The Lorry That Watches Itself: Fleet Telematics as Personal Data and as Evidence

A modern commercial vehicle is a rolling data collection platform. It records where it went, how fast, how hard the driver braked, how long the engine idled, when the seatbelt was fastened, and increasingly what the cab looked like at the moment something went wrong. Most of that recording happens continuously, without anyone consciously deciding to switch it on.

That creates a genuine tension. Every one of those records is personal data about an identifiable worker, subject to the full apparatus of data protection law. Every one of them is also potential evidence about how a serious collision occurred. Those two framings pull in opposite directions, and fleet operators frequently discover they have designed a policy for one while being exposed under the other.

When the Data Becomes Evidence

The litigation reality explains why the preservation question matters so much. In serious commercial vehicle collisions, the electronic record frequently determines what actually happened, because it is the only account not filtered through memory, trauma or self-interest.

Plaintiff firms handling this work move quickly for exactly that reason. A Kentucky practice such as Dolt Thompson Shepherd Conway & Stanton Louisville, which has represented injured clients since 1986 and maintains its own accident investigators and reconstructionists in-house, operates in a field where the first substantive step is usually a preservation demand directed at the carrier, sent before the systems cycle their storage. The firm’s attorneys include past leadership of the Kentucky Academy of Trial Attorneys, and the trucking side of its practice reflects a general pattern in the sector: cases are frequently decided by what the vehicle recorded rather than by what the parties recall.

For an operator, the lesson is that a data protection policy which cannot accommodate a legal hold is incomplete, regardless of how well it satisfies minimisation principles.

What a Commercial Vehicle Actually Records

Understanding the exposure requires knowing what exists. Several distinct systems are usually running simultaneously.

The engine control module, often called the black box, captures technical parameters in the seconds surrounding an event, including road speed, engine RPM, throttle position, brake application and sometimes sudden deceleration triggers. Electronic logging devices record driving hours and duty status, a category that in the United States is federally mandated rather than optional. Telematics and fleet management platforms track position, route, speed and driver behaviour scoring on a continuous basis. And dashcams, increasingly with both forward-facing and driver-facing lenses, record video and often audio.

Each of these was installed for a different purpose. The compliance system exists for regulatory reasons, the telematics for efficiency and insurance, the camera for defending against fraudulent claims. Very few operators have mapped how they interact.

Where the Regulators Landed

European supervisory authorities addressed this territory directly. The European Data Protection Board’s Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications, adopted in final form in March 2021, deal specifically with data processing inside the vehicle, the exchange of data between the vehicle and connected devices, and in-vehicle collection where data is transferred to outside entities.

The recommendations lean firmly toward minimisation. Data protection should be a design consideration from the outset rather than a compliance exercise afterwards. Where possible, processing should happen internally within the vehicle rather than by transferring data to third parties outside it, and where export genuinely is necessary, the data should be anonymised or at least pseudonymised. The Board also flags the need for additional safeguards when processing location, biometric or other data capable of revealing criminal offences or infractions, which is precisely the category most collision-relevant telematics falls into.

Underlying all of it is a framing worth noticing: the vehicle has evolved from an expression of personal autonomy into another controlled and monitored environment.

The Retention Clock Nobody Watches

Here is where organisations most often get caught out. These systems typically overwrite on a rolling basis, sometimes within days.

Data protection law encourages exactly that. Retaining personal data longer than necessary for the stated purpose is a compliance failure, so a well-designed policy deletes aggressively. But the moment a serious incident occurs, that same policy becomes a liability of a different kind, because evidence relevant to an investigation may be destroyed by an automated process nobody thought to suspend.

The practical answer is a documented preservation procedure that triggers on notification of an incident and freezes the relevant records, ring-fenced from the routine deletion schedule and justified as necessary for the establishment or defence of legal claims. Organisations that have not thought this through in advance tend to make the decision badly under pressure.

Two Systems, Two Instincts

The contrast between European and American approaches is instructive rather than simply divergent.

The European instinct is to ask first whether the data should exist at all, on what legal basis, for how long, and with what safeguards for the worker being monitored. The American instinct in litigation is to ask what exists, to demand its preservation immediately, and to treat its unexplained absence as itself significant.

Neither framing is wrong. They are answering different questions, and a multinational operator has to satisfy both simultaneously.

Who Actually Controls the Records

A question that becomes urgent the moment anyone demands the data: who holds it, and in what capacity?

Most fleets do not run their own telematics. They buy a platform from a vendor who stores the records on infrastructure the operator neither owns nor administers. That arrangement usually makes the operator the controller and the vendor a processor, which means the operator carries the obligations while the vendor holds the servers.

The practical consequences surface at the worst moment. Can the operator actually extract a complete record on demand, in a usable format, within the timeframe an investigation requires? Does the contract permit a legal hold that suspends the vendor’s own deletion cycle? What happens if the vendor is in a third country? These are contractual questions that need answering while relations are calm, not during the week after a fatality.

Driver-Facing Cameras and the Consent Difficulty

The sharpest current dispute concerns cameras pointed at the driver rather than the road. Operators argue they establish attentiveness and defend against unfounded claims. Drivers and their representatives regard continuous filming of a workplace as disproportionate, and in several European jurisdictions works councils have treated it accordingly.

Consent is a weak basis here, because the imbalance between employer and employee undermines whether it can be freely given. Operators generally need to rely on carefully documented necessity, apply strict limits on triggering and retention, and complete a data protection impact assessment that genuinely tests whether a less intrusive measure would achieve the same result.

Designing for Both Outcomes

Fleet operators do not have the luxury of choosing between compliance and evidential readiness, and the two can be reconciled with some deliberate design work.

Map every system that collects data about drivers and record the purpose and legal basis for each. Set retention periods that are defensible under minimisation principles. Build a legal hold procedure that overrides those periods on notification of an incident, with a documented justification. Be transparent with drivers about what is recorded and when. And review the arrangement periodically, because the technology adds capabilities faster than most policies are updated.

This article is general information rather than legal advice. Data protection obligations and litigation procedure vary considerably by jurisdiction, and operators facing a specific incident or compliance question should take advice appropriate to the countries in which they run.