Is It Legal to Track Company Vehicles? Consent, Privacy, and the Rules

Jul 27, 2026

Vehicle tracking is legal in most countries when the employer follows the data protection rules, though the rules tend to be stricter than most fleet operators expect going in.

Definition: A GPS tracker fitted to a company vehicle keeps producing coordinates the whole time it is running. Those coordinates identify whoever is driving, which is enough to make the data “personal data” under privacy law. The rules the fleet has to follow depend on where it operates. For fleets that operate in Europe or employ drivers there, the GDPR is the framework that applies first, and it is also the one with the most requirements attached to it.

Key Takeaways

  • GDPR draws no line between a location record and any other personal data once the record can be matched to a particular driver. Before any of that data gets processed, the fleet has to choose a lawful basis and write the choice down. Consent is technically one of the six bases available, but the employer employee power gap makes “freely given” almost impossible to demonstrate. [1]
  • “Legitimate interests” and “performance of a contract” are the two bases that hold up in practice. The documentation for whichever basis the fleet chooses has to be completed before tracking begins, because writing it up after the fact does not fix the gap. [2]
  • Every driver has to receive, in writing, a rundown of what the system collects, who can see it, how long it stays, and what rights they hold. Skipping the privacy notice does not leave the fleet somewhere in the middle of compliant and non compliant. It means the tracking programme was unlawful from the first day the devices were switched on.
  • Drivers who also use the vehicle privately need some way of switching the location feed off when the working day is over. This particular point has produced more regulator findings than any other part of fleet tracking. [3]
  • Tachograph data on EU commercial vehicles has its own retention rules: at least 12 months for the operator, with 56 days of records held on the driver card for international journeys. [4]
  • Outside the EU, the legal regime varies: the UK has its own UK GDPR, the US handles vehicle tracking mostly through state laws, and other jurisdictions land somewhere along the spectrum from “essentially unregulated” to “GDPR-equivalent.”
Table of Contents
  1. Why this is regulated at all
  2. The legal bases that actually work
  3. What “transparent” actually means
  4. The personal time question
  5. Retention: how long the data can be kept
  6. When a DPIA is required
  7. How this changes outside the EU
  8. 5 compliance mistakes that produce findings
  9. Frequently asked questions
  10. The Bottom Line

A service company has GPS trackers fitted to its twenty vans over a weekend. Nobody on the driving team is told. Four weeks later, one of the drivers notices a small box zip tied behind the dashboard trim. A privacy complaint follows. Legal advice comes back the same day, and there’s nothing ambiguous about it. Nobody had written down a lawful basis for collecting the location data. Nobody had handed the drivers a privacy notice before the devices went in. The lawful basis and the privacy notice were what was missing. The hardware was fine.

That scenario is not unusual. Vehicle tracking law is not complicated once it’s laid out, but the requirements are specific. The EU rules take up the first half of this guide. The UK, the US, and other jurisdictions come afterwards, with notes on where their local law differs from the EU approach.

Why this is regulated at all

Location data on its own is nothing more than a set of numbers, and a set of numbers with no person attached to it is not regulated. The regulation starts to apply at the point where the numbers can be connected to a person. In a fleet, some record that makes the connection already exists, a shift roster perhaps, or a driver login, or a vehicle assignment sheet, and through that record the coordinates can be matched to whoever was driving. Once the match is possible, the EU’s General Data Protection Regulation applies. The UK’s version of GDPR applies the same classification. [1] Six lawful bases exist under the regulation, and the fleet has to be operating under one of them. The processing also has to pass a necessity and proportionality test. On top of that, the driver whose data is being collected has to be told it’s happening.

A location feed that runs all day ends up saying more about how the driver spent the day than about the state of the vehicle. The log shows the address of each stop and how long the stop lasted, including a detour to the shop on the way back to the depot. The data reaches far enough into a person’s day that EU regulators have placed vehicle tracking in the high risk processing category, and the obligations that come with high risk processing are heavier than the ones attached to ordinary workplace data. [3]

GDPR lists six lawful bases for processing personal data. Three of them could in theory be applied to employee vehicle tracking. Two survive contact with an actual regulator.

Consent. It’s on the list of six, so fleets keep trying to use it. The problem is the “freely given” requirement that comes with it. A driver who gets asked by the company to sign a tracking consent form understands, even if nobody says it out loud, that saying no could carry a cost. The Irish DPC wrote about this in its 2020 guidance on employer vehicle tracking, and regulators in several other EU countries have taken the same line in their own guidance. The reasoning goes like this: a person who works for the party asking for consent is not in a position to give that consent freely, because the employment relationship stands in the way of a free choice. [2]

Legitimate interests. In practice, this is where most fleet tracking programmes land. The process starts with the employer identifying and writing down the specific interest the tracking serves. Fleet security is one. Fuel cost control is another. Customer service response times, vehicle utilisation, route compliance. After that, the employer weighs the interest against the driver’s right to privacy and writes up the conclusion. The assessment has a name. It’s called a legitimate interests assessment. It has to exist in writing, and it has to be completed before tracking starts.

Performance of a contract. The narrowest fit of the three. Where the employment contract can’t be performed without the tracking data, this basis applies. The standard example is a driver paid by driving hours, with the payroll run depending on the telematics log to verify what gets paid. [5] Not every fleet can use this basis. The ones where the employment contract genuinely depends on tracked data are the ones where it works.

The tracking vendor does not choose the lawful basis on behalf of its customers, and no platform on the market has a setting that deals with it. The decision sits with the employer, who should make it with legal input, put it in writing, and keep the paperwork somewhere it can be found. All of it has to be done before any hardware goes into any vehicle.

Interactive: tap a lawful basis to compare

Legitimate interests

In practice, this is where most fleet tracking programmes land. The employer identifies a specific interest, weighs it against the driver's right to privacy, and writes up the conclusion.

What it needs

A legitimate interests assessment, in writing, completed before tracking starts.

Interests that qualify

Fleet security, fuel cost control, customer service response times, vehicle utilisation, route compliance.

What “transparent” actually means

No matter which basis the fleet ends up relying on, the employer still has to tell the drivers what is going on. In writing. Three documents make up the standard compliance package:

  • The privacy notice. The notice starts by naming the employer as the data controller and the tracking platform as the data processor. Once the two parties are named, the notice goes through what data the system collects, which lawful basis the processing rests on, how long the data gets kept, and which people inside the company can look at it. The last part covers the driver’s rights under GDPR, which come down to the right to object to the processing, the right to ask for a copy of the data, and the right to complain to the national data protection authority.
  • The vehicle tracking policy. This one is a separate document and covers different ground. The day to day usage rules live here, along with the line between work time and personal time and the consequences for tampering with or disconnecting a device.
  • Written acknowledgement. Each driver puts a signature on a short confirmation saying the notice reached them and they read it. What the driver is signing is not a consent form. All the signature records is that the employer made the disclosure. An acknowledgement and a consent form can look almost the same on paper, but in legal terms they are two different documents doing two different jobs.

If a regulator or a driver asks for those three documents and the fleet cannot hand them over, the fleet has a compliance problem, and the quality of its tracking data will not fix that problem.

The personal time question

Regulators across the EU have been consistent on one point above most others. A fleet that tracks a vehicle’s location during private use, evenings, weekends, and personal errands is in a weaker position than a fleet that only tracks during working hours. The employer’s interest in knowing where the van is doesn’t extend to monitoring where the driver goes on a Saturday afternoon. [3]

For vehicles that stay at the depot overnight and only move during working hours, this question doesn’t come up. It gets harder once a driver takes the van home in the evening, or a pool car goes out on a Saturday, or some other arrangement leaves the vehicle with the driver after the shift has ended.

The tool most platforms have built for this situation is a privacy mode. The mode works by either letting the driver press a button (on the device or in the app) or running on a time schedule the fleet manager configures on the platform. When the mode is active, the server stops receiving precise coordinates from that vehicle. The device itself stays powered the whole time. Data that carries no location in it, ignition events and mileage counts for example, keeps arriving the way it always does. In their published decisions and guidance, regulators have been specific about one requirement. The control has to actually work at a technical level, either in the device or in the platform. A policy stating that the fleet respects driver privacy during personal use does nothing on its own if the platform running underneath it has no mechanism for stopping the feed.

For fleets where personal use of the vehicles is allowed, three configurations need to be in place:

  • A time window for location tracking (for example, 06.00 to 20.00 on weekdays) that goes quiet automatically outside those hours, unless the driver opts back in.
  • A driver activated privacy mode for personal stops during the workday.
  • A clear policy describing when the privacy mode can be used and what the boundaries are.

Example: A delivery fleet lets its drivers take the vans home at the end of the shift. The platform tracks location from 06.00 to 20.00 on weekdays. After 20.00, and through the whole weekend, the platform carries on logging ignition events and daily mileage while the coordinates stop being recorded. For personal errands during the day, there’s a privacy button. This kind of setup lines up with what the Irish DPC described in its 2020 guidance on employer vehicle tracking.

Retention: how long the data can be kept

One of the GDPR principles is storage limitation. In plain terms, when the reason for holding a piece of personal data goes away, the data is supposed to go away with it. [1] For a tracked fleet, that translates into a separate retention period for each category of data, one for live location, one for trip logs, one for driver scores. Each of those periods has to appear in the privacy notice the drivers received. The deletion should be something the platform does automatically. A manual purge that only happens when somebody in the office remembers to run it is not a control a regulator will accept as reliable.

Here are retention periods that have held up when regulators reviewed them:

Data type Common retention period Reason
Live and recent location data 30 to 90 days Operational use, customer queries
Trip history 12 to 24 months Dispute resolution, customer service
Driver behaviour scores 12 months Performance management cycles
Maintenance and fuel data As long as the vehicle is operated Operational records
Tachograph data (EU commercial fleets) At least 12 months held by operator [4] Mandatory under EU rules

Tachograph data on EU heavy goods vehicles and commercial passenger vehicles is a special case. Operators are required to download the tachograph data at regular intervals and keep it for at least 12 months. The driver card holds the previous 56 days of records for international journeys following the 2025 update to AETR rules. [4] Those are floors, not ceilings. The tachograph rules run on a separate track from the fleet’s general tracking retention policy. One doesn’t replace the other.

How long fleet tracking data gets kept (bars on a 24 month scale)
Live and recent location data
30 to 90 days
Driver behaviour scores
12 months
Tachograph data (operator copy)
12 months minimum, mandatory
Trip history
12 to 24 months
Retention the fleet sets and discloses
Minimum required by EU tachograph rules
Maintenance and fuel data sit outside the chart: they are kept for as long as the vehicle is operated. The blue periods are ceilings the fleet chooses and writes into the privacy notice; the amber period is a floor set by EU rules.

When a DPIA is required

Under GDPR, a Data Protection Impact Assessment (DPIA) is required when processing is likely to result in high risk to the rights of individuals. Tracking the location of a workforce on a continuous basis, where each driver is identifiable, meets that threshold in the view of most EU regulators. The DPIA should be completed before any tracking goes live. [3]

A DPIA documents:

  • What is being processed and why.
  • The lawful basis and the necessity test.
  • What risks the tracking creates for the drivers and what the employer has done to reduce those risks.
  • Whether the processing is proportionate as designed, or what would need to change to make it proportionate.

DPIA templates are published by most national data protection authorities. Length is not the issue. A two page DPIA that covers the right ground is fine. The document has to be finished and in the file before the first device is fitted. In an investigation, the first thing the regulator usually reads is the DPIA. A fleet that never wrote one goes into that investigation missing the document the regulator expected to find at the top of the file.

Interactive: the five things a compliant tracking programme has on file
1Lawful basis
Decided with legal input and written down before any hardware goes into any vehicle. Most fleets land on legitimate interests, documented in a written legitimate interests assessment. Consent rarely holds in employment.
2Privacy notice
Reaches every driver before the devices switch on. Names the controller and the processor, lists the data collected, the lawful basis, the retention period, who has access, and the driver's rights. Each driver signs an acknowledgement.
3DPIA
Finished and in the file before the first device is fitted. Covers what is being processed and why, the necessity test, the risks to drivers, and whether the processing is proportionate as designed.
4Retention schedule
A defined period for each data category, written into the privacy notice, with the platform deleting expired data automatically rather than waiting for a manual purge.
5Privacy mode
Scheduled or driver activated, on every vehicle that gets used outside working hours. The control has to work at a technical level, in the device or in the platform, not just in a policy document.

How this changes outside the EU

GDPR takes up most of this guide because it places the most demands on a fleet operator. Other countries have been heading in a similar direction, although none of them has adopted the regulation as written.

During the Brexit process, the UK converted the EU regulation into its own domestic law. The day to day obligations on a fleet operator came through that conversion more or less unchanged. A compliance file put together for the EU version, with the notice, the basis, the DPIA, and the retention schedule in it, will do the job under the UK regime with little or no extra work.

The United States has no federal law covering employee vehicle tracking, so the rules come from the individual states. Tracking an employee’s personal vehicle without consent is restricted or outright prohibited in several states. Tracking an employer owned vehicle is generally lawful, though many states require written notice to the employee. A few states go further than notice and require the employee’s written consent.

Canada, Australia, and New Zealand have privacy regimes that broadly require notice, a documented purpose, proportionality, and the right of the employee to know what is being collected. The exact requirements change from one country to the next, but the underlying ideas stay close to the EU model.

A fleet based outside the EU can save itself some work by building its compliance package to GDPR standards from the beginning. Most local regimes ask for some subset of what GDPR asks for, so a fleet that already meets the GDPR standard will rarely run into trouble in a local audit.

Example: A logistics company based in Germany opens branches in Poland, France, and the UK. The privacy notice is drafted to EU GDPR standards with country specific addenda for the local data protection authorities. The same notice then covers all four countries, with small adjustments for each one.

Example: A US service business with vehicles in five states writes a single tracking policy that meets the notice standard of the strictest state, then uses that policy in all five. Keeping up one compliance position takes less effort than keeping up five separate ones.

On the platform side, GPSWOX supports the controls this guide describes, among them configurable retention periods and privacy mode options for vehicles that get both business and personal use.

5 compliance mistakes that produce findings

1. Treating the tracking software vendor’s privacy policy as your privacy notice

The vendor is a data processor. The fleet operator is the data controller. The privacy notice that goes to drivers has to come from the controller, not from the vendor’s website. Any regulator who reviews the paperwork will see within a few minutes that a vendor policy is sitting in the place where the privacy notice should be.

2. Relying on consent

GDPR rarely accepts consent given inside an employment relationship as freely given. A tracking programme that rests on driver consent carries a structural weakness. The moment any driver withdraws consent, the legal basis under that driver’s tracking disappears. Neither legitimate interests nor performance of contract can be withdrawn by a driver, and that’s the point of using them. [2]

3. Continuous tracking on vehicles used for personal trips

This is the single most cited issue in regulator findings on vehicle tracking. Enforcement actions have concentrated on one pattern: the tracking runs past the end of the shift, and the driver has no off switch, not on the device and not in the app. A policy document that references privacy mode is worth nothing if the platform the fleet is running doesn’t actually have one. [3]

4. No DPIA on file

When a regulator opens a case on fleet tracking, the DPIA is typically the first document they ask for. A fleet that cannot produce one has nothing on file showing the necessity of the tracking, its proportionality, or the mitigations put in place for the drivers. The DPIA doesn’t have to be long, but it has to exist before tracking begins. [3]

5. Indefinite retention

Trip history kept for the lifetime of the fleet violates GDPR’s storage limitation principle. Defined retention periods, written into the privacy notice and actually enforced by the platform, are the standard expectation. [1]

Frequently asked questions

Do I have to get driver consent to track company vehicles?

Consent is one of the six lawful bases in GDPR, but it’s rarely the right one for fleet tracking. The employer employee relationship creates a power gap that makes “freely given” consent difficult to establish in front of a regulator. [2] Most fleets rely on legitimate interests or performance of a contract instead. Written disclosure to the drivers is required whichever basis applies. What decides whether the tracking is lawful is the basis the employer documented, and telling the drivers about the system does not, by itself, settle that question.

Can I track an employee’s personal vehicle used for work?

In most cases, only with genuine consent from the employee, and only if that consent would hold up if somebody challenged it. Most privacy regimes give personal vehicles a higher level of protection than employer owned ones. Legitimate interests get much harder to argue when the tracked asset is the employee’s own property. Fleets that want a simple compliance position usually track only the vehicles the company owns.

Is GPS tracking legal in the UK?

Yes. The UK GDPR began life as the EU regulation and was carried into domestic law at Brexit, and the fleet tracking obligations under the two versions remain nearly identical today. Compliance work done for the EU version carries across, with almost nothing needing to be added. [3]

How long can fleet tracking data be kept?

For as long as the collection purpose lasts and no longer, with the period fixed in advance and disclosed to the drivers. [1] Regulators have accepted 30 to 90 days on live location and 12 to 24 months on trip history. Tachograph data on EU commercial vehicles has its own minimum retention of 12 months by the operator. [4]

What if a driver objects to tracking?

Drivers have a right to object to processing based on legitimate interests. Where the objection is upheld, the employer has to stop processing that driver’s data, and the only exception is where the employer can show compelling grounds that outweigh the driver’s privacy rights. From there, things usually go in one of a few directions. Some drivers accept the tracking after the reasons for it get properly explained to them. Other drivers end up moving into roles that do not involve a tracked vehicle, and in a small number of cases the employment relationship comes to an end. Nothing about the objection makes any of these automatic. A formal objection has to go through a formal process.

The Bottom Line

Vehicle tracking is legal in the countries fleets typically operate in. What the law concerns itself with is the paperwork sitting behind the tracking, and not really the technology that does the tracking. Five things need to be in place before a system goes live. The lawful basis has to be decided with legal input and written down. Every driver needs to have received the privacy notice and signed an acknowledgement of it. The DPIA gets finished before the first tracker is installed. On the platform, the retention schedule needs configuring so that expired data deletes on its own. And a privacy mode, either scheduled or driver activated, on every vehicle that gets used outside working hours. A fleet with all five in place is tracking within the law. A fleet that fitted the hardware without doing the paperwork is carrying an exposure that keeps on growing until somebody notices it, and the somebody who notices tends to be a regulator.

Getting the paperwork in order takes a few days of work. A regulator finding, on the other hand, puts the company’s name into a published decision and hands control of the remediation timeline to somebody outside the company.

Article Sources

  1. Data Protection Commission Ireland. “Employer Vehicle Tracking.” https://www.dataprotection.ie/en/dpc-guidance/employer-vehicle-tracking
  2. GC Lawyers. “Employer Vehicle Tracking — Get Compliant.” https://gclawyers.eu/employer-vehicle-tracking/
  3. Data Protection Commission Ireland. “Guidance Note: Employer Vehicle Tracking (May 2020).” https://www.dataprotection.ie/sites/default/files/uploads/2020-09/Employer%20Vehicle%20Tracking_May2020.pdf
  4. European Commission. “Tachograph.” https://transport.ec.europa.eu/transport-modes/road/tachograph_en
  5. Information Commissioner’s Office. “Employment practices and data protection: Monitoring workers.” https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/