Balancing traveller privacy with duty of care obligations means collecting only the data you genuinely need to keep employees safe, being transparent about how you use it, and building consent into your travel policy from the start. The tension is real but manageable. Employers have a legal responsibility to protect staff during international travel, and that responsibility does not disappear because an employee values their privacy. The sections below address the most common questions travel risk managers face when trying to get this balance right.
What legal obligations require employers to track travelling employees?
Employers are legally required to take reasonable steps to protect the health, safety, and welfare of their employees, including when those employees travel for work. In most jurisdictions, this obligation derives from occupational health and safety legislation, employment law, and, where applicable, frameworks such as ISO 31030, which provides structured guidance on travel risk management. Failing to meet this standard can expose organisations to regulatory penalties, civil liability, and reputational damage.
The duty of care obligation does not automatically require continuous GPS tracking, but it does require employers to know where their people are, assess the risks they face, and have a plan to respond if something goes wrong. In practice, this means organisations must be able to locate a traveller in an emergency, communicate with them quickly, and coordinate assistance when needed. The legal threshold is proportionality: the level of monitoring must match the level of risk the traveller faces.
For travel into low-risk destinations, a basic itinerary and check-in protocol may be sufficient. For high-risk regions, more active monitoring becomes both legally defensible and operationally necessary. The key is that the organisation has documented its risk assessment and can demonstrate that its approach was reasonable given the circumstances.
What employee data can organisations lawfully collect during travel?
Organisations can lawfully collect employee data during travel when it is necessary, proportionate, and used solely for the purpose of keeping the traveller safe. Lawful categories typically include location data, itinerary details, emergency contact information, relevant medical information shared with consent, and communication records tied to incident response. Data protection regulations, including GDPR in the UK and EU, require that collection is limited to what is strictly necessary for a defined and legitimate purpose.
The principle of data minimisation is central here. Collecting more data than you need does not make employees safer; it creates additional compliance risk and erodes trust. A practical approach is to define, in your travel policy, exactly what data is collected, why it is collected, how long it is retained, and who can access it.
Medical data deserves particular attention. Health information is classified as special category data under GDPR, which means it requires explicit consent and stronger justification for processing. Organisations should collect medical information relevant to travel safety, such as pre-existing conditions that affect fitness to travel or emergency treatment requirements, but only with the employee’s informed agreement and with clear limits on who can see it.
How do you get meaningful consent from travelling employees?
Meaningful consent from travelling employees requires clear, plain-language communication about what data is being collected, how it will be used, who will have access to it, and what the employee can do if they have concerns. Consent must be freely given, which means employees should not feel that refusing will put their job at risk. In an employment context, this is one of the most challenging aspects of data privacy to get right.
The most effective approach is to embed consent into the pre-travel process rather than treating it as a one-time form. This means:
- Providing a clear privacy notice specific to business travel before any data is collected
- Explaining the specific tools used for tracking or communication, such as a corporate travel safety app or tracking platform
- Giving employees the opportunity to ask questions before they agree
- Making consent granular where possible, so employees can agree to location sharing without necessarily agreeing to share detailed medical records
- Documenting consent so the organisation can demonstrate compliance if challenged
Where tracking is a condition of travel to a high-risk destination, organisations should be honest about that. Framing it clearly as a safety measure, rather than a monitoring tool, and explaining the specific scenarios in which data would be accessed goes a long way toward building genuine acceptance rather than reluctant compliance.
What’s the difference between traveller tracking and employee surveillance?
Traveller tracking is the collection of location and status data for the purpose of ensuring employee safety and enabling emergency response. Employee surveillance is the monitoring of behaviour, productivity, or activity for the purpose of performance management or control. The distinction matters legally and ethically: the same technology can serve either purpose, and the difference lies in intent, scope, and transparency.
Tracking that is purpose-limited to duty of care is generally lawful and proportionate. Surveillance that extends beyond safety into monitoring an employee’s movements, communications, or behaviour during personal time is not. The line becomes blurred when tracking systems are active outside working hours, when data is retained longer than necessary, or when access to location data is not restricted to those with a genuine safety role.
Organisations should apply a clear test before deploying any tracking capability: would a reasonable employee, fully informed about what is being collected and why, consider this a safety measure or a control mechanism? If the honest answer is the latter, the approach needs to be redesigned. Business traveller tracking should be switched off or made opt-in during personal time, and access to live location data should be restricted to the operations or security function, not line management.
How should organisations handle traveller data after an incident?
After a travel incident, organisations should retain only the data that is necessary for incident review, insurance claims, legal proceedings, or regulatory reporting, and should delete or anonymise all other data according to a predefined retention schedule. The incident itself does not create an open-ended licence to hold personal data indefinitely. Data protection obligations continue to apply, and employees retain their rights even in the aftermath of an emergency.
In practice, post-incident data handling should follow a structured process:
- Identify what data was collected during the incident and categorise it by sensitivity
- Determine the lawful basis for retaining each category, for example, legal obligation or legitimate interest
- Set a clear retention period and document it
- Restrict access to retained data to those with a specific need
- Notify affected employees about what has been retained and why
- Delete or anonymise data once the retention period expires
Medical data collected during a medical evacuation or emergency treatment situation is particularly sensitive and should be handled with extra care. Employees should be informed of what medical information was shared with third parties, such as hospitals, insurers, or assistance providers, and should have the opportunity to correct any inaccuracies in their records.
What travel risk management tools support privacy-compliant duty of care?
Privacy-compliant duty of care tools are those that collect only the data required for safety purposes, give employees transparency and control over their information, restrict access to authorised personnel, and operate within a documented data governance framework. The best platforms combine real-time traveller tracking, travel risk alerts, and emergency communication capabilities while building privacy controls into the system architecture rather than treating them as an afterthought.
Key features to look for when evaluating a travel risk management platform include:
- Role-based access controls that limit who can view live location data
- Configurable data retention settings aligned with your organisation’s policies
- Transparent employee-facing interfaces that show what data is being collected
- Secure communication channels for two-way contact during incidents
- Integration with pre-travel risk briefing workflows to support informed consent
- Audit trails that document when data was accessed and by whom
Accreditations matter here. Platforms operated by providers holding ISO 27001 (information security management) and ISO 31030 (travel risk management) certifications offer a stronger baseline of assurance that data is handled responsibly. Pre-travel risk briefings, delivered through the platform or separately, also support privacy compliance by ensuring employees understand the tools being used before they travel.
How NGS helps with traveller privacy and duty of care
Northcott Global Solutions supports organisations in meeting their duty of care obligations without compromising employee privacy. NGS delivers this through a combination of technology, operational expertise, and a governance framework aligned with ISO 31030 and ISO 27001. Specifically, NGS provides:
- The Aurora platform for live traveller tracking, itinerary monitoring, and country risk intelligence, with access controls built in
- SIREN for mass emergency communication, enabling rapid, targeted contact with travelling employees during a crisis
- 24/7 UK Operations Centre support to monitor travellers and coordinate response, with trained specialists rather than automated systems making critical decisions
- Pre-travel risk briefings calibrated to destination risk level, supporting informed consent and employee awareness
- Travel risk policy development and consultancy, helping organisations document their approach to data collection, consent, and retention
If your organisation is working through how to structure a privacy-compliant travel risk programme, speak to the NGS team to discuss how our services can be tailored to your operational and compliance requirements.


