Is it legal to collect location data?

29th September 2022Geo location data image

We have recently been asked whether it is legal to collect location data.

Are you aware that under the GDPR, if you collect location data of an EU citizen (or UK citizen under the UK GDPR) then there are very strict rules around location data, which, in many cases, is classed as ‘personal information’ under the GDPR? NOTE – it is the location of the citizen, not the location of your company that is important here.

What you need to know about collecting location data.

Firstly, what is location data?

For this, it is best to refer directly to the Information Commissioner’s Office who are the custodians of the UK GDPR and the Privacy and Electronic Communication Regulations (PECR) which run alongside the GDPR and which are also very relevant here.

The ICO defines location data as :

“any data processed in an electronic communications network or by an electronic communications service indicating the geographical position of the terminal equipment of a user of a public electronic communications service, including data relating to—
(f) the latitude, longitude, or altitude of the terminal equipment;
(g) the direction of travel of the user; or
(h) the time the location information was recorded.

In other words, it is information collected by a network or service about where the user’s phone or other device is or was located – for example, tracing the location of a mobile phone from data collected by base stations on a mobile phone network.
In our view, this does not generally include GPS-based location information from smartphones, tablets, sat-navs or other devices, as this data is created and collected independently of the network or service provider.” Source ICO Guide to PECR
Does this apply to my organisation.

You might still be wondering whether that applies to you and that is a good question. ICO explains that many of the regulations within PECR only apply if your organisation provides a public electronic communication network or service (if that is you and you are unsure, please definitely get in touch with us as this blog is not intended to cover the in-depth all you should know).

This blog is going to be most relevant to you if your business has an app or a website or in-vehicle devices which collect location information.

This is because PECR also applies if your business does any telemarketing, email marketing, or marketing by text (or fax), or if you use cookies or similar technologies – which most websites these days do. You also need to be aware that PECR applies to your organisation if location tracking is used in any of your software applications or apps, or if you are tracking personal health data or employee movements.

It is essential that you carefully evaluate the impact on privacy. You might think your app is ‘safe’ because it collects the data anonymously and that the users have consented to be tracked (somewhere in your myriad of terms and conditions?) – but this is unlikely to hold up in court.
If your app regularly tracks (or pings) an individual’s phone and that therefore tracks their movements and regular locations, it is likely to make it obvious where they live and work for example. This in turn makes them identifiable as an individual and this would then fall under GDPR.

How to collect location data legally

The GDPR treats this kind of location data as personal data. This means that you have to treat location data in the same way as you would any other data that makes it possible to identify an individual – they must specifically (and knowingly) OPT-IN and it must be looked after according to all the principles of the GDPR.

The seven principles of the UK GDPR:-

  •  Lawfulness, fairness, and transparency
  •  Purpose limitation
  •  Data minimisation
  • Accuracy
  •  Storage limitation
  •  Integrity and confidentiality (security)
  •  Accountability

If you or your team need any data protection training, we have a menu of options at all different levels or can even create training bespoke to your organisation.

The best place to start is by taking advantage of your complimentary thirty-minute consultation which you can book here.
If you just want a refresh on the UK GDPR why not buy one of our handy pocket guides for each of your team?

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details