Dispatch uptime 99.98% · Live in 3 markets
Compliance · EU · 2026-03-12

GDPR for chauffeur operators: the six things auditors actually ask about.

Chauffeur companies process more personal data than most operators realise — passenger names, home addresses, phone numbers, corporate hierarchies and, increasingly, dashcam footage. GDPR takes all of it seriously.

Quick answer

GDPR-compliant chauffeur operations rest on six things: configurable data retention (36 months default, auto-pseudonymised after), first-name-plus-initial display to drivers, explicit dashcam data controllership, one-click subject-access-request exports, a signed data processing agreement with every corporate client, and 72-hour breach-reporting capability with a full audit trail. Ridezora ships all six as defaults — a DPA template ready to counter-sign, a per-passenger JSON export button, retention rules per data class, and immutable timestamps across bookings, allocations and payments. Auditors ask about these six every time. Answering with a screenshot beats answering with a promise.

Frequently asked questions

Is Ridezora GDPR-compliant?

Yes — Ridezora acts as a data processor under GDPR, ships a standard DPA, supports configurable retention windows, offers per-passenger data export, and provides the audit trail required for 72-hour breach reporting.

How long is passenger data retained?

Default is 36 months, configurable per operator or per corporate contract. Data beyond the retention window is pseudonymised automatically — trip statistics remain but personal identifiers are removed.

How do I handle a subject access request?

One click in the operator console generates a structured JSON export of everything Ridezora holds against a given passenger identifier — bookings, invoices, communications and consent records.

Where is passenger data hosted?

EU customer data is hosted in EU data centres by default. US, UK and AU regions have their own data residency options to match local requirements.

Data retention is the first thing auditors ask about. The default answer — 'we keep everything forever' — is wrong. Ridezora ships a configurable retention policy: passenger trip records default to 36 months, with corporate contracts often requiring longer. Anything beyond the retention window is pseudonymised automatically.

Passenger name display in the driver app is the second question. Best practice is to show the first name and last-name initial to the driver — enough for a kerbside greeting, not enough to identify the passenger to a bystander looking over the driver's shoulder.

Dashcams are the third. They generate personal data — passenger faces, sometimes audio. If the fleet uses them, the operator is a data controller for that footage. Ridezora doesn't ship a dashcam; if you do, the retention and subject-access-request pathway needs to include it explicitly.

Subject access requests are the fourth. A passenger has the right to ask what you hold on them. Ridezora provides a one-click export per passenger identifier, in a structured JSON format that satisfies the ICO's expectations.

The DPA — the data processing agreement — is the fifth. Every corporate contract needs one. Ridezora ships a standard DPA covering the operator-as-controller, Ridezora-as-processor relationship, ready to counter-sign.

The sixth is honest breach reporting: 72 hours to the ICO, no exceptions. The audit trail across bookings, allocations and payments makes the timeline reconstructable — which is what a regulator wants to see.

← All posts
10 min read
Ready when you are

Watch Ridezora dispatch your first booking.

Thirty minutes. A sample fleet configured for your city. No obligation, no sales script — just the console, the booker and the driver app in action.