DPE-2026-0038

Vehicle tracked outside working hours

A tracking unit keeps recording position when the vehicle is out of service, with no working way to mark private use.

In het NederlandsDienstvoertuig gevolgd buiten werktijdWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data vehicleIoTapp status active
Not a vulnerabilityNothing is exploited. The unit reports because that is what it was fitted to do, and the objection is to the period it covers rather than to a defect in it.

What it is

A tracking unit reports position, speed and ignition state at a fixed interval for as long as it has power. The purpose given for it, planning, theft recovery, mileage administration, concerns the vehicle in service. The unit knows nothing about shifts, so it records the drive home, the weekend, the pharmacy and the address where the driver sleeps. Where a private-use control exists it is often not fitted on the installed model, switched off in the fleet configuration, or it hides the track in the interface while the records keep arriving.

Why it is a separate entry

A position series over weeks is among the most revealing records there is. It shows where someone lives, who they visit and when they are away from home, and it does so for everyone else in the vehicle as well. The driver cannot see the record, cannot switch off the unit, and often has no other car.

How it arises

Not to be confused with

A device reporting at an interval that reveals when a house is empty is Reporting interval that reveals occupancy, where the subject is a household. A vehicle sending data to its manufacturer with no function behind it is Device telemetry without function. This entry is about the employment relationship and the boundary of the shift: records exist about time that is not the employer's.

How to establish it

Position records exist with timestamps outside the driver's recorded working hours, in the fleet system's own export or in the driver's access request. Where a private-use mode exists, records for the same period exist after it was switched on. The roster and the export are compared row by row.

method document-comparisonQoD 85

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itShow me the track of one vehicle for a Sunday.
In a DPIA, verify this

Verify the export of one vehicle for one week against the roster, instead of the statement that tracking is for business use.

As a procurement clause

The unit records no position outside service, or a private-use mode is fitted, works, and suppresses the record rather than the display.

With a complaint, hand over

The position export for one week, the roster for the same week, and the written answer about the private-use mode.

Reproduction

Legal framing

Objections, and the answer

“It is our vehicle.”

Owning the vehicle settles what may be driven in it, not what may be recorded about the person driving. Outside the shift, the time is not the employer's.

“It is for theft recovery.”

Theft recovery needs a position when a vehicle is reported stolen. A permanent series in a database is a different processing with a different retention, and the two can be told apart in the export.

“The driver can switch it off.”

Test it, and ask for the records of the period it was off. A mode that hides the track in the interface while the records keep arriving is the finding, not the refutation.

“We need it for the mileage administration.”

That needs distances per trip, which is a coarser record than a position every minute, and it needs nothing at all on days the vehicle was not in service.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0038 (Vehicle tracked outside working hours)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0038
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0038/index.json
Full
DPE Catalogue. DPE-2026-0038: Vehicle tracked outside working hours. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0038
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0038, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.