1.Purpose
The National Vehicle Service Register (“NVSR”) is committed to protecting personal information and handling all data responsibly, lawfully and transparently.
This Privacy & Data Protection Policy explains how NVSR collects, stores, protects, processes and shares information through the Register.
The Register has been designed around the principle of data minimisation, ensuring that only information necessary to provide vehicle maintenance records is collected and displayed.
2.Scope
This Policy applies to:
- Vehicle owners
- Workshops
- Technicians
- Business applicants
- Public users
- Website visitors
- Third-party service providers acting on behalf of NVSR
3.Data Protection Principles
NVSR is designed to operate in accordance with UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Our principles include:
- Lawfulness
- Fairness
- Transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity
- Confidentiality
- Accountability
4.Public Information
The Register is intended to publish vehicle maintenance records. Publicly viewable information may include:
- Vehicle registration
- Vehicle make
- Vehicle model
- Year of manufacture
- Service dates
- Recorded mileage
- Service category
- Workshop name
- Workshop verification status
- Certificate number
- Work completed
- Parts replaced
- Inspection summaries
- Public evidence authorised for release
- Record version
- Publication date
This information forms part of the vehicle’s maintenance history.
5.Information That Is Never Public
NVSR will not intentionally publish personal information belonging to vehicle owners. Examples include:
- Owner name
- Home address
- Telephone numbers
- Email addresses
- Payment information
- Bank details
- Driving licence information
- Government identity documents
- Insurance policy numbers
- Date of birth
- IP addresses
- Account credentials
- Private workshop verification documents
- Internal investigation notes
Where documents contain personal information they remain private unless there is a lawful reason to disclose them.
6.Vehicle Ownership
A vehicle record belongs to the vehicle’s maintenance history. Ownership of the vehicle does not automatically make every document publicly available.
Vehicle owners control:
- Private uploaded documents
- Shared links
- Temporary access
- Download permissions where applicable
Owner-supplied records are clearly labelled and are not treated as verified workshop records.
7.Workshop Information
Approved workshops may choose to publish business information. Public workshop profiles may include:
- Trading name
- Business type
- Workshop verification status
- Service categories
- Website
- Business contact information
- Workshop location
- Verified qualifications
- Public workshop photographs
- Verification dates
Private verification evidence remains restricted.
8.Identity Verification
Identity documents submitted during workshop verification are used solely for verification purposes. Identity documentation is:
- stored securely
- access restricted
- encrypted where appropriate
- not publicly available
- retained only where required
- reviewed by authorised personnel
Identity documents are never displayed within the public Register.
9.Data Security
NVSR is designed using multiple layers of technical and organisational security. Security measures may include:
- Encrypted connections (HTTPS/TLS)
- Encryption of stored information where appropriate
- Role-based access controls
- Multi-factor authentication support
- Secure password hashing
- Session management
- Access logging
- Audit logging
- Database security policies
- Backup procedures
- Infrastructure monitoring
- Secure cloud hosting
- Principle of least privilege
Security measures are reviewed periodically as the platform evolves.
10.Audit Logging
Certain activities are recorded for security and accountability. Examples include:
- Account sign-in
- Failed sign-in attempts
- Workshop verification decisions
- Record publication
- Record amendments
- Certificate generation
- Permission changes
- Administrative actions
- Security events
Audit records help maintain the integrity of the Register.
11.Access Controls
Different users have different permissions.
- Public users can search authorised public records only.
- Vehicle owners can access records linked to their account.
- Workshops can manage their own records.
- Administrators have controlled access necessary for operating the Register.
No user is granted unrestricted access to all information.
12.Data Retention
Information is retained only for as long as necessary to fulfil legitimate operational, legal or regulatory purposes.
Some vehicle maintenance records form part of the permanent historical record of the vehicle.
Identity verification information, application documentation and operational logs are retained in accordance with published retention schedules and applicable legal requirements.
13.Data Sharing
NVSR does not sell personal information. Information may be shared only where:
- authorised by the data subject
- necessary to operate the Register
- required by law
- required by a court order
- necessary to investigate fraud or misuse
- necessary to protect legal rights
- necessary to safeguard the integrity of the Register
14.Cookies and Analytics
NVSR uses cookies and similar technologies only where necessary to operate the website or where users have provided consent for optional technologies.
Users may manage cookie preferences through the website. Further information is provided within the Cookie Policy.
15.User Rights
Subject to applicable law, individuals may have rights including:
- Access personal information
- Request correction of inaccurate information
- Request deletion where applicable
- Restrict processing in certain circumstances
- Object to certain processing
- Data portability where applicable
- Withdraw consent where processing relies upon consent
- Lodge a complaint with the Information Commissioner’s Office (ICO)
Certain information may need to be retained where required by law or to preserve the integrity of vehicle maintenance records.
16.Security Incidents
NVSR maintains procedures for identifying, investigating and responding to suspected security incidents.
Where legally required, affected individuals and relevant supervisory authorities will be notified in accordance with applicable law.
17.International Transfers
Where personal information is processed outside the United Kingdom, NVSR will seek to ensure that appropriate safeguards are in place in accordance with applicable data protection legislation.
18.Children’s Information
The Register is intended for vehicle owners, workshops and other adults involved in vehicle maintenance. It is not designed for use by children.
19.Contact
Questions relating to privacy, data protection or personal information should be submitted using the Contact form available on the National Vehicle Service Register website.
Please select the most appropriate enquiry category, such as:
- Privacy
- Data Protection
- Personal Data Request
- Workshop Verification
- General Enquiry
This enables enquiries to be routed securely to the appropriate administrator. NVSR does not publish a general support email address.
20.Changes to this Policy
This Policy may be updated from time to time to reflect operational, legal or regulatory developments. The latest published version will always be available through the National Vehicle Service Register website.
21.Governing Law
This Policy is governed by the laws of England and Wales.
A.Appendix A — Privacy by Design
The Register has been designed around the following principles:
- Public vehicle history without exposing vehicle-owner identity.
- Business transparency without exposing confidential verification documents.
- Secure authentication for registered users.
- Permanent audit history for published records.
- Least-privilege access for all users.
- Clear separation between public and private information.
- Version-controlled record amendments.
- Secure evidence storage.
- Transparent governance.
- Regular review of security controls.
- Reference
- NVSR-GDPR-001
- Version
- 1.0
- Classification
- Public
- Review
- Annually or following legislative or operational changes
