GDPR in Transport and Logistics — Driver Data, Fleet and Carriers
Transport and logistics rely on the efficient flow of information. Personal data are involved at almost every stage of this process. Companies process driver data, vehicle location data, working-time information and shipment recipient data. They also use telematics systems, mobile applications and external carriers. In this sector, the GDPR intersects with transport regulations, employment law and day-to-day transport operations. Tachographs, GPS monitoring and extensive subcontracting chains are particularly important.
The scale of the risk is well illustrated by the DPD Polska case. In a decision described on 23 February 2026, the President of UODO imposed fines totalling PLN 11.46 million. The first concerned the absence of required data processing agreements with carriers. The second resulted from a failure to implement appropriate organisational measures for data security. The case shows that data protection does not end with IT systems. It also covers loading, transport, delivery and access by people working with the company.
In this article, I explain how to structure the key data processing activities in a transport company. I discuss driver data, GPS monitoring, tachographs, cooperation with carriers and practical security rules.
What Data Does a Transport and Logistics Company Process?
The scope of processing depends on the type of business. A road carrier operates differently from a logistics operator or courier company. However, several basic categories of data can usually be identified.
Driver data. These include identification details, driving licence data, driver card information and employment-related documents. A company may also process GPS location, working time, driving style and tachograph data. In certain cases, health information may also be involved.
Sender and recipient data. These usually include a first name, surname, address, telephone number and delivery-related information. Some of these data appear on labels, transport documents or courier applications.
Data relating to contractors and their employees. An organisation processes information about contact persons working for customers, carriers, freight forwarders and service providers.
Data from operational systems. TMS systems, telematics and mobile applications may combine information about routes, vehicles, drivers and shipments.
Each category requires a defined purpose, legal basis and retention period. In addition, some processing activities are subject to specific transport or employment-law requirements.
Driver Data — GPS Monitoring and Telematics
A vehicle’s location may constitute the driver’s personal data. This is the case where an organisation can link the vehicle to a specific person. Telematics systems often also process information about speed, route history and driving style. Their use therefore requires an assessment from a GDPR perspective. If monitoring involves employees, employment-law requirements must also be taken into account. A business justification or the purchase of a suitable system is not enough.
Purpose and Legal Basis for Monitoring
The organisation should first determine why it collects location data. The purpose may include work organisation, fleet management, route settlement or protection of company vehicles. In the case of employee monitoring, UODO points to the possible use of Article 6(1)(f) GDPR. However, this requires a balancing test. The employer must also comply with restrictions under the Polish Labour Code. Monitoring should not automatically be based on employee consent. Due to the imbalance between the parties, the voluntary nature of such consent may be questionable.
Employee Monitoring and Transparency Obligations
GPS used to monitor employees may constitute another form of monitoring under Article 22³ § 4 of the Polish Labour Code. The employer should define the purpose, scope and method of monitoring in an appropriate internal document. This may be workplace regulations, a collective agreement or a notice. In addition, employees must be informed about the introduction of monitoring at least two weeks before it begins. A new employee should receive the required information before being allowed to start work.
Proportionality and Data Minimisation
Monitoring should cover only the data necessary for the defined purpose. If a less intrusive solution is sufficient, it should be preferred. Particular caution is required where vehicles may also be used privately. Continuous tracking outside working hours may interfere excessively with the driver’s privacy. It is therefore worth considering a private mode or another solution limiting location recording. The driver should also know what data the company collects and how long they are retained.
Tachographs, Driver Cards and Working-Time Records
Not all driver data are processed solely for fleet management purposes. Some obligations arise directly from transport legislation. Regulation (EU) No 165/2014 governs the use of tachographs. Regulation (EC) No 561/2006 sets rules on driving times, breaks and rest periods. Where processing is necessary to comply with statutory obligations, Article 6(1)(c) GDPR will generally provide the legal basis. However, this does not allow unrestricted use of the data. Information from tachographs and driver cards remains personal data.
The organisation should restrict access to authorised persons and adequately protect the documentation. It must also determine retention periods required by the applicable legislation. Tachograph data should also be distinguished from GPS data. The former primarily support compliance with transport obligations and working-time controls. The latter may support operational management. If the company uses these data for additional purposes, it should assess those purposes separately.
Sharing Driver Data with Customers and Platforms
In everyday logistics operations, driver data are often shared with other entities. For example, a shipment recipient may see the driver’s name and telephone number. Similar information may be provided to customers, freight forwarders or transport platform operators. Each disclosure requires a defined purpose and an appropriate legal basis. The data disclosed should also be limited to what the recipient genuinely needs.
It is therefore worth determining who receives driver data and for what purpose. The process should then be properly reflected in the documentation and information provided to third parties. It should also not be assumed that every recipient acts as a processor. The role must be assessed based on how the data are actually processed.
Carriers and Subcontractors — Roles and Data Processing Agreements
The logistics chain often involves many independent entities. These may include carriers, freight forwarders, warehouses, telematics providers, TMS providers and settlement service providers. One of the most important tasks is therefore to correctly determine the roles of each participant. Not every business relationship automatically requires a data processing agreement. The decisive question is whether the entity processes data on behalf of the controller.
If an entity acts on the controller’s instructions and on its behalf, it may act as a processor. In that case, an agreement compliant with Article 28 GDPR is required. By contrast, an entity that independently determines the purposes and means of processing may act as a separate controller. In such a case, data sharing must be appropriately regulated.
Lessons from the DPD Polska Case
In the DPD Polska case, UODO challenged cooperation with certain external carriers without the required data processing agreements. The carriers participated in loading and unloading shipments. They therefore had access to address labels containing personal data. The authority also examined how authorisations to process personal data were organised. The company had not effectively implemented its own rules for granting such authorisations.
The President of UODO imposed a fine of PLN 6.251 million for the absence of data processing agreements. The second infringement resulted in a fine of PLN 5.209 million. The case shows that the title of a transport agreement alone does not determine a contractor’s role. The actual scope of activities and access to data must be analysed. Effective authorisations, instructions and access controls are equally important. Documentation should reflect how the organisation actually operates.
Data Security in Transport and Logistics
Data in the transport sector are often present in many places at the same time. Employees use mobile applications, TMS systems, telematics and transport documents. This operating model requires appropriate technical and organisational measures. Under Article 32 GDPR, the organisation should select safeguards appropriate to the level of risk. In practice, particular attention should be paid to:
- access control — users should only have access to data necessary for their duties,
- mobile device security — phones and tablets should have appropriate safeguards,
- encryption and transmission security — particularly when data are exchanged between systems,
- limiting data visibility — labels and applications should not reveal unnecessary information,
- authorisation management — access should be granted, updated and revoked in a structured manner,
- incident response procedures — employees should know how to report a lost device or unauthorised access.
Risks connected with paper documentation should also be considered. Data may be disclosed not only through an IT system, but also during the physical handling of shipments.
Transfers of Data Outside the EEA
International transport may involve transfers of data outside the European Economic Area. However, the mere fact that a driver passes through a third country does not automatically constitute a transfer under Chapter V GDPR. What matters is how data are actually disclosed to another entity.
Risks may arise when using foreign platforms, cloud providers or external support centres. The organisation should therefore determine where the data go and who may access them. If a transfer takes place, an appropriate legal mechanism must be used. This may be an adequacy decision or Standard Contractual Clauses. In certain cases, an additional transfer risk assessment may also be required.
Common Data Protection Mistakes in Logistics
No analysis of contractors’ roles. The organisation does not determine whether a carrier, freight forwarder or system provider acts as a controller or processor.
No required data processing agreements. An entity processes data on behalf of the company, but the parties have not concluded an agreement compliant with Article 28 GDPR.
GPS monitoring without proper implementation. The employer has not defined monitoring rules or informed employees within the required timeframe.
Excessive driver tracking. The system collects more data than necessary or also covers private time.
Combining different processing purposes. The company uses tachograph and GPS data without separately analysing the legal basis and scope.
Unrestricted access to data. Too many people can view information in applications, documents or operational systems.
Ineffective authorisation management. The organisation does not properly grant, update and revoke access rights.
Ignoring transfers outside the EEA. The company fails to verify foreign platform, cloud or support-service providers.
GDPR in a Transport Company — Practical Checklist
- Map the processing activities relating to drivers, recipients, contractors and systems.
- Define purposes and legal bases for individual categories of data.
- Review GPS monitoring rules and requirements under the Polish Labour Code.
- Inform employees about monitoring within the required timeframe and scope.
- Assess the proportionality of monitoring and the possibility of limiting data collection outside working hours.
- Establish rules for processing tachograph and driver card data.
- Set retention periods in accordance with applicable legislation and processing purposes.
- Analyse the roles of carriers, freight forwarders and service providers.
- Conclude the required data processing agreements and verify how they are implemented in practice.
- Regulate the disclosure of driver data to customers, platforms and contractors.
- Implement appropriate security measures and an effective authorisation management system.
- Check whether transfers outside the EEA take place and apply the required safeguards.
- Prepare appropriate privacy notices for drivers, recipients and other individuals.
- Include the processing activities in the records of processing activities and update the documentation regularly.
Do You Need to Bring Your Transport Company into GDPR Compliance?
Transport and logistics require data protection rules to work alongside day-to-day operational practice. Driver monitoring, data flows between entities and the security of the entire logistics chain are particularly important.
At Dr Joanna Maniszewska-Ejsmont Law Firm, we support transport and logistics companies in structuring their data processing activities. We help assess legal bases, determine contractors’ roles and prepare the required data processing agreements.
We also support organisations in implementing GPS monitoring in compliance with the GDPR and employment law. We prepare documentation, assess risks and help select appropriate security measures.
Contact us — we will help tailor the solutions to the scale of your operations, organisational structure and actual logistics processes.
