Logistics and distribution
California privacy rights for employee drivers: what CCPA means for fleet data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Under the CCPA, employee drivers who live in California generally hold the same privacy rights as other consumers: notice at collection, access, deletion, correction, opting out of sale or sharing, and limits on sensitive personal information such as precise location. Fleets should map each right to ELD logs, GPS history and camera video before a request or a license arrives.
Key takeaways
- California employee drivers are generally treated as consumers under the CCPA, so workforce fleet data is in scope.
- Each right maps to specific systems: ELD logs, telematics history, camera video, safety scorecards and settlement records.
- Deletion has exceptions, such as records kept to meet a legal obligation or defend a claim, which counsel applies case by case.
- Precise location from telematics may be sensitive personal information, which narrows its use beyond running the job.
- Licensing fleet data raises separate sale, sharing and de-identification questions that are assessed deal by deal.
Do employee drivers have CCPA rights?#
Employee drivers who are California residents generally do have CCPA rights over the personal information their employer holds. The CCPA, as amended by the CPRA, no longer sets workforce data apart the way it once did, so current and former employees, applicants and many contractors are treated as consumers, subject to the law's coverage thresholds and exceptions.
The change has a date. The employee and business-to-business exemptions expired on January 1, 2023, after the legislature ended its 2022 session without extending them. Under the CPRA amendments, an employee may request the specific pieces of personal information held about them that were generated on or after January 1, 2022. Coverage still depends on thresholds: secondary guides report the annual gross revenue threshold was adjusted to $26,625,000 effective January 2025, and many fleets with 50 to 500 employees may clear it.
The rules are still moving. The California Privacy Protection Agency opened preliminary rulemaking on April 20, 2026 on how the CCPA applies to employee, job applicant and independent contractor information, so check for any proposed or final regulations before relying on current practice.
For a fleet, that reaches well beyond the HR file. A company driver's information sits in the ELD, the telematics platform, the dashcam system, the dispatch or delivery app, safety scorecards, vehicle inspection reports and payroll records. Each of those systems may hold data a driver can ask about.
Residency, not the route, is the usual starting point. A driver who lives in California and runs interstate is generally in scope; a Nevada-based driver who passes through the state raises different questions. Mixed fleets should settle the approach with counsel rather than deciding request by request.
Which rights reach which fleet records?#
Each CCPA right reaches a different slice of fleet data, and each comes with limits that counsel applies to the facts. The table maps the rights to the records a carrier or private fleet usually holds.
| Right | What a driver can ask for | Fleet records it reaches | Limits to check with counsel |
|---|---|---|---|
| Notice at collection | What is collected, why, and how long it is kept | Telematics, cameras, ELD, dispatch apps, payroll | Notice must keep pace when systems or uses change |
| Right to know or access | Categories and specific pieces of personal information held | Duty status logs, GPS history, event video, scorecards, coaching notes | Protections for other people's information, trade secrets and security |
| Right to delete | Deletion of personal information collected from the driver | Location history, video, app data, scorecards | Exceptions for legal obligations, legal claims, security and compatible internal uses |
| Right to correct | Correction of inaccurate information | Driver profile, scorecards, incident records | Disputed judgments may be annotated rather than changed |
| Right to limit sensitive data | Limits on uses beyond what the job needs | Precise location, driver's license numbers, driver-facing video used to identify a person | Uses needed for employment, safety and security may continue |
| Right to opt out of sale or sharing | No sale or cross-context sharing of their data | Any license or data exchange that includes driver data | Whether a transfer is a sale is assessed deal by deal |
| Non-retaliation | No adverse treatment for using these rights | Discipline, route assignment and pay decisions | Document the legitimate reason for any adverse action |
What should a driver privacy notice cover?#
A driver privacy notice should describe each category of fleet data in plain terms, the purpose for each and how long each category is kept. Generic HR notices often skip telematics and cameras entirely, which is the gap a California driver is most likely to raise.
- Location: GPS breadcrumbs, geofence events and stop locations, and whether tracking continues off duty or during personal conveyance.
- Hours of service: ELD duty status, edits, annotations and unassigned driving events.
- Video and audio: road-facing and driver-facing cameras, what triggers recording and whether audio is captured.
- Driving behavior: harsh braking, speeding, following distance, phone use alerts and the resulting scores.
- Vendors: which platforms process the data on the company's behalf.
- Retention: how long each category is kept, and what overrides it, such as an open claim.
Precise location and camera data are the sensitive categories#
Precise location is the fleet data most likely to count as sensitive personal information under California law. Frequent telematics pings can show where a driver lives, parks overnight and spends breaks, and drivers may have a right to limit its use to purposes the job requires.
Running dispatch, proving delivery, logging hours of service and investigating a crash are uses tied to the job. Building a driver-level dataset for a third party is not. Driver-facing video adds questions under biometric and recording laws that vary by state, and audio raises consent issues of its own.
The practical step is to tag sensitive fields in each source system, so access requests, deletion reviews and any later licensing review all work from one field map instead of three separate ones.
Handling access and deletion requests against telematics systems#
Access and deletion requests against telematics systems are mostly a search problem, because one driver appears under different identifiers in each platform. The same person may be a login in the ELD, a name in the dispatch app, an employee number in payroll and an unlabeled face in camera footage filed under a truck number.
Telematics and camera vendors usually act as service providers, so their contracts should require them to help with requests. A contract that is silent on that point is worth fixing at renewal.
- Verify the request and the driver's identity through HR, not dispatch.
- Search each system by every identifier: login, employee number and truck assignment dates.
- Check for holds first: accident claims, workers' compensation files and litigation notices override deletion.
- Apply legal-obligation exceptions, such as hours-of-service records federal rules require the carrier to keep.
- Ask service providers to act on approved deletions under the contract's privacy terms.
- Log the response, any exceptions applied and the date the request closed.
What changes if you license fleet data?#
Licensing fleet data adds a separate CCPA question: is the company selling or sharing driver personal information, or providing data that is genuinely deidentified? A license of identifiable driver records can count as a sale, which brings opt-out rights and notice duties into play.
California law sets conditions before data counts as deidentified. Under Cal. Civ. Code 1798.140(m), the information must not reasonably be linkable to a particular consumer, and the business must take reasonable measures against re-association, publicly commit not to re-identify it and contractually bind any recipient to the same terms. Counsel should confirm a package meets them. In practice, most fleet packages drop driver identity, coarsen location and leave out driver-facing video, which also lowers the privacy burden that reduces net value under the SourceX Enterprise Data Value Framework.
Illustrative: a produce distributor answers a driver's request#
Illustrative: a fictional produce distributor runs a private fleet of refrigerated trucks in California, with ELDs and road-facing cameras on one telematics platform and a separate driver app for proof of delivery. A former driver sends an access request soon after leaving.
The privacy lead finds the driver's data in five systems and learns that the camera platform files clips by truck, not by driver. The team pulls clips by assignment dates, withholds frames that show other employees and keeps hours-of-service logs under the legal-obligation exception. The request closes within the required time.
The work pays off later. When leadership considers licensing delivery exception records, the field map already exists, so the team scopes out driver identity, stop-level location and all camera footage, and records the reasoning for counsel's review.
How SourceX approaches driver data#
Driver records get their closest scrutiny at two points in the SourceX five-step transaction. Rights review reads driver notices, telematics and camera contracts and any labor agreement before scope is set. Preparation then strips driver identifiers and coarsens or removes precise location, and driver-facing video stays out by default. The privacy record and release authorization sit in the SourceX Evidence Packet, and nothing moves without the fleet's sign-off.
Frequently asked questions
Do owner-operators have the same rights as employee drivers?
Owner-operators who live in California are generally consumers under the CCPA as well, though the records a carrier holds about them differ: lease agreements, settlement statements and equipment data. Contractor status does not remove privacy rights, and the lease may add terms. Map their records separately from employee files.
Can a driver force deletion of ELD logs?
Usually not while federal hours-of-service rules require the carrier to keep them, because the CCPA has exceptions for information needed to comply with a legal obligation. FMCSA guidance says records of duty status and supporting documents must be kept for six months, and its ELD FAQ adds that carriers must store them in a manner that protects driver privacy. Once the required period passes and no claim or hold applies, the logs return to the normal retention schedule, and a deletion request may then reach them.
Does the CCPA matter if most of our drivers live outside California?
The law protects California residents, so drivers based elsewhere usually fall outside it, though their own state's laws may apply. California-based drivers on interstate runs remain in scope. Many mixed fleets apply one privacy standard to every driver rather than tracking residency record by record.
Are driver safety scores personal information?
Yes, when they are tied to a driver. Scores, rankings and coaching notes are inferences about a person, which the CCPA generally treats as personal information. A driver can ask to see them and to correct inaccurate entries, so keep the underlying events that support each score.
Who should own driver privacy requests at a fleet?
One owner, usually in HR or legal, with a named contact in safety and in IT for each fleet system. Dispatchers and safety coaches should route requests rather than answer them, because an informal reply can disclose another driver's data or miss a hold.
Sources
- The CCPA employee and B2B exemptions expired on January 1, 2023 after the legislature ended its 2022 session without extending them. Source
- Under the CPRA amendments, an employee may request specific pieces of personal information generated on or after January 1, 2022. Source
- Secondary guides report the CCPA annual gross revenue threshold was adjusted to $26,625,000 effective January 2025. Source
- The CPPA initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to employee, applicant and contractor information. Source
- Cal. Civ. Code 1798.140(m) sets the conditions for information to count as deidentified, including reasonable measures, a public commitment and contractual obligations on recipients. Source
- Motor carriers must keep records of duty status and supporting documents, such as bills of lading, for six months under 49 CFR 395.8(k)(1). Source
- FMCSA's ELD FAQ says carriers must retain ELD records and back-up data for six months and store them in a manner that protects driver privacy. Source
Related resources
- QuestionShould companies sell or license their data?
- QuestionDo I need customer consent to license support tickets?
- InsightDo former employees have to consent before a closed company licenses their messages?
- InsightCan HVAC and plumbing companies license technician helmet-camera footage?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.