texting them to confirm a job they’ve already booked [5]. Consent becomes relevant for a different reason: sending marketing rather than running the job you were hired for.

Texting or WhatsApping about offers: when you need marketing consent

A separate set of rules, the Privacy and Electronic Communications Regulations, governs unsolicited marketing sent by “electronic mail” — a term defined broadly enough to include any text, voice, sound or image message sent over a public network, and explicitly including messages sent by short message service [7]. You can’t send marketing messages to an individual customer unless you have their permission, or you meet the conditions of the “soft opt-in” exception [6][8]. The soft opt-in lets a business market its own similar products or services to its existing customers without separately collected consent, provided it obtained their contact details in the course of selling to them, and gave them a clear, free way to opt out both when their details were first collected and with every marketing message since [6]. That exception doesn’t extend to a list bought in or handed over from somewhere else [9]. The same broad definition of electronic mail that catches text messages is treated by the regulator as covering app-based messages too, including WhatsApp and direct messages on social media, so a promotional message sent that way needs the same permission or soft opt-in as an email or text [9].

What this means day to day

In practice, the customer list itself is not the problem: using it to run jobs, invoice, and answer support queries doesn’t need a signed consent form for every entry [5]. What does need clear permission, or a soft opt-in that genuinely meets all its conditions, is any message that’s promotional rather than operational — a discount code, a seasonal offer, or a “refer a friend” text sent by SMS, email or WhatsApp [6][8][9]. And separately from marketing altogether, it’s worth checking whether the data protection fee applies to the business and registering if it does, since gov.uk treats sole traders the same as any other organisation on that point [3].

Book a £250 audit

Sources

  1. Data protection — GOV.UK, accessed 11 September 2026. https://www.gov.uk/data-protection
  2. Data protection: your business — GOV.UK, accessed 11 September 2026. https://www.gov.uk/data-protection-your-business
  3. Data protection: register with the ICO and pay the data protection fee — GOV.UK, accessed 11 September 2026. https://www.gov.uk/data-protection-register-notify-ico-personal-data
  4. The Data Protection (Charges and Information) (Amendment) Regulations 2025 — legislation.gov.uk (The National Archives), accessed 11 September 2026. https://www.legislation.gov.uk/uksi/2025/63/made
  5. UK GDPR, Article 6: lawfulness of processing — legislation.gov.uk (The National Archives), accessed 11 September 2026. https://www.legislation.gov.uk/eur/2016/679/article/6
  6. Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22 — legislation.gov.uk (The National Archives), accessed 11 September 2026. https://www.legislation.gov.uk/uksi/2003/2426/regulation/22
  7. Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 2 (definitions) — legislation.gov.uk (The National Archives), accessed 11 September 2026. https://www.legislation.gov.uk/uksi/2003/2426/regulation/2
  8. Marketing and advertising: the law — direct marketing — GOV.UK, accessed 11 September 2026. https://www.gov.uk/marketing-advertising-law/direct-marketing
  9. Direct marketing using email: ICO publishes new guidance — DWF Law LLP, accessed 11 September 2026. https://dwfgroup.com/en/news-and-insights/insights/2022/11/direct-marketing-using-email-ico-publishes-new-guidance

Not yet verified

  • A trade business that keeps records solely on paper, or processes personal data only for narrow purposes such as staff administration, is exempt from the ICO data protection fee even if it would otherwise fall into a paid tier.
  • The ICO can fine a business up to £4,000 for failing to pay the data protection fee when required.
Loomwork AI

AI automation for small & medium businesses.

Serving small & medium businesses across the United Kingdom.

How it worksROIServicesWorkGuidesFind a tradeContact

Services

About Web Design Programs AI Receptionist & PhoneFollow-up & RemindersLead CaptureInvoicing & PaymentsReview EngineSchedulingDatabase ReactivationLocal SEO & Google PresenceRecurring Revenue Plans

Loomwork-AI Ltd is a company registered in England & Wales (company no. 17288926). Registered office: 1 Wards Croft, Saffron Walden, England, CB11 4ET. ICO registration ZC216375.

Privacy Cookies Terms AI & Data

© 2026 Loomwork AI. All rights reserved.

hello@loomwork-ai.co.uk LinkedIn