← Back to blog

GDPR for dog fields: a plain-English guide for UK field owners

6th August 2026
GDPR for dog fields: a plain-English guide for UK field owners

You may think GDPR is something only big corporations need to worry about, but that isn’t the case. The moment you took your first booking, you started holding personal data – names, phone numbers, perhaps even CCTV. That makes you a data controller.

Don’t panic, though. For a typical one- or two-field operation this isn’t a big or complicated project, just an afternoon of admin. Here’s what applies to you, what changed in 2026, and the common ways small fields get caught out.

Please note, this is general guidance, not legal advice. The ICO helpline (0303 123 1113) is free and good with small businesses.

Yes, it does apply to you

There’s no exemption for being a small business, a sole trader, or running the field alongside a primary business. If you’re taking bookings, you’re processing personal data – whether that’s through a booking system or via Facebook Messenger and a paper diary.

You’re probably storing more than you think: names, contact details, addresses, booking history and CCTV footage. Perhaps vehicle registrations too, or occasionally health and disability information where a customer has particular access requirements. That last one is special category data and needs extra care.

Register with the ICO

Most businesses that process personal data electronically must pay the ICO’s annual data protection fee. Running CCTV for security is one trigger; keeping any computerised customer list is another.

For dog fields this is usually tier 1: £52 a year, or £47 by direct debit (correct at the time of writing in August 2026). You can check which tier applies using the ICO’s free self-assessment tool, which only takes a couple of minutes. Not paying comes with fixed penalties that can run into the thousands, so it really isn’t worth the gamble.

New for 2026: you need a complaints process

This is the one most likely to catch small businesses out, as it only came into force on 19 June 2026. Every organisation handling personal data, regardless of size, must now have a data protection complaints process.

People need a clear way to complain to you directly. You must acknowledge the complaint within 30 days, investigate it without unnecessary delay, and tell them the outcome. Mention this in your privacy notice alongside their right to complain to the ICO.

In most cases it’s a short paragraph explaining how to complain and acknowledging the 30-day clock, but it is now a legal requirement.

Lawful basis – what it means in practice

Three lawful bases cover almost everything you do:

  • Contract – you need a name, contact details and payment to deliver the booking. This covers your core operation.
  • Legitimate interests – CCTV for security, for example, or using contact details to tell someone about a gate fault. Make a note of why your interest doesn’t override their privacy.
  • Consent – required for marketing communications such as emails and texts. It must be freely given and easy to withdraw.

A good example: being given an email address so you can send gate codes and booking information is not permission to add that person to your newsletter.

Marketing: a common slip

It’s surprisingly common to assume that email addresses collected at the time of booking can be exported straight into a mailing list – they’re already customers, after all. In practice, you need consent to send marketing emails or texts. There’s a very narrow “soft opt-in” for existing customers, but even then a clear opt-out must be offered when you collect their details and in every message afterwards. Every message needs a working unsubscribe.

The simplest way to handle this is a clearly worded, unticked opt-in box at the point of booking. A smaller but genuinely interested audience is better anyway.

CCTV

Cameras are fine, and understandable. But there are a few things to consider:

  • Signage is compulsory – you need to say who is recording and why.
  • Only cover what you need – cameras should point at your land, not a neighbour’s or a public footpath.
  • Set a retention period – 14 to 30 days is common, followed by automatic overwrite.
  • Never share footage on social media – posting CCTV clips to shame disrespectful customers has become something of a trend, whether that’s people being rude to staff or leaving without paying, and we understand the temptation. But publishing identifiable footage of a customer for a purpose they never agreed to is good grounds for an ICO complaint.

People also have the right to ask for footage of themselves, so you need to be able to retrieve it while protecting anyone else in shot.

Requests and risk

Anyone can ask what data you hold on them, and you must answer free of charge, usually within a month. They can also ask you to delete it. You won’t necessarily have to, but you must consider the request properly.

There’s no fixed retention period for booking records, but the principle is that you shouldn’t keep personal data for longer than you need it. Tax is usually the deciding factor: sole traders and partnerships need to keep business records for at least five years after the 31 January Self Assessment deadline for the relevant tax year, while limited companies must keep theirs for at least six years from the end of the financial year they relate to. Set a period that covers your obligations, write it down, and delete anything older.

It’s unlikely you’d face regulatory action as a dog field, but practical problems are far more likely. Common ones include bookings run through WhatsApp, leaving customers’ numbers on your personal phone; customer spreadsheets on shared laptops; and several people sharing one admin login, which leaves them all able to see sensitive information about clients. If data is lost or exposed in a way that puts people at risk, you’ll usually need to tell the ICO within 72 hours – something you can’t do if you don’t know it’s happened.

A useful checklist

  • Check and pay the ICO fee
  • Publish a privacy notice – what you collect, why, how long you keep it, and who you share it with
  • Add your complaints route to it, with a working contact address
  • Note your lawful basis for bookings, CCTV and marketing
  • Add a separate, unticked marketing opt-in at booking
  • Put up CCTV signage and set a retention period
  • Decide how long you keep booking records, and delete anything beyond that
  • Get customer data off personal phones and loose spreadsheets
  • Give anyone who helps you their own login and appropriate access rights

This list doesn’t cover every scenario, but it’s a good place to begin.

How a booking system helps

Most of the items above are much easier to handle when all your customer data sits in the same place, and a booking system is the best way to do that.

With Muddy Booking you remain the data controller – it’s your business and your customer relationship. We act as your processor, handling storage and security under a written agreement. In practice, that means bookings sit in one system with proper access controls rather than scattered across your phone, your privacy notice is easy to make accessible to customers, and gate codes are issued automatically instead of messaged out by hand. (More on what manual bookings really cost you.)

It won’t make you compliant on its own – you still need the fee, the notice and the complaints route. But it removes many of the places small operators come unstuck.

See how Muddy Booking works →

Frequently asked questions

Do I need to register with the ICO to run a dog field? Most likely yes. If you take bookings electronically or run CCTV, you’ll usually need to pay the annual fee – £52, or £47 by Direct Debit at the time of writing. The ICO’s free self-assessment confirms which tier applies to you.

Can I put my dog field CCTV footage on Facebook? No. Publishing identifiable footage of a customer for a purpose they never agreed to is a clear data protection problem, however frustrating their behaviour.

Can I email past customers about offers? Only if they’ve opted in, or fall within the narrow soft opt-in for existing customers – and every message needs a working unsubscribe.

How long should I keep booking records? There’s no fixed period under data protection law, so tax rules usually decide it: five years after the relevant Self Assessment deadline for sole traders and partnerships, or six years from the end of the financial year for limited companies. Write the policy down and follow it.

Does GDPR apply if I only take bookings by WhatsApp? Yes. The law follows the data, not the tool – and informal channels usually make compliance harder.

What is the new complaints requirement? Since 19 June 2026, all organisations must offer a clear route to complain directly, acknowledge within 30 days, investigate, and report the outcome. There’s no small business exemption.