Skip to content
CheckBiz360by EncodeBiz

Data retention and protection

LOPD/GDPR: legal basis, retention and employee rights

Article 83 of 925 min read

CheckBiz360 and employees' personal data

CheckBiz360 processes the company's employees' personal data in order to provide its service. This means that, from the perspective of the General Data Protection Regulation (GDPR) and Spanish Organic Act 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), there are specific obligations that both the company and the platform have to meet.

This guide explains what data CheckBiz360 processes, on what legal basis, for how long it is retained and what employees' rights over their data are.

What personal data CheckBiz360 processes

The platform processes the following categories of data for each employee:

  • Identification data: full name, email address, phone number (if used for authentication).
  • Attendance data: entry and exit records with timestamps, the status of each workday, corrections made to the records.
  • Geolocation data: GPS coordinates at the moment of clocking, used to validate the geofence configured by the company.
  • In-app activity data: tasks assigned and completed, ratings received, notifications sent and read.
  • Device data: the identifier of the mobile device the clock records are made from, used to detect unauthorised devices.

The processing of personal data carried out through CheckBiz360 has two main legal bases:

Performance of the employment contract

Attendance recording and time control are inherent to the employment relationship. The employer has a duty to control working time and the worker has an obligation to keep to their schedule. The processing of attendance data is directly linked to the performance of the employment contract (Article 6.1.b of the GDPR).

RDL 8/2019 imposes on the company the obligation to record each employee's daily working time. The processing of the data needed to meet that obligation has as its legal basis Article 6.1.c of the GDPR (compliance with a legal obligation applicable to the controller).

Data retention periods

The different types of data have different retention periods:

Data typeRetention periodLegal basis
Attendance and workday recordsMinimum 4 yearsRDL 8/2019 — legal obligation
Geolocation dataOnly during clock-in validation; not stored indefinitelyData minimisation principle (GDPR art. 5.1.e)
Employee identification dataFor the duration of the employment relationship + 4 yearsEmployment and commercial obligations
Task and rating dataFor the duration of the employment relationship; configurable by the organisationPerformance of the contract

Employees' rights over their data

The GDPR gives employees the following rights over the processing of their personal data:

Right of access

The employee can ask what data about them the company processes and obtain a copy. In CheckBiz360, the employee can access their own attendance data directly from the app with no need for a formal request.

Right to rectification

If a piece of data is inaccurate, the employee can request its correction. In the case of attendance records, the correction has to be made by a manager with back office access, with full traceability of the modification.

Right to erasure

The employee can request the deletion of their data. However, this right has limitations where there is a legal obligation to retain: the company cannot delete attendance records before the four years required by RDL 8/2019 have elapsed, even if the employee requests it. Once the mandatory retention period has ended, the data has to be deleted unless there is another legal basis for keeping it.

Right to object and to restriction

The employee can object to the processing or request its restriction in certain cases. As with erasure, these rights have limitations where the processing is based on a legal obligation.

How the company should inform its employees

Before implementing CheckBiz360, the company has an obligation to inform its employees about the processing of their personal data. This information has to be provided proactively, clearly and in plain language, and include:

  1. The identity of the controller (the company itself).
  2. The purpose of the processing: working-time recording, attendance control and compliance with RDL 8/2019.
  3. The legal basis: performance of the contract and compliance with a legal obligation.
  4. The types of data that will be processed, including one-off geolocation at the moment of clocking.
  5. The data retention period.
  6. The employee's rights and how to exercise them.
  7. The identity of the processor: CheckBiz360 acts as processor on the company's behalf.

This information can be incorporated into the employment contract, into a specific information clause, into the company welcome document or into an internal communication signed by the employee.

Was this article useful?

Cookie settings

Choose what you want to allow. You can change your mind at any time from “Cookie settings”, at the bottom of the page. Read the cookie policy

NecessaryAlways on

They make the site work and remember this very choice, so we don’t have to ask you again. They identify no one and never leave this site, so they don’t depend on your permission.

They tell us which of our ads bring visitors and which don’t, so we stop spending on the ones that fail. That’s the Meta pixel (Facebook and Instagram) and Google Tag Manager (Google Analytics and Google Ads): they set first-party cookies and send data to Meta Platforms Ireland and Google Ireland.