GDPR for driving instructors: 7 data mistakes to fix, starting with the £52 ICO fee
If you're a UK driving instructor and you hold any information about your pupils (name, phone number, address, age, health conditions, progress notes, payment records), you're a data controller under UK GDPR and the Data Protection Act 2018. The same law that applies to banks and NHS trusts applies to you, scaled to what you do.
For a solo ADI, getting compliant is cheap and mostly paperwork. The Information Commissioner's Office (ICO) has an advice hub for small organisations, and the requirements are proportionate. But a few habits that are normal in the job, like pupil numbers in your personal phone and group chats, sit badly with the rules.
Here are seven common mistakes, the fix for each, and the minimum every ADI should have in place.
This isn't legal advice. If you're dealing with a specific complaint, talk to a solicitor or the ICO.
Why you're a data controller
UK GDPR defines a controller as the person who, "alone or jointly with others, determines the purposes and means of the processing of personal data" (UK GDPR Article 4). In plain English: if you decide what to do with someone's information, you're the controller.
Every ADI decides what pupil information to collect, where to keep it, how long to keep it and what to do with it. That makes you a controller whether or not you have staff, a company, or think of yourself as a business.
The data you handle includes:
- Contact details: name, address, phone, email
- Identifying details: date of birth, licence number
- Financial data: payment history, outstanding balances
- Progress notes: lesson feedback, assessments, test results
- Health information: anything a pupil has told you about anxiety, ADHD, autism, diabetes, epilepsy or any other condition. Health data is "special category" data under Article 9, with extra conditions for using it.
Most ADIs hold the first three for every pupil, and health information whenever a pupil tells them about a condition.
Mistake 1: not paying the ICO fee
If you process personal data as a controller, you have to pay the ICO an annual data protection fee unless an exemption applies.
The fee is set in law. Tier 1 covers a turnover of £632,000 or less, or no more than 10 staff, which takes in any sole-trader ADI. The tier 1 fee is £52, with £5 off if you pay by direct debit. Tier 2 is £78 and tier 3 is £3,763.
If you don't pay, the ICO sends a reminder, then can issue a notice of intent. You then have 28 days to pay or explain. After that, the ICO says you may be fined up to £4,350.
The exemptions are narrow. You don't pay if you only process personal data for staff administration, your own advertising and marketing, accounts and records, not-for-profit purposes, or without a computer at all (ICO exemptions). If you keep lesson progress notes, pupil health information or dashcam footage, don't assume you're exempt. Run the ICO's registration self-assessment.
The fix: do the self-assessment on ico.org.uk and pay the fee if it says you need to. Keep the confirmation with your business records. If you run a dashcam, see our dashcam and ICO guide: the same fee covers it.
Mistake 2: no privacy notice
You have to tell people what you do with their data at the time you collect it (Article 13). That's a privacy notice: what data you hold, why, how long you keep it, who you share it with, and what rights the pupil has.
A line buried in your terms and conditions doesn't do the job.
The fix: write one. It doesn't need to be long or legalistic, and the ICO's small business guidance on privacy notices walks you through it. An ADI privacy notice covers:
- Who you are: your business name and contact details
- What personal data you collect: the list above
- Why you collect it: to give driving lessons, take payments, track progress and keep tax records
- Your lawful basis: for most pupil data this is "contract", because you need it to provide the lessons the pupil has booked (ICO guidance on contract). Health information also needs an Article 9 condition, usually the pupil's explicit consent.
- How long you keep it: see Mistake 5
- Who you share it with: your software provider, your accountant, HMRC for tax, DVSA if required
- The pupil's rights: to access, correct, delete or restrict processing of their data
- How to contact you about their data
- How to complain to the ICO if they're unhappy with your answer
One page is plenty. Put it on your website or booking page, give it to every new pupil, and point to it from your terms.
Mistake 3: collecting more than you need
UK GDPR's data minimisation principle says you should only collect data that is "adequate, relevant and limited to what is necessary" for your purpose (Article 5). Intake forms tend to ask for more than that.
The test: for every field, ask "why do I need this to give driving lessons?" If the answer is "I don't, it's nice to know", drop it.
The fix: go through your pupil intake form. Fields that can often go:
- Previous driving experience, unless you actually use it to plan lessons
- Parents' names for adult pupils
- Home address, if you always pick up from the same place
- Occupation
- Emergency contact for adults (keep it optional)
Keep what supports the lessons: name, phone, email, pick-up address if it varies, licence details if you check them, and a free-text "anything I should know" box so pupils can share what's relevant, if they choose to.
Mistake 4: pupil data in your personal phone and WhatsApp
Plenty of instructors keep pupil numbers in their personal contacts and arrange lessons on WhatsApp. Both need care.
Phone contacts: pupil numbers mixed into your personal contacts get backed up and synced wherever your phone sends them (iCloud, Google, any backup app) and are visible to anyone who uses your phone. It's also hard to tell current pupils from ex-pupils whose details you should have deleted.
WhatsApp: personal messages are end-to-end encrypted, so WhatsApp can't read them. But its privacy policy says the contact upload feature sends WhatsApp the phone numbers in your address book on a regular basis, including your pupils'. Mention it in your privacy notice.
Group chats with several pupils (test-prep groups, "tip of the week") share each pupil's contact details with everyone else in the group. Don't run them without each pupil's agreement.
The fix: move pupil records out of your personal contacts into a system built for it. Orbit is one option and is free for instructors. Pupil records are held in a database where each instructor's data is walled off from everyone else's, encrypted at rest, and you can delete a pupil's record when you no longer need it. Our software comparison covers the alternatives.
For messages, a separate business phone number keeps pupils out of your personal contacts. If you use WhatsApp, use one-to-one chats, not groups.
Mistake 5: keeping everything forever
UK GDPR's storage limitation principle says you keep personal data for no longer than you need it (Article 5). Without a retention policy, pupils who passed years ago stay in your diary, your phone and your paper notes.
The more you keep, the worse any breach is, and the more work it is to answer a subject access request from a former pupil asking for everything you hold on them.
The fix: set a retention policy and put it in your privacy notice.
A reasonable ADI policy:
- Current pupils: kept while you're teaching them
- Ex-pupil contact details: deleted within 12 months of the last lesson, unless you have a specific reason to keep them
- Financial records: sole traders must keep business records for at least 5 years after the 31 January filing deadline for that tax year. Limited companies keep accounting records for 6 years from the end of the financial year they relate to.
- Lesson progress notes: deleted with the ex-pupil's contact details, unless the pupil asks you to keep them
- Complaint records: kept while a dispute could still arise
Then do it. Put a reminder in your diary each quarter to go through your pupil list and delete anything past its retention date.
Mistake 6: sharing pupil data without thinking
A parent asking how their adult son is getting on. Another instructor asking about a pupil who's moved to you. An insurer asking about an incident. A reference request. Social services asking about a young person you teach.
Each is a request to share personal data. The safe default to "can you tell me about your pupil?" is no, unless you have a lawful basis to share.
Common requests:
- Parent of an adult pupil: no, unless the pupil has agreed. The information belongs to the pupil.
- Parent of a 17-year-old: the pupil is still the data subject. If a parent is paying, agree with the pupil at the start what you'll share with them, and ask before discussing anything sensitive.
- Another ADI whose pupil has moved to you: no, unless the pupil has asked you to pass information on.
- Insurer after an incident: there may be a legitimate reason to give factual information about a claim. Confirm who you're dealing with first and share only what's needed.
- Social services about a young person: the ICO's safeguarding guide says data protection law "doesn't prevent" you sharing information to protect a child at risk of harm. Confirm the person is who they say they are, share what's relevant, and write down what you shared.
- Anyone on the phone you can't verify: no. Take their details, check them, and call back.
The fix: before sharing, ask who's asking, what their basis is, whether the pupil has agreed or would reasonably expect it, and whether you're sure of their identity. If any answer is unclear, decline politely and ask for the request in writing.
Mistake 7: no plan for a data breach
If you have a personal data breach that is likely to result in a risk to people's rights and freedoms, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33). If the risk to people is high, you must also tell them without undue delay (Article 34).
A stolen phone with pupil contacts on it can be a breach. So can an email of pupil details sent to the wrong person, or a hacked laptop or cloud account.
The fix: have a simple plan, even as a solo ADI.
- Work out what happened. What data, how many people, how it happened.
- Contain it. Remote-wipe a stolen phone. Ask a wrong recipient to delete the email. Change passwords and turn on two-factor authentication if an account was hacked.
- Assess the risk. Could it lead to identity theft? Could someone be put in danger, for example if a vulnerable pupil's address is exposed?
- Decide whether to report. If there's a risk to people, report it through the ICO's breach reporting page within 72 hours. If the risk is unlikely (one pupil's name sent to one wrong recipient who has confirmed deletion), you don't have to report it.
- Tell the pupils if the risk is high: what happened, what you're doing, and what they should do.
- Write it down. Article 33 requires you to document every breach, including ones you don't report: what happened, its effects and what you did about it.
The minimum to do this week
If you've done none of this, start with three things:
- Check whether you owe the ICO fee and pay it: £52 for a sole trader, £47 by direct debit.
- Write a one-page privacy notice covering the points in Mistake 2, and put it where pupils will see it.
- Move pupil records out of your personal phone contacts into proper software.
That doesn't fix everything, but it covers the fee, tells pupils what you do with their data, and deals with the riskiest habit.
DVSA's new driving instructor code of practice, due between late 2026 and early 2027, says instructors must "comply with privacy and data protection legislation". Most instructors only think about data protection when something goes wrong: a pupil complains, the ICO writes, or a phone goes missing. Better to have the basics in place before then.
Where Orbit fits
Orbit is free for instructors. In Orbit, you're the controller of your pupil records and Orbit processes them on your behalf, as set out in our privacy policy. Pupil records sit in a database where each instructor's data is kept separate, it's encrypted at rest, you can delete a pupil's record, and you can download a full export of your account's data from Settings.
Orbit doesn't make you compliant on its own. You still need to pay the ICO fee, write a privacy notice, keep your intake form lean, and handle sharing and retention properly. What it does is get pupil records out of your personal phone.