Balancing traveller privacy with duty of care obligations means collecting only the location and status data genuinely needed to protect employees, being transparent about how that data is used, and giving staff meaningful control over their own information. The tension is real but manageable. Most organisations that struggle with this are trying to resolve it through technology alone, when the real solution sits in policy, consent, and proportionality. The sections below address the specific questions that come up most often when organisations try to get this balance right.
What legal frameworks govern employee travel data collection?
Employee travel data collection is governed by a combination of data protection law, employment law, and sector-specific regulations that vary by jurisdiction. In the UK and EU, the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018 are the primary instruments. They require that any personal data collected, including location data, has a lawful basis, is proportionate to its purpose, and is retained only as long as necessary.
For organisations operating globally, the picture becomes more complex. Countries including the United States, Canada, Australia, and many in Asia-Pacific have their own data protection regimes, and what is permissible under one framework may not be under another. Location tracking that is entirely lawful in one jurisdiction may require additional consent or disclosure requirements in another.
Beyond data protection law, employers also have a legal duty of care toward travelling employees under health and safety legislation in most jurisdictions. In the UK, this obligation derives from the Health and Safety at Work Act 1974. ISO 31030, the international standard for travel risk management, provides a recognised framework for discharging that duty systematically. The standard explicitly addresses the need to balance protection with employee rights, making it a useful reference point when designing a travel data programme. Organisations that align their travel risk management services with ISO 31030 are better positioned to demonstrate that their data collection is proportionate and purposeful.
What data do organisations actually need to track travelling employees?
Organisations need enough data to locate an employee quickly in an emergency, confirm their welfare during a crisis, and communicate with them reliably. In practice, this means knowing where an employee is travelling, which locations they will pass through, how to reach them, and whether they are safe when an incident occurs near their itinerary.
The minimum viable data set for effective duty of care typically includes:
- Pre-trip itinerary details, including destination, accommodation, and planned movements
- Emergency contact information for the traveller
- Flight and transport booking data
- A means of two-way communication during the trip
- Real-time location access during declared emergencies or in high-risk environments
Continuous, passive location tracking throughout every trip is rarely necessary and often counterproductive. It generates large volumes of data that are difficult to manage, creates privacy concerns that erode employee trust, and rarely improves response times in a genuine emergency. The better approach is to define in advance which risk levels or destinations trigger active tracking, and to communicate those thresholds clearly to employees before they travel.
How can companies collect traveller location data without breaching privacy?
Companies can collect traveller location data lawfully and ethically by establishing a clear legal basis for collection, informing employees in plain language about what is collected and why, limiting collection to what is genuinely necessary, and securing the data appropriately. Consent alone is often insufficient under GDPR in an employment context because of the power imbalance between employer and employee. Legitimate interests or contractual necessity are typically more robust legal bases, provided the collection is proportionate.
Practical steps that help organisations stay on the right side of privacy law include:
- Publishing a clear travel data policy that explains what is collected, when, and for how long it is retained
- Using purpose-built travel risk platforms rather than general consumer tracking tools, which are harder to audit and control
- Limiting real-time tracking to high-risk destinations or declared emergencies rather than applying it universally
- Ensuring data is accessible only to those with a genuine operational need, not HR in general or line managers
- Deleting location data promptly once it is no longer operationally relevant
- Conducting a Data Protection Impact Assessment (DPIA) before deploying any new tracking technology
Transparency is the single most effective tool for maintaining employee trust. When people understand why data is collected and can see that its use is limited to their protection, resistance drops significantly.
What’s the difference between monitoring and surveillance in corporate travel?
Monitoring in a corporate travel context means collecting the minimum data needed to confirm employee safety and enable a rapid response if something goes wrong. Surveillance means continuous, granular observation of an employee’s movements and behaviour beyond what safety requires. The distinction matters legally, ethically, and practically.
Monitoring is proportionate and purposeful. An organisation that checks whether a traveller has arrived safely at their hotel, activates location tracking when a security incident occurs near their route, or sends a welfare check message during civil unrest is monitoring. The data serves a clear protective function.
Surveillance, by contrast, involves tracking employees continuously regardless of risk level, logging movements in detail for reasons unrelated to safety, or using travel data to assess productivity or behaviour. This crosses into territory that most data protection frameworks treat as disproportionate and that employees are right to push back against.
The practical test is straightforward: if you removed the data point and an emergency occurred, would your ability to protect the employee be materially reduced? If the answer is no, the data point is surveillance, not monitoring. Applying this test rigorously when designing a travel tracking programme keeps organisations on defensible ground.
Should employees be able to opt out of travel tracking?
Employees should generally have the ability to raise concerns about travel tracking and to understand what data is collected, but a blanket opt-out from all tracking in high-risk environments is difficult to reconcile with an employer’s duty of care. If an organisation cannot locate or communicate with an employee during an emergency, it cannot fulfil its legal obligation to protect them.
The more workable approach is to build a tiered system where the level of tracking corresponds to the risk level of the destination. For low-risk business travel, employees might simply confirm their itinerary in advance with no active tracking during the trip. For medium-risk destinations, check-in protocols might apply. For high-risk environments, active location sharing during movements might be required as a condition of travel approval.
Where employees have genuine concerns about a specific element of a tracking programme, those concerns deserve a proper response. Sometimes the concern reflects a policy that is more intrusive than the risk warrants, and adjusting the policy is the right outcome. In other cases, the concern reflects a misunderstanding of how data is used, which better communication can resolve. What organisations should avoid is treating opt-out requests as a compliance problem rather than a signal that the programme needs review.
How do you build a travel privacy policy that satisfies both employees and legal teams?
A travel privacy policy that works for both employees and legal teams starts with proportionality and transparency, then builds the legal architecture around those principles. The goal is a document that employees will actually read and understand, not a compliance artefact that sits unread in an intranet folder.
The core elements of an effective travel privacy policy are:
- Purpose statement: A plain-language explanation of why data is collected, limited to protective purposes
- Data inventory: A clear list of what data is collected, by what means, and at what points in the journey
- Risk-tiered thresholds: Explicit rules about which destinations or situations trigger which levels of tracking
- Access controls: Named roles or functions that can access traveller data, and under what circumstances
- Retention limits: Specific timelines for how long data is held and when it is deleted
- Employee rights: A clear statement of the employee’s right to access their own data and raise concerns
- Review schedule: A commitment to review the policy at defined intervals as technology and regulations evolve
Legal teams will want to see that the policy maps to applicable data protection legislation and that a DPIA has been completed for any tracking technology in use. Employees will want to see that the policy is honest about what is collected and that the purpose is genuinely protective rather than managerial. Both needs are compatible, and a well-drafted policy satisfies them simultaneously.
How NGS helps organisations navigate traveller privacy and duty of care
Northcott Global Solutions supports organisations in meeting their duty of care obligations without overreaching into employee privacy. The approach is built around proportionate, transparent, and operationally effective travel risk management aligned with ISO 31030. Key capabilities include:
- Live traveller tracking through the Aurora platform, with access controls that limit visibility to those with a genuine operational need
- 24/7 monitoring from a UK Operations Centre, enabling rapid response without continuous passive surveillance
- Mass emergency communication via SIREN, so organisations can reach all travelling employees simultaneously during a crisis
- Pre-travel briefings and risk-tiered protocols that define when and how data collection is activated
- Professional travel risk policy writing and consultancy to help organisations build frameworks that satisfy both employees and legal teams
If your organisation needs support designing a travel risk programme that protects people without compromising their privacy, find out more about NGS and how the team works with duty of care professionals across complex global environments.