← All articles
Compliance

GDPR for Taxi and Chauffeur Operators: A Practical Checklist

18 March 2026 · 7 min read · AirportRidePro Team

Ground transport data is unusually sensitive: where someone lives, where they went, and at what time. Regulators across the EU and UK treat it accordingly. Compliance is mostly a software capability question, and asking the right questions of a vendor is faster than writing policy from scratch.

What your platform must be able to do

If any of these is manual, it will not survive a subject access request under time pressure.

  • Cookie consent with granular categories on the booking site
  • Consent logging with timestamp and source for marketing
  • Right to be forgotten — anonymise a passenger while keeping financial records
  • Data export in a portable format on request
  • Retention policies that delete or anonymise automatically
  • Audit logs of who viewed or exported passenger data
  • An EU-hosted data option for continental clients

Erasure without breaking your accounts

You cannot simply delete a completed booking — tax law requires the financial record. The correct behaviour is pseudonymisation: strip name, phone, email and precise addresses, keep the fare, date and VAT trail. Confirm your platform does exactly this before you promise anything to a customer.

Drivers have rights too

Continuous vehicle tracking, in-car cameras and performance scoring are all processing of driver personal data. Document the lawful basis, tell drivers plainly what is recorded and for how long, and switch tracking off outside shift hours.

Key takeaways

  • Pseudonymise rather than delete to keep financial records lawful
  • Log consent with timestamp and source, not just a checkbox state
  • Driver tracking needs its own lawful basis and a clear notice

Take more bookings tonight, not next quarter

Launch your branded booking engine, driver app and dispatch dashboard in a single day. No free trial — a guided setup, your data migrated, and you go live.