Skip to main content
Guide

GDPR-Compliant Time Tracking: The Complete Guide

What GDPR actually requires from a time tracking tool, why EU data residency matters, and how to choose software that keeps employee time data lawful by default.

Compliance11 min read

Most time tracking tools are hosted in the United States and quietly pass the compliance burden back to the European teams that use them. That puts your company in charge of international transfers, processing agreements, and data-subject rights for software you do not control. We built Hourvio the other way around, and this guide explains, in plain language, what GDPR means for time tracking and what to look for before you commit.

Why GDPR applies to time tracking

Time tracking is data protection, even when it does not feel like it. The moment you record who worked, when, and on what, you are processing the personal data of an identifiable person. Under Article 4 of the GDPR, personal data is any information relating to an identified or identifiable natural person, and a timesheet attached to a named employee or freelancer clearly qualifies.

Because it is personal data, the processing needs a lawful basis under Article 6. In an employment or contractor relationship that basis is usually the performance of a contract (Article 6(1)(b)) or a legitimate interest in running and billing the business (Article 6(1)(f)). Consent is rarely the right basis at work, because the imbalance of power between employer and employee makes freely given consent difficult to establish.

Two more principles shape how a tool should behave. Data minimisation means you should collect only what you actually need to record working time and bill it. Purpose limitation means the data you gather for timesheets should not quietly turn into a behavioural profile. A compliant tool records durations, projects, and tasks, and stops there.

We designed Hourvio's reports and analytics around exactly that data and nothing more. This guide is a general explainer rather than legal advice, but the underlying point is simple: if your tool treats working time as sensitive personal data from the start, the rest of compliance gets much easier.

Where your data lives: EU residency and transfers

Where your data physically sits is one of the first questions GDPR asks, and one of the most common places teams get caught out. When a time tracker stores data on servers in the United States, every timesheet entry becomes an international transfer of personal data, which has to be justified under Chapter V of the GDPR.

In practice that means relying on Standard Contractual Clauses or the EU-US Data Privacy Framework. Both can be used, but both have moved repeatedly in recent years, and the framework's long-term stability has been questioned more than once in European courts. Building your working-time records on that foundation means inheriting legal uncertainty you did not create.

Keeping data inside the EU removes the transfer question almost entirely. We run the Hourvio application and all customer data on servers operated by Hetzner in Germany. Your tracked time, projects, and team records stay on EU servers in Germany rather than crossing the Atlantic. For teams with stricter requirements, the security options go further: isolated infrastructure with a dedicated database and server is available from the Professional tier, and an on-premises deployment is available for organisations that need data inside their own walls.

EU residency is not a premium add-on at Hourvio. It is how every plan works, including the free tier. You can confirm exactly what each plan includes on the pricing page.

What to look for in GDPR-compliant time tracking software

Marketing copy that says "GDPR compliant" tells you very little on its own. Compliance is the result of specific, checkable properties, so it helps to evaluate any tool against a concrete list rather than a label. When you compare options, look for the following:

  • EU data residency with a named provider and location, not a vague "global" region. Hosting in Germany on Hetzner is the right level of specificity to expect.
  • A data processing agreement included as standard, rather than reserved for an enterprise upgrade.
  • Data minimisation by design so the tool records working time, not behaviour. No screenshots, no keystroke capture, and no location monitoring.
  • Data portability and erasure. Article 20 gives people the right to receive their data in a usable format, and Article 17 covers erasure. Practical exports in CSV and Excel, plus the ability to delete records, make those rights real.
  • Access controls so the right people see the right data. Look for roles and groups in team management, plus multi-factor authentication, with SSO and audit logs for larger organisations.

Hourvio's reporting and exports cover the portability side, and our access model covers the rest. The point of the checklist is to turn a marketing claim into something you can actually verify before you sign up.

Data processing agreements and subprocessors

When you use a time tracking tool, you are the data controller and the vendor is your data processor. Article 28 of the GDPR requires a written contract between the two, setting out what the processor may do with the data, how it protects that data, and what happens when the relationship ends. That contract is the data processing agreement, or DPA.

A DPA is not optional paperwork. Without one in place, the underlying processing of your team's working-time data may not have the legal footing it needs. Yet some vendors treat the DPA as a feature to be unlocked on a higher plan, or bury it behind a sales conversation. We think that is the wrong way round, because the agreement is a legal requirement, not an upsell.

We make a DPA available to Hourvio customers so you can put the Article 28 relationship on a clear footing. You can read the terms on the data processing agreement page.

The DPA also matters because of subprocessors. A processor that uses other providers (for hosting, email, or backups) is relying on subprocessors, and you have a right to know who they are. A trustworthy vendor lists them and commits to notifying you of changes. Because we run the application and customer data on Hetzner in Germany, the hosting picture stays inside the EU rather than spreading across regions you cannot see, which keeps the subprocessor question short and answerable.

The line between time tracking and surveillance

There is a meaningful difference between recording how long work took and watching how someone works. GDPR, and the broader European tradition around employee data, treats the second with real suspicion. Continuous monitoring of behaviour is hard to square with the principles of data minimisation and proportionality, and works councils and courts in several member states have pushed back against it.

A useful test is proportionality: is the data you collect necessary for the stated purpose? Recording two hours against a project is proportionate to billing and planning. Capturing periodic screenshots of someone's screen, logging every keystroke, or tracking their physical location is not, because it gathers far more than running the business requires and treats employees as subjects to be watched rather than colleagues to be trusted.

We built Hourvio to track time, not people. There are no screenshots, no keystroke capture, and no location monitoring anywhere in the product. The timer records durations and the timesheet records what was worked on, and that is the whole picture. We trust your team, and we think your software should reflect that.

This is also where tools differ in practice. Some popular trackers bundle monitoring features alongside time tracking, which can shift the compliance balance for European teams. If you are weighing an EU-hosted alternative against a US-hosted incumbent, our comparison with Clockify walks through how the two approaches line up.

Your GDPR time-tracking checklist

Before you commit to any time tracking tool, run it through a short, practical checklist. If a vendor cannot answer these clearly, that is itself an answer:

  • Lawful basis. Can you state why you are processing working-time data, usually contract or legitimate interest rather than consent?
  • Data residency. Where is the data stored, and is it inside the EU? Look for a named provider and country, such as Hetzner in Germany.
  • Processing agreement. Is a DPA available and included, not reserved for an enterprise tier?
  • Data minimisation. Does the tool record working time only, with no screenshots, keystroke capture, or location monitoring?
  • Data-subject rights. Can you export data in a portable format and delete it on request, covering Article 20 and Article 17?
  • Access controls. Are there roles and groups, multi-factor authentication, and audit logs for sensitive operations?
  • Transparency. Are subprocessors listed, with notification when they change?

Hourvio is designed to answer yes to each of these by default. You can review what comes with each plan on the pricing page, or dig into the technical detail on our security page.

Key takeaways

  • Tracked working time is personal data, so GDPR applies the moment you attach an entry to a named person.
  • Hosting data on EU servers in Germany removes the international-transfer problem that comes with US-based tools.
  • A data processing agreement reflects an Article 28 obligation and should be included, never sold as an upgrade.
  • Compliant tools record working time, not behaviour: prefer time tracking over screenshots, keystroke capture, or location monitoring.

Frequently asked questions

Is time tracking allowed under GDPR?
Yes. Recording working time is permitted under the GDPR as long as you have a lawful basis, collect only what you need, and respect data-subject rights. In an employment or contractor relationship the basis is usually the performance of a contract or a legitimate interest in running the business, not consent.
Does GDPR require employee consent to track time?
Usually not. Consent is rarely the right lawful basis at work, because the power imbalance between employer and employee makes it hard to show consent was freely given. Most working-time processing rests instead on contract performance or legitimate interest, which is why a clear privacy notice matters more than a consent checkbox.
Where does Hourvio store time tracking data?
We run the Hourvio application and all customer data on servers operated by Hetzner in Germany, so your tracked time stays on EU servers. Teams that need more separation can choose isolated infrastructure from the Professional tier, and an on-premises deployment is available for organisations that require data inside their own systems.

Track time the European way

GDPR by default, EU servers in Germany. Join Early Access.