Data protection & GDPR
Data protection you can verify
ANPR only earns its place on your site if it's handled properly. Here's exactly how we collect, use, and protect data, and how to ask us about it.
Isn't this just surveillance?
It's a fair question, and one we'd rather answer up front than have you ask later. ANPR cameras are focused on vehicle number plates, and every record we hold exists for a specific, documented purpose: enforcement, safeguarding, or dispute evidence. Nothing is collected "just in case."
We've built ReadyPark around UK GDPR and the Data Protection Act 2018 from the ground up. That means a documented lawful basis for every use of data, minimisation by design, defined retention periods that actually get enforced, and a clear route for anyone to exercise their rights.
How we handle your data
The three principles everything else on this page is built on.
Lawful basis
Each site's ANPR use is registered against a specific lawful basis, typically legitimate interests for enforcement and site safety, assessed and documented before go-live. Where we act as your processor, this is set out in our Article 28 Data Processing Agreement, signed as part of onboarding.
Data minimisation
We capture number plates and timestamped entry/exit images, rather than running continuous video across the site. These images are taken at the point of entry and exit and may incidentally include people or other vehicles in view of the camera. Whitelisted vehicles (staff, residents, regular visitors) generate minimal records once recognised, so routine, authorised traffic isn't logged in the same detail as an enforcement event.
Defined retention
Routine ANPR images are held for a fixed retention window and then automatically deleted. Records only remain beyond that where they're needed as active evidence (for example a live Parking Charge appeal or an ongoing incident investigation), and are deleted once that purpose ends.
Documentation
The paperwork most operators in this sector can't show you
Any landowner is entitled to see how their data protection obligations are being met by a supplier acting on their behalf. We keep this documentation current and available on request, reviewing it regularly rather than leaving it to go stale.
Ask us for our documentationArticle 28 DPA
A signed data processing agreement setting out exactly what we do with your site's data as processor, and what stays your responsibility as controller.
Breach response procedure
A documented process for identifying, containing, and reporting a personal data breach, including notification timelines to controllers and the ICO where required.
ICO registration
Registered with the Information Commissioner's Office as required for an organisation processing personal data of this kind. Registration reference: ZC200905.
Who's responsible for what
You, as controller
You decide why and how your site's data is processed, for example, agreeing your site's enforcement policy and whitelist rules. You remain the point of contact for individuals wanting to exercise their data protection rights in relation to your site.
ReadyPark, as processor
We process data only on your documented instructions, under the terms of our Article 28 DPA: operating the cameras, running the platform, applying retention rules, and supporting you in responding to any request or incident.
If someone asks what we hold on them
Anyone can submit a subject access request. Here's what happens.
Request received
Requests can be made to the site's landowner, or directly to us, and are logged and verified against the individual's identity.
We search our records
We locate any personal data we hold relating to the individual: ANPR records, permit or whitelist entries, and any related enforcement or appeal history.
We respond within statutory timescales
We provide the information required under UK GDPR within one calendar month, keeping the controller informed throughout.
Have a question we haven't covered?