Consulting Independent advice across RTLS, RFID and IoT — no platform to sell. Book a call →
FOR DPO & PRIVACY

Location data with a purpose limitation you can defend.

DPIA-first locating programmes — what is collected, why, how long, who can see named trails. Vendor-neutral so privacy architecture is not dictated by a reseller.

Purpose before radios

If you cannot state the purpose in one sentence, you are not ready to tag people. Many programmes run on equipment and anonymised counts instead.

See GDPR & RTLS and clinical.

Retention and access

Named location trails need role-based access, retention clocks, and works-council-ready documentation. We design the evidence pack with you — not after go-live.

Processors and sub-processors

Cloud location platforms and OEM tunnels are processors. We map them before architecture lock-in so you are not stuck with a DPIA you cannot finish.

People vs assets — classify early

People-tracking is often high risk under GDPR; asset-only programmes often are not. Hybrid estates need a clear split: which tags identify a person, which identify equipment, and how long each class is retained. We classify before radio selection so you are not stuck finishing a DPIA after architecture lock-in.

DPIA as a design artefact

We treat the DPIA as an input to architecture, not a paperwork afterthought. Purpose, lawful basis, retention clocks, access roles, and processor maps are drafted with you before tags are ordered. Where anonymised counts meet the need, we prefer them — and document when identity is truly required.

Works councils and staff representation are stakeholders from week one on people-adjacent programmes. Surprise “productivity heatmaps” are a design fail.

What to demand from vendors

Data residency options, sub-processor lists, deletion and export on exit, and no permanent OEM tunnels that bypass your access policy. We put those requirements in the SOW so privacy architecture is not dictated by a reseller’s cloud default. See GDPR & RTLS and CISO.

Privacy buying criteria

Buying criteria DPOs need for locating programmes

When location can identify a person — badge, phone or wearable — GDPR and often works-council rules engage. DPO buying criteria:

  • Purpose limitation first — safety, mustering, clinical flow or asset-only; productivity monitoring is a different and harder basis.
  • DPIA before scale — risks, mitigations, retention and review schedule signed with the controller.
  • Lawful basis realism — employee consent is rarely freely given; legitimate interests needs a documented balancing test.
  • Minimisation by architecture — separate tag IDs from HR identity where possible; short raw-event retention; RBAC on queries.
  • Processor transparency — sub-processors, transfer mechanisms and audit rights in the contract.

Vendors ship continuous tracking defaults. SIs enable them for demos. The DPO's job is to force purpose, retention and access into the design — not as a post-hoc policy PDF.

Failure modes

Privacy failure modes in RTLS

  • Staff tracking justified as 'safety' while managers use paths for performance.
  • Indefinite retention of raw coordinates.
  • Broad admin roles in the vendor cloud.
  • Works-council engagement after contract signature in DACH/FR/NL contexts.
  • Asset programme quietly extended to people without a new DPIA.
Questions for vendors

Questions DPOs should ask vendors and programme sponsors

  • What personal data categories exist, and can we run asset-only without identifiable people?
  • Default and configurable retention for raw vs derived location — auto-deletion included?
  • Who can reconstruct an individual's path, and is every query logged?
  • List of processors/sub-processors and international transfers.
  • Will you support our DPIA and works-council pack with accurate technical descriptions?
Independent advice

How TRACIO differs for the DPO

We treat privacy as a design input to locating programmes. Independent of hardware vendors, we help classify people vs assets early, draft DPIA-ready architecture and refuse features that expand purpose without governance. No SKU incentive to maximise tracking.

Competitive framing

Competitive framing: defaults vs lawful locating design

Most RTLS platforms ship with continuous tracking, long retention and broad admin roles — convenient for demos, awkward under GDPR. Vendors will say the product is 'GDPR ready'; SIs will enable whatever makes the pilot pretty. Article 29 WP and supervisory guidance treat systematic employee monitoring as high-risk: expect a DPIA, necessity/proportionality analysis, transparent notice, and works-council involvement where national law requires it.

Consent is rarely a robust basis for employee location. Legitimate interests for safety may work with a balancing test and mitigations; productivity analytics usually does not wear the same clothes. Architecture choices matter more than policy PDFs: separate tag identity from HR identity where feasible, minimise raw coordinate retention (often days, not years), and log privileged path reconstructions.

Classify early: anonymous occupancy and asset-only tags may avoid personal data; badge-on-person programmes do not. Expanding purpose later without a new assessment is a classic compliance failure.

Independent advice

What independent advice changes for privacy

TRACIO helps programme sponsors write purpose, retention and access into the locating design before radios are purchased. Because we do not sell tags or platforms, we are free to recommend asset-only scopes, shorter retention, or on-prem enclaves when that is what the DPIA requires. We also translate technical reality into works-council-ready descriptions so consultation is based on what the system actually does.

Case studies on this site are composite worked examples unless an NDA reference is shown. Named references are available under NDA.

People vs assets — classify early

People-tracking is often high risk under GDPR; asset-only programmes often are not. Hybrid estates need a clear split: which tags identify a person, which identify equipment, and how long each class is retained. We classify before radio selection so you are not stuck finishing a DPIA after architecture lock-in.

DPIA as a design artefact

We treat the DPIA as an input to architecture, not a paperwork afterthought. Purpose, lawful basis, retention clocks, access roles, and processor maps are drafted with you before tags are ordered. Where anonymised counts meet the need, we prefer them — and document when identity is truly required.

Works councils and staff representation are stakeholders from week one on people-adjacent programmes. Surprise “productivity heatmaps” are a design fail.

What to demand from vendors

Data residency options, sub-processor lists, deletion and export on exit, and no permanent OEM tunnels that bypass your access policy. We put those requirements in the SOW so privacy architecture is not dictated by a reseller’s cloud default. See GDPR & RTLS and CISO.

Privacy buying criteria

Buying criteria DPOs need for locating programmes

When location can identify a person — badge, phone or wearable — GDPR and often works-council rules engage. DPO buying criteria:

  • Purpose limitation first — safety, mustering, clinical flow or asset-only; productivity monitoring is a different and harder basis.
  • DPIA before scale — risks, mitigations, retention and review schedule signed with the controller.
  • Lawful basis realism — employee consent is rarely freely given; legitimate interests needs a documented balancing test.
  • Minimisation by architecture — separate tag IDs from HR identity where possible; short raw-event retention; RBAC on queries.
  • Processor transparency — sub-processors, transfer mechanisms and audit rights in the contract.

Vendors ship continuous tracking defaults. SIs enable them for demos. The DPO's job is to force purpose, retention and access into the design — not as a post-hoc policy PDF.

Failure modes

Privacy failure modes in RTLS

  • Staff tracking justified as 'safety' while managers use paths for performance.
  • Indefinite retention of raw coordinates.
  • Broad admin roles in the vendor cloud.
  • Works-council engagement after contract signature in DACH/FR/NL contexts.
  • Asset programme quietly extended to people without a new DPIA.
Questions for vendors

Questions DPOs should ask vendors and programme sponsors

  • What personal data categories exist, and can we run asset-only without identifiable people?
  • Default and configurable retention for raw vs derived location — auto-deletion included?
  • Who can reconstruct an individual's path, and is every query logged?
  • List of processors/sub-processors and international transfers.
  • Will you support our DPIA and works-council pack with accurate technical descriptions?
Independent advice

How TRACIO differs for the DPO

We treat privacy as a design input to locating programmes. Independent of hardware vendors, we help classify people vs assets early, draft DPIA-ready architecture and refuse features that expand purpose without governance. No SKU incentive to maximise tracking.

Competitive framing

Competitive framing: defaults vs lawful locating design

Most RTLS platforms ship with continuous tracking, long retention and broad admin roles — convenient for demos, awkward under GDPR. Vendors will say the product is 'GDPR ready'; SIs will enable whatever makes the pilot pretty. Article 29 WP and supervisory guidance treat systematic employee monitoring as high-risk: expect a DPIA, necessity/proportionality analysis, transparent notice, and works-council involvement where national law requires it.

Consent is rarely a robust basis for employee location. Legitimate interests for safety may work with a balancing test and mitigations; productivity analytics usually does not wear the same clothes. Architecture choices matter more than policy PDFs: separate tag identity from HR identity where feasible, minimise raw coordinate retention (often days, not years), and log privileged path reconstructions.

Classify early: anonymous occupancy and asset-only tags may avoid personal data; badge-on-person programmes do not. Expanding purpose later without a new assessment is a classic compliance failure.

Independent advice

What independent advice changes for privacy

TRACIO helps programme sponsors write purpose, retention and access into the locating design before radios are purchased. Because we do not sell tags or platforms, we are free to recommend asset-only scopes, shorter retention, or on-prem enclaves when that is what the DPIA requires. We also translate technical reality into works-council-ready descriptions so consultation is based on what the system actually does.

FAQ

Frequently asked questions

Is RTLS always high risk under GDPR?

People-tracking often is. Asset-only programmes may not be. We classify before design.

Can we anonymise?

Often yes for occupancy and flow. We document when identity is truly required.

Employee monitoring?

Only with a published purpose, co-determination where required, and no surprise league tables.

Ready to scope it?

Thirty minutes on your decision — and the evidence behind it.

预约 30 分钟范围沟通

Last updated: