Certix

Employee time tracking and GDPR in the SME: payroll and cameras

Certix
Certix®
· 1 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

Processing workforce data concentrates the most serious risks of any Spanish SME. Payroll passes through the external payroll firm and the mutua insurer; time recording has been mandatory since Spanish Royal Decree-Law 8/2019 on time recording; video surveillance cameras record employees whenever a system is in place at the workplace; and corporate email contains customer data the company must be able to recover when the employment contract ends. Each of these fronts has its own regime, and the most common SME mistakes concentrate precisely here.

This guide explains how an SME manages its workforce's personal data in line with the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018), the Spanish Workers' Statute, Spanish Royal Decree-Law 8/2019 on time recording and the applicable constitutional case law, with a focus on what the average SME really needs: privacy notice, time recording, workplace video surveillance, employee offboarding and corporate email.

The employee privacy notice: what few SMEs hand over on signing

Article 13 GDPR requires the controller to inform the data subject at the time their data is collected. In the employment context that moment is signing the contract, when the employee provides their national ID, NIE/IBAN, health card, family details for tax withholdings and, where applicable, medical history for health surveillance. The employee-specific privacy notice must cover:

  • Identity of the controller (the company) and contact details of the DPO if there is one.
  • Purposes: employment management, payroll and social security contributions, tax withholdings, occupational risk prevention, health surveillance where applicable, time recording, holiday and leave management, training, performance appraisal, internal communications.
  • Legal bases: performance of the employment contract (art. 6(1)(b) GDPR) for activities inherent to the contract; compliance with legal obligations (art. 6(1)(c)) for those linked to TGSS (Spanish Social Security Treasury), AEAT (Spanish Tax Agency), occupational risk prevention and accidents; and consent (art. 6(1)(a)) or legitimate interest (art. 6(1)(f)) for additional purposes (use of the employee's image on corporate social media, internal loyalty programmes, etc.).
  • Usual recipients: TGSS, AEAT, the Spanish Public Employment Service, external payroll firm, mutua insurer, insurance bodies under the applicable collective agreement, occupational risk prevention service.
  • International transfers if the company uses HR software with servers outside the EEA.
  • Retention periods: during the term of the contract and the subsequent periods set by labour, tax and limitation-of-actions rules (four years for tax debts, five years for ordinary civil actions, specific periods for labour and social security claims).
  • Worker's rights and the specific channel to exercise them.

The notice is delivered, signed by the employee as proof of receipt, and filed in their personnel record. That signature is not consent to processing — the legal basis is the employment contract, not consent — but proof that the company has complied with its duty to inform.

Time recording: a mandatory obligation with several lawful solutions

Spanish Royal Decree-Law 8/2019 on time recording, of 8 March, amended art. 34 of the Spanish Workers' Statute to require employers to ensure daily recording of every worker's working day, with the specific start and end times. The SME has several legitimate and proportionate alternatives to comply with this obligation:

System When it fits well Considerations
Signed paper record Very small SME, stable hours, single site. Simple, no cost, easy to deploy. Keep the sheets for four years.
Individual PIN on a terminal SMEs with several workers rotating shifts. Minimal hardware investment. Each employee has their own PIN.
RFID proximity card Companies with physical access control to the workplace. Convenient. Integrates time recording with building access.
Corporate mobile app Mobile workers or remote working. Requires informing about geolocation data if used. Clear policy on phone use.
HR software with personalised login Companies with HR management already digitalised. Integration with holidays and payroll. Art. 28 GDPR contract with the provider.

Regardless of the system chosen, three principles must be respected:

  • Information to the employee: the system, the data recorded, the retention period (four years to meet the requirements of Spanish Labour Inspection) and who has access to the record must appear in the privacy notice.
  • Minimisation (art. 5(1)(c) GDPR): the record must capture only what is necessary. The start and end times of the working day fit; data that is not necessary for time recording does not.
  • Negotiation with legal representatives: art. 34(9) of the Spanish Workers' Statute provides for collective bargaining or, failing that, agreement with the legal representatives to establish the organisation and documentation of the record.

Workplace video surveillance: what is allowed and what is not

An SME with video surveillance cameras at the workplace must simultaneously respect the GDPR regime, art. 22 LOPDGDD (which regulates processing by video surveillance systems) and art. 89 LOPDGDD (which specifically regulates workplace video surveillance). What is allowed:

  • Cameras for the safety of persons and property in passageways, entrances, warehouses, tills and reception areas.
  • Informing workers and their legal representatives of the existence of the system (art. 89(2) LOPDGDD), before installation.
  • Visible information signs in line with art. 22(4) LOPDGDD: the AEPD's model or another that meets the required content (identity of the controller, possibility to exercise rights, general purpose).
  • Retention of images for the necessary period, generally one month (art. 22(3) LOPDGDD), unless the investigation of a specific event requires otherwise.
  • Viewing of the footage only by authorised personnel, with an access log.

What is strictly prohibited:

  • Cameras in rest areas, canteens, changing rooms, toilets and similar areas (art. 89(1) LOPDGDD). This prohibition is absolute: no legitimate purpose or consent can override it.
  • Sound recording together with image, save in very exceptional cases with prior legal analysis, given the additional impact on the right to privacy.
  • Hidden cameras installed systematically without informing workers. The exception in art. 89(2) LOPDGDD refers specifically to the use of footage from cameras already disclosed to verify flagrant breaches, not to general covert installation.
  • Sharing the camera viewer with unauthorised persons (the owner's family members, other employees without a role) or publishing employee images on corporate social media without their consent.

"In the SME, problems with employees rarely come from the legal document — they come from the day-to-day. Cameras in poorly defined areas, time recording deployed without negotiating with the representatives, the employee's email opened on the same day they leave, a payslip sent via WhatsApp. Ten minutes of procedure save a year of argument."

Mario P. Talamillo · Managing Partner, Certix®

Payroll, IBAN and financial data: how they travel and where they are stored

Payroll processing is one of the densest personal data flows in an SME. It involves identifying data on the worker, family data (for tax withholdings), IBAN, salary, length of service, professional category and, occasionally, medical diagnoses where there is sick leave or workplace accident. Critical points:

  • Encryption in transit: payroll must never travel over insecure channels. Standard email between the company and the payroll firm must come from a professional provider with in-transit encryption. Sending unencrypted PDFs to the employee's personal address is only reasonable when the PDF is password-protected with a password known only to the employee.
  • Secure storage: internal copies of payslips are kept in a system with access control. Not in a shared folder open to all staff.
  • Sick leave: sick notes contain health data (special category under art. 9 GDPR). Access must be restricted to staff with a specific role (HR, payroll firm, designated person). The sick note is not shared with team colleagues beyond the strictly necessary information to reorganise work.
  • Change of payroll firm: if the company switches its external payroll firm, the outgoing firm must return all documentation to the controller (art. 28(3)(g) GDPR) before destroying it, ensuring continuity of compliance.

Employee offboarding: corporate email and a clean exit

When an employee leaves the company — by voluntary resignation, dismissal or end of contract — the SME must manage several fronts simultaneously:

  • Suspension of access on the effective date: ERP, CRM, HR software, corporate tools, VPN, storage platform, time recording systems.
  • Return of company devices: laptop, corporate mobile phone, keys, access cards. Document the return with a signed handover record.
  • Management of corporate email: redirect incoming messages to another person for a reasonable period (three to six months is usually proportionate), with an auto-responder informing the sender of the change. After the period, delete the mailbox. Do not systematically open personal correspondence received in the meantime.
  • Copy of professional files: the professional documents the employee held on their device or in their corporate cloud storage pass to the company, in line with the policy on the use of electronic resources that the employee was made aware of when signing the contract.
  • Retention of the personnel file for the applicable legal periods: payslips, employment history, signed contracts, occupational risk prevention, training, certifications, disciplinary communications where they exist. The limitation period for labour and social security actions marks the retention horizon.

Minimum checklist for processing workforce data in the SME

  • Employee-specific privacy notice delivered and signed at onboarding, filed in each personnel record.
  • Time recording system deployed in line with Spanish Royal Decree-Law 8/2019, communicated to the employee and to their legal representatives where they exist.
  • Written video surveillance policy: recorded areas, retention periods, who has access, signage in line with art. 22(4) LOPDGDD.
  • Payroll process with encryption in transit and access-controlled storage.
  • Policy on the use of electronic resources communicated to the employee when signing the contract.
  • Offboarding protocol with access suspension, device return, email redirection and mailbox deletion.
  • Art. 28 GDPR contract with external payroll firm, mutua insurer, occupational risk prevention service and HR software.
  • Specific handling of health data (sick leave, health surveillance) with restricted access and appropriate retention.

Frequently asked questions

Must an SME hand its employees a data protection privacy notice when they sign the contract?

Yes. Article 13 GDPR requires the controller to provide the information on processing at the time the data is collected, which in the employment context is when the contract is signed. The notice covers employment purposes, usual recipients (TGSS, AEAT, payroll firm, mutua insurer), retention periods and the worker's rights. It is delivered, signed and filed in the personnel record.

How is mandatory time recording implemented without creating data protection problems?

There are several legitimate alternatives: signed paper record, individual PIN, RFID proximity card, corporate mobile app or HR software with personalised login. The system must reliably record the start and end of the working day, respect data minimisation and appear in the employee's privacy notice, with a four-year retention period to meet the requirements of Spanish Labour Inspection.

Can an SME install video surveillance cameras at the workplace that record employees?

Yes, within the limits of art. 89 LOPDGDD and constitutional case law. Workplace video surveillance must pursue a lawful and specific purpose, be applied to the strictly necessary place and time, comply with the duty to inform workers and representatives and display signage in line with art. 22(4) LOPDGDD. Cameras in rest areas, changing rooms, canteens and toilets are strictly prohibited (art. 89(1)).

What does the SME do with the corporate email and files of an employee when they leave the company?

The reasonable practice is to regulate email use in an internal policy known to the employee when they sign the contract; after they leave, redirect incoming messages to another person for a reasonable period (three to six months) with an auto-responder; delete the mailbox at the end of the period; and not systematically open personal correspondence received in the meantime. The whole procedure must be documented.

This content is purely informational and educational; it does not constitute specialised legal advice. Applying the regulations to each specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify deadlines and requirements.

Does your SME have orderly handling of staff data?

At Certix we assign you an SME compliance specialist. No commercial intermediaries, no generic templates.

Speak to a specialist

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →