Logistics and distribution
Is fleet GPS and ELD data personal information?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Fleet GPS and ELD data is often personal information, because it can be linked to the driver who was logged in or assigned to the truck. ELD records are built around a driver by design. The working test: if anyone holding the data could reasonably tie a trip, stop or log entry to a person, treat it as personal information.
Key takeaways
- ELD records are driver records by design, because every duty status entry belongs to a logged-in driver.
- GPS data from a truck becomes personal information when the truck is assigned to one driver or a trip starts at a home.
- Unit numbers, timestamps and trip endpoints can identify a driver even after names are removed.
- Aggregated lane, facility and dwell statistics are usually far less identifying than raw breadcrumbs.
- Whether data counts as personal information is a legal test applied with counsel, not a label fixed to a field.
The short answer: often yes#
Fleet GPS and ELD data is often personal information because most of it can be linked to a specific driver. Privacy laws generally define personal information as data that identifies, relates to or could reasonably be linked with a person, and a truck's position at a moment when one driver is at the wheel fits that description.
Owning the truck does not change the answer. The company owns the tractor and the telematics account, but the movement history describes what a person did during a shift. Which laws apply, and what duties follow, depends on where drivers live, the company's size and the intended use, which counsel assesses case by case.
Location adds a second layer. Several state privacy laws, California's among them, may treat precise geolocation as sensitive data, which can bring consent requirements or limits on uses beyond the job. Coarsened or aggregated location often falls outside that category, but the threshold depends on each law's definition.
Why ELD records are driver records by design#
ELD records are driver records by design, because the device logs hours of service against a driver login. Each duty status change, from off duty to driving to on duty not driving, is attributed to a named driver and usually stamped with a location.
The surrounding entries reinforce that link. Edits and annotations show who proposed a change and why. Unassigned driving events are later claimed by a driver. Team trucks record a co-driver. Even engine hours and odometer readings, which describe the vehicle, sit inside a log whose purpose is to show one person's compliance.
GPS breadcrumbs from the same platform are one step removed, since they follow the vehicle. They become driver data the moment they are joined to the log, the dispatch assignment or the payroll record, which in most fleets is a single query away.
What makes fleet location data identifiable#
Fleet location data becomes identifiable through direct identifiers, through proxies that stand in for a driver, and through patterns that only one person could have produced. Removing names deals with the first group only.
The right mix of reductions depends on the use. Internal route planning may need full detail under access controls; any data leaving the company usually needs most of the steps in the right-hand column.
| Factor | Why it identifies a driver | How to reduce it |
|---|---|---|
| Driver login or ID | Directly names or keys to a person | Remove, or replace with a token only the fleet can resolve |
| Truck assigned to one driver | The unit number becomes a proxy for the driver | Replace unit numbers and VINs with tokens; keep assignment tables internal |
| Trip start and end points | Overnight parking can reveal a home or a regular stop | Trim or blur the first and last segments of each trip |
| Precise coordinates with timestamps | A unique path through time belongs to one person | Coarsen to an area grid or lane and round times |
| Rare events | A crash or roadside inspection on a known date points to one driver | Remove or generalize dates and places of rare events |
| Small fleets or rare lanes | Few drivers means few candidates | Aggregate across drivers and periods before use |
| Linked records | Payroll, settlements and dispatch notes reconnect identity | Keep linking tables inside the company |
When fleet data is not personal information#
Fleet data is least likely to be personal information when it describes vehicles, facilities or lanes rather than a shift. Average dwell time at a customer dock across many visits, transit time on a lane across many trucks and fuel economy by truck model are typical examples.
The edge cases are where mistakes happen. Pooled trucks still carry a driver on each trip, and the dispatch record can reconnect them. A dwell report on a rural customer may cover only one regular driver. Data that is not personal information on its own becomes personal information again once it is joined to a roster.
- Can the fleet, a vendor or a recipient join the data back to a roster, schedule or payroll file?
- Do any trips start or end at a residence or a driver's regular parking spot?
- Is any lane, customer or time window served by a single driver or a very small group?
- Are rare events, such as crashes, inspections or roadside stops, dated and located?
- Does any free text, such as a log annotation or dispatch message, name or describe a person?
ELD and GPS fields: drop, transform or keep#
ELD and GPS fields fall into three treatments once a fleet decides to use them beyond operations: drop, transform or keep. The table shows a common starting point that counsel and the privacy lead then adjust for the specific use.
| Field | Personal information when linked? | Common treatment |
|---|---|---|
| Driver name, login, license number | Yes | Drop |
| Co-driver and unassigned driving claims | Yes | Drop or tokenize |
| Duty status changes with time and place | Yes | Keep the status sequence; coarsen time and place |
| Edit and annotation text | Often | Review free text; remove names and personal reasons |
| GPS breadcrumbs | Yes when tied to a shift | Coarsen, trim trip ends or aggregate to lanes |
| Engine hours, odometer, fault codes | Sometimes, through the truck | Keep with tokenized unit numbers |
| Geofence arrivals and departures at customers | Sometimes | Keep as facility events with the driver removed |
Illustrative: a beverage distributor reviews its route data#
Illustrative: a fictional beverage distributor runs its own delivery trucks on a telematics platform that combines ELD logs, GPS and engine data. Operations wants stop-level dwell history for route planning, and the CEO asks whether the same history could be licensed.
The general counsel finds that most route trucks stay assigned to one driver for years, so the unit number identifies a person. Breadcrumbs usually start at the yard, but a few drivers take trucks home. Log annotations include notes about family calls and medical appointments.
The decision: dwell and service-time events at customer stops are kept with driver and unit identifiers replaced by tokens and times rounded, while breadcrumbs, annotations and any trip that starts off the yard are excluded. Route planning keeps full detail internally; any external package gets only the reduced version.
How SourceX handles fleet location data#
SourceX starts from the assumption that fleet GPS and ELD records identify drivers until shown otherwise. Within the SourceX five-step transaction, rights review and preparation work through the factors in the tables above, so identifiers and proxies are removed or transformed before the fleet approves any scope. The SourceX Evidence Packet lists which fields were dropped, coarsened or tokenized, so the privacy record travels with the data.
Frequently asked questions
Is a VIN personal information?
A VIN identifies a vehicle, not a person, but it can become personal information once the vehicle is assigned to one driver or joined to a roster. In fleet datasets, treat unit numbers and VINs as indirect identifiers and replace them with tokens unless the truck is pooled and the link to drivers is broken.
Is hashing driver IDs enough?
Usually not on its own. A hashed ID still lets anyone follow one driver's full history, and anyone with the roster can recreate the hash. Hashing is pseudonymization: helpful, but location patterns, trip ends and rare events can still point to a person, so fleets combine it with coarsening and aggregation.
Do federal ELD rules decide who can use the data?
Federal ELD rules focus on how hours of service are recorded, transferred and kept, not on whether the data is personal information under privacy laws. FMCSA's ELD FAQ does say carriers must keep ELD records and back-up data for six months and store them in a manner that protects driver privacy, which is a useful signal that regulators see these logs as driver data. That question comes from state privacy laws, employment law, labor agreements and the telematics contract, which counsel reads together.
Does customer delivery location data raise the same issue?
Customer delivery points are usually business addresses, which are not personal information in themselves. Residential deliveries differ: an address plus a delivery time can identify a household. Fleets with home deliveries should treat those stops like any other personal data.
Is the answer different for owner-operators?
Owner-operators are often easier to identify, because the truck, the operating authority and the business may all belong to one person. Their data is usually personal information when linked to them, and the lease may also set terms on how the carrier uses equipment data.
Sources
- FMCSA's ELD FAQ says carriers must retain ELD records and back-up data for six months and store them in a manner that protects driver privacy. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.