Skip to content
What the Van Knows

All notes  /  Compliance

Holding the Data Safely

A fleet platform holds vehicle positions, home addresses by inference, and a live map. What that obliges, and where it goes wrong.

Compliance · Procedure

General orientation, not legal advice.

Even an asset-focused deployment accumulates data that matters, and the platform is a third party holding it.

What the platform holds

Vehicle positions, historical and live.

Which for take-home vehicles includes home addresses, derived rather than entered.

Maintenance and cost records, where integrated.

And a live map, which is the part with security consequences beyond privacy.

Why the live map matters

A fleet's live positions are useful to someone planning a theft, which is the specific exposure here.

Access to it should be narrow and authenticated properly.

Shared logins in a depot office make the access log meaningless, and they are common.

Multi-factor on every account, session timeouts, and prompt removal on departure, which is unremarkable advice and is unevenly applied in this category.

Retention, set deliberately

Asset data — codes, hours, consumption — has a long useful life and low sensitivity.

Position data has a short useful life and higher sensitivity.

Set them separately, which better platforms allow and defaults never do.

And check the compliance obligation, because maintenance records frequently need retaining longer than the platform keeps anything.

Export what compliance requires

Do not rely on the provider's retention for records you are legally obliged to hold.

A contract ending, a provider changing terms, or a platform migration can remove access to your own compliance evidence.

Export maintenance and inspection records into your own systems on a schedule.

The provider questions

Where is the data processed and stored?

Who at the provider can see it, and is that access logged?

What is the breach notification commitment, in hours?

What happens to the data on termination — returned, deleted, and confirmed?

Get the answers in the contract, because this data is theirs to lose as much as yours.

The check

Is multi-factor enforced?

Are there shared depot logins?

What is the configured retention for position, and was it chosen?

Could you produce three years of maintenance records if the platform contract ended tomorrow?

The last question is the one that finds the gap.

Ask about the provider's own access

A question that is rarely asked and always answerable.

Who at the provider can see your data, and is that access logged?

Support staff routinely have it, which is reasonable and should be visible.

Get the answer in the contract alongside the breach notification commitment, because this data is theirs to lose as much as yours.

Connect policy and data

The choices in this note can be compared with this professional-services page. Keep the written purpose in control and enable only the information needed at this boundary.

Independent reference

For a thematic point of reference, see the National Institute of Standards and Technology. Use this established source as an outside check before turning the principle into a system rule.