GDPR & RTLS — de vraag over het volgen van medewerkers.
RTLS-systemen die een individuele werknemer kunnen identificeren — zelfs indirect — vallen onder de AVG. De implementatie is niet illegaal, maar wordt gereguleerd, en de architectuurkeuzes bepalen of het legaal blijft. Dit is de operator-niveau samenvatting van wat er nodig is.
Waar de AVG van toepassing is, en waar niet
De AVG geldt wanneer locatiegegevens direct of in combinatie met andere gegevens aan een identificeerbare persoon kunnen worden toegeschreven. Anonieme personentelling en geaggregeerde bezetting zijn niet betrokken bij de AVG. Tag-on-badge tracking wel.
Voertuigtracking wordt ingeschakeld wanneer de bestuurder herkenbaar is. Geaggregeerde zone-heatmaps doen dat meestal niet, tenzij het team klein genoeg is om een individu af te leiden.
De juiste drempelvraag is: 'zou een redelijk persoon een functiegebeurtenis kunnen koppelen aan een benoemde werknemer?'
De zes wettelijke grondslagen en die hier van toepassing zijn
Er bestaan zes wettelijke gronden in Artikel 6 — voor het volgen van de locatie van werknemers zijn er slechts drie realistisch: legitieme belangen (met een gedocumenteerde afwegingstoets, de meest voorkomende basis voor veiligheid RTLS),
wettelijke verplichting (specifieke nalevingsregimes) en expliciete toestemming (zelden de juiste basis in een arbeidscontext omdat toestemming niet vrijelijk wordt gegeven).
De meeste veiligheidsgedreven RTLS-implementaties zijn gebaseerd op legitieme belangen met een gedocumenteerde DPIA. We helpen je bij het opstellen van beide.
Bedrijfsraden, vakbonden en de consultatievraag
In Duitsland, Frankrijk, Nederland, Oostenrijk en vele andere EU-rechtsgebieden vereist werknemersmonitoring formeel overleg met de bedrijfsraad (Betriebsrat / Comité Social et Économique / Ondernemingsraad) en vaak een schriftelijke overeenkomst.
Het overslaan van deze stap is de meest voorkomende reden dat RTLS-uitzendingen vastlopen in DACH.
We ontwerpen de implementatiespecificatie met de vragen van de bedrijfsraad ingebouwd — wat wordt verzameld, wat niet, behoud, toegang, transparantie — zodat de consultatie constructief is in plaats van vijandig.
Ontwerpkeuzes die het beeld van de AVG veranderen
Verschillende architectuurkeuzes verminderen de blootstelling aan de AVG wezenlijk: het scheiden van tagidentiteit van de personeelsidentiteit op de platformlaag; configureerbare retentie met automatische verwijdering (meestal 7-30 dagen voor raw positiegebeurtenissen);
rolgebaseerde toegang waarbij supervisors het geaggregeerde zien, niet individueel; en 'alleen alarm'-modi waarbij locatie onzichtbaar is totdat een dwanggebeurtenis plaatsvindt.
Geen van deze is leveranciersspecifiek — het zijn implementatie-ontwerpkeuzes die we in fase 1 (Ontwerp) van de TRACIO Programmamethode.
Lawful basis, DPIA and purpose limitation for location data
Identifiable location of staff or patients is personal data under the GDPR. Legitimate interests (safety, mustering, lone-worker) can work, but only after a documented balancing test; consent is fragile in employment and usually the wrong basis. Special-category data may engage if location reveals health status (e.g. ward assignment patterns).
A DPIA is effectively mandatory for systematic workplace monitoring. It should cover necessity, less-intrusive alternatives (zone events vs continuous trails), retention, access roles, and works-council or staff-representation input. Privacy by design means defaulting to pseudonymous tag IDs, work-hours only, and exclusion of break rooms / toilets by geofence policy — not by pinky promise.
Challenge vendors who ship continuous heatmaps for 'productivity' as a free add-on. That feature often expands purpose beyond the DPIA and becomes the works-council killer. Separate safety alerting from managerial analytics in the product configuration, with different retention clocks.
Works councils, national labour overlays and multi-country rollouts
In Germany, BetrVG §87(1)(6) co-determination routinely gates any system capable of monitoring behaviour or performance; Betriebsrat consultation is on the critical path. Comparable consultation or information duties appear in the Netherlands, France, Italy and Nordic markets. Build 8–16 weeks of social dialogue into the plan when staff tags are in scope.
Cross-border groups need a single architecture with country-specific purpose statements and retention. Hosting in the EU helps, but transfers to US support desks still need SCCs or equivalent. Prefer on-prem or EU-region SaaS with EU-only support for high-sensitivity sites.
Document what supervisors can see (alarms and zone breaches vs full trails), how long raw coordinates survive, and how a data-subject access request is answered from the locating store plus MES/WMS joins.
Vendor claims to pressure-test
Ask whether the platform can run alarm-only mode (store events, not continuous tracks), support automatic purge, export DSAR packages, and disable productivity modules per site. Demand written confirmation that training/demo tenants do not reuse production location data.
'GDPR compliant' badges are not a control. Require a completed DPIA template, residual-risk register, and configuration baseline that your DPO can attach to the record of processing activities.
Retention, DSAR and cross-border support desks
Raw high-frequency coordinates are rarely necessary beyond short operational windows. Keep long-term only what the purpose statement justifies — muster events, incident packages, access breaches — and automate deletion. DSARs must be answerable across RTLS plus MES/WMS/HR joins without a six-week archaeology project.
If US or APAC vendor support can open production tenants, treat that as a transfer. Contractual clauses, access logging and EU-only support tiers are design inputs, not legal footnotes after signature.
How we run GDPR-ready locating programmes
We draft purpose statements, DPIA inputs, role matrices and works-council briefing packs alongside the RF design. Safety-first configurations ship before any productivity analytics. Multi-country rollouts get a core platform with localised retention and notice text rather than eight divergent forks.
Patient vs staff location — different risk profiles
Patient flow engages health-related inferences more readily; staff tracking engages labour law. Separate purpose statements, retentions and role access. Never reuse a staff heatmap product for patient pathway work without a fresh DPIA.
Publish layered notices: what is collected, for which purpose, who sees it, how long, and how to raise concerns. Hidden features enabled by default after a firmware update are a recurring incident pattern — lock configuration baselines.
Veelgestelde vragen
Hebben we een DPIA nodig voor RTLS?
Bijna altijd, ja, waar medewerkers kunnen worden geïdentificeerd. Een DPIA (Data Protection Impact Assessment) documenteert de wettelijke basis, de afwegingstoets, risico's, mitigatiemaatregelen en het beoordelingsschema.
Wij maken een DPIA-sjabloon dat is afgestemd op RTLS tijdens fase 1, ondertekend samen met uw DPO.
Kunnen we het legitiem belang als wettelijke basis gebruiken?
Voor veiligheidsgedreven implementaties meestal wel, met een gedocumenteerde afwegingstest waaruit blijkt dat veiligheidsvoordelen zwaarder wegen dan privacyinbreuk en dat minder invasieve alternatieven niet haalbaar zijn.
Voor productiviteitsmonitoring is het legitieme belang moeilijker te verdedigen; Raadpleeg je DPO op tijd.
Welke retentieperiode is verdedigbaar?
Raw positietelemetrie wordt meestal 7-30 dagen bewaard; Geaggregeerde analyses langer. Alarmgebeurtenissen (dwang, oproepen) werden nog langer uitgevoerd waar het door veiligheidsvoorschriften vereist is.
Het principe is dataminimalisatie: verzamel voor het genoemde doel, bewaar alleen zolang het nodig is.
Hoe gaan we om met consultatie van bedrijfsraadszaken in Duitsland / Frankrijk?
Behandel het als een stage 1-oplevering, niet als een bijzaak. We hebben specificaties opgesteld die klaar zijn voor de bedrijfsraad voor DACH- en Franse inzet, die reikwijdte, toegang, behoud en beoordelingsfrequentie omvatten.
Ga in gesprek met de raad voordat je de SOW ondertekent, niet erna.
Laatst bijgewerkt: