GDPR (General Data Protection Regulation) isn't only for large companies with legal departments. Any business that collects, stores or processes personal data of individuals is subject to this regulation. And a mechanical workshop, by definition, handles personal data from its very first customer: name, phone number, email, vehicle registration, vehicle details.
What personal data a mechanical workshop handles
- Customer name and surname.
- Phone number and email address.
- Vehicle registration (which, linked to an owner, is personal data).
- Tax ID number if you issue invoices.
- Repair history, which can include information about the customer's life and routines (mileage, visit frequency, area where they live if they use the nearest workshop).
- Payment data if you store card or bank transfer information.
What specific obligations a workshop has
The obligations aren't as complex as they're sometimes made out to be. For a mid-sized workshop, the main ones are:
- Inform the customer that their data will be processed, for what purpose and for how long — this is done with a privacy notice the customer must be able to read.
- Obtain the customer's consent to process their data, especially if you're going to send them commercial communications.
- Not share that data with third parties without the customer's explicit consent.
- Apply minimum security measures: password-protected access, not leaving personal data visible on unattended screens, not sharing passwords between employees.
- Respond to customer requests if they ask to access, correct or delete their data (right of access, rectification and erasure).
- Record processing activities — basically, document what data you handle, for what purpose and on what legal basis.
The basic information document: what it must say and when to hand it over
The data protection document the customer signs (or signs digitally) is the starting point of any relationship with a new customer. It must include at minimum: who is responsible for the data processing (the workshop), what data is collected, what it will be used for, how long it will be kept, whether it will be shared with third parties, and how the customer can exercise their rights. It doesn't need to be a twenty-page document — one clear page in plain language is enough.
What happens if you don't comply
Data protection authorities can impose sanctions ranging from warnings to fines of tens of thousands of euros, though proportionality criteria usually apply for small businesses and sole traders. The most common risk for a workshop isn't a huge fine, but a complaint from a dissatisfied customer who knows the workshop doesn't have the correct procedure in place.
How TallerOS solves this
TallerOS includes automatic generation of the basic GDPR information document for each new customer. The document can be sent by email directly from the platform for the customer to sign digitally before any work begins, and it's linked to their record. This covers the obligation to inform and obtain traceable consent without any paperwork.
Additionally, as a cloud platform with individual username and password access, TallerOS automatically applies basic security measures: each employee accesses only with their own credentials, data is encrypted with automatic backup, and access can be revoked immediately if an employee leaves the workshop.
Frequently asked questions
Does a sole trader with a small workshop also have to comply with GDPR?
Yes. GDPR applies to any natural or legal person that processes personal data in the course of their activity, regardless of business size.
Is a vehicle registration plate personal data?
Yes, when linked to the vehicle owner. A plate number alone isn't personal data, but combined with the owner's name it is, and must be handled with the same safeguards.
Do I need to appoint a Data Protection Officer (DPO)?
For most workshops, no. A DPO is only mandatory for organisations that carry out large-scale data processing or handle special categories of data. A standard mechanical workshop doesn't fall into that category.
How long must I keep a customer's data?
Invoicing data must be kept for the period required by tax law (generally 5 years). Contact data with no active commercial relationship can be deleted sooner if the customer requests it.
Keep reading
Comply with GDPR from your very first customer with TallerOS's automatic information document. Try it free for 14 days.
Try TallerOS free →