The rule that decides almost everything
Data minimisation. You may process personal data you actually need for a defined purpose. In a rental business there are only a few purposes, and each justifies a limited set of data:
| Purpose | Data that is genuinely needed |
|---|---|
| Identifying the customer | Name, address, date of birth, identity or licence document type and number |
| Performing the contract | Contact details, booking dates, item, price, payment record |
| Legal compliance | Whatever invoicing and tax rules require |
| Enforcing claims | Handover and return reports, photographs, correspondence, contact log |
| Marketing | Email address, with a valid consent and an easy way to withdraw it |
Anything that does not map onto one of these has no reason to exist in your system. National identification numbers, copies of documents and health information almost never do.
Identity documents: verify, do not photocopy
This is the single most common mistake in the sector. The customer produces a passport or driving licence; the operator photographs it, "for security", and stores it forever.
Consider what that achieves. In a dispute the scan does not prove the person was the holder, does not prove the document was genuine and does not help you find them if they gave you a false address. What it does do is create a permanent store of highly sensitive documents that is attractive to attackers, expensive to secure and awkward to explain to a regulator.
The proportionate practice is:
- look at the document, physically, held by the person in front of you;
- check that the photograph matches, the document is in date and the name matches the booking;
- record the check: document type, an identifier where genuinely necessary, date of the check, who checked;
- do not store an image unless you can articulate a specific, documented reason and a retention period.
Where you hire vehicles that require a licence, the check itself matters far more than any copy — what to verify at the counter is a practical question in its own right, and it should be a defined step in the handover checklist.
Some countries do impose specific identification duties on certain rental categories. Where that applies, follow the national rule and store only what it requires, for as long as it requires.
Payment data is not yours to keep
Card numbers should never be written on paper forms, stored in a booking note or emailed. Use a payment provider: the card data goes to them, you keep only a reference, the last four digits and the transaction result. That is enough for refunds and for deposit returns.
The same applies to deposits held on cards. If your process requires a card number to be recorded manually somewhere, the process is the problem.
How long to keep what
Indefinite storage is the default in most small businesses and it is the wrong default. Every category needs a period, and something has to actually delete it.
| Category | Rough guide | Driven by |
|---|---|---|
| Accounting records, invoices | The statutory period in your country, often several years | Tax law |
| Signed agreements and handover reports | Long enough to cover claims, aligned to the limitation period | Enforcing or defending claims |
| Condition photographs | Same as the reports they belong to | Same |
| Customer contact record | While the relationship is live, then a defined period | Contract and legitimate interests |
| Marketing list | Until consent is withdrawn, reviewed periodically | Consent |
| Failed enquiries, abandoned bookings | Short — weeks or a few months | No lasting purpose |
The exact numbers differ by country: statutory accounting periods and limitation periods for claims are national matters. Write the periods down, put a date in the calendar, and delete on schedule. A retention policy nobody executes is worse than none, because it documents what you failed to do.
Photographs count too
Handover photographs are business records, but they routinely include number plates, sometimes the customer's own vehicle, occasionally the customer themselves. That makes the set personal data.
Practical consequences:
- store them with the booking, with access limited to staff who need it;
- keep them for the same period as the report they belong to, then delete;
- mention in your privacy information that condition photographs are taken at collection and return, and why;
- avoid photographing people unnecessarily — the item is the subject, not the customer.
The photography routine itself is covered in documenting condition with photos; the point here is that it needs a retention rule like everything else.
What you must be able to show
Beyond limiting what you collect, European rules expect you to be able to demonstrate how you handle it. For a small rental business the practical minimum is:
- Privacy information for customers: what you collect, why, on what basis, how long you keep it, who you share it with, and their rights. A page on your website plus a reference in the rental agreement.
- A record of your processing activities — for a small operator, a one-page table much like the one above.
- Contracts with your processors: your rental software provider, accountant, payment provider, email service. A written data processing agreement is standard and any competent supplier will have one.
- Access control: individual staff accounts rather than a shared login, and access removed when someone leaves.
- A breach routine: who is told, how quickly, and what gets recorded. Notification deadlines are short.
- A way to answer requests from customers who want a copy of their data or its deletion, within the statutory deadline.
Deletion requests interact with your other duties: you cannot delete an invoice you are legally obliged to keep, and you may retain records needed for an ongoing claim. Answer honestly, explain what is being kept and why, and delete the rest.
Staff access and the shared-login problem
The most common security weakness in small rental businesses is not hacking, it is a shared account and an old laptop. Individual accounts with roles — so that seasonal staff can run handovers without seeing revenue reports or deleting records — are both a security control and a data protection one, and they cost nothing.
Equally, keep customer data out of private phones and personal email. Photos on a personal camera roll, customer numbers in a private messaging app and spreadsheets on a home computer are all difficult to secure, difficult to delete and impossible to audit.
The UK question
Since Brexit the UK operates its own regime, the UK GDPR, which is substantially the same in content: the same principles, the same rights, comparable duties. Businesses hiring across borders should treat the frameworks as parallel rather than as two different systems, while checking specifics — notification routes and some detail differ. Data transfers between the UK and the EU are addressed by separate arrangements, which is worth confirming if your provider stores data in the other jurisdiction.
Applying this in practice
Three questions, at the counter and in the software:
- Do I need this field? If nobody can name the purpose, remove it from the form.
- Do I need to keep it? Verification is a moment; storage is a commitment.
- When does it get deleted? If there is no answer, the retention policy is incomplete.
Flotello is built around this: the customer record holds identification details as text fields rather than document scans, required fields are configurable per business so you collect only what your operation needs, and data lives on EU infrastructure with role-based access rather than a shared login. See team and roles for the access side, or try it free for 7 days.