ELEN

EMPLOYEE TRACKING BY EMPLOYER VIA GPS – €2,000 FINE BY THE HDPA

Tracking of an employee’s company car by the employer via GPS and a €2,000 fine imposed on the employer by the Hellenic Data Protection Authority. The Hellenic Data Protection Authority (HDPA) (Decision 6/2024) accepted the complaint of a former employee working as a sales clerk, according to which his personal data had been unlawfully processed through the geolocation system operating in a vehicle that had been provided to him by the respondent former employer company.

As the complainant specifically argued, “during his regular leave he was called on the telephone by the respondent and he did not respond to the calls. The respondent’s sales manager made use of the data of the geolocation system installed in the company car and appeared at the supermarket where the complainant had gone shopping.” On the issue of the installation of the system and his being informed of its operation, the complainant claimed that these had taken place two weeks before the incident.

The Authority notified the complaint to the respondent, requesting its written views on the matters raised. The company replied that “it had duly informed the complainant about the geolocation system and that use of the vehicle outside working hours was not permitted. The contested use of the geolocation system was carried out because the complainant did not respond to their telephone calls for three days, and there was concern for the health of the employee due to the fact that there had been a health incident in the past.”

Subsequently, and after the hearing of the parties before the Authority, the respondent argued that the use of the car which had been provided to the complainant concerned the coverage of work-related needs only and within working hours, while no technical possibility had been provided for deactivating the geolocation system in the said car, while also stating that the complainant had been informed about the installation of the system by letter.

Furthermore, the company brought to the Authority’s attention the actions it had taken following the complaint about the incident, in order to prevent any future misuse of the said tracking systems. These actions included the installation of new geolocation systems with the possibility of deactivation by users, the appointment of a designated operator, the updating of usage instructions and the drafting of new documents notifying installation and operation.

The decision of the Hellenic Data Protection Authority

After initially assessing the role of the respondent as data controller, an issue that was crucial since the contested processing – inquiry had been made by an employee of the company, the Authority recalled Opinion 2/2017 of the Article 29 Working Party, according to which “it is unlikely that there is a legal basis for monitoring the location of employees’ vehicles outside the agreed working hours. However, if such a need exists, use should be considered that is proportionate to the risks. For example, this could mean that, to prevent vehicle theft, the location of the vehicle is not recorded outside working hours, unless the vehicle leaves a wider location (region or even country). In addition, the location will only be displayed in emergencies – the employer activates the visibility of the location, accessing data already stored by the system, when the vehicle leaves a predefined area.”

Subsequently, and clarifying that it does not check the documentation of the legality of the operation of the system, but is limited to examining the complaint and the specific incident, the Authority found that “an employee of the respondent made use of the geolocation data of the vehicle manifestly outside working hours, since the complainant was on lawful leave, with the aim of locating the position where the complainant was, as evidenced by the fact that the said employee appeared at that location.”

On the basis of the above, the Authority found two infringements on the part of the respondent:

a. unlawful processing of the complainant’s personal data, due to the use of the location data of his vehicle outside working hours and for the purpose of locating the complainant, and

b. insufficient information provided to the complainant, in violation of Articles 5(1)(a), 12, 13 and 5(2)(b) of the GDPR, regarding the operation of the system that had been installed in the vehicle provided to him, regardless of the fact that he did not have the right to use it outside working hours, a fact admitted by the respondent, which took corrective actions thereafter.

For the first infringement, an administrative fine of €2,000 was imposed, while for the second the Authority issued a reprimand.

FREQUENTLY ASKED QUESTIONS ON EMPLOYEE TRACKING BY EMPLOYER VIA GPS

1. Is the employer permitted to monitor me via GPS?

The installation of a geolocation system in a company vehicle is permitted only under strict conditions and for specific, lawful purposes, such as protection of the vehicle or organisation of routes within working hours. According to the GDPR and the guidance of the Article 29 Working Party, monitoring outside working hours or during leave is generally considered unlawful processing.

The employer is obliged to inform the employee in writing and in detail about the operation of the system, the purposes, the data retention period and his rights. The absence of a technical possibility to deactivate the system outside working hours constitutes an aggravating element.

2. What can I do if I was tracked by GPS outside working hours?

The employee has two parallel routes. First, he may file a complaint with the Hellenic Data Protection Authority (HDPA), which conducts an investigation and imposes administrative fines and reprimands on the employer, as occurred in Decision 6/2024 with a €2,000 fine.

Second, he may file a lawsuit before the civil courts seeking pecuniary compensation for moral damages due to infringement of personality rights and personal data (Article 82 GDPR, Articles 57 and 59 of the Civil Code (AK)). The two routes operate independently and one procedure reinforces the other evidentially.

3. Within what time must I act to file a complaint?

The complaint to the Hellenic Data Protection Authority is not subject to a strict exclusive deadline; however, it must be filed within a reasonable time of becoming aware of the incident, so that it is not deemed abusive and so that the evidence is preserved. In practice, action within a few months is recommended.

For the action for damages, the five-year limitation period of Article 937 of the Civil Code (AK) applies, running from the time of awareness of the damage and of the liable party. The earlier the procedure is initiated, the easier it is to gather witness statements and electronic data from the geolocation system.

4. What documents and evidence do I need?

Useful evidence includes the employment contract, any letter or document notifying the installation of the GPS system, the employer’s decision approving leave, as well as any written communication (emails, messages) documenting the monitoring outside working hours.

Particularly crucial are those items that prove tracking in a private space or during leave, such as testimony from persons who saw the employer’s representative appear at the specific location. The lawyer may also request from the employer, by exercising the right of access, a copy of the data concerning the employee.

5. What compensation can I claim?

On the basis of Article 82 GDPR, the employee is entitled to recover any material damage and to receive pecuniary compensation for moral damages suffered as a result of the unlawful processing. The amount depends on the gravity of the infringement, its duration, the type of data, the position of trust that was breached and the impact on personal life.

By way of indication, case law awards amounts ranging from a few thousand to several tens of thousands of euros, depending on the circumstances. A prior decision of the Authority establishing the infringement operates as strong evidence in the civil trial and significantly increases the prospects of success of the lawsuit.

6. What is the role of the lawyer in such a case?

The lawyer first assesses whether the conditions for unlawful processing are met, drafts a documented complaint to the Hellenic Data Protection Authority with reference to the GDPR and European case law, and represents the employee at the hearing before the Authority. In parallel, he submits a request for access to the data and ensures protection from any retaliation.

He then files a lawsuit for moral damages, drafts the pleading on the basis of the findings of the Authority, and claims reasonable pecuniary compensation. Our firm has handled cases of employee monitoring via GPS, corporate emails and video surveillance, with expertise in the combination of labour law and personal data protection.