Vehicle geolocation in Luxembourg: CNPD requirements 2024
On 10 April 2024, the CNPD updated its guidelines: no continuous tracking or outside working hours, DPIA often required, retention generally 2 months, and obligations under Labour Code L. 261‑1.
Summary — On 10/04/2024, the CNPD updated its guidelines on employee vehicle geolocation. Key points: no continuous surveillance or tracking outside working hours, DPIA often required, retention generally limited to 2 months, and compliance with Labour Code L. 261‑1.
The case
On 10 April 2024, Luxembourg’s data protection authority (CNPD) updated its thematic file and the “Guidelines on geolocation of vehicles made available to employees.” The text clarifies GDPR legal bases, prohibitions (permanent monitoring, tracking outside working hours), acceptable purposes, retention periods and information duties, including under Labour Code L. 261‑1. Sources: CNPD – Thematic file; CNPD – Guidelines (PDF).
Legal reasoning
- GDPR legal basis. Article 6(1)(f) (legitimate interest) may apply subject to a documented necessity and balancing test; Article 6(1)(c) applies where a legal obligation exists (e.g., transport rules). Consent is generally inappropriate in employer–employee relations (guidelines §1). Refs: GDPR Article 6; CNPD guidelines.
- Luxembourg labour law specifics. Geolocation is “surveillance” under Article L. 261‑1: prior collective information to staff representation and the option to seek CNPD’s opinion with a one‑month suspensive effect. Ref: CNPD – Article L. 261‑1.
- Necessity and proportionality. “Permanent surveillance” and off‑duty tracking are prohibited. For mixed (business/private) use, the employee must be able to disable tracking outside working hours (guidelines §4.1). Ref: CNPD – Guidelines.
- Purpose limitation. Do not repurpose geolocation data to assess performance (e.g., speed, route optimisation) if the declared purpose is asset protection (guidelines §4.2).
- Data and security. Data must be “adequate, relevant and limited” (Art. 5(1)(c) GDPR). Recording speeding is generally disproportionate unless required by law (guidelines §4.3). Apply Article 32 security measures and Article 28 processor controls. Ref: GDPR, Arts. 28 and 32.
- Retention. Benchmark is “in principle” 2 months; longer periods only if duly justified (guidelines §4.4).
- DPIA. Often required (Art. 35 GDPR) given potential high risk (workplace surveillance, systematic tracking). Refs: CNPD – DPIA and geolocation; see also EDPB Guidelines 3/2019.
What this changes in practice
- For executives and DPOs. Demonstrate a genuine legitimate interest (three‑part test) or a sector‑specific legal obligation. Keep your balancing matrix and considered alternatives. An expert DPO mandate can help structure evidence.
- For CISOs. Implement an employee‑controlled “private mode”; log on/off without off‑duty location; encryption, strong auth, roles and day‑60 purging. An outsourced CISO can speed up secure configuration.
- For HR legal teams. Deliver L. 261‑1 collective information and GDPR individual notices; anticipate a potential CNPD prior opinion with suspensive effect.
- For cross‑border entities. Align legal basis and retention with the CNPD Luxembourg standard and prepare a robust DPIA for CNPD compliance in Luxembourg.
Illustrative scenarios
- 24/7 technical fleet (theft risk): Article 6(1)(f) with “asset protection” purpose; no performance assessment using these data; 2‑month retention, case‑by‑case freeze if theft reported. Source: CNPD guidelines.
- Mixed‑use vehicles: employee‑side “private button” off duty; no geolocation on weekends/holidays; evidence of user‑controlled deactivation. Source: CNPD guidelines.
- Regulated transport: Article 6(1)(c) possible when tracking is mandated; retention follows legal obligations while remaining proportionate.
Common pitfalls
- Purpose creep for discipline. Using GPS traces to sanction “sub‑optimal routes” when the declared purpose was theft prevention breaches purpose limitation (guidelines §4.2).
- No effective private mode. An admin‑only setting is not enough; the employee must be able to disable tracking off duty (guidelines §4.1).
- Excessive retention. Avoid 6–12 months “just in case”: CNPD benchmark is 2 months unless duly justified (guidelines §4.4).
- Wrong legal basis. Employment‑contract consent is usually invalid; prefer legitimate interest or legal obligation with transparent information (GDPR Art. 6).
- Ignoring labour law. Deploying without L. 261‑1 collective information and the CNPD opinion window risks suspension and disputes.
Official sources
- CNPD – Thematic file “Vehicle geolocation” (updated 10/04/2024): https://cnpd.public.lu/fr/dossiers-thematiques/surveillance/geolocalisation-vehicules.html
- CNPD – “Geolocation of employee vehicles” Guidelines (PDF): https://cnpd.public.lu/content/dam/cnpd/fr/dossiers-thematiques/geolocalisation/cnpd-lignes-directrices-golocalisation-vhicules.pdf
- CNPD – Labour Code Article L. 261‑1 (workplace surveillance): https://cnpd.public.lu/fr/dossiers-thematiques/surveillance/videosurveillance/article2611.html
- GDPR (EUR‑Lex) – Article 6; Articles 28, 32; Article 35: https://eur-lex.europa.eu/eli/reg/2016/679/art_6/oj/eng ; https://eur-lex.europa.eu/legal-content/EN-PT/TXT/?uri=CELEX%3A32016R0679
- EDPB – Guidelines 3/2019 (video devices): https://www.edpb.europa.eu/documents/guideline/guidelines-32019-on-processing-of-personal-data-through-video-devices_en
In short, in Luxembourg a corporate geolocation system is lawful only if the purpose is specific and necessary, monitoring is limited to working hours, retention generally does not exceed 2 months, L. 261‑1 information is provided, and a robust DPIA and demonstrable security are in place.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →