Consulting Independent advice across RTLS, RFID and IoT — no platform to sell. Book a call →
FÜR DPO & DATENSCHUTZ

Standortdaten mit einer Zweckbindung, die Sie verteidigen können.

DPIA-first Ortungsprogramme — was erhoben wird, warum, wie lange, wer benannte Trails sieht. Herstellerneutral, damit Datenschutzarchitektur nicht vom Reseller diktiert wird.

Zweck vor Funk

Wenn Sie den Zweck nicht in einem Satz sagen können, sind Sie nicht bereit, Menschen zu taggen. Viele Programme laufen auf Equipment und anonymisierten Zählungen.

See GDPR & RTLS and clinical.

Aufbewahrung und Zugriff

Benannte Standorttrails brauchen rollenbasierten Zugriff, Retention-Uhren und betriebsratsfähige Dokumentation. Wir designen das Evidence Pack mit Ihnen — nicht nach Go-Live.

Auftragsverarbeiter und Unterauftragsverarbeiter

Cloud-Ortungsplattformen und OEM-Tunnel sind Auftragsverarbeiter. Wir mappen sie vor Architektur-Lock-in, damit Sie nicht mit einer unvollendbaren DPIA stecken.

Fallstudien on this site are composite worked examples unless an NDA reference is shown. Named references are available under NDA.

People vs assets — classify early

People-tracking is often high risk under GDPR; asset-only programmes often are not. Hybrid estates need a clear split: which tags identify a person, which identify equipment, and how long each class is retained. We classify before radio selection so you are not stuck finishing a DPIA after architecture lock-in.

DPIA as a design artefact

We treat the DPIA as an input to architecture, not a paperwork afterthought. Purpose, lawful basis, retention clocks, access roles, and processor maps are drafted with you before tags are ordered. Where anonymised counts meet the need, we prefer them — and document when identity is truly required.

Works councils and staff representation are stakeholders from week one on people-adjacent programmes. Surprise “productivity heatmaps” are a design fail.

What to demand from vendors

Data residency options, sub-processor lists, deletion and export on exit, and no permanent OEM tunnels that bypass your access policy. We put those requirements in the SOW so privacy architecture is not dictated by a reseller’s cloud default. See GDPR & RTLS and CISO.

Privacy buying criteria

Buying criteria DPOs need for locating programmes

When location can identify a person — badge, phone or wearable — GDPR and often works-council rules engage. DPO buying criteria:

  • Purpose limitation first — safety, mustering, clinical flow or asset-only; productivity monitoring is a different and harder basis.
  • DPIA before scale — risks, mitigations, retention and review schedule signed with the controller.
  • Lawful basis realism — employee consent is rarely freely given; legitimate interests needs a documented balancing test.
  • Minimisation by architecture — separate tag IDs from HR identity where possible; short raw-event retention; RBAC on queries.
  • Processor transparency — sub-processors, transfer mechanisms and audit rights in the contract.

Vendors ship continuous tracking defaults. SIs enable them for demos. The DPO's job is to force purpose, retention and access into the design — not as a post-hoc policy PDF.

Failure modes

Privacy failure modes in RTLS

  • Staff tracking justified as 'safety' while managers use paths for performance.
  • Indefinite retention of raw coordinates.
  • Broad admin roles in the vendor cloud.
  • Works-council engagement after contract signature in DACH/FR/NL contexts.
  • Asset programme quietly extended to people without a new DPIA.
Questions for vendors

Questions DPOs should ask vendors and programme sponsors

  • What personal data categories exist, and can we run asset-only without identifiable people?
  • Default and configurable retention for raw vs derived location — auto-deletion included?
  • Who can reconstruct an individual's path, and is every query logged?
  • List of processors/sub-processors and international transfers.
  • Will you support our DPIA and works-council pack with accurate technical descriptions?
Independent advice

How TRACIO differs for the DPO

We treat privacy as a design input to locating programmes. Independent of hardware vendors, we help classify people vs assets early, draft DPIA-ready architecture and refuse features that expand purpose without governance. No SKU incentive to maximise tracking.

Competitive framing

Competitive framing: defaults vs lawful locating design

Most RTLS platforms ship with continuous tracking, long retention and broad admin roles — convenient for demos, awkward under GDPR. Vendors will say the product is 'GDPR ready'; SIs will enable whatever makes the pilot pretty. Article 29 WP and supervisory guidance treat systematic employee monitoring as high-risk: expect a DPIA, necessity/proportionality analysis, transparent notice, and works-council involvement where national law requires it.

Consent is rarely a robust basis for employee location. Legitimate interests for safety may work with a balancing test and mitigations; productivity analytics usually does not wear the same clothes. Architecture choices matter more than policy PDFs: separate tag identity from HR identity where feasible, minimise raw coordinate retention (often days, not years), and log privileged path reconstructions.

Classify early: anonymous occupancy and asset-only tags may avoid personal data; badge-on-person programmes do not. Expanding purpose later without a new assessment is a classic compliance failure.

Independent advice

What independent advice changes for privacy

TRACIO helps programme sponsors write purpose, retention and access into the locating design before radios are purchased. Because we do not sell tags or platforms, we are free to recommend asset-only scopes, shorter retention, or on-prem enclaves when that is what the DPIA requires. We also translate technical reality into works-council-ready descriptions so consultation is based on what the system actually does.

FAQ

Häufig gestellte Fragen

Ist RTLS unter der DSGVO immer hochriskant?

Personen-Tracking oft ja. Nur-Asset-Programme oft nicht. Wir klassifizieren vor dem Design.

Können wir anonymisieren?

Oft ja für Occupancy und Flow. Wir dokumentieren, wann Identität wirklich nötig ist.

Mitarbeiterüberwachung?

Nur mit veröffentlichtem Zweck, Mitbestimmung wo nötig, und ohne Überraschungs-Ranglisten.

Bereit zum Scoping?

Dreißig Minuten zu Ihrer Entscheidung — und den Belegen dahinter.

30-Minuten-Scoping-Gespräch buchen

Zuletzt aktualisiert: