Locatiegegevens met een doelbeperking die u kunt verdedigen.
Localisatieprogramma’s DPIA-first — wat wordt verzameld, waarom, hoe lang, wie genaamde trails ziet. Vendor-neutraal zodat privacy-architectuur niet door een reseller wordt opgelegd.
Doel vóór radio’s
Als u het doel niet in één zin kunt zeggen, bent u niet klaar om mensen te taggen. Veel programma’s draaien op equipment en geanonimiseerde tellingen.
See GDPR & RTLS and clinical.
Retentie en toegang
Genaamde locatietrails vragen rolgebaseerde toegang, retentieklokken en ondernemingsraad-klare documentatie. We ontwerpen het evidence pack met u — niet na go-live.
Verwerkers en subverwerkers
Cloud-locatieplatforms en OEM-tunnels zijn verwerkers. We mappen ze vóór architectuur-lock-in zodat u niet vastzit met een onafmaakbare DPIA.
Gerelateerde lectuur.
Casestudy’s on this site are composite worked examples unless an NDA reference is shown. Named references are available under NDA.
People vs assets — classify early
People-tracking is often high risk under GDPR; asset-only programmes often are not. Hybrid estates need a clear split: which tags identify a person, which identify equipment, and how long each class is retained. We classify before radio selection so you are not stuck finishing a DPIA after architecture lock-in.
DPIA as a design artefact
We treat the DPIA as an input to architecture, not a paperwork afterthought. Purpose, lawful basis, retention clocks, access roles, and processor maps are drafted with you before tags are ordered. Where anonymised counts meet the need, we prefer them — and document when identity is truly required.
Works councils and staff representation are stakeholders from week one on people-adjacent programmes. Surprise “productivity heatmaps” are a design fail.
What to demand from vendors
Data residency options, sub-processor lists, deletion and export on exit, and no permanent OEM tunnels that bypass your access policy. We put those requirements in the SOW so privacy architecture is not dictated by a reseller’s cloud default. See GDPR & RTLS and CISO.
Buying criteria DPOs need for locating programmes
When location can identify a person — badge, phone or wearable — GDPR and often works-council rules engage. DPO buying criteria:
- Purpose limitation first — safety, mustering, clinical flow or asset-only; productivity monitoring is a different and harder basis.
- DPIA before scale — risks, mitigations, retention and review schedule signed with the controller.
- Lawful basis realism — employee consent is rarely freely given; legitimate interests needs a documented balancing test.
- Minimisation by architecture — separate tag IDs from HR identity where possible; short raw-event retention; RBAC on queries.
- Processor transparency — sub-processors, transfer mechanisms and audit rights in the contract.
Vendors ship continuous tracking defaults. SIs enable them for demos. The DPO's job is to force purpose, retention and access into the design — not as a post-hoc policy PDF.
Privacy failure modes in RTLS
- Staff tracking justified as 'safety' while managers use paths for performance.
- Indefinite retention of raw coordinates.
- Broad admin roles in the vendor cloud.
- Works-council engagement after contract signature in DACH/FR/NL contexts.
- Asset programme quietly extended to people without a new DPIA.
Questions DPOs should ask vendors and programme sponsors
- What personal data categories exist, and can we run asset-only without identifiable people?
- Default and configurable retention for raw vs derived location — auto-deletion included?
- Who can reconstruct an individual's path, and is every query logged?
- List of processors/sub-processors and international transfers.
- Will you support our DPIA and works-council pack with accurate technical descriptions?
How TRACIO differs for the DPO
We treat privacy as a design input to locating programmes. Independent of hardware vendors, we help classify people vs assets early, draft DPIA-ready architecture and refuse features that expand purpose without governance. No SKU incentive to maximise tracking.
Competitive framing: defaults vs lawful locating design
Most RTLS platforms ship with continuous tracking, long retention and broad admin roles — convenient for demos, awkward under GDPR. Vendors will say the product is 'GDPR ready'; SIs will enable whatever makes the pilot pretty. Article 29 WP and supervisory guidance treat systematic employee monitoring as high-risk: expect a DPIA, necessity/proportionality analysis, transparent notice, and works-council involvement where national law requires it.
Consent is rarely a robust basis for employee location. Legitimate interests for safety may work with a balancing test and mitigations; productivity analytics usually does not wear the same clothes. Architecture choices matter more than policy PDFs: separate tag identity from HR identity where feasible, minimise raw coordinate retention (often days, not years), and log privileged path reconstructions.
Classify early: anonymous occupancy and asset-only tags may avoid personal data; badge-on-person programmes do not. Expanding purpose later without a new assessment is a classic compliance failure.
What independent advice changes for privacy
TRACIO helps programme sponsors write purpose, retention and access into the locating design before radios are purchased. Because we do not sell tags or platforms, we are free to recommend asset-only scopes, shorter retention, or on-prem enclaves when that is what the DPIA requires. We also translate technical reality into works-council-ready descriptions so consultation is based on what the system actually does.
Veelgestelde vragen
Is RTLS onder de AVG altijd hoog risico?
People-tracking vaak wel. Alleen-assetprogramma’s vaak niet. We classificeren vóór design.
Kunnen we anonimiseren?
Vaak ja voor occupancy en flow. We documenteren wanneer identiteit echt nodig is.
Medewerkersmonitoring?
Alleen met gepubliceerd doel, medezeggenschap waar vereist, en geen verrassingsranglijsten.
Laatst bijgewerkt: