Fleet Tracking Regulations Explained: A Guide for Vehicle Leasing Companies in France

Compliance guide for vehicle leasing firms in France on GPS tracking, GDPR/CNIL rules, employee rights, retention and controller duties.

Share
Fleet Tracking Regulations Explained: A Guide for Vehicle Leasing Companies in France

Jurisdiction Scope

French national data-protection and employment context

Overview of Fleet Tracking Laws

Applicable Business Type

Vehicle leasing companies and fleet operators providing or managing connected vehicles in France

Country or Region

France

A France-focused compliance guide for vehicle leasing companies covering connected-vehicle and employee-vehicle geolocation, GDPR and French data-protection obligations, transparency, permitted purposes, retention, user rights, and operational safeguards.

Legal Requirements Summary

In France, connected-vehicle and fleet-geolocation data linked or linkable to a person are personal data subject to the GDPR and French data-protection law. Vehicle leasing companies and fleet operators should define a lawful, proportionate purpose and legal basis, provide clear information, restrict access and retention, and respect user rights. For employee vehicles, representatives must be consulted before installation; employees must be informed, able to suspend tracking outside working time, and protected from continuous or disproportionate surveillance. CNIL states that geolocation data should normally be retained no longer than 2 months, subject to specific exceptions.

Main Regulatory Topics

  • GDPR and French data protection
  • Connected-vehicle location data
  • Employee transparency and information
  • Employee representative consultation
  • Driver/user consent and lawful basis
  • Purpose limitation and proportionality
  • Outside-working-time tracking controls
  • Data-subject access, objection and disablement rights
  • Record retention
  • Data security and authorised recipients
  • CNIL enforcement and penalties

Key Compliance Obligations

  • Identify and document the controller, purposes, lawful basis, recipients, retention period, and data-subject rights under the GDPR.
  • Inform each employee or vehicle user clearly before or at collection; information may be included in a lease, employment, service, or vehicle-documentation package where appropriate.
  • Consult employee representative bodies before deciding to install geolocation in vehicles made available to employees.
  • Use tracking only for legitimate, proportionate purposes; do not use it for continuous employee surveillance, speed-limit enforcement, or tracking outside working time.
  • Allow employees to disable location collection or transmission outside working time and provide access to their location data and applicable rectification or objection mechanisms.
  • Apply retention limits: normally 2 months, with defined exceptions for route optimisation/service proof and working-time monitoring.
  • Ensure personal-data processing has an Article 6 GDPR legal basis; obtain consent where CNIL’s connected-vehicle guidance requires it.
  • Protect data and restrict access to authorised recipients; provide a route for complaints to the CNIL.
  • Avoid using geolocation where the employee has genuine freedom to organise their travel, and do not track employee representatives during their representative mandate.

Driver Consent Requirement

Consent Rule: Employee consent is not stated as a general prerequisite for employer vehicle tracking; the employer must inform employees, consult employee representatives before installation, permit location collection to be disabled outside working time, and respect opposition and access rights. For connected-vehicle operations involving users, CNIL guidance says prior consent is required unless the operation is strictly necessary to provide an expressly requested service or is exclusively necessary to enable electronic communication.

Data Retention Period

Minimum Retention: 2 months in principle for employee-vehicle geolocation data; up to 1 year for route optimisation or proof of service, and 5 years for working-time monitoring data limited to hours worked

Enforcement Authorities

  • Commission nationale de l’informatique et des libertés (CNIL) — France’s independent data-protection supervisory authority and primary enforcement body for these tracking/privacy obligations.
  • CNIL’s restricted committee and simplified-sanctions procedure handle administrative sanctions; CNIL reported that simplified sanctions cannot exceed €20,000.
  • Where processing spans several EEA countries, the GDPR one-stop-shop/cooperation mechanism and other EU supervisory authorities may also be involved.

Penalties for Non-Compliance

Non-compliance can lead to CNIL corrective orders, injunctions (including periodic penalty payments), public decisions, warnings and administrative fines. The CNIL reported 78 fines among 83 sanctions in 2025 and €486,839,500 in total sanctions; its simplified procedure is capped at €20,000. The actual penalty depends on the infringement, scale, duration, cooperation, affected individuals and other GDPR factors—there is no single fleet-tracking tariff. CNIL examples include a €3.5 million fine in January 2026 for unlawful personal-data transmission and a €240,000 fine in December 2024, illustrating that privacy failures can be materially costly.

Implementation Best Practices

Treat the leasing company’s role as purpose-dependent rather than assuming ownership of the vehicle makes it the controller. Create a data-flow map for the vehicle, embedded system, app, leasing platform, customer and service providers; record controller/processor decisions and contractual instructions. Offer purpose-specific tracking modes—for example, theft/non-return recovery rather than continuous customer surveillance—using the lowest practicable collection frequency and shortest retention. Build privacy notices, rights handling, deletion, audit logs and access controls into the product before installation. For employee-use vehicles, include an obvious off-duty privacy control and test that it actually stops transmission; train customer administrators not to repurpose location data for employee performance monitoring. Conduct a DPIA where the scale, systematic monitoring or risk warrants it, and periodically audit suppliers, international transfers and device configuration.

Compliance Checklist

  1. Define the specific purpose for each tracking function and select an appropriate GDPR legal basis; contractual necessity is not established merely because tracking is written into a lease contract.
  2. Identify whether the leasing company, customer, telematics provider or multiple parties are controller, joint controllers or processor; document the allocation of responsibilities and use Article 26/28 agreements where applicable.
  3. Provide clear privacy information covering the controller, purposes, legal basis, recipients, retention, access/rectification and objection rights, and CNIL complaint rights.
  4. Apply data minimisation: limit tracking frequency, data fields, access and retention to what the purpose requires.
  5. For connected vehicles leased to private customers, explain tracking in the customer-facing contract and privacy notice and provide practical rights-request channels.
  6. For vehicles provided to employees, inform drivers before deployment, permit access to their data, and enable location collection/transmission to be disabled outside working time.
  7. Do not use employee geolocation for permanent surveillance, speed-limit enforcement, tracking during breaks or commuting, or where the employee has genuine freedom over travel organisation.
  8. Set retention by purpose: CNIL’s employee-vehicle guidance states two months in principle, up to one year for route optimisation or proof of service where necessary, and five years for working-time monitoring.
  9. Maintain the Article 30-style processing record where applicable, including purposes, data, recipients, transfers, retention and security measures.
  10. Put technical and organisational security controls, supplier instructions, access logging and deletion procedures in place; review the configuration periodically.

Industry-Specific Guidance

Vehicle leasing companies are expressly within the scope of CNIL’s June 2026 connected-vehicle recommendation, which addresses short- and long-term rental providers and focuses on vehicles used by private owners or lessees. A leasing company that decides to geolocate leased vehicles—for example, to recover a vehicle after non-return—and chooses the telematics means may be the controller; the customer, manufacturer, fleet manager and telematics provider may instead be separate or joint controllers depending on who determines purposes and means. The recommendation does not cover company cars or service vehicles made available to employees, so those deployments must also follow CNIL’s specific employee-geolocation rules: prior information, no permanent/off-duty tracking, a disable function outside working time, and purpose-limited retention. Leasing firms should therefore separate private-customer connected-vehicle flows from employer fleet-monitoring flows and assign responsibilities in each contract and notice.

Recent Legal Updates

As at 8 October 2026, the key recent development is CNIL’s June 2026 final Recommendation on the use of connected-vehicle location data, following the March 2025 draft. It expressly addresses connected vehicles offered in short- and long-term rental and clarifies controller/joint-controller/processor allocation, information duties, legal bases and data minimisation. CNIL also published consumer-facing connected-vehicle guidance on 30 June 2026. The recommendation is guidance rather than a new statute, but it is the principal current French compliance reference and should be reflected in new deployments and contract/privacy documentation.

Authoritative Resources

Related Blog Posts