Automotive Fleet
MenuMENU
SearchSEARCH

How Fleets Inadvertently Violate Privacy Laws

There are more than 3,000 federal and state laws and regulations prohibiting unauthorized dissemination or access to employee personally identifiable information (PII). However, employee privacy is sometimes inadvertently compromised by fleets. The reason this occurs is because the PII that was electronically captured by the out-of-service fleet vehicle is not deleted.

Mike Antich
Mike AntichFormer Editor and Associate Publisher
Read Mike's Posts
December 18, 2016
5 min to read


There are more than 3,000 federal and state laws and regulations prohibiting unauthorized dissemination or access to employee personally identifiable information (PII). This includes any information that can be used to identify, contact, or locate a single person, such as name, address, zip code, phone number, social security number, etc.

A company in possession of this information is legally required to safeguard the privacy of this data. However, employee privacy is sometimes inadvertently compromised with vehicle sales to other employees, remarketing in the wholesale market, accident-damaged vehicles sold as salvage, and “hostage” vehicles repossessed from disgruntled former employees. The reason this occurs is because the PII that was electronically captured by the out-of-service fleet vehicle is not deleted.

Ad Loading...

There are four areas where PII is electronically captured by a vehicle: a universal garage door opener, navigation system, a Bluetooth module, and telematics system. (While PII derived from a telematics device may not reside in a vehicle, it does reside elsewhere in a database. What are the safeguards to protect PII at these locations?)

Let’s examine each vulnerability.

Integrated Garage Door Opener: If a vehicle features an integrated remote that can be pair to your garage door opener and that data is not erased or reset, the new owner of that vehicle has the ability to gain entry to the employee’s home. Before reselling a vehicle, reset the integrated remote to the original factory setting. This information is found in the vehicle’s owner’s manual.

Navigation System: Every navigation system gives the option to program a home address. Just as you wouldn’t release an employee’s home address to an unauthorized third-party, why retain that same information in a vehicle’s navigation system?

Bluetooth: If a vehicle has hands-free calling via Bluetooth, some employees download phone contact list from cell phone into the vehicle’s onboard computer. If not deleted, this contact information is there for the next owner of the vehicle. Not only is a driver’s personal information at risk, but so too is company information. For healthcare companies, this data may include data on patients, which, if released, violates the Health Insurance Portability and Accountability Act (HIPAA), designed to protect a patient's protected health information (PHI), similar to PII.

Ad Loading...

These concerns have not escaped the attention of OEMs, some of whom are developing an option for future models to easily delete all PII from a vehicle. One scenario is to enter this information via the OBD II port, time-stamp it, and upload to a secure location or to an online remarketing site verifying PII was deleted.

It is important to remind employees to thoroughly check their vehicle prior to turn-in to remove all personal items. When company vehicles are resold to other employees or non-employees, there is the risk of PII information left in the vehicle, such as bank statements, credit card bills, prescriptions, documents that lists the driver’s home address, etc. This also applies to vehicles taken away from terminated employees. What is your company policy about removing all PII from a vehicle before it is reassigned to another employee or sent to auction? What about vehicles that have been in an accident and are declared salvage?

Based on one industry study, one-quarter of the used vehicles still have PII information in them that can be extracted and used for potentially malicious intent.

Privacy More Complicated for Multinationals

Data privacy laws enacted by the European Union (EU) restrict the extent to which U.S. fleet managers can manage data generated by subsidiary fleets in Europe. Known as the European Union Data Protection Directive, it has a direct bearing on U.S.-headquartered fleets, even though it is not law in the U.S. The Directive creates strict rules on the transfer of data concerning European Union employees (past or present) to companies headquartered outside the EU.

Ad Loading...

The “data” covered by the directive is information about EU employees that identifies the individual by name or other means. The Directive creates rights for employees about whom data is collected. Each of the 28 national governments comprising the EU is allowed to implement the directive in its own way. Entities that collect information must give EU employees notice explaining who is collecting the data, who will ultimately have access to it, and why the data is being collected. EU employees also have the right to access and correct data about themselves.

In the context of fleet management, this privacy protection involves a tremendous amount of personal data contained in MVR records, accident histories, drivers’ home addresses, phone numbers, names of spouses (if personal use is allowed), etc. Likewise, EU privacy laws inhibit the transfer of data about its citizens to third parties, such as fleet management companies. Under EU law, the data subject (driver) must be explicitly informed of these plans and given the chance to object.

When is the Employee Responsible?

The counterargument is at what point does a driver have to take responsibility of their own PII? This is an emerging legal issue for fleets that is already being played out in other industries, such as the financial industry. For instance, the Gramm-Leach-Bliley Act, also known as the Financial Modernization Act of 1999, is a federal law enacted to control how financial institutions deal with the private information of individual. This comes into play with repossessed vehicles, which, procedurally is not much different than repossessing a “hostage” company vehicle from a disgruntled employee. Many of these regulations are enforced by the Consumer Financial Protection Bureau (CFPB), which has been known to stretch the scope of who these regulations cover, especially in the automotive sector.

If someone gets unauthorized access to PII data from one of your company vehicles and uses it for nefarious purposes, does this put your company at risk? I’m not sure. But I am sure that some enterprising attorney will argue that it does.

Ad Loading...

Let me know what you think.

mike.antich@bobit.com

Subscribe to Our Newsletter

More Blog Posts

Market Trendsby Mike AntichSeptember 7, 2023

Fleets Want Trust Restored with Suppliers

During this period of ongoing supply constraints, the trust that fleet managers had with OEMs, upfitters, and dealers has been strained. Fleet managers say they have had too many experiences over the past three years coping with erroneous information, adjusting to multiple price increases, and feeling betrayed by inadequate transparency from suppliers.

Read More →
Market Trendsby Mike AntichAugust 23, 2023

Scheduled Replacement Cycles Are Becoming a Distant Memory

The ongoing difficulty in sourcing replacement vehicles is forcing companies to extend the service lives of vehicles that are unable to be replaced, which, inevitably, increases unscheduled maintenance expenses.

Read More →
Market Trendsby Mike AntichJuly 7, 2023

Fleet Simplification is the Antidote to Asset Variability

Fleet simplification identifies asset functions to uncover commonality among the equipment and assets. Simplification increases operational efficiency as end-users become accustomed to the controls, displays, and operation of less diverse units.

Read More →
Ad Loading...
Market Trendsby Mike AntichJune 29, 2023

The Dangers of Static Fleet Policies

A fleet policy is a living document, flexible enough to adapt to evolving business priorities, developing industry trends, and changing industry best practices and standards.

Read More →
Market Trendsby Mike AntichApril 17, 2023

Short-Term vs. Long-Term Cost Reductions

Corporate procurement staff are often driven by short-term, immediate cost reductions. However, a longer perspective to soft cost savings is critical because fixating on short-term results will hurt a company in the long run.

Read More →
Market Trendsby Mike AntichMarch 29, 2023

Uptick in Unscheduled Maintenance Increasing Vehicle Downtime

Fleet data analysis can identify recurring downtime issues. It’s important to determine the root causes of downtime so procedures can be developed to minimize such problems.

Read More →
Ad Loading...
Market Trendsby Mike AntichDecember 6, 2022

Eliminate Needless Curb Weight to Maximize ICE & EV Efficiencies

Vehicle weight relates directly to fuel economy. In today’s era of electrification, there is also a direct correlation between vehicle weight and battery range.

Read More →
Market Trendsby Mike AntichOctober 5, 2022

Tech Dependence Risks Dumbing Down Fleet Manager Expertise

The line between creative thinking and problem solving and doing what the data indicates is thin. To lead in fleet management, you need to balance understanding the fundamentals and embracing what smart technology offers.

Read More →
Market Trendsby Mike AntichAugust 15, 2022

Leverage the Synergy of Safe Driving to Achieve Sustainability and Cost Goals

Safe driving, emission reductions, and cost containment can all be achieved at the same time.

Read More →
Ad Loading...
Market Trendsby Mike AntichMay 19, 2022

The Playbook for Fleet Manager Success

There are many paths to success — most of them involve being flexible, open-minded, and willing to learn.

Read More →