Data Protection
This is not legal advice, and data protection is an area where a qualified opinion is genuinely worth paying for. For an additional implementation-oriented example, see employee time clock software.
Working time records are personal data. Having a legal duty to create them settles one question and leaves several others open, and the ones left open are where the problems are. For additional workplace and technology context, see Court of Justice of the European Union.
Reviewed August 9, 2026.
What the duty settles
A legal obligation is a lawful basis for processing. An employer recording start, end and duration because the law requires it does not need consent for that processing, and consent in an employment relationship is a weak basis anyway.
So the core record is straightforward, and this is the part most employers worry about unnecessarily.
What it does not settle
Everything beyond the core record.
Location, screenshots, activity levels, application logs, task attribution are not required by the duty, so the duty is not a basis for them. Each needs its own justification, and "the system collects it by default" is not one.
Retention. The duty implies a period; it does not authorise keeping the data indefinitely, and indefinite retention is a processing decision that needs a basis of its own.
Access. Who inside the organisation can see whose records is a separate question, and a system where any manager can see any employee's data is a decision somebody made.
And secondary use. A record created for working time compliance, used for performance assessment, is being processed for a purpose it was not collected for. That is the single most common problem in this area and it is settled cheaply in advance.
The principles that bite here
Purpose limitation. Collected for working time compliance means used for working time compliance. Extending it to performance is the failure case.
Data minimisation. Collect what the duty requires and configure the rest off. A system capturing location because location was in the box it shipped with is collecting more than it can justify.
Storage limitation. A defined retention period, applied, with actual deletion.
And transparency. Employees told what is recorded, why, how long it is kept and who can see it — which is also what a works agreement covers where one exists.
The employee's own rights
Frequently forgotten and cheap to accommodate.
Access to their own record, which the accessibility limb of the standard requires anyway. The two obligations point the same way, so building it once satisfies both.
Rectification, which in practice is the correction procedure.
And information about the processing, which is the short policy every employer should have regardless.
The practical checklist
Six items, once.
Record only what the duty requires, and disable the rest.
Define retention and apply it.
Write down who can see what.
Say what the data will not be used for, explicitly.
Give employees access to their own records without asking.
And check where the data physically is if a hosted system is involved — processor agreements and transfer questions are ordinary and are somebody's job.
The short version
- A legal duty to record is a lawful basis for the core record, so consent is not needed and would be weak anyway
- The duty is not a basis for location, screenshots, activity levels or task attribution, and system defaults are not a justification
- It does not settle retention, internal access, or secondary use — and secondary use for performance is the commonest problem
- Purpose limitation, data minimisation, storage limitation and transparency are the principles that bite
- Employee access to their own record satisfies both data protection and the accessibility limb of the standard
- Six items: record the minimum, define retention, document access, state what it will not be used for, give employees access, check where the data sits