A time recording system is monitoring under Article L.261-1 of the Labour Code. The locks are prepared at scoping, and that is where Luxgap’s DPO expertise makes the difference: DPIA, notices, CNPD file and draft agreement come with the tool.
| Requirement | Source | Our deliverable |
|---|---|---|
| GDPR legal basis (Art. 6.1 a to f) and limited purposes | L.261-1 | Record of processing, purposes locked in the tool |
| Prior information to each employee and the delegation, or the ITM if none: purpose, methods, retention, no diversion | L.261-1 | Individual and collective notices ready to send |
| Prior CNPD opinion requested by the delegation or employees within 15 days; answer within a month; suspensive effect | L.261-1 | CNPD file ready, schedule that includes this period |
| Co-decision if monitoring serves health and safety, exact pay calculation or flexitime | L.261-1, referring to L.211-8 and L.414-9 | Draft agreement with the delegation |
| Co-decision from 150 employees for technical installations monitoring behaviour and performance | L.414-9 | Same draft agreement |
| Informing and consulting the delegation before new equipment or working methods | Labour Code | Project presentation note |
| DPIA (GDPR Art. 35): systematic monitoring of employees, vulnerable persons under WP248 guidelines, plus biometrics, location or AI depending on options | GDPR | Template DPIA written by our DPO |
The CNPD lists working-time control among biometric uses and recommends avoiding it when identification can be done otherwise. It prefers traceless characteristics stored on an individual medium. Our doctrine: badge or mobile first; if biometrics, template on the employee’s card, no central database, a non-biometric alternative for everyone.
CNPD guidelines only allow tracking working time by location if clocking is otherwise impossible, and reject permanent monitoring. Retention: 2 months as a rule, 3 years if it is the only way to track working time. Our mobile clocking captures the position only at the moment of clocking and stores “in the zone” or “outside the zone” by default.
Decision 13FR/2023 of 21 September 2023 concerns location tracking used notably to check working-time declarations: purposes and information breached, EUR 2,500 fine. Decision 16FR/2022 of 7 July 2022 fines permanent video surveillance of employees EUR 10,500. In both cases information and purpose were lacking: two points the tool locks down.
Opinion 2/2017 of the Article 29 Working Party recalls that consent is rarely a valid basis between employer and employee, that the least intrusive means and a DPIA are needed before any new monitoring technology. Attendance data must not be used to assess performance.
Sources: CNPD, biometrics · CNPD, decisions · WP249 opinion
Time tracking processes employee data every day: GDPR documentation comes with the tool and retention periods apply automatically.
| Data | Proposed period | Rationale |
|---|---|---|
| Register, approved punches and raw log | 3 years | Salary limitation period, period accepted by the CNPD when location is used to track working time |
| GPS coordinates, if enabled | 2 months | General rule of CNPD guidelines |
| Zone result (in or out) | Same as the register | Part of the punch |
| Photo at clocking, if enabled | 30 days at most | Time needed for visual check |
| Biometric template | On the employee’s card only | No central database, erased on return |
| Exported payroll items | 10 years | Accounting records |
| AI suggestions and related decisions | Same as the register | Proof of human involvement |
| Audit and security logs | 12 months, extendable for incidents | Detection and investigation |
Periods to be set in each client’s DPIA; purge is automatic and logged.
Record entries (clocking, mobile, AI), DPIA per options, individual and collective notices (L.261-1) and AI notice, draft co-decision agreement, processing contract (GDPR Art. 28) with EU sub-processors, retention policy, rights procedure, NIS2 and DORA evidence.
Hosting in Luxembourg or the EU, encryption at rest and in transit, SSO and MFA, least privilege, tamper-evident audit log with chained hashes, penetration tests, Luxgap SOC monitoring, encrypted backups and tested recovery plan, tag and badge keys unique to each client.
Access to all their data and correction history from the portal, rectification through the correction circuit, explanation of every alert and guaranteed human involvement (GDPR Art. 22), answers within a month (GDPR Art. 12).
| Provision | Content | Our design choice |
|---|---|---|
| Annex III, point 4 b | High risk: decisions on working conditions, monitoring and evaluation of behaviour | AI corrects data, it does not score people; behavioural analysis is excluded from the core |
| Art. 5(1)(f) | Emotion recognition at work banned since 2 February 2025 | No face, voice or emotion analysis |
| Annex III, point 1 a | 1:1 biometric verification is not high risk | Badge plus fingerprint-on-card option, no remote identification |
| Art. 26(7) | Inform representatives and employees before a high-risk system | AI notice provided from the start, even outside high risk |
| Art. 4 | AI literacy of the staff concerned | LuxApps e-learning module for managers and HR |
Regulation (EU) 2024/1689 classifies as high risk AI systems that monitor and evaluate workers’ performance and behaviour or decide their working conditions. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus) postponed these obligations to 2 December 2027. The final classification depends on the functions enabled at each client: it is settled in the DPIA.
AI safeguards (no automated decision, no scoring, models hosted in Europe or on site, traceability) are detailed on the Engine and AI page.

Luxapps develops LuxApps Pointage and integrates it with your HRIS. Its compliance is carried by Luxgap, the Luxembourg firm that runs our outsourced DPO and CISO mandates (GDPR, AI Act, NIS2, DORA): impact assessment, notices, CNPD file, draft delegation agreement and security monitoring by the Luxgap SOC.
Show us your hardware and your agreements: we show you the path to payroll, compliance included.