GDPR & Time Tracking: Legal Basis, Location Data, Retention

When you log working hours — your own, your employees', or contractors' — privacy rules apply. The GDPR affects time tracking more than most business owners realise: names, working times, and especially location data are all personal data. This page explains the legal basis for recording hours, when location data is permitted, and how long you may keep records.

Not legal advice — consult a tax adviser or privacy specialist for your specific situation.

Why the GDPR Applies to Time Tracking

Once you link working times to a name or identifiable person, you are processing personal data. That applies to a simple spreadsheet with names and to automated time-tracking software alike. If you are a UK-based business processing EU residents' data, or an EU-based business, you must comply with GDPR principles and be able to demonstrate a valid legal basis.

Example: you are an IT consultant recording which employee works on which project and for how many hours. That combination (person, time, activity) is a processing activity under the GDPR, and you are the data controller.

Choosing the Right Legal Basis

The GDPR provides six lawful bases. In practice, three are relevant for time tracking:

Legal Basis When It Applies Key Point
Performance of a contract Payroll processing, invoicing clients Most common basis for employers
Legal obligation CBA requirements, tax administration Also covers construction CBA time tracking
Legitimate interests Project management, capacity planning Requires a balancing test; employees may object

Consent is rarely a suitable basis for employers: the power imbalance makes genuinely free consent problematic. Document your chosen basis in your records of processing activities.

Location Data: When Is It Allowed?

GDPR shield protecting personal data

Modern time-tracking systems can capture GPS location or IP addresses — useful for field workers or remote staff, but also sensitive data.

When location data is permitted:

  • There is a demonstrable, proportionate reason (e.g. site safety or verifying presence at a client location).
  • Employees have been clearly informed in advance — ideally via a privacy notice and employment contract.
  • You only record during working hours, not continuously.

When location data is not permitted:

  • Tracking outside working hours, even on employer-owned devices.
  • When the purpose can be achieved without location data (necessity test).
  • When you cannot identify an explicit legal basis.

Explore PrikKlokPlus privacy settings to see how you can configure time tracking to collect only what is necessary.

Retention Periods: How Long Can You Keep Time Records?

The GDPR sets no fixed retention period. Data may only be kept for as long as is demonstrably necessary for the original purpose.

Two frameworks are relevant in practice:

  1. Tax retention obligation: Tax authorities generally require payroll records to be kept for seven years. Timesheets that underpin salary calculations fall under this requirement. Check the guidance of your national tax authority for the current rules.
  2. Project administration: Hours invoiced to clients support your invoices. Keep these for seven years for tax purposes, then delete or anonymise the personal data once the period expires.

Freelancers tracking hours against the 1,225-hour criterion for self-employment tax relief must retain timesheets as supporting evidence. The seven-year rule applies here too.

Practical rule of thumb: set a retention period for each data category, record it in your processing register, and set up an automatic deletion or anonymisation process.

What Else You Need to Arrange

Inform Your Staff

A transparent privacy notice is required under the GDPR. Explain which data you record, for what purpose, how long you keep it, and who staff can contact with questions.

Data Processing Agreement with Your Software Provider

Using cloud-based time-tracking software? Your provider processes personal data on your behalf. Under the GDPR, you are required to sign a data processing agreement. Check that your provider's servers are located within the EU to avoid issues with international data transfers.

Data Protection Officer (DPO)

SMEs may be required to appoint a DPO — for example, if core activities involve large-scale, systematic monitoring of individuals or large-scale processing of special category data. Check with your national supervisory authority whether this applies to you.

For guidance on using generative AI tools in a GDPR-compliant way, see GDPR & Generative AI: What Freelancers Must Know.

Conclusion

Time tracking and the GDPR go hand in hand. Choose a clear legal basis, be cautious with location data, observe retention periods, and document everything in a processing register. For freelancer-specific time tracking advice, Time tracking as a freelancer: 5 tips for accurate invoicing offers practical guidance.

Not legal advice — consult a tax adviser or privacy specialist for your specific situation.


Frequently Asked Questions

As a freelancer, do I need to comply with the GDPR for time tracking? Yes — as soon as you record working times linked to another identifiable person (a client, employee, or subcontractor), you are processing personal data and the GDPR applies. Your own hours as a sole trader are not covered.

How long must I retain timesheets? The GDPR sets no fixed term, but tax retention obligations generally require you to keep records for seven years if timesheets form part of your financial administration. Delete or anonymise personal data once that period expires.

Can I record employees' GPS location via time-tracking software? Only if you have a valid legal basis, the processing is proportionate, employees have been informed in advance, and you do not record outside working hours. Continuous tracking without demonstrable necessity is not permitted.

Do I need a data processing agreement with my time-tracking provider? Yes. If your software provider processes personal data on your behalf — standard with cloud solutions — the GDPR requires a data processing agreement to be in place. Also verify that servers are located within the EU.

When is a Data Protection Officer mandatory for an SME? A DPO is required when core activities involve large-scale, systematic monitoring of individuals or large-scale processing of special category data. Consult your national supervisory authority for a definitive assessment.


Set up GDPR-compliant time tracking today

PrikKlokPlus combines time tracking, project management, and invoicing in one platform — with the privacy settings you need to stay compliant.

Start free with no commitment