Compliance 11 min read

POPIA and location tracking: what the Act actually requires.

Before a hospital, clinic or retirement village tracks where its people are, four questions have to be answered. The Act answers all four — and one of them surprises most employers.

By Frank Guo · Technology & Product Leadership, addanode

TL;DR — POPIA names "location information" in its own definition of personal information, so a location system processes personal information from day one. For patients and residents in a health setting the information also touches health, a special category that is prohibited by default — but section 32 expressly permits healthcare institutions and facilities to process it where necessary for treatment and care or for the administration of the institution, provided a confidentiality obligation attaches. For staff, the usual basis is legitimate interests or a legal obligation — and here is the part employers miss: where processing rests on legitimate interests, a data subject may object, and once they do the Act says processing may no longer continue. That single provision is why the design decisions — room-level not centimetre-level, weeks not years of retention, a narrow stated purpose — matter more than the technology you buy.

Why this is a POPIA question at all

People sometimes assume that a badge which reports which ward someone is in is operational data rather than personal data. The Act removes the argument. Section 1 defines personal information as information relating to an identifiable living person, and the list of examples explicitly includes "any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person".

So the threshold question is settled before you start. What remains is the set of questions POPIA always asks: on what basis are you processing, for what purpose, for how long, with what safeguards, and have you told the people concerned. The rest of this article works through them for the two populations a health or care facility deals with — because the answers are genuinely different, and conflating them is the most common mistake.

Patients and residents: the health category, and the exception that matters

Section 26 prohibits processing "special personal information", and health is on that list alongside race, religion, trade union membership, political persuasion, sex life and biometric information. Left there, a hospital could not operate. Section 32 provides the way through, and it is worth reading closely, because its wording is more useful than most buyers expect. The prohibition does not apply to processing by "medical professionals, healthcare institutions or facilities or social services, if such processing is necessary for the proper treatment and care of the data subject, or for the administration of the institution or professional practice concerned".

That second limb — administration of the institution — is the one that covers a great deal of what a location system does. Knowing that a call was answered, that a resident is inside the building, that an infusion pump is on the third floor: these are administration of the institution, and the Act contemplates them.

Two conditions ride along with it. Section 32(2) says the information may only be processed by responsible parties subject to an obligation of confidentiality — by virtue of office, employment, profession or legal provision, or by written agreement. Section 32(3) adds that a responsible party permitted to process this information who is not already under a professional confidentiality obligation must nonetheless treat it as confidential. In practice this means the confidentiality obligation has to reach everyone who can see the screen, including administrative staff, contractors and any supplier with support access — and that it should be in writing.

Staff: the provision most employers have not read

Tracking employees is not a special-category problem — a nurse's position in a corridor is not health information about the nurse — so it falls under the general grounds in section 11(1). Facilities usually rely on one of three:

  • Section 11(1)(c) — processing complies with an obligation imposed by law. The Occupational Health and Safety Act places a general duty on employers to provide a working environment that is safe and without risk to health as far as is reasonably practicable; a lone-worker duress system is a direct response to that duty.
  • Section 11(1)(f) — processing is necessary for pursuing the legitimate interests of the responsible party. Response-time evidence, staff safety and incident investigation sit here.
  • Section 11(1)(a) — consent. Attractive-looking, and usually the weakest option in an employment relationship, for the reason below.

Now the provision that changes system design. Section 11(3) says a data subject may object, at any time, to processing carried out on the grounds in subsection (1)(d) to (f) — which includes legitimate interests — on reasonable grounds relating to their particular situation, unless legislation provides for the processing. And section 11(4) is blunt about what follows: "If a data subject has objected to the processing of personal information in terms of subsection (3), the responsible party may no longer process the personal information."

Consent is not the escape route either: section 11(2)(b) allows a data subject to withdraw consent at any time. An employer who builds a safety system on consent has built it on something each employee can switch off, and in an employment relationship the freeness of that consent is questionable from the start.

The practical consequence is not that staff tracking is impossible. It is that the narrower and more clearly safety-directed your purpose, the more robust your position — because an objection is assessed on reasonable grounds relating to a particular situation, and "this system exists so that someone comes when I press the button at 02:00" is a very different proposition to answer than "this system exists so management can see where everyone is". Facilities that introduce location as a productivity surveillance tool invite objections they will struggle to resist. Facilities that introduce it as a duress and response-time system, and can show the design reflects exactly that, are in a much stronger place.

Two subjects, two different halves of the Act Tracking a patient and tracking a nurse are not the same legal question. The patient sits in the special-information regime with an express route through it for administration of the institution; the employee sits in the general grounds, where the provision that changes the engineering is the right to object and the requirement that processing then stops. Patients and residents Staff Which part of the Act applies Section 26 prohibits special personal information, and health is on that list Section 11(1) general grounds — a nurse's position in a corridor is not health information about the nurse What makes the processing lawful Section 32: necessary for treatment and care, or for administration of the institution Usually a legal obligation under 11(1)(c), or legitimate interests under 11(1)(f) The condition that rides along with it Confidentiality under 32(2) and 32(3), reaching everyone who can see the screen Section 11(3): the subject may object at any time, and 11(4) says processing must then stop Where consent sits Not the ground being relied on here Withdrawable at any time under 11(2)(b), and questionable in an employment relationship from the start What that does to the system design Purpose written as administration of the institution, and the confidentiality obligation in writing The narrower and more clearly safety-directed the purpose, the more robust the position against an objection
Two subjects, two different halves of the Act Special information with a route through it, against general grounds with a right to object. Which part of the Act applies Patients Section 26 prohibits special personal information, and health is on that list Staff Section 11(1) general grounds — a nurse's position in a corridor is not health information about the nurse What makes the processing lawful Patients Section 32: necessary for treatment and care, or for administration of the institution Staff Usually a legal obligation under 11(1)(c), or legitimate interests under 11(1)(f) The condition that rides along with it Patients Confidentiality under 32(2) and 32(3), reaching everyone who can see the screen Staff Section 11(3): the subject may object at any time, and 11(4) says processing must then stop Where consent sits Patients Not the ground being relied on here Staff Withdrawable at any time under 11(2)(b), and questionable in an employment relationship from the start What that does to the system design Patients Purpose written as administration of the institution, and the confidentiality obligation in writing Staff The narrower and more clearly safety-directed the purpose, the more robust the position against an objection
The two subjects dealt with above, side by side. The provision that changes the engineering is in the staff column — a right to object, with processing that must then stop, which is why a narrow safety-directed purpose is worth more than a broad one.

The four design decisions that carry the compliance

POPIA requirement What it means here The design decision
Minimality — processing must be adequate, relevant and not excessive for the purposeCollect the resolution the purpose needs, not the resolution the hardware can produceRoom and door level, not centimetre level. "Attended room 12 at 02:14" answers the question; a continuous centimetre trace does not improve the answer and enlarges the exposure
Purpose specification — collected for a specific, explicitly defined and lawful purposeThe purpose has to be written down before go-live, not reverse-engineered afterwardsName the purposes narrowly — duress response, call response times, resident egress safety, equipment location — and configure reports to those, not to free-form staff queries
Section 14 — records must not be retained longer than necessary for the purposeRaw position history is the risky asset; aggregate response statistics are notShort retention on raw traces (weeks), longer on the aggregate measures you actually report. Incidents under investigation are preserved on purpose, not by default
Section 19 — secure integrity and confidentiality by appropriate technical and organisational measuresWhere the data lives and who can reach it is part of the compliance positionOn-premises processing, role-based access so ward staff see their ward, audit logging of who ran which report, and written confidentiality terms for any supplier with support access

Telling people: section 18 is a checklist, so use it as one

Section 18 requires the responsible party to take reasonably practicable steps to ensure the data subject is aware of what is being collected, who is collecting it, the purpose, whether supply is voluntary or mandatory and the consequences of refusing, any law authorising the collection, whether it will be transferred to a third country, and — the items most notices omit — the recipients, the rights of access and rectification, the existence of the right to object under section 11(3), and the right to lodge a complaint with the Information Regulator together with its contact details.

For staff this belongs in a written notice issued before the system goes live, not buried in an employment contract annexure. For residents and their families it belongs in the admission pack and in a conversation, because the people best placed to raise an objection on a resident's behalf are usually relatives. Facilities that do this well find it defuses the issue; facilities that install first and explain later create the objection they were hoping to avoid.

Residents in a retirement village: privacy is also their statutory right

POPIA is not the only instrument in play. The Older Persons Act gives an older person residing in a residential facility a set of rights in addition to those in the Bill of Rights, and privacy is expressly among them. A wander-management or resident-safety system therefore has to be justified against a named statutory right, not merely against a general expectation.

That is a workable standard, not a prohibition — a system that raises an alarm when a resident with dementia leaves the building through an external door is protecting that resident, and it can be configured to do only that, rather than logging every movement inside their own home. The distinction between monitoring an exit and monitoring a person is the whole argument, and it is an engineering setting as much as a policy one. We work through it in the nurse call and staff safety design and in our wander management guide.

A short pre-deployment checklist

  • Write the purpose down, narrowly, before procurement — it governs everything downstream.
  • Decide the lawful basis separately for staff and for patients or residents, and record the reasoning.
  • Set resolution to the minimum the purpose needs; if room-level answers it, do not collect finer.
  • Set retention per data type, with a shorter period for raw position history than for aggregate reports.
  • Put the confidentiality obligation in writing for everyone who can see the data, suppliers included.
  • Issue a section 18 notice that actually contains the right to object and the Regulator's details.
  • Define how an objection will be handled operationally — before the first one arrives.
  • Restrict reporting to the named purposes; no free-form "where was this person" queries.
  • Log access to the system and review the log.
  • Keep the processing on premises unless there is a reason not to, and if there is, address section 72 on transborder flows properly.

This article explains what the legislation says and how it shapes system design. It is not legal advice, and your Information Officer or attorney should sign off the assessment for your facility.

FAQ

POPIA and location tracking — common questions

What are the POPIA compliance requirements for a location system?

POPIA compliance for a location system comes down to six things you must be able to show. A lawful basis, chosen separately for staff and for patients or residents and recorded with its reasoning. A specific, explicitly defined purpose, written before procurement rather than after go-live. Minimality — the resolution and the data collected must be adequate, relevant and not excessive for that purpose. A retention period per data type under section 14. Security safeguards under section 19, covering where the data lives and who can reach it. And notification under section 18, which has a specific list of contents including the right to object and the Information Regulator's details. Everything else in this article is an elaboration of one of those six.

Is it legal to track your employees in South Africa?

Yes, if you do it on a proper basis and within limits — POPIA does not prohibit it, but it constrains it in ways most employers have not read. You need a lawful ground under section 11(1); for a safety system that is usually compliance with an obligation imposed by law, which is where the employer's general duty under section 8 of the Occupational Health and Safety Act sits, or the legitimate interests of the responsible party. Consent is a weak choice in an employment relationship and can be withdrawn at any time under section 11(2)(b). The provision that changes things is section 11(3): an employee may object on reasonable grounds relating to their particular situation, and section 11(4) then says the responsible party may no longer process. A narrow, safety-directed purpose is what makes that objection answerable.

Is location data personal information under POPIA?

Yes, explicitly. Section 1 of the Act defines personal information as information relating to an identifiable living person and lists examples, among them "location information". There is no threshold argument to have: as soon as a position can be tied to an identified person — a named badge, an allocated wristband — the Act applies, and with it the conditions for lawful processing, retention limits, security safeguards and the obligation to tell the person what you are collecting.

Do we need staff consent to run a duress or response-time system?

Usually you should not rely on consent. Section 11(1) offers other grounds that fit better — compliance with an obligation imposed by law, which is where the employer's general duty under the Occupational Health and Safety Act sits, or the legitimate interests of the responsible party. Consent is weak here because section 11(2)(b) lets a data subject withdraw it at any time, and because consent given inside an employment relationship is open to challenge on whether it was freely given. Choosing the ground deliberately, and recording why, is part of the compliance work.

Can an employee refuse to be tracked?

They can object, and the Act gives that objection real force. Section 11(3) allows a data subject to object at any time to processing based on subsection (1)(d) to (f) — legitimate interests included — on reasonable grounds relating to their particular situation, unless legislation provides for the processing. Section 11(4) then says the responsible party may no longer process the information. This is precisely why a narrow, safety-directed purpose matters: an objection is weighed against the grounds, and a system that exists so help arrives when someone presses a button is far more defensible than one that exists so management can watch movement.

Is tracking patients or residents allowed at all, given health is special personal information?

Yes, within section 32. Section 26 prohibits processing special personal information including health, but section 32(1)(a) disapplies that prohibition for medical professionals, healthcare institutions or facilities and social services where processing is necessary for the proper treatment and care of the data subject, or for the administration of the institution concerned. Most of what a location system does in a facility falls within that second limb. The conditions in section 32(2) and (3) then apply: everyone processing the information must be under an obligation of confidentiality, whether by office, employment, profession, legal provision or written agreement.

How long may we keep location records?

Section 14 sets the principle rather than a number: records must not be retained longer than is necessary for achieving the purpose for which they were collected, unless retention is required by law, reasonably required for lawful purposes related to your functions, required by contract, or consented to. In practice that argues for splitting the data — a short retention period on raw position history, which is the sensitive and rarely-needed part, and a longer one on the aggregate measures you actually report and are asked to evidence. Records relevant to an incident under investigation should be preserved deliberately, as an exception you can justify.

Does keeping the system on our own server help our POPIA position?

It helps in two concrete ways. Section 19 requires appropriate technical and organisational measures to secure integrity and confidentiality, and a system inside your own network under your own access control is a simpler thing to secure and to describe. It also avoids engaging section 72, which restricts transfers of personal information outside South Africa and requires specific conditions to be met. On-premises processing is not compulsory, but if the data is going somewhere else, that decision needs its own justification rather than being a by-product of how the product happens to be built.

What must a POPIA notice to staff actually say?

Section 18 lists it: what is being collected and from where, who the responsible party is and their address, the purpose, whether supplying the information is voluntary or mandatory and what happens if it is not supplied, any law authorising the collection, whether it will be transferred to a third country, and further information including the recipients, the nature of the information, the right of access and rectification, the existence of the right to object under section 11(3), and the right to complain to the Information Regulator with its contact details. The right to object and the Regulator's details are the two most commonly omitted, and their absence is what turns a notice into a problem.

Does POPIA say what accuracy we may use?

Not in those words, but the minimality condition gets there. Processing must be adequate, relevant and not excessive given the purpose, which means you collect what the purpose needs rather than what the equipment can produce. If the purpose is evidencing that a call was answered, room-level certainty answers it and a continuous centimetre-accurate trace does not answer it any better — it simply creates a more intrusive record to secure, justify and eventually delete. Setting resolution down to the purpose is one of the cheapest compliance decisions available, and it is made at design time or not at all.

Primary sources

Section references are to the Act as published in Government Gazette 37067 of 26 November 2013. This article is an explanation of the legislation's requirements for system design, not legal advice.

Design the compliance in, not around.

The resolution, the retention and the reporting are set at survey. Tell us the purpose and we will design a system your Information Officer can sign off.