Understanding GDPR VAT Number Personal Data Classification

If you run a business that processes VAT numbers for credit checks, supplier verification, or customer onboarding, you've likely asked yourself: is a VAT number personal data under GDPR? The answer is more nuanced than a simple yes or no, and getting it wrong could expose your organisation to regulatory risk or unnecessary compliance burdens.

For SMEs operating across the EU, understanding whether GDPR VAT number personal data rules apply to your daily operations is crucial. This question becomes particularly important when you're using platforms like VerigoPay to verify supplier solvency or assess customer creditworthiness in real time across France, Belgium, and other EU markets.

In this article, we'll examine the legal framework, explore the special case of sole traders, review recent guidance from the European Data Protection Board (EDPB), and discuss the practical implications for businesses using credit scoring and verification tools.

What Does GDPR Consider Personal Data?

Under Article 4(1) of the General Data Protection Regulation (GDPR), personal data is defined as any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, or online identifier.

The key phrase here is "relating to an identified or identifiable natural person." This means that data about companies, as legal entities separate from individuals, generally falls outside GDPR's scope. However, the distinction becomes blurred when dealing with certain business structures.

The Corporate Veil: Limited Companies vs Sole Traders

For limited companies registered at Companies House (UK), the Companies Registration Office (Ireland), or the Registre du Commerce et des Sociétés (Luxembourg), the VAT number is assigned to the legal entity itself. The company has a separate legal personality from its directors and shareholders. In these cases, the VAT number clearly relates to the company, not to a natural person.

However, sole traders present a different scenario entirely. A sole trader is not a separate legal entity; the business and the individual are legally one and the same. When you process a sole trader's VAT number, you're processing an identifier that relates directly to an identifiable natural person.

Business Data That May Identify Individuals

Even when dealing with corporate entities, certain business information can constitute personal data if it identifies natural persons:

The European Court of Justice has consistently held that the context and purpose of data processing matter when determining whether information constitutes personal data.

Is a VAT Number Personal Data for Sole Traders?

The short answer is yes: when a VAT number belongs to a sole trader, it typically qualifies as personal data under GDPR. This is because the VAT registration is in the individual's name, and the number serves as a direct identifier of that natural person in their business capacity.

In the UK, for example, a sole trader's VAT number is linked to their personal National Insurance number in HMRC's systems. In France, auto-entrepreneurs receive a SIRET number that similarly identifies the individual. In Belgium, the KBO/BCE number for a sole proprietorship (eenmanszaak/entreprise individuelle) relates directly to the natural person operating the business.

The EDPB Position on Business Data

The European Data Protection Board (EDPB), which provides authoritative guidance on GDPR interpretation, addressed related questions in its 2023 guidance materials. While the EDPB has not issued a standalone opinion exclusively on VAT numbers, its doctrine on business contact information provides relevant principles.

The EDPB has clarified that information used in a professional context can still constitute personal data if it relates to an identifiable individual. The fact that data is used for business purposes does not automatically exclude it from GDPR's scope. What matters is whether the information relates to a natural person, not whether that person is acting in a professional or private capacity.

This interpretation has significant implications for B2B data processing, challenging the common assumption that "business-to-business means GDPR doesn't apply."

National Variations Across the EU

Different EU member states have varying business structures and registration systems, which affects how VAT numbers relate to individuals:

CountrySole Trader StructureIdentifier TypePersonal Data?
United KingdomSole traderVAT number (GB + 9 digits)Yes
IrelandSole traderVAT number (IE + 8 digits)Yes
FranceEntreprise individuelle / Auto-entrepreneurSIRET / VAT (FR + 11 digits)Yes
BelgiumEenmanszaak / Entreprise individuelleKBO/BCE numberYes
NetherlandsEenmanszaakBTW-nummerYes
GermanyEinzelunternehmenUSt-IdNr.Yes

For limited companies, partnerships with separate legal personality, and other corporate structures, the VAT number generally does not constitute personal data because it identifies the legal entity rather than an individual.

Practical Implications for Credit Scoring and Verification Tools

If you're using solvency verification tools, credit scoring platforms, or supplier onboarding systems that process VAT numbers, understanding the GDPR VAT number personal data distinction has real operational consequences.

When GDPR Compliance Is Required

When your business processes VAT numbers that may belong to sole traders, you must ensure:

Many businesses mistakenly believe that B2B transactions fall entirely outside GDPR. This is incorrect. While GDPR provides certain exemptions for purely corporate data, any processing that involves identifiable natural persons—including sole traders—requires compliance.

Legitimate Interests for B2B Verification

For most credit checking and solvency verification purposes, the appropriate legal basis is "legitimate interests" under Article 6(1)(f) GDPR. Businesses have a recognised legitimate interest in assessing the financial stability of potential customers and suppliers to protect themselves from commercial risk.

However, you must still conduct a legitimate interests assessment (LIA) that balances your business needs against the rights and freedoms of the individuals whose data you process. This assessment should consider:

In the B2B context, sole traders generally have a reasonable expectation that their business identifiers will be verified by potential commercial partners. This supports the legitimacy of processing, provided it's proportionate and transparent.

Impact on Automated Decision-Making and Profiling

Article 22 GDPR restricts automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals. If your credit scoring system automatically rejects sole traders based on algorithmic assessment of their VAT number and associated data, this could trigger Article 22 protections.

To comply, you should either:

Platforms like VerigoPay's pricing tiers are designed with compliance in mind, providing transparency about how verification decisions are made and offering appropriate safeguards for data subjects.

GDPR VAT Number Personal Data: Cross-Border Considerations

For businesses operating across multiple EU markets, the GDPR VAT number personal data question becomes more complex due to varying business structures and supervisory authority interpretations.

The Corporate Seat Directive and CSDDD

The Corporate Sustainability Due Diligence Directive (CSDDD), while primarily focused on environmental and human rights due diligence, reinforces the importance of proper supplier verification. Companies subject to CSDDD must identify their business partners throughout the supply chain, which necessarily involves processing business identifiers including VAT numbers.

This creates an interesting intersection: businesses have regulatory obligations to verify suppliers, but must do so in a GDPR-compliant manner when those suppliers are sole traders or other structures where identifiers constitute personal data.

Data Transfers and Third-Country Access

If you're using verification tools that transfer VAT numbers outside the EU—for example, to cloud servers in the United States or United Kingdom (post-Brexit)—you must ensure appropriate transfer mechanisms are in place under Chapter V GDPR. This applies even to "business data" when it relates to identifiable individuals.

Standard Contractual Clauses (SCCs) or adequacy decisions provide the legal framework for such transfers, but many businesses overlook this requirement for B2B data, creating compliance gaps.

Best Practices for Compliant VAT Number Processing

To process VAT numbers in a GDPR-compliant manner while maintaining efficient business operations, consider these practical steps:

Implement a Tiered Approach

Not all VAT numbers carry the same privacy implications. Develop processes that distinguish between:

  1. Corporate entities: Limited companies, PLCs, SARLs, GmbHs, and other structures with separate legal personality—lower privacy risk
  2. Sole traders and partnerships: Structures where the VAT number relates to identifiable individuals—full GDPR compliance required
  3. Uncertain cases: When business structure isn't immediately clear—apply GDPR safeguards as a precaution

Update Your Privacy Documentation

Ensure your privacy notice explicitly addresses:

Train Your Teams

Sales, finance, and procurement teams who handle supplier and customer onboarding should understand:

Choose Compliant Verification Tools

When selecting credit checking and solvency verification platforms, evaluate their GDPR compliance features:

VerigoPay is built with these compliance requirements in mind, providing real-time solvency verification across EU markets while maintaining GDPR standards for all processed data, including VAT numbers belonging to sole traders.

Conclusion: Navigating the Grey Areas

The question "is a VAT number personal data under GDPR?" doesn't have a universal answer. For limited companies and other corporate entities with separate legal personality, VAT numbers generally fall outside GDPR's scope. For sole traders and similar structures, the VAT number clearly constitutes personal data because it identifies a natural person.

The 2023 EDPB guidance reinforces that business context doesn't automatically exclude data from GDPR protection. What matters is whether information relates to an identifiable individual, regardless of whether they're acting in a professional capacity.

For SMEs operating across EU markets, the practical approach is to assume GDPR applies to VAT number processing unless you can clearly establish that you're dealing exclusively with corporate entities. This precautionary stance ensures compliance while allowing efficient business operations.

By understanding these nuances, implementing appropriate safeguards, and choosing compliant verification tools, you can confidently assess supplier and customer solvency across France, Belgium, and the broader EU market while respecting data protection obligations. The intersection of commercial necessity and privacy protection need not be a barrier—with proper processes, it becomes simply another aspect of professional business practice.