Datos de localización con una limitación de finalidad que pueda defender.
Programas de localización con EIPD primero — qué se recoge, por qué, cuánto tiempo, quién ve trazas nominativas. Neutral para que la arquitectura de privacidad no la dicte un revendedor.
Finalidad antes que las radios
Si no puede enunciar la finalidad en una frase, no está listo para etiquetar personas. Muchos programas operan con equipos y conteos anonimizados.
See GDPR & RTLS and clinical.
Retención y acceso
Las trazas nominativas requieren acceso por roles, relojes de retención y documentación lista para el comité. Diseñamos el pack de evidencias con usted — no después del go-live.
Encargados y subencargados
Las plataformas cloud de localización y túneles OEM son encargados. Los mapeamos antes del lock-in de arquitectura para no quedar con una EIPD imposible de terminar.
Lecturas relacionadas.
Casos de estudio on this site are composite worked examples unless an NDA reference is shown. Named references are available under NDA.
People vs assets — classify early
People-tracking is often high risk under GDPR; asset-only programmes often are not. Hybrid estates need a clear split: which tags identify a person, which identify equipment, and how long each class is retained. We classify before radio selection so you are not stuck finishing a DPIA after architecture lock-in.
DPIA as a design artefact
We treat the DPIA as an input to architecture, not a paperwork afterthought. Purpose, lawful basis, retention clocks, access roles, and processor maps are drafted with you before tags are ordered. Where anonymised counts meet the need, we prefer them — and document when identity is truly required.
Works councils and staff representation are stakeholders from week one on people-adjacent programmes. Surprise “productivity heatmaps” are a design fail.
What to demand from vendors
Data residency options, sub-processor lists, deletion and export on exit, and no permanent OEM tunnels that bypass your access policy. We put those requirements in the SOW so privacy architecture is not dictated by a reseller’s cloud default. See GDPR & RTLS and CISO.
Buying criteria DPOs need for locating programmes
When location can identify a person — badge, phone or wearable — GDPR and often works-council rules engage. DPO buying criteria:
- Purpose limitation first — safety, mustering, clinical flow or asset-only; productivity monitoring is a different and harder basis.
- DPIA before scale — risks, mitigations, retention and review schedule signed with the controller.
- Lawful basis realism — employee consent is rarely freely given; legitimate interests needs a documented balancing test.
- Minimisation by architecture — separate tag IDs from HR identity where possible; short raw-event retention; RBAC on queries.
- Processor transparency — sub-processors, transfer mechanisms and audit rights in the contract.
Vendors ship continuous tracking defaults. SIs enable them for demos. The DPO's job is to force purpose, retention and access into the design — not as a post-hoc policy PDF.
Privacy failure modes in RTLS
- Staff tracking justified as 'safety' while managers use paths for performance.
- Indefinite retention of raw coordinates.
- Broad admin roles in the vendor cloud.
- Works-council engagement after contract signature in DACH/FR/NL contexts.
- Asset programme quietly extended to people without a new DPIA.
Questions DPOs should ask vendors and programme sponsors
- What personal data categories exist, and can we run asset-only without identifiable people?
- Default and configurable retention for raw vs derived location — auto-deletion included?
- Who can reconstruct an individual's path, and is every query logged?
- List of processors/sub-processors and international transfers.
- Will you support our DPIA and works-council pack with accurate technical descriptions?
How TRACIO differs for the DPO
We treat privacy as a design input to locating programmes. Independent of hardware vendors, we help classify people vs assets early, draft DPIA-ready architecture and refuse features that expand purpose without governance. No SKU incentive to maximise tracking.
Competitive framing: defaults vs lawful locating design
Most RTLS platforms ship with continuous tracking, long retention and broad admin roles — convenient for demos, awkward under GDPR. Vendors will say the product is 'GDPR ready'; SIs will enable whatever makes the pilot pretty. Article 29 WP and supervisory guidance treat systematic employee monitoring as high-risk: expect a DPIA, necessity/proportionality analysis, transparent notice, and works-council involvement where national law requires it.
Consent is rarely a robust basis for employee location. Legitimate interests for safety may work with a balancing test and mitigations; productivity analytics usually does not wear the same clothes. Architecture choices matter more than policy PDFs: separate tag identity from HR identity where feasible, minimise raw coordinate retention (often days, not years), and log privileged path reconstructions.
Classify early: anonymous occupancy and asset-only tags may avoid personal data; badge-on-person programmes do not. Expanding purpose later without a new assessment is a classic compliance failure.
What independent advice changes for privacy
TRACIO helps programme sponsors write purpose, retention and access into the locating design before radios are purchased. Because we do not sell tags or platforms, we are free to recommend asset-only scopes, shorter retention, or on-prem enclaves when that is what the DPIA requires. We also translate technical reality into works-council-ready descriptions so consultation is based on what the system actually does.
Preguntas frecuentes
¿El RTLS es siempre de alto riesgo bajo el RGPD?
El tracking de personas a menudo sí. Programas solo de activos a menudo no. Clasificamos antes del diseño.
¿Podemos anonimizar?
A menudo sí para ocupación y flujo. Documentamos cuándo la identidad es realmente necesaria.
¿Monitorización de empleados?
Solo con finalidad publicada, codecisión donde proceda, y sin ligas sorpresa.
Última actualización: