Fleet Tracking Regulations Explained: A Guide for Delivery Firms in Ireland

GDPR guidance for Irish delivery firms on lawful fleet tracking: transparency, privacy switches, retention and tachograph rules.

5 min read

Jurisdiction Scope

Republic of Ireland; Irish GDPR and Data Protection Commission guidance.

Overview of Fleet Tracking Laws

Applicable Business Type

Delivery firms and other employers operating tracked work vehicles in Ireland.

Country or Region

Ireland.

An Ireland-focused compliance guide for delivery firms using vehicle telematics or GPS tracking. It explains GDPR lawful-basis, transparency, purpose-limitation, proportionality, security and retention requirements, as well as privacy controls where vehicles may be used privately.

Legal Requirements Summary

Irish delivery firms may use fleet tracking only on a documented GDPR legal basis and with clear advance transparency. Tracking must be necessary, proportionate, purpose-limited and secure, and must not become general monitoring of employees. Where vehicles can be used privately, the system must support privacy through a privacy switch; tracking records have no single universal statutory retention period and should be deleted once no longer necessary, subject to any separate legal retention duties.

Main Regulatory Topics

  • Data Privacy
  • GDPR Lawful Basis
  • Driver Transparency
  • Driver Consent
  • Purpose Limitation
  • Data Minimisation and Proportionality
  • Record-Keeping and Retention
  • Privacy Switches and Private Use
  • Security and Accountability
  • Employee Monitoring
  • Tachograph and Other Statutory Records

Key Compliance Obligations

  • Identify and document a lawful basis under GDPR Article 6 before implementing in-vehicle tracking.
  • Inform drivers in advance about the tracking system, data collected, purposes, retention period, access and disclosures.
  • Use tracking for specified, legitimate purposes and do not repurpose the data incompatibly.
  • Ensure processing is necessary, proportionate, secure and consistent with GDPR principles, including minimisation, accuracy, storage limitation and accountability.
  • Do not use vehicle tracking for general monitoring of staff or treat it as a general-purpose driver-surveillance tool.
  • Fit and maintain a privacy switch when company vehicles may be used privately or privately owned vehicles are used for work; train drivers in its operation.
  • Create and provide a vehicle-tracking and private-use policy, including the purposes for which tracking data may be used.
  • Set, document and periodically review retention and deletion limits; securely erase data when no longer necessary.
  • Apply any separate legal record-keeping requirements relevant to the vehicle or delivery operation, such as tachograph obligations where applicable.

Driver Consent Requirement

Consent Rule: Prior employee consent is not generally required and is usually unsuitable as the legal basis because of the employer–employee power imbalance. The employer must instead identify and document an appropriate GDPR legal basis, notify drivers in advance, and obtain freely given consent only where consent is genuinely appropriate. A privacy switch is required where a company vehicle is permitted for private use or a privately owned vehicle is used for work; it is not required for vehicles used exclusively for work.

Data Retention Period

Minimum Retention: No universal fixed minimum period for fleet-tracking data. Retain it only for as long as necessary for the stated purpose, establish and periodically review deletion limits, and observe any separate statutory or industry retention rules.

Enforcement Authorities

  • Data Protection Commission (DPC) — GDPR and Data Protection Act 2018 compliance, investigations, corrective orders, reprimands, and administrative fines.
  • Road Safety Authority (RSA) — road-transport, tachograph, drivers’ hours, operator-licensing, and road-haulage enforcement.
  • An Garda Síochána — roadside enforcement under the Irish road-transport regulations.
  • Customs officers — enforcement of applicable tachograph and road-transport requirements.

Penalties for Non-Compliance

Non-compliant GPS monitoring can lead to DPC corrective action, including reprimands, enforcement notices, orders to comply or change processing, and administrative fines under GDPR Article 83 and the Data Protection Act 2018. Tachograph and road-transport breaches can lead to roadside intervention, vehicle or tachograph inspection, prosecution, and—depending on the offence—class A fines of up to €5,000 and/or imprisonment of up to six months. Certain indictable offences under the 2017 regulations can attract fines up to €100,000 and/or imprisonment up to two years; operator-licensing breaches may carry higher penalties, including up to €500,000 and/or up to three years’ imprisonment. The exact sanction depends on the offence and circumstances.

Implementation Best Practices

Start with a documented purpose-and-necessity assessment and DPIA. Configure the system for data minimisation: restricted users, role-based access, appropriate retention and deletion, audit logs, and secure backups. Give each driver a concise privacy notice before activation and document acknowledgement/training rather than treating consent as the default legal basis. Separate operational fleet data from employee-performance monitoring, disable or mask tracking during permitted private use, and define escalation rules for access requests, incidents, inaccurate data, and misuse. For regulated road transport, integrate GPS administration with tachograph workflows so downloads, card expiry, secure storage, signature preservation, and inspection readiness are automatically monitored.

Compliance Checklist

  1. Define and document a specific, lawful purpose for GPS tracking; do not use vehicle tracking for general monitoring of drivers or staff.
  2. Identify the employer as the GDPR controller where applicable, establish a lawful basis, and complete a Data Protection Impact Assessment before implementing systematic location monitoring.
  3. Give drivers clear advance privacy information covering what data is collected, why it is needed, how tracking operates, retention periods, access, and disclosures.
  4. Limit collection, access, retention, and use to what is necessary for the stated purpose; do not repurpose tracking data incompatibly.
  5. Provide a privacy switch or equivalent method to disable or mask tracking when personal use or privately owned vehicles are permitted, and train drivers in its use.
  6. Where tachograph rules apply, use the required company tachograph card and approved equipment; download vehicle-unit data at least every 90 days and driver-card data at least every 28 days.
  7. Store downloaded tachograph data securely, preserve its downloaded format and digital signature, maintain backups/disaster recovery, and retain it for at least one year for inspection.
  8. Maintain procedures for driver-card expiry, lost/stolen/malfunctioning cards, tachograph checks, and prompt corrective action.
  9. Prepare records and vehicles for roadside or premises inspections by RSA Transport Officers, An Garda Síochána, and other authorised enforcement officers.

Industry-Specific Guidance

Irish delivery firms commonly need to manage two distinct compliance layers. Ordinary GPS fleet tracking is primarily an employment-privacy and GDPR issue: location data linked to a driver is personal data, and the DPC says tracking should not become general staff surveillance. Delivery operations should therefore use tracking for clear purposes such as vehicle allocation, route coordination, security, or customer-service evidence, while avoiding excessive continuous behavioural monitoring. Separately, vehicles and journeys within the scope of EU/Irish drivers’ hours and tachograph rules must meet RSA requirements; this includes company-card administration, regular downloads, secure one-year retention, and availability for inspection. Applicability depends on vehicle type, weight, journey, and exemptions, so firms should assess each fleet category rather than assume every delivery van has identical obligations. Contractors and agency drivers must also receive appropriate transparency information where the firm determines the tracking purposes and means.

Recent Legal Updates

The RSA has published a 2026 Guide to Digital Tachographs, confirming the current operational expectations of 90-day vehicle-unit downloads, 28-day driver-card downloads, secure storage, and backup/disaster-recovery arrangements. RSA Smart Tachograph 2 guidance also addresses retrofit requirements for relevant vehicles and states that the amended Irish rules are enforceable by RSA Transport Officers, Customs Officers, and An Garda Síochána. Delivery firms should check the RSA’s current Smart Tachograph 2 applicability and retrofit timetable for each vehicle category, as the requirement is not universal to every light commercial vehicle. No source reviewed establishes a new Ireland-specific 2026 change to the core GDPR principles for employer vehicle tracking; the DPC’s existing guidance remains the key privacy reference.

Authoritative Resources

Related Blog Posts

Talk to GRS

Tell us about your fleet.

Get a package recommendation, transparent pricing and a practical deployment route.