GDPR, CNPD, delegation and AI Act

Compliant before the first punch,
and every day after.

A time recording system is monitoring under Article L.261-1 of the Labour Code. The locks are prepared at scoping, and that is where Luxgap’s DPO expertise makes the difference: DPIA, notices, CNPD file and draft agreement come with the tool.

Before the first punch

Two locks: the CNPD opinion and co-decision.

Replay a scenario
Two locks before the first punch: the CNPD opinion and co-decision1. DPIA and recordrisk analysis by the DPOpurposes and periods set2. Prior informationeach employee and the delegationor the ITM if there is none3. 15-day periodthe delegation or employeesmay refer to the CNPDReferral to the CNPD?Co-decision required?no4. Delegation agreementflexitime, exact pay,health, or from 150 staffyes5. Go-livefirst punch recordednoCNPD opinionwithin a month, project on holdyesLock: may suspend or condition the project

The 15-day period and any CNPD opinion, suspensive for one month at most, are planned at scoping; co-decision is added as soon as one of the listed cases applies.
RequirementSourceOur deliverable
GDPR legal basis (Art. 6.1 a to f) and limited purposesL.261-1Record of processing, purposes locked in the tool
Prior information to each employee and the delegation, or the ITM if none: purpose, methods, retention, no diversionL.261-1Individual and collective notices ready to send
Prior CNPD opinion requested by the delegation or employees within 15 days; answer within a month; suspensive effectL.261-1CNPD file ready, schedule that includes this period
Co-decision if monitoring serves health and safety, exact pay calculation or flexitimeL.261-1, referring to L.211-8 and L.414-9Draft agreement with the delegation
Co-decision from 150 employees for technical installations monitoring behaviour and performanceL.414-9Same draft agreement
Informing and consulting the delegation before new equipment or working methodsLabour CodeProject presentation note
DPIA (GDPR Art. 35): systematic monitoring of employees, vulnerable persons under WP248 guidelines, plus biometrics, location or AI depending on optionsGDPRTemplate DPIA written by our DPO
Biometrics, location, penalties

CNPD red lines, built in by design.

CNPD

Biometrics: possible, never by default

The CNPD lists working-time control among biometric uses and recommends avoiding it when identification can be done otherwise. It prefers traceless characteristics stored on an individual medium. Our doctrine: badge or mobile first; if biometrics, template on the employee’s card, no central database, a non-biometric alternative for everyone.

Location

At the moment of clocking, never continuously

CNPD guidelines only allow tracking working time by location if clocking is otherwise impossible, and reject permanent monitoring. Retention: 2 months as a rule, 3 years if it is the only way to track working time. Our mobile clocking captures the position only at the moment of clocking and stores “in the zone” or “outside the zone” by default.

Penalties

What the CNPD penalises

Decision 13FR/2023 of 21 September 2023 concerns location tracking used notably to check working-time declarations: purposes and information breached, EUR 2,500 fine. Decision 16FR/2022 of 7 July 2022 fines permanent video surveillance of employees EUR 10,500. In both cases information and purpose were lacking: two points the tool locks down.

WP249

European position

Opinion 2/2017 of the Article 29 Working Party recalls that consent is rarely a valid basis between employer and employee, that the least intrusive means and a DPIA are needed before any new monitoring technology. Attendance data must not be used to assess performance.

Compliance of the system itself

Retention, security and rights.

Time tracking processes employee data every day: GDPR documentation comes with the tool and retention periods apply automatically.

DataProposed periodRationale
Register, approved punches and raw log3 yearsSalary limitation period, period accepted by the CNPD when location is used to track working time
GPS coordinates, if enabled2 monthsGeneral rule of CNPD guidelines
Zone result (in or out)Same as the registerPart of the punch
Photo at clocking, if enabled30 days at mostTime needed for visual check
Biometric templateOn the employee’s card onlyNo central database, erased on return
Exported payroll items10 yearsAccounting records
AI suggestions and related decisionsSame as the registerProof of human involvement
Audit and security logs12 months, extendable for incidentsDetection and investigation

Periods to be set in each client’s DPIA; purge is automatic and logged.

Deliverables

The file provided

Record entries (clocking, mobile, AI), DPIA per options, individual and collective notices (L.261-1) and AI notice, draft co-decision agreement, processing contract (GDPR Art. 28) with EU sub-processors, retention policy, rights procedure, NIS2 and DORA evidence.

Security

The technical foundation

Hosting in Luxembourg or the EU, encryption at rest and in transit, SSO and MFA, least privilege, tamper-evident audit log with chained hashes, penetration tests, Luxgap SOC monitoring, encrypted backups and tested recovery plan, tag and badge keys unique to each client.

Rights

Employee rights

Access to all their data and correction history from the portal, rectification through the correction circuit, explanation of every alert and guaranteed human involvement (GDPR Art. 22), answers within a month (GDPR Art. 12).

AI Act

Where our AI sits under the AI Act.

ProvisionContentOur design choice
Annex III, point 4 bHigh risk: decisions on working conditions, monitoring and evaluation of behaviourAI corrects data, it does not score people; behavioural analysis is excluded from the core
Art. 5(1)(f)Emotion recognition at work banned since 2 February 2025No face, voice or emotion analysis
Annex III, point 1 a1:1 biometric verification is not high riskBadge plus fingerprint-on-card option, no remote identification
Art. 26(7)Inform representatives and employees before a high-risk systemAI notice provided from the start, even outside high risk
Art. 4AI literacy of the staff concernedLuxApps e-learning module for managers and HR

Regulation (EU) 2024/1689 classifies as high risk AI systems that monitor and evaluate workers’ performance and behaviour or decide their working conditions. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus) postponed these obligations to 2 December 2027. The final classification depends on the functions enabled at each client: it is settled in the DPIA.

AI safeguards (no automated decision, no scoring, models hosted in Europe or on site, traceability) are detailed on the Engine and AI page.

Luxgap, Luxembourg cybersecurity, GDPR and AI firm

Luxapps develops LuxApps Pointage and integrates it with your HRIS. Its compliance is carried by Luxgap, the Luxembourg firm that runs our outsourced DPO and CISO mandates (GDPR, AI Act, NIS2, DORA): impact assessment, notices, CNPD file, draft delegation agreement and security monitoring by the Luxgap SOC.

DPO & CISO expertise
LuxApps Pointage

Your time clocks, your rules, your payroll.

Show us your hardware and your agreements: we show you the path to payroll, compliance included.

Book a demo