
GDPR Compliance for UK Businesses Collecting Customer Data
Most local businesses collect customer data without thinking twice. A review request goes out by text message. A customer signs up to a mailing list at the counter. A feedback form captures a complaint and a phone number. Each of those moments creates a legal responsibility. Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, personal data has to be handled properly, and the rules apply to small shops, tradespeople, clinics, and agencies just as much as they apply to large corporations.
This guide explains what GDPR compliance means for a UK business that collects reviews, stores customer feedback, and runs email or SMS outreach. It is written for owners and operators who need practical answers, not legal jargon.
What Is the General Data Protection Regulation?
The GDPR is a data protection law approved by the European Parliament in 2016. It replaced a data protection initiative that dated back to 1995, and it became applicable in all EU member states on 25 May 2018. The central aim of the regulation was to harmonise data privacy laws across Europe so that individuals had consistent rights no matter where their data was processed.
In the UK, the regulation continues to apply through the UK GDPR, supported by the Data Protection Act 2018. The Information Commissioner’s Office (ICO) is the public body that publishes UK GDPR guidance and resources. Its library of official guidance covers subject access requests, individual rights, lawful basis, special category data and criminal offence data, and the responsibilities of controllers.
For practical purposes, the term “controller” describes the organisation that decides why and how personal data is processed. If you own a business and you collect customer details for review requests or marketing, you are almost certainly the controller. That status brings duties with it, and the ICO guidance exists to help you understand them.
Why GDPR Compliance Matters for Review Collection
Review collection is data processing. When a customer leaves a review on Google, Trustpilot, or any other platform, they are sharing their name, their opinion, and often details about their experience with your business. When you send a review request by email or SMS, you are collecting and using their contact details. Both activities fall inside the scope of the UK GDPR.
Before you collect any personal data, you need a lawful basis for doing so. The ICO’s guidance on lawful basis explains the different options and when each one can be used. You also need to be transparent about what you are doing. The ICO’s individual rights guidance stresses the importance of a clear privacy notice, which tells customers what data you hold, why you hold it, and how it is used.
For a review management process, that means being straightforward. Tell customers why you are asking for their email address or phone number. Explain that you may share feedback with a review platform, and make it easy for them to opt out of future messages. A customer who understands how their data will be used is more likely to trust the request and more likely to respond.

Email and SMS Outreach Under the UK GDPR
Email and SMS outreach, including automated review requests, depends on the same underlying principle. You can only process personal data if you have a lawful basis, and you should be able to explain that basis if a customer asks. For marketing messages, consent is often the most appropriate route, although the specific rules that govern electronic marketing sit alongside the GDPR and are covered by separate guidance.
Before you build an email list or send a text campaign, check the ICO’s guidance on lawful basis and electronic marketing. The language matters. A consent box that is unticked by default is not valid consent. A request that bundles consent for marketing into a terms and conditions form is unlikely to stand up to scrutiny. If a customer cannot easily withdraw their consent, your process may not be compliant.
There is also a practical benefit to getting this right. Customers who have genuinely agreed to hear from you are more responsive than contacts who were added to a list without understanding why. A clean, consent-based outreach list tends to produce better review response rates and fewer complaints.
Storing Customer Feedback Safely
Customer feedback, including negative reviews, complaints, and private dispute messages, is personal data. The same rules apply to a spreadsheet of feedback as to a customer relationship management system. You need to keep the data secure, only keep it for as long as you genuinely need it, and make sure your team knows how to handle it.
The ICO’s guidance covers when to delete, change, move, or stop processing people’s information. That is not a one-off exercise. If a customer asks you to correct a review response that misstates their name, you should be able to do so. If they ask you to stop processing their data, you need a process for honouring that request.
Secure storage matters throughout. Feedback should not be left in unsecured spreadsheets on shared laptops, and access should be limited to staff who need it. If you use a review management platform, check where the data is stored and how it is protected. The GDPR has become a consideration in every software decision a business makes.

Subject Access Requests and Individual Rights
The UK GDPR gives individuals a set of rights over their personal data. The ICO groups these under the heading of individual rights, and they include the right to access, correct, delete, and restrict the use of personal information. A customer can ask to see the data you hold about them at any time. This is called a subject access request, or SAR.
The ICO’s subject access request guidance explains how to recognise a SAR and when and how to respond to it. Many small business owners assume a SAR will never come their way. In practice, the more customer data you collect, the more likely you are to receive one. A customer who has a dispute with your business, or who simply wants to know what you hold, can submit a request with a short email.
Having a straightforward internal process makes a big difference. Know where your customer data lives, who can access it, and how quickly you can pull it together. If you use multiple tools for outreach and feedback, check that data can be retrieved from each one. The ICO guidance is the place to confirm the current response requirements before you act.
Data Transfers and Third-Party Tools
Most UK businesses use third-party tools for review management, email marketing, and SMS outreach. Those tools may process customer data outside the UK or the EU. The GDPR includes rules on international data transfers, and controllers are expected to make sure their partners meet the same standards.
One way to ensure that partnerships and data transfers comply with the GDPR is to use standard contractual clauses. These are prewritten clauses that have been preapproved for use in data transfer agreements. If a software provider tells you that your data is processed overseas, ask how the transfer is protected and whether standard contractual clauses are in place.
The European Commission has also looked at simplifying compliance through reduced record-keeping obligations, and the EU data protection framework continues to evolve. For a busy business owner, the practical takeaway is simple. The tools you choose should be able to show you how they handle data protection. If they cannot, that is a reason to look elsewhere.

Practical Steps for GDPR Compliance
Compliance does not require a legal qualification, but it does require a few consistent habits. Start by auditing what customer data you actually hold. Every spreadsheet, email inbox, and review platform account counts. Next, confirm the lawful basis for each type of processing and write it down so you can explain your reasoning if asked.
Publish a clear privacy notice and link it anywhere you collect data. That includes review request emails, SMS messages, and feedback forms. Review your consent processes so that customers know what they are agreeing to and can withdraw easily. Then build a simple system for handling subject access requests, including a named person who takes responsibility for responding.
Finally, keep records in proportion to your business. The EU data protection framework allows for reduced record-keeping obligations, and smaller organisations should not let compliance paperwork become a burden. Focus on the fundamentals. A clear lawful basis, transparent communication, secure storage, and a workable response process cover most of the ground.
For businesses that collect reviews and use customer feedback to improve their reputation, GDPR compliance is not an obstacle. It is part of running a trustworthy operation. Customers share their data because they expect it to be respected. When you respect it, you protect your business and strengthen the relationship at the same time.
Frequently Asked Questions
What is the GDPR?
The GDPR is a data protection law approved by the European Parliament in 2016 to replace an earlier framework from 1995. It became applicable across EU member states on 25 May 2018, harmonising data privacy rules throughout Europe. In the UK it operates as the UK GDPR alongside the Data Protection Act 2018, with the ICO providing official guidance.
Does GDPR still apply to UK businesses after Brexit?
Yes. Data protection in the UK is governed by the UK GDPR and the Data Protection Act 2018. The core principles are the same as the EU regulation, and UK businesses must continue to meet their obligations when collecting, storing, or using personal data. The ICO publishes UK-specific guidance and resources to help organisations comply.
Do I need consent to send review requests by email or SMS?
You need a valid lawful basis before processing personal data for any outreach, including review requests. The ICO’s lawful basis guidance explains the options and when each one applies. For electronic marketing, the rules around consent sit alongside the GDPR, so check the ICO guidance before sending campaigns from your review or marketing tools.
What should I do if a customer asks for a copy of their data?
That request is called a subject access request. The ICO’s guidance explains how to recognise a SAR and when and how to respond to it. You should locate all data held about the customer, including review responses and feedback records, and confirm the current response requirements against the official ICO guidance before acting.
