At NextGen Workforce, we are committed to protecting the privacy and security of our employee’s data. In line with the European Union’s General Data Protection Regulation (GDPR), we have an entire policy regarding how to collect, process, and store the time-tracking of employees. This document outlines how we comply with GDPR principles to ensure that our employee time-tracking practices respect privacy rights while maintaining operational efficiency.
Personal Data Collected in Time Tracking
Identification Information
Employee names and identification numbers.
Work Location
For employees working on-site or in the field, geolocation data may be collected.
Biometrics
Legal Basis for Data Processing
Contractual Necessity
Time tracking is required to fulfill employment contracts, such as payroll, comply with labor laws, and pay workers accurately for work hours.
Legal Obligation
Legitimate Interests
Keep your team aligned and motivated with clear goals and progress tracking.
Transparency and Employee Consent
We will ensure transparency in how we collect and use employee data. All employees will be informed of the following
- The specific types of data collected (e.g., clock-in times, work locations, project/task information).
- The reason for collating these data (for instance, in processing payrolls; compliance to legal requirements; monitor productivity levels).
How the long the data will be retained
- Who would gain access to the data; (For example: HR payroll team and/or managers)
- While explicit consent is not always required under GDPR (due to the contractual necessity or legal obligation basis), we ensure that employees are fully informed about their data processing rights.
Data Minimization
- Time tracking data is used solely for payroll processing, compliance with labor laws, and managing employee tasks and projects.
- We do not collect excessive or irrelevant data beyond, other than what is needed for operations or legal reasons.
Accuracy of Data
- Review their time-tracking data regularly.
- Report any discrepancies or errors in their records to HR or management for correction.
Data Storage and Retention
- Payroll and tax records may be retained for several years in compliance with local tax and labor regulations.
- Once time-tracking data is no longer required for operational or legal purposes, it will be securely deleted or anonymized.
Employee Rights Under the GDPR
Employees have certain rights under the GDPR regarding their time-tracking data:
Right to Access
Any employee can be granted access to his/her time-tracking data at any time.
Right to Rectification
Employees can request corrections to any inaccuracies in their time tracking records.
Right to Erasure
Employees are entitled to request the deletion of their data collected under certain conditions, such as when the data is no longer necessary for the purpose it was collected.
Right to Object
Employees have the right to object to the processing of their data in certain situations, such as where they believe the processing is unnecessary or excessive.
Data Security
- All personal data is stored securely, with encryption used where appropriate.
- Access to time tracking data is restricted to authorized personnel, such as HR and payroll teams.
- Regular audits and updates are conducted to ensure that our systems remain secure and up to date with the latest protection standards.
Third-Party Data Processors
- These providers are GDPR-compliant and adhere to strict data protection policies.
- We have entered into a Data Processing Agreement (DPA) with all third-party service providers who handle employee data, stipulating the terms on which they process employee data.
Data Breach
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, if applicable.
- Notify the affected employees if the breach would be used against their rights and freedoms.
- Corrective actions are taken immediately to reduce the impact of the breach.
Biometric Compliance
- Employees must be informed and consent before collecting biometric data. Biometric data shouldn’t be used for personal profits.
- Protection and retention of data according to the laws.
- Refrain from selling, leasing, or disclosing biometric information without consent Storing and protecting identifying information from disclosure.
Data Storage on Local Servers
NextGen Workforce’s time tracking system, when data is being stored on local servers, will be compliant with GDPR policies regarding personal data. Only essential data needed to track the hours worked and attendance is collected and securely stored on local servers.
All personal data is encrypted both at rest and in transit to prevent unauthorized access, and access to the data is limited to authorized personnel based on role-based permissions. The data is retained only for as long as required to fulfill its purpose, and employees are informed about how their data is being processed and stored.
NextGen Workforce provides employees with the capability to exercise their GDPR rights: access, rectification, and erasure. It also ensures that third-party vendors supporting the system follow the standards of GDPR. NextGen Workforce frequently audits to ensure continued compliance with data protection standards.
Conclusion
feel free to reach out to our team @ care@ngworkforce.com
