GDPR-compliant time tracking combined with access control systems requires compliance with strict legal requirements, in particular the GDPR and the Working Time Act. Companies must ensure that personal data is processed for a specific purpose, transparently, and with appropriate technical and organisational measures. Biometric methods are permitted only under narrow conditions and require careful consideration of proportionality.

Independent expertise for your access control and working time recording

The obligation to track working time and the strict requirements of the GDPR present companies with complex challenges. A legally compliant integration of time tracking and access control requires precise planning and in-depth expertise, to minimise risk and maximise efficiency.

Key Takeaways

  • Time tracking has been mandatory since the ECJ and Federal Labour Court rulings and must be carried out in a GDPR-compliant way, with working time counted as personal data.
  • Integrating time tracking and access control offers efficiency but carries data protection risks around data minimisation and purpose limitation. Biometric methods are permitted only under strict conditions.
  • Independent planning and consulting by experts such as PLANATEL® is decisive for implementing manufacturer-independent, legally compliant, future-proof systems and involving the works council at an early stage.

The digitalisation of the world of work brings numerous benefits, but also growing requirements for data processing. Time tracking and access control at companies in particular have moved into focus since the 2019 European Court of Justice (ECJ) ruling and the 2022 Federal Labour Court (BAG) decision. Employers are obliged to systematically record their employees' working time, to ensure occupational health and safety and to guarantee compliance with maximum working hours and rest periods. At the same time, these processes must meet the strict requirements of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). The challenge lies in implementing a system that is both functional and legally sound. PLANATEL® supports you as an independent planning partner in mastering this complexity and developing tailored, legally compliant solutions.

Article image: GDPR-compliant time tracking access - hero

The legal framework for time tracking in Germany is decisively shaped by the ruling of the European Court of Justice (ECJ) of 14 May 2019 (C-55/18) and the subsequent decision of the Federal Labour Court (BAG) of 13 September 2022 (1 ABR 22/21). These rulings oblige employers in Germany to set up an objective, reliable and accessible system to record the entire daily working time of their employees. The aim is to protect employee rights, in particular compliance with maximum working hours and rest periods under the Working Time Act (ArbZG).

At the same time, time tracking is subject to the strict requirements of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). Working time is personal data within the meaning of Art. 4(1) GDPR, since it can be attributed to an identified or identifiable natural person. This means its processing may only take place on a valid legal basis (e.g. Art. 6(1)(b) or (c) GDPR in conjunction with section 26(1) BDSG), and the principles of data processing (such as lawfulness, transparency, purpose limitation and data minimisation) must be strictly observed. Failure to comply with these provisions can lead not only to employment law disputes but also to significant fines. Planning a time tracking system must therefore integrate both legal areas from the outset, to ensure comprehensive legal compliance.

Integrating time tracking and access control: opportunities and risks

Linking time tracking and access control offers companies considerable efficiency potential. An integrated system makes it possible to automatically record the start and end of work when entering or leaving the building or specific areas. This reduces administrative effort and increases data accuracy. Access control systems govern who is granted access, when and where, and are thus an essential part of physical security. The VdS guidelines for access control systems (e.g. VdS 2358:2009-10) set minimum requirements here that must be considered during planning.

However, combining both functions also carries specific data protection risks. Recording access data can create movement profiles of employees, which represents a potential form of surveillance and can violate the principle of data minimisation. It must be clearly defined which data is recorded for which purpose, and processed accordingly. Strict purpose limitation is essential here: access data should primarily serve security, and time-tracking data should serve documentation of working time. Mixing the two, or using them for other, not explicitly communicated purposes, is impermissible. The challenge lies in designing a system that provides the necessary functionality without disproportionately restricting employees' personal rights. This requires a detailed needs analysis and careful weighing of the technical possibilities against the legal requirements.

Data minimisation and purpose limitation: core principles of the GDPR

The principles of data minimisation (Art. 5(1)(c) GDPR) and purpose limitation (Art. 5(1)(b) GDPR) are central pillars of legally compliant time tracking and access control. Data minimisation means that only personal data strictly necessary for the respective purpose may be collected and processed. In the context of time tracking, this is generally the start, end and duration of working time, as well as breaks. Additional information not directly related to working time documentation, such as precise location outside company premises (e.g. via GPS in mobile time tracking), requires separate, voluntary consent and a clear justification of proportionality.

Purpose limitation requires that data may only be processed for the purposes for which it was originally collected. Where access data is recorded to manage physical security, it may not simply be used to monitor employee performance or conduct. Such use would constitute repurposing and a breach of the GDPR. Companies must therefore develop a clear concept that separates the various purposes of data collection and ensures that data is not used for incompatible purposes. This requires transparent information to employees about the nature, scope and purpose of data processing (Art. 13/14 GDPR) and, where applicable, obtaining consent, particularly where data is to be processed for purposes going beyond the fulfilment of the employment contract or statutory obligations.

Article image: GDPR-compliant time tracking access - mid

Technical and organisational measures (TOMs) for data security

Ensuring data security is a fundamental aspect of GDPR-compliant time tracking and access control, anchored in Art. 32 GDPR. Companies must implement appropriate technical and organisational measures (TOMs) to guarantee the confidentiality, integrity, availability and resilience of the systems and services. These include, among others:

  • Entry control: measures that prevent unauthorised persons from gaining access to data processing facilities (e.g. physical security of server rooms, access control systems for sensitive areas).
  • Access control: ensuring that only authorised personnel can access personal data (e.g. role and permission concepts, strong authentication).
  • Transfer control: protection against unauthorised transfer of data during transmission or storage (e.g. encryption, secure transmission protocols).
  • Input control: logging of data entries, changes and deletions, to ensure traceability (audit trails).
  • Availability control: protection against data loss or destruction (e.g. regular backups, redundant systems, contingency plans).

Certification to ISO 27001, the international standard for information security management systems (ISMS), can be a strong indicator of compliance with high security standards and provides a solid basis for data protection. The VdS 10010 guidelines also offer a practical framework, specifically for small and medium-sized companies, for implementing GDPR requirements. PLANATEL® supports the design of these TOMs, to establish a robust, legally compliant security architecture.

Biometric time tracking and access control: limits and alternatives

The use of biometric data such as fingerprints, facial recognition or iris scans for time tracking and access control is particularly sensitive from a data protection perspective. Biometric data is classified as a special category of personal data under Art. 9(1) GDPR, and therefore enjoys enhanced protection. Its processing is, in principle, prohibited unless one of the exceptions in Art. 9(2) GDPR applies. In the context of an employment relationship, this is usually the explicit, voluntary consent of the data subject, or the necessity to fulfil employment law obligations, provided this is proportionate.

Supervisory authorities and labour courts tend to regard biometric time tracking as disproportionate in most cases, since equally suitable but milder means are generally available. Arguments such as preventing "buddy punching" (a colleague clocking in for someone else) are often insufficient to justify the use of biometric methods. Employers may not compel employees to use biometric systems and must always offer data-protection-friendly alternatives. These alternatives include RFID chips, transponders, PIN entry, smartphone apps, or web-based time clocks. PLANATEL® provides manufacturer-independent advice on selecting systems that meet both security requirements and strict data protection requirements, without taking on unnecessary risk through the use of sensitive biometric data.

The role of the works council and transparent communication

When introducing and designing time tracking and access control systems, the works council plays a decisive role. Under section 87(1) no. 6 of the Works Constitution Act (BetrVG), the works council has a comprehensive co-determination right in the introduction and use of technical facilities intended to monitor employee behaviour or performance. Since time tracking systems potentially enable such monitoring, a works agreement with the works council is mandatory. This agreement should regulate in detail:

  • The purpose of the data collection (e.g. payroll, compliance with the Working Time Act).
  • Exactly which data is recorded.
  • Who has access to the data and for what purposes.
  • Retention periods and deletion concepts.
  • Data security measures.
  • Employees' rights to information and correction.

Open, transparent communication with employees is also essential. They must be comprehensively informed about how the system works, the type of data collected, the purpose of processing, and their rights. This builds trust and acceptance for the new processes. Early involvement of the works council and a clear information policy contribute significantly to a smooth, legally compliant implementation and avoid later conflicts or legal disputes. PLANATEL® supports you in developing concepts and moderating these processes, to ensure a smooth introduction.

Selecting and implementing legally compliant systems: the PLANATEL® approach

Selecting and implementing a time tracking and access control system that meets both operational requirements and complex legal requirements is a demanding task. Many companies face the challenge of finding the right solution among a multitude of providers and technologies. Manufacturer-independent, independent consulting is decisive here, to avoid manufacturer dependency and identify the objectively best solution. PLANATEL® has offered exactly this expertise since 1992.

Our approach begins with a detailed as-is survey and needs analysis, in which we precisely analyse your specific requirements for time tracking and access, your company structure, and existing processes. Building on this, we develop a target concept that takes account of all relevant aspects, from functionality through data security to legal compliance under the GDPR and the Working Time Act. We prepare a detailed plan covering technical specifications and organisational measures. We then accompany you through the tendering and award process, evaluate bids objectively, and select certified installers together with you. Our financial independence guarantees that our recommendations serve solely your best interest. We plan maintenance concepts and support you with implementation, acceptance and invoice verification, to ensure the system meets your expectations and all legal requirements.

The landscape of working time regulation and data protection is dynamic. The legislature continues to work on a concrete design for the statutory obligation to record working time electronically, with a new Working Time Act expected for 2026 that would make electronic recording the standard. Companies must therefore remain flexible and continuously adapt their systems to new legal requirements. This requires not only technical adjustments but also regular review of internal processes and documentation.

Best practices for sustainable legal compliance include:

  • Regular audits: review, at fixed intervals, whether your time tracking and access system complies with the GDPR and the Working Time Act.
  • Staff training: raise awareness among all those involved on data protection topics and the correct use of the systems.
  • Updating documentation: keep your record of processing activities (Art. 30 GDPR) and your privacy notices always up to date.
  • Proactive risk management: carry out data protection impact assessments (DPIAs) under Art. 35 GDPR, particularly when introducing new technologies or making significant changes to existing systems.
  • Seeking expert advice: consult independent specialist advisers such as PLANATEL® for complex questions, to avoid legal pitfalls and implement future-proof solutions.

Through forward-looking planning and continuous adjustment, companies can use the obligation to track working time as an opportunity to optimise processes, create transparency, and strengthen employee trust. PLANATEL® stands by your side as a reliable partner with over 34 years of experience, to help you successfully master these challenges.

Article image: GDPR-compliant time tracking access - bottom

Next Step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de

Frequently Asked Questions

Why is time tracking relevant to the GDPR at all?

Because working time is personal data, its collection and processing are subject to the strict requirements of the GDPR and the BDSG. This includes the need for a legal basis, compliance with data minimisation, purpose limitation and transparency, and the implementation of appropriate technical and organisational measures (TOMs) to protect this data. Non-compliance can lead to substantial fines and legal consequences.

What data may be collected during time tracking?

In principle, only the data necessary for the purpose of working-time documentation may be collected. This generally includes the start and end of the daily working time, the duration of breaks, and overtime. Additional data not directly related to working-time documentation, such as GPS location data in mobile time tracking, requires separate, voluntary consent from employees and must be proportionate. The principle of data minimisation is the guiding rule here.

How long may time-tracking data be stored?

The storage period for time-tracking data must comply with the principle of storage limitation (Art. 5(1)(e) GDPR). Data may only be stored for as long as necessary for the original purpose, or as required by statutory retention periods. Once the purpose no longer applies, or the periods expire, the data must be deleted without delay. A clear deletion concept is part of legally compliant data processing and should be set out in a works agreement.

What are the consequences of non-GDPR-compliant time tracking?

Breaches of the GDPR in time tracking can have far-reaching consequences. These include high fines of up to 20 million euros or 4% of global annual turnover, employment law disputes with employees, reputational damage, and corrective measures ordered by data protection supervisory authorities. Faulty payroll calculations and a loss of trust within the company can also result. Independent review and consulting helps to proactively minimise such risks.

Can time tracking be delegated to employees?

Yes, employers can delegate the task of time tracking to their employees, so that they document their working time in the system on their own responsibility. Overall responsibility for correct, legally compliant time tracking, however, remains with the employer. The employer must ensure that the system is objective, reliable and accessible, and that employees are trained and informed accordingly. Regular monitoring of compliance is essential.

Is time tracking really mandatory in Germany?

Yes, since the 2019 ECJ ruling and the 2022 BAG decision, employers in Germany are obliged to systematically record their employees' working time. This serves to protect employee rights and ensure compliance with the Working Time Act.

May biometric data be used for time tracking?

The use of biometric data is highly sensitive from a data protection perspective. It is only permitted under strict conditions, requires voluntary consent from employees, and must be proportionate. Data-protection-friendly alternatives are generally preferred.

What role does the works council play in introducing time tracking systems?

The works council has a comprehensive co-determination right in the introduction of technical monitoring facilities, which includes time tracking systems. A works agreement is mandatory to establish the framework conditions for data collection.

What does "purpose limitation" mean in the context of time tracking?

Purpose limitation means that the data collected may only be processed for the specific purpose for which it was originally recorded. Time-tracking data may therefore not simply be used for other purposes, such as performance or conduct monitoring.

Sources and further information

  • accenon.de
  • proliance.ai
  • timr.com
  • weka.de
  • clockodo.com