← All articles

Rental operations6 min read

What Customer Data Can a Rental Business Keep? (GDPR, IDs and Licences)

Which customer details a rental business genuinely needs, why ID scans are a liability, how long to keep records and how to write a retention rule that works.

The rule that decides almost everything

Data minimisation. You may process personal data you actually need for a defined purpose. In a rental business there are only a few purposes, and each justifies a limited set of data:

Anything that does not map onto one of these has no reason to exist in your system. National identification numbers, copies of documents and health information almost never do.

Identity documents: verify, do not photocopy

This is the single most common mistake in the sector. The customer produces a passport or driving licence; the operator photographs it, "for security", and stores it forever.

Consider what that achieves. In a dispute the scan does not prove the person was the holder, does not prove the document was genuine and does not help you find them if they gave you a false address. What it does do is create a permanent store of highly sensitive documents that is attractive to attackers, expensive to secure and awkward to explain to a regulator.

The proportionate practice is:

  • look at the document, physically, held by the person in front of you;
  • check that the photograph matches, the document is in date and the name matches the booking;
  • record the check: document type, an identifier where genuinely necessary, date of the check, who checked;
  • do not store an image unless you can articulate a specific, documented reason and a retention period.

Where you hire vehicles that require a licence, the check itself matters far more than any copy — what to verify at the counter is a practical question in its own right, and it should be a defined step in the handover checklist.

Some countries do impose specific identification duties on certain rental categories. Where that applies, follow the national rule and store only what it requires, for as long as it requires.

Payment data is not yours to keep

Card numbers should never be written on paper forms, stored in a booking note or emailed. Use a payment provider: the card data goes to them, you keep only a reference, the last four digits and the transaction result. That is enough for refunds and for deposit returns.

The same applies to deposits held on cards. If your process requires a card number to be recorded manually somewhere, the process is the problem.

How long to keep what

Indefinite storage is the default in most small businesses and it is the wrong default. Every category needs a period, and something has to actually delete it.

The exact numbers differ by country: statutory accounting periods and limitation periods for claims are national matters. Write the periods down, put a date in the calendar, and delete on schedule. A retention policy nobody executes is worse than none, because it documents what you failed to do.

Photographs count too

Handover photographs are business records, but they routinely include number plates, sometimes the customer's own vehicle, occasionally the customer themselves. That makes the set personal data.

Practical consequences:

  • store them with the booking, with access limited to staff who need it;
  • keep them for the same period as the report they belong to, then delete;
  • mention in your privacy information that condition photographs are taken at collection and return, and why;
  • avoid photographing people unnecessarily — the item is the subject, not the customer.

The photography routine itself is covered in documenting condition with photos; the point here is that it needs a retention rule like everything else.

What you must be able to show

Beyond limiting what you collect, European rules expect you to be able to demonstrate how you handle it. For a small rental business the practical minimum is:

  • Privacy information for customers: what you collect, why, on what basis, how long you keep it, who you share it with, and their rights. A page on your website plus a reference in the rental agreement.
  • A record of your processing activities — for a small operator, a one-page table much like the one above.
  • Contracts with your processors: your rental software provider, accountant, payment provider, email service. A written data processing agreement is standard and any competent supplier will have one.
  • Access control: individual staff accounts rather than a shared login, and access removed when someone leaves.
  • A breach routine: who is told, how quickly, and what gets recorded. Notification deadlines are short.
  • A way to answer requests from customers who want a copy of their data or its deletion, within the statutory deadline.

Deletion requests interact with your other duties: you cannot delete an invoice you are legally obliged to keep, and you may retain records needed for an ongoing claim. Answer honestly, explain what is being kept and why, and delete the rest.

Staff access and the shared-login problem

The most common security weakness in small rental businesses is not hacking, it is a shared account and an old laptop. Individual accounts with roles — so that seasonal staff can run handovers without seeing revenue reports or deleting records — are both a security control and a data protection one, and they cost nothing.

Equally, keep customer data out of private phones and personal email. Photos on a personal camera roll, customer numbers in a private messaging app and spreadsheets on a home computer are all difficult to secure, difficult to delete and impossible to audit.

The UK question

Since Brexit the UK operates its own regime, the UK GDPR, which is substantially the same in content: the same principles, the same rights, comparable duties. Businesses hiring across borders should treat the frameworks as parallel rather than as two different systems, while checking specifics — notification routes and some detail differ. Data transfers between the UK and the EU are addressed by separate arrangements, which is worth confirming if your provider stores data in the other jurisdiction.

Applying this in practice

Three questions, at the counter and in the software:

  • Do I need this field? If nobody can name the purpose, remove it from the form.
  • Do I need to keep it? Verification is a moment; storage is a commitment.
  • When does it get deleted? If there is no answer, the retention policy is incomplete.

Flotello is built around this: the customer record holds identification details as text fields rather than document scans, required fields are configurable per business so you collect only what your operation needs, and data lives on EU infrastructure with role-based access rather than a shared login. See team and roles for the access side, or try it free for 7 days.

Frequently asked questions

Can I photocopy or scan a customer's ID?

Generally you should not, unless a specific legal duty requires it or you can document a strong justification and a retention period. Verifying the document in person and recording that the check was made — type, date, who checked — is both safer and more useful.

What customer data does a rental business actually need?

Enough to identify the person and enforce the contract: name, address, date of birth, contact details, the type and number of the document you verified where necessary, plus the booking, payment and handover records. Anything beyond that needs a purpose you can state.

How long can I keep rental records?

Accounting records for the statutory period in your country, agreements and handover reports for as long as claims can realistically arise, marketing data until consent is withdrawn. Write the periods down and actually delete on schedule.

Are handover photos personal data?

Yes, in practice, because they usually show number plates and sometimes people or their belongings. Store them with the booking, restrict access, keep them for the same period as the report and mention them in your privacy information.

Does the UK GDPR differ from the EU GDPR?

The content is substantially the same — the same principles, rights and core obligations — though some procedural details and the supervisory route differ. If you operate in both, check the specifics rather than assuming full identity.

What must I do if a customer asks me to delete their data?

Respond within the statutory deadline, delete what has no remaining purpose, and explain clearly what you must keep and why — typically invoices required by tax law and records needed for an ongoing claim.

Running your rental company on paper?

Flotello runs the whole rental from reservation to deposit refund — calendar, signed contract, protocol with photos, payments and invoice.

Try 7 days free