Register operational · Records verified against workshop evidence
Login
Governance framework · Instrument

Privacy & Data Protection Policy

How the National Vehicle Service Register collects, stores, protects, processes and shares information through the Register.

Document reference
NVSR-GDPR-001
Version
1.0
Status
In force
Effective date
1 August 2026

1.Purpose

The National Vehicle Service Register (“NVSR”) is committed to protecting personal information and handling all data responsibly, lawfully and transparently.

This Privacy & Data Protection Policy explains how NVSR collects, stores, protects, processes and shares information through the Register.

The Register has been designed around the principle of data minimisation, ensuring that only information necessary to provide vehicle maintenance records is collected and displayed.

2.Scope

This Policy applies to:

  • Vehicle owners
  • Workshops
  • Technicians
  • Business applicants
  • Public users
  • Website visitors
  • Third-party service providers acting on behalf of NVSR

3.Data Protection Principles

NVSR is designed to operate in accordance with UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our principles include:

  • Lawfulness
  • Fairness
  • Transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity
  • Confidentiality
  • Accountability

4.Public Information

The Register is intended to publish vehicle maintenance records. Publicly viewable information may include:

  • Vehicle registration
  • Vehicle make
  • Vehicle model
  • Year of manufacture
  • Service dates
  • Recorded mileage
  • Service category
  • Workshop name
  • Workshop verification status
  • Certificate number
  • Work completed
  • Parts replaced
  • Inspection summaries
  • Public evidence authorised for release
  • Record version
  • Publication date

This information forms part of the vehicle’s maintenance history.

5.Information That Is Never Public

NVSR will not intentionally publish personal information belonging to vehicle owners. Examples include:

  • Owner name
  • Home address
  • Telephone numbers
  • Email addresses
  • Payment information
  • Bank details
  • Driving licence information
  • Government identity documents
  • Insurance policy numbers
  • Date of birth
  • IP addresses
  • Account credentials
  • Private workshop verification documents
  • Internal investigation notes

Where documents contain personal information they remain private unless there is a lawful reason to disclose them.

6.Vehicle Ownership

A vehicle record belongs to the vehicle’s maintenance history. Ownership of the vehicle does not automatically make every document publicly available.

Vehicle owners control:

  • Private uploaded documents
  • Shared links
  • Temporary access
  • Download permissions where applicable

Owner-supplied records are clearly labelled and are not treated as verified workshop records.

7.Workshop Information

Approved workshops may choose to publish business information. Public workshop profiles may include:

  • Trading name
  • Business type
  • Workshop verification status
  • Service categories
  • Website
  • Business contact information
  • Workshop location
  • Verified qualifications
  • Public workshop photographs
  • Verification dates

Private verification evidence remains restricted.

8.Identity Verification

Identity documents submitted during workshop verification are used solely for verification purposes. Identity documentation is:

  • stored securely
  • access restricted
  • encrypted where appropriate
  • not publicly available
  • retained only where required
  • reviewed by authorised personnel

Identity documents are never displayed within the public Register.

9.Data Security

NVSR is designed using multiple layers of technical and organisational security. Security measures may include:

  • Encrypted connections (HTTPS/TLS)
  • Encryption of stored information where appropriate
  • Role-based access controls
  • Multi-factor authentication support
  • Secure password hashing
  • Session management
  • Access logging
  • Audit logging
  • Database security policies
  • Backup procedures
  • Infrastructure monitoring
  • Secure cloud hosting
  • Principle of least privilege

Security measures are reviewed periodically as the platform evolves.

10.Audit Logging

Certain activities are recorded for security and accountability. Examples include:

  • Account sign-in
  • Failed sign-in attempts
  • Workshop verification decisions
  • Record publication
  • Record amendments
  • Certificate generation
  • Permission changes
  • Administrative actions
  • Security events

Audit records help maintain the integrity of the Register.

11.Access Controls

Different users have different permissions.

  • Public users can search authorised public records only.
  • Vehicle owners can access records linked to their account.
  • Workshops can manage their own records.
  • Administrators have controlled access necessary for operating the Register.

No user is granted unrestricted access to all information.

12.Data Retention

Information is retained only for as long as necessary to fulfil legitimate operational, legal or regulatory purposes.

Some vehicle maintenance records form part of the permanent historical record of the vehicle.

Identity verification information, application documentation and operational logs are retained in accordance with published retention schedules and applicable legal requirements.

13.Data Sharing

NVSR does not sell personal information. Information may be shared only where:

  • authorised by the data subject
  • necessary to operate the Register
  • required by law
  • required by a court order
  • necessary to investigate fraud or misuse
  • necessary to protect legal rights
  • necessary to safeguard the integrity of the Register

14.Cookies and Analytics

NVSR uses cookies and similar technologies only where necessary to operate the website or where users have provided consent for optional technologies.

Users may manage cookie preferences through the website. Further information is provided within the Cookie Policy.

15.User Rights

Subject to applicable law, individuals may have rights including:

  • Access personal information
  • Request correction of inaccurate information
  • Request deletion where applicable
  • Restrict processing in certain circumstances
  • Object to certain processing
  • Data portability where applicable
  • Withdraw consent where processing relies upon consent
  • Lodge a complaint with the Information Commissioner’s Office (ICO)

Certain information may need to be retained where required by law or to preserve the integrity of vehicle maintenance records.

16.Security Incidents

NVSR maintains procedures for identifying, investigating and responding to suspected security incidents.

Where legally required, affected individuals and relevant supervisory authorities will be notified in accordance with applicable law.

17.International Transfers

Where personal information is processed outside the United Kingdom, NVSR will seek to ensure that appropriate safeguards are in place in accordance with applicable data protection legislation.

18.Children’s Information

The Register is intended for vehicle owners, workshops and other adults involved in vehicle maintenance. It is not designed for use by children.

19.Contact

Questions relating to privacy, data protection or personal information should be submitted using the Contact form available on the National Vehicle Service Register website.

Please select the most appropriate enquiry category, such as:

  • Privacy
  • Data Protection
  • Personal Data Request
  • Workshop Verification
  • General Enquiry

This enables enquiries to be routed securely to the appropriate administrator. NVSR does not publish a general support email address.

20.Changes to this Policy

This Policy may be updated from time to time to reflect operational, legal or regulatory developments. The latest published version will always be available through the National Vehicle Service Register website.

21.Governing Law

This Policy is governed by the laws of England and Wales.

A.Appendix A — Privacy by Design

The Register has been designed around the following principles:

  • Public vehicle history without exposing vehicle-owner identity.
  • Business transparency without exposing confidential verification documents.
  • Secure authentication for registered users.
  • Permanent audit history for published records.
  • Least-privilege access for all users.
  • Clear separation between public and private information.
  • Version-controlled record amendments.
  • Secure evidence storage.
  • Transparent governance.
  • Regular review of security controls.
Document control
Reference
NVSR-GDPR-001
Version
1.0
Classification
Public
Review
Annually or following legislative or operational changes