Pipeline Data and UK GDPR: What Small Businesses Need to Know
Tracking enquiries means processing personal data
If you record a customer's name, phone number, what they asked about, and when they enquired, you are processing personal data under the UK GDPR (the Data Protection Act 2018). This applies whether you use a CRM, a spreadsheet, or a notebook. The legal obligations are the same regardless of the tool.
This is not a reason to avoid tracking — it is a reason to do it properly from the start. The compliance requirements for a small business tracking enquiries are straightforward, but ignoring them carries real risk: the highest UK GDPR fine is up to 4% of global annual turnover or £17.5 million, whichever is higher.
Lawful basis: Legitimate Interests, not the new shortcut
The UK Data (Use and Access) Act 2025 (DUAA) introduced a new lawful basis called "Recognised Legitimate Interests" (RLI). This has generated confusion, because the name suggests it simplifies the existing Legitimate Interests pathway.
It does not apply here. RLI covers specific public interest scenarios: safeguarding vulnerable adults, responding to emergencies, preventing crime. It explicitly does not extend to commercial processing, marketing, or general business operations (ICO guidance, 2026; Usercentrics compliance analysis, 2026; Hunton Andrews Kurth legal analysis, 2026).
For tracking customer enquiries in a pipeline or CRM, the lawful basis will usually be standard Legitimate Interests under Article 6(1)(f). This requires a documented Legitimate Interests Assessment (LIA) — a written record of what you are doing, why it is necessary for your business, and why it does not override the customer's rights.
For a small business, the LIA does not need to be a legal document written by a solicitor. It needs to exist, in writing, and say something like: "We log enquiries to respond promptly, track which customers need follow-up, and improve our service. We process only the data needed for these purposes and do not share it externally."
Special category data: the trap to watch
Conversational data frequently contains information that triggers a higher standard of protection under Article 9 of the UK GDPR.
In clinics and salons, customers routinely share health information (skin conditions, medical histories, treatment preferences). In tuition centres and swim schools, parents share detailed information about minor children (age, learning needs, sometimes medical conditions like asthma or anxiety).
For health data and other Article 9 special-category data, standard Legitimate Interests alone is not enough. The business must identify an Article 9 condition; explicit consent is one possible condition, not an automatic requirement (ICO lawful basis guidance; Data Protection Network, 2026). Children's personal data is not automatically special-category data, but it still needs careful, age-appropriate handling.
In practice, this means: if your enquiry tracking system captures WhatsApp messages that reveal a client's medical condition or other Article 9 data, you need an appropriate Article 9 condition before that data enters your pipeline. A message about a child is not automatically special-category data, but an automated system that processes sensitive incoming messages without distinguishing the risks is a compliance concern.
What you must tell your customers
The UK GDPR requires transparency about what you do with personal data. If you track enquiries — manually or through software — your privacy policy must state:
- That you log incoming messages and calls for the purpose of responding to enquiries and managing your service.
- What specific data you collect (name, contact details, enquiry content, dates).
- How long you retain it.
- That customers can object to this processing or request deletion of their data.
This is a privacy policy update, not a consent gate. Under Legitimate Interests, you do not need the customer's permission to log their enquiry. You do need to tell them that you are doing it and give them a way to object.
Right to Object and Right to Erasure
If a customer asks you to stop processing their data or to delete what you hold, you must assess and respond under the applicable UK GDPR right. The Right to Object and Right to Erasure can apply to pipeline data, but neither is absolute in every circumstance.
In practical terms: if someone messages "delete my data" or "I don't want you to keep my details," your system — whether manual or automated — needs to flag that request, assess it promptly, stop processing where required, and delete or anonymise the stored information when the right applies.
The DUAA codifies that Subject Access Request response clocks stop during active clarification windows, which gives businesses a practical buffer when requests are ambiguous.
Third-party software: the DPA requirement
If a CRM, messaging platform, or cloud-based tool processes customer enquiry data on your behalf, the UK GDPR requires a written controller-processor contract, commonly called a Data Processing Agreement (DPA).
Check the provider's terms and contract for how it uses the data, including whether it is used to train AI models or shared beyond the purposes you have authorised. Put any required restrictions in writing.
ICO enforcement under the DUAA
The DUAA expanded the ICO's investigatory powers. The regulator can now issue Interview Notices, compelling a person who works or has worked for an organisation under investigation to attend an interview and answer questions. It can also require an organisation to nominate an approved person to prepare a report on a specified matter, with the organisation paying that person's costs (Clifford Chance analysis, 2026; Crowell & Moring analysis, 2026).
For a small business, the practical takeaway is: document your lawful basis, update your privacy policy, and handle rights requests. The bar is not high, but it does exist.
Frequently Asked Questions
Do I need consent to track customer enquiries?
Not usually for basic enquiry tracking. Standard Legitimate Interests (Article 6(1)(f)) may cover logging names, contact details, and enquiry content for the purpose of responding and managing your service. You do need a documented Legitimate Interests Assessment and a privacy policy that explains what you do. For special-category data, you need both an Article 6 lawful basis and an Article 9 condition; explicit consent is one possible condition. Children's data is not automatically special-category data.
Does the new Recognised Legitimate Interests basis apply to my CRM?
No. Recognised Legitimate Interests under the DUAA covers specific public interest scenarios (safeguarding, emergencies, crime prevention). Commercial pipeline tracking and marketing still require the standard Legitimate Interests pathway with a documented LIA.
What if a customer asks me to delete their data?
You must assess the request and comply where the right applies and no exemption or overriding ground permits continued processing. Flag the record, restrict processing where required, and delete or anonymise the stored data when appropriate. This applies whether you use a CRM, a spreadsheet, or any other method. The DUAA allows you to pause the response clock if the request needs clarification.
Conciergr answers your enquiries in seconds, around the clock, from documents you own — and your team keeps using WhatsApp exactly as before.
Join the waitlist