Certix

GPS and geolocation in company vehicles: labour limits and GDPR

Certix
Certix®
· 2 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

Installing geolocation devices (GPS, integrated telematics systems, tracking apps on the corporate smartphone) in company vehicles is common practice in transport, logistics, last-mile delivery, technical services and commercial fleets. It allows route optimisation, control of delivery times, calculation of allowances and resolution of incidents. But it is also one of the areas with the most litigation before the AEPD and the labour courts, because employer monitoring intersects with the worker's fundamental right to data protection.

The applicable framework is clear: GDPR (Regulation (EU) 2016/679), LOPDGDD (Spain's Organic Law 3/2018) and, specifically, art. 90 LOPDGDD on geolocation devices in the workplace. This guide explains what a company can and cannot do, and how to document it correctly.

The art. 90 LOPDGDD regime

Art. 90 LOPDGDD provides that employers may process data obtained through geolocation systems for the exercise of their monitoring functions over workers, provided this is exercised within the legal framework and its inherent limits. As a counterweight, it sets out a reinforced information duty that is the centrepiece of the regime.

The company must inform, in an express, clear and unambiguous manner, before the system is activated, the affected workers and their legal representatives, about:

  • The existence and specific characteristics of the installed devices.
  • The exercise of the monitoring functions that may be carried out through them.
  • The specific purposes of the processing.
  • The retention periods for the data.
  • The measures adopted to safeguard the worker's rights.

Opaque installation, covert installation or presentation as mere "vehicle telematics" without disclosing the labour monitoring dimension is unlawful and produces a double consequence: invalidity of evidence in employment proceedings and AEPD sanction for breach of the information duty.

Legal bases and legitimate purposes

Geolocation of company vehicles can rely on different art. 6 GDPR bases depending on the specific purpose:

Purpose Legal basis Limit
Service organisation (route assignment, optimisation) Performance of the employment contract (6(1)(b)) or legitimate interest (6(1)(f)). Only during effective working hours.
Vehicle security (anti-theft, recovery) Legitimate interest (6(1)(f)). Activation only on incident; no continuous processing.
Disciplinary monitoring of the worker Art. 20(3) of the Spanish Workers' Statute together with art. 90 LOPDGDD. Prior express information; proportionality.
Compliance with Regulation (EU) 561/2006 (driving times) Legal obligation (6(1)(c)). Data limited to what the rule requires.
Billing to end client (services billed by kilometre) Performance of contract with the client (6(1)(b)). No driver profiling.

Working hours vs outside working hours

The most relevant operational principle: GPS must remain inactive or inaccessible outside working time. This applies particularly when:

  • The vehicle is also used for authorised personal journeys (mixed use).
  • The worker keeps the vehicle at the end of the working day (commercial agents, service technicians).
  • There are prolonged rest periods along the route (long-distance transport).
  • It is a weekend, public holiday or holiday period.

Standard technical options to respect this limit are automatic deactivation of tracking outside working hours, a private button that the worker can press during personal trips (without that giving rise to suspicion or labour consequence) and access segregation in the tool's console, so that no manager can view data generated outside working hours.

The AEPD has sanctioned, on several occasions, companies keeping tracking active 24/7 without justification, and the labour courts have invalidated evidence obtained through continuous geolocation during non-working periods.

Information to workers and to the legal representation

Compliance with art. 90 LOPDGDD is documented through two parallel channels:

  1. Individual information: to each affected worker, in writing, with signature of receipt. It must be delivered before the system goes live or before joining the role if the system already exists.
  2. Collective information: to the workers' legal representation (works council, staff delegates, trade union sections) where it exists. In writing, with proof of delivery, before the system is implemented.

The minimum content of both communications includes: existence of the system, specific devices installed, processing purposes, types of data generated, retention periods, identity of the processor (provider of the telematics tool), potential disciplinary use, worker rights and how to exercise them, contact of the controller or DPO where applicable.

The internal geolocation policy is the reference document. It must be signed by management, archived with dates, included in the RoPA and delivered during the onboarding of each new worker.

"Geolocation of company vehicles is not unlawful; what is unlawful is activating it without telling the worker and their representation, or keeping it on Saturday afternoons. Art. 90 LOPDGDD sets the pattern: express prior information, proportionate monitoring within working hours and disconnection outside. If the company complies, its evidence will be lawful. If it does not, sanction and nullity are served."

Mario P. Talamillo · Managing Partner, Certix®

Disciplinary use and proportionality

Using geolocation data as evidence in disciplinary proceedings is permitted by case law subject to strict conditions:

  • The system previously complied with the duty to inform under art. 90 LOPDGDD.
  • The company expressly warned of potential disciplinary use.
  • The data has been handled proportionately, without continuous or indiscriminate monitoring.
  • The breach detected is sufficiently evidenced: a single data point does not suffice; it is cross-checked with other indications.
  • The disciplinary procedure respects the worker's rights (hearing, access to the data, the possibility to challenge it).

When one of these elements fails, the usual outcome is a declaration of unfairness or nullity of the dismissal in the labour court and the opening of an AEPD sanctioning procedure for disproportionate use.

Retention, access and tool provider

Essential operational aspects:

  • Retention period: strictly that necessary for the purposes. For service organisation, weeks or a few months. For billing, the relevant tax periods. For disciplinary use, until the final resolution of the proceeding.
  • Restricted access: only personnel with a direct organisational function should see the data. Block access for positions that do not need it.
  • Art. 28 GDPR contract with the telematics tool provider: the provider is a processor. The contract must regulate purposes, instructions, sub-processing, international transfers where applicable (Data Privacy Framework where relevant) and return of data on service termination.
  • Traceability: logs of who accesses what information and when, especially when used for disciplinary purposes.

Common mistakes

  • Installing GPS and not formally informing the worker (handing over the vehicle does not count as information).
  • Not informing the legal representation before implementing the system.
  • Keeping tracking active outside working hours without justification.
  • Accessing a specific worker's data without documented motivation (ad hoc tracking).
  • Keeping the information for years "just in case".
  • Not having a processor contract signed with the telematics provider.
  • Using geolocation as the only evidence in a dismissal without contrast with other indications.

Workplace geolocation checklist

  • Signed, archived, delivered internal geolocation policy.
  • Individual information to each worker, with signature of receipt.
  • Information to the legal representation before implementation.
  • Processing limited to working hours; deactivation or blocking outside hours.
  • Different retention periods by purpose.
  • Role-based restricted access and traceability of consultations.
  • Art. 28 GDPR contract with the telematics provider.
  • Verification of international transfers (DPF) if the provider operates outside the EEA.
  • Inclusion of the processing in the RoPA with all art. 30 GDPR elements.
  • Documented procedure for disciplinary use.

Frequently asked questions

Can a company install GPS in its vehicles without informing workers?

No. Art. 90 LOPDGDD requires prior, express, clear and unambiguous information to the worker and to the legal representation. Without that information, the evidence is not lawful and the AEPD sanctions the breach.

Can vehicle geolocation be used outside working hours?

No. Processing must be limited to effective working hours. Outside working hours, holidays or authorised personal trips, tracking must be deactivated or segregated. The right to digital disconnection in art. 88 LOPDGDD also applies.

Must the workers' legal representatives be informed before installing GPS?

Yes, where they exist. Art. 90 LOPDGDD expressly requires this, in addition to individual information to each employee. The communication must be prior, in writing and with proof of receipt.

Can the company use GPS data to sanction a worker?

Yes, if the system already complies with art. 90 LOPDGDD (express information, declared monitoring purpose, proportionality). The breach must be sufficiently evidenced and cross-checked with other indications. A single data point does not suffice.

This content is for general information purposes only and does not constitute specialist legal advice. The application of the rules to each specific case requires individual analysis. Spanish regional sector-specific rules and collective bargaining may extend or modify requirements.

Does your fleet have GPS and you are unsure whether worker information is properly done?

At Certix we assign you an expert in compliance for the transport sector. We review the policy, individual and collective information, and the contract with the telematics provider.

Talk to an expert

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →