Skip to main content

Lone Worker GPS Tracking & GDPR: What UK Managers Need to Know

Guides · 7 min read · 19 September 2026

By Syed Muhammad Daud Rizvi Co-founder of TapOkie Work. Building lone worker visit check-ins and audit-ready monitoring for small teams — without enterprise lock-in.

GPS tracking lone workers is lawful under UK GDPR when you have a legitimate interest (health & safety), inform staff clearly, and keep monitoring proportionate. Session-based check-ins — where location is captured at visit start and SOS, not continuously — are far easier to justify than all-day tracking.

Why GPS tracking and lone worker safety is a live GDPR question

If you manage staff who work alone — field engineers, care workers, estate agents, delivery drivers, cleaners — you have a duty of care to keep them safe. Location-aware technology can be a genuine lifeline. But the moment you start capturing where someone is, you are processing personal data, and UK GDPR applies.

This post is not legal advice. Think of it as a practical starting point you should then take to your Data Protection Officer (DPO) or employment solicitor. The goal: help you understand the landscape well enough to ask the right questions and build monitoring that is genuinely proportionate — good for safety and for staff trust.

The core tension: safety vs. surveillance

There is a meaningful difference between:

  • Safety-triggered location capture — recording where a worker is when they start a visit or press an SOS button (so responders have a last known point if a check-out is missed).
  • Continuous all-day GPS surveillance — logging a worker's position every few seconds throughout their shift.

Both can be used in lone worker tools. Only the first is easily defensible under UK GDPR, and only the first is compatible with a workplace culture where people feel respected rather than tracked.

Staff who feel surveilled push back. They forget to carry their phone, or they leave it in the van. You end up with worse safety coverage, not better.

Lawful basis under UK GDPR

To process location data lawfully, you need a lawful basis under Article 6 UK GDPR (and, because precise location can be sensitive-adjacent in context, you should also document your Article 9 position if special category data is ever in scope).

For most lone worker monitoring programmes, the most credible basis is legitimate interests — specifically your legal obligation under the Health and Safety at Work etc. Act 1974 to ensure the safety of employees. You can also look at legal obligation directly if your sector has specific lone worker requirements.

Legitimate interests requires a three-part test:

StepWhat you must show
Purpose testThere is a genuine safety purpose, not commercial tracking.
Necessity testThe monitoring is necessary to achieve that purpose.
Balancing testYour interests do not override workers' reasonable privacy expectations.

Session-based monitoring passes this test more comfortably than continuous GPS, because it is harder to argue that logging every 30-second position is necessary for a welfare check.

ICO employment monitoring principles — the headlines

The ICO's employment practices guidance (check the ICO website for the current version — guidance evolves) sets out broad principles you should embed in your approach:

  • Transparency: workers must know they are being monitored, what is being captured, and why.
  • Proportionality: collect only what you genuinely need for the stated purpose.
  • Minimisation: do not retain location data longer than necessary.
  • Consistency: apply the same rules to everyone in the same role; selective monitoring raises fairness concerns.

None of this means you cannot monitor lone workers for safety purposes. It means you need to be deliberate and documented about how you do it.

Do you need a DPIA?

A Data Protection Impact Assessment is formally required under UK GDPR when processing is "likely to result in a high risk" to individuals. Systematic monitoring of employees' location very probably meets that threshold.

Even if it is not technically mandated in your specific case, doing a DPIA is good practice. It forces you to:

  1. Define the safety purpose clearly.
  2. Assess whether less intrusive options (manual check-in by phone, scheduled callbacks) would achieve the same result.
  3. Document why location capture is necessary and proportionate.
  4. Identify retention periods and access controls.
  5. Consult with workers or staff representatives.

A completed DPIA is also your evidence file if you ever face an ICO inquiry or an employment tribunal challenge.

Session-based vs. always-on tracking: a practical comparison

Session-based check-insContinuous all-day GPS
Location captured whenVisit start, SOS, missed check-outContinuously throughout shift
Data volumeLow — discrete timestamped eventsHigh — potentially thousands of records per worker per day
Easier to justify as proportionate?YesHarder — requires strong documented justification
Staff trust impactGenerally accepted when explained clearlyOften resented; can damage trust and recruitment
Suitable for most lone worker use cases?YesOnly if the role genuinely demands it (e.g., very high-risk environments)

TapOkie Work is built around session-based safety visits. When a worker starts a timed visit, the system captures location context so that if they miss their check-out — or hit SOS — responders know where to go. Between sessions, TapOkie Work is not tracking anyone. That design choice is deliberate: it is proportionate monitoring, not an all-day leash.

What your policy and privacy notice must cover

Before you go live with any lone worker monitoring tool, you need two documents updated:

Your lone worker policy

  • Which roles are subject to lone worker monitoring and why.
  • What the monitoring system does and does not record.
  • How workers activate a visit session and what triggers an alert.
  • Who receives alerts and what the escalation chain is.
  • How workers can raise concerns.

See our guide on how to write a lone worker policy for a fuller template.

Your employee privacy notice

Plain English, covering:

  • What data: location at session start and SOS, plus escalation timestamps.
  • Why: to enable welfare checks and emergency response for lone workers.
  • Lawful basis: legitimate interests / legal obligation (health & safety).
  • Who can see it: named manager roles and escalation contacts.
  • Retention: for example, audit trail retained for 12 months then deleted.
  • Workers' rights: how to request access, raise an objection, or ask for erasure.
  • Contact: your DPO or data controller contact point.

Handing this to workers before deployment — and giving them a chance to ask questions — is both legally sound and the right thing to do.

Practical steps before you deploy

  1. Check your lawful basis with your DPO or solicitor — do not assume.
  2. Complete a DPIA and keep it on file.
  3. Update your lone worker policy and employee privacy notice.
  4. Consult your workers — explain the purpose clearly and address concerns honestly.
  5. Configure the tool proportionately — session-based capture, not continuous tracking, unless your risk assessment specifically demands otherwise.
  6. Set retention rules — agree how long event logs are kept and who can access them.
  7. Train managers on what they can and cannot do with location data.

With TapOkie Work, managers receive email and push alerts when a visit escalates, can review an exportable audit trail for incident review or insurance purposes, and can set escalation contacts — without any contract lock-in. Plans start from $5 per worker per month. There is no monitoring operations centre (ARC) dependency; you control who gets alerted.

If you want to see how session-based safety visits work in practice, explore TapOkie Work.

The bottom line

GPS tracking for lone workers is not inherently unlawful — but it requires thought, documentation, and genuine proportionality. The question is not "can we track our people?" but "what is the minimum data we need to keep them safe, and have we been transparent about it?"

Session-based monitoring that captures location only at safety-critical moments is far easier to justify under UK GDPR, far better for staff trust, and — in practice — perfectly adequate for the vast majority of lone worker safety scenarios.

Get the policy right, do the DPIA, be transparent with your team, and use a tool designed for proportionate monitoring. That is the combination that keeps both your workers and your organisation on the right side of the law.

Related reading

Common questions

Is GPS tracking of lone workers legal under UK GDPR?

It can be, provided you have a clear lawful basis — typically legitimate interests grounded in health and safety obligations — and you are transparent with workers about what data is collected, why, how long it is kept, and who can see it. Always confirm your specific approach with your DPO or employment solicitor.

Do I need a Data Protection Impact Assessment (DPIA) before deploying lone worker location monitoring?

A DPIA is strongly recommended — and may be legally required — whenever you systematically monitor employees' location. It forces you to document the purpose, necessity, and proportionality of the monitoring, and to consider less privacy-intrusive alternatives before you go live.

What is the difference between session-based location capture and continuous GPS tracking?

Continuous GPS tracks and logs a worker's position all day, every day. Session-based capture records location only at defined safety moments — typically when a timed visit starts and when the worker triggers an SOS — so responders have a last known point if a check-out is missed. Session-based monitoring is easier to justify as proportionate and typically far less intrusive for staff.

What should our privacy notice say about lone worker monitoring?

It should explain what location data is collected and when, the lawful basis relied on, who has access (managers, escalation contacts), how long records are retained, workers' rights (access, erasure, objection), and a contact point for queries. Plain English beats legal boilerplate every time.

Your team is out there right now. Know they're safe.

Free to set up. No card required. Add your first worker in minutes.

Start Free Trial