Vehicle tracking is lawful under UK GDPR and the Data Protection Act 2018, provided the monitoring is necessary, proportionate and disclosed to staff. A compliant company vehicle tracking policy needs a documented lawful basis, a clear privacy notice, private-use rules, and a Data Protection Impact Assessment (DPIA) wherever the system carries higher risk, such as audio or video capture. The sections below turn those requirements into a working checklist HR can build a policy around.
TL;DR:
- Using vehicle tracking in the UK requires a documented lawful basis, either legitimate interests or legal obligation, supported by a risk assessment and staff disclosure.
- High-risk monitoring features like audio, video, or continuous recording mandate a mandatory Data Protection Impact Assessment and strict mitigation measures such as default audio deactivation.
- Location data should be minimized outside work hours through reduced precision, geofenced private modes, or manual disables to avoid undue privacy intrusion.
- Data used for disciplinary purposes must have been lawfully collected and clearly linked to the original purpose, with proper disclosure and corroboration to avoid legal risks.
- Policies should define scope, retention, access controls, purpose, private-use rules, and staff rights, and require supplier contracts to specify data handling, security, and deletion obligations.
Table of Contents
- Lawful basis and legal framework for tracking company vehicles
- When do you need a DPIA for vehicle tracking?
- What data can you collect, and where’s the line on private use?
- Can you use vehicle tracking data in a disciplinary?
- What must a company vehicle tracking policy include?
- How should you govern access, retention and ICO registration?
- How do you communicate tracking to drivers and roll it out fairly?
- What should you check in supplier and processor contracts?
- Practical examples and where Thatcham Trackers fits
- Fitting insurer-approved hardware into your compliant policy
- Sources
- FAQ
Lawful basis and legal framework for tracking company vehicles
There is no single “vehicle tracking law” in the UK. Instead, a company vehicle tracking policy sits at the crossroads of the Data Protection Act 2018, UK GDPR, the Human Rights Act 1998, and general employment law. Get the lawful basis wrong and every downstream use of the data, from route planning to disciplinary evidence, becomes shaky ground.
Most employers rely on one of two lawful bases. Legitimate interests covers routine operational tracking: route optimisation, fuel management, vehicle recovery, and driver safety. Legal obligation applies where drivers’ hours or tachograph rules require monitoring, common in haulage and passenger transport. Consent rarely works here. The ICO is clear that consent is inappropriate in most employment monitoring because the power imbalance between employer and employee means consent is rarely freely given, and an employee cannot meaningfully refuse without risking their job.
If legitimate interests is the chosen basis, you need a documented Legitimate Interests Assessment (LIA), not just a line in the handbook asserting it. That assessment should record:
- The specific purpose (theft prevention, route efficiency, duty-of-care safety checks).
- Why tracking is necessary to achieve that purpose, and whether a less intrusive method exists.
- The balancing test weighing business need against the employee’s reasonable expectation of privacy.
The Human Rights Act adds another layer. Article 8 protects a right to private life, and courts have found that this extends into the workplace, particularly where a vehicle is used for both work and personal journeys. Employers who ignore this and track indiscriminately, including during clearly private time, expose themselves to challenge. On the employment side, the ACAS code of practice on disciplinary and grievance procedures sets a fairness floor that applies the moment tracking data feeds into any staff-facing decision, not just formal disciplinaries.
Keep every assessment on file. ICO investigations and employment tribunals both ask for evidence of reasoning, not just outcome, and a business that cannot show its balancing test starts any dispute on the back foot.
When do you need a DPIA for vehicle tracking?
A DPIA becomes mandatory, not optional, once vehicle monitoring is likely to result in high risk to employees’ rights. ICO guidance on surveillance in vehicles sets the trigger points plainly: audio recording, inward-facing cameras, behavioural analytics, and continuous monitoring that captures third parties such as passengers or members of the public.
Basic GPS location tracking for route logging carries lower risk and may not need a full DPIA, but the moment you add a dashcam, telematics scoring, or always-on audio, the assessment stops being a nice-to-have.
Run the DPIA in this order:
- Describe the processing. What data, from which devices, held for how long, accessed by whom.
- Assess necessity and proportionality. Could a less invasive method achieve the same business goal?
- Identify risks to individuals. Function creep, third-party capture, chilling effect on private journeys.
- List mitigations. Private-mode switches, audio disabled by default, encrypted storage, defined retention periods.
- Document the decision. Record who approved it and on what basis, dated and version-controlled.
The most common mitigation the ICO recommends is switching audio off by default and only activating it in exceptional, clearly justified circumstances. Continuous audio recording in a work vehicle is one of the fastest ways to turn a routine tracking policy into a data-protection liability.
Pro Tip: Treat the DPIA as a living document, not a one-off exercise. Revisit it whenever you add a new device feature, change data retention settings, or extend tracking to a new fleet category.
What data can you collect, and where’s the line on private use?
Location logs, timestamps, speed readings and diagnostic events form the backbone of most fleet tracking, and none of it needs to be intrusive if you scope it correctly, as detailed in this practical business guide. Audio and video sit in a different category entirely and demand a much stricter justification before they’re switched on.
The ICO’s monitoring-workers guidance is blunt about minimisation: don’t monitor “just in case.” Every data point collected should trace back to a documented purpose. If you can’t explain why you need second-by-second GPS precision outside working hours, you shouldn’t be collecting it.
Practical ways to draw the work/private boundary:
- Reduce GPS precision or sampling frequency outside declared working hours.
- Build a geofenced “private mode” the driver can activate for personal errands.
- Offer a manual disable switch where the vehicle is used for both business and private mileage.
- Cap retention on granular trip data separately from summary mileage records.
A dual-mode setup works well in practice: full-resolution tracking during working hours, reduced-resolution or off entirely once the driver logs out or the vehicle re-enters a private-use window. The ICO has flagged this kind of business/private split as a sensible mitigation rather than an optional extra.
What to avoid: continuous audio capture, GPS precision far beyond what the stated purpose needs, and tracking that continues once a vehicle is confirmed to be on a private journey. Each of these is exactly the kind of “high risk, low justification” processing that draws ICO scrutiny and employee grievances alike.
Can you use vehicle tracking data in a disciplinary?
Yes, but only if the collection was lawful in the first place and the use is compatible with the purpose you originally told staff about. A legal review of vehicle tracker use in disciplinaries makes clear that lawful collection does not automatically mean lawful use for every purpose you might later think of.
If the policy states tracking exists for fuel management and route safety, and you then use the same data to build a disciplinary case about unauthorised stops, you’ve shifted purpose. That shift needs re-notification to staff and a fresh look at your lawful basis, not silent repurposing.
Where tracking data does feed into a disciplinary, follow these steps:
- Disclose the specific data relied on to the employee before any hearing, not during it.
- Explain the system’s limitations honestly. GPS drift, signal loss near buildings, and timestamp gaps are real and courts expect employers to acknowledge them.
- Corroborate tracker data with other evidence, such as delivery logs, timesheets, or manager observations, rather than treating GPS output as the sole determinant.
- Follow the ACAS code of practice at every stage: investigation, disclosure, right to be accompanied, and appeal.
Relying on tracker data as the only evidence in a dismissal case is a risky strategy. Tribunals routinely ask about data provenance, so keep a technical log of device ID, firmware version, and time-synchronisation records to answer reliability challenges before they’re raised.
What must a company vehicle tracking policy include?
A workable policy template needs roughly eleven building blocks, and most employers get through them faster than they expect once the legal groundwork above is settled.
- Purpose statement. Why tracking exists (safety, theft recovery, route efficiency, legal compliance).
- Scope. Which vehicles, which employees, and whether personal-use vehicles used for work are covered.
- Device types. GPS trackers, dashcams, telematics units, and whether audio or camera features are active.
- Lawful basis. Legitimate interests or legal obligation, with a reference to the LIA on file.
- DPIA summary. A short pointer to the full assessment, not the whole document reprinted in the handbook.
- Permitted uses. What the data will and won’t be used for, stated precisely.
- Private-use rules. How employees switch to private mode and what stops being recorded.
- Retention periods. How long each data category is kept, and why.
- Access controls. Who can view raw tracking data, and under what approval process.
- Disciplinary process reference. A link to how tracking data may feed into investigations, cross-referenced with the disciplinary policy.
- Rights and contacts. How employees exercise subject access requests and who to contact with concerns.
On retention, most fleet policies keep granular GPS trip data for 30 to 90 days for operational use, with summary mileage records held longer for tax or insurance purposes. Set the shorter figure as default and only extend it where you can justify the operational or legal need. Reference your DPIA and data-flow map directly in the policy rather than duplicating the analysis.
Fold the policy into the employee handbook and, where tracking is a condition of using a company vehicle, reference it in the contract of employment. Sign-off should sit with HR, data protection lead, and fleet management jointly, since each sees a different risk angle.
Pro Tip: Draft the policy in plain English first, then have your data protection lead cross-check it against the DPIA. A policy nobody on the shop floor can understand is a policy nobody follows.
If audio or camera features are in play, the dashcam laws guide is worth reading alongside this checklist, since dashcam footage carries its own data-protection expectations around retention and third-party capture.
How should you govern access, retention and ICO registration?
Access to tracking data should be role-based, not “whoever asks.” Fleet managers might see live location and route history; HR should only see data relevant to an active, disclosed process; and raw logs shouldn’t be exportable without an audit trail recording who accessed what and when.
Build in periodic access reviews, ideally quarterly, to catch permissions that have drifted since the last audit. A driver who left the fleet team eighteen months ago still having dashboard access is a common finding in ICO enforcement cases.
On technical controls:
- Encrypt data both in transit and at rest.
- Automate deletion workflows so retention limits are enforced by the system, not by someone remembering to run a manual purge.
- Check supplier SLAs cover breach notification timeframes, not just uptime.
- Confirm backups follow the same retention limits as live data, since a forgotten backup that outlives the stated retention period breaches your own policy.
Most businesses running cameras or tracking systems that process personal data also need to register with the ICO and pay the annual data protection fee, which for most small businesses is £52 in 2026. Check your registration status using the ICO’s online fee checker rather than assuming an existing entry covers new tracking activity, since adding cameras or telematics to a previously simple registration can change which tier applies.
How do you communicate tracking to drivers and roll it out fairly?
Staff need to know about tracking before it starts, not after. A written notice, distributed through the handbook, email, and a signed acknowledgement, should cover what’s tracked, why, how long it’s kept, and how to raise concerns. Verbal mentions in a team meeting don’t count as documented transparency.
In-cab signage matters too, particularly where audio or camera features are fitted. A simple notice on the sun visor or dashboard stating that the vehicle is fitted with tracking and, where relevant, recording equipment, meets the spirit of transparency requirements and reassures passengers or third parties who might otherwise be recorded unknowingly.
A practical rollout runs in stages:
- Pilot with one depot or team to catch operational issues before wider deployment.
- Consult employee representatives or, where present, trade union officials, particularly if the change is significant enough to affect terms of use of a company vehicle.
- Full roll-out with manager training so line managers can answer driver questions accurately rather than guessing.
- Review after three to six months, checking whether the policy is working as intended and whether any purpose has quietly shifted.
Manager training should specifically cover what tracking data can and cannot be used for, since an untrained manager threatening disciplinary action based on a misread GPS log is exactly the kind of incident that ends up at tribunal.
What should you check in supplier and processor contracts?
Your tracking provider is a data processor, and UK GDPR makes you responsible for their compliance as much as your own. Before signing, the contract needs clear processing instructions, defined security measures, a list of any sub-processors, audit rights, and firm deletion and breach-notification obligations.
Technically, verify encryption standards, how long the supplier itself retains logs, whether they can prove deletion when asked, and whether data resides in the UK where that matters for your sector. A guide to commercial vehicle tracker differences is a useful starting point for comparing device and data-handling capabilities across providers.
During procurement, ask for independent assurance evidence rather than taking marketing claims at face value, and run a short checklist covering each contract clause above before committing. A supplier who can’t answer basic questions about deletion proof or sub-processor lists is a compliance risk you’re inheriting, not just a vendor choice.
Practical examples and where Thatcham Trackers fits
Insurer-approved trackers exist for a narrower purpose than most HR policies cover: theft prevention and vehicle recovery, verified against Thatcham Research’s own certification standards. That purpose is usually low-risk and easy to justify under legitimate interests, which makes it a sensible starting point for employers building a policy from scratch.
Thatcham Trackers’ GDPR guidance for fleet managers and installation resources sit alongside this checklist for teams working through their own DPIA and supplier assessment.
— Thatcham Trackers
Fitting insurer-approved hardware into your compliant policy
Once your DPIA and lawful basis are documented, the hardware decision becomes far simpler. Suppliers offer insurer-approved S7, S5 and S5+ devices with a mandatory digital certificate required by UK insurers, supporting the theft-prevention purpose with hardware designed to meet certification standards rather than generic trackers retrofitted to the job.
![]()
For fleets and individual company vehicles alike, browsing the Thatcham-approved tracker range shows the practical difference between certification tiers, from the S7 through to the S5 Plus, alongside Ghost immobilisation for vehicles needing a higher security tier. Mobile installation options help minimise disruption to fleet schedules compared to traditional workshop bookings.
Before ordering, check the device’s data-handling features against your DPIA and supplier-contract checklist covered above, particularly retention settings and access logging. If those line up, view the Thatcham S5 tracker or the S7 range to compare specifications and get a quote for installation.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Data protection and monitoring workers | ICO
- Can a vehicle tracker be used in a disciplinary? | DavidsonMorris
- ACAS code of practice on disciplinary and grievance procedures
FAQ
Can you refuse a tracker on a company car?
Employees generally can’t refuse tracking on a vehicle owned by the employer if it’s a lawful, disclosed condition of using that vehicle, though they can raise objections through the concerns process the policy should include. Where the vehicle is genuinely mixed-use, private-mode options should address most objections.
Can my employer track my company car?
Yes, provided the employer has a documented lawful basis such as legitimate interests, has told staff clearly how and why tracking happens, and has run a DPIA where the monitoring is high risk. Tracking without transparency or a documented basis falls short of ICO requirements.
What are the legal requirements for using company vehicle trackers?
Employers need a documented lawful basis, a privacy notice explaining the monitoring, a DPIA for higher-risk features like audio or cameras, and disciplinary use that stays compatible with the original stated purpose under the ACAS code.
What are the GDPR requirements for a vehicle tracking policy?
A GDPR-compliant policy documents necessity and proportionality, avoids relying on consent, sets clear retention limits, restricts access on a role basis, and updates staff notification if the purpose of tracking changes. Insurer-approved hardware, such as the devices reviewed in the Thatcham-approved range, can support the theft-prevention purpose specifically, but doesn’t replace the wider policy documentation.
How do you handle a subject access request for tracking data?
Employees can request their own tracking data under a data subject access request, and employers must respond within the standard statutory timeframe, providing the location, timestamp and related records held about that individual unless a specific exemption applies.