Automatic Working Time Recording: What the Employer Must Prove
An employer that deploys an automatic working time recording system (badge readers, biometric clocks, tracking software) must satisfy two regimes simultaneously: the evidential reliability required by employment law and the compliance imposed by the GDPR. In concrete terms, Article L.3171-4 of the French Labour Code places on the employer the burden of providing the court with objective evidence of hours actually worked; the system must therefore be tamper-proof and documented. In parallel, any recording of personal clocking data requires a legal basis, employee information and a limited retention period. A system that is technically efficient but poorly framed in legal terms exposes the employer to a twofold dispute: before the employment tribunal (claims for overtime) and before the CNIL (France’s data protection authority, administrative sanction). Below is the compliance procedure, the employer’s precise responsibilities and the standard types of litigation identified.
The Twofold Legal Basis: Proof of Working Time and Data Protection
An automatic working time recording system falls under more than one branch of the law. It sits at the intersection of two distinct logics that do not pursue the same objective.
Employment law basis. Article L.3171-4 of the French Labour Code organises the burden of proof regarding effective working time (temps de travail effectif). In the event of a dispute over overtime, the employer must provide “the evidence capable of justifying the hours actually worked”. A reliable automatic record is precisely such evidence. Conversely, the absence of a system, or a contestable one, reverses the dynamics of the trial to the employer’s detriment.
GDPR basis. Clocking data (arrival and departure times, break times, any geolocation) constitute personal data. Their processing requires a legal basis within the meaning of the GDPR, prior information of the persons concerned, a proportionate retention period and, in certain cases, an impact assessment.
The operational difficulty lies in the fact that these two regimes sometimes pull in opposite directions: employment law encourages the retention of detailed and durable evidence, while the GDPR imposes minimisation and erasure. The point of balance must be built case by case.
Legal Basis for Processing: Legitimate Interest, Not Consent
The first recurring mistake in mid-sized companies is to believe that the employee’s consent must be obtained to install a time clock. This is incorrect, and even counterproductive.
Consent presupposes a free choice. Yet, within the relationship of subordination, the employee is never in a position to freely refuse a system imposed by the employer. The CNIL has long taken the view that consent is not a valid basis in the context of the employment contract for processing imposed by the organisation. The relevant basis is the employer’s legitimate interest (organising and monitoring working time, fulfilling its legal obligations to account for hours) or, depending on the case, the legal obligation to record working time.
This classification is not cosmetic. It determines employees’ rights: on a legitimate interest basis, the employee retains a right to object which the employer will have to examine case by case, something that must be anticipated in the internal documentation.
Practitioner’s note. “The most frequent case is not the illegal time clock, it is the legal time clock whose legal basis declared in the record of processing activities is wrong. You read ‘consent’ when the processing is in fact imposed. On the day of the CNIL inspection, that single word makes the entire record unreliable — and an unreliable record is a standalone breach of Article 30 of the GDPR.”
Proportionality: The Trap of Over-Collection and Biometrics
The minimisation principle requires collecting only the data strictly necessary for the purpose. A working time recording system does not need to track the employee continuously or trace every movement.
Geolocation can never serve as the principal means of monitoring working time where another, less intrusive means exists. The French Supreme Court (Cour de cassation) has held that the use of a geolocation device to monitor working time is lawful only where such monitoring cannot be carried out by another means, even a less effective one. A declarative or badge-based clocking system must therefore be preferred.
Biometrics (fingerprint, facial recognition for clocking in) constitute sensitive data. Their use for the mere management of working time is in principle disproportionate: the CNIL reserves biometrics for high-security stakes, not for accounting for hours. Deploying a biometric time clock “because it is more practical” constitutes a clear breach.
Key point: the evidential reliability sought under employment law never, on its own, justifies a disproportionate interference with privacy. The employment court will set aside evidence obtained by an unlawful process where its production is not indispensable and proportionate.
Information and Consultation: The Mandatory Prior Formalities
No automatic recording system may be put into service without prior formalities. Three obligations are cumulative.
-
Individual information of employees. Each employee must be informed, before implementation, of the existence of the system, its purpose, the legal basis, the recipients of the data, the retention period and their rights (access, rectification, objection). A monitoring process not brought to the employee’s attention beforehand cannot be relied upon against them.
-
Consultation of the CSE. The social and economic committee (comité social et économique, the employee representative body) must be consulted prior to the decision to implement any means of monitoring employees’ activity. Failure to consult constitutes an obstruction offence (délit d’entrave) and undermines the evidential value of the system.
-
Internal GDPR documentation. Entry in the record of processing activities, definition of the retention period, and where appropriate a data protection impact assessment (DPIA) where the processing is likely to result in a high risk — a frequent scenario for systematic monitoring of working hours.
Document to produce, evidence to keep. The information notice given to employees (with signature or dated acknowledgement of receipt), the minutes of the CSE consultation, and the extract from the record of processing activities. These three items form the defensive foundation in the event of litigation.
Retention Period: The Most Frequently Sanctioned Blind Spot
This is where the most frequent flaw lies. Companies configure the collection carefully, then forget to purge.
Clocking data serve to establish payroll and to account for working time. Their retention in the active database must be limited to the period necessary for managing payroll variables and handling any short-term disputes. Beyond that, the data must be archived or deleted.
The interaction with employment law is delicate: claims for overtime are time-barred after three years (Article L.3245-1 of the French Labour Code). The employer therefore has a legitimate interest in retaining, in intermediate archiving (restricted access, not used on a day-to-day basis), the accounting records for the duration of the applicable limitation period. But keeping all clocking data in the active database for years, accessible to any administrator, is disproportionate and constitutes a breach.
Counter-intuitive angle. Keeping too little is as dangerous as keeping it too long. An employer who purges its clocking data after one year deprives itself of its own evidence in the event of an employment tribunal dispute over overtime claimed over three years. The retention period must be calibrated on the employment law limitation period, not below it — otherwise GDPR compliance weakens the employment law position. This is exactly the opposite of the intuition that “the less I keep, the better”.
Standard Types of Litigation: Where the Employer’s Liability Is Decided
Three litigation configurations arise systematically.
Employment tribunal litigation — overtime. The employee claims arrears over three years. If the recording system is found to be unreliable (data modifiable without traceability, no reliable time-stamping, a system contested at the implementation stage), the court may set it aside and rule solely on the evidence produced by the employee. The technical and procedural quality of the system is decisive here.
Evidential litigation — unlawful evidence. The employer produces clocking records to justify a sanction or dismissal (lateness, absences). If the system was not brought to the employee’s attention, or if it was implemented without consulting the CSE, the evidence may be set aside. The production of evidence derived from an unlawful system is admitted only where it is indispensable to the exercise of the right to evidence and proportionate to the aim pursued — an assessment the court applies strictly.
CNIL litigation — the GDPR breach. On-site or documentary inspection, an employee complaint, or a report from the CSE. The breaches typically found: incorrect legal basis, over-collection, lack of information, excessive retention, absence of a DPIA. The sanction is standalone: it does not depend on any demonstrated individual harm.
Seven-Step Compliance Procedure
For a deployment or a regularisation, the following sequence structures a provable compliance file.
- Map the purpose. Set out in writing what the system is for (accounting for time, payroll management, attendance monitoring). A vague purpose makes everything else indefensible.
- Determine the legal basis. Rely on legitimate interest or legal obligation — never consent. Document the balancing test for legitimate interest.
- Apply minimisation. Rule out biometrics and geolocation unless necessity is demonstrated. Limit the fields collected to the strict recording of hours.
- Set the retention period. Active database limited to payroll management; intermediate archiving aligned with the three-year limitation period (L.3245-1).
- Inform and consult. Dated individual information notice + prior consultation of the CSE with minutes.
- Document on the GDPR side. Record of processing activities, DPIA if high risk, policy for managing rights (access, objection).
- Test technical reliability. Reliable time-stamping, traceability of modifications, restriction of access. The system must withstand a challenge before the employment tribunal.
At each of these stages, the firm intervenes to audit the existing setup, identify breaches and secure the defensive documentation. Upstream, DAIRIA AI answers classification questions (legal basis, retention period, interaction with limitation periods) by citing the applicable texts; it equips the HR department to frame the file before our lawyers step in.
Frequently Asked Questions
Must a time clock be declared to the CNIL before installation?
No, the prior declaration regime disappeared with the GDPR. The obligation is now to enter the processing in the record of processing activities and, if systematic monitoring of hours generates a high risk, to carry out an impact assessment (DPIA) kept internally and available for inspection.
Can an employee refuse to clock in?
On a legitimate interest basis, the employee has a right to object which the employer must examine in light of their particular situation. However, a systematic and unjustified refusal may constitute a disciplinary breach where the system is lawful and proportionate. Each objection is assessed individually.
Are clocking records sufficient to prove overtime?
They are a central but not exclusive item. Under L.3171-4, the employer must provide objective evidence; a reliable and tamper-proof record carries significant weight. Conversely, a system whose data can be modified without traceability may be set aside by the court.
Can clocking data be kept for five years “just in case”?
Not in the active database. Day-to-day retention must be limited to payroll management. Intermediate archiving with restricted access may cover the three-year limitation period for wages (L.3245-1). Keeping all data accessible for five years is disproportionate.
Is facial recognition for clocking in permitted?
In principle no, for the mere recording of working time. Biometrics are sensitive data and their use is reserved for high-security stakes. Using a biometric process solely for managing hours is regarded as disproportionate.
What does an employer risk by not consulting the CSE?
Two cumulative risks: an obstruction offence (délit d’entrave) and the system’s inadmissibility as a means of proof. A clocking record derived from a system installed without prior consultation of the CSE may be set aside by the employment tribunal.
Does remote working change the obligations to record time?
The obligation to account for time remains, but the arrangements must respect the privacy of the employee at home. Monitoring cannot justify permanent surveillance or geolocation. A declarative system or a proportionate software-based clocking method is preferred.