Why this is a POPIA question at all
People sometimes assume that a badge which reports which ward someone is in is operational data rather than personal data. The Act removes the argument. Section 1 defines personal information as information relating to an identifiable living person, and the list of examples explicitly includes "any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person".
So the threshold question is settled before you start. What remains is the set of questions POPIA always asks: on what basis are you processing, for what purpose, for how long, with what safeguards, and have you told the people concerned. The rest of this article works through them for the two populations a health or care facility deals with — because the answers are genuinely different, and conflating them is the most common mistake.
Patients and residents: the health category, and the exception that matters
Section 26 prohibits processing "special personal information", and health is on that list alongside race, religion, trade union membership, political persuasion, sex life and biometric information. Left there, a hospital could not operate. Section 32 provides the way through, and it is worth reading closely, because its wording is more useful than most buyers expect. The prohibition does not apply to processing by "medical professionals, healthcare institutions or facilities or social services, if such processing is necessary for the proper treatment and care of the data subject, or for the administration of the institution or professional practice concerned".
That second limb — administration of the institution — is the one that covers a great deal of what a location system does. Knowing that a call was answered, that a resident is inside the building, that an infusion pump is on the third floor: these are administration of the institution, and the Act contemplates them.
Two conditions ride along with it. Section 32(2) says the information may only be processed by responsible parties subject to an obligation of confidentiality — by virtue of office, employment, profession or legal provision, or by written agreement. Section 32(3) adds that a responsible party permitted to process this information who is not already under a professional confidentiality obligation must nonetheless treat it as confidential. In practice this means the confidentiality obligation has to reach everyone who can see the screen, including administrative staff, contractors and any supplier with support access — and that it should be in writing.
Staff: the provision most employers have not read
Tracking employees is not a special-category problem — a nurse's position in a corridor is not health information about the nurse — so it falls under the general grounds in section 11(1). Facilities usually rely on one of three:
- Section 11(1)(c) — processing complies with an obligation imposed by law. The Occupational Health and Safety Act places a general duty on employers to provide a working environment that is safe and without risk to health as far as is reasonably practicable; a lone-worker duress system is a direct response to that duty.
- Section 11(1)(f) — processing is necessary for pursuing the legitimate interests of the responsible party. Response-time evidence, staff safety and incident investigation sit here.
- Section 11(1)(a) — consent. Attractive-looking, and usually the weakest option in an employment relationship, for the reason below.
Now the provision that changes system design. Section 11(3) says a data subject may object, at any time, to processing carried out on the grounds in subsection (1)(d) to (f) — which includes legitimate interests — on reasonable grounds relating to their particular situation, unless legislation provides for the processing. And section 11(4) is blunt about what follows: "If a data subject has objected to the processing of personal information in terms of subsection (3), the responsible party may no longer process the personal information."
Consent is not the escape route either: section 11(2)(b) allows a data subject to withdraw consent at any time. An employer who builds a safety system on consent has built it on something each employee can switch off, and in an employment relationship the freeness of that consent is questionable from the start.
The practical consequence is not that staff tracking is impossible. It is that the narrower and more clearly safety-directed your purpose, the more robust your position — because an objection is assessed on reasonable grounds relating to a particular situation, and "this system exists so that someone comes when I press the button at 02:00" is a very different proposition to answer than "this system exists so management can see where everyone is". Facilities that introduce location as a productivity surveillance tool invite objections they will struggle to resist. Facilities that introduce it as a duress and response-time system, and can show the design reflects exactly that, are in a much stronger place.