If your company runs even a handful of vehicles, the Driver and Vehicle Licensing Agency (DVLA) holds data that directly affects your legal obligations. Most fleet managers know the DVLA issues licences and registers vehicles, but far fewer understand exactly who the DVLA shares that data with, under what conditions, and what that means for the employer sitting between the regulator and the driver.
Get this wrong and you face gaps in your duty-of-care process, potential liability if an unlicensed driver causes an incident, and possible scrutiny from the Health and Safety Executive or your insurer. This post explains the framework plainly so you can act on it.
What is DVLA data sharing?
The DVLA holds two main categories of data relevant to fleet operators:
- Driver records: licence status, endorsements, penalty points, medical restrictions, and entitlement categories (e.g. B, C, D, CE).
- Vehicle records: registered keeper details, MOT status, tax status, and technical specifications.
The DVLA does not keep this data entirely to itself. Under the Road Traffic Act 1988 and subsequent regulations, it is authorised to disclose information to specific recipients for specific purposes. The official list of who the DVLA shares data with is published and updated at gov.uk.
Recipients include:
- Police forces and other law-enforcement bodies.
- Courts and the Driver and Vehicle Standards Agency (DVSA).
- Local authorities (including for ULEZ and Clean Air Zone enforcement).
- Insurance companies (via the Motor Insurance Bureau).
- Approved third-party organisations, which include fleet-management and licence-checking providers.
That last category is the one most relevant to fleet operators. Approved third parties can query licence data on your behalf, but only with the explicit consent of the individual driver. Without that consent, the query cannot lawfully proceed.
What are my obligations as a fleet operator?
1. Obtain and record driver consent
Before any third-party licence check takes place, each driver must give informed consent. This is not a one-off tick-box. Best practice, and the standard expected by most insurers and the HSE, is to renew consent each time a check is run, or to hold a standing consent that the driver can withdraw at any time.
Your consent process should be documented. If a driver refuses consent, you cannot force the check, but you should not allow that driver to operate a company vehicle until the situation is resolved through your internal policy.
2. Run checks at a defensible frequency
There is no single statute that prescribes exactly how often fleet licence checks must occur, but the HSE's guidance on managing work-related road risk and the Fleet Operator Recognition Scheme (FORS) both point to a risk-based approach:
- Low-risk drivers (occasional business miles, clean licence): at least once per year.
- Medium-risk drivers (regular business use): every six months.
- High-risk drivers (professional drivers, HGV/PSV, previous endorsements): every three months or more frequently.
The Road Traffic Act 1988 makes it an offence to cause or permit an unlicensed driver to drive. Demonstrating a regular, documented checking regime is your primary defence if something goes wrong.
3. Keep your own records accurate
If your business operates as an Authorised Testing Facility (ATF) or interacts with the DVLA in an official capacity, you have an additional obligation: keep your contact details current. The DVLA requires ATFs to notify it promptly of any changes to contact information via the dedicated process at gov.uk/guidance/tell-dvla-about-changes-to-your-atf-contact-details. Stale contact details can delay communications about inspections, approvals, or compliance notices.
For standard fleet operators, the equivalent obligation is to ensure that the registered keeper details for all your vehicles are correct and updated within the legally required timeframe whenever a vehicle changes hands, is taken off the road, or is disposed of.
4. Understand what data you can and cannot use
Data obtained from the DVLA through an approved third party can only be used for the purpose stated at the point of consent. Using driver licence data for any other purpose (for example, passing it to a debt recovery company or sharing it with an unrelated third party) would breach both the DVLA's terms and UK GDPR obligations under the Data Protection Act 2018.
What happens if I get it wrong?
Permitting an unlicensed driver
Under Section 143 of the Road Traffic Act 1988, using or permitting the use of a vehicle without a valid licence or insurance is a criminal offence. An employer who fails to check and thereby allows an unlicensed driver to operate a company vehicle can face prosecution. Conviction can result in unlimited fines in the Crown Court, and the reputational damage to a business is considerable.
HSE enforcement
The HSE can investigate road traffic incidents involving employees driving for work. If an investigation reveals no licence-checking regime was in place, the employer may face improvement notices, prohibition notices, or prosecution under the Health and Safety at Work etc. Act 1974. Fines under this Act have reached seven figures for serious failures.
Insurance voidance
Most commercial fleet policies contain a condition that the insured will maintain adequate driver-vetting procedures. If a claim arises and the insurer discovers no licence checks were being conducted, it may decline to indemnify, leaving the business personally liable for third-party damages. Those costs can be ruinous for a small or mid-sized company.
Data protection breaches
Misuse of DVLA-sourced driver data is a UK GDPR matter. The Information Commissioner's Office (ICO) can fine organisations up to £17.5 million or 4% of global annual turnover (whichever is higher) for serious breaches.
What does compliance actually look like?
A functional, defensible programme for most small-to-mid-sized fleets involves the following components:
Driver consent capture. A signed (paper or digital) consent form for each driver, filed against their employee record, stating precisely what data will be checked and how often.
A regular check schedule. Checks run on the appropriate frequency for each risk tier. Automated reminders are far more reliable than manual diaries.
A clear escalation policy. If a driver has accrued points that change their risk tier, or if a licence has been revoked, you need a written procedure for what happens next: restricted vehicle access, referral to HR, or temporary suspension from driving duties.
Registered keeper accuracy. All vehicles on your fleet should show the correct registered keeper in the DVLA's records. Run a periodic audit against your own asset list.
Audit trail. Every check, every consent form, every escalation decision should be logged with a date and the name of the person who acted. If the HSE or an insurer asks for evidence, you need to produce it quickly.
Contact details hygiene. If you are an ATF or hold any formal relationship with the DVLA, update your contact information promptly whenever it changes, using the process described at gov.uk.
The DVLA itself has invested significantly in its service infrastructure. In 2023, it became the first government organisation in the world to achieve 5-Star Service Desk Institute certification (gov.uk), which means queries and issues raised through official channels are handled to a demonstrably high standard. If you have a legitimate dispute about data held on a driver or vehicle, the official channels are your first port of call.
Summary: one-glance checklist
- Obtain written, informed consent from every driver before running any DVLA data check.
- Check licences at least annually for low-risk drivers; every three months for high-risk or professional drivers.
- Document every check, consent, and escalation decision with a date and responsible person.
- Ensure all company vehicles show the correct registered keeper in DVLA records.
- Update DVLA contact details promptly if your business is an ATF or holds an official DVLA relationship.
- Use DVLA-sourced data only for the purpose consented to; any other use risks UK GDPR liability.
- Maintain a written escalation policy for drivers whose licence status changes.
Compliance here is not complicated, but it does require consistency. A documented process run reliably is worth far more than an elaborate system operated sporadically.
Get weekly fleet compliance updates
One concise email per week on UK and DE fleet regulation changes. No spam, unsubscribe anytime.
We only use your email for the newsletter.