FieldApp field-service app FieldApp FIELDAPP · GUIDE
GDPR

GDPR for Trade Businesses: Handling Customer Data Right

20 June 2026 · 7 min · GDPRdata protectiontrade businesscustomer dataIMY

As a tradesperson you collect personal data all day without thinking about it: a name and address when someone books, a phone number to call ahead, photos of the bathroom, a personal identity number on the ROT paperwork, and maybe years of invoice history. All of it falls under GDPR. The good news is that a normal electrical, plumbing or carpentry business doesn't need a legal department to get this right. You need to understand a few core principles and clean up the sloppiest habits.

FÖRE kalkyl.xls papper post-it EFTER FieldApp
Ditch the scattered tools — everything in one place, in your brand.

This guide is written for owners of smaller trade businesses in Sweden. The supervisory authority is the Swedish Authority for Privacy Protection (IMY, Integritetsskyddsmyndigheten), which is where both complaints and serious incidents are reported. The rules rarely change, but because they are interpreted on an ongoing basis you should verify the details against imy.se before making any important decision.

What data does a trade business actually handle?

Personal data is anything that can be linked to a living person. For a typical field-service business that usually means:

Note that personal identity numbers have extra protection in Sweden: they may only be processed when clearly justified, for example for secure identification or tax documentation. Writing a personal identity number in an email subject line or an open chat is a classic mistake.

You need a legal basis — and you usually already have one

GDPR requires that every processing activity rests on a legal basis. You don't need to collect consent for everything — consent is actually often the weakest basis, because it can be withdrawn. For trade businesses, these three are the most common:

The point isn't to fill in forms. It's that for each type of data you can answer the question: why do we hold this, and on what basis?

How long can you keep data — and when must you delete it?

This is the question that causes the most confusion, because two sets of rules pull in different directions. GDPR says you shouldn't keep personal data longer than necessary (storage limitation). At the same time the Bookkeeping Act requires you to keep accounting records for seven years after the end of the financial year — and that law takes precedence, because it is exactly the kind of legal obligation GDPR makes an exception for.

In practice this means:

A good pattern is to separate: keep active customers in your working tool, and archive closed invoices so they aren't sitting in daily operations. Always confirm the exact retention periods and any exceptions with the Swedish Tax Agency (Skatteverket) and the Swedish Accounting Standards Board (Bokföringsnämnden), as the details can change.

Five concrete steps you can take this week

You don't have to do everything at once. Start here:

Much of this gets easier when your systems are built for it from the start. In FieldApp, booking, ROT paperwork, invoicing and field documentation sit in one tenant-isolated system with access controls, and invoicing syncs to Fortnox where the bookkeeping lives — so accounting data ends up in the right place instead of scattered across loose email threads.

What happens if you don't get it right?

Most small trade businesses aren't facing record fines, but the penalties are real. Under GDPR an administrative fine for the most serious infringements can reach EUR 20 million or 4 percent of global annual turnover, whichever is higher; for less serious cases the ceiling is EUR 10 million or 2 percent. In practice the fine can land anywhere from zero up to that ceiling, and IMY takes into account the size of the business and how serious the failing is.

The most common reality isn't a huge fine but a complaint from a customer or a neighbour who feels their data was handled carelessly — and that's when you want to be able to show you have your house in order. Being able to answer what you store, why and for how long is 90 percent of the job.

Want to bring booking, ROT paperwork and invoicing into one system built for Swedish tradespeople from the ground up? Try FieldApp free for 14 days and see how much calmer data handling becomes when it all hangs together.

FAQ

Does my small trade business need a data protection officer?

Almost never. The requirement for a data protection officer mainly applies to public authorities and businesses doing large-scale or sensitive processing. A normal electrical, plumbing or carpentry business usually needs no officer — but you are still responsible for complying with the rules yourself. Verify your specific situation with IMY if you're unsure.

Do I have to delete a customer who asks under GDPR?

Not if the data is in your bookkeeping. The right to erasure doesn't override the Bookkeeping Act's requirement to keep accounting records for seven years. You can delete contact details not tied to an invoice, but invoice records may and should remain until the retention period expires.

Can I store personal identity numbers for the ROT deduction?

Yes. When it's needed to administer the ROT deduction and tax documentation you have grounds for it. Personal identity numbers do have extra protection in Sweden and should only be used when clearly justified. Never send one in plain text by email or chat, and confirm the current ROT rules with the Swedish Tax Agency.

What counts as a personal data breach, and when must it be reported?

It's when personal data is lost, leaked or reaches the wrong person — for example a lost unlocked phone or an email to the wrong recipient. If the breach poses a risk to those affected it must be reported to IMY within 72 hours of discovery. Always document what happened, even when you judge that no report is needed.

Do I need an agreement with my bookkeeping or booking system?

Yes. Vendors that process customer data on your behalf are data processors, which means you need a data processing agreement governing how they may handle the data. Reputable cloud systems provide one — check that it's in place for every service that stores your customers' data.

One system for your field-service business

Booking, quotes with ROT, scheduling, an offline app, time tracking and invoicing — in your own brand.

Try FieldApp free