The paper timesheet had one undeniable advantage: it was invisible to data-protection law. No one asked where the data lived, who had access, or whether retention rules were followed. Switching to an app changes that overnight.
The good news: GDPR-compliant is doable. The important news: you have to design for it consciously — not as an afterthought.
What counts as "personal data" in time tracking?
Once you can record who worked when, for how long, on which site, you have personal data. That's true regardless of whether the data lives on paper, in Excel or in an app — the only difference is visibility to supervisory authorities.
Concrete data points typically captured:
- Employee name
- Start, end, breaks of a shift
- Location (site / address)
- Possibly the activity or task performed
- Possibly the employee's comments
Each one is GDPR-relevant.
"Personal data" is interpreted broadly. Just a name plus "worked today" is personal. You don't need a national-insurance number or bank details to fall within scope.
The processing register — what must be in it
Every employer with at least one staff member must keep a register of processing activities (RoPA). It's not bureaucracy for its own sake — it's the foundation when a supervisory authority asks: "what are you doing with the data?"
For digital time tracking, the RoPA must cover at minimum:
- Purpose of processing: "Recording working time per Working Hours Act and § 16(2) ArbZG"
- Legal basis: Art. 6(1)(b) GDPR (contract performance) plus § 26 BDSG (employment relationship)
- Categories of data subjects: employees
- Categories of personal data: name, working time, breaks, location, activity
- Recipients: software vendor (as processor), possibly tax adviser
- Third-country transfers: must be denied, otherwise standard contractual clauses apply
- Retention periods: typically 6 years after end of employment (tax-law retention)
- Technical and organisational measures (TOM): encryption, access control, backup concept
The AVV with the software vendor — what really must be in it
The moment you use cloud software for time tracking, the vendor becomes your processor. You need a data processing agreement (AVV) under Art. 28 GDPR. Most vendors have a standard AVV — you should still review it.
These five points are critical:
- Server location: EU/EEA is required, otherwise standard contractual clauses plus a transfer-impact assessment apply. US servers without safeguards have been legally risky since Schrems II.
- Sub-processors: which third parties does the vendor use? Cloud hoster, email delivery, backups — all must be disclosed and you must be able to object.
- Deletion concept: what happens to your data when the contract ends? Deletion or return — within what timeframe? 30 days is industry standard.
- Breach notification: the vendor must notify you without delay so you can meet the 72-hour deadline towards the supervisory authority.
- Audit rights: you must have the right to verify the vendor's TOMs — directly or via a recognised audit scheme (e.g. ISO 27001).
Most fines I see don't come from a missing AVV — they come from AVVs nobody read. Template signed, drawer, done.
Access concept — who sees what?
Data protection isn't only about the outside. Internally, you need a role-based access concept:
- Employees see their own timesheets — not their colleagues'
- Foremen see their team's hours — not other teams'
- Management sees everything — but accesses are logged
- Payroll exports anonymised aggregates for billing
Without this concept, the "pizza effect" is guaranteed: at some point, an employee sees data they shouldn't. That's a breach — and it's reportable.
Location capture in time tracking is extremely sensitive under data protection law. Continuous GPS tracking without explicit consent is unlawful. Site-based assignment ("employee X was on site Y") is fine if the employee is informed. Permanent movement profiles are not — even "only during working hours".
Meistify hosts on German servers, AVV available on request.
We host in Frankfurt am Main, the AVV is plainly worded with no legal small print. Plus: no GPS requirement, role-based access, configurable retention. 14-day free trial.
Try Meistify for freeInform employees — the mandatory step
Before rolling out the app, your employees must be informed. It's not just polite — it's required (Art. 13 GDPR).
Three things belong in the notice:
- Which data is collected and for what purpose
- Who has access (role-based) and where the data lives
- Which rights the employee has (access, rectification, erasure)
Consent, by the way, is not a robust legal basis in employment relationships — the legal basis is the employment relationship itself (§ 26 BDSG). Still, document that the notice was provided.
Conclusion: GDPR is work, but not rocket science
If you keep a RoPA, sign a clean AVV, implement a role-based access concept and inform your employees, you've covered 95 % of typical risks. The remaining 5 % are edge cases (foreign employees, authority requests, audits) — you can address those when they arise.
More important than perfect compliance: act in a documented way. When the supervisory authority asks what you did, the worst answer is "don't know". The second-worst is "we hadn't realised". Both are avoided by a RoPA.