GDPR & RTLS — the employee-tracking question.
RTLS that can identify an employee — even indirectly — is personal data under GDPR. Lawful basis, DPIA and retention come before anchor plans.
Where GDPR applies, and where it doesn't
GDPR engages whenever location data can be attributed to an identifiable person, directly or by combination with other data. Anonymous people-counting and aggregated occupancy do not engage GDPR. Tag-on-badge tracking does.
Vehicle tracking engages when the driver is identifiable. Aggregated zone heat-maps usually do not, unless the team is small enough that an individual can be inferred. The right threshold question is: ‘could a reasonable person link a position event back to a named worker?’
The six lawful bases and which apply here
Six lawful bases exist in Article 6 — for employee location tracking, only three are realistic: legitimate interests (with a documented balancing test, the most common basis for safety RTLS),
legal obligation (specific compliance regimes), and explicit consent (rarely the right basis in an employment context because consent is not freely given).
Most safety-driven RTLS deployments rely on legitimate interests with a documented DPIA. We draft both.
Works councils, unions and the consultation question
In Germany, France, the Netherlands, Austria and many other EU jurisdictions, employee monitoring requires formal works-council (Betriebsrat / Comité Social et Économique / Ondernemingsraad) consultation and often a written agreement.
Skipping this step is the single most common reason RTLS deployments stall in DACH.
We design the deployment specification with the works-council questions built in — what's collected, what's not, retention, access, transparency — so the consultation is constructive rather than adversarial.
Design choices that change the GDPR picture
Several architecture choices materially reduce GDPR exposure: separating tag identity from staff identity at the platform layer; configurable retention with auto-deletion (typically 7-30 days for raw position events);
role-based access where supervisors see aggregate, not individual; and ‘alarm-only’ modes where location is invisible until a duress event fires.
None of these are vendor-specific — they are deployment-design choices we bake into stage 1 (Design) of the TRACIO Programme Method.
Lawful basis, DPIA and purpose limitation for location data
Identifiable location of staff or patients is personal data under the GDPR. Legitimate interests (safety, mustering, lone-worker) can work, but only after a documented balancing test; consent is fragile in employment and usually the wrong basis. Special-category data may engage if location reveals health status (e.g. ward assignment patterns).
A DPIA is effectively mandatory for systematic workplace monitoring. It should cover necessity, less-intrusive alternatives (zone events vs continuous trails), retention, access roles, and works-council or staff-representation input. Privacy by design means defaulting to pseudonymous tag IDs, work-hours only, and exclusion of break rooms / toilets by geofence policy — not by pinky promise.
Challenge vendors who ship continuous heatmaps for 'productivity' as a free add-on. That feature often expands purpose beyond the DPIA and becomes the works-council killer. Separate safety alerting from managerial analytics in the product configuration, with different retention clocks.
Works councils, national labour overlays and multi-country rollouts
In Germany, BetrVG §87(1)(6) co-determination routinely gates any system capable of monitoring behaviour or performance; Betriebsrat consultation is on the critical path. Comparable consultation or information duties appear in the Netherlands, France, Italy and Nordic markets. Build 8–16 weeks of social dialogue into the plan when staff tags are in scope.
Cross-border groups need a single architecture with country-specific purpose statements and retention. Hosting in the EU helps, but transfers to US support desks still need SCCs or equivalent. Prefer on-prem or EU-region SaaS with EU-only support for high-sensitivity sites.
Document what supervisors can see (alarms and zone breaches vs full trails), how long raw coordinates survive, and how a data-subject access request is answered from the locating store plus MES/WMS joins.
Vendor claims to pressure-test
Ask whether the platform can run alarm-only mode (store events, not continuous tracks), support automatic purge, export DSAR packages, and disable productivity modules per site. Demand written confirmation that training/demo tenants do not reuse production location data.
'GDPR compliant' badges are not a control. Require a completed DPIA template, residual-risk register, and configuration baseline that your DPO can attach to the record of processing activities.
Retention, DSAR and cross-border support desks
Raw high-frequency coordinates are rarely necessary beyond short operational windows. Keep long-term only what the purpose statement justifies — muster events, incident packages, access breaches — and automate deletion. DSARs must be answerable across RTLS plus MES/WMS/HR joins without a six-week archaeology project.
If US or APAC vendor support can open production tenants, treat that as a transfer. Contractual clauses, access logging and EU-only support tiers are design inputs, not legal footnotes after signature.
How we run GDPR-ready locating programmes
We draft purpose statements, DPIA inputs, role matrices and works-council briefing packs alongside the RF design. Safety-first configurations ship before any productivity analytics. Multi-country rollouts get a core platform with localised retention and notice text rather than eight divergent forks.
Patient vs staff location — different risk profiles
Patient flow engages health-related inferences more readily; staff tracking engages labour law. Separate purpose statements, retentions and role access. Never reuse a staff heatmap product for patient pathway work without a fresh DPIA.
Publish layered notices: what is collected, for which purpose, who sees it, how long, and how to raise concerns. Hidden features enabled by default after a firmware update are a recurring incident pattern — lock configuration baselines.
Lawful basis, DPIA and purpose limitation for location data
Identifiable location of staff or patients is personal data under the GDPR. Legitimate interests (safety, mustering, lone-worker) can work, but only after a documented balancing test; consent is fragile in employment and usually the wrong basis. Special-category data may engage if location reveals health status (e.g. ward assignment patterns).
A DPIA is effectively mandatory for systematic workplace monitoring. It should cover necessity, less-intrusive alternatives (zone events vs continuous trails), retention, access roles, and works-council or staff-representation input. Privacy by design means defaulting to pseudonymous tag IDs, work-hours only, and exclusion of break rooms / toilets by geofence policy — not by pinky promise.
Challenge vendors who ship continuous heatmaps for 'productivity' as a free add-on. That feature often expands purpose beyond the DPIA and becomes the works-council killer. Separate safety alerting from managerial analytics in the product configuration, with different retention clocks.
Works councils, national labour overlays and multi-country rollouts
In Germany, BetrVG §87(1)(6) co-determination routinely gates any system capable of monitoring behaviour or performance; Betriebsrat consultation is on the critical path. Comparable consultation or information duties appear in the Netherlands, France, Italy and Nordic markets. Build 8–16 weeks of social dialogue into the plan when staff tags are in scope.
Cross-border groups need a single architecture with country-specific purpose statements and retention. Hosting in the EU helps, but transfers to US support desks still need SCCs or equivalent. Prefer on-prem or EU-region SaaS with EU-only support for high-sensitivity sites.
Document what supervisors can see (alarms and zone breaches vs full trails), how long raw coordinates survive, and how a data-subject access request is answered from the locating store plus MES/WMS joins.
Vendor claims to pressure-test
Ask whether the platform can run alarm-only mode (store events, not continuous tracks), support automatic purge, export DSAR packages, and disable productivity modules per site. Demand written confirmation that training/demo tenants do not reuse production location data.
'GDPR compliant' badges are not a control. Require a completed DPIA template, residual-risk register, and configuration baseline that your DPO can attach to the record of processing activities.
Retention, DSAR and cross-border support desks
Raw high-frequency coordinates are rarely necessary beyond short operational windows. Keep long-term only what the purpose statement justifies — muster events, incident packages, access breaches — and automate deletion. DSARs must be answerable across RTLS plus MES/WMS/HR joins without a six-week archaeology project.
If US or APAC vendor support can open production tenants, treat that as a transfer. Contractual clauses, access logging and EU-only support tiers are design inputs, not legal footnotes after signature.
How we run GDPR-ready locating programmes
We draft purpose statements, DPIA inputs, role matrices and works-council briefing packs alongside the RF design. Safety-first configurations ship before any productivity analytics. Multi-country rollouts get a core platform with localised retention and notice text rather than eight divergent forks.
Patient vs staff location — different risk profiles
Patient flow engages health-related inferences more readily; staff tracking engages labour law. Separate purpose statements, retentions and role access. Never reuse a staff heatmap product for patient pathway work without a fresh DPIA.
Publish layered notices: what is collected, for which purpose, who sees it, how long, and how to raise concerns. Hidden features enabled by default after a firmware update are a recurring incident pattern — lock configuration baselines.
Frequently asked questions
Do we need a DPIA for RTLS?
Almost always, yes, where employees can be identified. A DPIA (Data Protection Impact Assessment) documents the lawful basis, balancing test, risks, mitigations and review schedule. We produce a DPIA template tailored to RTLS during stage 1, signed off jointly with your DPO.
Can we use legitimate interest as the lawful basis?
For safety-driven deployments, usually yes, with a documented balancing test showing safety benefits outweigh privacy intrusion and that less-invasive alternatives are not viable. For productivity monitoring, legitimate interest is harder to defend; consult your DPO early.
What retention period is defensible?
Raw position telemetry is typically retained 7-30 days; aggregated analytics longer. Alarm events (duress, mustering) longer still where required by safety regulation. The principle is data minimisation: collect for the named purpose, retain only as long as necessary.
How do we handle works-council consultation in Germany / France?
Treat it as a stage 1 deliverable, not an afterthought. We have produced works-council-ready specifications for DACH and French deployments that include scope, access, retention and review cadence. Engage the council before signing the SOW, not after.
Last updated: