How Long to Keep It
Route history has a short operational life and a long liability. Setting a period per purpose, and the deletion that has to actually happen.
Location data is useful for days and held for months. That gap is where a substantial share of enforcement findings in this field sit.
How long each purpose actually needs
Dispatch: the current position. History has no dispatch value at all.
Proof of attendance: as long as an invoice can be queried. Commonly weeks to a few months, and it applies to the geofence events rather than to a trail.
Lone worker safety: the duration of the shift, plus whatever an incident investigation needs.
Mileage and expenses: as long as the expense record, which is a tax retention question and concerns totals rather than routes.
Driver behaviour: long enough to coach, which is weeks.
Almost nothing in this list needs six months of continuous position data, and retention periods of that length have been found excessive by regulators examining exactly this.
Setting the periods
Per data category, not one global figure.
Raw positions: shortest. These are the most intrusive and the least operationally useful once aggregated.
Derived events — arrivals, departures, distances: longer, because they serve the commercial purposes.
Incident data: held under its own rule, with a hold mechanism so it survives the routine deletion.
Write the numbers down in the assessment, because "as long as necessary" is not a period and will not survive a question.
Deletion that happens
Automated, because manual deletion does not occur.
Verified: attempt to retrieve something past its period and confirm it is gone rather than hidden from a report.
Including backups, which is where retained data outlives a deletion policy.
Including exports. A route history downloaded to a spreadsheet for a manager is outside every control the system has, and this is the commonest leak.
Including the vendor's copy, which needs to be in the contract.
Aggregate before deleting
The operational value usually survives aggregation.
Daily distance per vehicle. Visit counts per site. Average duration by job type.
Keep those; delete the positions they came from.
This preserves the planning capability that the long retention was defended on, while removing the record of individual movements.
What to check
What is the configured retention, per category, in days?
Was it chosen, or is it the vendor default? Defaults in this category are commonly generous.
Has a deletion actually run, and did anyone verify it?
Where are the exports?
Does the vendor's retention match yours? They frequently differ, and theirs is the one that matters after you delete.
Find the exports
The leak that defeats every retention policy.
A route history downloaded to a spreadsheet sits outside every control the system has.
It survives deletion, appears in access requests, and nobody knows it exists.
Ask who has exported what, and where it went.
Then decide: either exports are logged and time-limited, or reporting is done inside the system. Both work; the current arrangement of neither does not.
An implementation prompt
During configuration, view this scope example can prompt questions about fields, ownership and output. Confirm current capabilities and document each plan, integration or policy assumption.