Requests to Refuse
The asks that arrive once a tracking system exists, why each should be declined, and what to offer instead.
A working deployment attracts requests. Some would breach the basis it was built on, and the answer is easier if it was decided in advance.
"Show me where she went last month"
Why to refuse: individual history browsing is not one of the stated purposes and has no basis.
Offer instead: if there is a specific concern, the authorised investigation route with a scope and a record.
"Turn on the driver-facing camera, it came free"
Why to refuse: a free feature is still a processing operation needing its own basis, assessment and notice, and the proportionality test for driver-facing is much harder.
Offer instead: forward-facing with event triggering, which addresses the collision case.
"Rank the team on time-on-site"
Why to refuse: dwell time contains waiting, travel within the site, customer conversation and breaks, and rounds are not comparable.
Offer instead: job outcomes, and aggregate round analysis to find the rounds that overrun.
"Track him this weekend, I think he's working elsewhere"
Why to refuse: out-of-hours tracking is where the enforcement cases are, and this is covert surveillance of private life.
Offer instead: if there is a genuine conflict-of-interest concern, it is an HR matter with a proper process and advice.
"Extend retention to a year, just in case"
Why to refuse: excess retention is a breach in its own right, enlarges every access request and every breach, and no purpose here needs it.
Offer instead: aggregates kept indefinitely, positions deleted on schedule, a hold for incidents.
"Put a tracker on his own van"
Why to refuse: restricted or criminal in several jurisdictions, and consent from someone economically dependent is not a sound basis.
Offer instead: customer confirmation of attendance, or a job-completion record.
"Make the pause harder to find, people overuse it"
Why to refuse: a control that is hard to use is not a control, and the absence of a usable one has been an aggravating factor in enforcement.
Offer instead: find out why it is being used so much. Usually the answer is that personal use is more common than the deployment assumed, which is a design finding.
What not to help improve
Making collection less noticeable. Hiding the indicator. Extending collection quietly after an upgrade.
None is a partial improvement. A better-concealed version of the thing is still the thing.
Recording it
What was asked, by whom, when. What was declined and why. What was offered instead. Who decided.
Findable, so the second identical request is answered by reference rather than argued again.
Answer the real concern
Every request has a question behind it, and it is usually answerable.
"Show me where she went" is usually "I think something is wrong", answered by a conversation or, if serious, an authorised investigation.
"Rank the team" is usually "the round overruns", answered by aggregate analysis.
"Track him at the weekend" is usually a conflict-of-interest worry, answered by an HR process.
Offering the real answer turns a refusal into a consultation, which keeps you in the room for the next one.
Turn the principle into a test
For an example that can make this requirement testable, consult the record-transfer example. Treat the page as a starting point rather than proof: reproduce the workflow with real roles, failures and permissions.