klokly
GuidesSign inStart free
Guide

GDPR-compliant time tracking, in plain terms

Last updated: 1 August 2026

Employee time entries are personal data, which makes your time tracker a GDPR decision as much as a productivity one. This guide covers what the regulation actually asks of you, the questions to put to any vendor, and why hosting region and surveillance features matter more than long feature lists. It is general information, not legal advice.

01

Why time entries are personal data

A time entry says who worked, when, on what, and for how long. Under the GDPR that is personal data: it identifies an employee and describes their working day. String a few weeks of entries together and you have a fairly detailed picture of someone's workload, pace, and habits.

That has two practical consequences. First, your company is the data controller for employee time data. You need a lawful basis for collecting it, a retention plan, and a way to honour access and deletion requests. Second, any time-tracking vendor is a data processor acting on your behalf — and you are responsible for choosing that processor with care.

None of this makes GDPR time tracking difficult. Tracking hours for billing, payroll, and reporting is a routine, legitimate business need. The point is simply that time data deserves the same care as any other employee record.

02

Five questions to ask any vendor

Before you commit to a tracker, make sure you can answer these five questions from the vendor's own documentation:

  1. Where is the data hosted? Not where the company is registered — where the servers are. EU-hosted time tracking keeps employee time data inside the jurisdiction the GDPR was written for.
  2. Who are the subprocessors? Every service your vendor relies on — hosting, payments, email — inherits access risk. A short, published list is a good sign.
  3. Can you export everything? If answering a subject access request means "contact support", that is a weakness. Look for self-serve CSV or file export.
  4. Can you delete data yourself? Removing a former employee's entries, or your whole account, should not require a ticket queue.
  5. Does the product itself track people? A time tracker stuffed with analytics scripts and advertising cookies collects more data than it needs, which sits awkwardly with data minimisation.

If a vendor cannot answer these plainly, treat that as your answer.

03

Why US-cloud hosting complicates things

This is the part most teams find murky, so here it is calmly — and to be clear, this is general information, not legal advice.

The 2020 Schrems II ruling from the Court of Justice of the EU struck down the Privacy Shield framework for EU-US data transfers. Transfers to US providers did not become illegal, but they became conditional: you need a valid transfer mechanism, such as standard contractual clauses or the newer EU-US Data Privacy Framework, plus in many readings an assessment of whether US surveillance law undermines that protection in practice.

For a small company, that translates into paperwork and residual uncertainty. Every US-hosted tool in your stack is one more transfer to assess and document. Keeping employee time data in the EU does not make your GDPR obligations disappear — you still need contracts, retention rules, and processes — but it removes the transfer question entirely. That is one less thing in your records, and one less thing for a data protection officer or works council to query.

04

The surveillance trap

Some trackers ship screenshots, keystroke counts, or idle detection. These features are marketed as accountability. Under the GDPR they are a proportionality problem.

Monitoring must be necessary and proportionate to a legitimate purpose, and regulators across the EU have repeatedly found routine screenshotting and activity monitoring hard to justify for ordinary knowledge work — there are less intrusive ways to learn what a project cost. In Germany, Austria, and the Netherlands, among others, introducing monitoring software can trigger co-determination rights, meaning the works council must be consulted before rollout. And even where it is lawful, surveillance corrodes exactly the trust a time tracker depends on.

The safest surveillance feature is the one your tracker does not have.

If you bill or report on time, you need honest hours, not screenshots. Choose a tool whose data collection matches that purpose and nothing more.

05

How Klokly approaches it

Klokly is built for teams that bill or report on time — agencies, studios, consultancies — and its GDPR posture is deliberately boring:

  • EU hosting. Klokly is securely hosted in the EU, so employee time data stays in the EU by default.
  • Isolation at the database level. Each company's data is separated with row-level security in a multi-tenant database, not merely filtered in application code.
  • No tracking cookies. No analytics, advertising, or tracking scripts — which is why there is no cookie banner.
  • Full export. Timesheets export as CSV or printable PDFs via your browser's print dialog, whenever you need them — for a client, an audit, or a subject access request.
  • No surveillance by design. No screenshots, no idle detection, no activity scoring. One timer, one click.
  • Payments via Stripe. Card details never reach Klokly's servers.

For the remaining questions on the list — subprocessors and deletion — apply the same scrutiny you would to any vendor. The privacy policy is the place to start.

Klokly is deliberately small. There is no invoicing, no budgeting or forecasting, and no integrations marketplace. If you need an all-in-one platform, a larger suite may fit better — just put the five questions above to it. If you mainly need clean, defensible hours, small is a feature.

06

A short compliance checklist

GDPR time tracking is mostly tidy habits:

  1. Write down why you track time — billing, payroll, reporting — and tell your team.
  2. Pick a processor you can defend: hosting region, subprocessors, export, deletion.
  3. Set a retention period for old entries and stick to it.
  4. Skip surveillance features you cannot justify, and consult the works council where one exists.
  5. Test the export and deletion paths before you need them.

If EU-hosted time tracking with no surveillance and no tracking cookies covers your needs, you can start a free trial — 14 days, no credit card required, from $2 per seat/month.

FAQ

Frequently asked questions

Are time entries personal data under the GDPR?
Yes. A time entry identifies an employee and describes their working hours and tasks, so it counts as personal data. Your company is the data controller and your time-tracking vendor is a data processor acting on your behalf.
Is it illegal to use a US-hosted time tracker in the EU?
No, but since the Schrems II ruling, transfers to US providers need a valid transfer mechanism and often an extra assessment, which means more paperwork and residual uncertainty. EU hosting removes the transfer question entirely. This is general information, not legal advice.
Are screenshots and idle detection GDPR-compliant?
They are hard to justify for ordinary knowledge work, because monitoring must be necessary and proportionate to its purpose. In several EU countries they can also trigger works-council consultation before rollout. Transparent, manual time tracking avoids the problem.
Where does Klokly store employee time data?
Klokly is securely hosted in the EU, and each company's data is isolated at the database level with row-level security. There are no analytics, advertising, or tracking cookies, and payments are handled by Stripe so card details never reach Klokly's servers.
Can I export our time data from Klokly?
Yes. Timesheets export at any time as CSV or as printable PDFs via your browser's print dialog, with no support ticket needed. That covers retention reviews, audits, and subject access requests.
Try it

Klokly is simple time tracking for teams — EU-hosted, from $2 per seat per month, with printable timesheets built in.

Start your free 14-day trial
klokly

Made in Denmark · Hosted in the EU · Written on Solar power

ProductStart freeSign inGuides
Companylarssohl.dkPrivacy & cookiesTerms of service© 2026 Klokly