The GDPR concerns you too
If you have a chiptuning workshop and collect customer data (name, telephone, email, VAT number, license plate, ECU file), the GDPR applies. It doesn't matter if you are a freelancer, a flat-rate VAT number or an LLC: the European privacy legislation applies to everyone since 2018.
What data do you collect
Typical for a chiptuner:
- Personal data: name, surname, address, telephone, email
- Tax data: VAT number, tax code
- Vehicle: make, model, year, VIN, license plate
- ECU files: ORI and MOD (sensitive data for vehicle modifications)
- Payments: card/account details, amounts
All personal data. All covered by GDPR.
The 5 minimum obligations
1. Privacy information
You must explain to customers, before collecting data: who you are, what you collect, why, for how long, who you pass it on to, what rights they have. 2-3 page document, downloadable from the site.
2. Explicit consent
For email marketing, profiling, sharing with third parties, active OPT-IN is required. The "I accept privacy" box must be TICKED BY HAND, never pre-ticked.
3. Treatment register
Internal document (also Excel) that lists: data types, purposes, legal basis, retention period. Mandatory if you have 250+ contacts or process sensitive data.
4. Security measures
Data encryption at rest (storage), HTTPS on site, strong passwords, regular backups. NO ECU files on shared Google Drive or WhatsApp.
5. Procedure for user requests
The customer can request: data deletion, data export, modification, blocking. You must respond within 30 days.
Sanctions
The Italian Privacy Guarantor has sanctioned in 2025:
- Workshops without privacy information: €5,000-€15,000
- Email marketing without consent: €10,000-€30,000
- Failure to register treatments (with >250 customers): €5,000-€20,000
- Unnotified data breach: €20,000-€100,000
Real sanctions, not theoretical.
Are ECU files "personal data"?
Yes, because they can be connected to a vehicle, and therefore to an owner. So:
- Encrypted storage: always
- Access only authorized personnel
- Max storage 5-10 years (further, cancellation)
- No sharing with third parties without consent
Practical checklist
- ✅ Privacy information on the site (free templates on iubenda)
- ✅ Cookie compliant banner
- ✅ Opt-in consent in registration
- ✅ Encrypted storage for ECU files
- ✅ Automatic off-site backup
- ✅ Strong passwords + 2FA where possible
- ✅ Internal procedure for user requests
- ✅ Treatment register (also basic Excel)
- ✅ Contract with the accountant as "external manager"
- ✅ Contract with the chiptuning platform supplier
The hidden advantage
A chiptuning GDPR-compliant by design platform takes away 90% of the work from you: native encryption, access logs, user procedures, consents tracked, DPA signed. You sign the contract and you are covered.
Conclusion
The GDPR is not a nuisance: it is a level of professionalism that differentiates serious workshops from improvised ones. Investing 5-10 hours of setup avoids the risk of sanctions and increases the trust of corporate customers (who ALWAYS ask for compliance before signing).
