French Labour Law

Automatic Working Time Tracking in France: Employer Legal Obligations

DAIRIA Law · 2026-09-08 · 10 min

Automatic Working Time Tracking: What the Employer Must Be Able to Prove

An employer that rolls out an automatic working time tracking system (badge readers, biometric clocking devices, tracking software) must satisfy two regimes at the same time: the evidentiary reliability required by employment law and the compliance imposed by the GDPR. In practical terms, Article L.3171-4 of the French Labour Code places on the employer the burden of providing the court with objective data on the time actually worked; the system must therefore be tamper-proof and documented. In parallel, any recording of personal clocking data requires a legal basis, information to employees, and a limited retention period. A technically high-performing but legally poorly framed system exposes the employer to dual litigation: before the labour court (prud’hommes, France’s employment tribunal — claims for overtime back-pay) and before the CNIL (France’s data protection authority — administrative fines). Below are the compliance procedure, the employer’s precise responsibilities and the typical litigation scenarios identified.

An automatic working time tracking system does not fall under a single branch of law. It sits at the intersection of two distinct logics that do not pursue the same objective.

Employment-law foundation. Article L.3171-4 of the French Labour Code organises the burden of proof regarding effective working time. In the event of a dispute over overtime, the employer must provide “the evidence capable of justifying the hours actually worked.” A reliable automatic record is precisely that evidence. Conversely, the absence of a system, or a challengeable system, shifts the dynamics of the case to the employer’s disadvantage.

GDPR foundation. Clocking data (arrival time, departure time, break time, any geolocation) constitute personal data. Their processing requires a legal basis within the meaning of the GDPR, prior information of the data subjects, a proportionate retention period and, in certain cases, a data protection impact assessment.

The operational difficulty lies in the fact that these two regimes sometimes pull in opposite directions: employment law encourages the retention of detailed and durable evidence, while the GDPR imposes minimisation and erasure. The point of balance must be built case by case.

The first recurring mistake in mid-sized companies is to believe that the employee’s consent must be obtained to install a clocking device. This is wrong, and even counterproductive.

Consent implies a free choice. Yet, within the relationship of subordination, the employee is never in a position to freely refuse a system imposed by the employer. The CNIL has long held that consent is not a valid basis in the context of the employment contract for processing operations imposed by the organisation. The relevant basis is the employer’s legitimate interest (organising and monitoring working time, meeting its statutory time-recording obligations) or, depending on the case, the legal obligation to record working time.

This classification is not cosmetic. It determines employees’ rights: on a legitimate-interest basis, the employee retains a right to object that the employer must examine on a case-by-case basis, which must be anticipated in the internal documentation.

Practitioner’s verbatim. “The most frequent case is not the illegal badge reader, it’s the legal badge reader whose declared legal basis in the record of processing activities is wrong. We read ‘consent’ when the processing is in fact imposed. On the day of the CNIL inspection, that single word makes the entire record unreliable — and an unreliable record is a standalone breach of Article 30 of the GDPR.”

Proportionality: the trap of over-collection and biometrics

The minimisation principle requires collecting only the data strictly necessary for the purpose. A working time tracking system does not need to monitor the employee continuously or trace every movement.

Geolocation can never serve as the primary means of monitoring working time where another, less intrusive means exists. The French Cour de cassation (Supreme Court) has held that the use of a geolocation device to monitor working time is lawful only where such monitoring cannot be carried out by any other means, even a less effective one. A declarative or badge-based clocking system must therefore be preferred.

Biometrics (fingerprint, facial recognition for clocking in) fall within the category of sensitive data. Their use for the mere management of working time is in principle disproportionate: the CNIL reserves biometrics for high-security stakes, not for time recording. Deploying a biometric clocking device “because it’s more convenient” constitutes a clear breach.

Key point: the evidentiary reliability sought under employment law never justifies, on its own, a disproportionate infringement of privacy. The labour court will disregard evidence obtained by an unlawful process where its production is not indispensable and proportionate.

Information and consultation: the mandatory prior formalities

No automatic tracking system may go live without prior formalities. Three obligations apply cumulatively.

  1. Individual information of employees. Each employee must be informed, before implementation, of the existence of the system, its purpose, the legal basis, the recipients of the data, the retention period and their rights (access, rectification, objection). A monitoring process not brought to the employee’s knowledge beforehand cannot be relied upon against them.

  2. Consultation of the CSE. The social and economic committee (Comité social et économique, the elected staff representative body) must be consulted prior to the decision to implement a means of monitoring employee activity. Failure to consult constitutes an obstruction offence (délit d’entrave) and undermines the evidentiary value of the system.

  3. Internal GDPR documentation. Entry in the record of processing activities, definition of the retention period, and where applicable a data protection impact assessment (DPIA) where the processing is likely to result in a high risk — a frequent scenario for systematic monitoring of working hours.

Document to produce, evidence to keep. The information notice given to employees (with signed acknowledgement or dated receipt), the minutes of the CSE consultation, and the extract from the record of processing activities. These three items form the defensive foundation in the event of litigation.

Retention period: the most heavily sanctioned blind spot

This is where the most frequent flaw lies. Companies configure the collection carefully, then forget to purge.

Clocking data serve to prepare payroll and to record working time. Their retention in the active database must be limited to the period necessary for managing payroll variables and handling any short-term disputes. Beyond that, the data must be archived or deleted.

The interaction with employment law is delicate: overtime claims are time-barred after three years (Article L.3245-1 of the French Labour Code). The employer therefore has a legitimate interest in keeping, in intermediate archiving (restricted access, not used day-to-day), the time-recording evidence for the applicable limitation period. But keeping all clocking data in the active database for years, accessible to any administrator, is disproportionate and constitutes a breach.

Counter-intuitive angle. Keeping too little is as dangerous as keeping it too long. An employer who purges its clocking data after one year deprives itself of its own evidence in a labour-court dispute concerning overtime claimed over three years. The retention period must be calibrated on the employment-law limitation period, not below it — otherwise GDPR compliance weakens the employment-law position. This is exactly the opposite of the intuition that “the less I keep, the better.”

Typical litigation: where the employer’s liability is decided

Three litigation configurations arise systematically.

Labour-court litigation — overtime. The employee claims back-pay over three years. If the tracking system is found unreliable (data modifiable without traceability, no certain timestamping, system challenged as to its implementation), the court may disregard it and rule solely on the evidence produced by the employee. The technical and procedural quality of the system is decisive here.

Evidentiary litigation — unlawful evidence. The employer produces clocking records to justify a sanction or dismissal (lateness, absences). If the system was not brought to the employee’s knowledge, or if it was implemented without CSE consultation, the evidence may be disregarded. Evidence derived from an unlawful system is admitted only if it is indispensable to the exercise of the right to evidence and proportionate to the aim pursued — a strict assessment by the court.

CNIL litigation — GDPR breach. On-site or documentary inspection, an employee complaint, or a CSE report. The breaches typically identified: incorrect legal basis, over-collection, lack of information, excessive retention, absence of a DPIA. The sanction is autonomous: it does not depend on any demonstrated individual harm.

Seven-step compliance procedure

For a deployment or a remediation, the following sequence structures a provable compliance file.

  1. Map the purpose. Set out in writing what the system is for (time recording, payroll management, attendance monitoring). A vague purpose makes everything else indefensible.
  2. Qualify the legal basis. Choose legitimate interest or legal obligation — never consent. Document the balance test for legitimate interest.
  3. Apply minimisation. Rule out biometrics and geolocation unless a proven necessity exists. Limit the fields collected to strict time recording.
  4. Set the retention period. Active database limited to payroll management; intermediate archiving aligned with the three-year limitation period (L.3245-1).
  5. Inform and consult. Dated individual information notice + prior consultation of the CSE with minutes.
  6. Document on the GDPR side. Record of processing activities, DPIA if high risk, policy for handling rights (access, objection).
  7. Test technical reliability. Certain timestamping, traceability of changes, access restrictions. The system must withstand a labour-court challenge.

On each of these steps, the firm intervenes to audit the existing setup, identify breaches and secure the defensive documentation. Upstream, DAIRIA IA answers classification questions (legal basis, retention period, interaction with limitation periods) by citing the applicable texts; it equips the HR department to frame the file before our lawyers step in.

Frequently asked questions

Must a clocking device be declared to the CNIL before installation?

No, the prior declaration regime disappeared with the GDPR. The obligation is now to enter the processing in the record of processing activities and, if systematic monitoring of working hours creates a high risk, to carry out an impact assessment (DPIA) kept internally and available in the event of an inspection.

Can an employee refuse to clock in?

On a legitimate-interest basis, the employee has a right to object that the employer must examine in light of their particular situation. However, a systematic and unjustified refusal may constitute a disciplinary breach where the system is lawful and proportionate. Each objection is assessed individually.

Are clocking records sufficient to prove overtime?

They are a central but not exclusive element. Under L.3171-4, the employer must provide objective evidence; a reliable, tamper-proof record carries significant weight. Conversely, a system whose data can be modified without traceability may be disregarded by the court.

Can clocking data be kept for five years “just in case”?

Not in the active database. Day-to-day retention must be limited to payroll management. Intermediate archiving with restricted access may cover the three-year limitation period for wages (L.3245-1). Keeping all data accessible for five years is disproportionate.

Is facial recognition for clocking in allowed?

In principle no, for the mere recording of working time. Biometrics fall within the category of sensitive data and their use is reserved for high-security stakes. Using a biometric process for the sole purpose of managing working hours is regarded as disproportionate.

What does an employer risk by not consulting the CSE?

Two cumulative risks: an obstruction offence and the inadmissibility of the system as a means of evidence. A clocking record from a system installed without prior CSE consultation may be disregarded by the labour court.

Does remote working change the time-recording obligations?

The recording obligation remains, but the methods must respect the privacy of the employee at home. Monitoring cannot justify permanent surveillance or geolocation. A declarative system or a proportionate software-based clocking method is preferred.