UK taxi and private hire operators sit on more sensitive personal data than they realise. A single booking record links a passenger's name, phone number, home address, workplace, payment card token, ride history, and — through dashcam and app telemetry — their movements on a given day. Multiply that by a few hundred drivers, each with a DBS certificate, medical record, PHV badge number and bank details, and your dispatch database becomes one of the highest-value targets a small business can hold.
This 2026 guide explains what UK taxi dispatch software must do to keep you compliant with UK GDPR and the Data Protection Act 2018, what the ICO is actually enforcing against taxi and PHV operators right now, and the practical controls you should have in place this quarter. If you operate a private hire fleet, our broader overview of private hire software covers the licensing and dispatch foundations that sit alongside compliance.
The UK Regulatory Picture in 2026
After Brexit the UK retained GDPR as "UK GDPR", which sits alongside the Data Protection Act 2018 (DPA 2018). Both are enforced by the Information Commissioner's Office (ICO). For taxi and private hire operators, three other regulatory bodies interact with data law:
- Transport for London (TfL) for PHV operators in Greater London, with specific record-keeping obligations under the Private Hire Vehicles (London) Act 1998.
- Local licensing authorities across England, Wales, Scotland and Northern Ireland, each with their own retention and disclosure rules for driver and vehicle records.
- HMRC, requiring tax-relevant booking and invoicing records to be kept for six years.
The practical result is that you cannot delete data simply because a passenger asks — you must balance their UK GDPR rights against statutory retention requirements set by TfL, your local council, and HMRC. A GDPR-ready dispatch platform handles this balance for you with a retention engine; a spreadsheet-based operation does not.
What Counts as Personal Data in a Taxi Operation
Under Article 4 UK GDPR, "personal data" is any information relating to an identified or identifiable living individual. In a taxi or PHV business that includes:
| Category | Examples | Sensitivity |
|---|---|---|
| Passenger booking data | Name, phone, email, pickup, drop-off, fare, payment token | Standard |
| Location data | GPS pings, booking history, regular pickup patterns | High |
| Dashcam / in-vehicle CCTV | Video and audio of passengers and the street outside | High |
| Payment data | Card tokens, transaction IDs, refund history | High (PCI-DSS) |
| Driver data | Name, address, NI number, DBS, PHV badge, medical, bank | Special category |
| Call recordings | Voice bookings, complaints, dispatcher conversations | High |
| Marketing data | Email opt-ins, SMS opt-ins, app push tokens | Consent-based |
Driver DBS records and medical fitness data are special category data under Article 9 UK GDPR. They need a separate condition for processing — usually "employment, social security and social protection law" under Article 9(2)(b) and Schedule 1 of the DPA 2018.
Lawful Bases You'll Actually Use
UK GDPR gives you six lawful bases for processing in Article 6. Taxi operators typically rely on four:
- Contract (Article 6(1)(b)) — for the booking itself. You cannot dispatch a driver without the passenger's name, phone and pickup address. Document this in your privacy notice and you don't need consent.
- Legitimate interests (Article 6(1)(f)) — for dashcam footage, fraud detection, and operational analytics. Each use needs a written Legitimate Interests Assessment (LIA) showing the interest is real, the processing is necessary, and the impact on the individual is proportionate. The ICO has a free LIA template.
- Legal obligation (Article 6(1)(c)) — for HMRC tax records, TfL/council disclosures, police data requests under Schedule 2 DPA 2018, and safeguarding referrals.
- Consent (Article 6(1)(a)) — only for marketing emails, SMS and push notifications, and for any non-essential cookies on your booking site. Consent must be specific, granular, freely given, and as easy to withdraw as to give.
The single biggest ICO complaint trend against PHV operators in 2025–26 has been operators marketing to passengers under "contract" or "legitimate interests" when they should have collected consent. If a passenger booked a ride, you have a contract basis for the ride — not for the monthly newsletter. Keep these flows separate in your online booking system.
Retention: How Long You Can Actually Keep Booking Data
UK GDPR sets no fixed retention period — the rule is "no longer than necessary for the purposes for which the personal data are processed" (Article 5(1)(e)). For taxi operators, the practical schedule that survives ICO scrutiny is:
| Data type | Recommended retention | Driver |
|---|---|---|
| Live booking records (full PII) | 12–24 months | Customer service & disputes |
| Anonymised booking analytics | Indefinite | Demand forecasting |
| Invoice and payment records | 6 years | HMRC s.386 Companies Act 2006 |
| Dashcam / in-vehicle CCTV | 30–60 days (default) | ICO CCTV Code |
| Dashcam clips flagged for incident | Until matter resolved + 12 months | Insurance & police |
| Call recordings | 3–6 months | Complaint resolution |
| Driver records (active) | Duration of engagement | Licensing & payroll |
| Driver records (ex-driver) | + 6 years | HMRC, tribunal time limits |
| DBS certificate copies | 6 months after decision | DBS Code of Practice |
| Marketing opt-in / opt-out logs | Until withdrawn + 2 years | PECR compliance evidence |
Publish this schedule in your privacy notice, then configure your dispatch software to enforce it. Modern platforms like Taxi Web Design automatically anonymise booking PII after 24 months while preserving aggregate analytics — you get the operational insight without the compliance liability.
Data Subject Access Requests (DSARs)
Article 15 UK GDPR gives passengers and drivers the right to a copy of all personal data you hold about them. The clock starts the day after the request lands and you have one calendar month to respond. You may extend by two further months for complex requests, but you must tell the requester within the first month.
For a taxi operator a DSAR export normally needs to include:
- Account profile and contact history.
- Full booking history with pickup/drop-off, driver, fare and any notes.
- Payment metadata (not full card numbers — those are tokenised).
- Dashcam footage where the requester is clearly identifiable (other passengers and bystanders must be redacted).
- Call recordings where the requester is the caller.
- Complaint and feedback history.
- Marketing opt-in/opt-out timeline.
- Any internal notes that mention the requester (yes, "difficult passenger" notes are disclosable).
The ICO is unsympathetic to "our system can't export that". GDPR-ready taxi software should produce a DSAR export in under 10 minutes — if yours takes a week of manual spreadsheet work, that is itself a compliance signal worth fixing.
The Right to Erasure (and Where It Doesn't Apply)
Article 17 — the "right to be forgotten" — is heavily qualified. Passengers can request erasure of their account, marketing preferences and booking PII, but you may legitimately refuse to delete:
- Invoice and payment records still inside the 6-year HMRC window.
- Records subject to an active TfL or local council audit.
- Dashcam footage tied to an ongoing insurance, police or safeguarding matter.
- Records needed to defend a legal claim that has been notified or is reasonably foreseeable.
The right answer is almost never "we'll delete everything" — it is "we'll delete what we can and ring-fence what we must keep, with a documented reason and a future deletion date." Build this into your platform, not into a manual checklist.
Breach Notification: The 72-Hour Clock
If a personal data breach is "likely to result in a risk to the rights and freedoms of natural persons" you must notify the ICO within 72 hours of becoming aware (Article 33). If the risk is high, you must also notify affected individuals "without undue delay" (Article 34).
Real-world breach scenarios for taxi operators include:
- A driver tablet stolen with the dispatch app still logged in.
- A misdirected booking confirmation email containing another passenger's pickup address.
- An unprotected database backup left in a public cloud bucket.
- A dashcam SD card lost during a vehicle handover.
- A ransomware attack on the booking server.
- A staff member emailing a passenger list to a personal Gmail account.
Maintain a written breach response runbook with named owners, ICO portal credentials ready, and a template notification letter. Run a tabletop exercise once a year. The ICO consistently reduces fines for operators who can show a calm, documented response — and dramatically increases them where the operator obviously panicked or concealed.
Cookies, PECR and Your Booking Website
Your booking website is regulated by the Privacy and Electronic Communications Regulations (PECR) in addition to UK GDPR. PECR requires prior consent for any non-essential cookie or tracker — Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, chat widgets, retargeting tags. A pre-ticked "Accept" box, a banner with no "Reject" option, or an "implied consent" pattern is not compliant in 2026 and the ICO has been actively writing to UK websites about it.
The minimum acceptable pattern is a banner with equally prominent "Accept" and "Reject" buttons, no trackers fired before the user chooses, and a granular preferences panel for categories. Our own approach on Taxi Web Design uses exactly this pattern, and we build it into every customer site as standard.
Processor Contracts and Your Software Vendors
Your dispatch software vendor, payment processor, SMS gateway, cloud hosting provider and email delivery service are all data processors under Article 28 UK GDPR. You need a written Data Processing Agreement (DPA) with each one covering the eight mandatory clauses in Article 28(3): subject-matter, duration, nature, type of personal data, categories of data subjects, obligations and rights of the controller, sub-processor authorisation, and the standard processor obligations.
Most reputable vendors publish their DPA as a downloadable PDF and accept it through an online click-through. Keep a register of every processor, the DPA you signed, the date, and any international transfer mechanism (UK Addendum to the EU Standard Contractual Clauses, or a UK adequacy decision). The ICO asks for this register on day one of any investigation.
The 10-Point GDPR Readiness Checklist for UK Operators
- Pay the ICO data protection fee and renew it annually.
- Appoint a named individual responsible for data protection (a formal DPO is only mandatory in narrow cases, but every operator needs an owner).
- Publish a UK GDPR-compliant privacy notice covering all data categories above.
- Document your lawful basis for each processing activity in a Record of Processing Activities (ROPA).
- Sign DPAs with every software vendor, payment processor and marketing tool.
- Configure automatic retention and anonymisation in your dispatch platform.
- Implement role-based access in the dispatch system — dispatchers do not need access to payment data, drivers do not need access to other drivers' records.
- Run a granular cookie consent banner on every public web page.
- Write a breach response runbook and rehearse it annually.
- Train all staff and drivers on data protection at induction and refresh annually.
Why GDPR-Ready Software Beats GDPR-Ready Paperwork
Compliance is not a policy folder — it is a set of controls that run every day without anyone having to remember them. A modern UK taxi dispatch platform bakes the controls in:
- Automatic PII anonymisation at the retention deadline.
- One-click DSAR exports per passenger and per driver.
- Role-based access control with audit logging of every record viewed.
- Encrypted storage of card tokens via a PCI-DSS-certified processor.
- Region-locked hosting inside the UK or EU, with a documented international transfer mechanism for any sub-processor.
- A breach detection dashboard surfacing unusual export volumes or off-hours admin logins.
- Built-in cookie consent and email opt-in/opt-out management linked to your booking platform.
If your current dispatch system was built before 2018, none of this is likely true by default. Modernising is usually faster and cheaper than retrofitting compliance — and it removes the ongoing human-error tax that produces most ICO complaints in the first place.
Where to Go Next
If you're scoping a compliance upgrade, start with a data audit: list every system that holds passenger or driver data, the lawful basis, the retention period and the processor contract. Then compare what your current platform forces you to do manually against what a modern platform automates. Our team builds GDPR-ready dispatch, booking and driver-app systems for UK operators end-to-end — see our private hire software overview and our GDPR compliance hub for the wider regulatory picture, or book a demo to walk through how compliance controls look inside a live dispatch dashboard.
This article is general guidance for UK taxi and private hire operators and is not legal advice. For specific situations consult a qualified data protection professional or your appointed DPO.
