Ownership is the wrong frame, but it is the frame everyone reaches for, so it is worth working through properly.
The four claims
The driver. They were there. The footage is of their work, their behaviour and sometimes their mistake. It can be used in a performance review, a disciplinary process, or a court case in which they are the defendant. Of the four parties they carry the most personal exposure and, in most arrangements, hold the least power.
The fleet. They bought the vehicle and the system, they carry the liability when a collision happens, and they are accountable for the safety of the person driving. Their claim is contractual and it is also genuinely a duty-of-care claim.
The insurer. They are pricing risk they cannot otherwise observe and paying claims they cannot otherwise verify. Their interest is legitimate, and it is the one most likely to expand quietly if nobody sets a boundary.
The public. Nobody in the frame agreed to anything. They were crossing a road. Their claim is the weakest legally and, we would argue, the strongest morally, precisely because they had no opportunity to negotiate.
Why ownership resolves nothing
Assign ownership to any one party and the result is unacceptable.
Give it to the fleet and the driver has no recourse against a system that misreads them and the public has no protection at all. Give it to the driver and incident reconstruction becomes impossible, which removes the exoneration that most often benefits the driver. Give it to the insurer and you have built exactly the surveillance apparatus everyone fears. Give it to the public and nothing functions.
The useful question is not who owns the record. It is which decisions each party gets to make about it.
Rights, allocated by decision
What we have landed on, and what the privacy commitments implement:
- The driver gets access, dispute and escalation. They can see what was recorded about them, challenge a detection, and come to us directly if a deployment appears to be hidden from them. They do not get deletion on demand, because that would destroy the exoneration case.
- The fleet gets operational use, bounded. They see their own events for safety, coaching and claims. They do not get a live view of a person, because the platform has no such feature to give them.
- The insurer gets aggregates and specific claims. Risk by geography, condition and behaviour; the specific incident under a specific claim. Not a general window into a workforce.
- The public gets removal. Their faces and plates are obscured on the device before upload. They are not a party to any of this and the correct treatment of a non-party is to make them unidentifiable rather than to manage their data carefully.
The part we find hardest
The driver’s position is the unresolved one, and we would rather say so than pretend otherwise.
A driver in most fleets did not choose the system, cannot decline it and keep the job, and is subject to consequences based on what it records. Our commitments — access, dispute, escalation, no live view, no audio, no face matching, mandatory disclosure — improve that position materially. They do not make it a free choice, and no commitment we can write will, because the imbalance is in the employment relationship rather than in the software.
What we can do is refuse to make it worse, keep the most sensitive category on the shortest retention, and build a platform that cannot do the things a driver would most reasonably fear. What we cannot do is claim the underlying tension is solved.
Where this lands
The record is not a possession. It is a set of obligations to four parties with different exposure and different power, and the design question is which of them can decide what.
Getting that allocation right is more consequential for this industry than any model architecture, and almost nobody is writing it down.