When people think about GDPR, they usually think about cookie banners, marketing emails and newsletter opt-ins. But the General Data Protection Regulation (EU Reg. 2016/679) has a very concrete impact on something far more routine: the way your business tracks employee attendance.
Every time an employee clocks in, every time a system logs an early departure, every time a GPS app certifies that a worker is on site โ you are processing personal data. And if you do it without the right safeguards, you face fines starting at โฌ10,000 and reaching up to 4% of your global annual turnover.
This guide explains what you need to do, in practical terms, to stay compliant. It is not legal advice โ for that, consult a qualified professional โ but it gives you the map to understand where you stand and what might be missing.
What Data Does an Attendance Tracking System Collect?
Before discussing obligations, it helps to be clear about which data we are talking about. An attendance tracking system typically processes at least three categories:
Clock-in/clock-out times: the most basic data. These record when an employee started and ended their working day, including overtime, breaks and intermediate exits. These are ordinary personal data, but still subject to GDPR.
Geolocation data: if you use an app with GPS or geofencing, the system also records where the employee was at the moment of clocking in. This data is considered more sensitive because it can reveal habits, movements and even information about an employee's private life outside work.
Holiday, sick leave and absence requests: this falls into the territory of special category data (Art. 9 GDPR). Health-related data โ such as illness or hospitalisation โ enjoys enhanced protection and requires specific legal bases to be processed lawfully.
The GDPR and Employee Data: Applicable Legal Bases
GDPR does not prohibit processing your employees' data. It requires that you have a legal basis for doing so (Art. 6 GDPR). For attendance tracking, the two most relevant bases are:
Performance of a contract (Art. 6(1)(b)): the employment contract includes working time obligations. Recording arrivals and departures is necessary to perform and verify compliance with that contract. This basis covers most standard time and attendance data.
Legal obligation (Art. 6(1)(c)): certain regulations require employers to retain attendance records โ for example, health and safety requirements on construction sites or social security reporting obligations. This basis applies alongside or instead of the contractual one where a specific legal requirement exists.
Consent is not the right basis for employees. Data protection authorities across the EU have consistently held that consent in the employment relationship is not freely given โ the employee is in a position of structural imbalance relative to the employer. Relying on consent alone to process attendance data is an error that invalidates the entire processing activity.
When Is Consent Actually Needed?
Consent is only required for processing that goes beyond the normal management of the employment relationship โ for example, sharing attendance data with third parties for statistical research, or for uses the employee could not reasonably anticipate.
For standard attendance tracking for payroll and working time management, consent is not required.
Geolocation: The Special Rules
Geolocation deserves separate treatment. Processing GPS location data of workers requires:
- A solid legal basis (legitimate interest or contractual/legal obligation โ not consent)
- Compliance with applicable national labour law on workplace monitoring
- A specific privacy notice explaining what is tracked, when, for how long and who can access the data
The Employer's Concrete Obligations
Privacy Notice for Employees (Art. 13 GDPR)
This is where many SMEs fall short. Before the attendance tracking system goes live, every employee must receive a clear and understandable notice explaining:
- Who the data controller is (your company)
- What data is collected (working hours, GPS location if applicable)
- For what purposes (attendance management, payroll, legal obligations)
- How long data is retained
- Who it is shared with (payroll consultant, software provider, any sub-processors)
- What rights the employee has (access, rectification, erasure, objection)
The notice must be provided in writing, with a signed acknowledgement of receipt. Telling employees verbally is not enough.
Data Retention: How Long Should You Keep the Data?
GDPR does not set a single retention period for attendance data. The principles of data minimisation and storage limitation apply (Art. 5 GDPR). In practice:
- Data needed for payslips should be retained for at least 5 years (statute of limitations for wage claims in most EU countries)
- Data required for tax and social security purposes follows fiscal retention periods โ typically 10 years for accounting records
- Geolocation data used solely to verify presence on site should not be kept longer than necessary โ in many cases a few months is sufficient
Define a written data retention policy and implement automatic deletion mechanisms. If you use SaaS software, check that your provider supports these features.
Who Is the DPO and When Is One Required?
The Data Protection Officer is mandatory only in specific cases (Art. 37 GDPR): public authorities, organisations that carry out large-scale systematic monitoring of individuals, or that process special category data on a large scale. Most SMEs running a standard attendance system are not required to appoint a DPO.
However, voluntary appointment can be useful if your organisation has a large workforce or uses continuous geolocation tracking.
Records of Processing Activities
Organisations with more than 250 employees must maintain a record of processing activities (Art. 30 GDPR). For smaller organisations, the obligation applies only where the processing is not occasional or presents risks to individuals' rights.
Attendance tracking with geolocation typically falls into this category. Maintain a record even if you are not strictly obliged to โ in the event of an inspection, it demonstrates a responsible approach.
Geolocation and Workplace Monitoring Under National Labour Law
Beyond GDPR, many EU member states have national rules on electronic monitoring of employees that add further requirements. In the UK, the ICO's Employment Practices Code sets expectations on transparency and proportionality. In Germany, employee works councils have co-determination rights over monitoring tools. In Italy, Article 4 of the Workers' Statute regulates remote monitoring technology.
The common thread across all jurisdictions: transparency and proportionality. Employees must know what is being tracked, and the tracking must be limited to what is strictly necessary for the stated purpose.
A geofencing attendance app that records only the moment of clocking in โ not continuous movement throughout the day โ is generally considered proportionate. Continuous GPS tracking of office-based staff throughout the working day is not.
What You Risk If You Are Not Compliant
GDPR fines are well known: up to โฌ20 million or 4% of global annual turnover, whichever is higher. In practice, supervisory authorities across the EU have issued significant fines to employers specifically for attendance and monitoring violations:
- Fines for installing geolocation systems on company vehicles without informing employees or obtaining required approvals.
- Enforcement action for retaining time and attendance data beyond the necessary period without legal basis.
- Orders against employers who failed to provide employees with a privacy notice before activating new monitoring systems.
Beyond financial penalties, a supervisory authority order can result in a suspension of the processing โ meaning your attendance system gets shut down until you rectify the situation.
How to Choose a GDPR-Compliant Tool
When evaluating attendance tracking software, always verify:
- EU data hosting: is data stored on servers within the EU/EEA? Does the provider offer adequate guarantees for any data transfers outside the EEA?
- Processor agreement: is the software provider a data processor under Art. 28 GDPR? They must be, and you need a written Data Processing Agreement (DPA) with them.
- Retention features: can you configure automatic deletion after a defined period?
- Access logs: who in your organisation can view attendance data? Does the system log access?
- Compliance support: does the provider help you prepare the employee privacy notice?
Pintime is designed with these requirements in mind: European infrastructure, DPA available on request, geofencing that records only the moment of clocking in โ not continuous tracking. Try it free during Beta to see how it fits your specific situation.
This article is for informational purposes only and does not constitute legal advice. For an assessment specific to your situation, consult a qualified employment lawyer or data protection specialist.