CheckedSourced, dated, and no one pays us

Time Tracking / People

Time Tracking · People

Time Records as Employment Records

These are personal data with retention, access and accuracy obligations. The operational half of what that means, and the settings people forget to configure.

Facts checkedAugust 2026 For: Decision-makers

Time data is treated as operational reporting until the moment it is evidence — in a pay dispute, an inspection, a claim, or a data access request.

Requirements differ substantially by country, and within some countries by state or province. What follows is the operational half: what these obligations generally mean for how a system is set up. The specifics for your jurisdictions need checking there.

For a vendor-side perspective on online timesheets, see further details from Monitask.

What they are

A record of hours worked by an identifiable person. Which makes them two things at once.

An employment record, with retention requirements in most places, and an obligation to be accurate.

Personal data, with purpose limitation, minimisation, access rights and retention limits.

Both apply to the same rows.

What that means for the system

Retention, set and configured

Set a period per data type, from the applicable rules.

Configure it in the system, not only in a policy document. The common failure is a correct policy that was never implemented, leaving the system's default — usually indefinite — as what actually applies.

Consider more than one clock. The hours record may have one requirement; detailed activity capture from automatic tracking is more sensitive and usually warrants a shorter one. See automatic tracking.

And too long is its own exposure. Data kept indefinitely because nobody decided is a liability, not caution.

Access for the individual

People generally have a right to their own records. Building that in is cheaper than assembling it on request.

And it improves the data, because people correct their own entries when they can see them.

An audit trail on corrections

Amended time records are routine and legitimate. Amended records with no trace of who changed what, and when, are a problem — in a dispute, and for the credibility of the whole dataset.

Purpose, stated and honoured

A legal requirement in many places and the operational foundation regardless.

Collected for scheduling, payroll and operational management. Using them for something else may be permissible and should be anticipated rather than discovered. See what time data must never be used for.

Minimisation

Collect what the purpose needs.

A system that also captures application use, location or activity because the vendor offers it has expanded the obligation without expanding the benefit. See choosing a tool.

Access control internally

Who inside the organisation can see an individual's records, and is that limited to people who need to.

Detailed automatic capture in particular should not be broadly visible.

Third parties and location

If the system is hosted, who else holds the data and where.

Cross-border transfer has its own requirements in several frameworks, and distributed teams make this normal rather than exceptional.

Where organisations commonly get it wrong

Not jurisdiction-specific claims — recurring patterns worth checking against your own rules.

Records that do not reflect actual hours. Work outside recorded time, rounding that consistently favours one side, breaks recorded as taken when they were not.

Retention configured nowhere. Policy exists, system default applies.

No route for an individual to see their own data.

Corrections with no audit trail.

Leavers. Records still needed after someone departs. Deleting on exit and keeping forever are both wrong; the middle is a decision to make deliberately.

And monitoring data collected under a timekeeping justification, which is where the obligations diverge most sharply.

The overlap with doing it well

The compliance requirements and the operational ones point the same way, which is convenient.

Complete records are needed for payroll correctness and for any useful analysis.

An audit trail on corrections is what lets you find out why a number moved. For broader independent background, see ICO guidance on monitoring workers.

Individual access improves accuracy.

Stated purpose is what makes people record honestly.

Minimisation keeps the dataset focused on what you will actually use.

An organisation that keeps time records well for operational reasons has most of the compliance position already.

A checklist

  • [ ] Retention period set per data type and configured in the system
  • [ ] Individuals can see their own records
  • [ ] Audit trail on corrections
  • [ ] Purpose stated in writing and communicated
  • [ ] Only data the purpose requires is collected
  • [ ] Internal access limited to those who need it
  • [ ] Hosting location and third parties documented
  • [ ] Leaver policy decided
  • [ ] Practices checked against the rules for every jurisdiction your people are in

For small teams and solo

Lighter, and not nothing.

If you employ anyone, the obligations apply at any size.

A spreadsheet is a record, with the same retention and accuracy expectations as a platform.

Solo, tracking only yourself, most of this does not apply — until you track a contractor or an employee.

The short version

Time records are employment records and personal data at once, and both sets of obligations apply.

Configure the retention period in the system, because a policy that was never implemented leaves the default in force.

Build individual access in — it is an obligation in many places and it improves accuracy.

Keep an audit trail on corrections, which matters in a dispute and for credibility generally.

And collect only what the purpose needs, because capture the vendor offers is obligation you took on for nothing.