Almost certainly yes. The ICO treats monitoring that tracks location and behaviour, then uses analytics to score how someone drives, as high risk. That makes a data protection impact assessment mandatory, not optional. Do it before installation, consult your drivers, and record the decision. Mickai runs on hardware you own, so the data stays with you.
Do you need a DPIA for AI driver monitoring and telematics?
Yes, in almost every real deployment. If the system does more than show a vehicle's position on a map, plan on a data protection impact assessment being mandatory rather than discretionary.
The test sits in Article 35 of the UK GDPR: a DPIA is required where processing is likely to result in a high risk to the rights and freedoms of individuals. The ICO's guidance on when a DPIA is needed sets out screening criteria, and fleet monitoring usually meets several at once: tracking an individual's location or behaviour, profiling on a large scale, and using innovative technology. Where processing hits more than one indicator, treat the DPIA as required.
Timing matters as much as content. The assessment has to be complete before processing starts, which means before the units are fitted and, ideally, before the supplier contract is signed. The ICO's guidance on surveillance in vehicles is direct on the point: carry out the assessment before installation. A DPIA written afterwards documents a decision you had already taken.
The other reason to do it properly is internal. Driver monitoring fails on trust more often than on technology, and the DPIA is the only artefact that forces you to write down what you collect, why, and what you chose not to do.
What counts as driver monitoring under the ICO guidance?
More than most operators assume, and the boundary is not the camera. Two families of data are in scope. The first is vehicle telemetry: position, speed, harsh braking, cornering, idling, fuel use, route and timing. The second is in-cab recording: forward and inward facing cameras, and sometimes audio.
All of it is personal data the moment a vehicle can be linked to a named driver, which on a rostered fleet is always. "It is vehicle data, not personal data" is the argument I hear most, and it does not survive contact with a shift pattern.
Audio needs its own decision. The ICO treats continuous audio recording in a vehicle as more intrusive than video and expects it to be disabled unless you can justify it specifically. If your supplier ships microphones enabled, that is a configuration change to make on day one and to record in the assessment.
Systems that analyse a driver's face or physical state sit in a harder category, because you may be handling biometric data and need an Article 9 condition on top. I would keep that out of a first deployment. Everything below assumes location, speed, braking and route analytics.
Why does AI analytics push telematics into high risk?
Because analytics turns a record into a judgement. A tracker tells you where the vehicle was. A model tells you this driver sits in the bottom decile, is likely to have an incident, or should not take the night run. That is profiling, and it has consequences for pay, route allocation and disciplinary process.
Three factors escalate the risk together. Continuity: monitoring runs for the whole shift rather than sampling an event. Inference: the system makes a claim about the person that nobody observed. Consequence: the output feeds a decision the driver cares about. The ICO's guidance on monitoring workers is built around that shape, expecting employers to choose the least intrusive means available and to show the monitoring is necessary and proportionate to the stated purpose rather than merely useful.
Scoring also pulls in the automated decision-making rules. If a score alone settles something significant for a driver with no meaningful human involvement, you are in the territory Article 22 was written for. The Data (Use and Access) Act 2025 reforms that framework rather than removing it: telling the person, allowing representations and providing human review all survive. Commencement is staged, so check the current position on legislation.gov.uk before relying on any particular reading. For a fleet, the safer design is to keep a named manager in the loop on anything that affects a driver's work.
What lawful basis can a fleet operator rely on?
Rarely consent, usually legitimate interests, occasionally legal obligation. Consent looks attractive and fails in practice, because the ICO's view is that consent is unlikely to be valid where there is an imbalance of power between employer and worker. Build on consent and you also have to honour withdrawal, which means running the fleet in two modes.
Legitimate interests is the workable basis for most operational monitoring, and it comes with homework: an assessment that names the interest (road safety, insurance defence, duty of care, vehicle security), tests whether monitoring is necessary to achieve it, and balances it against the driver's reasonable expectations. Legal obligation covers a narrow slice, such as the records you must keep to satisfy drivers' hours rules. Do not stretch it to cover behaviour scoring.
Two habits make the analysis stronger. Name your purposes separately and hold each to its own necessity test, because "safety" as a single justification tends to authorise everything. And set retention per purpose, not per system.
What should the DPIA cover, step by step?
Article 35(7) sets the minimum content. In order:
- Describe the processing concretely: every field the units collect, the sampling interval, where it goes, who can query it, how long each field is kept.
- State each purpose separately, with the lawful basis for each.
- Assess necessity and proportionality: what less intrusive option did you consider, and why did you reject it.
- Identify the risks to drivers: constant observation, inaccurate scoring, function creep into performance management, inference about private life from location, and the effect on earnings.
- Record the configuration decisions: audio disabled, private use handling, no continuous inward recording, what triggers a clip.
- Set the measures that reduce each risk, including access control, who can see an individual score, and the route for a driver to challenge one.
- Record the consultation with drivers and their representatives, and what you changed because of it.
- Sign off at the level that can genuinely accept the residual risk, and diary a review for any material change.
If high risk remains after your measures, Article 36 requires you to consult the ICO before you begin. That is uncommon, and it is the step people forget exists. The same structure serves any AI deployment assessment.
How do you consult drivers and their representatives?
Early, with the real specification, and before the decision is locked. Article 35(9) requires you to seek the views of data subjects or their representatives where appropriate, and in a fleet with recognised unions that means the representatives as well as the drivers.
What works: publish what the system collects in plain terms, including what it does not collect; run sessions where drivers can ask what happens to a score; and answer the question they ask first, which is whether it will be used to discipline them. Then record the objections and what you did about each. A consultation record showing you changed two settings because drivers pushed back carries more weight with a regulator than a polished document reporting unanimous agreement.
What does not work is consulting after fitting. The drivers know the decision was already made, and so will anyone reviewing it later.
What changes when the analysis runs on your own hardware?
The DPIA still happens. What changes is how much of it concerns other people. The Mickai Sovereign Intelligence Operating System runs on hardware the customer owns and is built to work offline, so telematics data does not leave the estate to be analysed. That removes or shrinks whole sections of work: no international transfer assessment for the analysis itself, no third-party processor chain to map for it, and no reliance on a vendor's assurance about deletion, because retention is enforced where the data actually sits. The same effect shows up in our note on DPIAs for on-premise processing.
It also changes what you can prove. Every consequential action is sealed in an Open Audit Record under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024, and an auditor verifies an exported record offline with a public key, using tools that are not ours. That is tamper-evident, which is not the same as tamper-proof, and the difference matters. Nothing stops someone altering a record. Altering it makes verification fail, and the failure is visible to whoever checks. The distinction matters at a tribunal, where the question is not whether your logs are invulnerable but whether they can be shown to be unchanged. Consequential actions also wait for a named person to approve them, which keeps a named human in the loop where the automated decision rules expect one.
None of this is an argument against cloud. For work that is not regulated it remains the sensible choice. The argument is narrower: when the data describes named workers, being able to say where it is and show what happened to it is worth the hardware. We are in closed beta, with one regulated company onboarding as a design partner.
Frequently asked questions
Do we need a DPIA for basic vehicle tracking with no AI?
Usually yes. Continuous location tracking of an identifiable driver is itself one of the ICO's high risk indicators, and analytics is not what triggers it. A simple tracker following a named driver through a shift is systematic monitoring. The assessment will be shorter than one for behaviour scoring, but skipping it is not defensible.
Can we monitor drivers in vehicles they also use privately?
Yes, with limits. Where a vehicle is available for private use, the ICO expects drivers to have a way to switch tracking off outside working hours, or expects you to justify clearly why that is not possible. Record which you chose in the DPIA, tell drivers plainly, and do not collect location during private journeys you have no purpose for.
Does driver scoring count as an automated decision?
Only where the score alone determines something significant for the driver with no meaningful human involvement. A score that a transport manager reviews before acting is not a solely automated decision. A score that automatically removes a driver from a rota or cuts a bonus probably is, and that brings duties to explain it and to allow a challenge.
Who should sign off the DPIA in a haulage business?
The person who can genuinely accept the residual risk, which in most haulage businesses is a director rather than the fleet engineer. The data protection officer or adviser should give a documented opinion, but advising and deciding are different roles. Involve the transport manager on operational detail and the head of HR on anything touching discipline or pay.
How long should telematics and driver monitoring data be kept?
There is no single legal period. Set retention per purpose and justify each one: camera footage for days unless an incident is open, event data for the period your safety process actually uses, and aggregate figures after that. Records kept to satisfy drivers' hours rules follow that regime's own retention requirement. Delete on schedule automatically rather than by memory.
Related briefings
Data protection and UK GDPR
- UK GDPR and AI: Does Your Data Have to Stay in the UK?
- UK Data Storage vs AI Processing: What Is the Difference
- Controller or Processor? AI Suppliers and UK GDPR Roles
- Right to Erasure in an AI Knowledge Base: How to Comply
- Employee Pasted Client Data Into AI: Is It a Breach?
Governance, audit and oversight
- Tamper-Evident vs Immutable Log: The Real Difference
- Human on the Loop vs In the Loop: AI Oversight Explained
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)