Picture the moment. You run a cleaning firm, or a maintenance crew, or a squad of installers who spend the day hopping from one site to the next, and you have finally had enough of paper timesheets that turn up crumpled, half filled in, and roughly as reliable as a British weather forecast. So you decide to put a GPS clock-in on the phones: one tap to start, one tap to finish, the time and the place recorded at the exact moment it happens. Sensible. And then you freeze on the same two questions everybody freezes on. Is this even legal? And what on earth am I meant to hand the staff before I switch it on?
Good news first: the instinct is right, and the law is not trying to stop you. Under the UK GDPR, recording where and when someone clocks in is processing their personal data, and that does not make it forbidden, it makes it something you set up on purpose rather than by accident. The rule is not “do not do this”. The rule is “do it properly”. The difference between the two is a short stack of paperwork that most owners overcomplicate in their heads and then never actually get round to.
And the list really is short. You need a proper reason in law for collecting the data, a plain notice that tells your people what is being collected and why, a system that only touches what it needs to, and, where the risk is higher, a bit of homework and a chat with the team. Get those in order and the GPS clock-in stops being a legal grey area and becomes the most solid record your business has ever kept. Let us walk through them in the order that makes sense.
Want your field team clocking in properly from tomorrow morning?
Before a single phone gets the software, you need a lawful basis, which is just the reason the law recognises for you holding this data at all. Consent is a poor fit in an employment setting, because a boss asking a worker to agree is never quite a free choice, and the ICO says as much. The basis that fits a GPS clock-in is legitimate interests. To lean on it you run what the ICO calls a three-part test: the purpose test, whether you are actually pursuing a genuine interest, the necessity test, whether the data is genuinely needed to do it, and the balancing test, whether your reason still stands once you weigh it against the worker’s rights and reasonable expectations. Write that reasoning down in a short legitimate interests assessment, an LIA, and keep it on file. It is not busywork. It is the document that lets you show, months later, that you thought this through instead of switching on a tracker because a sales rep told you to.
Try GeoTapp free for 14 days
No credit card required. Get started in 2 minutes.
This is the informativa, the privacy notice, and it is the part most owners get wrong by making it either a legal brick nobody reads or a two-line note that says nothing. Neither works. A good notice tells your workers, in language a human being can follow, exactly what is collected (the time and the place at the moment they clock in and out, nothing more), why you collect it (to confirm the work was done, on time, at the right site), how long you keep it, and who gets to see it. The ICO is blunt about the principle: in almost every case workers must be made aware of monitoring before it happens, never after. Hand the notice over, let them read it, keep a record that you did. A field engineer who knows precisely what the app records, and what it does not, is one who is not going to feel spied on, and that matters more than any clause.
Proportionality is the whole game
Here is where good intentions go off a cliff. There is a world of difference between recording a location at the punch and following a person as a moving dot across the map for eight hours. The first confirms a fact. The second is surveillance, and the ICO’s monitoring guidance treats it exactly that way: monitoring cannot rely on legitimate interests if it collects data in ways workers would find unexpected or intrusive, and the more it strays into private life, the harder it is to defend. A crew that clocks in at a site does not need a live trail of every corner shop they stop at on the way. So collect the fact and leave the person alone. Proportionality is not a nice-to-have you bolt on at the end. It is the thing that decides whether the whole arrangement is lawful or a complaint waiting to happen.
Do the homework, and have the conversation
Where monitoring is likely to be high risk, the ICO expects a Data Protection Impact Assessment, a DPIA, and location data on staff sits close enough to that line that doing one is the sensible default. The DPIA is where you spell out the risk and how you have cut it down, and an honest LIA feeds straight into it, so the two are not separate mountains of work. Alongside the paperwork, talk to your team before you flip the switch, not after the grumbling starts. It is the difference between people who understand why the clock-in exists and people who assume the worst because nobody told them. Ten minutes in the van beats ten emails to the ICO.
Why the notice matters for proof, not just paperwork
Now the part nobody mentions when they talk about privacy notices, and the part that should make you want one. A clock-in record is not just a payroll line, it is evidence. It settles the dispute over whether the team was on site at nine, backs you up when a client swears nobody turned up, and answers a wage claim before it turns into a tribunal. But evidence is only as strong as the way it was gathered. Data collected on the quiet, with no lawful basis and no notice, is fragile: the moment someone challenges it, it can be waved away as an unlawful bit of snooping, and a record you cannot rely on is worse than no record at all, because you trusted it. The very same data, gathered on a clean legitimate interests basis with a notice everyone saw, holds. The notice is not the tax you pay to keep the data. It is what turns the data into proof that stands up.
A clock-in built to stay inside the lines
Once you see the framework, you start wanting a tool that was designed to live inside it rather than one you have to wrestle into shape. That is the whole reason GeoTapp was built the way it is. The software records the fact and only the fact: one tap to start, one tap to finish, the time and the place captured at the punch, and then it stops looking. There is no dot trailing your people across the day, because continuous tracking was never the point, and the data stays in the EU. It sits inside the proportionality line on purpose, so the record you get is both compliant and the kind of proof that does not fall over when someone leans on it. The paperwork around it, the lawful basis, the notice, the DPIA, is still yours to put in place, but the app is not quietly working against you.
So no, you are not doing anything dodgy by wanting a GPS clock-in for a field team. You are doing something perfectly legitimate, and the only real task is doing it in the right order: a lawful basis you can defend, a notice your people actually read, a system that collects the fact and nothing more, and the homework where the risk calls for it. Get that right and you end up with a timesheet that pays fairly, protects you when a dispute lands, and treats your crew like adults instead of suspects. To see what a clock-in that records only the fact looks like in practice, start a free GeoTapp trial and try it on your own team.
Get articles like this in your inbox
Practical insights on GPS tracking, field operations and GDPR. No spam, just useful content.