GuideLevel: IntermediateData ProtectionUK GDPRTime TrackingEmployment LawCompliance

Data Protection in Time Tracking – UK GDPR, Biometrics, and Location Data

What may be collected, what lawful basis supports it, and where statutory boundaries lie under UK law

7 min read · Updated on

Time tracking involves processing personal data concerning employee attendance and working patterns. Keeping adequate records is a statutory obligation for employers — and for that reason, the key legal question is not whether data may be processed, but to what extent and on what lawful basis.

The Lawful Basis

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), every processing activity requires a lawful basis under Article 6:

  • Legal Obligation (Article 6(1)(c)): Mandatory recording of working hours and rest periods to comply with Regulation 9 of the Working Time Regulations 1998 (WTR 1998) and Section 9 of the National Minimum Wage Act 1998 (NMWA).
  • Legitimate Interests (Article 6(1)(f)) or Contractual Necessity (Article 6(1)(b)): Operational time recording extending beyond statutory baselines — such as client billing, project time allocation, and resource planning — where the employer's business interests are balanced against employee privacy rights.

Data Minimisation in Practice

Under the UK GDPR data minimisation principle (Article 5(1)(c)), employers must collect only data that is adequate, relevant, and strictly necessary for the specified purpose.

Necessary and therefore permissible:

  • Start, finish, and duration of daily working time,
  • Rest breaks taken during shifts exceeding 6 hours (Regulation 12 WTR 1998),
  • Absence categories necessary for statutory leave and payroll administration (e.g. sickness, statutory annual leave, parental leave),
  • In project time tracking: assignment of logged hours to specific clients, cost centres, or operational projects.

Not necessary and therefore impermissible:

  • Diagnostic medical details on self-certification forms or Statement of Fitness for Work ("fit notes") beyond what is required to manage workplace adjustments or Statutory Sick Pay (SSP),
  • Covert monitoring, automated desktop screenshots, keystroke logging, or webcam surveillance as proof of presence,
  • Continuous GPS tracking during working hours or during employee rest periods,
  • Excessive behavioural profiling without documented operational justification,
  • Public leaderboards or performance ranking tables based solely on raw time-tracking metrics.

Biometric Methods

Biometric technologies — including fingerprint scanning, facial recognition, and vascular pattern recognition — process biometric data for the purpose of uniquely identifying an individual. This constitutes special category data under Article 9 of the UK GDPR.

Processing special category data requires both an Article 6 lawful basis and an Article 9 exemption condition (as well as meeting Schedule 1 conditions under the Data Protection Act 2018). The Information Commissioner's Office (ICO) has issued strict enforcement action against employers deploying biometric clock-in systems where less intrusive alternatives — such as proximity fobs, RFID smart cards, or secure PINs — achieve the same objective.

Employers seeking to introduce biometric time tracking must:

  1. Conduct and document a rigorous Data Protection Impact Assessment (DPIA) demonstrating strict necessity and proportionality,
  2. Store irreversibly encrypted mathematical templates rather than raw biometric images,
  3. Store templates locally on individual encrypted tokens or devices where feasible, and
  4. Provide a genuine, fully functional, non-biometric alternative without penalty.

Location Data and Mobile Working

For remote, field, or mobile workers, location capture presents acute data privacy risks. Proportionate implementation follows a clear hierarchy:

VariantAssessment
No location captureFully compliant and privacy-preserving
One-off geofence verification at clock-in (storing a pass/fail confirmation)Generally justifiable for a legitimate operational need
Recording exact GPS coordinates at clock-in/out timestampsRequires documented legitimate interest and transparency
Continuous GPS tracking throughout the working dayRoutinely disproportionate and unlawful under UK GDPR / ICO guidance

A legitimate operational purpose includes verifying presence at a designated client site or hazardous work location where contracted or mandated by health and safety standards — never general, continuous surveillance.

Access Control and Role-Based Permissions

A compliant time-tracking architecture enforces strict role-based access control (RBAC):

  • Workers: Direct self-service access to view, submit, and rectify their own time and absence records.
  • Line Managers: Visibility restricted strictly to direct subordinates for shift approval, holiday management, and statutory rest oversight.
  • HR & Payroll: Access restricted to aggregate timesheets, verified absences, and payroll-relevant adjustments.
  • System Administrators: Technical maintenance access only, backed by immutable audit logging for any administrative data access.

Data Storage and Statutory Retention Periods

Data must not be held longer than necessary for its stated purpose. UK employers must align their retention schedules with statutory limitation and compliance windows:

Data CategoryStatutory AuthorityMandatory Retention Period
Working time records (maximum 48-hour week limits, night work)Working Time Regulations 1998 (Reg 9)At least 2 years
Pay, hours worked, and wage calculation recordsNational Minimum Wage Act 1998 / RegulationsAt least 6 years
PAYE income tax, National Insurance, and SSP recordsHMRC Regulations / Social Security Administration Act 1992At least 3 years after the end of the relevant tax year
Timesheets and records supporting commercial contracts or breach of contract claimsLimitation Act 19806 years
Access and security audit logsUK GDPR Article 32 (Security)Short, predefined operational window (e.g. 6–12 months)

Once statutory retention periods expire and ongoing claims are precluded, the legal obligation to retain records transitions into a mandatory duty to erase under Article 17 of the UK GDPR.

Data Subject Rights

Under Chapter III of the UK GDPR, employees have enforceable statutory rights:

  • Right of Access (Article 15): The right to receive a copy of all logged personal time tracking data through a Subject Access Request (SAR).
  • Right to Rectification (Article 16): The right to have inaccurate time entries, missed clock-ins, or incorrect absence classifications promptly corrected.
  • Right to Erasure (Article 17): The right to request deletion of historical time records once statutory retention limits have expired.

Self-service employee portals that provide transparent, real-time access to time logs satisfy the majority of routine data access requests automatically.

Data Processing Agreements (DPA)

Deploying a cloud-based SaaS time-tracking solution means engaging a third-party data processor under Article 28 of the UK GDPR. Employers (as data controllers) must ensure:

  • A legally binding Data Processing Agreement (or UK Addendum / International Data Transfer Agreement where transfers outside the UK occur),
  • Documented Technical and Organisational Measures (TOMs) covering encryption in transit and at rest, access controls, and business continuity,
  • Clear contractual terms governing sub-processor appointments and prompt data return or deletion upon contract termination.

Statutes and Statutory Instruments

Regulatory Guidance and Judicial Authorities

  • Information Commissioner's Office (ICO) — Employment Practices and Data Protection Guidance: Monitoring at Work
  • Information Commissioner's Office (ICO) — Guidance on Special Category Data and Biometrics in the Workplace
  • Court of Justice of the European Union (CJEU) – Federación de Servicios de Comisiones Obreras (CCOO) v Deutsche Bank SAE (Case C-55/18) — Employer duty to establish an objective, reliable, and accessible system enabling the duration of daily working time to be measured
  • High Court of Justice / Employment Appeal Tribunal (EAT) authorities on workplace surveillance, constructive dismissal arising from breach of trust and confidence, and Article 8 ECHR (Right to respect for private and family life)

Current as of: August 2026. This guide provides general informational guidance under English employment and data protection law and does not constitute formal legal advice.

Frequently asked questions

Primarily compliance with a legal obligation under Article 6(1)(c) of the UK GDPR, as employers must keep adequate records under the Working Time Regulations 1998 (WTR) and the National Minimum Wage Act 1998 (NMWA). Where processing exceeds statutory duties (e.g. client project billing), legitimate interests under Article 6(1)(f) or contractual necessity under Article 6(1)(b) serves as the lawful basis.
Only in exceptionally rare circumstances. Biometric data used for unique identification constitutes special category data under Article 9 UK GDPR. The Information Commissioner's Office (ICO) makes clear that if less intrusive alternatives exist (such as RFID fobs or PINs), biometric clock-in systems are routinely unlawful and disproportionate.
Only for a specific, justified business purpose and using the least intrusive method possible — such as a one-off geofence verification at the exact moment of clocking in. Continuous GPS tracking throughout the working day is intrusive, disproportionate, and breaches UK data protection principles.
Retention periods must strictly mirror statutory requirements: at least 2 years under the Working Time Regulations 1998, 3 years after the relevant tax year for PAYE/HMRC records, and at least 6 years under the National Minimum Wage Act 1998 and the Limitation Act 1980 for breach of contract and payroll claims. Once retention periods expire, data must be securely erased.
Author
PlainStaff Editorial Team
HR Editorial Team
Updated on