GDPR for pet-service providers: what data rules mean for you
How UK/EU data protection law applies to pet-service providers: client data, photos, records, and how to stay compliant without paperwork overload.
Pet-service providers hold real personal data: client names, addresses, phone numbers, key codes, home layout, health details of pets, and sometimes payment information. UK GDPR and its EU parent apply. Following the rules is easier than it looks.
This is not legal advice. Consult the Information Commissioner's Office for authoritative guidance.
What data protection law actually covers
UK GDPR and EU GDPR apply when you process personal data about identifiable people.
Personal data includes:
- Names and contact details.
- Addresses.
- Payment information.
- Photos of people (if identifiable).
- Written notes about clients.
- Booking history.
Pet data (breed, age, medical) is not personal data about a human, but pet data linked to a client is.
Your six lawful bases
You must have a lawful basis to process personal data. The relevant ones for pet-service providers:
- Contract: processing needed to deliver the booked service.
- Legitimate interests: for business operations, marketing to existing clients.
- Consent: for marketing to new prospects, using photos publicly.
- Legal obligation: tax records, insurance claims.
Most day-to-day processing (client contact, service delivery, payment) is covered by "contract."
The four things you must do
- Have a privacy notice available to clients.
- Store data securely.
- Respond to data-subject rights requests.
- Report significant data breaches.
That is it. Everything else is documentation of these four.
The privacy notice
Every provider should have a short privacy notice available to clients.
Content:
- What data you collect.
- Why you collect it.
- Who you share it with (nobody, or specific parties like accountants, insurers, platforms).
- How long you keep it.
- Contact for data queries.
Length: 200-400 words. Keep it plain.
The ICO's SME hub has templates.
Data security in practice
For a solo pet-service provider, "secure" means:
- Passwords on all devices holding client data.
- Two-factor authentication on your business email.
- No client information in shared or public cloud folders.
- Physical documents stored securely (locked or in a controlled space).
- Backups.
You do not need enterprise-grade encryption. You do need not-leaving-a-notebook-in-a-coffee-shop.
Client rights
Clients have specific rights over their data.
- Access: they can ask for a copy of what you hold.
- Rectification: they can ask you to correct errors.
- Erasure: they can ask you to delete data (with exceptions).
- Portability: they can ask for a copy in a usable format.
- Objection: they can object to certain uses.
You have one month to respond to a valid request.
Data retention
Do not keep client data forever.
- Active client: retain during service and 12 months after last booking.
- Financial records: 6 years under most tax rules.
- Incident records: retain as long as any potential claim remains open.
- Marketing consent: retain the consent record with the data.
Delete old data on a regular schedule.
Photos and social media
Photos of client pets often include identifiable information.
- Do not post photos of a client's pet without their consent.
- Do not include recognisable house features (front doors, house numbers).
- Ask separately for permission to tag or link social profiles.
- Respect removal requests immediately.
Sharing data with third parties
You may share client data with:
- Your accountant (contract with them covers this).
- Your insurer (in the event of a claim).
- Your booking platform (implicit in booking through the platform).
- A vet or emergency service (in an emergency).
Do not share client data with:
- Other clients.
- Other providers (unless the client explicitly authorised the referral).
- Marketing lists you did not build with their consent.
Data breach handling
If client data is lost or stolen:
- Assess the risk to affected clients.
- If risk is high, notify the ICO within 72 hours.
- Notify affected clients where risk to them is high.
- Document the incident.
Breaches are more common than providers think. A stolen laptop with client keys and addresses is a serious breach.
The record you actually need
For a solo provider, one page of documentation is enough:
- Privacy notice (200-400 words).
- Data map (what data you collect, where it lives, who has access).
- Retention schedule.
That is your GDPR file. Update annually.
Platforms and GDPR
Using a marketplace shifts some responsibility to the platform.
OnlyPaw is a pet-services marketplace covering walking, sitting, boarding, grooming, training, and pet taxi. Client data collected through the platform is held securely by the platform. Providers upload ID during 24-48 hour verification. Payouts land Monday to bank transfer or PayPal, $50 minimum, 5 percent platform fee.
Providers still need to comply with GDPR for any data they hold themselves outside the platform.
What triggers ICO enforcement
The ICO focuses enforcement on:
- Repeat breaches.
- Refusal to respond to data-subject requests.
- Serious security failures.
- Unsolicited marketing.
Solo pet-service providers who follow the basics rarely face enforcement action. Providers who ignore data-subject requests do.
The one habit that keeps you compliant
Before adding any new client to your records, ask yourself: "Where is this data going to live, and how long am I going to keep it?"
If you cannot answer, do not collect the data.
The California and other US privacy laws
US pet-service providers should note:
- California Consumer Privacy Act (CCPA) applies above certain thresholds.
- Various state privacy laws are emerging (Virginia, Colorado, Connecticut).
- FTC oversight on data privacy generally.
Small solo providers are usually below the thresholds, but as businesses grow, monitor state-level developments.
Ready to earn on your own terms?
Data protection is a small part of running a professional pet-service business, and it protects you as much as it protects your clients. Set up your OnlyPaw provider profile at onlypaw.net/pages/signup-provider.html, prepare a one-page privacy notice, and get verified in 24 to 48 hours.
Ready to earn on OnlyPaw?
Verified providers get bookings the first week. ID + selfie check, insurance, weekly Monday payouts at a flat 5% platform fee.
Apply as a provider I need pet careMore from OnlyPaw: All posts · All services · Trust & Safety