Understanding Your Legal Obligations for Test Drive Data
When a potential buyer requests a test drive, you collect personal data including their name, contact details, and often a copy of their driving licence. Under GDPR, this data collection requires a lawful basis, appropriate security measures, and clear retention policies. The lawful basis for processing test drive requests is typically legitimate interests, where your need to verify driver credentials and arrange the appointment is balanced against the individual's privacy rights. You must document this balancing test and ensure buyers understand how their data will be used before they submit their details.
The stakes are significant. GDPR violations can result in fines up to £17.5 million or 4 per cent of annual turnover, whichever is higher. For most independent dealers, even a minor penalty would be financially devastating. Beyond fines, poor data handling damages customer trust and can lead to complaints that consume time and resources. Establishing compliant processes from the outset protects both your business and your customers.
Establishing Lawful Basis for Processing Test Drive Requests
Legitimate interests is the most appropriate lawful basis for processing test drive enquiries in most circumstances. This basis applies when you have a genuine business need to process the data and the processing does not override the individual's rights and freedoms. For test drives, your legitimate interest includes verifying that the person is legally permitted to drive the vehicle, protecting your stock from theft or damage, and managing appointment scheduling.
You must conduct and document a legitimate interests assessment (LIA) that demonstrates you have considered less intrusive alternatives and concluded that data collection is proportionate. The assessment should explain why you need each piece of information you collect. For example, you need a driving licence to verify entitlement, a phone number to confirm appointments, and potentially an address to assess proximity to your dealership. If you cannot justify a data field, remove it from your form.
Consent is not the appropriate lawful basis for test drive requests. Consent must be freely given, and when someone wants to test drive a vehicle, they have little genuine choice about providing their details. Using consent as your lawful basis creates additional obligations around withdrawal and makes your data processing vulnerable to challenge. Stick with legitimate interests and document your reasoning clearly.
For detailed guidance on selecting and documenting your lawful basis, refer to our complete guide to lawful basis for processing buyer enquiries.
What Information You Can Legitimately Collect
Limit data collection to what is strictly necessary for the test drive. Essential information includes full name, contact telephone number, and driving licence details (number, expiry date, and categories). You may also collect email address if you send confirmation messages electronically. Requesting a photocopy or photograph of the driving licence is acceptable, but you must have a documented reason (such as insurance requirements or theft prevention) and delete it once the test drive is complete or the enquiry lapses.
Avoid collecting excessive information that serves no clear purpose. You do not need the buyer's home address unless your insurance specifically requires it or you offer vehicle delivery. You do not need employment details, marital status, or other demographic information unrelated to the test drive itself. Marketing preferences should be collected separately with clear opt-in consent, never bundled with the test drive request.
When you photograph or copy a driving licence, treat this as special category data requiring heightened protection. Store copies in encrypted folders with restricted access, not in general email inboxes or shared drives. Set automatic deletion rules so licence copies are removed after a defined period (typically 30 days if the enquiry does not progress, or when the sale completes).
Creating a Transparent Privacy Notice
Your privacy notice must explain how you handle test drive data in language that ordinary people understand. Position the notice prominently on your test drive request form, either as a short summary with a link to your full privacy policy or as a dedicated section above the submit button. The notice should cover who you are, what data you collect, why you need it, how long you keep it, and who you might share it with.
A compliant privacy notice for test drive requests should include your dealership name and contact details, a statement that you process data under legitimate interests to arrange and conduct test drives, a list of the specific data fields you collect, your retention period (for example, 90 days for unsuccessful enquiries, duration of ownership plus six years for completed sales), and information about third parties who may receive the data (such as your insurance provider or finance broker if applicable).
Avoid legal jargon and generic templates copied from other websites. Write in plain English and be specific about your actual practices. If you use a third-party booking system, name it. If you share data with your finance partner, say so. Transparency builds trust and reduces the likelihood of complaints. Buyers are more willing to share information when they understand exactly how it will be used.
Managing Consent for Marketing Communications
Test drive requests and marketing consent are separate issues requiring different approaches. Never assume that someone requesting a test drive has consented to receive marketing emails, SMS messages, or phone calls about other vehicles or services. You must obtain explicit opt-in consent for marketing, presented as a clearly worded, unticked checkbox that is separate from the test drive request itself.
The consent request should be specific about what the buyer is agreeing to. Instead of a vague statement like "I agree to receive updates", use clear language such as "I would like to receive emails about similar vehicles and special offers from [Dealership Name]. You can unsubscribe at any time." If you plan to use multiple channels (email, SMS, phone), provide separate consent options for each or clearly list all channels in a single consent statement.
Record when and how consent was given, including the exact wording of the consent statement and the IP address or timestamp of the submission. This evidence is essential if you need to demonstrate compliance during an audit or investigation. Implement a simple process for buyers to withdraw consent, such as an unsubscribe link in every marketing email or a dedicated email address for opt-out requests. Process withdrawal requests promptly, ideally within 24 hours.
Setting Appropriate Data Retention Periods
Data retention policies define how long you keep test drive information before deleting it. Different scenarios require different retention periods. For enquiries that do not result in a test drive (for example, the buyer cancels or does not respond), delete personal data after 90 days unless you have obtained marketing consent. For completed test drives that do not lead to a sale, retain data for up to six months to handle any follow-up queries, then delete unless the individual has consented to marketing.
When a test drive leads to a sale, retention periods extend significantly. You must keep transaction records for six years after the sale to comply with tax and accounting regulations. This includes the buyer's name, contact details, vehicle purchased, and sale price. However, you should still delete unnecessary data such as driving licence copies once the sale completes, as this information no longer serves a legitimate purpose.
Document your retention schedule in a simple table that staff can reference. Include categories such as "cancelled test drive request", "completed test drive, no sale", "completed sale", and "marketing consent given", with the corresponding retention period and deletion method for each. Review stored data quarterly to ensure old records are being deleted as scheduled. Manual review is necessary because automated deletion systems sometimes fail or exclude certain file types.
Our GDPR compliance checklist for vehicle dealers provides a complete framework for documenting and implementing retention policies across all buyer interactions.
Securing Test Drive Data Against Unauthorised Access
Personal data security is a core GDPR requirement. Test drive information should be stored in systems with appropriate technical and organisational measures to prevent unauthorised access, accidental loss, or data breaches. At minimum, this means password-protected systems, encrypted storage for driving licence copies, and access controls that limit who can view buyer information.
If you use paper forms to collect test drive requests, store completed forms in a locked cabinet accessible only to authorised staff. Do not leave forms on desks, in vehicles, or in unsecured areas where customers or unauthorised personnel might see them. When you no longer need paper records, shred them using a cross-cut shredder or use a certified document destruction service. Simply throwing forms in the bin is a data breach.
For digital systems, use strong passwords and enable two-factor authentication where available. Avoid storing test drive data in personal email accounts or consumer-grade cloud storage services that lack business-grade security features. If you use a customer relationship management (CRM) system or dealer management system (DMS), verify that the provider is GDPR-compliant and has appropriate data processing agreements in place. Your software provider is a data processor, and you remain responsible for ensuring they handle data securely.
Train all staff who handle test drive requests on data protection basics. They should understand that buyer information is confidential, must not be shared with unauthorised parties, and should only be accessed when necessary for legitimate business purposes. Regular training (at least annually) reinforces good practices and keeps data protection front of mind.
Handling Test Drive Requests Efficiently While Staying Compliant
Compliance and efficiency are not mutually exclusive. A well-designed test drive workflow protects data while reducing administrative burden. Start by creating a standard form (digital or paper) that collects only necessary information and includes your privacy notice. Digital forms can include mandatory fields to ensure you collect everything you need and automatic timestamping to record when consent was given.
When a request comes in, acknowledge it promptly with a confirmation message that includes the appointment details and a reminder of what the buyer should bring (driving licence, proof of address if required by your insurance). This confirmation serves as evidence that you communicated clearly about the test drive and reinforces the professional impression of your dealership.
During the test drive, verify the driving licence against the details provided in the request. If you photograph the licence, do so on a business device (not a personal phone) and transfer the image to secure storage immediately. After the test drive, record the outcome in your CRM or DMS (completed, vehicle purchased, buyer not interested, follow-up required). This record helps you track retention periods and ensures timely deletion of data.
For practical workflow guidance that integrates compliance with operational efficiency, see our dealer workflow guide for handling buyer enquiries.
Responding to Data Subject Rights Requests
Buyers have specific rights under GDPR, including the right to access their data, request corrections, ask for deletion, and object to processing. You must respond to these requests within one month, free of charge in most cases. Establish a clear process for receiving and handling rights requests so you can meet the deadline consistently.
The most common request is a subject access request (SAR), where someone asks for a copy of all personal data you hold about them. To fulfil a SAR, search all systems where you might store buyer data (CRM, email, paper files, driving licence copies) and compile a complete list. Provide the information in a commonly used electronic format (such as PDF) unless the individual requests a specific format. Include details of how you obtained the data, why you are processing it, and who you have shared it with.
Deletion requests (also called the right to erasure or right to be forgotten) require you to delete personal data unless you have a compelling legal reason to retain it. If someone requests deletion of their test drive data and you have no ongoing legal obligation to keep it (such as a completed sale within the six-year tax retention period), delete the data and confirm deletion in writing. If you must retain the data, explain why and specify when it will be deleted.
Document every rights request you receive, including the date received, action taken, and date of response. This documentation demonstrates compliance and helps you identify patterns (for example, if multiple buyers request deletion, it may indicate confusion about your retention policies that you should address proactively).
Insurance Considerations for Test Drives
Your motor trade insurance policy may impose specific requirements on test drive data collection. Some insurers require you to verify driving licence details, record the buyer's address, or obtain a signed agreement before allowing a test drive. These requirements can affect what data you collect and how you justify collection under GDPR.
Review your insurance policy to identify any data-related requirements. If your insurer mandates collection of information that seems excessive (such as employment details or income), query whether it is genuinely necessary or whether alternative verification methods would suffice. Insurers sometimes include standard clauses that are not strictly enforced, and you may be able to negotiate more proportionate requirements.
When insurance requirements conflict with data minimisation principles, document the conflict and your resolution. For example, if your insurer requires a copy of the driving licence but GDPR encourages you to minimise data collection, your documented position might be that you take a photograph, verify the details, and delete the image within seven days unless the test drive leads to a sale. This approach satisfies both the insurance requirement and the GDPR principle of storage limitation.
Common GDPR Mistakes Dealers Make with Test Drives
Many dealers inadvertently violate GDPR through practices that seem harmless but create compliance risks. One common mistake is keeping all test drive records indefinitely in email inboxes or CRM systems. Without defined retention periods and regular deletion, you accumulate personal data that serves no purpose and increases your exposure in the event of a data breach.
Another frequent error is using consent as the lawful basis for test drive processing. As explained earlier, consent is inappropriate because it is not freely given in this context. If you have been relying on consent, switch to legitimate interests and update your privacy notice to reflect the change. You do not need to re-contact previous test drive customers unless you are actively marketing to them, in which case you need valid marketing consent anyway.
Sharing test drive data with third parties without a clear legal basis is a serious violation. If you send buyer details to a finance broker, warranty provider, or other partner without informing the buyer in your privacy notice, you are breaching GDPR. Always disclose third-party data sharing in advance and ensure you have a data processing agreement with any organisation that processes buyer data on your behalf.
Failing to respond to rights requests within the one-month deadline is another common mistake. Even if a request is inconvenient or arrives during a busy period, you must prioritise it. If you need more time, you can extend the deadline by two months, but you must notify the individual within the original one-month period and explain why the extension is necessary.
Integrating GDPR Compliance with Your Broader Dealer Operations
Test drive data handling is one component of a comprehensive data protection framework. Your dealership likely processes personal data in multiple contexts including finance applications, part-exchange valuations, service bookings, and warranty registrations. Consistent policies across all these areas reduce confusion and ensure staff apply the same standards regardless of the interaction type.
Develop a single, overarching privacy policy that covers all ways you collect and use personal data, then create specific guidance for each process (test drives, finance applications, service bookings). This structure allows you to maintain consistency while addressing the unique requirements of each scenario. Train staff on the general principles (lawful basis, data minimisation, security, retention) and the specific procedures for their roles.
Regularly audit your data processing activities to identify gaps or inconsistencies. A simple annual review where you list all the ways you collect personal data, verify that you have documented lawful basis for each, and check that retention periods are being followed will catch most compliance issues before they become serious problems. Document the audit and any corrective actions taken.
GDPR compliance also intersects with other regulatory requirements. For dealers offering finance, the Financial Conduct Authority's Consumer Duty regulations impose additional obligations around transparency and fair treatment. Our guide to FCA compliance for car dealers in 2026 explains how these requirements interact with data protection obligations.
Frequently Asked Questions
How long can I keep driving licence copies after a test drive?
You should delete driving licence copies as soon as they have served their purpose. If the test drive does not lead to a sale, delete the copy within 30 days. If a sale proceeds, you may retain the copy until the transaction completes, then delete it unless you have a specific legal obligation to keep it longer (which is rare). Prolonged retention of driving licence copies is difficult to justify under data minimisation principles.
Do I need separate consent for test drives and marketing emails?
Yes. The lawful basis for processing test drive data is legitimate interests, not consent. Marketing communications require separate, explicit opt-in consent that is freely given. Never assume that someone who requests a test drive has consented to marketing. Provide a clear, unticked checkbox for marketing consent on your test drive form, worded separately from the test drive request itself.
What happens if someone requests deletion of their test drive data but I need it for a legal claim?
If you have a legitimate legal claim (for example, the buyer damaged the vehicle during the test drive and you are pursuing compensation), you can refuse the deletion request. You must inform the individual of your refusal, explain the legal basis (establishment, exercise, or defence of legal claims), and confirm when the data will be deleted once the claim is resolved. Document your reasoning carefully.
Can I share test drive details with a finance broker without telling the buyer?
No. If you share personal data with third parties, you must inform buyers in your privacy notice before they submit their details. The notice should name the categories of third parties (such as finance brokers, warranty providers, or insurance companies) and explain why you share data with them. Undisclosed data sharing is a GDPR violation.
What should I do if a buyer submits a test drive request but refuses to provide a driving licence?
You can refuse the test drive. Verifying driving entitlement is a legitimate requirement, and you are not obliged to allow someone to drive your vehicle if they will not provide the necessary credentials. Explain politely that your insurance and risk management policies require driving licence verification, and offer alternative ways to view the vehicle (such as a dealer-driven demonstration) if appropriate.