Fleet Management Software Data Security: What to Look For
A fleet platform holds location history, driver identity data, and behaviour scores on every employee who gets behind the wheel. Here's what to actually check before trusting a vendor with it.
Fleet data is personal data, not just vehicle data
It's easy to think of fleet management software as a system for tracking vehicles, but in practice it holds a significant amount of personal data about the people driving them. GPS location tied to a named driver, driving behaviour scores, licence details, and job records all count as personal data under UK GDPR, which means a fleet platform deserves the same security scrutiny as any HR or payroll system — arguably more, given how much it can reveal about an individual's movements.
| Data held | Why it matters |
|---|---|
| Location and route history | Reveals driver movements and, indirectly, patterns of life outside work |
| Driver licence and identity details | Directly identifiable personal data requiring GDPR-compliant handling |
| Driving behaviour scores | Can affect employment decisions if inaccurate or accessed inappropriately |
| Job and delivery records | May include client names, addresses, and commercially sensitive details |
Our vehicle tracking and GDPR guide covers the legal basis for collecting this data in the first place. This article focuses on the security side — how it's protected once collected.
Six things to check before signing up
None of these questions require a technical background to ask, and a vendor confident in its security posture should be able to answer all of them clearly and specifically:
| Area | What to check |
|---|---|
| Hosting location | Where servers are physically located and whether data leaves the UK/EU |
| Encryption | Data encrypted both in transit (TLS) and at rest in the database |
| Access controls | Role-based permissions, individual logins, and audit logging |
| Certifications | Cyber Essentials as a baseline; ISO 27001 for larger or regulated fleets |
| Data processing agreement | Written DPA covering processing scope, breach notification, and sub-processors |
| Data retention and deletion | Clear policy on how long data is kept and how it's deleted on request or contract end |
Why hosting location and jurisdiction matter
Where a vendor physically hosts its data has real consequences beyond speed of access. Moving personal data outside the UK or EU triggers additional UK GDPR safeguards — either an adequacy decision covering the destination country or standard contractual clauses built into the vendor contract — and a vendor that can't clearly explain where data sits and what safeguards apply is adding legal complexity a fleet manager didn't ask for. A straightforward answer here is a reasonable proxy for how seriously a vendor takes the wider question.
Access controls matter as much as encryption
Encryption in transit and at rest is table stakes and worth confirming, but it's only part of the picture. Role-based access — so a dispatcher can't pull payroll-linked mileage data, and a driver can only see their own records — limits the damage a single compromised account can do. Individual logins rather than one shared password per depot, combined with an audit log of who accessed or changed what, turn a "we think someone did X" situation into a "we can see exactly what happened" one.
The data processing agreement is not optional
Any fleet software vendor processing driver and vehicle data on a business's behalf is a data processor under UK GDPR, and that relationship needs to be governed by a written data processing agreement — covering what the vendor can do with the data, how quickly they'll notify the business of a breach, and which sub-processors (cloud hosting providers, for example) are involved. FleetGS's compliance module and reporting tools are built with UK data protection requirements in mind from the outset, with a DPA available on request as part of onboarding.
Frequently asked questions — fleet management software data security
What kind of data does fleet management software actually hold?
Fleet platforms typically hold vehicle location history, driver identity and licence details, driving behaviour data, job and delivery records, and sometimes payment or fuel card information. Location and driving behaviour data tied to a named individual counts as personal data under UK GDPR, which is why fleet software security deserves the same scrutiny as any other system handling employee information — not just vehicle telematics.
Does it matter where a fleet software vendor hosts its data?
Yes, for two reasons. Practically, UK-based or EU-based hosting tends to mean lower latency and clearer legal jurisdiction if a dispute arises. Legally, transferring personal data outside the UK or EU triggers additional UK GDPR requirements around adequacy decisions or standard contractual clauses, which adds complexity a fleet manager may not want to take on. Asking a vendor directly where data is hosted, and getting a specific answer rather than a vague one, is a reasonable first check.
What certifications should a UK fleet look for in a software vendor?
Cyber Essentials (or Cyber Essentials Plus) is a reasonable baseline for any UK-facing software vendor, showing basic security controls are in place and independently checked. ISO 27001 certification is a stronger signal for larger fleets or those in regulated sectors, since it covers a formal information security management system rather than a point-in-time check. Neither certification guarantees a vendor is secure, but their absence is worth asking about directly.
What access controls should fleet software have?
At minimum, role-based access so that not every user can see or export every piece of data — a dispatcher doesn't necessarily need access to payroll-linked mileage data, for example — plus individual user logins rather than shared accounts, and an audit log showing who accessed or changed what and when. This matters particularly for larger fleets with multiple depots or departments, where the blast radius of a single compromised login should be limited by design.
Is a data processing agreement (DPA) required with a fleet software vendor?
Yes. Under UK GDPR, any vendor processing personal data on a business's behalf — which a fleet platform does, given driver and location data — is a data processor, and the relationship must be governed by a written data processing agreement setting out what the vendor can and can't do with the data, breach notification timelines, and sub-processor arrangements. A vendor unable or unwilling to provide a DPA on request is a genuine red flag, regardless of how polished the product looks.
Comments
Leave a comment
Fleet data handled with UK GDPR in mind
Role-based access, encrypted storage, and a data processing agreement available from day one. From £45/month.
Get started free