Modern fleet vehicles generate far more information than mileage and diagnostic codes.
Depending on the vehicle and systems connected to it, data can include location, speed, braking behavior, vehicle health, routes, driver behavior and potentially biometric information.
That information can help fleets improve safety, maintenance, accountability and operational decisions.
It also raises a question fleet leaders need to be asking:
Who has access to connected vehicle data, and what can they do with it?
For public and enterprise fleets, this isn't simply a technology issue. It's a question of data governance, risk, employee privacy and control.
Connected vehicle data is information generated, stored or transmitted by a vehicle and the systems connected to it.
The exact information varies by vehicle, manufacturer and technology provider, but common categories can include:
Not all of that data necessarily leaves the vehicle. Some information is used internally to operate vehicle systems, while other information may be transmitted to manufacturers, telematics providers, fleet systems or other connected services.
That distinction matters.
The question for fleet leaders isn't simply, "What data does this vehicle generate?"
It's also: Where does that data go?
There isn't one simple answer that applies to every type of vehicle data, system and situation.
Different data may be subject to different agreements, privacy policies, laws and contractual terms.
A vehicle owner may control certain information while a manufacturer, technology provider or other party may have rights to collect or use other types of data under an agreement.
For a fleet, that makes "Who owns the data?" only the beginning.
Fleet leaders should also ask:
Those questions should be answered before the information becomes important, not after an incident, dispute or data request.
Driving behavior data can be valuable because it can provide a detailed picture of how a vehicle is being operated.
That can include speed, acceleration, braking and other driving behaviors.
Insurance is one area where that information can matter.
The Federal Trade Commission finalized an order in 2026 settling allegations that General Motors and OnStar collected, used and sold precise geolocation and driving behavior data from millions of vehicles without adequately notifying consumers and obtaining affirmative consent.
The case is an important reminder for fleet leaders: vehicle data can have value well beyond the maintenance shop.
That makes it important to understand not only what the fleet can see, but what other organizations may be able to see as well.
The larger question for fleets is straightforward:
Could data generated for one purpose eventually be used for another?
That is exactly the type of question a fleet data policy should address.
Not every data point carries the same level of risk.
A fault code indicating that a vehicle needs maintenance is different from information showing where an employee has traveled or how that person has been driving.
Several categories deserve particular attention.
Connected vehicles may generate precise location information.
For a fleet, location data can be extremely useful. It can support routing, dispatching, emergency response, theft recovery and operational accountability.
But location data can also reveal where a vehicle has been, when it was there and potentially patterns of behavior over time.
Fleet leaders should understand when location is collected, who can access it and how long it is retained.
Speed, braking, acceleration, seat belt use and similar information can help fleets identify risk and coach drivers.
It can also create problems when the purpose of the data isn't clear.
Drivers should understand what is being measured and how the fleet intends to use that information.
As vehicle technology evolves, biometrics create another set of questions.
A vehicle could potentially use a fingerprint or other biometric identifier for authentication, personalization or security.
That may be convenient.
But biometric information is fundamentally different from a password. A password can be changed. A fingerprint cannot.
Fleet leaders considering vehicles or systems with biometric capabilities should understand what information is captured, whether it is stored, where it is stored and who can access it.
The technology may be useful. The important question is whether the organization understands the data implications before deploying it.
Access to vehicle data depends on the type of information, where it is stored, who controls it and the legal circumstances surrounding a request.
Fleet leaders shouldn't assume that all vehicle data is private, nor should they assume every third party can freely access it.
Instead, public fleets in particular should work with their legal, IT, risk and records teams to establish how requests for connected vehicle information will be handled.
The policy should answer questions such as:
Waiting until a request arrives is a poor time to start figuring out the rules.
Connected vehicle data doesn't come only from the vehicle manufacturer.
Fleets increasingly operate an ecosystem of connected technology.
A single vehicle may interact with:
Each connection can provide useful information.
Each can also introduce another place where fleet data is collected, transmitted or stored.
This is where fleets can develop a significant blind spot.
A fleet manager may know exactly what appears on a telematics dashboard without knowing where the underlying information is stored, which third parties process it, how long they retain it or what happens when the contract ends.
Public fleets operate under a level of accountability that makes data governance especially important.
Fleet leaders are responsible for vehicles that support essential community services. They may also need to answer questions from leadership, risk management, employees, legal teams, auditors or the public.
That makes defensibility important.
A fleet should be able to explain:
What information is being collected?
Why is it being collected?
Who can use it?
How is it protected?
What decisions are being made with it?
Collecting more data doesn't automatically create better visibility.
If the organization doesn't know where its information lives or how it is being used, more data can create another fleet blind spot.
A connected vehicle data policy doesn't need to account for every technology that might exist five years from now.
It should establish clear principles for how the organization handles the technology it has today and evaluates what comes next.
At minimum, fleet leaders should consider documenting:
Create an inventory of the information generated by vehicles and connected systems.
Include telematics, cameras, OEM portals, maintenance systems, mobile applications and other integrations.
Every major category of information should have a clear operational purpose.
Safety. Maintenance. Dispatch. Compliance. Asset utilization. Incident investigation.
If the fleet can't explain why information is being collected, it should ask whether that information is necessary.
Access shouldn't automatically be available to everyone who can technically log into a system.
Define who needs access and why.
Employees and supervisors should understand the difference between information collected for safety, maintenance, coaching, investigation or disciplinary purposes.
Ambiguity creates distrust.
Keeping information indefinitely because storage is available isn't the same as having a retention strategy.
Retention should reflect operational needs, legal requirements and organizational policy.
Understand what manufacturers, vendors and other partners can access under their agreements with the fleet.
This should be part of technology procurement, not an afterthought.
Selling a connected vehicle shouldn't be treated exactly like selling an older asset with no connected accounts or stored information.
Fleets should have a process for removing stored information, disconnecting accounts and ending access where appropriate.
Before purchasing or renewing a connected fleet technology, fleet leaders should ask vendors:
The answers should be understandable to fleet leadership, not buried in language no one outside a legal department can interpret.
Connected vehicle data isn't inherently good or bad.
Used well, it can give fleet leaders visibility they couldn't have imagined a generation ago.
It can help identify unsafe behavior, diagnose maintenance problems, understand vehicle utilization, investigate incidents and make better decisions.
The risk comes from collecting information without understanding it.
Fleet leaders don't need to become data privacy attorneys or cybersecurity engineers.
They do need to know enough to ask better questions.
Because as vehicles become more connected, fleet management is no longer only about knowing where the vehicles are and whether they're ready for service.
It's also about knowing where the fleet's information is.
And who else might have access to it.
Depending on the vehicle and connected systems, data may include location, speed, braking, acceleration, mileage, diagnostics, vehicle health, navigation information, driver behavior, video and certain biometric information.
There is no single answer for every category of vehicle data. Ownership, access and usage rights can depend on the type of information, the technology involved, contracts, privacy policies and applicable law. Fleets should review these terms for each connected system they use.
Driving behavior data can be relevant to insurance. Access and use depend on the specific program, permissions, agreements and applicable requirements. Fleet managers should understand whether their connected vehicle or telematics data can be shared with insurers or other third parties.
It can be, depending on the technology, agreements, permissions and applicable requirements. Fleets should review vendor and manufacturer policies to determine what information may be shared, with whom and for what purpose.
A vehicle data policy helps establish what information the fleet collects, why it is needed, who can access it, how it may be used, how long it is retained and how third-party requests are handled. Clear policies can reduce risk while making connected vehicle data more useful.
Connected vehicles give fleet leaders access to information that can make operations safer, more efficient and more accountable.
But access to more information isn't the same as control over it.
As vehicles, telematics systems, cameras and fleet platforms become more connected, fleet leaders need a clear picture of their entire data environment.
That means understanding what is being collected, where it goes, who can access it and what decisions are being made with it.
The fleets that ask those questions now will be better prepared for whatever connected vehicle technology comes next.
Build the fleet you're proud to lead.
This article was inspired by a recent episode of our podcast. Check out the full episode for even more tips and tricks: