Tracking company vehicles involves personal data — the location and movements of your drivers. GDPR does not prohibit GPS tracking, but it sets clear conditions for doing it correctly. Here are the key points every business should know.
Tracking company vehicles is usually based on the employer's legitimate interest (fleet safety, cost management, efficiency) rather than employee consent, since consent given in an employment context is not always considered freely given. Still, the lawful basis must be documented and proportionate to the purpose.
Drivers need to know that their vehicle is being tracked, why, what data is collected, and who has access to it. A clear, written tracking policy — communicated to staff before implementation — is a core compliance requirement.
Tracking should be limited to what's necessary for the stated purpose — typically working hours and company vehicles. Tracking outside working hours or during personal use of a vehicle requires extra care, often including the option to disable it.
Location data should not be kept indefinitely. Set a specific retention period (months, not years) proportionate to the purpose — fleet safety, dispute resolution, tax obligations — and systematically delete older data.
Location data must be protected with encryption in transit and at rest, and access should be limited to authorized personnel (e.g. the fleet manager), not the entire organization.
The FahrTrack platform runs on SSL/TLS encryption and is fully GDPR compliant, so the technical infrastructure is ready — the rest of your compliance (informing employees, retention policy) depends on your business's own policies. Learn more on our Services page.
Related articles
Contact us — our team usually replies within a few hours.
Contact