It’s Monday morning. Your best engineer is already on site, phone in hand, ready to clock in via the GPS app. But something nags at him, nobody ever asked him to sign anything about location tracking. No privacy notice, no consent form, nothing. And you, sitting in the office, have no idea that document is missing.
It feels like a small thing. A piece of paperwork you never got around to. But under UK GDPR and the ICO‘s employment practices guidance, that missing document is a compliance gap that could cost you thousands in fines, and your defence in any employment tribunal disappears overnight.
The legal requirements nobody explains at purchase
If you use GPS-enabled software to record when and where your employees clock in and out, you have specific obligations under data protection law. The UK GDPR (retained from EU Regulation 2016/679) requires a clear privacy notice under Article 13, explaining what data you collect, why, how long you keep it and what rights employees have. The ICO has made it explicitly clear: location data is personal data, and processing it without proper notice is a breach.
Beyond the privacy notice, you need a lawful basis for processing. For most field service businesses, this is legitimate interest, but you must document a Legitimate Interest Assessment (LIA). If you can’t show you’ve balanced your business need against the employee’s right to privacy, the ICO will treat your GPS tracking as unlawful. And the fines under UK GDPR go up to £17.5 million or 4% of global turnover.
There’s also the question of proportionality. The ICO’s guidance on monitoring at work states that employers must only collect location data that is strictly necessary. GPS at clock-in and clock-out? Proportionate. Continuous real-time tracking throughout the working day? Almost certainly disproportionate, and a red flag for any investigation.

What actually happens in small businesses
Most small field service businesses buy a GPS time-tracking app, install it on the team’s phones and start using it the same day. No privacy notice. No LIA. No data protection impact assessment. It works, the timesheets are accurate, everyone’s happy, until someone files a complaint with the ICO, or an ex-employee raises it at tribunal.
Sound familiar? You’re not alone. But the ICO has been increasingly active in this space. Their 2025-2026 enforcement priorities specifically mention employee monitoring technologies. A single complaint from a disgruntled employee can trigger an investigation, and if you can’t produce a signed privacy notice, the outcome is predictable.
How GeoTapp Flow solves this automatically
When you invite a new employee in GeoTapp Flow, the system automatically generates a GDPR-compliant GPS privacy notice personalised with your company details, name, registered address, DPO contact if applicable. The employee receives a link by email, opens the page on their phone or computer, fills in their details, reads the full notice and signs with one click.
No printing. No scanning. No chasing signatures. The system records the digital signature with date, time and IP address, generates a signed PDF and archives it automatically. From your Flow dashboard, you can see a green badge next to every employee who has signed, and an amber badge next to those who haven’t.
The notice is available in four languages – English, Italian, German and French, because if you employ workers whose first language isn’t English, the notice must be in a language they understand.





