RTLS, RFID & IoT compliance — by the regulation, not by the marketing claim.
Every RTLS programme touches one or more of these regulations. Each page below sets out what the regulation actually requires, where the deployment must change, and the architecture decisions that survive an audit.
One page per regulation. No marketing.
GDPR & RTLS
Employee tracking, lawful basis, works council, retention
21 CFR Part 11
Pharma data integrity, ALCOA+, IQ/OQ/PQ
HIPAA & RTLS
PHI scope, BAAs, minimum necessary, breach response
IEC 62443
OT cybersecurity, Purdue model, zones and conduits
IATF 16949
Automotive traceability, JIS verification, OEM CSRs
AS9100
Aerospace tool control, FOD prevention, NADCAP
ATEX / IECEx
Hazardous-area zones, intrinsically-safe hardware
DSCSA & GS1
Pharma serialisation, EPCIS, aggregation hierarchies
Frequently asked questions
Does my deployment touch all of these?
Few do. Most touch one or two — typically GDPR (any EU deployment), plus one industry-specific regulation (HIPAA for healthcare, IATF 16949 for automotive, etc.). We scope which apply to your specific deployment at gate 1.
Are these compliance pages legal advice?
No. They are operator-level summaries of how compliance affects RTLS architecture. Always engage your DPO, QA function, security and legal teams for formal compliance sign-off.
Do compliance requirements rule out certain vendors?
Sometimes yes. HIPAA needs BAA-willing vendors. ATEX/IECEx needs hardware-certified vendors. 21 CFR Part 11 needs validation-capable vendors. We map this in stage 1 vendor scrutiny.
How does TRACIO handle compliance scope?
Compliance scoping is part of our stage 1 (Design) deliverable — we map your regulatory environment to the architecture so deployment-time decisions are made with compliance built in, not retro-fitted.
Last updated: