They are two different functions, with different risks, and they are treated together for a precise reason: both make your device observable to whoever is around you, even when you are not using them.
Bluetooth broadcasts, location records. The first says “I am here”, the second says “I have been here”. And both stay on for weeks without anybody noticing, because there is nothing to bring them back to attention.
What this recommendation says
Recommendation R12 establishes that wireless connections and geolocation should be kept on only when they are genuinely needed, and that which applications use them should be reviewed.
In practice it concerns three things:
- Bluetooth, on by default on most devices;
- location, and above all which apps use it and how continuously;
- the connected settings, such as scanning for networks even with Wi-Fi turned off.
What it is not. It is not an invitation to give up headphones, watches or navigation. Most people use Bluetooth every day for good reasons. The recommendation concerns the time they stay on without being needed.
Scope. Phones and tablets first of all, where these functions are always present and always on.
Why it matters
The main risk is not technical: it is one of observability.
| Function | What it makes possible | Who benefits |
|---|---|---|
| Bluetooth on | The device is detectable by nearby equipment | Presence-detection systems in shops and public spaces |
| Bluetooth listening | A technical surface exposed | Whoever looks for known vulnerabilities |
| Location on | Continuous recording of movements | The apps using it, and whoever receives that data |
| Location history | A detailed record of places | Anybody with access to that account |
| Network scanning with Wi-Fi off | Detection of your presence | Footfall analysis systems |
The rows about location carry particular weight, and it is worth saying clearly: location is among the most revealing data a device produces. Where you live, where you work, who you spend time with, which places you visit and how regularly: it is information describing a life precisely, and it gets collected continuously with nothing flagging it.
A concrete example
Helen downloads an app to convert units of measurement. On first launch the app asks for access to her location. She accepts without thinking: permission requests are so frequent that they get accepted out of habit.
From that moment the app records her position, even when she is not using it. It does nothing illegal: the permission was granted.
The point is not that the app is malicious — it probably collects data to sell to analytics services, which is a widespread and largely regulated practice. The point is that an app converting units of measurement has no technical reason to know where you are, and that the permission was given in two seconds with no assessment.
When to apply it
- When you are not using connected devices. If you have no headphones, watch or car connected, Bluetooth is not needed.
- When setting up a new device, where the defaults are the most permissive.
- After installing an app, to check what it asked for and what it got.
- Periodically, to review the list of accumulated permissions.
- In crowded places, where presence detection is most widespread.
- When travelling, if you would rather not leave a detailed trail of your movements.
- On children’s devices, where collecting location deserves more attention than elsewhere.
How to apply it
- Review the apps’ location permissions. Settings → Privacy → Location. You will see the complete list and, on many systems, which apps used it recently.
- Set “only while using the app” wherever possible. It is the right compromise: the app works when needed and records nothing the rest of the time.
- Revoke permission from apps that do not need it. If you cannot see why an app would need to know your location, it probably should not.
- Turn on approximate location where the system allows it: many apps work well knowing the city instead of the address.
- Turn off location history in your account, if you do not need it, and consider deleting what has accumulated.
- Switch Bluetooth off when you are not using connected devices. On recent phones the consumption is low, but the observability remains.
- Check the network scanning settings: many systems keep scanning for Wi-Fi and Bluetooth for location services even when you have turned them off. The entry sits in the advanced settings.
Common mistakes to avoid
- Granting permissions out of habit. The requests are so frequent that they get accepted unread: it is the mechanism nearly all the collection rests on.
- Leaving “always” instead of “while using the app”. It is the difference between occasional access and continuous recording.
- Never reviewing the permissions granted. They accumulate for years and nobody looks at them.
- Switching Bluetooth off from the quick control panel. On some systems that only turns it off temporarily, and it comes back on by itself.
- Thinking it only matters for map apps. Many apps collect location for reasons unrelated to their function.
- Overlooking the history already accumulated. Turning off collection does not delete the record.
- Confusing the two functions. Bluetooth exposes the device; location records your movements. The remedies are different.
The two functions, separated
They are worth telling apart, because they need different kinds of attention.
| Bluetooth | Location | |
|---|---|---|
| What it exposes | The device’s presence | Movements over time |
| Range | A few metres | Everywhere |
| Technical risk | Vulnerabilities in the components | None |
| Privacy risk | Detection of presence | High: a complete profile |
| Who takes advantage | Local detection systems | Apps and analytics services |
| Main remedy | Turning it off when not needed | Reviewing the permissions |
The highlighted row is the most important point in this unit: the greater risk does not come from strangers but from the apps you installed yourself, to which you granted a permission in two seconds.
And that is why the main remedy is not switching something off, but looking at a list.
Why these functions stay on
It is worth understanding the mechanism, because it explains why the recommendation is necessary and why saying it once is not enough.
They are on from the factory. Nobody turns them on: they are already like that, and the defaults are designed to make everything work without questions.
They are not a nuisance. Modern Bluetooth’s battery use is low. There is nothing bringing attention back to them.
Permissions get granted in two seconds. At an app’s first launch the request appears at a moment when attention is on wanting to use the app, not on weighing the request.
Nobody reviews the list. Permissions accumulate for years, app after app, and there is no natural moment to look at them.
Apps ask for more than they need. Not always for improper purposes: asking for the broadest permission simplifies development and avoids future problems. But the result is the same.
Hence a useful conclusion: the problem is not a wrong decision, it is the absence of a decision. And that is why the countermeasure is not a habit to maintain but a review to carry out — once, and then now and again.
Where these functions genuinely help
So as not to turn the recommendation into a sacrifice, the legitimate uses are worth listing.
| Use | What it requires |
|---|---|
| Headphones and earbuds | Bluetooth on while listening |
| A watch or fitness band | Bluetooth on continuously |
| A car | Bluetooth on while driving |
| Navigation | Precise location, while using the app |
| Finding a lost device | Location on and the service enabled |
| Emergency calls | The location gets transmitted anyway |
| Reminders tied to a place | Location in the background too |
| Contactless payments | Dedicated technology, not Bluetooth |
Rows five and six deserve a note: location is also a personal safety function. It serves to find a lost device and, in emergency calls, to get help to the right place.
Turning it off entirely is therefore not the best choice for almost anybody. The best choice is to reduce who has access to it, which is a different thing.
How this connects to the Cyber Welfare Framework
| Pillar | How it contributes |
|---|---|
| Awareness | Understanding that location is the most revealing data a device produces |
| Skills | Telling “always” from “while using the app” and managing permissions |
| Secure Behaviour | Weighing permission requests instead of accepting them out of habit |
Digital maturity levels.
- FL1 — Basic. Bluetooth always on, permissions granted out of habit, history on and never looked at.
- FL2 — Beginner. The main apps’ permissions have been reviewed at least once.
- FL3 — Autonomous. “Only while using the app” wherever possible; Bluetooth off when not needed.
- FL4 — Skilled. Approximate location where it is enough; history turned off or managed; permissions reviewed periodically.
- FL5 — Expert-Guide. You help others — particularly families and children — set permissions deliberately.
R12 anticipates R13: here two specific permissions are examined, there the complete system of authorisations.
How to check you are applying it correctly
- How many apps have “always” location permission on my phone?
- Is Bluetooth on right now, and am I using something that needs it?
- Is there a history of my movements somewhere, and have I ever looked at it?
Quick checklist
- ☐ Location permissions reviewed at least once
- ☐ “Only while using the app” set wherever possible
- ☐ No app has access to location without a reason
- ☐ Approximate location turned on where it suffices
- ☐ Location history checked and managed
- ☐ Bluetooth off when no devices are connected
- ☐ Network scanning with Wi-Fi and Bluetooth off turned off
For an overall measure of where you stand, you can take the digital resilience self-assessment.
In short
Bluetooth and location are not dangerous functions: they are functions that stay on.
Bluetooth makes the device observable within a few metres. Location, and above all the apps you granted it to, builds the most detailed trail there is of where you have been and when.
The most effective remedy is not switching things off: it is looking at the list of permissions granted, which almost nobody does and which takes five minutes.
Something to think about. If you opened the list of apps that can know your location right now, how many would you find with no reason at all to know?
Explore this recommendation
- Impact of always on connections — what a broadcasting device exposes
- Consequences of location tracking — what a history really says
- How to manage connections and location — the configuration, system by system
- Signs of unwanted tracking — how to notice something is recording
- How Bluetooth and location work — the mechanisms, explained simply
- Bluetooth attacks — what is realistic and what is not
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



