Time tracking involves processing personal data concerning employee attendance and working patterns. Keeping adequate records is a statutory obligation for employers — and for that reason, the key legal question is not whether data may be processed, but to what extent and on what lawful basis.
The Lawful Basis
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), every processing activity requires a lawful basis under Article 6:
- Legal Obligation (Article 6(1)(c)): Mandatory recording of working hours and rest periods to comply with Regulation 9 of the Working Time Regulations 1998 (WTR 1998) and Section 9 of the National Minimum Wage Act 1998 (NMWA).
- Legitimate Interests (Article 6(1)(f)) or Contractual Necessity (Article 6(1)(b)): Operational time recording extending beyond statutory baselines — such as client billing, project time allocation, and resource planning — where the employer's business interests are balanced against employee privacy rights.
Data Minimisation in Practice
Under the UK GDPR data minimisation principle (Article 5(1)(c)), employers must collect only data that is adequate, relevant, and strictly necessary for the specified purpose.
Necessary and therefore permissible:
- Start, finish, and duration of daily working time,
- Rest breaks taken during shifts exceeding 6 hours (Regulation 12 WTR 1998),
- Absence categories necessary for statutory leave and payroll administration (e.g. sickness, statutory annual leave, parental leave),
- In project time tracking: assignment of logged hours to specific clients, cost centres, or operational projects.
Not necessary and therefore impermissible:
- Diagnostic medical details on self-certification forms or Statement of Fitness for Work ("fit notes") beyond what is required to manage workplace adjustments or Statutory Sick Pay (SSP),
- Covert monitoring, automated desktop screenshots, keystroke logging, or webcam surveillance as proof of presence,
- Continuous GPS tracking during working hours or during employee rest periods,
- Excessive behavioural profiling without documented operational justification,
- Public leaderboards or performance ranking tables based solely on raw time-tracking metrics.
Biometric Methods
Biometric technologies — including fingerprint scanning, facial recognition, and vascular pattern recognition — process biometric data for the purpose of uniquely identifying an individual. This constitutes special category data under Article 9 of the UK GDPR.
Processing special category data requires both an Article 6 lawful basis and an Article 9 exemption condition (as well as meeting Schedule 1 conditions under the Data Protection Act 2018). The Information Commissioner's Office (ICO) has issued strict enforcement action against employers deploying biometric clock-in systems where less intrusive alternatives — such as proximity fobs, RFID smart cards, or secure PINs — achieve the same objective.
Employers seeking to introduce biometric time tracking must:
- Conduct and document a rigorous Data Protection Impact Assessment (DPIA) demonstrating strict necessity and proportionality,
- Store irreversibly encrypted mathematical templates rather than raw biometric images,
- Store templates locally on individual encrypted tokens or devices where feasible, and
- Provide a genuine, fully functional, non-biometric alternative without penalty.
Location Data and Mobile Working
For remote, field, or mobile workers, location capture presents acute data privacy risks. Proportionate implementation follows a clear hierarchy:
| Variant | Assessment |
|---|---|
| No location capture | Fully compliant and privacy-preserving |
| One-off geofence verification at clock-in (storing a pass/fail confirmation) | Generally justifiable for a legitimate operational need |
| Recording exact GPS coordinates at clock-in/out timestamps | Requires documented legitimate interest and transparency |
| Continuous GPS tracking throughout the working day | Routinely disproportionate and unlawful under UK GDPR / ICO guidance |
A legitimate operational purpose includes verifying presence at a designated client site or hazardous work location where contracted or mandated by health and safety standards — never general, continuous surveillance.
Access Control and Role-Based Permissions
A compliant time-tracking architecture enforces strict role-based access control (RBAC):
- Workers: Direct self-service access to view, submit, and rectify their own time and absence records.
- Line Managers: Visibility restricted strictly to direct subordinates for shift approval, holiday management, and statutory rest oversight.
- HR & Payroll: Access restricted to aggregate timesheets, verified absences, and payroll-relevant adjustments.
- System Administrators: Technical maintenance access only, backed by immutable audit logging for any administrative data access.
Data Storage and Statutory Retention Periods
Data must not be held longer than necessary for its stated purpose. UK employers must align their retention schedules with statutory limitation and compliance windows:
| Data Category | Statutory Authority | Mandatory Retention Period |
|---|---|---|
| Working time records (maximum 48-hour week limits, night work) | Working Time Regulations 1998 (Reg 9) | At least 2 years |
| Pay, hours worked, and wage calculation records | National Minimum Wage Act 1998 / Regulations | At least 6 years |
| PAYE income tax, National Insurance, and SSP records | HMRC Regulations / Social Security Administration Act 1992 | At least 3 years after the end of the relevant tax year |
| Timesheets and records supporting commercial contracts or breach of contract claims | Limitation Act 1980 | 6 years |
| Access and security audit logs | UK GDPR Article 32 (Security) | Short, predefined operational window (e.g. 6–12 months) |
Once statutory retention periods expire and ongoing claims are precluded, the legal obligation to retain records transitions into a mandatory duty to erase under Article 17 of the UK GDPR.
Data Subject Rights
Under Chapter III of the UK GDPR, employees have enforceable statutory rights:
- Right of Access (Article 15): The right to receive a copy of all logged personal time tracking data through a Subject Access Request (SAR).
- Right to Rectification (Article 16): The right to have inaccurate time entries, missed clock-ins, or incorrect absence classifications promptly corrected.
- Right to Erasure (Article 17): The right to request deletion of historical time records once statutory retention limits have expired.
Self-service employee portals that provide transparent, real-time access to time logs satisfy the majority of routine data access requests automatically.
Data Processing Agreements (DPA)
Deploying a cloud-based SaaS time-tracking solution means engaging a third-party data processor under Article 28 of the UK GDPR. Employers (as data controllers) must ensure:
- A legally binding Data Processing Agreement (or UK Addendum / International Data Transfer Agreement where transfers outside the UK occur),
- Documented Technical and Organisational Measures (TOMs) covering encryption in transit and at rest, access controls, and business continuity,
- Clear contractual terms governing sub-processor appointments and prompt data return or deletion upon contract termination.
Workplace Agreement on Working Time Recording (Template)
Regulatory Framework under the Information and Consultation of Employees (ICE) Regulations 2004, Trade Union Recognition Agreements, and the UK GDPR / Data Protection Act 2018
Compatible with: Microsoft Word 2016+, Microsoft 365, LibreOffice Writer, Google Docs
Sources and Legal Framework
Statutes and Statutory Instruments
- UK GDPR (United Kingdom General Data Protection Regulation) — Principles of data processing (Art. 5), lawful bases (Art. 6), special category data (Art. 9), data subject rights (Arts. 12–23), and processor obligations (Art. 28)
- Data Protection Act 2018 (DPA 2018) — UK application of data protection law, employment context provisions, and Schedule 1 conditions for processing special category data
- Working Time Regulations 1998 (SI 1998/1833) — Regulation 9 (record keeping), Regulation 10 (daily rest), Regulation 11 (weekly rest), Regulation 12 (rest breaks), and Regulation 4 (maximum weekly working time)
- National Minimum Wage Act 1998 — Section 9 duty of employers to maintain records proving minimum wage compliance, retained for at least 6 years under Regulation 59 of the National Minimum Wage Regulations 2015
- Employment Rights Act 1996 (ERA 1996) — Section 1 written statements of employment particulars and statutory rights
Regulatory Guidance and Judicial Authorities
- Information Commissioner's Office (ICO) — Employment Practices and Data Protection Guidance: Monitoring at Work
- Information Commissioner's Office (ICO) — Guidance on Special Category Data and Biometrics in the Workplace
- Court of Justice of the European Union (CJEU) – Federación de Servicios de Comisiones Obreras (CCOO) v Deutsche Bank SAE (Case C-55/18) — Employer duty to establish an objective, reliable, and accessible system enabling the duration of daily working time to be measured
- High Court of Justice / Employment Appeal Tribunal (EAT) authorities on workplace surveillance, constructive dismissal arising from breach of trust and confidence, and Article 8 ECHR (Right to respect for private and family life)
Current as of: August 2026. This guide provides general informational guidance under English employment and data protection law and does not constitute formal legal advice.
Frequently asked questions
- Author
- PlainStaff Editorial Team
- HR Editorial Team
- Updated on