Hours-of-Service and Trip Records: How Long to Keep Fleet Tracking Data

Jul 23, 2026

Every fleet keeps data longer than it needs to or shorter than it should. How long the data actually has to stay depends on what kind of data it is, not on how much server space the company is paying for.

Definition: A retention period is the amount of time a particular category of fleet data has to be kept on file before anybody is allowed to delete it. The periods differ from one category to the next, and what sets them is a mix of regulation, operational need, and privacy law rather than any one rule that covers the whole lot.

Key Takeaways

  • Fleet tracking data does not come with one retention period that covers everything. Location data, driver behaviour data, tachograph downloads, and IFTA records each sit under their own rule, and the rules come from different regulators.
  • In the EU, tachograph data for goods and passenger transport vehicles must be retained for at least 12 months by the operator, with drivers required to produce 56 days of records at roadside inspections on international journeys. [1]
  • Drivers operating in the EU must be able to show records for the current day and the previous 28 days (or 56 days on international journeys) at roadside inspections. [2]
  • In the US, IFTA fuel and distance records must be kept for four years from the quarterly return’s due date or filing date, whichever is later, and federal hours-of-service supporting documents must be kept for six months.
  • GDPR does not set a number. What it says is that location data and driver behaviour data should only be kept for as long as the operational purpose behind the collection still exists, and that holding it indefinitely without a reason is not lawful.
  • What the platform is actually doing with the data matters as much as what the policy document says. When a platform holds onto data forever because nobody went into the settings and changed the default, then forever is what the retention period actually is, no matter what the privacy notice told the drivers.
Table of Contents
  1. The four data categories and what governs each
  2. EU tachograph retention: 12 months minimum, 56 days on the road
  3. Hours-of-service in the US: six months for supporting documents
  4. IFTA: four years from the later of due date or filing date
  5. GDPR retention on the operational data
  6. When the rules conflict and how to resolve it
  7. Retention is a platform setting, not just a policy
  8. 5 retention mistakes that come back around
  9. Frequently asked questions
  10. The Bottom Line

An operator has been keeping two years of trip history on the platform and two months worth of tachograph downloads, and during an inspection it comes out that the legal minimum for each runs in the opposite direction. The trip history has been sitting on the server far longer than any operational purpose would justify, and that is a GDPR problem. The tachograph data is ten months short of the 12 month minimum, which is a compliance problem. Buying more storage does not fix either one. The thing that fixes it is a retention policy where each data category is matched to the specific rule that actually applies to it.

What this guide covers is the retention rules that matter most to fleet operators, the categories the data falls into, and the platform configuration work that turns retention from a quarterly task somebody has to remember into something the system handles by itself.

The four data categories and what governs each

The data a fleet tracking system produces falls into four broad categories. The rules that govern each one come from a different source, which is the reason a single retention period set across the whole platform is always going to get at least one of the categories wrong.

Data category What it is Retention driver
Location and trip dataGPS coordinates, routes, stops, geofence eventsOperational use + GDPR data minimisation
Driver behaviour dataHarsh braking, acceleration, scorecards, speeding eventsHR cycles + GDPR data minimisation
Tachograph and HOS dataEU driver activity, breaks, rest periods, work timeEU/national tachograph regulations
Tax and compliance recordsIFTA mileage, fuel purchases, ELD logsFiscal and transport regulations

The categories do not substitute for each other. A retention policy that applies the same period to location data and tachograph data is going to be wrong on at least one of them, and which one it gets wrong depends on which direction the error runs.

EU tachograph retention: 12 months minimum, 56 days on the road

Goods transport vehicles over 3.5 tonnes and passenger transport vehicles carrying more than nine people are required under EU law to operate with a tachograph recording driving time, breaks, rest periods, and other work activities. [3] The operators of those vehicles carry two separate retention obligations, and the two run on different timelines.

The first obligation sits with the operator. Tachograph records have to be downloaded from the vehicle unit and from the driver card at regular intervals, and the downloaded data has to be stored securely for a minimum of 12 months. The storage has to protect what is on it from being accessed or changed by anybody who should not have access to it. [1] The 12 month figure is the legal floor. In practice, most operators end up holding the data for somewhere between two and three years, on the basis that inspection requests, employment disputes, and incident investigations have a way of surfacing well after the 12 month mark.

The second obligation is the one that applies to the driver personally, and it comes into play at roadside inspections. A driver operating within the EU has to be able to show records for the current day and the previous 28 days. For drivers on international journeys, the 2025 update to the AETR rules pushed that number to 56 days. [4] The records can come from the driver card itself, from a printout the driver carries, or from downloaded data stored on a device in the cab. The source does not matter as long as the records are there and readable. [2]

The download schedule is part of the obligation, not a suggestion sitting alongside it. The expectation is that operators pull data from the vehicle unit at least once every 90 days and from the driver card at least once every 28 days. When the schedule slips, the risk goes beyond a finding at the next audit. The driver card has limited memory, and once that memory fills up, the oldest records get overwritten. Once data has been lost to an overwrite, the operator has no way of producing it again, and that gap in the records is not something that can be filled after the fact.

Retention periods at a glance (bars on a 48 month scale)
Live location data
30 to 90 days
US HOS supporting documents
6 months
Driver behaviour data
12 months
EU tachograph data (operator)
12 months minimum
Trip history
12 to 24 months
IFTA fuel and distance records
4 years
Fleet sets and discloses
Regulatory minimum
Maintenance and fuel data sits outside the chart: retained for the life of the vehicle in the fleet. Blue periods are ceilings the fleet chooses; amber periods are floors set by law.

Hours-of-service in the US: six months for supporting documents

The FMCSA hours-of-service rules in the US apply to drivers of commercial motor vehicles. The retention requirements that come with those rules are shorter than most fleet operators would guess.

Carriers have to keep HOS supporting documents and ELD records for six months, counted from the date the carrier received them. What counts as a supporting document includes records of duty status, fuel receipts, toll receipts, dispatch records, and any other paperwork the carrier relies on to confirm that the hours a driver reported match the hours the driver actually worked. Six months is not long, but the rule applies specifically to the HOS supporting documents. The business records that sit behind the supporting documents, payroll records and fuel card statements. For example, tend to have their own separate retention periods set by other parts of the law, and those periods are usually longer than six months.

The ELD itself also has to hold at least six months of records, either on the device or in whatever back office system the device feeds into. Those records have to be transferable on demand to any authorised safety official who asks.

IFTA: four years from the later of due date or filing date

Fleets that operate across multiple US and Canadian jurisdictions and file quarterly fuel tax returns under the International Fuel Tax Agreement are subject to a uniform retention rule across all IFTA member jurisdictions.

The rule is four years, counted from either the due date of the quarterly return or the date the return was actually filed, whichever of the two came later. A fleet that files its return late ends up extending its own retention window, because the four year clock does not begin running until the return has actually been submitted. The records have to be producible on request. Paper, scanned, or electronic form all qualify, and the request can come from the base jurisdiction or from any IFTA member jurisdiction.

For fleets that generate their IFTA reports from telematics data, the practical consequence is that the GPS trip data and the fuel purchase data sitting underneath those reports both fall under the four year obligation. If somebody reads the GDPR storage limitation principle as a reason to purge the trip data at six months, and then four years later an auditor asks the fleet to produce the records behind an IFTA mileage figure, the fleet has a documentation gap that is not going to be straightforward to close.

The way to handle the overlap between the two obligations is to recognise that trip data being used for IFTA reporting sits under tax law in addition to sitting under privacy law. GDPR allows retention for as long as a legal obligation the controller is subject to requires it, and the IFTA four year obligation is exactly that kind of legal obligation.

GDPR retention on the operational data

For any fleet data that does not fall under a specific regulatory retention period, GDPR’s storage limitation principle is what governs. The principle says personal data should not be kept any longer than the purpose it was originally collected for requires, and the retention period has to be defined in advance and disclosed to the people whose data it is.

In practice, the periods that have survived regulator review on the operational side of fleet tracking look like this:

  • Live location and recent trip history: 30 to 90 days. That window is long enough for most customer queries and delivery disputes to be settled, and short enough that the data does not start looking like driver surveillance.
  • Older trip history: 12 to 24 months. Fleets that go to the upper end of that range generally defend it by pointing out that regulatory or contractual disputes can take up to two years to surface, and that once the underlying trip data has been deleted, there is no way to get it back.
  • Driver behaviour data: 12 months. The 12 month figure lines up with a typical annual performance review. Scorecards that summarise the data at a monthly level can stay on the platform longer than the raw event records, because the scorecard is aggregated and it is the raw data, not the summary, that identifies the individual driver.
  • Maintenance and fuel data: For the full period the fleet operates the vehicle, with a short tail after the vehicle leaves the fleet to cover warranty and tax matters. This kind of vehicle data is generally not considered personal data in the way driver data is, and that distinction makes it easier to justify a longer retention period.
  • Compliance and tax data: Whatever the applicable regulation says. 12 months for tachograph data, four years for IFTA, six months for US HOS supporting documents, and longer for general business records in most countries.

The practical approach is to set each period at the lower end of what the business can justify needing, write down the reasoning behind that number, and then make sure the platform is set up to enforce the deletion when the period expires. If the privacy notice says 24 months but the platform never actually deletes anything when the 24 months are up, then what the fleet has, in the eyes of a regulator, is indefinite retention.

Example: A logistics company puts together a tiered retention policy. Live location data leaves the platform after 30 days. Trip history stays for 18 months. Driver behaviour data is summarised into monthly scorecards after 90 days, with the raw event data deleted at that point. Tachograph data is held for 24 months. IFTA-relevant data on US operations is held for four years. The policy gets written into the privacy notice, the platform gets configured to match it, and once a year somebody goes in and checks that the deletions are actually happening the way they should be.

Example: A passenger transport company running international routes across the EU downloads driver cards every 28 days and vehicle units every 90 days. The tachograph data goes into encrypted storage and stays there for 24 months. Once a year, somebody audits the platform’s stored records against what the retention schedule says should still be on file. A roadside inspection in Belgium asks for the past 56 days of records for one of the drivers. The data is on the card, on the platform, and in the archive, sitting in three places and available from any of them.

Example: A small fleet with five vans and no compliance obligations beyond the usual business records sets one retention period of 12 months covering trip data and behaviour data, writes it into the privacy notice, turns on the platform’s auto delete function, and comes back once a year to check that the settings are still doing what they should. The entire retention programme takes less than an hour of work per year to maintain.

When the rules conflict and how to resolve it

The conflict that fleet operators run into most often is between GDPR’s data minimisation principle, which pushes in the direction of shorter retention, and the longer holding periods that tax law, transport law, or employment law impose on specific categories of data. Resolving it is not a matter of picking one obligation over the other. What makes it work is recognising that the regulatory retention obligation creates a lawful basis of its own for holding onto the data, and that basis stands apart from the operational basis that justified collecting the data in the first place.

For each category of data, the questions to work through are:

  1. Does a regulation set a minimum retention period for this data? If it does, that minimum applies regardless of anything else. GDPR’s general preference for shorter retention does not override a specific legal obligation to keep the data longer.
  2. Is the data still being used for an active operational purpose? If it is, the operational retention period applies, and the data stays.
  3. Could the data be needed to defend a legal claim? Litigation holds and dispute windows can push the retention period out on specific records, but they do not extend retention across the entire data set.
  4. If none of the above, is the data still useful? If no, the data goes.
Interactive: should this data category be kept or deleted?
1
Is there a regulatory minimum retention period?
Tachograph: 12 months. IFTA: 4 years. US HOS: 6 months. If yes, that minimum binds regardless of GDPR. Keep → regulatory period
2
Is the data still serving an active operational purpose?
Customer queries, dispatch, performance reviews. If the purpose is still live, the operational retention period applies. Keep → operational period
3
Could the data be needed to defend a legal claim?
Litigation holds and dispute windows extend retention on specific records, but not on the entire data set. Keep → dispute window
4
None of the above?
The data has no regulatory floor, no operational use, and no litigation hold. Delete

The platform configuration has to follow the same logic. A platform that keeps everything for the longest period that applies to any data category in the fleet, rather than keeping each category for its own appropriate period, is not GDPR compliant. That is true even if every individual retention number the fleet chose is defensible on its own.

Retention is a platform setting, not just a policy

The two ways retention most commonly fails in practice are platforms that hold data forever because nobody changed the default, and policies that exist in a document but were never wired into the platform’s configuration.

The first one plays out like this. The platform ships with a default setting of “retain indefinitely.” The fleet manager writes a privacy notice promising drivers that trip history will be deleted after 18 months. Four years later, every trip the fleet has ever recorded is still sitting on the server. A regulator request pulls up the gap, and the company’s privacy notice turns out to have been misleading from the start.

The second failure is more subtle. The platform’s retention settings exist but are not configured. The default holds, the fleet manager thinks the policy is enforced because the policy exists, and the actual data tells a different story.

Three checks close both gaps:

  • Compare the platform’s actual retention settings, screen by screen, against the written policy. They have to match per data category.
  • Run an annual audit. Pick a random week of data from longer ago than the retention period and confirm it has actually been deleted. If it has not, the policy is fiction.
  • Document the audit. The audit log is what a regulator asks to see.

GPSWOX fleet management platforms support configurable retention settings per data category, which means the policy and the platform can be brought into line without somebody having to run a manual purge.

Interactive: tap a data category to see its retention rule
30 to 90 days
Set by fleet, governed by GDPR storage limitation
Long enough to cover customer queries and delivery disputes. Short enough that a regulator won't treat it as driver surveillance. The period goes into the privacy notice and the platform enforces the deletion.
If you keep it too long
Indefinite retention of location data is the most common finding in GDPR fleet tracking reviews. The data becomes dead weight with regulatory exposure attached.

5 retention mistakes that come back around

1. One retention period for everything

Applying a single retention rule across location data, behaviour data, tachograph data, and IFTA records is going to produce an error in at least one category. The retention policy has to be built with a separate period for each category of data.

2. Counting from the recording date for tax data

IFTA’s clock runs from the return’s due date or filing date, whichever is later. Counting from the trip date understates the retention period by months for trips that fall in the early part of a quarter.

3. Tachograph download intervals slipping

The 28 day download cadence for the driver card and the 90 day cadence for the vehicle unit are not advisory targets. Falling behind risks losing data when the card or unit memory overwrites, which is a documentation failure no longer fixable.

4. Deleting too late and trusting the platform default

On many platforms, indefinite retention is the factory default because it is the cheapest option from an engineering standpoint. Deleting too late, including not deleting at all, is one of the most common findings in regulator reviews. The configuration has to be deliberate.

5. Deleting too early on records that are also tax records

Deleting trip data at six months because privacy law says minimum retention can be short produces an IFTA documentation gap four years later. Records that double as tax records inherit the longer retention period.

Frequently asked questions

How long do I have to keep EU tachograph data?

The operator has to keep the downloaded tachograph data for a minimum of 12 months, stored securely and protected from unauthorised access. [1] Drivers on international journeys need to have the current day plus the previous 56 days of records available at any roadside inspection, with the operator downloading from the driver card every 28 days and from the vehicle unit every 90 days. [4]

How long do I have to keep IFTA records?

Four years from the quarterly return’s due date or filing date, whichever is later. Late filing extends the retention period, because the clock runs from the later date. The records must be producible on request to the base jurisdiction or any IFTA member jurisdiction.

Does GDPR set a maximum retention period?

There is no numeric maximum written into the regulation. What the regulation actually says is that personal data should not sit on the system any longer than the purpose it was originally collected for requires. [5] For a fleet, that works out to mean each data category needs its own defined retention period, and that period has to appear in the privacy notice and actually get enforced by the platform. Holding data indefinitely is not lawful unless a specific legal obligation, such as the IFTA four year rule or the tachograph 12 month minimum, requires the data to stay.

What if my fleet operates in multiple jurisdictions with different rules?

Each piece of data follows the strictest rule that applies to it. A fleet with operations in both the EU and the US would apply GDPR retention to the personal data that comes out of the European operations, US HOS retention to the American driver hours data, and IFTA retention to the American mileage and fuel records. One retention policy can cover the whole fleet, provided each data category inside that policy points to the correct rule for the jurisdiction the data came from.

Can I just delete everything every six months to keep things simple?

No, because a blanket six month deletion would violate the regulatory retention minimums on tachograph data, IFTA data, and several others. On top of that, it would leave documentation gaps in the file that turn into findings the next time an inspector or an auditor pulls the records. The retention schedule has to be broken out by data category. Trying to flatten the whole thing down to one number is what causes the problems.

The Bottom Line

There is no single retention period that works for all the data a fleet tracking system produces, and any policy that tries to use one is going to be wrong in at least one direction. The approach that holds up over time is to sort the data into its categories, figure out which rule actually governs each one, set up the platform to enforce the corresponding periods automatically, and then audit the actual deletions once a year to make sure what the platform is doing lines up with what the policy says it should be doing. A fleet that does those four things is going to be running lawful retention across the EU, the US, and whichever other regimes apply to its operations. A fleet that skips the exercise is carrying an exposure that stays open until a regulator, an auditor, or a roadside inspector turns up and finds it.

Most of the work involved is one off. The policy gets written once. The platform gets configured once. The annual audit takes a few hours. Everything else is automatic.

Article Sources

  1. GOV.UK / Driver and Vehicle Standards Agency. “Drivers’ hours and tachographs: goods vehicles — 4. Tachograph rules.” https://www.gov.uk/guidance/drivers-hours-goods-vehicles/4-tachograph-rules
  2. Fleet News. “28-Day Tachograph Warning for Drivers Entering EU.” https://www.fleetnews.co.uk/news/latest-news/2022/07/07/28-day-tachograph-warning-for-drivers-entering-eu
  3. European Commission. “Tachograph.” https://transport.ec.europa.eu/transport-modes/road/tachograph_en
  4. Trans.info. “EU Clarifies Tachograph Checks on Borders and 56-Day Records.” https://trans.info/en/eu-clarifies-tachograph-checks-464391
  5. EUR-Lex. “Regulation (EU) 2016/679 (General Data Protection Regulation).” https://eur-lex.europa.eu/eli/reg/2016/679/oj