Skip to content
Product Data & Architecture

Can You Track Products with BLE or UWB Without Tracking People?

BLE, UWB and RFID create different location evidence. Learn what each observation proves, what silence means and when asset tracking becomes people tracking.

Reading time
10 min
Last verified
Sources
7
Share article
LinkedIn X Email
Hands at a packing bench working with cartons, labels and a tape roll with paperwork and racking behind.

A dot on a map looks like a fact. Often it is an inference assembled from a receiver, a radio method, uncertainty and a policy. The first job is to record what was actually observed. The second is to stop useful product tracking quietly turning into a history of where people have been.

The short answer

Yes. A business can track products or assets without necessarily creating a person-tracking system, but only if the architecture keeps observation, inference and person linkage separate. BLE, UWB, RFID-style read events and device location create different kinds of evidence, with different uncertainty and coverage. The safest design is to collect the minimum sufficient spatial evidence for the decision, avoid unnecessary joins to people and retain location history only for as long as the purpose actually needs it.

A product tag does not create legal or privacy immunity. If a carried object is persistently linked to an identifiable person, repeated product-location events can become behavioural or personal data.

Activatea Product.
Share
LinkedInXEmail
Navigate this page

What was actually observed?

Location systems fail when they store the conclusion but throw away the observation that created it.

A browser geolocation call, for example, returns location associated with the hosting device. W3C also defines the accuracy value as a radius with a 95% confidence level. That is not the same as proving the exact location of the physical product being scanned.

Likewise, a BLE receiver that hears an advertisement has observed a radio transmission under particular conditions at a particular time. NIST’s work on BLE proximity estimation is a strong counterweight to overclaiming: signal strength is affected by environment, orientation, obstruction and radio conditions. Hearing a transmission does not, by itself, prove exact distance, continuous presence, ownership or human interaction.

This is the same discipline used in what a scan actually tells you: record the observation first, then label the inference separately.

For a spatial event, we would preserve at least:

  • the product or asset identifier
  • the observer or receiver
  • the observation method
  • the observation time
  • the read point, zone or estimated coordinates
  • uncertainty or evidence class
  • relevant receiver state or coverage
  • the binding used between observation and product
  • permission or purpose context where relevant
  • the security profile or protocol version where material

We call that the Spatial Evidence Event Envelope. It is an ActivateDigital synthesis, not an industry standard.

BLE, RFID, UWB and device location create different evidence

The practical mistake is to treat every technology as if it creates “location”. It does not. It creates an observation from which a location claim may be inferred.

MethodUseful evidence classWhat you can safely sayWhat you should not silently infer
Browser or phone geolocationDevice-associated coordinates plus accuracy estimateThe hosting device reported a location estimate at that timeThe product itself was exactly there, or remained there afterwards
BLE advertisementReceiver observed a transmissionThis receiver heard this identifier or payload under these radio conditionsExact distance, continuous presence, ownership or person interaction
BLE Direction FindingEngineered angular evidence using antenna arraysA managed receiver system can estimate direction more strongly than basic RSSIThat ordinary BLE scanning provides the same result
Bluetooth Channel SoundingFine-ranging inputs using PBR and RTTNewer Bluetooth versions can support stronger ranging evidenceThat every device implements the same distance algorithm, accuracy or security profile
UWBRelative ranging and direction in supported implementationsUWB can provide strong ranging evidence in industrial and device ecosystemsThat the word “UWB” itself guarantees secure ranging or a particular field accuracy
RFID-style portal/read-zone eventReader or zone observationThe item was observed by a defined reader context or zone under the configured systemExact continuous coordinates between reads, or absence when no read occurs

The RFID row is deliberately framed at the event level rather than as a technology-buying comparison. If you need detailed event semantics such as read points, business steps and event context, that belongs with EPCIS events versus product master data.

Why RSSI and silence are easy to overstate

RSSI is not a ruler

Bluetooth RSSI is attractive because it is cheap to collect. It is also tempting to convert it into a precise distance number.

NIST’s proximity work shows why that can be misleading. The same physical separation can produce different signal-strength readings because of walls, bodies, orientation, multipath and device differences. A strong signal may be consistent with closeness, but it is not a universal exact-distance measurement.

Bluetooth Direction Finding is a different proposition because it uses engineered antenna arrays for Angle of Arrival or Angle of Departure positioning. Bluetooth Channel Sounding is different again, using phase-based ranging and round-trip timing. Even then, the final distance result depends on implementation, environment, device support and the security capabilities of the Bluetooth Core version in use.

The words “Bluetooth” or “Channel Sounding” are not, by themselves, a security guarantee.

Silence is not absence

A missed observation can occur because the product was not there. It can also occur because the receiver was down, the scan interval missed the transmission, radio propagation was poor, the tag battery failed, the platform filtered the result or the coverage design had a gap.

So “not seen” should only become “absent” when the system can also establish the conditions under which the item would have been seen.

This is a denominator problem as much as a radio problem. A useful metric needs an eligible-observation denominator, not just a count of detections. The wider measurement pattern is covered in the denominator problem.

The Spatial Evidence Ladder

We use a Spatial Evidence Ladder to make location claims easier to govern. It is an ActivateDigital synthesis.

LevelEvidenceExample decision it may supportMain risk if overstated
L0: Identifier seenA receiver or reader observed an identifier“This item interacted with this observation system”Treating a read as exact position
L1: Zone or read pointObservation is bound to a known doorway, shelf, room or controlled area“The item was observed in this operational zone”Assuming continuous presence
L2: Proximity classEvidence supports coarse near/far or encounter logic“The item was probably within the configured proximity band”Converting noisy radio evidence into exact metres
L3: Estimated positionSystem produces coordinates with uncertainty“The item was estimated here, within this uncertainty model”Dropping accuracy/confidence metadata
L4: Secure ranging inputStronger ranging protocol and security profile are part of the event“This interaction passed the implemented ranging checks”Treating protocol label as universal anti-relay security
L5: Decision-ready spatial evidencePosition, uncertainty, identity, purpose, coverage and policy are jointly evaluated“This spatial evidence is sufficient for this specific decision”Reusing high-precision data for unrelated purposes

More precision is not automatically more truth, and it is not automatically more value.

UWB and Channel Sounding can strengthen evidence, not abolish uncertainty

UWB is already used for precise relative ranging in supported smartphones, access systems and industrial real-time location systems. FiRa and Android documentation show mature implementation paths. But security depends on configuration and implementation rather than the UWB label alone. Peer-reviewed research has demonstrated weaknesses in unsafe or historical configurations, while current stacks include stronger timing and security mechanisms.

Apple makes the boundary especially clear in Nearby Interaction documentation: its distance output should not be relied upon as a secure-access decision by itself.

Bluetooth Channel Sounding is newer. Bluetooth Core 6.0 introduced the feature, while Core 6.2 and Core 6.3 added security and accuracy improvements. That version history matters. A product specification that merely says “supports Channel Sounding” is incomplete evidence unless the implementation and security profile are also known.

If spatial evidence is being used to grant a permission, stop here and hand the decision to the dedicated proximity as permission model. Range is an input. It is not entitlement.

When product tracking becomes people tracking

The transition can be subtle.

A warehouse may start by locating tools. A logistics system may track returnable assets. A retailer may monitor carts or equipment. None of those purposes automatically means the organisation is tracking people.

But the risk changes when one or more of these joins appear:

  1. Identity linkage: the asset is persistently linked to an employee, customer or household.
  2. High granularity: location becomes precise enough to infer movement or behaviour.
  3. Persistence: observations accumulate into a history rather than serving a short operational purpose.
  4. Long retention: raw location is kept after the operational need has passed.
  5. Purpose expansion: data collected for asset operations is reused for performance monitoring, behavioural scoring or unrelated analytics.
  6. Downstream sharing: more systems or parties gain access to the movement history.

We call this the Product-to-Person Tracking Transition Test. It is an ActivateDigital synthesis of the privacy and governance boundaries in the accepted evidence.

Under GDPR, location or proximity data becomes personal data where it relates to an identified or identifiable person. Repeated spatial events can support profiling of movement. Purpose limitation, data minimisation, accuracy and storage limitation then become architectural requirements, not just policy text.

For worker monitoring, the ICO also warns that consent is often not an appropriate lawful basis because of the power imbalance. Necessity, proportionality, transparency and, where required, impact assessment become central.

The detailed legal question belongs with Digital Product Passports and personal data. The engineering lesson here is simpler: do not assume an “asset tag” remains non-personal once the system persistently knows who carries it.

Controls that reduce the tracking transition

Product tracking can be useful without building a centralised behavioural history.

Controls include:

  • avoid joining product identifiers to named people unless the use case genuinely requires it
  • use zone-level evidence instead of exact coordinates when a zone is enough
  • keep raw observations for the shortest period that supports the operational purpose
  • derive a business event, then discard unnecessary radio detail where appropriate
  • separate operational asset views from HR or customer profiles
  • limit who can query historical movement
  • process some detection or unwanted-tracker logic on-device where that reduces centralisation
  • create explicit rules for carried products and take-home assets
  • record receiver coverage and health so missed reads are not converted into false absence
  • rotate or minimise identifiers where the product-location use case does not require a long-lived public tracking handle

Apple and Google’s unwanted-tracker controls are useful evidence that object-finding networks need explicit anti-stalking design. The IETF DULT threat model reaches the same conclusion at protocol-threat level.

These controls reduce risk. They do not create legal immunity.

Minimum Sufficient Spatial Evidence: how much precision do you need?

Our Minimum Sufficient Spatial Evidence, or MSSE, rule is simple:

Use the least precise spatial evidence that reliably supports the decision.

It is an ActivateDigital decision framework, not a standard.

A practical sequence is:

  1. Name the decision. Find a pallet, trigger a workflow, recover a lost item, route a repair, detect an impossible movement pattern or grant access.
  2. Name the loss from being wrong. What happens if the system says “here” when the asset is not here, or “gone” when it is still present?
  3. Choose the weakest evidence class that keeps that loss acceptable. A read zone may be enough. If not, move up the ladder.
  4. Pilot in the real environment. Radio performance and operational losses are site-specific.
  5. Add privacy and security cost to the decision. Extra precision creates extra governance surface.
  6. Keep uncertainty in the event. Do not collapse a probability or confidence radius into a false exact point.

This is also why technology selection should not begin with “BLE or UWB?”. Begin with “what evidence does the decision actually need?”.

Production examples and bounded economics

Industrial RTLS is already in production. Vendor and customer case studies describe UWB deployments at Toyota, SEG Automotive and Continental, Bluetooth-based tracking at Dyer Engineering and employee-location use cases at Enel.

These cases show that the systems can be deployed. They do not establish a universal business case.

The Toyota case reports a two-year payback, a 50% safety-stock reduction and 18,000 annual man-hours freed. The Dyer Engineering case estimates up to £10,000 per month of workflow savings. Both are useful deployment-specific figures, but neither is an independently audited market denominator. They should not be converted into a generic RTLS ROI claim.

A different pattern comes from Apple Find My and SITA’s baggage workflow. Users can share the location of a lost item with participating airlines for a controlled period. That is a real example of a product-location workflow designed with user-controlled sharing rather than an unrestricted central tracking feed. SITA’s reported outcomes still apply to the opted-in workflow and should not be generalised to all baggage.

If the goal is to generate product events without an explicit scan, that is a separate canonical question. See physical products creating events without being scanned.

If the goal is to turn identity, location and time into clone, diversion or impossible-movement signals, hand off to identity + location + time anomaly detection. This article owns the spatial evidence semantics, not the anomaly logic.

What to do now

Before buying a location technology, write one sentence describing the evidence the business decision actually needs.

Then:

  1. Store the observation and the inference separately.
  2. Preserve observer, method, time, uncertainty and coverage state.
  3. Do not use BLE RSSI as an exact-distance ruler.
  4. Treat “not observed” as unknown unless coverage makes absence inferable.
  5. Record the protocol and security version when fine ranging matters.
  6. Use the least precise evidence that safely supports the decision.
  7. Test whether the data becomes person-linked through persistence, granularity, retention or downstream joins.
  8. Increase governance before increasing precision when people become identifiable.

The goal is not a more accurate dot on a map. It is a spatial event whose meaning can still be defended when someone asks, “What did you actually observe?”

Keep exploring

The questions this page usually raises next.

Sources as at 4 September 2026

Key sources used for this article include:

Does this reach your products?

Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.