French Labour Law

Automated Working Time Tracking in France: Employer Legal Obligations

DAIRIA Law · Published · 10 min

Automated Working Time Tracking: What the Employer Must Prove

An employer that deploys an automated working time tracking system (badge readers, biometric clock-in devices, tracking software) must satisfy two regimes simultaneously: the evidential reliability required under employment law and the compliance imposed by the GDPR. In practical terms, Article L.3171-4 of the French Labour Code places on the employer the burden of providing the court with objective evidence of hours worked; the system must therefore be tamper-proof and documented. In parallel, any recording of personal clock-in data requires a legal basis, employee information and a limited retention period. A system that is technically effective but poorly framed in legal terms exposes the company to two-fold litigation: before the labour court (prud’hommes – employment tribunal) for overtime back-pay, and before the CNIL (the French data protection authority) for administrative sanctions. Below is the compliance procedure, the employer’s precise responsibilities and the typical disputes identified.

An automated working time tracking system does not fall under a single branch of law. It sits at the intersection of two distinct logics that do not pursue the same objective.

Employment law basis. Article L.3171-4 of the French Labour Code organises the burden of proof regarding actual working time. In the event of a dispute over overtime, the employer must provide “the elements likely to justify the hours actually worked.” A reliable automated record is precisely such an element. Conversely, the absence of a system, or a challengeable system, shifts the dynamics of the proceedings to the employer’s detriment.

GDPR basis. Clock-in data (arrival time, departure time, break time, possibly geolocation) constitute personal data. Their processing requires a legal basis within the meaning of the GDPR, prior information of the data subjects, a proportionate retention period and, in certain cases, an impact assessment.

The operational difficulty is that these two regimes sometimes pull in opposite directions: employment law encourages keeping detailed and durable evidence, while the GDPR requires minimisation and erasure. The point of balance must be built case by case.

The first recurring mistake in mid-sized companies is to believe that the employee’s consent must be obtained in order to install a clock-in system. This is incorrect, and even counterproductive.

Consent presupposes a free choice. Yet, within the relationship of subordination, the employee is never in a position to freely refuse a system imposed by the employer. The CNIL has long held that consent is not a valid basis in the context of the employment contract for processing operations imposed by the organisation. The relevant basis is the employer’s legitimate interest (organising and monitoring working time, fulfilling its statutory recording obligations) or, depending on the case, the legal obligation to record working time.

This characterisation is not cosmetic. It determines employees’ rights: on a legitimate interest basis, the employee retains a right to object that the employer must examine on a case-by-case basis, which must be anticipated in the internal documentation.

Practitioner’s verbatim. “The most frequent case is not the illegal clock-in system, it is the legal clock-in system whose legal basis declared in the record of processing activities is wrong. You read ‘consent’ whereas the processing is imposed. On the day of the CNIL inspection, that single word makes the entire record unreliable — and an unreliable record is a standalone breach of Article 30 of the GDPR.”

Proportionality: The Trap of Over-Collection and Biometrics

The minimisation principle requires collecting only the data strictly necessary for the purpose. A working time tracking system does not need to monitor the employee continuously or trace every movement.

Geolocation can never serve as the primary means of monitoring working time where another, less intrusive means exists. The French Supreme Court (Cour de cassation) has held that the use of a geolocation device to monitor working time is lawful only where such monitoring cannot be carried out by another means, even if that means is less effective. A declarative or badge-based clock-in system must therefore be preferred.

Biometrics (fingerprint, facial recognition for clocking in) fall under special category (sensitive) data. Their use for the mere management of working time is in principle disproportionate: the CNIL reserves biometrics for high-security stakes, not for recording hours. Deploying a biometric clock-in device “because it is more convenient” constitutes a characterised breach.

Key point: the evidential reliability sought under employment law never, on its own, justifies a disproportionate interference with private life. The employment court excludes evidence obtained by an unlawful process where its production is neither indispensable nor proportionate.

Information and Consultation: The Mandatory Prior Formalities

No automated tracking system may be put into service without prior formalities. Three obligations are cumulative.

  1. Individual information of employees. Each employee must be informed, before implementation, of the existence of the system, its purpose, the legal basis, the recipients of the data, the retention period and their rights (access, rectification, objection). A monitoring process not brought to the employee’s attention beforehand cannot be relied upon against them.

  2. Consultation of the CSE. The social and economic committee (comité social et économique – CSE, employee representative body) must be consulted prior to the decision to implement a means of monitoring employee activity. Failure to consult constitutes the offence of obstruction (délit d’entrave) and undermines the evidential value of the system.

  3. Internal GDPR documentation. Entry in the record of processing activities, definition of the retention period and, where applicable, a data protection impact assessment (DPIA) where the processing is likely to result in a high risk — a frequent scenario for systematic monitoring of working hours.

Document to produce, evidence to keep. The information notice given to employees (with signed acknowledgement or dated receipt), the minutes of the CSE consultation, and the extract from the record of processing activities. These three items form the defensive foundation in the event of litigation.

Retention Period: The Most Frequently Sanctioned Blind Spot

This is where the most common flaw lies. Companies configure the collection carefully, then forget to purge.

Clock-in data are used to establish payroll and to record working time. Their retention in the active database must be limited to the period necessary to manage payroll variables and to handle any short-term disputes. Beyond that, the data must be archived or deleted.

The interaction with employment law is delicate: claims for overtime back-pay are subject to a three-year limitation period (Article L.3245-1 of the French Labour Code). The employer therefore has a legitimate interest in retaining, in intermediate archiving (restricted access, not used on a daily basis), the recording elements for the applicable limitation period. However, keeping all clock-in data in the active database for years, accessible to any administrator, is disproportionate and constitutes a breach.

Counter-intuitive angle. Keeping too little is as dangerous as keeping data too long. An employer that purges its clock-in data after one year deprives itself of its own evidence in the event of a labour dispute over overtime claimed across three years. The retention period must be calibrated on the employment limitation period, not below it — otherwise GDPR compliance weakens the employment law position. This is exactly the opposite of the intuition “the less I keep, the better.”

Typical Disputes: Where the Employer’s Liability Is Decided

Three litigation scenarios recur systematically.

Labour tribunal dispute — overtime. The employee claims back-pay over three years. If the recording system is deemed unreliable (data modifiable without traceability, no certain time-stamping, system challenged in its implementation), the court may set it aside and rule solely on the elements produced by the employee. The technical and procedural quality of the system is decisive here.

Evidential dispute — unlawful evidence. The employer produces clock-in records to justify a sanction or a dismissal (lateness, absences). If the system was not brought to the employee’s attention, or if it was implemented without consulting the CSE, the evidence may be set aside. Evidence obtained from an unlawful system is admitted only where it is indispensable to the exercise of the right to adduce evidence and proportionate to the aim pursued — a criterion strictly assessed by the court.

CNIL dispute — GDPR breach. On-site or documentary inspection, an employee complaint, or a CSE report. The typically identified breaches: incorrect legal basis, over-collection, lack of information, excessive retention, absence of a DPIA. The sanction is standalone: it does not depend on any demonstrated individual harm.

Seven-Step Compliance Procedure

For a deployment or a remediation, the following sequence structures a provable compliance file.

  1. Map the purpose. Set out in writing what the system is for (recording time, managing payroll, monitoring attendance). A vague purpose makes everything else indefensible.
  2. Characterise the legal basis. Choose legitimate interest or legal obligation — never consent. Document the balancing test for legitimate interest.
  3. Apply minimisation. Rule out biometrics and geolocation unless a demonstrated necessity exists. Limit the fields collected to the strict recording of hours.
  4. Set the retention period. Active database limited to payroll management; intermediate archiving aligned with the three-year limitation period (L.3245-1).
  5. Inform and consult. Dated individual information notice + prior consultation of the CSE with minutes.
  6. Document on the GDPR side. Record of processing activities, DPIA if high risk, policy for handling rights (access, objection).
  7. Test technical reliability. Certain time-stamping, traceability of modifications, access restrictions. The system must withstand a labour tribunal challenge.

On each of these steps, the firm intervenes to audit the existing setup, identify breaches and secure the defensive documentation. Upstream, DAIRIA IA answers characterisation questions (legal basis, retention period, interaction with the limitation period) by citing the applicable texts; it equips the HR department to frame the file before our lawyers step in.

Frequently Asked Questions

Must a clock-in system be declared to the CNIL before installation?

No, the prior declaration regime disappeared with the GDPR. The obligation is now to enter the processing in the record of processing activities and, if the systematic monitoring of hours creates a high risk, to carry out an impact assessment (DPIA) kept internally and available in the event of an inspection.

Can an employee refuse to clock in?

On a legitimate interest basis, the employee has a right to object that the employer must examine in light of their particular situation. A systematic and unjustified refusal may nonetheless constitute disciplinary misconduct where the system is lawful and proportionate. Each objection is assessed individually.

Are clock-in records sufficient to prove overtime?

They are a central but not exclusive element. Under L.3171-4, the employer must provide objective evidence; a reliable and tamper-proof record carries significant weight. Conversely, a system whose data can be modified without traceability may be set aside by the court.

Can clock-in data be kept for five years “just in case”?

Not in the active database. Daily retention must be limited to payroll management. Intermediate archiving with restricted access may cover the three-year limitation period for wages (L.3245-1). Keeping all data accessible for five years is disproportionate.

Is facial recognition for clocking in permitted?

In principle no, for the mere recording of working time. Biometrics fall under sensitive data and their use is reserved for high-security stakes. Using a biometric process solely for managing hours is considered disproportionate.

What does an employer risk by not consulting the CSE?

Two cumulative risks: the offence of obstruction (délit d’entrave) and the unenforceability of the system as a means of evidence. A clock-in record from a system installed without prior consultation of the CSE may be set aside by the labour tribunal.

Does remote work change the working time recording obligations?

The recording obligation remains, but the arrangements must respect the private life of the employee at home. Monitoring cannot justify permanent surveillance or geolocation. A declarative system or a proportionate software-based clock-in is preferred.