Location data becomes high-risk processing when a person's position is tracked systematically over time, particularly employees or app users. Datatilsynet will then usually require a DPIA. The business needs a clear purpose and legal basis, must inform plainly and delete early. Apps reading the phone's position normally also need consent under the Electronic Communications Act § 3-15.
A plumbing firm with 40 service vans switches fleet management system. The new one shows the vans on a live map, stores every trip for twelve months and gives each driver a score for driving style. After a customer complaint, the managing director asks whether the log can be used to check a fitter’s timesheet. The same week, the product team at another company wants its customer app to read the phone’s position to show the nearest shop. Both are handling location data, and both need an answer before the system goes live.
What is location data under the GDPR?
Location data is information that shows, or allows someone to work out, where a person is or has been. GPS points from a vehicle or a phone are the obvious example. IP addresses, Wi-Fi networks, Bluetooth signals and the use of key cards also reveal position, just less precisely.
The information is personal data under GDPR Art. 4(1) of the GDPR as soon as it can be linked to a person, including when it is stored against a registration number or a device ID. Location data is not one of the special categories in GDPR Art. 9. Even so, a few weeks of movements show where someone lives, which doctor she sees and where she spends the night. The Article 29 Working Party made exactly this point in Opinion 13/2011 on geolocation services on smart mobile devices, where the main rule for location services is prior consent with the default setting switched off.
What did the Irish regulator find in the Google case?
On 21 September 2026 the Irish Data Protection Commission (DPC) fined Google Ireland Limited a total of EUR 403 million over its processing of location data. The case concerned three features in the period from 25 May 2018 to 4 February 2020. The DPC opened its inquiry in February 2020 following complaints from several European consumer organisations, among them BEUC. Google was also ordered to bring its processing into compliance within six months. This is set out in the DPC’s press release.
| Feature | What it does | Infringements found by the DPC |
|---|---|---|
| Web & App Activity | Stores activity in Google services, including location | Lawfulness and fairness, transparency, storage limitation |
| Location History | Tracks the position of signed-in devices, also when Google services are not in use | Lawfulness and fairness, transparency, storage limitation |
| Location Accuracy | Android feature giving a more precise position than GPS alone | Transparency, and failure to demonstrate compliance |
The press release names the principles rather than the article numbers, and the full decision had not been published when this article was written. The principles correspond to lawfulness and fairness in GDPR Art. 5(1)(a) and the legal basis in GDPR Art. 6, transparency in GDPR Arts. 12–14, storage limitation in GDPR Art. 5(1)(e) and accountability in GDPR Art. 5(2). The exact provisions applied should be checked against the decision once it is available.
The DPC’s reasoning applies directly to businesses in Norway. Users may have been unaware that their location was used to target them with advertising or to draw inferences about their interests. Long retention made the loss of control worse. Very little of this is specific to Google.
Location data kept longer than the purpose requires is a breach in its own right. Deleting early is the cheapest measure a business has.
When is location data high-risk processing?
Processing location data requires a data protection impact assessment (DPIA) under GDPR Art. 35 where it is likely to result in a high risk. The Norwegian Data Protection Authority (Datatilsynet) keeps a list of processing that always requires a DPIA. Processing location data is on it where at least one other criterion is also met. Systematic monitoring of employees is a separate item on the list.
In practice the threshold is low. Live tracking of a vehicle fleet is systematic monitoring, and the drivers are employees in a dependent relationship. That makes two criteria. An app that collects the position of tens of thousands of users to target offers meets both large scale and profiling. A single position used once and then deleted, for example to find the nearest shop, is not normally high risk.
| Situation | DPIA? |
|---|---|
| Fleet management with a live map and history for employees | Yes, as a rule |
| Driving style report or score per driver | Yes |
| App logging position in the background for advertising or analytics | Yes |
| App fetching position once at the user’s request without storing it | Normally no |
| Electronic logbook recording business mileage only | Assess case by case |
How to structure a DPIA is covered in our article on DPIAs for AI tools. The method is the same for tracking systems.
What rules apply to GPS tracking of employees and vehicles?
GPS in a company vehicle and fleet management are normally a control measure under the Working Environment Act (arbeidsmiljøloven). Under Working Environment Act § 9-1, the measure must have an objective basis in the business’s circumstances and must not impose a disproportionate burden on the employee. Working Environment Act § 9-2 requires the employer to discuss the need, design and implementation with the employee representatives as early as possible, to inform employees of the purpose, practical consequences and expected duration before the measure starts, and to review the need regularly with the representatives.
The GDPR applies alongside. Datatilsynet’s guidance on GPS and tracking of work vehicles points to legal obligation (driving and rest time rules, for example) and legitimate interests (fleet management, safety, protection of goods) as the relevant legal bases. Where the purpose is fleet management, what is needed is the live position, and in the authority’s view there is then no need to store the data. Employee consent is rarely valid, because employees are not in a position to refuse their employer freely.
The purpose limits later use. In HR-2013-234-A (Avfallsservice), a waste collection company had fitted GPS to its vehicles as a tool for operations and reporting. It later used the log together with the timesheets to check a driver, who was then dismissed. The Supreme Court of Norway held that this use was incompatible with the original purpose and therefore unlawful. The driver was nevertheless not awarded compensation for non-pecuniary loss. In PVN-2017-07, the Privacy Appeals Board (Personvernnemnda) upheld a NOK 100,000 fine against an asphalt company that had matched GPS data from a company car against the employee’s timesheets without telling him. Both cases were decided under the former Personal Data Act, but purpose limitation is carried forward in GDPR Art. 5(1)(b).
The Article 29 Working Party goes further in Opinion 2/2017 on data processing at work. Where private use of the company vehicle is allowed, the employee should in principle be able to switch tracking off temporarily, for example for a visit to the doctor. The employer is unlikely to have a basis for following the vehicle outside agreed working hours. Notice of the tracking should be displayed in the vehicle.
The same thinking applies to other sources of position at work, such as apps on a work phone and logins from different locations. The rules on an employer reading email and files are covered in our article on employer access to employee email. If the business uses AI to analyse driving patterns or productivity, that should also be addressed in its AI policy for employees.
Does an app need consent to collect location data from the phone?
Yes, as a rule. When an app reads the position from a phone, it gains access to information stored in the user’s terminal equipment. Under Electronic Communications Act § 3-15 of the Electronic Communications Act (ekomloven), that requires information and consent meeting the GDPR standard. The exemption covers what is strictly necessary to deliver a service the user has expressly asked for. A map app showing the way after the user taps “Get directions” is within it. Background logging for advertising and analytics is outside.
The permission prompt in iOS or Android is not enough on its own. It controls technical access, but says nothing about what the position is used for, who it is shared with or how long it is kept. Consent must be specific to each purpose, and withdrawing it must be as easy as giving it. The same rule applies to cookies on websites, as discussed in our article on cookie consent.
What should a business do about location data now?
The Google case concerned a period that is now six years old. The requirements are the same today, and they apply in Norway through the EEA Agreement. More decisions are collected on the data protection topic page. This is the order we recommend.
- Map where you collect location data, including in supplier systems, telematics in leased vehicles and third-party SDKs in your own apps.
- Write down one purpose per processing operation and lock the system to that purpose. If the log is to be used to check individual employees, that must be part of the stated purpose and discussed with the employee representatives before the system goes live.
- Carry out a DPIA before introducing employee tracking or background logging in an app.
- Set short deletion periods in the system, and switch off any history the purpose does not require.
- Let employees switch off tracking during private use of the vehicle, and stop recording outside working hours.
- Review the consent flow in the app, and remove location collection that is not strictly necessary for the service the user has asked for.
For the plumbing firm in the example, that means two things. The log cannot be used against the fitter if fleet management was the only purpose the employees were told about, and the driving style score should not be switched on until it has been discussed with the employee representatives and assessed in a DPIA.
Questions and answers
Is location data special category data under the GDPR?
No, location data is not on the list of special categories in GDPR Art. 9. But a person's position over time can reveal health, religion or political affiliation, for example visits to a doctor or a place of worship. Supervisory authorities therefore treat location data as highly personal, and that counts when deciding whether a DPIA is required.
Can an employer use the GPS log from a company vehicle in a dismissal case?
Only if checking individual employees was an express purpose that the employees were told about before the log was collected. In the Avfallsservice case, the Supreme Court of Norway found that using a GPS log to check a driver's timesheets breached purpose limitation, because the system had been introduced for operations and administration.
Do employees have to consent to GPS tracking of company vehicles?
No, consent is rarely a valid basis in an employment relationship, because the employee is not free to refuse. The employer normally relies on legitimate interests or a legal obligation, and must also meet the requirements of Chapter 9 of the Working Environment Act on objective grounds, proportionality, discussion and information.
- Data Protection Commission, Data Protection Commission fines Google €403 million following Inquiry into Google's processing of location data (21.9.2026)
- General Data Protection Regulation (EU) 2016/679 Arts. 4(1), 5, 6, 12–14 and 35
- Norwegian Working Environment Act (arbeidsmiljøloven) §§ 9-1 and 9-2
- Norwegian Electronic Communications Act (ekomloven, 2024) § 3-15
- Supreme Court of Norway, judgment of 31 January 2013, HR-2013-234-A (Rt. 2013 p. 143)
- Privacy Appeals Board (Personvernnemnda), PVN-2017-07 Employer's use of collected data for a new purpose
- Norwegian Data Protection Authority (Datatilsynet), GPS and tracking of work vehicles
- Norwegian Data Protection Authority (Datatilsynet), When must a data protection impact assessment be carried out?
- Article 29 Working Party, Opinion 13/2011 on Geolocation services on smart mobile devices (WP185)
- Article 29 Working Party, Opinion 2/2017 on data processing at work (WP249) section 5.7
Next legal review: 15 December 2026