Recording hours is not monitoring people
The two get sold as one product and they are not the same thing. Knowing when someone started work is ordinary. Watching what they do while they work is a decision you have to be able to defend.
What staff should be told before anything starts
- What is recorded — for us: the time of each clock-in and clock-out, breaks, and which site or job if you switch that on.
- Why, in plain words: working time records, pay, holiday accrual.
- Who can see it: the person themselves, their manager, the office. Not the whole company.
- How long it is kept, and what happens when they leave.
- How to query or object, and to whom.
None of this is bureaucracy for its own sake. In the Serco case the ICO counted the absence of a clear route to object as part of what made the processing unfair — the information gap was itself a finding.
The necessity test, which is where most systems fail
Processing has to be necessary for the purpose, and "necessary" means there is no less intrusive way of achieving it. The ICO applied that to biometric clocking and named the alternatives itself: cards, fobs, a sign-in sheet. The same logic runs through every monitoring decision. Before you buy a feature, the question is not "would this be useful?" but "what is the least intrusive thing that answers the same question?"
Where we deliberately stop
- No fingerprints and no facial recognition. Why not.
- No screenshots, activity scores or keystroke counts.
- No continuous location. With clocking places on, the check happens at the punch and the person sees it before they tap.
- Role-based access, so a manager sees their team and not the whole company, and every access is logged.
If you recognise a competitor in that list, that is the point. Several of them sell all four. The comparison.
Consultation, where you have it
There is no statutory works council in Great Britain, so this is a matter for your own arrangements: a recognised union, an employee forum, or simply telling people properly. Two practical notes. First, a workforce or collective agreement can modify some Working Time Regulations provisions, so what you have agreed may change what applies. Second, a system people understand gets used correctly, and one they resent gets worked around — which quietly ruins the record you were trying to build.
Questions we get
Do we have to tell staff we are recording their hours?
Yes. Transparency is a principle of the UK GDPR in its own right (Article 5(1)(a)), and the ICO treated a failure to explain the system — and to say how to object — as part of the unfairness in its 2024 Serco decision. People should know what is recorded, why, who sees it and how long it is kept, before it starts.
Is a DPIA needed for a time clock?
For an ordinary PIN or card clock, usually not — it is the same kind of record employers have always kept. For biometrics it is required, and for continuous location or activity monitoring you should assume so. The test is whether the processing is likely to result in a high risk to people.
Can we monitor productivity as well as hours?
That is a different and much harder question. Recording when someone worked is proportionate and expected. Screenshots, activity scores and keystroke counts are not, and you would have to justify them against less intrusive alternatives — the same necessity test that defeated biometric clocking at Serco.
Free for up to 3 employees, forever
Thirty days with everything included, AI assistant and all, no card and no automatic renewal. When the trial ends, companies with up to 3 employees simply keep working for free. And within the first 60 days you get your money back if it does not fit.
Questions? Write to time@irot.com. We answer on working days, usually by the next one.