Check 1: working hours are personal data and have to be treated as such
Working hours can always be assigned to a specific person. That makes details such as the start of work, breaks or overtime personal data within the meaning of the GDPR and of the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Personal data means all information relating to an identified person or an identifiable natural person. Because working time (the information) is linked to the employee (the identified person), it is therefore personal data.
What matters here:
The fact that working time data is personal does not mean that processing it is problematic. Data protection does not mean collecting as little data as possible at any cost, but lawful, purpose-bound processing.
Anyone who understands that working hours are not a special case under data protection law, but part of everyday data processing in the employment relationship, has already settled the first key point.
Check 2: data protection compliant time tracking under employment law
Under Section 16(2) of the German Working Hours Act (Arbeitszeitgesetz, ArbZG) employers are legally obliged to record overtime as well as work on Sundays and public holidays. That makes the introduction of a system for time tracking a legal requirement.
Section 26(1) of the German Federal Data Protection Act likewise legitimises recording working hours in order to carry out the employment relationship. But a law on recording working time does not (yet) exist, and so there is no requirement tailored to this particular situation.
How that recording takes place is not laid down anywhere. Whether it is done in the classic way on a timesheet, via software or an app, or with a time clock, is up to each business.
Check 3: using time tracking data correctly
As mentioned above, recording working hours is governed not only by employment law, but also by administrative law – more precisely: by the German Federal Data Protection Act.
Section 1 of the German Federal Data Protection Act states: “The purpose of this Act is to protect individuals against impairment of their right to privacy through the handling of their personal data.” This means that the German Federal Data Protection Act applies when working hours are recorded (BDSG) and protects the recorded data against misuse or unlawful disclosure.
| Area of control | Principle & requirement under the BDSG | How clockin implements it |
|---|---|---|
| Physical and system access control | Access to systems in which personal data is processed must be limited. It must also be ensured that only authorised people are given access to this data. | Your data is held on German, GDPR compliant servers. |
| Disclosure control | The BDSG requires that personal data cannot be read, copied, altered or removed without authorisation. Alongside restricting access, manipulation by unauthorised people must also be prevented. | All your data is protected by a login and can only be viewed by authorised people. |
| Input control | It must be traceable at all times who entered, changed or deleted personal data. Changes must not be made anonymously or without being attributed to a person. | Every change to your recorded hours can still be traced afterwards. |
| Availability control | Personal data must be protected against loss or destruction. That includes technical and organisational measures to ensure the data remains available. | Your data is stored securely on a server. |
| Further processing | Data collected in order to record working hours may not, without further agreement, be used for purposes other than checking working hours and billing. | Recorded working hours are used exclusively for working time tracking and billing. |
Important: continuous monitoring of an employee is not legally permitted!
The data protection authorities of Rhineland-Palatinate and Lower Saxony state that a spot check of the recorded data on a monthly basis can be carried out without concern. Viewing individual entries via software, by contrast, has to be expressly set out in the staff agreement.
.png)
Check 4: storing the data correctly
Under Section 16(2) of the German Working Hours Act employers are obliged to keep the records of working hours currently required by law (overtime and work on Sundays and public holidays) for at least two years. However, this data may only be kept for as long as it is actually necessary.
That means: apart from the retention obligation described above, a ten-year retention obligation applies only for tax law reasons. Other attendance data, beyond the data collected as required by law, should be kept for up to two years.
Check 5: making the most of digital time tracking
Fear of being monitored runs high for many people, particularly when it comes to digital working time tracking. But as we have seen above, there are statutory requirements for time tracking that are meant to prevent misuse of the data. So as long as all legal rules are followed and the right to inspect the data, plus co-determination by a works council where applicable, is guaranteed, there is nothing to worry about.
The great advantage of digital time tracking is that it makes it possible to deliver exactly what is so widely called for: greater flexibility through mobile time tracking, including via an app on your phone, transparency about the hours worked between employer and employee, and more efficient work processes thanks to the automation of certain bureaucratic steps.


.png)
.avif)
.avif)