Fleet Tracking Regulations Explained: A Guide for Delivery Firms in Scotland
Guide for Scottish delivery firms on GPS tracking, GDPR duties, tachographs, privacy safeguards and retention rules.
Jurisdiction Scope
Scotland, under UK-wide data-protection and road-transport rules; Scottish delivery operations are also subject to the applicable UK goods-vehicle, drivers’ hours, tachograph, and operator-licensing requirements.
sbb-itb-499a7f0
Overview of Fleet Tracking Laws
Applicable Business Type
Delivery firms and goods-vehicle operators in Scotland
Country or Region
United Kingdom — Scotland
A practical compliance guide for Scottish delivery firms using GPS tracking, telematics, tachographs, or other vehicle-monitoring systems. It explains how UK data-protection rules apply to identifiable driver and passenger information, distinguishes ordinary fleet tracking from legally required drivers’ hours and tachograph records, and highlights privacy, proportionality, transparency, retention, and higher-risk monitoring requirements.
Legal Requirements Summary
Scottish delivery firms may use fleet telematics, but location, route, mileage, speed, and driver-behaviour information can be personal data. The firm must establish a lawful basis, provide transparent privacy information, use monitoring proportionately, protect the data, and delete it when no longer necessary. Private-use monitoring should normally be disabled or separated. Cameras, audio, continuous behaviour monitoring, and risk analytics generally require a documented DPIA. Where the vehicle and operation are within the relevant goods-vehicle rules, tachograph and drivers’ hours obligations apply independently of ordinary GPS tracking, including periodic data downloads and record keeping.
Main Regulatory Topics
- UK GDPR and data privacy
- Lawful basis and transparency
- Driver and passenger privacy
- Private-use restrictions and privacy mode
- Driver consent and tachograph-data transmission
- Data minimisation, security, and retention
- Data protection impact assessments
- Tachographs and drivers’ hours
- Record keeping and regulatory inspections
- Operator licensing and enforcement
Key Compliance Obligations
- Document a lawful basis for processing identifiable telematics and vehicle-monitoring data.
- Tell drivers and passengers what is monitored, why it is monitored, who controls the data, and how long it is retained.
- Use tracking only where necessary, proportionate, and limited to legitimate business purposes.
- Provide a privacy mode or otherwise disable or limit monitoring during permitted private use; monitoring private journeys will rarely be justified.
- Carry out and document a DPIA for intrusive monitoring such as cameras, audio, continuous driver-behaviour monitoring, or analytics that infer or predict driver risk.
- Secure the tracking system and apply data protection by design.
- Where tachographs apply, download vehicle-unit data at least every 90 days and driver-card data at least every 28 days, then analyse compliance.
- Maintain any separately required operator-licensing, vehicle-maintenance, drivers’ hours, working-time, and tachograph records for their applicable statutory periods.
- Do not treat GPS fleet tracking as a universal legal requirement for ordinary delivery vans; determine whether the vehicle and operation trigger tachograph or drivers’ hours duties.
Driver Consent Requirement
Consent Rule: Prior driver consent is not generally required for ordinary business fleet tracking. The firm should identify and document an appropriate UK GDPR lawful basis, give drivers and passengers clear privacy information, and ensure monitoring is necessary and proportionate. Consent may be required in particular tachograph-data transmission contexts under the applicable technical rules; employee consent is generally not the preferred lawful basis because of the employment power imbalance.
Data Retention Period
Minimum Retention: No fixed minimum period for ordinary fleet-tracking data under UK GDPR; retain it only for as long as necessary and justified. Separate statutory records may have specific periods, including tachograph downloads at least every 90 days for vehicle units and every 28 days for driver cards.
Enforcement Authorities
- Information Commissioner’s Office (ICO) for UK data-protection compliance and surveillance/monitoring practices
- Driver and Vehicle Standards Agency (DVSA) for drivers’ hours and tachograph enforcement in Great Britain, including Scotland
- Police Scotland and other police officers with relevant powers to inspect tachograph records and road vehicles
Penalties for Non-Compliance
Non-compliance can lead to ICO regulatory action and data-protection consequences, including investigation, enforcement notices and potentially significant UK GDPR penalties depending on the breach. Dashcam/CCTV operators may also face the applicable ICO data-protection fee requirements. Drivers’ hours and tachograph breaches can result in graduated fixed penalties, deposits, court proceedings, prohibition of vehicle use until defects are remedied, improvement or prohibition notices, and action against serious or falsified records. Employers may protect themselves from conviction for record offences only where they can demonstrate that they took all reasonable steps to ensure proper records were kept.
Implementation Best Practices
Use purpose-limited, proportionate tracking: normally track vehicles only during working operations, with a documented private-use/off-duty control. Map each data field to a defined business or legal purpose; complete a DPIA for intrusive monitoring; issue a concise driver notice and vehicle signage; switch audio off; limit dashboard access; encrypt or otherwise secure transfers and storage; define retention and deletion rules; and test retrieval for subject-access requests and DVSA inspections. Maintain an auditable compliance file containing the lawful-basis assessment, DPIA, notices, configuration records, operator records, training logs, incident handling and periodic review.
Compliance Checklist
- Identify and document a lawful basis for location, telematics, dashcam or driver-monitoring data; do not rely on consent automatically where processing is necessary for employment or legal compliance.
- Complete and document a Data Protection Impact Assessment before high-risk monitoring, including driver-behaviour analytics, cameras, audio or extensive surveillance.
- Give drivers and passengers clear privacy information and in-vehicle signage explaining what is collected, the purposes, monitoring circumstances, controller identity and contact details.
- Disable audio recording by default; use it only in exceptional, specifically justified circumstances and record the necessity and proportionality assessment.
- Provide a privacy-preserving off-duty/private-use mode; monitoring during private use will rarely be justifiable.
- Restrict access to authorised personnel, set a documented retention schedule, protect the data, and maintain procedures for access requests and appropriate disclosures.
- Where goods-vehicle drivers are within tachograph rules, ensure tachographs and driver cards/manual records are used correctly and records can be produced for enforcement.
- Retain and produce operator records for 12 months; ensure drivers can produce the current day and preceding 28 days, or 56 days where the applicable international journey rules require it.
- Train drivers and managers, audit tracking and tachograph data, and keep evidence of policies, DPIAs, notices, training and corrective action.
- Check whether the business must register and pay the ICO data-protection fee, particularly where work-vehicle dashcams or CCTV are used.
Industry-Specific Guidance
A delivery firm in Scotland is subject to Great Britain road-transport rules and UK data-protection law. Ordinary GPS route, dispatch and proof-of-delivery tracking is not subject to a general rule requiring driver consent, but it identifies drivers and therefore constitutes personal-data processing when linked to them. The firm must be transparent, proportionate and avoid using tracking as unrestricted continuous employee surveillance. If vans or lorries fall within assimilated or domestic drivers’ hours rules, the required tachograph or written records are distinct from optional telematics and must be complete and available for inspection. Delivery operations should also account for passenger data, customer addresses and incidental bystander information, applying minimisation and access controls. Vehicles used privately require especially careful off-duty controls.
Recent Legal Updates
The Drivers’ Hours and Tachographs (Amendment and Modification) Regulations 2025 came into force on 21 April 2025 and expressly extend to Scotland. The amendments update infringement wording to cover inability to produce records for the current day and preceding 28 days, or 56 days where applicable, including relevant manual records and printouts. As at 2 October 2026, delivery firms should use the current GOV.UK/DVSA guidance and check whether their routes involve the 56-day international-record requirement. The core UK GDPR/ICO expectations—transparency, proportionality, DPIAs for high-risk monitoring and privacy safeguards—remain central.
Authoritative Resources
- Information Commissioner's Office (ICO): Surveillance in vehicles
- ICO: Monitoring workers and work vehicles
- GOV.UK/DVSA: Drivers' hours and tachographs
- legislation.gov.uk: Drivers’ Hours and Tachographs (Amendment and Modification) Regulations 2025