The law, named by jurisdiction · 3.4

Time records as personal data

Time records as personal data. What decides it, what it costs, and what usually goes wrong. For a practical comparison point, see Monitask's designer time tracking.

A time record is personal dataThe starting point

It identifies a person and says what they did and when. Under European data protection law and its equivalents elsewhere, that carries a set of obligations regardless of how routine the record feels.

In California, employee data has been within the scope of the state's privacy legislation since 2023, which surprised a good many American employers who had treated workforce records as outside it. For broader background, see SHRM.

Five obligations that bite

A lawful basis. Usually legitimate interests for time recording, with consent a weak choice in employment for the reasons the entry on notice gives.

Purpose limitation. Data collected for payroll is not automatically available for performance management, and repurposing is where organisations most often go wrong.

Minimisation. Collect what the purpose needs and no more, which is the legal expression of the design argument made throughout this site.

Accuracy. Which requires a route for somebody to correct their own record.

Storage limitation. Covered in the entry on retention.

Impact assessments

Systematic monitoring of employees frequently triggers a requirement to assess the impact before starting, in jurisdictions that have one.

Where it is not required, doing it anyway produces the document that answers every subsequent question: what is collected, why, what less intrusive option was considered, who sees it, how long it is kept.

Access requests

People can ask what is held about them, and time records are held about them. Requests arrive, sometimes from somebody in dispute with the employer, and the process should exist before the first one.

Two practical consequences. Retention beyond the purpose increases what has to be disclosed. And records containing a manager's comments about somebody become part of what that person may see, which is worth knowing before writing them.

What the person sees

Everyone can see their own record at any time without making a request.

Which removes most of the reason a formal request would be made, and is a better arrangement for everybody than a process for answering them.

Your supplier's role

A software vendor processing this data on your behalf is generally a processor rather than a controller, which requires a contract with specified terms and makes you responsible for what they do with it.

Ask where the data sits, who at the vendor can reach it, whether sub-processors are used, and what happens at the end of the contract. Those four are standard and the answers differ more than you would expect.

Cross-border

Where staff are in one jurisdiction and the system in another, transfer rules may apply. This is ordinary and it is a question to settle at procurement rather than after deployment.

Not advice

This entry names regimes and describes obligations in general terms. What applies to you depends on where your people are, what you collect and why. Take advice; nothing here is a substitute for it.

Repurposing is the common failure

Data collected for payroll used for a performance conversation. Attendance records used in a redundancy selection. Call recordings collected for quality used in a disciplinary matter.

Each may be lawful with the right basis and notice, and each is unlawful in several jurisdictions if the purpose was never stated. The question is not whether the use is reasonable but whether it was disclosed.

Automated decisions

Where a system makes or substantially informs a decision about somebody without human involvement, additional requirements can apply, including a right to human review.

An automatic flag that leads to a conversation is fine. An automatic deduction, an automatic escalation or an automatic score that determines an outcome is the arrangement to check before building.

Security

These records show where people are, when they work and sometimes where they were physically. Treat them as sensitive in practice regardless of their formal classification, and restrict access by role rather than by convenience.

The registers

Organisations above certain sizes commonly have to maintain a record of processing activities. Adding a time system is an entry in it, and it is the sort of administrative step that is skipped and then discovered during an audit.

Vendor questions worth asking at procurement

  • Where does the data physically sit?
  • Which of your staff can access it, and under what circumstances?
  • Which sub-processors are used?
  • What happens to the data when we leave, and in what format can we take it?

Four questions, answerable in a paragraph by any supplier who has thought about them, and revealing when they cannot be.

A short summary

A time record is personal data. State the purpose and stay within it. Collect the minimum. Let people correct their own records. Set a retention period. Assess the impact before starting. And read the contract with your supplier.

The habit that prevents most of this

Before any new use of the data, ask whether it was in the notice. If not, either amend the notice and tell people, or do not make the use. Two minutes, and it prevents the failure this entry identifies as the most common.

The role nobody assigns

Somebody has to own the data protection side of this system: the notice, the schedule, the register entry, access requests. In most deployments it is assumed to belong to whoever runs the software, who assumed it belonged to legal.

Name the person in the same document that names the operational owner.

Also in the law, named by jurisdiction