The risk sitting in your fleet data right now
Every time one of your drivers turns on a telematics device, your company collects personal data: location, speed, braking behaviour, working hours. Add dashcam footage, fuel card transactions, and driver licence checks, and a typical fleet of 20 vehicles generates thousands of personal data points every single day.
Until now, the legal framework governing that data has been the UK GDPR and the Data Protection Act 2018. From June 2026, the Data (Use and Access) Act (DUAA) changes the rules. The Act received Royal Assent in June 2025, and key provisions are expected to come into force across 2026 (Fleet World, 2025).
If you manage a fleet, you almost certainly act as a data controller. That means the compliance obligations land with you, not solely with your telematics provider or leasing company.
What is the Data (Use and Access) Act?
The DUAA is the UK government's post-Brexit replacement and update to the data protection framework inherited from the EU. It does not tear up UK GDPR entirely; instead, it modifies and, in places, simplifies it, while introducing new obligations that matter directly to fleet operations.
The headline changes relevant to fleet managers are:
- Recognised Legitimate Interests (RLI). The Act introduces a shortlist of processing activities that automatically qualify as "legitimate interests," removing the need to conduct a balancing test each time. Some routine fleet monitoring activities may fall within these categories, but this is not a blanket exemption. You still need to document your lawful basis for every processing activity.
- Senior Responsible Individual (SRI). For many organisations, the formal Data Protection Officer (DPO) requirement is replaced by a designated Senior Responsible Individual. This person does not need to be a qualified lawyer, but they must have genuine accountability for data protection decisions and be named in your records.
- Record-keeping thresholds. Smaller organisations (broadly, those with fewer than 250 employees and no high-risk processing) face reduced record-keeping obligations. However, telematics data, dashcam footage, and driver behaviour monitoring are likely to count as high-risk processing, which means the reduced threshold will not apply to most fleets.
- Data Subject Access Requests (DSARs). The timeframe for responding to a DSAR remains 30 days, but the Act clarifies when requests can be refused or extended, particularly where requests are deemed "vexatious or excessive." Fleet managers who have received DSAR requests from departing drivers (a common scenario) will find this useful.
- Automated decision-making. If your fleet management system automatically flags drivers, restricts vehicle access, or feeds disciplinary processes without human review, the Act tightens the rules around this. Drivers gain stronger rights to contest purely automated decisions.
What are my obligations as a fleet manager?
Whether you run 5 vans or 500 HGVs, the following obligations apply if you collect data about drivers or vehicles.
1. Audit what data you actually hold
Start with a data mapping exercise. List every system that captures personal data: telematics platforms, dashcam systems, fuel cards, driver licence checking services, HR systems that hold vehicle allocation records, and any third-party apps your drivers use. For each one, document:
- What data is collected
- Why it is collected (your lawful basis)
- How long it is retained
- Who has access to it
- Whether it is shared with any third party (including your leasing company or insurance provider)
2. Appoint and name your Senior Responsible Individual
If you do not currently have a DPO, you need to designate an SRI before the relevant DUAA provisions come into force. For a small fleet operation, this is often the fleet manager, office manager, or a director. The role requires genuine engagement with data protection decisions, not just a job title on a document.
3. Review your driver privacy notices
Your drivers have a right to know what data you collect and why. If your privacy notices still reference only UK GDPR without accounting for the DUAA changes, update them before June 2026. Notices must be written in plain language, not legal boilerplate.
4. Assess automated decision-making in your systems
Review whether your fleet management platform makes any decisions about drivers automatically. Common examples include: automatic penalty point flags that trigger HR processes, speed threshold alerts that are sent directly to a line manager without fleet manager review, and insurance scoring that affects a driver's ability to use certain vehicles. Each of these needs a human review step, and drivers must be told that automated processing occurs.
5. Check your contracts with telematics and data providers
Under UK GDPR and the DUAA, if a third party processes personal data on your behalf, you need a Data Processing Agreement (DPA) in place. Many telematics contracts include these, but they are often out of date or signed by a previous manager. Review and re-sign where necessary before June 2026.
What happens if I get it wrong?
The Information Commissioner's Office (ICO) enforces data protection law in the UK. Fines under UK GDPR can reach the higher of £17.5 million or 4% of global annual turnover for the most serious breaches. For less severe infringements, the cap is £8.7 million or 2% of global turnover.
For a small fleet operator, the realistic risk is not a nine-figure fine. It is:
- An ICO investigation triggered by a driver complaint, which consumes management time and damages reputation
- A formal reprimand or enforcement notice requiring you to change systems within a fixed deadline
- Civil claims from drivers whose data was mishandled (a growing area of litigation)
- Reputational damage with employees, insurers, and customers if a breach becomes public
The DUAA does not reduce these enforcement powers. In some areas, it gives the ICO additional tools (Fleet World, 2025).
What does compliance actually look like?
For a fleet operator of any size, a realistic compliance programme before June 2026 looks like this:
By end of Q3 2025:
- Complete a data mapping exercise covering all fleet systems
- Identify your SRI and document the appointment internally
- Pull every third-party data processing contract and check it has a current DPA
By end of Q4 2025:
- Update driver privacy notices to reflect current processing activities
- Review your telematics and dashcam retention policies (most fleets retain dashcam footage far longer than necessary, creating unnecessary risk)
- Conduct a brief DSAR simulation: could you respond fully within 30 days if a driver submitted a request tomorrow?
By end of Q1 2026:
- Map any automated decision-making in your fleet platform and add human review steps where required
- Brief your SRI and any managers who handle driver data on the key changes
- Re-run your data mapping exercise if you have changed telematics providers or added new systems
Before June 2026:
- Confirm all DPAs are signed and current
- Ensure your privacy notices are live and accessible to drivers
- Document that you have completed the above steps (the ICO expects to see evidence of compliance, not just assurances)
None of this requires a specialist law firm. It requires time, organisation, and a willingness to treat driver data with the same seriousness you would apply to financial records.
One-glance summary
- What is changing: The Data (Use and Access) Act modifies UK GDPR from June 2026, affecting how fleets collect, store, and process driver data.
- Key new concepts: Recognised Legitimate Interests, Senior Responsible Individual, clearer rules on automated decision-making, refined DSAR handling.
- Who it affects: Any fleet operator that uses telematics, dashcams, fuel cards, or driver licence checking services (that is, almost every fleet).
- Maximum fines: Up to £17.5 million or 4% of global turnover for serious breaches.
- Your immediate actions: Data audit, appoint SRI, review DPAs, update privacy notices, check automated decision-making processes.
- Deadline: Key provisions in force from June 2026; start now to avoid a last-minute scramble.
This post is for general information only and does not constitute legal advice. If you have specific concerns about your organisation's compliance position, consult a qualified data protection professional.
Get weekly fleet compliance updates
One concise email per week on UK and DE fleet regulation changes. No spam, unsubscribe anytime.
We only use your email for the newsletter.
