Compliance · 8 min read · 30 March 2026
UK GDPR checklist for holiday and caravan parks (2026 update)
Parks collect a lot of personal data — guests, owners, staff, CCTV. A practical UK GDPR checklist with the controls the ICO actually looks at, and how modern park software helps you cover them.
Want a tailored number for your park?
Get a pricing estimate instantly, then decide if a walkthrough makes sense.
Holiday parks process more personal data than most operators realise. Guest names, addresses, payment details, vehicle registrations, owner financial records, staff records, CCTV footage. UK GDPR applies to all of it. This checklist covers the controls UK parks should have in place.
This article is informational. It is not legal advice. For an authoritative position, consult a qualified data protection professional or the ICO directly.
The 12-point UK GDPR checklist for parks
- Registered with the ICO as a data controller. £40-£60 a year for most parks. Failing to register is itself a breach.
- Privacy notice on your website explaining what you collect, why, how long you keep it, and who you share it with.
- Privacy notice for owners covering the additional data you hold for caravan and lodge owners.
- Lawful basis documented for each processing activity (contract, legitimate interest, consent, legal obligation).
- CCTV signage at every camera and an internal CCTV policy with retention periods.
- ANPR / vehicle registration — usually legitimate interest, but document the assessment.
- Subject access request process — you must respond within one calendar month.
- Data retention schedule — what gets deleted and when. Bookings, owner records, staff records, marketing lists.
- Marketing consent for guest emails and SMS. Opt-in, with a clear unsubscribe.
- Data processing agreements with every vendor that touches personal data — your booking platform, payment processor, marketing tool, accountancy software.
- Breach notification process — you must notify the ICO within 72 hours of becoming aware of a notifiable breach.
- Staff training on data handling, refreshed annually.
What modern park software should do for you
A reasonable platform should help you cover items 4, 7, 8, 10 and 11 without you building anything custom:
- Lawful basis fields on guest and owner records
- One-click subject access export for any guest or owner
- Configurable retention windows with auto-purge
- DPA published and signed as part of the standard contract
- Audit log of who accessed what data, exportable for breach notification
If your current platform can't do these, you're carrying compliance risk that the platform should be carrying for you.
Where ParkSphere helps
ParkSphere is hosted in UK regions, ships a published DPA, exposes one-click subject access export, supports configurable retention per data type, and includes an audit log on every personal-data-touching action. We're working toward formal Cyber Essentials and ISO 27001 certification for ParkSphere itself in 2026.
Specific compliance questions? Email us — we'll send you the DPA template and our hosting attestation.
See ParkSphere on your park's real layout.
30-minute demo. No slides. We'll reply within one working day.
More articles
How to choose holiday park software in 2026 (without getting locked in)
A practical, vendor-neutral guide to evaluating holiday park management platforms. The 11 questions that matter, the 4 red flags to walk away from, and how to think about total cost of ownership.
Read article →Online booking engine vs channel manager: which does your park actually need?
Park owners often confuse the two — and end up either paying for both or for neither. A clear breakdown of what each does, when you need each, and when an all-in-one is the right call.
Read article →What guests actually want from a holiday park app in 2026
What guests actually praise in reviews when a park has a good app, the features they ignore, and the ones that reliably trigger complaints when they're missing.
Read article →