Car tracker location data can be processed lawfully in the UK — but only if you have a valid lawful basis under UK GDPR and you meet the obligations set out in the Data Protection Act 2018 and ICO guidance. For most fleet managers and vehicle owners, that lawful basis will be legitimate interests. For private individuals fitting a tracker to their own vehicle, it may be consent. Either way, you cannot simply install a device and start collecting location data without a compliance framework in place.
Your three immediate obligations are:
- ✅ Identify your lawful basis before the tracker goes live (legitimate interests, consent, or contract necessity in limited cases)
- ✅ Carry out a Data Protection Impact Assessment (DPIA) if the system is likely to be intrusive to driver rights
- ✅ Tell drivers and vehicle users what data is collected, why, for how long, and how they can exercise their rights
Pro Tip: If you are unsure whether your current tracker deployment is compliant, the fastest first step is to open a DPIA template and work through the purpose, the data flows, and the risks. You do not need a lawyer to start — you need a clear record.
Key takeaways
Car tracker location data is lawful in the UK only when you have a documented lawful basis, a completed DPIA for high-risk systems, and transparent communication with every driver whose data you collect.
| Point | Details |
|---|---|
| Lawful basis is mandatory | Identify legitimate interests, consent, or contractual necessity before any tracker goes live. |
| DPIA required for continuous tracking | Document purpose, data flows, risks, and mitigations — and keep the DPIA updated when systems change. |
| Transparency with drivers is non-negotiable | Issue a written policy, in-vehicle notice, and app privacy screen before the first journey is recorded. |
| Retention and deletion must be scheduled | Set defined retention periods by data type and wipe all data when a vehicle changes hands. |
| Lrd-track provides Thatcham-certified compliance support | Professionally installed, insurance-approved trackers with driver ID and documented security reduce your compliance burden. |
Table of Contents
- 1. What lawful basis applies to car tracker data privacy — and when is a DPIA required?
- 2. Telling drivers and employees: what you must communicate and when
- 3. What tracker data you can collect: types, sensitivity and proportionality
- 4. Handling mixed-use fleets and employee-owned vehicles
- 5. How to write a legally compliant vehicle-tracking policy
- 6. Sharing tracker data with third parties and contractual safeguards
- 7. Retention, deletion and steps to take when a vehicle changes hands
- 8. Security controls and privacy-by-design measures
- 9. Responding to data subject requests: access, erasure, restriction and objections
- 10. ICO enforcement, likely penalties and practical regulatory risks
- 11. Your step-by-step compliance checklist and 30-day action plan
- 12. What to ask a Thatcham-approved tracker supplier before you sign
- Lrd-track: Thatcham-approved tracking with compliance built in
- Sources
1. What lawful basis applies to car tracker data privacy — and when is a DPIA required?
ICO guidance on surveillance in vehicles confirms that vehicle tracking is lawful where the controller identifies a clear lawful basis and that a DPIA is required for systems likely to be intrusive to driver rights. That is the starting point for every fleet operator, business owner, and Land Rover owner fitting a professional tracker.
The three most common lawful bases
Legitimate interests is the most widely used basis for fleet and security tracking. You must complete a three-part test: identify a legitimate interest (vehicle security, fleet management, insurance compliance), show the processing is necessary for that interest, and balance it against the driver’s rights. The ICO is clear that legitimate interests is not an open licence to monitor employees — you must separate security purposes from behavioural monitoring and document your justification.
Consent applies when you are tracking a vehicle for purposes that go beyond what a driver would reasonably expect, or when the vehicle is privately owned and the driver is not your employee. Consent must be freely given, specific, informed, and withdrawable without detriment. For employer-employee relationships, the ICO treats consent with scepticism because of the power imbalance — it is rarely the right basis for workplace tracking.
Contractual necessity covers a narrow set of cases: for example, where a lease agreement or insurance policy explicitly requires location tracking as a condition of cover. Even then, you must still meet transparency obligations.
| Lawful basis | Typical use case | Key limit |
|---|---|---|
| Legitimate interests | Fleet security, theft recovery, insurance compliance | Must pass three-part balancing test; cannot override driver rights |
| Consent | Private vehicle owner; non-employee passengers | Must be freely given and withdrawable; not appropriate for employees |
| Contractual necessity | Insurer-mandated tracking; lease conditions | Narrow scope; does not remove transparency duties |
When is a DPIA legally required?
A DPIA is required before you deploy any tracking system that is likely to result in high risk to individuals. Continuous GPS location tracking almost always meets that threshold. The ICO expects you to document why less intrusive measures — alarms, immobilisers, geofencing alerts — are insufficient for your stated purpose, and to record that a legitimate interest balancing exercise has been carried out.
Your DPIA must cover: the scope and purpose of processing; the data flows (device, cloud platform, third parties); the risks to drivers; the mitigations you will apply; and evidence that you consulted affected individuals or their representatives where practicable.
Pro Tip: Keep your DPIA as a living document. If you change tracker supplier, add a new data feed, or extend monitoring to personal journeys, update the DPIA before the change goes live — not after.
2. Telling drivers and employees: what you must communicate and when
ICO guidance is explicit: businesses using vehicle surveillance must provide clear privacy information, and individuals can request access to their location data or deletion, subject to legal retention obligations. Transparency is not optional — it is a legal requirement under UK GDPR Article 13.
What you must tell drivers
Every person whose location data is collected must receive the following before tracking begins:
- ✅ The identity and contact details of the data controller (your organisation)
- ✅ The purpose of the tracking and the lawful basis you are relying on
- ✅ How long location data is retained and the criteria used to set that period
- ✅ Who receives the data (monitoring centre, insurer, recovery service, law enforcement)
- ✅ Their rights: access, erasure, restriction, and the right to object
- ✅ How to raise a query or complaint, including the ICO’s contact details
- ✅ Whether data is transferred outside the UK and the safeguards in place
How and when to deliver this information
A written vehicle-tracking policy, issued at onboarding and reviewed annually, is the minimum. For employees, include it in the employment contract pack or a standalone monitoring policy. For fleet vehicles used by contractors or agency staff, issue it before the first journey.
Physical in-vehicle notices matter too. A small, durable sticker near the dashboard or sun visor — stating “This vehicle is fitted with a GPS tracker for security purposes. See [policy URL] for details” — satisfies the layered notice requirement and reduces the risk of a driver claiming they were unaware. App-based privacy screens, shown at first login to any companion app, should repeat the key points.
Pro Tip: Place your in-vehicle notice where it is visible to the driver before they start the engine — not in the glovebox. The ICO expects notices to be ‘just in time’, not buried in a document the driver may never read.
3. What tracker data you can collect: types, sensitivity and proportionality
Not all tracker data carries the same privacy weight. Understanding what you are collecting — and whether you actually need it — is where most compliance failures begin.
Common data types and their risk level
Real-time GPS location is the core output of any tracker. Historical journey records (origin, destination, route, timestamps) are higher risk because, as EDPB Guidelines 01/2020 warn, continuous collection of location data can reveal sensitive information about a person’s life: medical appointments, religious attendance, political activity, relationships. That is not an abstract concern — it is a documented regulatory risk.
Driver identification data (tokens, PIN codes, biometric recognition) is higher risk still. Biometric data is a special category under UK GDPR and requires explicit consent or another Article 9 condition. Speed and acceleration telemetry, when combined with location, can reveal potential traffic offences — another category requiring careful handling.
Proportionality in practice
Collect only what your stated purpose genuinely requires. A theft-recovery tracker needs real-time location on demand and perhaps a motion alert — it does not need continuous second-by-second telemetry or detailed driving-style scores unless your insurer specifically requires them. If your purpose is fleet management, journey-level summaries may be sufficient rather than granular route data.
The EDPB’s connected vehicles guidance recommends preferring local in-vehicle processing over external cloud processing, and advises that tracking activation should not be set as default. Where data can be processed on-device and only aggregated results transmitted, that is the privacy-preserving approach. Raw sensitive telemetry should not leave the vehicle unless there is a clear, documented reason.
Pro Tip: Before your next tracker renewal, list every data field your platform currently collects and ask: “Which of these do we actually use?” Fields you cannot justify should be switched off at the platform level, not just ignored.
4. Handling mixed-use fleets and employee-owned vehicles
When a vehicle is used for both business and personal journeys, the privacy stakes rise sharply. Tracking a driver’s personal errands, weekend trips, or medical appointments is disproportionate and likely unlawful unless you have a very specific justification.
Policy controls for mixed-use vehicles
A clear written policy must state exactly when tracking is active. The most common approach is a private mode toggle — a physical button, driver ID token, or in-app switch that suspends location reporting during personal use. The policy should specify:
- ✅ How to activate and deactivate private mode
- ✅ That the employer will not access location data recorded during private use
- ✅ What happens if the private mode function fails (data should be deleted, not reviewed)
- ✅ How long private-journey data is retained before automatic deletion
Employee-owned vehicles (grey fleet)
If an employee uses their own vehicle for work, your organisation becomes a data controller for the location data collected during business journeys. You must issue a privacy notice, limit tracking strictly to working hours, and give the employee a straightforward way to verify that personal journeys are not being recorded.
Driver ID tokens — a physical fob or app-based credential that the driver presents before a business journey — are the cleanest technical control. They create a clear audit trail showing which journeys were business-related and which were not. The S5 tracker with driver ID is one example of a professionally installed system that supports this kind of credential-based journey separation.

Employee rights in a mixed-use context include: the right to access their own journey data, the right to object to processing of personal journeys, and the right to request deletion of any data collected outside business hours. Document how you will respond to each of these in your policy.
5. How to write a legally compliant vehicle-tracking policy
A vehicle-tracking policy does not need to be long. It needs to be complete, accurate, and accessible to the people it covers.
What your policy must include
- ✅ Purpose statement: why you use tracking (security, theft recovery, fleet management, insurance compliance)
- ✅ Lawful basis: which basis you rely on and a brief explanation of the balancing test if using legitimate interests
- ✅ Data types: what is collected (location, timestamps, driver ID, telemetry) and what is not
- ✅ Retention period: how long data is kept and the criteria for that period
- ✅ Recipients: who receives data (monitoring centre, insurer, recovery service, law enforcement on request)
- ✅ Security measures: encryption, access controls, audit logging
- ✅ Rights procedures: how drivers submit access requests, erasure requests, or objections, and your response timescale
- ✅ Complaints: ICO contact details and your internal escalation route
Legal compliance checklist
| Item | Why it is required | Responsible party |
|---|---|---|
| DPIA completed and signed off | UK GDPR — high-risk processing | Data Protection Officer / senior management |
| Record of Processing Activities (Article 30) | UK GDPR / Data Protection Act 2018 | Data controller |
| Privacy notice issued to all drivers | UK GDPR Articles 13 and 14 | HR / fleet manager |
| Legitimate interest assessment documented | ICO guidance on lawful basis | Data Protection Officer |
| Data Processing Agreement with tracker supplier | UK GDPR Article 28 | Procurement / legal |
| Retention schedule reviewed and applied | UK GDPR Article 5(1)(e) | IT / fleet manager |
| Incident response procedure in place | UK GDPR Article 33 | Data Protection Officer |
For consent-based processing, add a consent management clause: record when consent was given, the exact wording used, and the mechanism for withdrawal. Store this record separately from the tracking data itself so it survives any data deletion request.
For employee-owned vehicles, add a clause confirming that tracking is limited to business journeys, that private mode is available, and that the employee has been issued a privacy notice specific to grey-fleet use.
6. Sharing tracker data with third parties and contractual safeguards
Every time tracker data leaves your systems — to a monitoring centre, an insurer, a recovery service, or a law enforcement body — you need a legal basis for that transfer and, in most cases, a written contract.
Data Processing Agreement checklist
When your tracker supplier or monitoring service processes data on your behalf, they are a data processor under UK GDPR Article 28. Your contract must cover:
- ✅ Subject matter and duration of processing
- ✅ Categories of personal data and data subjects
- ✅ Security measures the processor will apply
- ✅ Subprocessors: who they are, where they are based, and your right to object
- ✅ International transfers: if data leaves the UK, the transfer mechanism (adequacy decision, standard contractual clauses)
- ✅ Audit rights: your right to inspect or request evidence of compliance
- ✅ Breach notification: the processor must notify you without undue delay
Sharing with insurers and recovery services
When an insurer or recovery service requests location data, share only what is strictly necessary for the specific purpose. A theft-recovery query does not require six months of journey history — it requires the current or last-known location. Prefer aggregated driving scores to raw telemetry when insurers request behavioural data.
Pro Tip: Ask your tracker supplier whether they hold a Thatcham or insurance-approved certification and request a copy of their security documentation. Thatcham certification — the standard recognised by UK insurers — is evidence that the hardware and monitoring infrastructure meet a defined security baseline. This documentation supports your DPIA and your contractual due diligence.
Law enforcement requests sit outside the standard data-sharing framework. You are not required to share data without a lawful authority (a court order, production order, or statutory power). Keep a log of every law enforcement request, the authority cited, and the data disclosed.
7. Retention, deletion and steps to take when a vehicle changes hands
Keeping location data longer than necessary is one of the most common UK GDPR breaches. The principle of storage limitation under Article 5(1)(e) requires that data is kept no longer than necessary for the purpose it was collected.
Retention schedule
| Data type | Suggested retention period | Justification |
|---|---|---|
| Real-time location (active alert) | Until alert resolved, then delete | No ongoing purpose once incident closed |
| Journey records (fleet management) | 30 days | Operational review; align with insurer requirements |
| Journey records (insurance evidence) | Duration of policy + 12 months | Potential claims window |
| Driver ID logs | Duration of employment + 6 months | HR and legal disputes |
| Incident / theft-recovery data | Duration of investigation + 12 months | Legal proceedings |
Vehicle change of ownership: what to do
When a vehicle is sold, leased vehicle is returned, or a company car changes driver, the previous owner’s data must be wiped. Steps to follow:
- ✅ Unlink the vehicle from all user accounts on the tracking platform
- ✅ Perform a factory reset of the tracker device (follow the manufacturer’s procedure)
- ✅ Confirm with the platform provider that all stored journey data for that vehicle has been deleted
- ✅ Obtain written confirmation of deletion from the provider and retain it for your records
- ✅ Issue a deletion confirmation to the previous driver if they request one
The EDPB’s connected vehicles summary specifically recommends that vehicles include easy wipe functions precisely because change-of-ownership data leakage is a documented risk. If your tracker supplier cannot demonstrate a clear wipe procedure, that is a procurement red flag.
8. Security controls and privacy-by-design measures
Security is not a bolt-on. Under UK GDPR Article 25, privacy-by-design and by-default are legal requirements, not aspirational standards.
Technical controls to implement
- ✅ Encryption in transit and at rest: all location data transmitted between the tracker device and the platform must use TLS 1.2 or higher; stored data must be encrypted at rest
- ✅ Role-based access control: only personnel with a documented need should be able to view live or historical location data; access should be logged
- ✅ Audit logs: every access to location data should be timestamped and attributed to a named user account
- ✅ Secure firmware updates: tracker devices should receive updates over authenticated, encrypted channels to prevent tampering
- ✅ Dashboard indicators: the EDPB recommends that drivers should be able to see when location tracking is active — an in-app indicator or dashboard icon meets this requirement
- ✅ Local processing preference: where the tracker can process telemetry on-device and transmit only summary data, that is the privacy-preserving default
Incident response for tracker data breaches
If a data breach occurs — unauthorised access to the platform, a stolen device with stored data, or a misconfigured API exposing journey records — your response timeline is fixed by law:
- ✅ Contain the breach immediately (revoke access, isolate affected systems)
- ✅ Assess the risk to affected individuals within 24 hours
- ✅ Notify the ICO within 72 hours of becoming aware if the breach is likely to result in risk to individuals
- ✅ Notify affected drivers without undue delay if the breach is likely to result in high risk to their rights
- ✅ Document the breach, your assessment, and your response — even if you decide not to notify the ICO
Pro Tip: Run a tabletop breach exercise once a year. Walk your team through a scenario where the tracking platform is compromised. The 72-hour ICO notification window is shorter than most people expect — you need a pre-agreed escalation path, not a plan you write in a crisis.
9. Responding to data subject requests: access, erasure, restriction and objections
Drivers have the right to know what data you hold about them, to request deletion, to restrict processing, and to object. These are not administrative niceties — failure to respond correctly is an enforcement risk.
Step-by-step response process
- Verify identity: confirm the requester is who they claim to be before disclosing any data. A copy of a driving licence or employee ID is usually sufficient.
- Scope the request: clarify exactly what data the person wants — all journey records, a specific date range, driver ID logs, or platform account data.
- Search all systems: check the tracking platform, any cloud backups, third-party monitoring services, and any local exports or spreadsheets.
- Apply redactions: if journey data includes information about third parties (passengers, locations that reveal sensitive information about others), redact appropriately.
- Compile and deliver: provide the data in a commonly used electronic format within one calendar month of receiving the request. You may extend by a further two months for complex or numerous requests, but you must notify the requester within the first month.
- Document the response: record the request date, the data provided, any exemptions applied, and the delivery date.
Common exemptions
Law enforcement investigations, ongoing legal proceedings, and statutory retention obligations can all justify withholding or delaying disclosure. If you apply an exemption, tell the requester that you are withholding data and why (without compromising the investigation), and tell them they can complain to the ICO.
For erasure requests, the right is not absolute. Data retained for legal proceedings, insurance claims, or under a statutory obligation can be kept despite an erasure request — but only for as long as that obligation exists.
Standardised response templates reduce the operational burden significantly. A template for access requests, one for erasure, and one for objections — each pre-populated with your organisation’s details and the standard legal text — means your team can respond consistently without drafting from scratch each time.
10. ICO enforcement, likely penalties and practical regulatory risks
Vehicle tracking is not a niche area — the ICO has published specific guidance on surveillance in vehicles and has taken enforcement action against employers who monitored staff without adequate transparency.
What attracts regulatory scrutiny
The ICO’s surveillance in vehicles guidance identifies the absence of a DPIA, lack of transparency with drivers, and continuous unnecessary location logging as the primary risk factors for enforcement action. Organisations that cannot produce a DPIA, a privacy notice, and a legitimate interest assessment when asked are in a weak position regardless of their intentions.
Common mistakes that prompt ICO attention:
- ✅ No DPIA carried out before deployment
- ✅ Drivers not informed that tracking is in place
- ✅ Continuous 24/7 location logging with no private mode for personal journeys
- ✅ Data retained indefinitely with no deletion schedule
- ✅ No written contract with the tracker supplier or monitoring centre
- ✅ Sharing raw journey data with insurers beyond what is strictly necessary
Mitigation steps
A remedial DPIA — carried out after deployment but before any complaint or investigation — demonstrates good faith. Pair it with a documented legitimate interest assessment, a revised privacy notice issued to all drivers, and a written record of when each driver received it. The ICO’s enforcement decisions consistently show that organisations with documented compliance processes receive more lenient treatment than those with none.
The Data Use and Access Act 2025 introduced changes affecting data processing and access rules relevant to vehicle-related data. Review the government’s commencement guidance to confirm whether any provisions affect your specific tracker deployment, particularly around automated processing and data access rights.
11. Your step-by-step compliance checklist and 30-day action plan
Getting compliant does not require months of legal work. It requires a structured sprint.
Seven-day triage
| Action | Owner | Evidence to create |
|---|---|---|
| Review current privacy notice — does it cover tracker data? | Data Protection Officer / HR | Updated notice, version-controlled |
| Scope a DPIA — identify data flows, purposes, risks | DPO / fleet manager | DPIA scope document |
| Issue in-vehicle notices to all tracked vehicles | Fleet manager | Photo record, delivery log |
| Notify all drivers in writing that tracking is in place | HR / fleet manager | Signed acknowledgement or email record |
| Confirm Data Processing Agreement exists with tracker supplier | Procurement / legal | Signed DPA on file |
30-day actions
- ✅ Complete the full DPIA, including risk assessment and mitigation measures
- ✅ Update the Record of Processing Activities under Article 30 of UK GDPR to include tracker data flows
- ✅ Deploy private mode controls for mixed-use vehicles and test them
- ✅ Review and update the retention schedule; configure automatic deletion in the platform
- ✅ Train relevant staff on data subject rights and the response process
- ✅ Request security documentation from your tracker supplier (encryption standards, subprocessors, breach history)
- ✅ Set a calendar reminder to review the DPIA annually or when the system changes
Recordkeeping for insurers and the ICO
Keep your DPIA, legitimate interest assessment, privacy notices, driver acknowledgements, and Data Processing Agreements in a single compliance folder. If an insurer or the ICO asks for evidence of compliance, you can produce it within hours rather than days. That speed of response is itself a signal of good governance.
12. What to ask a Thatcham-approved tracker supplier before you sign
Procurement is where privacy compliance is won or lost. A supplier who cannot answer these questions clearly is a liability.
Supplier questions to ask
- ✅ Do you hold a current Thatcham certification? Can you provide the certificate number and category?
- ✅ Where is location data stored — UK, EEA, or third countries? What transfer mechanism applies?
- ✅ What is your data retention period and how is deletion enforced?
- ✅ What encryption standards do you apply in transit and at rest?
- ✅ Who are your subprocessors and where are they based?
- ✅ Can you provide input to our DPIA, including a description of your data flows and security controls?
- ✅ What is your breach notification procedure and what is your average time to notify customers?
- ✅ Do you support private mode or driver ID controls?
- ✅ What is your wipe procedure when a vehicle changes hands?
What counts as acceptable proof
Thatcham certification is issued by Thatcham Research and is the standard recognised by UK motor insurers. Ask for the certificate number and verify it directly with Thatcham Research if the value of the vehicle warrants it. For security assurances, ask for a summary of the supplier’s most recent penetration test or vulnerability assessment — not the full report, but a confirmation that testing has been carried out and that critical findings have been remediated.
Pro Tip: A supplier who is reluctant to share their subprocessor list or their breach history is not a supplier you want processing your customers’ or employees’ location data. Transparency from your supplier is a proxy for their overall data governance maturity.
Vendor security checklist
- ✅ Evidence of annual penetration testing or vulnerability assessment
- ✅ Confirmation of SOC 2 Type II or equivalent security certification (or a clear explanation of why not)
- ✅ Written breach history disclosure for the past 24 months
- ✅ Incident response plan available on request
- ✅ Named data protection contact within the supplier organisation
A vehicle security specialist’s view on compliance pitfalls
The compliance mistakes I see most often are not technical — they are procedural. Organisations fit a tracker, tick the insurance box, and assume the privacy obligations are someone else’s problem. They are not. The moment you deploy a system that records where a person’s vehicle is at any given moment, you are a data controller, and the full weight of UK GDPR applies.
The second most common mistake is treating the DPIA as a one-time exercise. A DPIA completed at deployment and never revisited is almost useless if your supplier changes, your data flows expand, or you start using telemetry data for purposes beyond theft recovery. The document needs to live alongside the system.
One practical priority that gets overlooked: the balance between insurer requirements and privacy. Insurers increasingly require Thatcham-approved trackers as a condition of cover for high-value vehicles — and that requirement is legitimate. But the insurer’s requirement to know the vehicle is tracked does not extend to a right to access raw journey data on demand. Keep those two things clearly separated in your contracts and your policy.

Lrd-track: Thatcham-approved tracking with compliance built in
If you are fitting a tracker to a Land Rover Defender, Discovery, or Range Rover, the compliance burden is real — but a professionally installed, insurance-approved system makes it significantly more manageable.

Lrd-track supplies and installs Thatcham-certified GPS trackers specifically engineered for Land Rover models, with features that directly support your compliance obligations: driver ID controls for journey separation, 24/7 monitored response, remote immobilisation, and documented hardware security. When you need to complete a DPIA or respond to an insurer query, a Thatcham certificate and a supplier who can describe their data flows clearly is worth more than a cheap device with no documentation trail.
Lrd-track can provide the Thatcham certification evidence, security documentation, and supplier input your DPIA requires. Use the Lrd-track product finder to match the right tracker to your vehicle and compliance needs, or go straight to the S7 Classic Defender Tracker if you are ready to proceed. Contact Lrd-track directly to request supplier documentation for your compliance file.
Sources
These are the primary sources you should consult and keep on file for audits, DPIA evidence, and policy drafting:
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.