Skip to content

GDPR Checklist for Shared Mobility Operators

By Axons Mobility Team · · Updated · Technology · 9 min read

The short answer

To follow GDPR as a shared mobility operator, know what personal data you hold (identity, ID documents and selfies, trips and location, payments and driving behaviour), have a lawful basis for each use, collect as little as you can, limit who on your team can see it, and let riders download or delete their data. Also host data where transfers stay simple, set retention periods, check where every vendor stores data, plan for breaches and keep personal data out of AI prompts.

A GDPR checklist for a shared mobility operator comes down to ten questions: what personal data you hold, where it lives, why you may use it, how little you can collect, who can see it, how riders use their rights, how long you keep it, which vendors touch it, what you do after a breach, and how AI tools use it. The table at the end turns each one into something you can tick off.

This is practical guidance from Axons Mobility, a shared mobility software company, not legal advice. Every business and country is different, so check your own set-up with a data protection lawyer or your data protection officer. Where our software handles a step for you, we say so. The full text of the regulation is on EUR-Lex.

What personal data does a sharing service handle?

More than most apps. A scooter, bike, moped or car sharing service links a named person to where they went, when, how they rode and how they paid. Start by listing every type of data you hold:

DataExamplesWhy it needs care
Account and contactName, phone number, email addressDirectly identifies the rider
IdentityID document photos, selfies, check resultsAmong the most sensitive data you hold; biometric data used to identify a person gets extra protection
Trips and locationStart and end points, routes, times, parking photosRepeated trips can reveal home, work and daily habits
PaymentsTransactions, wallet balance, deposits, refundsFinancial data, often also needed for tax records
Driving behaviour and safetyHarsh events, crash detections, driving scores, emergency alertsCan change how a rider is treated, for example a warning or a ban
Support and disputesChat messages, complaint details, dispute photosRiders often share more than you asked for, sometimes about other people
StaffConsole logins, activity log entriesYour team’s personal data is covered too

For each line, note where the data is stored, who can see it, which vendors receive it and how long you keep it. This list, often called a record of processing, is the base for every other step below.

Where should rider data be hosted?

GDPR does not forbid storing data outside the EU, but moving personal data to other countries needs extra steps, such as checking whether the country is recognised as protecting data well enough, or signing standard contractual clauses with the receiver. Hosting data for EU riders inside the EU keeps your main platform out of those questions, and makes it easier to answer riders, partners and cities who ask where their data goes.

EU hosting does not replace the rest of GDPR, and it only covers the systems hosted there. Check backups, support tools, email tools and analytics too, and ask each vendor the questions in the vendor section below.

What lawful basis do you need?

GDPR says you need a lawful reason, called a lawful basis, for each way you use personal data. There are six. The ones sharing operators rely on most are:

  • Contract: data you need to give riders the service they signed up for, such as their account, the ride’s location data and the payment.
  • Legal obligation: data the law makes you keep, such as invoices and tax records.
  • Legitimate interests: uses riders would reasonably expect, such as preventing fraud or protecting vehicles, once you have weighed your interest against the rider’s privacy and written that down.
  • Consent: uses riders are free to refuse, such as promotional messages. Consent must be a clear yes, given for a specific purpose, and as easy to withdraw as it was to give.

Two mistakes are common. The first is asking for consent for something the service cannot run without: if a rider who says no cannot ride, the consent was not really free. The second is one tick box that covers everything. Explain each use in plain words in your privacy notice instead.

In Axons Mobility, offers go only to riders who opted in, and riders turn each kind of notification on or off themselves in the app, with quiet hours.

How can you collect less data?

GDPR expects you to collect only what you need. Data you never hold cannot leak, needs no retention rule and never appears in an access request. Practical ways to collect less:

  • Check on the phone where you can. The Axons Mobility helmet photo check happens on the rider’s phone, and the photo is not uploaded. You learn that the rider has a helmet without storing a photo of them.
  • Ask only when a check is needed. Decide which riders and vehicles need an ID check, and explain why at the moment you ask.
  • Tie location to a purpose. A ride needs route data. For every other use of location, ask whether you really need it and for how long.
  • Limit exports. Every spreadsheet of riders on a laptop is another copy to protect and delete. Export only what a task needs, and remove the file afterwards.
  • Protect what you keep. In Axons Mobility, rider phone numbers are stored securely for every operator, and card details stay with the payment provider, never with us.

Who on your team can see personal data?

Many privacy problems inside a business are ordinary ones: too many people can see too much. Give each person only the access their job needs. A support agent needs a rider’s history; a field technician needs vehicles, not riders’ phone numbers.

In the Axons Mobility operator console, you assign roles from full control to view-only and choose exactly what each person can see and do. You can hide rider details and money from chosen staff, keep site managers to their own fleet, and choose who can send vehicle commands, give credit and refund. Each team member has an activity history, and you can see who changed prices and zones, and when. When someone leaves, you suspend or remove them in one place. Whatever software you use, remove access on the day someone leaves.

How should you handle rider rights requests?

GDPR gives riders rights over their data. The requests you will see most often are:

  • Access: a copy of the personal data you hold about them.
  • Portability: their data in a common format they can take elsewhere.
  • Erasure: deleting their data, where you have no legal reason to keep it. It is often called the right to be forgotten.
  • Correction: fixing data that is wrong.
  • Objection: stopping certain uses, and always stopping direct marketing when asked.

Answer without undue delay, and generally within one month. Confirm who is asking before you send any data: a request from inside the rider’s own signed-in account is the simplest proof.

Self-service saves your team time. In the Axons Mobility rider app, riders download a copy of their personal data and delete their account themselves, with no email back and forth. When the 30-day waiting period after a deletion ends, personal details such as name, email address and phone number are removed. Removing who the rider was, rather than wiping every record, lets you keep the financial records the law may require.

How long should you keep rider data?

GDPR sets no single period. You may keep personal data only as long as you need it for the purpose you collected it for. Write a retention schedule that covers at least:

  • ID check images and results
  • trip routes and vehicle data linked to riders
  • parking photos and dispute evidence
  • support conversations
  • payment and invoice records, where tax law in your country often sets a minimum
  • staff activity logs
  • data from closed accounts

For each, write the purpose, the period, what happens at the end (delete or anonymise) and who checks that it happened. Keep dispute evidence at least as long as riders can dispute a charge. Review the schedule once a year.

What should you ask your vendors?

Every company that handles personal data for you is a processor: your software platform, payment provider, identity check provider, email and support tools, analytics and AI tools. GDPR requires a written agreement with each one, usually called a data processing agreement. Ask every vendor:

  • Where is our data stored, and where is it accessed from, including backups and support staff?
  • Which other companies do you use to process it, where are they, and how will you tell us about changes?
  • Will you sign a data processing agreement?
  • How is the data encrypted, and who at your company can reach it?
  • How quickly will you tell us about a breach?
  • How do we export our data, and how is it deleted when we leave?

Ask Axons Mobility the same questions. With Axons Mobility, riders pay into your own Stripe account, so you also have your own agreement with the payment provider; read its data terms too.

What should you do if there is a data breach?

A breach is any security incident where personal data is lost, destroyed, changed, or seen by someone who should not see it. A lost staff laptop with a rider export counts. Write the plan before you need it:

  1. Name who decides. One person owns the response, with a named backup.
  2. Contain it. Remove access, reset passwords and revoke keys. In Axons Mobility, you can suspend a team member’s access in one step.
  3. Find out what happened. Which data, how many riders, since when. In Axons Mobility, each team member’s activity history shows what they did, and when.
  4. Report it where required. Unless the breach is unlikely to put people at risk, tell your data protection authority within 72 hours of becoming aware of it. If the risk to riders is high, tell them too, without undue delay.
  5. Record every breach, including the ones you did not have to report, and what you changed afterwards.

Can you use AI tools with rider data?

AI assistants are good at questions like “which zones lost the most trips last week?”. The risk is pasting rider exports into a general chat tool, which sends personal data to a new processor, possibly outside the EU and without an agreement. A few rules keep AI use safe:

  • Keep personal data out of prompts. Ask about totals and trends, and remove names, phone numbers and emails. The Axons Mobility assistant never sees rider names, emails or phone numbers.
  • Use tools that follow permissions. The Axons Mobility AI assistant answers from your data, and only from the data the person asking is allowed to see.
  • Write down who uses what. Keep a list of the AI tools your team uses, and for what.
  • Keep a person in charge. In the Axons Mobility console, the assistant can propose an action, but nothing happens until a person presses Confirm.
  • Control outside connections. You can connect Claude, ChatGPT or another MCP app to your Axons Mobility workspace: each person signs in and approves it, and it works only within their own permissions. Check the AI provider’s own terms on where prompts are processed and kept.

GDPR checklist for shared mobility operators

AreaWhat to doDone when
Data mapList every type of personal data, where it lives and who receives itA written record you review each year
HostingKnow where every system stores data, including backupsNo transfer outside the EU without safeguards
Lawful basisChoose a basis for each use of dataEach use has a basis written next to it
Privacy notice and consentExplain uses in plain words; ask consent only for optional usesConsent is recorded and easy to withdraw
MinimisationCollect only what each purpose needs; check on the phone where possibleEvery field has a reason
Access controlRoles by job; personal data hidden where not needed; fleet limitsAn activity log and a leaver process
Rider rightsAccess, portability, erasure, correction and objectionRequests tracked and answered within one month
RetentionSet a period for each type of dataData is deleted or anonymised on schedule
VendorsAsk where they host; sign data processing agreementsA signed agreement for every processor
BreachesWrite a response plan with an ownerReady to report within 72 hours; every breach recorded
AI toolsKeep personal data out of prompts; use permissions and logsA written rule your team follows

Much of this list is easier when the software handles the routine parts. With Axons Mobility, riders download and delete their own data, offers reach only riders who opted in, and each person on your team sees only what their role allows. See how on our security page. For the checks that create identity and driving data in the first place, see our guide to rider safety in shared mobility, or request a free 15-day trial and try these tools on your own vehicles.

Frequently asked questions

Does GDPR apply to scooter sharing and car sharing operators?

Yes, if you are based in the EU or offer rides to people in the EU. Rider accounts, trips, locations and payments are all personal data. The operator usually decides why and how that data is used, which makes it the controller, while its software, payment and identity check providers process data on its behalf.

Is GPS location data personal data under GDPR?

Yes, when it can be linked to a person. A trip route tied to a rider’s account is personal data, and a series of trips can reveal where someone lives and works and what their habits are. Treat trip and location data with the same care as names and phone numbers.

Do sharing apps need consent to track a rider’s location?

Not always. Location needed to run and bill the ride a rider asked for is often based on the contract with the rider rather than consent. Optional uses, such as marketing, need their own lawful basis, often consent. Tell riders clearly what you collect and why, and check your set-up with a data protection adviser.

How long can a mobility operator keep rider data?

GDPR sets no single period. You may keep personal data only as long as you need it for the purpose you collected it for. Tax and accounting laws in your country often set how long financial records must be kept. Write a retention schedule for each type of data and delete or anonymise data when its period ends.

Can we use ChatGPT or Claude with our rider data?

Only with care. Keep names, phone numbers and emails out of prompts in general chat tools. If an AI tool needs your workspace data, use a connection that follows staff permissions and is covered by an agreement with the provider. In Axons Mobility, the built-in assistant never sees rider names, emails or phone numbers, and you can connect Claude, ChatGPT or another MCP app that works only within each person’s own permissions.

Related on Axons Mobility