A lone worker presses an SOS button in a plant room. The control room needs to know who called, where they are and which responder can reach them. That is a legitimate use of location data, but it does not give an employer a blank cheque to track every movement indefinitely. This RTLS privacy guide answers the central question: how can UK organisations use real-time location systems to protect staff and improve operations without creating unnecessary employee surveillance? The answer is to design every signal, location zone and data-retention rule around a defined operational purpose.
An RTLS, or real-time location system, uses devices and infrastructure to determine the location of people or assets. Depending on the environment, it may use ultra-wideband (UWB) for precise indoor positioning, Bluetooth Low Energy (BLE) for zone-level presence, or GPS for outdoor and vehicle-based location. Privacy depends less on the acronym than on what the system records, how precise it is, who can see it and what decisions follow.
What should an RTLS privacy policy cover?
A useful policy should explain the operational problem being solved in plain language. “To improve efficiency” is rarely specific enough. “To send the nearest trained responder to an SOS alert in a defined high-risk area” is much clearer. Staff should be able to understand when their location is processed, what device or signal is involved, and how the information helps them or the service.
For each use case, document five points: the purpose, the people and assets in scope, the location precision needed, the action enabled, and the retention period. This forces a practical distinction between a system that confirms a guard reached a checkpoint and one that continuously reconstructs their whole shift.
A BLE badge detecting entry into a service zone may be sufficient for proof of attendance at a location. A fall alert inside a large industrial facility may require more accurate indoor positioning, potentially using UWB infrastructure and a wearable badge. A vehicle travelling between sites may need GPS, but GPS is not designed to tell a manager which room somebody is in. Selecting more precision than the workflow needs creates more privacy exposure, cost and infrastructure to manage.
Start with purpose, not tracking capability
The best RTLS deployments begin with a frontline decision that is currently slow, uncertain or unsafe. The technology is then configured to provide only the physical-world data needed for that decision.
Consider a facilities team completing statutory checks across a hospital estate. A tagged device, badge or fixed checkpoint can confirm that an authorised worker attended the relevant area at the required time. The system can trigger a missed-check workflow or create a time-stamped proof of completion. It does not necessarily need second-by-second movement data between checkpoints.
The same principle applies to task allocation. If a cleaning supervisor needs to assign an urgent spill response, a system may use BLE or UWB presence data to identify available operatives in the relevant zone. The data supports a live decision. It should not automatically become a performance score based on walking routes or minutes spent in every corridor.
For each proposed workflow, ask:
- What safety, service or operational decision will this location data enable?
- Is the system locating a person, an asset, a device or a zone?
- What is the minimum useful precision: site, building, floor, room or sub-metre position?
- Must data be real time, historical, or both?
- What happens when a device is not worn, a signal is unavailable or the location is uncertain?
These questions also improve system design. A location reading is not the same as proof that work was completed. A badge may show a worker was at a plant room door, while a digital checklist, scan or sensor event may be needed to verify the task itself.
Explain what the system knows and how it knows it
Trust weakens when staff hear that they are “being tracked” but cannot see the boundaries. Be explicit about the source of the data and its limitations.
A wearable badge may transmit a BLE signal detected by gateways, showing that a person is in a defined area. A UWB badge and installed anchors can support more precise indoor coordinates where the use case justifies it, such as directing emergency responders to a worker who has raised an alert. GPS uses satellite signals and is usually most suitable outdoors, where it can support site arrival, geofenced rules or vehicle-related workflows.
Each approach has trade-offs. UWB can offer high indoor precision but requires appropriate infrastructure planning. BLE can be effective for presence and zone-based workflows, though it is not a substitute for precision locating when room-level certainty is essential. GPS supports broad outdoor location but can be unreliable inside buildings. Mixed indoor and outdoor estates may require more than one technology, with clear handover rules between them.
Do not describe location data as more certain than it is. Interfaces should make uncertainty understandable, particularly where an alert could lead to an emergency response or a management conversation. A last-known location, a zone event and a precise coordinate are different data points and should be treated differently.
Build privacy into the deployment design
In UK workplaces, employee location data is personal data when it relates to an identifiable person. Organisations should establish an appropriate data protection basis, provide clear information to workers and involve privacy, HR, IT, security and health and safety stakeholders early. Where processing is likely to create a high risk to individuals, a data protection impact assessment may be required. The ICO’s guidance should inform that assessment and the resulting controls.
Consultation matters as much as paperwork. Explain the intended safety or operational benefit before devices are issued, invite practical feedback from the people who will wear them, and test whether policies reflect the reality of a shift. For example, an SOS badge may need to remain active in isolated work areas, but not during breaks in a designated welfare space if no safety purpose exists.
Access should be role-based. A control-room operator responding to a live alert may need to see a current location. A supervisor reviewing whether a scheduled task was completed may need an event record for that task. Neither automatically needs unrestricted access to every employee’s live or historical movement data.
Retention should also match purpose. Live response data may have a short operational life, while an incident record may need to be kept for a defined investigation or safety process. Avoid keeping detailed movement histories simply because storage is available. Set deletion or aggregation rules, test them and assign ownership for reviewing exceptions.
Avoid using RTLS as a shortcut to performance management
Location data can support fairer operational conversations when used carefully. It can show that a worker was delayed by an access issue, assigned to an emergency task or unable to reach an area because a route was closed. Used without context, it can produce misleading conclusions.
Before location information is used in a disciplinary, capability or payroll-related process, establish whether the data is sufficiently accurate for that purpose, whether the worker understands the rule being applied, and whether there is corroborating evidence. A missed geofence event may reflect a flat battery, a device left in a locker, a coverage gap or a changed assignment. Technical data should inform judgement, not replace it.
This is particularly relevant for clocking. A geofenced arrival event can help verify that a worker reached the right site, but the organisation should define the permitted clocking window, exceptions process and method for correcting records. If attendance is the primary need, a zone-based confirmation may be more proportionate than continuous tracking throughout the shift.
A practical RTLS privacy checklist
Before go-live, confirm that every workflow has a named owner and a documented reason for processing location data. Map where gateways, anchors, tags, badges, buttons and sensors collect or transmit information. Test coverage in real conditions, including lifts, basements, outdoor yards and transition points between sites.
Then make the operating rules visible: who can view live locations, who can export historical data, how alerts are escalated, how staff request access or correction, and how device failures are handled. Train managers not only on the dashboard but on the limits of the data and the need for context.
Finally, review the deployment after it has been used in practice. Are teams relying on data that is more detailed than needed? Are emergency workflows working as intended? Have new use cases appeared without privacy review? Location technology should be governed as an evolving operational system, not treated as a one-off hardware installation.
FAQ
Is employee consent required for RTLS?
Consent is not always the appropriate basis in an employment relationship because of the imbalance of power between employer and worker. Organisations should take advice on the correct lawful basis for their circumstances, communicate processing clearly and avoid presenting a choice as voluntary when it is not.
Can RTLS be used for lone-worker safety?
Yes, where the design matches the risk. A wearable badge or button can initiate an SOS alert, while appropriate indoor or outdoor location technology helps responders identify where assistance is needed. The required precision depends on the site layout and response plan.
How long should RTLS data be kept?
There is no universal period. Keep it only for as long as the defined purpose requires. Live positioning, task evidence and incident investigation records may each justify different retention periods.
Is GPS enough for workplace location tracking?
Usually not for indoor workflows. GPS is generally suited to outdoor location and broad geofences. Indoor safety, room-level task allocation or asset finding may require BLE, UWB or another indoor positioning approach.
A privacy-respecting RTLS programme makes location data useful at the moment work needs to happen, then limits its reach once that purpose has passed. That is how organisations can protect staff, coordinate complex operations and retain the confidence of the people carrying the devices.