GDPR Compliance

    Complete documentation of Traice's data protection and regulatory compliance measures

    GDPR Principles

    How Traice is designed to align with the core principles of European GDPR

    Lawfulness, Fairness, and Transparency

    Traice is designed to align with GDPR requirements for European markets. Our platform follows data protection principles and works with customers to establish appropriate legal frameworks for vehicle location data processing.

    Purpose Limitation

    Geolocation data is collected and processed exclusively for legitimate vehicle recovery purposes (e.g., contract breach, asset protection). Data is never used for marketing, profiling, or unrelated business purposes.

    Data Minimization

    Traice retrieves only the minimum necessary data: GPS coordinates, timestamp, and vehicle identification. No personal data about drivers or passengers is collected. Location data is not stored permanently unless required by law.

    Accuracy and Storage Limitation

    Location data is retrieved in real-time directly from OEM APIs, ensuring maximum accuracy. Data is retained only as long as necessary for recovery operations and audit trail compliance (typically 30-90 days, configurable per customer DPA).

    Integrity and Confidentiality

    All data is protected with industry-standard encryption at rest and in transit. Role-based access control (RBAC) ensures only authorized recovery personnel can request location data. Multi-factor authentication (MFA) is enforced for all user accounts.

    Accountability

    Traice maintains comprehensive audit logs of all location requests, including user identity, legal basis, timestamp, and vehicle details. These logs are available for regulatory audits and customer compliance reviews.

    Legal Basis for Data Processing

    EU GDPR Art. 6(1)(f)

    Legitimate Interest (EU/EEA)

    Processing is necessary for the purposes of legitimate interests pursued by the data controller (vehicle recovery due to contract breach or payment default), provided those interests are not overridden by the fundamental rights and freedoms of the data subject. This is the primary legal basis for EU/EEA operations.

    UK GDPR Art. 6(1)(f)

    Legitimate Interest (UK)

    The UK GDPR retains an identical legitimate interest provision under Art. 6(1)(f). Traice relies on this legal basis for UK-based customers and vehicles, supplemented by the UK Data Protection Act 2018.

    DPA Requirements

    Data Processing Agreements

    Traice signs Data Processing Agreements (DPAs) with all customers, clearly defining data controller and processor responsibilities, data retention policies, and breach notification procedures.

    Technical & Organizational Measures

    Security and data protection practices safeguarding your data

    Enterprise-grade security infrastructure

    EU-based data hosting (no data transfer outside Europe)

    End-to-end encryption at rest and in transit

    Role-based access control (RBAC) with least privilege principle

    Multi-factor authentication (MFA) enforcement

    Comprehensive audit logging (immutable)

    Automated data retention and deletion policies

    Regular security audits and monitoring

    Data processing agreements with OEM partners

    Data Subject Rights

    Right to Access (Art. 15)

    Vehicle owners can request access to all location data processed about their vehicle. Traice provides this data within 30 days of request via the customer's organization.

    Right to Erasure (Art. 17)

    Vehicle owners can request deletion of their location data, subject to legal obligations (e.g., audit trail retention for regulatory compliance). Traice deletes data within 30 days.

    Right to Object (Art. 21)

    Vehicle owners can object to processing based on legitimate interest. However, if the leasing company demonstrates compelling legitimate grounds (e.g., contract breach), processing may continue.

    Data Breach Notification (Art. 33-34)

    In the event of a data breach, Traice notifies affected customers within 72 hours and coordinates with them to notify relevant supervisory authorities and affected individuals.

    Data Protection & Compliance Framework

    Security Best Practices

    Following industry-standard security frameworks

    EU GDPR

    Designed to align with EU data protection requirements

    UK GDPR

    Following UK Data Protection Act 2018

    Questions About Compliance?

    Our legal and compliance team is available to discuss your specific requirements