Are You Falling Short on GDPR? 5 Everyday Risks in Community Transport

Updated: July 25, 2026

Written by Road XS

  • Reading Time: 7 minutes

Many community transport providers unknowingly put passenger data at risk through everyday habits like paper diaries, personal email accounts, printed run sheets, legacy software, and shared spreadsheets. With records often containing home addresses and medical details classed as special category data, a single misstep can trigger mandatory ICO reporting within 72 hours and serious reputational harm.

In This Article

Key Takeaways

  • In the UK, passenger data is governed by the UK GDPR and the Data Protection Act 2018, updated by the Data (Use and Access) Act 2025.
  • Everyday habits such as paper diaries, personal email, printed run sheets, legacy software and shared spreadsheets are the most common causes of avoidable breaches.
  • Passenger records often include home addresses and medical details, which count as special category data and carry a higher risk if exposed.
  • Where a breach is likely to risk people's rights and freedoms, you must report it to the ICO within 72 hours and tell affected passengers if the risk is high.
  • Secure, cloud based software removes most of these risks by centralising bookings, controlling access and keeping an audit trail.

Community transport keeps vulnerable people connected, yet many providers still run daily bookings on paper diaries, personal email and shared spreadsheets. These familiar routines carry real data protection risk. Passenger records often include home addresses and medical notes, so a single mislaid sheet can trigger a reportable breach and lasting reputational harm.

This guide sets out the five everyday practices that most often put operators in breach, explains what the law now expects, and shows how moving away from paper and personal accounts protects your passengers and your organisation.

The Law That Applies to Your Passenger Data

In the UK, passenger information is governed by the UK GDPR and the Data Protection Act 2018. Personal data belongs to the individual, not your organisation. Unless a formal data processing agreement transfers responsibility, your charity or transport service stays fully accountable for how that data is collected, stored and shared.

These rules were updated by the Data (Use and Access) Act 2025, with the main data protection provisions taking effect from February 2026. The Act adjusts parts of the UK GDPR but leaves the core duties intact. You must still process data lawfully and securely, protect special category information, and report qualifying breaches.

One change is directly relevant to this sector. Safeguarding vulnerable people now sits within a new recognised legitimate interests basis, which reduces some paperwork for that specific purpose. It does not, however, weaken your obligations around security, retention or breach reporting, which is where most community transport risk actually lies.

The Information Commissioner's Office (ICO) is the UK regulator and expects organisations to handle personal data fairly, lawfully and securely. The 2025 Act also establishes the Information Commission as its successor body. Falling short can lead to serious consequences, including:

  • Reporting a breach to the ICO within 72 hours where it is likely to risk people's rights and freedoms.
  • Telling every affected passenger directly and without undue delay where the risk to them is high.
  • Investigations, enforcement action and fines of up to 17.5 million pounds or 4 percent of annual global turnover, whichever is higher.
  • Loss of passenger trust, damaged reputation and, in some cases, lost service contracts.
Recommended:
HMRC’s Mileage Rate Increase Is More Significant Than It First Appears

If you recognise any of the five practices below in your own operation, review it now and, if you are unsure whether you are compliant, seek advice from the ICO.

Paper Diaries and Paper Records

paper diary used for community transport bookings

Paper diaries feel simple, but they expose you to several data protection risks that are hard to control once records are written down.

  • Loss or theft: a misplaced diary can expose home addresses and health information in one go.
  • Uncontrolled access: anyone who picks it up can see who is travelling, when and why.
  • Weak security: unless the diary is locked away, for example in a safe, it sits at high risk.
  • No audit trail: you cannot demonstrate accountability or show who accessed what.
  • Right to erasure: you cannot easily remove a passenger's bookings, which may mean tearing out or blanking pages across every diary you hold.

Implication: a lost diary could force you to notify every affected passenger and report a breach to the ICO.

Emailing Drivers via Personal Accounts

emailing drivers passenger details from a personal account

Sending passenger details to drivers' personal Hotmail, Gmail or Yahoo accounts is another common risk. Personal inboxes sit outside your control and rarely meet the standards you would expect of a managed system.

  • Unsecured inboxes: personal accounts often lack strong password practices and two factor authentication.
  • Forwarding and leaks: data can be forwarded on, hacked or stored on servers outside the UK.
  • Sensitive detail exposed: notes on mobility needs or hospital appointments may be included or easily inferred.
  • Over sharing: when you email all drivers at once to check availability, you often share more than any single driver needs to see.

Implication: this can amount to a reportable data breach and cause significant reputational damage.

Printed Run Sheets

printed run sheets left in a vehicle

Printed journey sheets can make a shift feel easier, but they make compliance harder. Once a sheet is printed, you lose control of where it goes and who can read it.

  • Visibility: personal and medical details can be seen by passengers, family members or passers by.
  • Uncontrolled copies: sheets are easy to duplicate and hard to recall, and paper is rarely shredded daily to recognised secure destruction standards such as BS EN 15713.
  • Loss: a sheet left in an unattended vehicle can become an immediate breach.

Implication: if medical details are exposed, that is special category data, and a breach is more likely to meet the threshold for ICO notification.

Legacy Transport Software and VPNs

old VPN server hosting legacy transport software

Older systems hosted on remote servers and reached through a VPN can create risks that are easy to overlook. Unpatched software and poorly configured remote access are among the routes into networks that the National Cyber Security Centre repeatedly warns about.

  • Outdated platforms: known vulnerabilities often go unpatched for months.
  • Weak VPNs: poor configuration leaves an open door for attackers.
  • Unclear hosting: data may sit outside the UK, or on an unmanaged machine that is easy to reach. Even a desktop left switched on can quietly act as a server.

Implication: if your provider does not meet UK hosting and security standards, the liability still rests with your organisation.

Shared Spreadsheets and USB Drives

shared spreadsheets and USB drives holding passenger data

Spreadsheets and USB sticks are still widely used to move bookings around, but both are data protection red flags once passenger information is involved.

  • Unencrypted transfers: data can be intercepted or lost in transit.
  • Multiple copies: once a file is shared, you have no control over where it travels.
  • No guarantee of deletion: data can linger on devices long after it is needed.

Implication: breaches here can lead to enforcement notices, fines and the loss of service contracts.

Why This Matters for Community Transport

Community transport does not just handle names and phone numbers. Day to day, it often involves far more sensitive information than most people realise, including:

  • Home addresses, which reveal when someone is likely to be out.
  • Medical and mobility details, which count as special category data.
  • Records that identify vulnerable individuals.
Recommended:
Haunted by Legacy Transport Software? The Scary Truth Behind Hidden Costs

Breaches of special category data are generally treated as high risk, which is why medical details deserve particular care. Exposure can affect passenger safety and wellbeing, and it can put your organisation in breach of the law. For trustees, the responsibility is personal as well as organisational, as covered in our guide to trustee liability and community transport.

What You Should Do

  • Review your processes now: check honestly whether any of the five practices above are still in use.
  • Log and assess any incidents: keep a record of every breach, then decide whether it meets the threshold for reporting to the ICO.
  • Seek guidance from the ICO: if you think you may be in breach, contact the Information Commissioner's Office for advice.
  • Upgrade your systems: move away from paper, personal email and legacy software toward secure, managed tools.

The Case for Secure, Cloud Based Software

Secure, cloud based systems like Road XS, built on infrastructure from established providers such as Google and Amazon Web Services, remove most of the risks above and help you:

  • Centralise bookings securely, with no more paper diaries or loose spreadsheets.
  • Communicate with drivers through secure portals rather than personal email.
  • Share real time journey information without leaving paper around.
  • Control access with permissions and keep a clear audit trail.
  • Protect special category data such as health and mobility notes.
  • Reduce risk, stay compliant and build trust with passengers and volunteers.

Frequently Asked Questions

Does GDPR apply to volunteer drivers and small charities?

Yes. The UK GDPR and Data Protection Act 2018 apply to any organisation handling personal data, whatever its size and whether staff are paid or volunteers. A small charity running a handful of journeys has the same core duties as a large operator, because the data belongs to the passenger either way.

Do I have to report every data breach to the ICO?

No. You only need to report a breach where it is likely to result in a risk to people's rights and freedoms. You must, however, record every breach internally and be able to justify your decision. If the risk to individuals is high, you also have to tell those affected without undue delay.

Recommended:
How Community Transport Connects Communities

How quickly must a reportable breach be reported?

Within 72 hours of becoming aware of it, where feasible. You do not need every detail before you report. The ICO accepts an initial notification with the information you have, followed by updates. If you report later than 72 hours, you must explain the reason for the delay.

Is passenger medical information special category data?

Yes. Health and mobility details are special category data under the UK GDPR and attract extra protection. Breaches involving this type of information are generally treated as high risk, which makes secure handling and controlled access especially important for community transport providers.

Did the Data (Use and Access) Act 2025 change my obligations?

It refined the framework rather than replacing it. The main provisions took effect from February 2026 and adjusted areas such as legitimate interests and automated decisions. Your core duties around security, special category data and breach reporting remain, so the everyday risks in this article are unchanged.

What are the maximum fines for a serious breach?

For the most serious infringements, fines can reach 17.5 million pounds or 4 percent of annual global turnover, whichever is higher. A lower tier, for example failing to report a breach when required, carries a maximum of 8.7 million pounds or 2 percent. Most community transport cases turn on reputational and contractual harm rather than the top figures.

Key Insights

Data protection is not optional. It is the law, and it protects people's data, dignity and safety. If your organisation still relies on paper, personal email, spreadsheets or legacy systems, you are carrying avoidable risk that a modern approach can remove.

Familiar routines are hard to give up, and "this is how we have always done it" is a common response. The legal duties apply all the same. Where habits are hard to shift, that is usually a sign that volunteers need a little more training on why data protection matters, rather than a reason to leave things as they are.

Take a clear first step. Review your processes, seek ICO advice if you are unsure, and move your bookings somewhere secure.

New Guide

Paper Run Sheets & Data Compliance

This plain English guide explains the UK GDPR risks hiding in paper run sheets, helping trustees and transport managers understand what the law demands in 2026 and how to keep their transport schemes compliant.

Send this to a friend