In the UK, vehicle trackers are lawful when the controller identifies and documents a valid lawful basis, often legitimate interests or legal obligation for businesses, and meets UK GDPR transparency and DPIA duties. Unauthorised tracking of someone else’s vehicle, or covert constant monitoring of employees with no justification, is likely unlawful. The immediate next step for any fleet or private owner is to pause deployment until the lawful basis and transparency measures are written down.
TL;DR:
- Vehicle owners must provide specific transparency, including purpose, data retention, and contact details, through written notices and signage.
- Legitimate interests or legal obligations, not consent, usually justify lawful vehicle tracking in the UK, requiring proper documentation and a Legitimate Interests Assessment.
- Inward-facing cameras, audio recording, or continuous monitoring trigger mandatory DPIAs to ensure proportionality and privacy safeguards.
- Data collection should be minimized and retained only as long as necessary, with security measures like encryption, access restrictions, and automatic deletion schedules.
- Using certified trackers with established standards from Thatcham Research simplifies insurer approval and ensures compliance with both security and data protection requirements.
Table of Contents
- When and how to inform vehicle owners, drivers and passengers
- Choosing and documenting the lawful basis: consent, legitimate interests and legal obligation
- DPIA and proportionality: when tracking counts as high risk
- Data minimisation, retention schedules and security controls for tracker data
- Third-party providers: contracts, processor duties and due diligence
- Cameras and dashcams: audio, inward-facing systems and higher-risk monitoring
- Step-by-step vehicle-tracking policy and compliance checklist to adopt today
- How Thatcham Research certification relates to privacy-compliant tracking
- Balancing security and privacy in vehicle tracking
- Get insurer-approved tracking without the compliance guesswork
- Sources
- FAQ
When and how to inform vehicle owners, drivers and passengers
Ownership is the starting point. A tracker cannot lawfully be fitted to a vehicle someone else owns without their agreement or another clear legal basis, whatever the reason for wanting to fit one.
Once ownership or authority is settled, the privacy information given to drivers must be specific. It should state the purpose of tracking, how long data is kept, who receives it and how to contact the controller. Written notice plus in-vehicle signage covers most situations.
Company cars, leased vehicles and personal cars used occasionally for work all need separate treatment, since the balance between employer interest and personal privacy shifts with each.
- State the purpose, retention period, recipients and controller contact details in writing.
- Use in-vehicle signage for any vehicle with fitted cameras or continuous monitoring.
- Keep a record of when notices were issued and to whom.
- Set out a clear process for mixed-use vehicles, including how private journeys are handled.
Choosing and documenting the lawful basis: consent, legitimate interests and legal obligation
Employee “consent” is rarely valid in this context. The ICO’s guidance on monitoring workers points out the imbalance in the employment relationship, meaning employers usually need to rely on legitimate interests or a legal obligation instead, backed by documentation.
Legitimate interests requires a Legitimate Interests Assessment, a three-part test businesses should record in full:
- Purpose: state exactly why tracking is needed, such as route planning or theft recovery.
- Necessity: show that tracking is the least intrusive way to meet that purpose.
- Balancing: weigh the business’s interest against the individual’s privacy rights.
Legitimate interests tends to succeed for route planning and theft prevention. It tends to fail for continuous behavioural monitoring or inward-facing cameras used routinely. Some sectors, such as haulage with tachograph rules, have a legal obligation basis instead.
Pro Tip: Write the LIA before the tracker is fitted, not after a complaint arrives.
DPIA and proportionality: when tracking counts as high risk
Some setups tip tracking into high-risk territory: inward-facing cameras, audio recording, 24/7 continuous monitoring or behavioural profiling and analytics. Under ICO guidance on surveillance in vehicles, any of these triggers a Data Protection Impact Assessment.
A compliant DPIA sets out the scope of processing, the data flows involved, the risks to individuals’ privacy, the mitigations applied, the alternatives considered and the residual risk once mitigations are in place.
- Log only geofence entry and exit rather than continuous GPS points where that meets the purpose.
- Disable tracking during confirmed private use.
- Fit a driver-operated privacy switch so location logging can be paused outside working hours.
- Review and update the DPIA whenever the technology or the purpose changes.
Pro Tip: A privacy switch is one of the simplest ways to satisfy the proportionality test the ICO expects.
Data minimisation, retention schedules and security controls for tracker data
Precise location data counts as personal data under the Data Protection Act 2018 whenever it can identify an individual, so collection should be limited to what the stated purpose actually needs.
Retention needs a documented reason, not a default setting. The ICO’s dashcam guidance for small organisations notes that many small businesses using tracking or dashcam footage must register with the ICO and pay the data-protection fee, and must be ready to handle subject access requests within statutory time limits.
- Set a retention band for each type of data and record why that period was chosen.
- Encrypt data both in transit and at rest.
- Restrict access to named staff with a business need.
- Log access and delete data automatically once the retention period ends.
- Maintain a written incident-response plan covering breaches involving location data.
Third-party providers: contracts, processor duties and due diligence
Using an external tracking vendor does not shift responsibility away from the business. Under ICO guidance on controllers and processors, the business will usually remain the controller and carries ultimate accountability for how the data is handled.
Contracts with providers should specify the purpose of processing, security standards, sub-processing arrangements, deletion timescales and audit rights.
- Ask suppliers for evidence of security certification such as ISO 27001 before onboarding.
- Require written instructions covering exactly how tracking data may be used.
- Flag any provider running analytics or AI models on the data and demand documented safeguards.
- Review supplier contracts on a fixed schedule, not only when problems arise.
Cameras and dashcams: audio, inward-facing systems and higher-risk monitoring
Inward-facing cameras and audio recording raise the risk level noticeably, and audio should stay off by default and only activate in exceptional, clearly justified circumstances.
Where cameras are fitted, signage and privacy notices need to account for passengers and other third parties who may be recorded, not just the driver. Footage retention should follow the same documented schedule as other tracking data, and a DPIA is expected wherever continuous recording is involved.
- Use triggered recording linked to an event, rather than routine continuous capture.
- Apply privacy zones or masking where cameras might capture private premises.
- Anonymise footage before sharing it beyond the incident investigation team.
- Keep footage only as long as an investigation or insurance claim requires.
Step-by-step vehicle-tracking policy and compliance checklist to adopt today
A written policy turns scattered good intentions into something the ICO, insurers and staff can all check against.
- State the purpose of tracking and the lawful basis relied on.
- Set a retention schedule for each data type collected.
- Summarise the DPIA outcome and any mitigations applied.
- Explain the transparency measures given to drivers and passengers.
- Document the opt-out or private-use process, including any privacy switch.
- List vendor contract terms and the audit schedule.
| Policy item | What it should record |
|---|---|
| Lawful basis | Purpose, necessity and balancing test outcome |
| Retention schedule | Data type, retention period, justification |
| Transparency | Notice format, signage, distribution record |
| Private use | Opt-out method, privacy switch, review cadence |
| Vendor oversight | Contract terms, audit dates, security evidence |
How Thatcham Research certification relates to privacy-compliant tracking
Thatcham Research’s S5 and S7 certification sets out tamper resistance, roaming SIM connectivity and 24/7 monitoring compatibility. These features insurers rely on to assess theft risk. Thatcham S5 devices also include driver identification, which supports a theft-prevention justification for tracking.
Certification says nothing about data protection on its own. Transparency, a documented lawful basis and a DPIA where needed still sit alongside the hardware standard, not underneath it. Compliant, insurer-approved trackers and professional fitting are available through Thatcham Trackers.
Balancing security and privacy in vehicle tracking
Some providers pair certified hardware with the expectation that buyers document their DPIA and transparency measures properly. Lawful, proportionate tracking protects drivers and supports insurers at the same time, not one at the expense of the other. When a case feels unclear, the right move is to check ICO guidance or speak to a legal adviser before fitting anything.
— Thatcham Trackers
Get insurer-approved tracking without the compliance guesswork
Certified devices built to recognised standards are available, each accepted by UK insurers and issued with a digital certificate on fitting. Pairing a certified tracker with the compliance checklist above covers both the insurer’s security requirement and the data-protection paperwork in one pass.
![]()
- Thatcham S7 trackers for straightforward insurer acceptance.
- Thatcham S5 and Thatcham S5 Plus for higher specification cover.
- Casper Ghost-Like Immobiliser options for added tamper prevention.
Fitting can be carried out by accredited engineers. Consult product providers for advice on matching devices to your policy and documentation.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
FAQ
Is it illegal to put a tracker on a car in the UK?
It depends on ownership and purpose. Fitting a tracker to your own vehicle is generally lawful provided you meet UK GDPR duties, but fitting one to a vehicle you do not own, without agreement or another lawful basis, is likely to breach the Data Protection Act 2018.
Is it illegal to track someone without consent in the UK?
Tracking another adult without their knowledge or a lawful basis raises serious legal risk, including under data protection law and potentially harassment law. Employers specifically cannot rely on consent alone in most cases, according to ICO guidance on monitoring workers, and should document legitimate interests or a legal obligation instead.
Can a company use a vehicle tracker to spy on you?
A company must have a documented lawful basis, give drivers clear transparency information and complete a DPIA when monitoring is continuous or covers private use, as set out in ICO guidance on vehicle surveillance. Tracking that goes beyond the stated business purpose, or that ignores private-use periods, moves outside what the law allows.
Can someone track your car without you knowing?
Covert tracking without a lawful basis or proper notice is unlikely to comply with UK data protection law, since transparency to the individual is a core requirement. If you suspect unauthorised tracking, the ICO is the right body to raise a complaint with.
