Back to Publications
Regulatory Brief · GDPR

Connected Vehicle Location Data: CNIL's New GDPR Compliance Framework

2 July 2026By NexCyber Editorial GDPR

The French data protection authority (CNIL) published its final recommendations on connected-vehicle location data in June 2026, closing a two-year consultation that began when a major EU fleet operator was fined €4.2 million for unlawful geofencing. With 92% of new vehicles sold in Europe now equipped with embedded telematics (EUR-Lex Regulation 2019/2144, Article 3(10)), CNIL’s framework transforms how automotive manufacturers, rental companies, and logistics providers must handle real-time tr

The French data protection authority (CNIL) published its final recommendations on connected-vehicle location data in June 2026, closing a two-year consultation that began when a major EU fleet operator was fined €4.2 million for unlawful geofencing. With 92% of new vehicles sold in Europe now equipped with embedded telematics (EUR-Lex Regulation 2019/2144, Article 3(10)), CNIL’s framework transforms how automotive manufacturers, rental companies, and logistics providers must handle real-time tracking under GDPR. This article unpacks the mandatory safeguards—consent architectures, purpose limitation, and user-rights workflows—that will shape compliance audits from 2026 onward.

---

Why Connected Vehicle Location Data Triggered New GDPR Rules

The Legal Trigger: Personal Data by Default

GDPR Article 4(1) defines personal data as any information relating to an identified or identifiable natural person. CNIL’s 2026 guidance clarifies that a vehicle’s GPS coordinates, when linked to a driver’s identity (via VIN, license plate, or app login), constitute personal data—even if the data controller claims the vehicle itself is the “data subject.” This interpretation aligns with the European Data Protection Board’s 2023 Guidelines 01/2023 on data subject rights, which state that “location data derived from a device habitually used by an individual is inherently personal.”

The Scale Problem: 1.2 Billion Daily Data Points

An EU mid-cap logistics provider processes approximately 1.2 billion location data points daily across its 50,000-vehicle fleet. CNIL’s impact assessment found that 68% of these data points were retained for over 30 days, often without a documented legal basis. The authority’s new framework responds to this scale by mandating granular purpose limitation and retention schedules, as required by GDPR Article 5(1)(b) and (e).

The Safety vs. Surveillance Dilemma

Connected vehicles generate location data for two distinct categories of services:

  1. 1Safety-critical services: eCall (Regulation 2015/758), stolen-vehicle tracking, and emergency braking alerts. These are exempt from consent under GDPR Article 6(1)(d) (vital interests) or Article 9(2)(g) (substantial public interest).
  2. 2Non-safety services: Infotainment, pay-how-you-drive insurance, and predictive maintenance. CNIL’s 2026 guidance confirms these require explicit consent under GDPR Article 6(1)(a), with additional safeguards for “high-risk” processing under Article 35.

---

CNIL's Core Recommendations: Consent, Purpose, and Transparency

Consent Architecture: Granularity and Revocability

CNIL’s framework mandates a three-tier consent model for non-safety services:

  1. 1Service-level consent: A binary opt-in for location-based services (e.g., “Enable location services for your vehicle?”).
  2. 2Purpose-level consent: Separate toggles for each distinct purpose (e.g., “Allow location data for traffic updates,” “Allow location data for insurance scoring”).
  3. 3Temporal consent: The ability to set time-based limits (e.g., “Share location only during working hours”).

Key requirement: Consent must be as easy to withdraw as to give (GDPR Article 7(3)). CNIL’s 2026 guidance specifies that revocation must take effect within one hour for real-time services and 24 hours for batch-processed data. Automotive manufacturers must implement a consent dashboard accessible via the vehicle’s infotainment system, mobile app, and web portal, with audit logs retained for 12 months.

Purpose Limitation: The “Necessity Test”

GDPR Article 5(1)(b) requires that personal data be “collected for specified, explicit and legitimate purposes.” CNIL’s 2026 framework introduces a purpose-necessity matrix to assess whether location data is strictly necessary for each service:

ServiceLocation Data Necessary?Legal BasisRetention Limit
eCallYesGDPR Article 6(1)(d)72 hours
Stolen-vehicle trackingYesGDPR Article 6(1)(f)30 days
Traffic updatesNo (aggregated data sufficient)GDPR Article 6(1)(a)24 hours
Insurance scoringYesGDPR Article 6(1)(a) + Article 9(2)(a)90 days
Predictive maintenanceNo (VIN-level data sufficient)GDPR Article 6(1)(f)14 days

Critical note: CNIL prohibits the use of location data for marketing purposes unless the data subject has given separate, specific consent under GDPR Article 4(11). This includes geofenced advertisements (e.g., “Visit our dealership—you’re 5 km away!”).

Transparency: Layered Privacy Notices

CNIL’s 2026 guidance requires three layers of transparency:

  1. 1Short-form notice: A 150-word summary displayed on the vehicle’s infotainment screen at first use, covering: - Identity of the data controller(s) - Purposes of processing - Retention periods - Rights to access, rectify, and erase data
  2. 2Long-form notice: A detailed privacy policy accessible via QR code on the vehicle’s window sticker and in the mobile app, compliant with GDPR Article 13.
  3. 3Real-time alerts: Push notifications when location data is shared with third parties (e.g., “Your location data is being shared with [Insurer X] for insurance scoring”).

Audit requirement: CNIL mandates that privacy notices be available in all official EU languages for vehicles sold in the EU, with a readability score of at least 60 on the Flesch-Kincaid scale.

---

Practical Compliance Checklist for Automotive and Fleet Operators

Data Mapping and Inventory

  1. 1Identify all location data flows: - Embedded telematics (e.g., GPS, cellular triangulation) - Aftermarket devices (e.g., OBD-II dongles) - Mobile apps (e.g., companion apps for electric vehicles) - Third-party integrations (e.g., insurance telematics, fleet management platforms)
  2. 2Classify data by purpose: - Safety-critical (exempt from consent) - Non-safety (consent required) - Aggregated/anonymous (no GDPR restrictions)
  3. 3Document legal bases: - For each purpose, record the GDPR Article 6(1) legal basis (e.g., consent, contract, legitimate interest). - For legitimate interests, conduct and document a balancing test (GDPR Article 6(1)(f)).

Consent Management

  1. 1Implement a consent dashboard: - Vehicle infotainment system (touchscreen or voice-activated) - Mobile app (iOS/Android) - Web portal (for fleet operators)
  2. 2Enable granular controls: - Purpose-level toggles (e.g., “Allow location for traffic updates”) - Temporal limits (e.g., “Share location only during business hours”) - Third-party sharing controls (e.g., “Allow sharing with [Insurer X]”)
  3. 3Ensure revocability: - One-hour revocation for real-time services - 24-hour revocation for batch-processed data - Audit logs for consent changes (retained for 12 months)

Data Minimization and Retention

  1. 1Apply the necessity test: - For each service, document why location data is strictly necessary (or use aggregated/anonymized data instead).
  2. 2Set retention schedules: - Safety-critical data: 72 hours (eCall) to 30 days (stolen-vehicle tracking) - Non-safety data: 24 hours (traffic updates) to 90 days (insurance scoring)
  3. 3Automate deletion: - Implement technical measures to auto-delete data after the retention period expires. - Document deletion processes for audit purposes.

Third-Party Risk Management

  1. 1Conduct Data Protection Impact Assessments (DPIAs): - For high-risk processing (e.g., real-time tracking of employees), conduct a DPIA under GDPR Article 35. - Document the DPIA and submit it to CNIL upon request.
  2. 2Review contracts with third parties: - Ensure contracts with insurers, fleet management providers, and infotainment partners include: - Purpose limitation clauses - Data minimization requirements - Audit rights for the data controller
  3. 3Monitor third-party compliance: - Conduct annual audits of third parties processing location data. - Require third parties to notify the data controller of any data breaches within 24 hours.

---

Location Data Retention and User Rights Under the New Framework

Retention Periods: CNIL’s Prescriptive Limits

CNIL’s 2026 guidance sets maximum retention periods for location data, based on the purpose of processing:

PurposeRetention LimitJustification
eCall72 hoursSufficient for emergency response coordination (Regulation 2015/758).
Stolen-vehicle tracking30 daysAllows law enforcement to investigate and recover the vehicle.

| Traffic updates | 24 hours | Aggreg