Time tracking is mandatory - but it processes sensitive employee data. What matters from a data protection standpoint, explained concisely.
As soon as you track working hours, you are processing personal data within the meaning of the GDPR. This includes not only the start, end and duration of daily working time, but also breaks, overtime and absences such as vacation or sick leave. This data can be attributed to individual employees - and is therefore subject to the rules of data protection.
This doesn't mean that time tracking is problematic. It simply means that anyone who does it must observe a few basic data protection obligations.
Data processing always requires a legal basis. For time tracking, this is usually straightforward: the processing is necessary to fulfil the statutory recording obligation and takes place within the framework of the employment relationship.
The relevant provisions are Art. 6 GDPR (lawful processing, including to fulfil legal obligations and to perform the employment contract) as well as § 26 BDSG (German Federal Data Protection Act) on data processing in the employment context. Separate consent from employees is therefore generally not required for the mandatory recording.
You may only collect what's actually necessary for time tracking - nothing more. Real-time location tracking, covert surveillance or hidden behavioral tracking have no place here and are impermissible under data protection law.
Purpose limitation also applies: data you collect for time tracking may only be used for that purpose - not, for instance, to monitor performance or break behavior on the side. Transparency toward employees is part of this too: they should know what data is collected and for what purpose.
Working-time data may only be stored for as long as is necessary or legally required. For the records under § 2a Schwarzarbeitsbekämpfungsgesetz (German Act to Combat Undeclared Work), for example, a retention period of at least two years applies; longer periods may result from payroll and tax records. Once the respective period expires, the data must be deleted.
In practice, it helps to have a solution that lets you cleanly export data and delete it in a targeted way once retention periods expire - so you stay in control of what is stored for how long.
If you use a provider's software for time tracking, that provider processes the personnel data on your behalf. In that case, Art. 28 GDPR requires a Data Processing Agreement (DPA) between you as the responsible employer and the provider.
The DPA governs, among other things, which data is processed for which purpose, what technical and organizational safeguards apply, and that the provider does not use the data for its own purposes. A reputable provider makes the DPA available to you - at Presio you'll find it on the page Security.
The GDPR grants employees concrete rights. Chief among them is the right of access: employees can find out what data is stored about them and request access to their own recorded times. There are also rights to have inaccurate data corrected and - within the statutory time limits - to have it deleted.
A time-tracking system in which employees can view their own hours at any time satisfies the need for access practically on its own.
Yes. Recording working time is permitted if only the necessary data is processed (start, end, breaks), the processing is based on a legal ground, the data is stored encrypted within the EU, and employees can exercise their rights. A data processing agreement (AVV) with the provider is part of this.
Records of working time must generally be retained for at least two years under the Arbeitszeitgesetz (ArbZG, German Working Hours Act). Payroll- and tax-relevant documents are subject to longer retention periods of six to ten years under commercial and tax law. Once these periods expire, the data must be deleted (purpose limitation). This is not legal advice - please have your specific case reviewed by a professional.
Only what is necessary for recording working time: the start of work, the end of work, and breaks, and where required the place of work. Any monitoring beyond this (e.g. continuous location tracking) is not permissible under data protection law. The principle of data minimisation applies throughout.
Presio hosts exclusively in the EU, transmits with encryption and makes the DPA available to you. You'll find all the details on the page Security. Free to start through 31.10.2026, no credit card required.
Try Presio for freeSign up, create your team, get started - try Presio free and with no obligation, no credit card needed.
Start your free trial