Tracking vehicles, monitoring drivers, and the line between them
Vehicle location becomes personal data the moment it identifies a driver. The obligations that follow are specific and manageable, but they are not optional.
A tracker on a company van reports where a vehicle is. Where the system also identifies who is driving, whether by RFID card, iButton, BLE tag or app sign-in, the processing concerns an identifiable person and the GDPR applies to it in full. This is the point most deployments get wrong, because driver ID is usually added later and the paperwork is not revisited.
The governing principles are necessity and proportionality. Processing must be limited to what is necessary for the purpose, and the purpose has to be specified in advance. Continuous monitoring of all vehicle activity, including outside working hours, is difficult to justify against a purpose like route efficiency or asset security. Narrower configurations are easier to defend: recording during working hours only, or attributing trips to a driver without scoring behaviour.
A data protection impact assessment is the practical instrument here. Systematic monitoring of employees appears on the categories of processing that the Information and Data Protection Commissioner, Malta's supervisory authority, identifies as likely to require one. Carrying out a DPIA before deployment is far less work than reconstructing the reasoning after a complaint.
Transparency is the other half. Drivers need to be told what is collected, why, how long it is kept and who sees it, in terms they can actually understand. A clause buried in a contract of employment is weak evidence of that.
On the technical side, the platform holds data on EU servers, encrypts in transit with TLS 1.3 and at rest with AES-256, and sets location history retention by contract, typically around five years. Retention is configurable, which matters in both directions, because keeping data longer than the stated purpose requires is itself a compliance problem rather than a safety margin.
This briefing describes the framework. It is not legal advice, and the specific configuration a controller can justify depends on their own purposes and workforce arrangements. Take advice on those.
Sources
- Regulation (EU) 2016/679, General Data Protection Regulation · EUR-Lex, European Union · checked 2026-08-13
- Information and Data Protection Commissioner · Government of Malta · checked 2026-08-13
Last updated .