Avoid £17.5m ICO Fines: UK Vehicle Tracking Policy for Fleets
![]()
Vehicle tracking is lawful under UK GDPR and the Data Protection Act 2018 when you can show it’s necessary, proportionate and properly documented. A compliant vehicle tracking policy must set out your lawful basis, exactly what data you collect, how long you keep it, who can access it, and how drivers can switch off tracking for personal journeys. The template and checklist below give you everything you need to draft or update your policy today.
TL;DR:
- Most vehicle tracking relies on a documented legitimate interest assessment rather than driver consent, because of power imbalances and legal risks.
- Tracking data must be limited to necessary types like location, speed, and journey times, with safeguards against misuse such as continuous or covert monitoring.
- A comprehensive DPIA is needed for large-scale or intrusive tracking, involving risk assessment, technical safeguards, and clear organizational controls.
- Using tracking data for disciplinary actions is permissible only if the collection was lawful, proportionate, and drivers were informed beforehand.
- Reviewing the policy annually and implementing automated retention and privacy controls minimizes legal exposure and supports ongoing compliance.
Table of Contents
- What does UK law actually say about vehicle tracking policy compliance?
- Which lawful basis should you use, and where does consent fit in?
- What data can you collect, and where’s the line?
- How do you run a DPIA for vehicle tracking, and what controls reduce risk?
- Can you use vehicle tracking data in a disciplinary hearing?
- How do you build a compliant company vehicle tracking policy?
- How should you roll out a vehicle tracking policy without disrupting drivers?
- What happens if tracking data is breached, and what are the penalties?
- How often should you review and audit your tracking policy?
- The trade-off nobody talks about honestly
- How Fleetalyse supports a compliant vehicle tracking policy
- Where to check the primary rules and templates
- Sources
What does UK law actually say about vehicle tracking policy compliance?
Three pieces of legislation govern how you can track company vehicles: UK GDPR, the Data Protection Act 2018, and the Human Rights Act 1998. Together they form the legal skeleton your policy has to hang on.
Under UK GDPR and the Data Protection Act 2018, you become a “data controller” the moment you process location data tied to an identifiable driver. That triggers specific duties: you need a lawful basis for processing, you must tell drivers what’s happening, and you must be able to demonstrate accountability if the Information Commissioner’s Office ever asks. Vehicle location data counts as personal data even without a name attached, because a vehicle can usually be traced back to a specific driver through rotas, shift patterns or vehicle allocation records.
Article 8 of the Human Rights Act 1998 protects the right to private and family life, and this doesn’t stop at the office door. Employees carry a reasonable expectation of privacy even in a company van, particularly once they leave the depot at the end of a shift or use a vehicle for any personal errand you permit. Tracking that ignores this expectation, especially continuous tracking with no way to pause it, sits on shaky legal ground regardless of how good your operational reasons are.
The Regulation of Investigatory Powers Act (RIPA) becomes relevant mainly for public authorities running covert surveillance, or where an employer suspects serious misconduct and considers hidden monitoring. Covert tracking without a legitimate, documented, proportionate justification is a serious legal risk, and specialist legal guidance treats it as an exception requiring its own strict necessity and proportionality test, not a default option.
The ICO enforces all of this. It can issue improvement notices, enforcement orders and, in serious cases, substantial fines. Enforcement typically follows a complaint from an employee, a data breach report, or a routine audit that turns up gaps between what a policy promises and what actually happens on the ground.
Which lawful basis should you use, and where does consent fit in?
Most employers rely on legitimate interests as their lawful basis for vehicle tracking, not consent. That surprises a lot of fleet managers who assume they need a signed consent form from every driver.
Consent is a weak basis in an employment relationship because of the imbalance of power involved. If a driver’s job depends on accepting tracking, their agreement isn’t freely given in the way UK GDPR requires, which means a consent-based policy can unravel the moment it’s challenged. Legitimate interests works far better because it lets you balance your operational need (route efficiency, driver safety, theft recovery, duty of care) against the employee’s privacy rights, and you document that balancing exercise formally.
That documentation is called a Legitimate Interest Assessment (LIA). It doesn’t need to be lengthy, but it does need to cover three tests: is the purpose genuine, is tracking necessary to achieve it, and does the business interest outweigh the impact on the driver. Keep this on file. If the ICO or a tribunal ever questions your approach, the LIA is your evidence that you thought it through rather than switched trackers on by default.
Consent still has a place in specific scenarios: tracking a driver’s own personal vehicle for business mileage claims, or any tracking that continues outside contracted working hours. In those cases, get it in writing and make clear it can be withdrawn.
Whatever basis you choose, your notice to employees must cover:
- The specific purposes tracking serves (route optimisation, safety, theft recovery, compliance)
- Exactly what data types you collect and for how long
- Who within the business can access that data and under what circumstances
- Employees’ rights to access, query or complain about how their data is handled
Notify drivers before tracking starts, not retrospectively. The RAC’s guidance for fleet employers is unambiguous on this point: tracking someone without prior notice, even briefly, breaches the transparency principle at the heart of UK GDPR.
What data can you collect, and where’s the line?
Minimisation is the golden rule: collect only what actually supports your stated purpose, nothing more. If your justification is “safety and route efficiency,” you don’t need to be logging every second a vehicle sits stationary outside someone’s house on a Sunday.
Data types you can legitimately collect include:
- Vehicle location and journey routes during working hours
- Journey start and end times, and total mileage
- Speed events and harsh braking or acceleration data
- Tachograph and driver hours data, where working time regulations require it
The ICO explicitly warns against “mission creep,” where data gathered for one purpose gets quietly repurposed for another without fresh assessment or notice. If you started tracking for fuel efficiency and now want to use the same data for performance appraisals, that’s a new purpose requiring its own justification.
Some practices carry disproportionate risk relative to their benefit:
- Continuous 24/7 tracking with no privacy mode or pause function
- Covert installation of trackers without informing the driver
- Default-on audio recording inside cabs, which the ICO treats as significantly more intrusive than location data alone
Pro Tip: Build tracking around working hours, not calendar days. A geofenced schedule that automatically suspends location logging outside shift times does more to protect you legally than any amount of policy wording alone.
How do you run a DPIA for vehicle tracking, and what controls reduce risk?
A Data Protection Impact Assessment (DPIA) is mandatory whenever tracking involves systematic monitoring of individuals on a large scale, which covers most fleet rollouts, and the ICO specifically flags in-vehicle surveillance as high risk. If you’re tracking more than a handful of vehicles, or adding any form of video or audio capability, assume you need one.
Run your DPIA through these steps:
- Describe the processing. What data, how collected, how long retained, and by which system.
- Assess necessity and proportionality. Could a less intrusive method achieve the same outcome?
- Identify risks to drivers. Consider intrusion into personal time, misuse of data, and disciplinary overreach.
- Set mitigations. Privacy modes, retention limits, access restrictions, encryption.
- Sign off and review. A named owner (ideally a DPO or senior compliance lead) approves it and commits to periodic review.
Once the DPIA identifies risks, translate them into actual controls rather than leaving them as observations on a document nobody revisits. On the technical side: a driver-controlled privacy mode, geofencing that automatically limits tracking to working hours, automated deletion once your retention period expires, encryption of stored location data, and role-based access so only named individuals can view records.
Organisationally, you need clear governance. Assign responsibility to a specific person or committee, restrict viewing rights to defined roles, train anyone with access on what they can and can’t do with the data, and keep every policy version dated and signed off. Fleetalyse’s guide on before you switch on GPS walks through these DPIA prompts in more detail if you’re building one from scratch.
![]()
Can you use vehicle tracking data in a disciplinary hearing?
Yes, but only if three conditions hold: the data was collected lawfully, its use is proportionate to the alleged issue, and drivers were told in advance that tracking data could be used this way. Skip any of those three and you’re exposed to an unfair dismissal claim.
Employment law guidance makes clear that GPS evidence works best as corroboration, not as the sole basis for a decision. If tracking shows a driver stationary for two hours during a delivery run, don’t jump straight to a disciplinary letter. Give the employee a chance to explain, because there might be a legitimate reason, a breakdown, a blocked road, an unscheduled welfare stop, that the data alone can’t show.
Best practice for any tracking-based investigation:
- Corroborate GPS data with other evidence where possible (delivery records, customer sign-offs, driver logs)
- Give the employee a genuine right to respond before any decision is made
- Get sign-off from HR and, for serious cases, legal advice before proceeding
- Apply the ACAS fairness tests: was the process reasonable, consistent and proportionate
Document every step. If a tribunal later asks how you reached a decision, you need a clear chain showing who accessed the data, when, and why.
How do you build a compliant company vehicle tracking policy?
Your policy needs to work as both a legal shield and a practical reference document that HR, drivers and managers can actually use. Structure it around these essential clauses:
- Purpose and scope: why you track, which vehicles and roles are covered
- Lawful basis: legitimate interests (with your LIA referenced) or consent, and when each applies
- Data collected: location, speed, mileage, journey times, tachograph data where mandated
- Retention period: a defined number of days or months, not “as long as necessary”
- Access controls: named roles permitted to view data, and how access is logged
- Disciplinary use: when and how tracking data may inform investigations
- Employee rights: how to request access, raise a query, or complain to the ICO
For your notification wording, something close to this works well: “[Company name] uses GPS tracking on company vehicles to support driver safety, route efficiency and legal compliance. Location data is collected during scheduled working hours and retained for [X months]. You can activate privacy mode to pause tracking outside these hours. Access to your data is restricted to [named roles]. Contact [DPO/HR contact] with any questions or to exercise your data rights.”
A short privacy-mode clause: “Drivers may switch tracking to privacy mode at the end of a shift or during personal use of a company vehicle. Activating privacy mode does not affect driver pay or performance assessment.”
A practical policy example, such as Montracon’s published vehicle monitoring policy, shows how these clauses look when assembled into a working document, with governance typically assigned to a named data protection lead and annual review built in.
| Policy clause | Evidence you should hold |
|---|---|
| Lawful basis | Completed LIA, dated and signed off |
| Data minimisation | DPIA identifying purpose and data types |
| Retention schedule | Automated deletion logs matching stated period |
| Access controls | Role-based access list, access log history |
| Staff notification | Signed acknowledgement or induction record |
| Disciplinary use | ACAS-aligned investigation records, sign-off trail |
How should you roll out a vehicle tracking policy without disrupting drivers?
Rolling out tracking badly, with no warning and no explanation, is one of the fastest ways to trigger grievances and turnover in a fleet team. A staged approach avoids that.
- Finish your DPIA and get stakeholder sign-off before any hardware goes into a vehicle, involving HR, operations and, where relevant, employee representatives.
- Run a small pilot with a handful of vehicles or a single depot, so you catch practical issues before a full rollout.
- Communicate clearly in writing, ideally through an updated contract clause or standalone policy document that every driver signs.
- Add in-vehicle signage confirming tracking is in operation, which the ICO expects as standard practice for transparency.
- Build tracking into induction training, covering how privacy mode works, what data is collected, and how to raise concerns.
- Train managers separately on what they can and can’t do with tracking data, especially around disciplinary use.
Address personal-vehicle use and opt-out questions directly during induction rather than leaving drivers to ask later. If someone occasionally uses a company vehicle for personal errands with permission, tell them exactly how privacy mode protects that time. Fleetalyse’s guide to getting drivers to accept vehicle tracking covers the communication side of this in more depth.
What happens if tracking data is breached, and what are the penalties?
Security failures around location data carry some of the steepest penalties in UK data protection law. As of February 2026, severe UK GDPR breaches can attract fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, and failing to report unauthorised access on time can bring separate penalties of up to £8.7 million.
Minimum technical controls to demonstrate reasonable security include encrypted data storage, role-based access restrictions, regular access log audits, and secure deletion once your retention period expires. If a breach occurs, you must notify the ICO within 72 hours of becoming aware of it, and notify affected drivers directly if the breach poses a high risk to their rights. Delay or silence turns a manageable incident into a much bigger enforcement problem.
How often should you review and audit your tracking policy?
Review your policy at least annually, and immediately whenever something material changes: new tracking hardware, a change in data retention practice, a fleet expansion, or a near-miss data incident that exposes a gap.
Keep these records on file as audit evidence: your current DPIA, access logs showing who viewed tracking data and when, deletion logs confirming your retention schedule is actually enforced, and training records showing drivers and managers received induction on the policy. Log every policy change with a date and the reason behind it, and keep a named owner accountable for governance year to year. This paper trail is what turns “we have a policy” into “we can prove we followed it.”
The trade-off nobody talks about honestly
Most guidance on this topic treats compliance and operational efficiency as if they’re in tension, as though every privacy safeguard costs you something in fleet performance. That’s rarely true in practice. A well-built privacy mode doesn’t slow down route optimisation, and automated retention deletion doesn’t hurt your safety analytics, because the data you actually need for those purposes is generated during working hours anyway.
The real risk isn’t over-collecting data. It’s collecting it without a documented reason, which leaves you defending decisions you can’t actually justify when challenged.
If you do one thing after reading this: automate your retention schedule and switch on privacy mode by default rather than as an opt-in extra. It costs you almost nothing operationally and closes off the two most common gaps ICO investigations find.
— Vytautas
How Fleetalyse supports a compliant vehicle tracking policy
Building a policy is one job. Enforcing it every single day across a working fleet is another, and that’s where the right platform earns its place. The platform is designed to include controls such as driver-activated privacy mode, role-based access so only authorised staff can view location data, and automated retention rules that delete data on schedule.

For fleets running HGVs, the Teltonika FMC650 with Fleetalyse’s PAYG platform pairs compliant hardware with the access controls your DPIA will call for. Mixed fleets and vans are covered by the Teltonika FMC920, plug-and-play units that don’t need a professional install. If you’re ready to move from policy draft to working system, request a demo through Fleetalyse and ask about a compliance pack tailored to your fleet size.
Where to check the primary rules and templates
For the legal text itself, go to legislation.gov.uk’s UK GDPR page and cross-reference it with ICO guidance on surveillance in vehicles for DPIA expectations. For penalty structures, GOV.UK’s fining guidance sets out current thresholds. Montracon’s published policy example offers a useful drafting reference for clause structure.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Surveillance in vehicles — ICO
- Legislation
- Vehicle Monitoring and Tracking Policy (example) — Montracon
- Can a vehicle tracker be used in a disciplinary? — Davidson Morris
