Vehicle tracking GDPR compliance for UK fleet managers

Hands installing compliant vehicle tracker inside van

Vehicle tracking of employees is lawful under UK GDPR and the Data Protection Act 2018, provided you have a documented lawful basis, transparent staff communication, and a completed Data Protection Impact Assessment where the monitoring carries elevated risk. The ICO’s monitoring workers guidance is explicit: tracking must be lawful, fair and transparent, and a DPIA is expected wherever processing is likely to result in high risk to drivers.

Before reading further, take three immediate actions:

  • Suspend any covert tracking or out-of-hours monitoring that staff haven’t been told about.
  • Start a DPIA now if you haven’t got one on file, particularly for GPS combined with cameras or driver-behaviour scoring.
  • Draft a plain-English privacy notice covering what’s collected, why, and for how long.

These three steps address the majority of complaints the ICO receives about workplace vehicle monitoring.

Key Takeaways

Compliant vehicle tracking under UK GDPR rests on a documented lawful basis, upfront transparency, a completed DPIA for high-risk monitoring, and hardware with genuine privacy controls.

Point Details
Lawful basis first Document a Legitimate Interest Assessment before deploying tracking; consent rarely suffices in employment.
Tell staff before you track Issue a privacy notice and fit vehicle signage before any device goes live, not after.
Switch off for private use Fit a working privacy mode; monitoring during personal journeys is rarely justifiable.
Run the DPIA early Complete it before procurement, covering necessity, alternatives, and mitigations.
Choose certified hardware Thatcham Trackers supplies S5, S5+, and S7 certified devices with encryption and access controls built in.

Table of Contents

Vehicle tracking GDPR: which lawful basis actually applies?

Three lawful bases cover almost every fleet-tracking scenario, and picking the wrong one is the most common compliance mistake.

Legitimate interest works for most operational tracking: route optimisation, fuel efficiency, theft recovery, insurance compliance. It requires a documented Legitimate Interest Assessment (LIA) showing you’ve weighed the business need against the driver’s privacy expectations.

Consent rarely holds up in an employment relationship. The power imbalance between employer and employee means consent is unlikely to be “freely given” in the UK GDPR sense, so relying on it alone is a weak foundation for ongoing tracking.

Legal obligation applies in narrower cases, such as tachograph recording for HGV drivers under existing transport regulations, where a separate statutory duty does the heavy lifting.

  • Legitimate interest: needs a written LIA and a defined retention period.
  • Consent: only appropriate for genuinely optional add-ons, not core monitoring.
  • Legal obligation: applies where another law already mandates the recording.

Pro Tip: Attach a retention limit to whichever lawful basis you choose at the point you document it. An LIA without a stated retention period is one of the first gaps an ICO investigator will flag.

How should you tell staff their vehicle is being tracked?

Transparency has to happen before tracking starts, not after a complaint. A privacy notice specific to vehicle tracking should name the data controller, state the purposes of processing, confirm the lawful basis, set out retention periods, and explain how drivers can exercise their rights.

Keep a record of when notices were issued and when staff were consulted, since the ICO treats consultation evidence as a strong transparency signal.

  • Controller’s name and contact details.
  • The exact purposes: safety, routing, insurance, theft recovery.
  • Lawful basis relied upon and why.
  • Retention period for each data type.
  • Who can access the data internally and under what conditions.
  • Vehicle signage confirming tracking is in operation and where to find full details.

Signage should be visible from the driver’s seat, not buried in a handbook nobody rereads. Combine the sticker with a written policy handed out during induction so there’s no argument later about whether someone “knew.”

Can you track vehicles during personal or private use?

Monitoring during personal use is rarely justifiable, and draft employment guidance is blunt about this: private journeys deserve a materially higher level of privacy protection than work trips. If a vehicle is used outside working hours or for personal errands, the safest position is to switch tracking off entirely for that period.

For employee-owned vehicles used for business (grey fleet), this becomes sharper still. Tracking someone’s own car usually needs explicit, separately recorded agreement, distinct from whatever employment contract clause covers company vehicles.

  • Fit a privacy mode or manual off switch drivers can use outside shift hours.
  • Use geo-fencing tied to rostered working hours rather than blanket 24/7 monitoring.
  • Put personal-use terms in writing, signed separately from the main contract.

Pro Tip: A common compliance pitfall is relying on legitimate interest to justify continuous tracking on vehicles that are also used privately. If private use is allowed, a working privacy mode isn’t optional; it’s the control that makes the lawful basis defensible.

What data can you collect, and for how long should you keep it?

Location, speed, mileage, and diagnostic fault codes are low-risk and easy to justify for fleet management. In-cab audio and video, and granular driver-behaviour profiling, sit in a different category entirely. The ICO’s surveillance in vehicles guidance recommends switching audio recording off by default because it’s one of the most intrusive forms of monitoring you can deploy in a vehicle.

Retention should reflect purpose, not convenience: routine telematics data typically has no business reason to sit on a server for more than 12 to 24 months, while incident-related footage can be kept longer, but only with a written justification tied to the specific event.

  • Location and speed data: lower risk, standard retention windows apply.
  • Diagnostic and fuel data: low risk, useful for maintenance planning.
  • In-cab audio: high risk, off by default per ICO guidance.
  • Behavioural scoring profiles: higher risk, needs explicit justification and a DPIA.

Data minimisation isn’t just a compliance checkbox. Sampling location pings less frequently, aggregating behavioural scores rather than storing raw event logs, and pseudonymising driver identifiers wherever the operational purpose allows all reduce your exposure if data is ever breached or subject to a legal challenge.

Can tracking data be used for disciplinary action?

Yes, but only carefully, and only where the evidence relates to the purpose the data was originally collected for. Using GPS logs gathered for route planning to build a disciplinary case about a completely different issue risks what DavidsonMorris describes as function creep, where data drifts from its original justification into something the driver never consented to or was informed about.

Validated evidence of repeated dangerous speeding tied directly to a safety policy is generally defensible. Using location history from someone’s lunch break or a personal errand is high risk and likely to draw a grievance or an ICO complaint.

  • Corroborate tracking data with another source before acting on it alone.
  • Involve HR or your DPO in the review before any disciplinary step is taken.
  • Keep a written record of why the data was relevant to the specific incident.

Pro Tip: Treat every disciplinary use of tracking data as a decision that needs a paper trail. If you can’t explain in one sentence why this data was collected for this purpose, don’t use it.

When do you need a Data Protection Impact Assessment?

A DPIA is mandatory wherever vehicle tracking is likely to result in high risk, and the ICO expects it completed before procurement, not bolted on afterwards. This matters most when GPS is combined with cameras, audio, or behavioural analytics, since the Stephenson Harwood analysis of employee vehicle monitoring flags this combination as the point where compliance risk climbs sharply.

A workable DPIA checklist covers:

  • The specific purpose the tracking serves.
  • Why the monitoring is necessary and proportionate to that purpose.
  • What less intrusive alternatives were considered and why they were rejected.
  • Risk mitigations built into the system (privacy mode, access limits, retention caps).
  • Evidence of staff consultation before go-live.
  • A review date to reassess as the fleet or technology changes.

Pro Tip: Document explicitly why a manual log or driver self-reporting wasn’t sufficient. The ICO’s proportionality test hinges on showing you actually considered a lighter-touch option before choosing continuous electronic monitoring.

What’s the step-by-step process to become compliant?

Compliance is sequential. Skipping the order (buying hardware before the DPIA, for instance) is how fleets end up retrofitting policy around technology instead of the other way round.

  1. Run the DPIA before you approach suppliers, covering purpose, necessity, and alternatives considered.
  2. Choose your lawful basis and complete a Legitimate Interest Assessment if that’s the route you’re taking.
  3. Draft the vehicle-tracking policy, with headings for purpose, scope, data types, retention, employee rights, security measures, and escalation routes for complaints.
  4. Issue privacy notices and install vehicle signage before any device goes live.
  5. Consult employees or their representatives, and keep a written record that consultation happened.
  6. Procure hardware with encryption, access controls, and a genuine privacy mode built in.
  7. Update your Record of Processing Activities (RoPA) to reflect the new processing.
  8. Involve your DPO, where you have one, at both the DPIA and procurement stages.
  9. Set an audit cadence, reviewing the policy and DPIA annually or whenever the fleet or technology changes materially.

What technical safeguards should you look for when procuring trackers?

Legal compliance and hardware choice are the same decision viewed from two angles. Devices should encrypt data in transit and at rest, restrict access on a role basis so only authorised staff can view location or behavioural data, and log every access event so you can demonstrate control if a data subject access request lands on your desk.

Look for a built-in privacy mode, time-based tracking windows that respect shift patterns, and remote immobilisation only where the risk genuinely justifies it. In the UK insurance market, Thatcham Research certification (S5, S5+, and S7) carries real procurement weight beyond data protection: insurers use it to assess theft risk, and many require it before offering reduced premiums.

  • In-transit and at-rest encryption as standard, not an add-on.
  • Role-based access with a visible audit trail.
  • A genuine, easy-to-use privacy mode for personal-use periods.

Pro Tip: Ask any supplier for their certification level in writing before you sign. A device without Thatcham approval can leave you exposed on the insurance side even if your GDPR paperwork is flawless.

What are the penalties for getting vehicle tracking GDPR wrong?

The ICO can issue enforcement notices, reprimands, and fines, with the most serious cases involving systemic failures across multiple vehicles or a complete absence of transparency. The documents that most reduce your exposure are a completed DPIA, issued privacy notices, a consultation record, an up-to-date RoPA entry, and evidence that technical controls like encryption and access restrictions were actually implemented, not just written into a policy nobody follows.

If a breach does happen, the clock starts immediately: you generally have 72 hours to report a qualifying breach to the ICO, alongside notifying affected staff and containing the exposure internally.

  • Keep DPIA and LIA documents on file, not just referenced in a policy.
  • Retain consultation records showing staff were told before tracking began.
  • Log technical controls (encryption, access lists) as evidence, not assumption.

Why compliance and hardware choice go together

Fleets that treat legal compliance and equipment procurement as separate projects usually end up redoing one to fix the other. Pairing a properly documented DPIA and privacy notice with Thatcham-approved hardware gives fleet managers a position that satisfies both the ICO and their insurer at the same time. That combination, in our experience advising fleets on deployment, is what actually reduces theft risk while evidencing genuine due diligence.

Thatcham S7

Get compliant hardware with the paperwork already sorted

Buying a tracker and sorting your GDPR paperwork don’t have to be two separate headaches. Thatcham Trackers supplies S5, S5+, and S7 Thatcham-approved trackers with the mandatory digital certificate UK insurers accept, fitted through nationwide mobile installation, and built with the encryption, access controls, and tamper alerts your DPIA needs to reference.

Thatcham Trackers

Whether you’re outfitting a single van or a full commercial fleet, choosing certified hardware from the outset means your procurement decision already lines up with the technical safeguards regulators expect. Browse the S5 tracker range or get in touch to discuss a fleet-wide installation, and take the guesswork out of matching your GDPR documentation to the devices you actually put on the road.

Where to check the official rules

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

Is it illegal to put a tracker on a vehicle in the UK?

No, fitting a tracker is lawful, but tracking an employee’s journeys requires a documented lawful basis, transparency, and a DPIA where the monitoring is high risk under ICO guidance.

Can a company use a vehicle tracker to spy on you?

Covert or undisclosed tracking breaches transparency requirements under UK GDPR; employers must inform staff before tracking starts and provide a clear privacy notice.

Can vehicle tracking data be used in a disciplinary UK case?

Yes, but only where the data relates to the original purpose it was collected for; using it for unrelated matters risks function creep and potential privacy breaches, as DavidsonMorris notes.

Consent isn’t the only valid lawful basis, so tracking without consent can still be lawful if legitimate interest or a legal obligation applies and staff have been properly informed.

Do Thatcham-approved trackers help with GDPR compliance?

Thatcham certification addresses insurer acceptance and hardware security standards; pairing it with a documented DPIA and privacy notice from Thatcham Trackers covers both the insurance and data protection sides of deployment.

Featured collection Thatcham-Approved Trackers
Shop now