Fleet Tracking Regulations Explained: A Guide for Van Rental Companies in the UK

UK GDPR guide for van rental firms using GPS/telematics: lawful basis, transparency, retention, DPIAs and RVSS compliance.

6 min read

Jurisdiction Scope

UK-wide data-protection framework, primarily the UK GDPR and Data Protection Act 2018; the cited ICO guidance is not limited to a particular UK nation.

Overview of Fleet Tracking Laws

Applicable Business Type

Van rental companies (self-drive and commercial van hire businesses)

Country or Region

United Kingdom

A UK-focused compliance guide for van rental companies using GPS or telematics to protect vehicles, prevent theft, investigate misuse or damage, support insurance and operational needs, and manage rental-contract obligations. It explains UK GDPR transparency, lawful-basis, proportionality, access, security and retention expectations, including how to communicate tracking to hirers and approved drivers.

Legal Requirements Summary

UK van rental operators may use vehicle tracking for legitimate security, theft-prevention, insurance and contract-administration purposes, but must comply with UK GDPR principles. They should document a lawful basis, tell hirers and drivers clearly and in advance about the tracking, limit collection and use to necessary purposes, secure and restrict access to the data, honour data-subject rights, and retain information only for a justified period. Driver consent is not universally mandatory, although it is required if consent is the chosen lawful basis; transparency and proportionality remain mandatory. Rental terms should disclose telemetry and its consequences, including possible contact or contractual action for misuse.

Main Regulatory Topics

  • UK GDPR lawful basis
  • Privacy notices and transparency
  • Driver and hirer information
  • Data minimisation and proportionality
  • Vehicle security and theft prevention
  • Rental-contract disclosures
  • Personal-use/off-hours safeguards
  • Data retention and deletion
  • Access controls and information security
  • Data-subject rights
  • DPIAs and risk assessment
  • Vehicle cameras and audio
  • Enforcement and contractual remedies

Key Compliance Obligations

  • Identify and document a lawful basis for GPS/telematics processing, commonly contract necessity or a carefully assessed legitimate interest such as vehicle security and theft prevention.
  • Provide clear privacy information before tracking begins, including the data collected, purposes, controller identity/contact details, recipients or access, retention and individuals’ rights.
  • Use tracking fairly, proportionately and only for specified purposes; do not repurpose location data incompatibly with the original purpose.
  • Include tracking disclosures and relevant operational rules in rental terms, privacy notices and information provided to hirers and approved drivers.
  • Apply data minimisation and security controls; restrict access and protect tracking data against unauthorised use.
  • Assess whether a Data Protection Impact Assessment is required for systematic or high-risk monitoring, particularly where individuals’ movements are monitored.
  • Offer appropriate privacy safeguards for personal journeys or non-working use, such as disabling tracking where continuous monitoring is not necessary.
  • Set and document retention periods by purpose, securely delete or anonymise data when no longer needed, and preserve it longer only where justified by claims, disputes, investigations or legal obligations.
  • Support data-subject rights, including access to relevant personal data and information about the processing.
  • If cameras or audio are added to vehicle surveillance, conduct a separate necessity and proportionality assessment; switch audio off by default unless exceptionally justified.

Driver Consent Requirement

Consent Rule: Driver consent is not automatically required where tracking has another valid UK GDPR lawful basis, such as contract necessity or legitimate interests. The rental company must nevertheless give clear advance privacy information and explain what is tracked, why, who can access it and how long it is retained. If consent is used, it must be specific, informed, freely given and documented; tracking should be limited or disabled for private/non-work use where applicable.

Data Retention Period

Minimum Retention: No single UK statutory minimum period is stated for GPS tracking data; retain it only for as long as necessary for the stated purpose, with longer retention where reasonably necessary for an insurance claim, dispute, investigation or legal matter. Example policies retain different categories for periods ranging from deletion at the end of an active job to 2, 5, or 7 years.

Enforcement Authorities

  • Information Commissioner’s Office (ICO) — UK data protection enforcement and monetary penalties
  • Department for Transport / GOV.UK — Rental Vehicle Security Scheme guidance and code of practice
  • Driver and Vehicle Licensing Agency (DVLA) — vehicle-register information and lawful disclosure processes
  • Police and other law-enforcement agencies — lawful requests for rental and vehicle-security information

Penalties for Non-Compliance

Non-compliance can lead to ICO investigation, enforcement notices, orders to stop or change processing, and administrative fines. The UK GDPR/DPA 2018 statutory maximum is the higher of £8.7 million or 2% of worldwide annual turnover for standard infringements, and £17.5 million or 4% of worldwide annual turnover for higher-level infringements. Poor security or unlawful disclosure can also expose the business to complaints, compensation claims, reputational harm and loss of customer trust. Under the RVSS framework, failure to follow scheme requirements can undermine participation and vehicle-security assurance; lawful data-sharing records and staff training are specifically expected.

Implementation Best Practices

Operate tracking as a documented privacy-and-security control rather than as unrestricted driver surveillance. Maintain a processing record and DPIA where appropriate; configure geolocation, driver-behaviour, camera and audio features to the minimum necessary; use role-based access, encryption and supplier contracts; publish privacy notices at booking and in the vehicle; set short, purpose-based retention periods; log disclosures; and perform a return-to-rental data reset covering telematics accounts, connected apps and digital keys. Review the configuration and policy after any change in purpose, technology or rental model.

Compliance Checklist

  1. Identify and document a UK GDPR lawful basis for location, telematics, camera or other tracking data; do not assume consent is required or sufficient in every case.
  2. Define the purposes of tracking, such as vehicle security, theft recovery, contract administration, safety or regulatory compliance, and collect no more data than necessary.
  3. Complete and document a Data Protection Impact Assessment where monitoring is systematic or likely to create a high risk to renters, drivers, passengers or members of the public.
  4. Provide clear privacy information before or at hire, including what is tracked, purposes, lawful basis, recipients, retention, rights and the controller’s contact details.
  5. Use visible in-vehicle notices where surveillance or recording occurs; explain when it operates and who customers can contact.
  6. Put retention and deletion rules in place for telematics, journey and incident data, with controlled access and an auditable disclosure process.
  7. At vehicle return, remove or reset renter-linked accounts, paired apps, digital keys and personal data stored in connected-vehicle systems before re-letting the van.
  8. Keep audio recording switched off by default; activate it only in exceptional, well-justified circumstances and document the risk assessment.
  9. Train staff on UK GDPR, the Data Protection Act 2018, secure handling and lawful sharing with police or other authorities.
  10. For face-to-face commercial rentals, follow applicable RVSS controls: verify identity and driving entitlement, apply additional checks for commercial vehicle hires, fit appropriate security technology based on risk, and maintain a recognised security contact where participating in the scheme.

Industry-Specific Guidance

Van rental companies commonly track vehicles for theft prevention, recovery, damage or misuse investigations and fleet operations. The customer or driver may be a renter rather than an employee, but their location and driving data can still be personal data. The rental company should therefore identify the controller and explain tracking before hire, rather than relying on a hidden device or a broad contractual clause. For commercial-vehicle hires, the 2026 RVSS code highlights enhanced identity, licence and hire-purpose checks and appropriate security technology. Tracking should not automatically be treated as a general-purpose productivity-monitoring tool, and private use or multiple drivers require especially clear notices and proportional controls. On return, the company should securely erase renter-linked connected-car data before the van is issued to another customer.

Recent Legal Updates

The latest material update identified for this article is the GOV.UK RVSS code of practice published on 7 April 2026. It expressly lists data-protection/GDPR compliance, staff training, engagement with law enforcement, identity and licence verification, additional commercial-vehicle checks, and appropriate security technologies such as trackers among its requirements or recommendations. The underlying UK GDPR and DPA 2018 obligations remain in force: there is no general UK rule requiring every rental van to have real-time tracking, so any tracking must be justified, transparent, proportionate and securely operated. Businesses should check the current GOV.UK RVSS page and ICO guidance before publication or implementation.

Authoritative Resources

  • Information Commissioner’s Office (ICO): Surveillance in vehicles
  • ICO: Data protection and monitoring workers
  • GOV.UK: Rental Vehicle Security Scheme (RVSS) code of practice
  • ICO: UK GDPR and Data Protection Act 2018 fining guidance
  • DVLA: Release of information from vehicle registers

Related Blog Posts

Talk to GRS

Tell us about your fleet.

Get a package recommendation, transparent pricing and a practical deployment route.