Skip to content

Home services and trades

Technician GPS and timecard data: privacy rules before sharing

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Technician GPS tracking and timecard data is personal information about employees, so notice, privacy and recordkeeping rules need checking before any of it leaves the company. The working rule: share job-level aggregates such as drive time and time on site, keep exact routes and location pings in-house, and confirm which state rules apply with counsel.

Key takeaways

  • GPS pings, clock-in locations and job timestamps can reveal a technician's movements, home address and habits.
  • California's CCPA has covered employee data since its employee exemption expired on January 1, 2023, while many other state privacy laws exclude employment data.
  • Some states require notice before employers monitor employees electronically, so confirm what your technicians were told and when.
  • Aggregate to job-level durations and service zones before sharing; exact routes rarely need to leave the company.
  • Time cards carry wage-hour retention duties, so sharing a copy never replaces keeping the original.

What technician location and time records reveal#

Technician GPS and timecard records reveal where a named employee was, minute by minute, which makes them personal information even when collected for dispatch or payroll. Joined with customer addresses, they also show which homes a technician entered and when.

The records are spread across systems that rarely talk to each other, so a sharing request for one of them often pulls in more than anyone intended.

What technician location and time records reveal
RecordTypical systemWhat it can reveal
Vehicle location pings and trip historyFleet telematics platformHome address, breaks, personal stops and driving behavior
Clock-in and clock-out with locationField service mobile app or time clockWhere a technician started and ended the day
Job status timestampsServiceTitan, Housecall Pro, Jobber or FieldEdgeDispatched, en route, on site and completed times for each job
Timesheets and payroll recordsPayroll or HR systemHours, overtime, pay rates and deductions
Biometric punchesFingerprint or face time clocksBiometric identifiers covered by separate laws
Dash cam footageTelematics camerasFaces, voices, license plates and locations

Which privacy rules may apply#

Several layers of rules may apply to technician location and time data, and which ones do depends on where your technicians live and work. Treat the list as questions for counsel, not conclusions.

Because these rules differ by state and by record type, they are assessed deal by deal, before any record leaves the company.

  • State electronic monitoring rules: a few states require employers to give written notice before monitoring employees electronically, and some limit tracking devices on vehicles.
  • California's CCPA: its employee exemption expired on January 1, 2023, and the California Privacy Protection Agency opened preliminary rulemaking on April 20, 2026 on how the law applies to employee, applicant and contractor data.
  • Other comprehensive state privacy laws: many exclude employment-context data, as the Virginia and Colorado laws do, though definitions differ.
  • Biometric privacy laws: the Illinois Biometric Information Privacy Act covers fingerprint and face scans, with liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation; a 2024 amendment limits recovery to one violation per person when the same identifier is collected repeatedly by the same method.
  • Wage-hour recordkeeping: Department of Labor guidance says time cards should be kept for two years and payroll records for three.
  • Collective bargaining agreements and your own handbook, which may limit how tracking data can be used.

Why exact routes rarely leave the company#

Exact routes rarely leave the company because they identify people even after names are removed. A trace that starts and ends at the same house each day points to the technician's home, and every stop in between points to a customer's.

Outside parties seldom need that detail. Routing software vendors, benchmarking projects and AI developers studying field service work usually want the shape of the work: how long jobs take, how travel time varies by zone and hour, and how schedules hold up against emergency calls. Job-level aggregates answer those questions without exposing anyone's movements.

Keep raw traces inside the company for the purposes employees were told about, such as dispatch, safety and payroll checks, on retention settings you chose deliberately. Telematics vendors apply their own defaults: Samsara, for example, keeps DVIR and Hours of Service data in the cloud for as long as you are a customer unless you change its data retention settings.

What to aggregate before anything is shared#

Aggregation turns location and time records into work measures that no longer track a person. Apply these steps to any extract before it leaves the company, and leave the original data where it is.

Then test the result by trying to re-identify someone. If a dispatcher could look at the extract and name the technician or the customer, aggregate further.

  • Convert GPS pings into job-level fields: drive time to the job, time on site and time to the next job.
  • Drop the first and last legs of each day, which start or end at a technician's home.
  • Replace street addresses with service zones large enough that a single home cannot be picked out.
  • Replace technician names with stable codes, and remove codes for anyone whose role makes them easy to spot.
  • Round timestamps and remove off-clock, lunch and personal-use periods entirely.
  • Suppress small groups, such as a zone served by one technician or a job type only one person performs.

Notice and policy checks before sharing#

Notice and policy checks confirm that what technicians were told matches what you now plan to do. A GPS policy that says tracking is for dispatch and safety does not obviously cover sharing derived data with a vendor or licensing it.

Where the notice falls short, update it before sharing anything and explain the change to technicians in plain words. An employee notice about data licensing can do that job if licensing is on the table.

Notice and policy checks before sharing
CheckWhere to lookWhat to confirm
Monitoring noticeHandbook, signed acknowledgments, onboarding packetNotice was given where state law requires it, before tracking began
Stated purposeGPS or vehicle use policyWhether the planned use fits the purposes described
Vendor termsTelematics and field service contractsWho controls the data and whether exports for other uses are allowed
Labor agreementsCollective bargaining agreement, if anyLimits on using tracking or timekeeping data
Biometric consentTime clock enrollment formsWritten consent and a retention schedule where biometric laws apply

Illustrative: an electrical contractor reviews its fleet data#

Illustrative: a fictional electrical contractor runs service vans on a telematics platform and logs job timestamps in its field service system. A routing software vendor asks for historical data to tune a scheduling model, and separately the owner is exploring licensing de-identified job histories.

The COO finds that the GPS policy technicians signed mentions dispatch, safety and payroll only, and that one state where the company works has a monitoring notice rule. Counsel recommends updating the notice first. The company then shares job-level drive and on-site durations by service zone, with technician codes and no traces, and keeps raw GPS history inside the company.

How SourceX handles workforce location data#

SourceX treats technician location and time data as high-sensitivity material within the SourceX five-step transaction. The Rights step checks employee notices, monitoring rules and vendor terms, the Preparation step aggregates or removes location detail, and the supplier approves the final scope before Delivery.

The SourceX Evidence Packet documents what was aggregated or removed, the permitted use and who authorized release, so the company can show technicians and counsel exactly what left and in what form. Nothing is shared during the initial fit check.

Frequently asked questions

Do we need technician consent or just notice to track company vans?

It depends on the state and the device. Many employers rely on notice for company vehicles used for work, while tracking personal phones or off-duty time raises harder questions, and some states set specific notice requirements. Have counsel review your policy for each state where technicians drive.

Does tracking through a technician's personal phone change things?

Often, yes. When the field service app runs on a personal phone, location collection can continue outside work hours unless the app limits it to clocked-in periods. Confirm the app's location settings, tell technicians when location is collected and exclude off-clock data from anything you keep or share.

How long must we keep timecards?

Department of Labor guidance under the Fair Labor Standards Act says records on which wage computations are based, such as time cards, should be kept for two years, and payroll records for at least three. State rules can require longer. Sharing a copy with anyone never replaces keeping the original.

Can technicians ask to see their location data?

In some states, yes. Under California's law as amended by the CPRA, an employee of a covered business may request the specific pieces of personal information the employer holds about them that were generated on or after January 1, 2022. Other states vary, so set up a simple request process either way.

Is dash cam footage treated like GPS data?

Dash cam footage is more sensitive. It can show faces, voices, license plates and homes, and cameras that record audio inside the cab can raise recording consent questions. Keep footage out of any shared dataset unless counsel approves a specific, de-identified use.

Sources

  • The California legislature did not extend the CCPA employee and business-to-business exemptions, so they expired on January 1, 2023. Source
  • The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 focused on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial or employment context. Source
  • The Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context and does not apply to data maintained for employment records purposes. Source
  • The Illinois Biometric Information Privacy Act lets a prevailing party recover liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, or actual damages if greater; Illinois SB 2979, signed August 2, 2024, limits recovery to a single violation per person when the same biometric identifier is collected repeatedly by the same method. Source
  • DOL Fact Sheet 21 states employers shall preserve payroll records for at least three years, and for two years records on which wage computations are based, such as time cards. Source
  • Samsara customers can customize data retention under Settings > Data Retention, and by default Samsara keeps DVIR and Hours of Service data in the cloud for as long as you are a customer. Source
  • Under the CPRA amendments, an employee may request the specific pieces of personal information an employer holds about them that were generated on or after January 1, 2022. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify