---
title: "Who is Allowed to See it: Designing a European Control Tower Around Jurisdictional Access Limits"
id: "26090"
type: "post"
slug: "european-control-tower-jurisdictional-access-limits-2026"
published_at: "2026-08-28T15:00:00+00:00"
modified_at: "2026-08-28T12:50:53+00:00"
url: "https://locus.sh/blogs/european-control-tower-jurisdictional-access-limits-2026/"
markdown_url: "https://locus.sh/blogs/european-control-tower-jurisdictional-access-limits-2026.md"
excerpt: "Multi-country visibility programmes are scoped on coverage and capped by permission. The four limits that decide what a European control tower may display, and what to specify before you procure."
taxonomy_category:
  - "General"
---

#### [General](https://locus.sh/blogs/category/general/)

# Who is Allowed to See it: Designing a European Control Tower Around Jurisdictional Access Limits

[Ishan Bhattacharya](/author/ishan_locus/)

Aug 28, 2026

15 mins read

## Key Takeaways

- European visibility programmes are scoped on coverage: how many feeds, how fresh, how predictive. The constraint that actually caps them is that the visibility you may display is narrower than the visibility you can collect, and it varies by country.
- A vendor’s GDPR attestation confirms the platform can process personal data lawfully. It says nothing about whether a specific screen, shown to a specific viewer, in a specific country, is lawful.
- Four limits shape the interface rather than the data pipeline: purpose limitation, granularity and proportionality, retention, and collective consultation.
- Refresh rate is a legal parameter, not only a technical one. Continuous driver-level tracking is disproportionate where a coarser signal answers the same operational question.
- Role-based access modelled on role alone is insufficient in Europe. The access decision is a function of role, jurisdiction, purpose, granularity, and retention window at once.
- Rollout pace is set by approval lead time rather than integration lead time. Sequencing by market size usually means starting with the hardest consultation.

## The screen that is lawful in Rotterdam and not in Hamburg

A European retailer runs a visibility programme across eleven countries. The control tower is built, the carrier feeds are connected, and the pilot in the Netherlands works. One screen shows every active vehicle, its driver, current dwell time at the stop, and a performance comparison against the depot average.

The German rollout stops. Not on integration, and not on data quality. The works council objects to the driver-level view, and under German co-determination that objection is substantive rather than advisory.

The programme now has a problem it did not budget for. The single view was the entire point, and the single view cannot be shown in the country holding a quarter of the volume. The available responses are all bad: run a separate German instance and abandon the single view, strip the driver dimension everywhere and lose the capability the business case promised, or pause and enter a consultation nobody scheduled.

This is the constraint that caps multi-country visibility in Europe, and it is almost never in the design. Visibility programmes are scoped on coverage: how many feeds, how fresh, how predictive. What actually limits them is permission. The visibility an operation may display is narrower than the visibility it can technically collect, and the boundary moves when you cross a border.

**Also Read:** [The Control Tower Test: 7 Signals Your Supply Chain Visibility Stack Isn’t Working in 2026](https://locus.sh/blogs/control-tower-test-supply-chain-visibility-signals-europe-2026/)

## Why this is not a GDPR checkbox

Most procurement treats this as settled by a vendor attestation. GDPR readiness, ISO certification, role-based access controls, audit trails. Those are necessary and they answer a different question.

An attestation confirms the platform is capable of processing personal data lawfully. It does not establish that a particular screen, shown to a particular viewer, in a particular country, for a particular purpose, is lawful. That determination belongs to the operation deploying it, and it is made per view rather than per platform.

Three distinct bodies of law apply, and conflating them is what produces the Hamburg problem.

Data protection law governs whether the processing has a valid basis and whether the data is proportionate to the stated purpose. Rules on automated decision-making and worker management govern what may be decided about a person by a system, with employment and worker management treated as a high-risk category under the EU AI Act. And collective employment law governs whether the workforce’s representatives must agree before a monitoring capability is introduced at all.

The third one is the one that stops projects, because it is procedural. It cannot be resolved by a better privacy notice or a tighter permission set. It requires an agreement with a body that has its own timetable.

One clarification worth making, because it is where this discussion usually stops. The question of whether an algorithm may determine a driver’s working day is well established and separately argued: dispatch logic falls within co-determination scope because it shapes the shift. The under-examined half is the viewing layer. A control tower does not necessarily decide anything. It displays. And display, where what is displayed is a named worker’s behaviour in real time, is monitoring in its own right.

## The four limits that shape the interface

**Purpose limitation.** Telemetry collected to optimise routes is not automatically available for managing people. The [purpose limitation and data minimisation principles](https://gdpr-info.eu/art-5-gdpr/)
 require that data gathered for one stated purpose is not repurposed for an incompatible one without its own basis. In practice this separates two products that look like one feature: a vehicle on a map serving a delivery-promise purpose, and a driver league table serving a performance-management purpose. The second is a different decision with different obligations, and building it because the data was already there is the most common way a visibility programme acquires a legal problem.

**Granularity and proportionality.** Data minimisation means granularity has to be justified by the question being answered. If the operational question is whether a delivery will miss its window, a five-minute vehicle-level position usually answers it. Ten-second driver-level telemetry answers it no better and collects considerably more. This makes refresh rate and field-level detail legal parameters rather than purely technical ones, which is an unfamiliar idea in a category that markets latency as a virtue.

**Retention.** Historical visibility has a jurisdictional expiry. Carrier scorecards, dwell-time baselines, and trend analytics built on identifiable data cannot be held indefinitely simply because the analytics improve with history. The workable answer is to aggregate or pseudonymise on a defined schedule so the analytical value survives while the personal data does not, which is a design decision that has to be made before the first year of history accumulates rather than after.

**Collective consultation.** In Germany, co-determination gives the works council a substantive role, and the introduction of technical systems capable of monitoring employee performance or behaviour sits squarely inside it under section 87(1) no. 6 of the Works Constitution Act. France and the Netherlands impose consultation duties of different shape and timing. The consequence is that the same dashboard requires different approvals, obtained from different bodies, on different timelines, in each country you operate.

**Also Read:** [Logistics AI Governance EU 2026: Six Architectural Mechanisms](https://locus.sh/blogs/logistics-orchestration-governance-six-mechanisms-autonomous-decisioning-2026/)

## Three ways enterprises scope a European control tower

| Dimension | Coverage-first | Compliance-gated | Jurisdiction-modelled access |
| --- | --- | --- | --- |
| What sets the scope | Feed availability and latency | Legal sign-off before each release | Access policy per jurisdiction, purpose, and granularity |
| Where it fails | Blocked at the first works council | Slow, and legal becomes a queue | Requires the platform to model jurisdiction |
| Single network view | Promised, then fragmented | Preserved but delayed | Preserved |
| Typical workaround | Country-specific instances | Feature stripped everywhere | None needed |
| Rollout pace set by | Integration effort | Legal review throughput | Approval lead time, planned upfront |
| Driver-level detail | On everywhere, until challenged | Off everywhere, to be safe | On where permitted, aggregated elsewhere |
| Analytics continuity | Breaks at retention limits | Breaks at retention limits | Preserved through pseudonymisation |

The row that decides the others is the workaround. Country-specific instances are how most operations resolve this in year two, and they defeat the purpose of the programme: eleven dashboards is the situation the control tower was bought to replace. The stripped-everywhere alternative is safer and quietly expensive, because it removes capability from the nine countries where it was permitted in order to satisfy the two where it was not.

## What role-based access has to mean in Europe

Standard role-based access control models permission as a function of role. A depot manager sees their depot, a regional lead sees the region, an administrator sees everything.

That model is insufficient here, because the same role legitimately has different entitlements in different countries. A depot manager in Spain and a depot manager in Germany hold the same job and may not lawfully see the same fields on the same screen.

So the access decision is a function of five variables at once: role, jurisdiction, purpose, data granularity, and retention window. A platform that models only the first forces the operation into instance separation, which is why this is an architectural question rather than a configuration one.

The design that works is a single data layer with jurisdiction-aware presentation. Events are ingested once, tagged with the purpose they were collected under, and rendered according to the viewer’s entitlement in the relevant jurisdiction. The network view stays whole. What varies is the resolution at which any given viewer sees it, which is the opposite of the usual arrangement where the data is fragmented and the view is uniform.

**Also Read:** [Supply Chain Control Tower: Build Real-Time Visibility](https://locus.sh/blogs/supply-chain-control-tower-real-time-visibility/)

## The rollout consequence nobody plans for

Multi-country visibility rollouts are almost always sequenced by commercial logic: largest market first, or the market with the worst service problem first.

In Europe that ordering is frequently wrong, because it optimises for value and ignores approval lead time. Works council agreement in Germany can take months and cannot be compressed by executive sponsorship. Sequencing the programme to begin there means the whole initiative reports no progress for two quarters while the consultation runs.

Two adjustments make the difference. Sequence by approval lead time rather than market size, so integration work in slow-approval countries proceeds in parallel with consultation instead of after it. And ship an aggregate-only mode first, showing volumes, lane performance, and exception counts without personal data, so the network view exists and delivers value in every country while jurisdiction-specific detail is unlocked as each approval completes.

The second point is the more useful one, because it changes the negotiation. Arriving at a works council with a system already running in an aggregate mode, and a specific proposal for what additional field is needed and why, is a materially different conversation from arriving with a dashboard that shows everything and a request for permission.

## What to specify before you procure

Six requirements that belong in the RFP rather than in a later change request.

**Per-jurisdiction access policy,** not per-role alone, with evidence that entitlements can differ by country for the same role.

**Field-level display control,** specifically the ability to show a vehicle and its status without exposing driver identity, as a configuration rather than a bespoke build.

**Purpose tagging at ingest,** so the basis on which data was collected travels with it and repurposing is detectable rather than accidental.

**Retention policy per data class and per country,** with automated aggregation or pseudonymisation on expiry so analytics survive the deletion of personal data.

**An aggregate view mode** that is genuinely useful without personal data, since this is what you will operate in pending jurisdictions.

**A viewer-level audit trail** recording who accessed which records and when. This is an accountability obligation in its own right, and it is also the evidence you will need if a works council asks how the capability has actually been used.

**Also Read:** [Why Governance Matters More Than Autonomy in Enterprise Logistics AI](https://locus.sh/blogs/ai-governance-enterprise-logistics-five-dimensions/)

## What to measure

**Share of countries live at full entitlement.** Distinguished from countries integrated. The gap between the two is the real programme status and is usually not reported.

**Approval lead time per jurisdiction.** Measured from request to agreement. This is the number that should drive the rollout sequence and rarely exists at planning time.

**Proportion of views served from aggregate mode.** High is not a failure. It indicates the fallback is doing real work.

**Purpose-tag coverage at ingest.** The percentage of ingested events carrying a recorded collection purpose. Without this, repurposing cannot be prevented or evidenced.

**Retention compliance by data class.** Whether expiry and pseudonymisation are executing as specified, per country, verified rather than assumed.

**Also Read:** [European Cross-Border Fulfilment and Returns: Operational Complexity](https://locus.sh/blogs/european-cross-border-fulfilment-returns-operational-complexity/)

## How Locus supports a control tower you can actually switch on

Locus, the world’s first Decision-Intelligent, Agentic TMS, treats access and traceability as properties of the decision record rather than as a reporting layer added afterwards, which is what allows the same network view to be rendered at different resolutions for different viewers. Its [control tower software](https://locus.sh/control-tower-software/)
 provides order-level and milestone-level visibility across owned fleet, contracted 3PLs, and parcel partners, with the Dispatch, Capacity, and Carrier agents running a continuous Sense-Decide-Execute-Learn loop against a model of more than 250 real-world constraints.

Three properties matter for the argument in this piece. Role-based access controls and full audit trails are native rather than bolted on, which is what makes viewer-level accountability evidenceable to a works council. Certification covers SOC 2 Type II, ISO 27001, ISO 27701 for privacy information management, and GDPR readiness, with ISO 27701 being the relevant one here because it addresses privacy management specifically rather than security alone. And because each decision retains its inputs and the plan version it produced, the record of what was collected and what it informed exists without a separate exercise to reconstruct it.

Locus is recognized by Gartner for seven consecutive years, featured in the 2026 Hype Cycle for Supply Chain Execution and Logistics Technologies, named a Leader in TMS by QKS Group (SPARK Matrix), and ranked #1 in Route Planning on G2’s 2026 Best Software Awards. In October 2025, Ingka Investments, the investment arm of Ingka Group, the world’s largest IKEA retailer, acquired Locus. Locus continues to operate independently. Further [analyst recognition](https://locus.sh/analyst-recognition/)
 is published in full.

One deployment illustrates the sequencing point at scale. A [Fortune 50 parcel and logistics provider](https://locus.sh/case-studies/fortune-50-parcel-centralized-dispatch/)
 centralised dispatch across 51 sites in a 120-country network, running more than a million freight shipments a year against a driver pool of 4,500 split between captive and third-party capacity. Two features are directly relevant. The rollout was staged site by site rather than switched on network-wide, which is the structure that allows approval-led sequencing rather than value-led sequencing. And the captive and third-party split matters legally as well as operationally, because a contracted carrier’s drivers sit in a different relationship to the operation than employees do, which changes both the consultation obligation and the lawful basis for anything driver-identifiable. Weekly execution rose from 75% to 92% at 99.99% uptime, and more than $14 million in previously unused capacity was surfaced.

Request a Locus [European control tower readiness assessment](https://locus.sh/schedule-demo/)
 to map your per-jurisdiction entitlement requirements, establish approval lead times by country, and define the aggregate mode you will operate while consultations complete.

## Ask which screen you are actually approving

Before the next visibility milestone, take the highest-value screen in the design and answer three questions in writing.

Which fields on it identify a person, directly or in combination. What purpose each of those fields was collected under, and whether this screen serves that purpose or a different one. And which of your operating countries requires an agreement before this screen can be shown to a line manager.

If the answers are not on paper, the programme does not have a coverage problem yet. It has a permission problem that will surface at the first border, and it is considerably cheaper to design for now than to renegotiate later.

## Frequently Asked Questions (FAQs)

Can a European control tower show driver-level location in real time?

It depends on the country, the purpose, and whether the workforce’s representatives have agreed. Displaying an identified worker’s location and behaviour in real time is monitoring, which brings data protection obligations on lawful basis and proportionality, and in several jurisdictions a collective consultation or agreement requirement. In Germany the introduction of technical systems capable of monitoring employee performance or behaviour falls under works council co-determination, meaning agreement is required rather than advisable. The practical design answer is to make driver-level detail a jurisdictional entitlement rather than a global default.

Does a vendor’s GDPR compliance cover our control tower deployment?

No. A vendor attestation confirms the platform is capable of processing personal data lawfully and that appropriate security and privacy controls exist. Whether a specific view, shown to a specific role, in a specific country, for a specific purpose, is lawful is determined by the deploying organisation. That assessment is made per view rather than per platform, and it is the part most procurement processes omit because the certification appears to have settled it.

What is purpose limitation and why does it affect visibility dashboards?

Purpose limitation requires that personal data collected for one stated purpose is not further processed in a way incompatible with it. In a visibility context this separates two things that look like one feature. Telemetry collected to improve delivery reliability supports an operational view of where a vehicle is. Using the same telemetry to rank drivers by performance is a different purpose requiring its own basis. Building the second because the data already exists is the most common route to a compliance problem.

How should a multi-country visibility rollout be sequenced?

By approval lead time rather than market size. Consultation in jurisdictions with substantive co-determination can take months and is not compressible by sponsorship, so beginning with the largest market often means the programme reports no progress for two quarters. Running integration work in parallel with consultation, and shipping an aggregate-only view first so every country gains value immediately, allows jurisdiction-specific detail to be unlocked as each approval completes.

What does jurisdiction-aware role-based access mean?

It means entitlement is calculated from role, jurisdiction, purpose, data granularity, and retention window together, rather than from role alone. The same job title in two countries may lawfully see different fields on the same screen. Platforms modelling role only push operations towards country-specific instances, which fragments the single network view the control tower was procured to provide. The alternative is one data layer with jurisdiction-aware presentation, where the view stays whole and the resolution varies by viewer.

How do retention limits affect supply chain analytics in Europe?

Identifiable data cannot be retained indefinitely merely because longer history improves the analysis, which puts a jurisdictional expiry on trend analytics, dwell baselines, and driver-linked carrier scorecards. The workable approach is scheduled aggregation or pseudonymisation, so the analytical value persists after the personal data is removed. This has to be designed before the first year of history accumulates, because retrofitting it usually means discarding the history rather than converting it.

MEET THE AUTHOR

Ishan Bhattacharya

Lead - Content

Ishan, a knowledge navigator at heart, has more than a decade crafting content strategies for B2B tech, with a strong focus on logistics SaaS. He blends AI with human creativity to turn complex ideas into compelling narratives.

### Related Tags:

[https://locus.sh/blogs/cfo-guide-verifying-last-mile-ai-savings-2026/](https://locus.sh/blogs/cfo-guide-verifying-last-mile-ai-savings-2026/)
#### [General](https://locus.sh/blogs/category/general/)

## [A US CFO’s Guide to AI Investment in Last-Mile Delivery Efficiency: Proving the Savings Arrived](https://locus.sh/blogs/cfo-guide-verifying-last-mile-ai-savings-2026/)

[Aseem Sinha](https://locus.sh/blogs/author/aseem_locus/)

Aug 28, 2026

Building the business case is the solved half. Twelve months later, four confounders have invalidated the baseline you forecast against. How to attribute realized savings defensibly, and what to fix at approval time.

[Read more](https://locus.sh/blogs/cfo-guide-verifying-last-mile-ai-savings-2026/)

[https://locus.sh/blogs/real-time-visibility-cod-cash-chain-southeast-asia-2026/](https://locus.sh/blogs/real-time-visibility-cod-cash-chain-southeast-asia-2026/)
#### [General](https://locus.sh/blogs/category/general/)

## [Real-Time Visibility Ends at Handover: Tracking the COD Cash Chain in Southeast Asia](https://locus.sh/blogs/real-time-visibility-cod-cash-chain-southeast-asia-2026/)

[Anas T](https://locus.sh/blogs/author/anas_locus/)

Aug 28, 2026

In high-COD Southeast Asian markets a delivery is also a payment. Real-time visibility instruments the parcel to the second and the money not at all. The custody chain, and what to measure.

[Read more](https://locus.sh/blogs/real-time-visibility-cod-cash-chain-southeast-asia-2026/)

## Who is Allowed to See it: Designing a European Control Tower Around Jurisdictional Access Limits

- Share
- [Print](javascript:window.print())
- [Download](#)
- [Schedule a Demo](https://locus.sh/schedule-demo/)

### Is your team spending more time on fixing logistics plan than running the operation?

- Agentic transportation management from order intake to freight settlement
- Route optimization built on 250+ real-world constraints
- AI-driven dispatch with automatic execution handling

20%Cost Reduction

66%Faster Planning Cycles

[Schedule a demo](/schedule-demo/)

Insights Worth Your Time

#### [General](https://locus.sh/blogs/category/general/)

## [Locus 2026 UK Consumer Survey: Why Returns Visibility is Now the Conversion Engine for AI-Driven Shopping in UK Retail](https://locus.sh/blogs/returns-visibility-conversion-engine-ai-shopping-uk-retail-locus-q2-2026-consumer-survey/)

[Aseem Sinha](https://locus.sh/blogs/author/aseem_locus/)

May 29, 2026

#### [General](https://locus.sh/blogs/category/general/)

## [Locus 2026 US Consumer Survey: Generative AI isn’t Just Changing How Consumers Shop, it’s Breaking the Demand Patterns US Retail Was Built On](https://locus.sh/blogs/generative-ai-shopping-effect-retail-fulfillment-operations-locus-q2-2026-consumer-survey/)

[Ishan Bhattacharya](https://locus.sh/blogs/author/ishan_locus/)

May 29, 2026

#### [General](https://locus.sh/blogs/category/general/)

## [Embedded vs Bolted-On AI: The Architecture Question European Logistics Buyers Are Asking](https://locus.sh/blogs/embedded-vs-bolted-on-ai-european-logistics-platform-architecture-business-benefits/)

[Aseem Sinha](https://locus.sh/blogs/author/aseem_locus/)

May 21, 2026

#### [General](https://locus.sh/blogs/category/general/)

## [Hybrid Fleet Management: How Owned, 3PL, Gig, ICE, and EV Capacity Actually Operate at Most Enterprises](https://locus.sh/blogs/three-workforce-fleet-reality-owned-3pl-gig-drivers/)

[Aseem Sinha](https://locus.sh/blogs/author/aseem_locus/)

May 7, 2026

#### [General](https://locus.sh/blogs/category/general/)

## [US Returns Hit $850 Billion in 2025: Why US Retailers Are Restructuring Reverse Logistics in 2026](https://locus.sh/blogs/850-billion-us-returns-ai-routing-reverse-logistics-2026/)

[Ishan Bhattacharya](https://locus.sh/blogs/author/ishan_locus/)

May 7, 2026
