Privacy policy
When you use our services, you’re trusting us with your information. We understand this is a big responsibility and we work hard to protect your data and privacy.
GDPR Overview
Note: The contents of this section should not be construed as legal advice or a substitute for legal advice. While Netradyne attempts to provide relevant and current information regarding regulatory requirements under the GDPR, it makes no claims that the information provided here is exhaustive, current, or adequate. Similarly, Netradyne makes no claims that the assessments and forms provided by Netradyne are sufficient to comply with all applicable legal and regulatory requirements in your jurisdiction. It is imperative to seek definitive legal advice and check applicability of different laws in your region before activation of installed devices and use of Netradyne Systems.
Under the General Data Protection Regulation (“GDPR”) there are several requirements that apply to companies that collect, use, store or process personal data of data subjects.
It is possible that some or all of these GDPR requirements could be relevant to companies, that are considering the use of Netradyne Devices and the Driver•i app (“Netradyne Systems”), as such systems have the potential to collect, process and store data on behalf of fleets.
The following requirements are examples and do not represent an exhaustive list of requirements found under the GDPR:
- Lawful Basis (Article 6)
- Transparency and Privacy Notices (Articles 13 & 14)
- Purpose Limitation (Article 5(1)(b))
- Data Minimisation (Article 5(1)(c))
- Accuracy (Article 5(1)(d))
- Storage Limitation (Article 5(1)(e))
- Security and Integrity (Article 5(1)(f) and Article 32)
- Accountability (Article 5(2) and Article 24)
- Data Protection by Design and Default (Article 25)
- Data Protection Impact Assessments (Article 35)
- Data Subject Rights (Articles 15–22)
- International Transfers (Articles 44–49)
- Data Breach Notification (Articles 33 & 34)
- Appointment of a Data Protection Officer (Article 37)
It might be helpful for fleets to look over the various requirements and responsibilities set out in the GDPR Articles and determine which ones could be relevant to their situation, configuration and intended use of Netradyne Systems.
In addition to the above, any fleet that uses Netradyne, will be entering into a Data Processing Addendum (“DPA”) for the provision of services associated to Netradyne Systems.
Documentation & Review
Fleets may wish to consider the various requirements and responsibilities set out in the GDPR to determine which ones could be applicable to their circumstances, configuration and intended use of Netradyne Systems. This could help fleets reflect on what is most relevant for them and what documentation they are required to have to satisfy different requirements under the GDPR.
Below Netradyne has set out a checklist of the different documents and forms that it has produced for review and use by fleets.
- Conduct Data Protection Impact Assessment (DPIA) where required.
- Complete Legitimate Interest Assessment (LIA) and or provide Consent Forms as applicable.
- Ensure Data Processing Addendum (DPA) is executed.
- Document and maintain Records of Processing Activities (ROPAs).
Assessment & Forms Available
Data Protection Impact Assessment Form
The European Data Protection Board (EDPB) has published Guidelines on Data Protection Impact Assessment concerning DPIAs, which offer practical advice on identifying when a DPIA is mandatory and the steps to undertake one. These guidelines, together with the provisions of Article 35 itself, should be treated as essential reference materials.
Netradyne has carried a review of the aforementioned guidelines and created Templated DPIAs in relation to Netradyne Systems which are accessible for review here.
When should the DPIA be made?
For the use of Netradyne Systems, we recommend that a DPIA is complete before activation of installed devices. You can request a copy of a templated Data Protection Impact Assessment by contacting your account manager or by contacting the privacy team at dpo@netradyne.com.
Legitimate Interest Assessment Form
Where legitimate interest is the legal basis for processing, to meet accountability requirements, an LIA is recommended to be completed. Further information about LIAs including our template can be accessed here. You can request a copy of a templated Legitimate Interest assessment by contacting your account manager or by contacting the privacy team at dpo@netradyne.com.
Consent Form
Upon request, Netradyne may provide a template consent form for fleets. This template is intended for review and to be adapted by a fleet to meet its operational requirements. You can request a copy of a templated Consent Form by contacting your account manager or by contacting the privacy team at dpo@netradyne.com.
Records of Processing Activities (ROPAs)
Article 30 of the EU GDPR requires both controllers and processors to keep a Record of Processing Activities, with limited exceptions.
Data Protection Authorities provide guidance and templates on how to create ROPAs. The ICO has provided guidance and a template for ROPAs here.
What do ROPAs contain?
In its essence ROPAs establish for each processing activity:
- What data you process;
- Why do you process it (the purpose);
- Who you share it with;
- Where it is stored or transferred to;
- How long you keep it;
- What legal basis you rely on; and
- What security measures you have in place.
Ancillary records could include Agreements or Contracts in association with processing activities.
Data Processing Addendum (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between a controller and a processor that governs how personal data is processed on the controller's behalf.
It is a mandatory requirement under Article 28 of the EU GDPR, a controller cannot lawfully use a processor without one in place.
Our DPA forms part of, and is incorporated within our standard Agreement and can be found here. Any fleet that executes our standard Agreement will already be bound by these terms, which set out Data Processing Responsibilities between fleets and Netradyne.
Data Protection Authorities Additional Guidance
United Kingdom
The Information Commissioners Office (ICO) has released several guidance and documents in relation to rights and responsibilities for data controllers and processors.
These include*:
Guide to accountability and governance
Sets out the UK GDPR accountability principle, including how controllers can demonstrate compliance through policies, staff training, records of processing activities, and data protection by design.
Data Protection Officers (DPOs)
Covers when controllers are required to appoint a DPO, what qualifications and tasks the role involves, and the independence and resources the DPO must be given.
Records of processing activities (RoPA)
Outlines controllers’ duty to keep records of processing activities, including the required content of those records and the circumstances in which exemptions may apply.
Data Protection Impact Assessments (DPIAs)
Guidance on when controllers must carry out a DPIA, what the assessment must cover, and how to consult the ICO when a high risk cannot be mitigated.
Controllers must identify and document a lawful basis before processing personal data. This guide covers all six bases under Article 6 and how to choose between them.
Detailed guidance for controllers on applying the legitimate interests basis, carrying out the three-part Legitimate Interests Assessment (LIA) test, and documenting the balancing exercise.
Sets out when consent is valid, including the need for it to be freely given, specific, informed, and unambiguous, as well as requirements for keeping records and allowing withdrawal.
Summarises the rights individuals have against controllers, including access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.
Note: The above summarise ICO guidance available in April 2026. The ICO updates its guidance periodically. Always verify the current version at https://ico.org.uk before relying on any specific guidance for compliance purposes.
Netherlands
The Autoriteit Persoonsgegevens (AP) has created a plethora of short form guidance and material which are available in the AP’s portal here. Covering topics including:
Note: This document summarises AP’s guidance available in April 2026. The AP updates its guidance periodically. Always verify the current version at https://www.autoriteitpersoonsgegevens.nl before relying on any specific guidance for compliance purposes.
Germany
Germany maintains a comprehensive data protection framework under the Federal Commissioner for Data Protection and Freedom of Information (BfDI) which oversees enforcement at the federal level, focusing on public sector entities as well as telecommunications and postal service providers. Additionally, there are 16 regional Data Protection Authorities (DPAs) [one for each state], each tasked with enforcing data protection regulations in both the public and private sectors within their respective state jurisdictions. The regional DPAs confer under the umbrella of the Data Protection Conference or the Datenschutzkonferenz (DSK).
Both the BfDI and the DSK respectively release guidance and materials spanning different topics and decisions made in relation to data protection enforcement in Germany, these are predominantly found under the DSK’s website.
The documents are available only in German, and accessible within the DSK’s portal here.
Note: This document summarises BfDIs and DSK guidance available in April 2026. The authorities update and review their guidance periodically. Always verify the current version at https://www.datenschutzkonferenz-online.de/kurzpapiere.html before relying on any specific guidance for compliance purposes.
For any enquiries or document requests in relation to data protection and privacy, please contact dpo@netradyne.com.
