Working time records for shift teams: what employers must track (EU overview + Spain case study)
What working time records must contain across Europe, how long to keep them, how to handle corrections and evidence — with Spain’s daily register as a case study.
Across Europe, employers are increasingly expected to answer a simple question with evidence: who worked, when, and for how long? For shift-based teams in hospitality, retail, healthcare or logistics, that answer lives in the working time record. This guide covers what those records should contain, how long to keep them, who gets access to them, and how Spain — home to one of the most explicit daily registration rules in the EU — handles it in practice. One note before we start: this article is general information, not legal advice. Requirements differ by country and sector, so confirm the specifics of your situation with a qualified adviser.
Why working time records became a European compliance topic
The EU Working Time Directive sets minimum standards that every member state must transpose: limits on average weekly working time, minimum daily and weekly rest, breaks during long working days and paid annual leave. These are floors, not ceilings — national law can and often does go further.
None of those limits can be verified without measurement. That is why, in 2019, the Court of Justice of the EU ruled — in a case brought by a Spanish union — that member states must require employers to set up an objective, reliable and accessible system that measures each worker’s daily working time.
Since then, the direction of travel has been consistent. Spain introduced a mandatory daily register the same year, and courts and legislators in several other countries — Germany among them — have read existing law as requiring systematic time recording. If you run shift teams in Europe, it is safest to assume that some form of working time record is, or soon will be, expected of you.
What a working time record should contain
The core of a usable record is simple: the employee’s identity, the date, the actual start and end time of work, and the daily total. Depending on national rules and your sector, you may also need to record breaks, on-call periods, or the location and role worked — especially where those trigger pay supplements.
The key word is actual. A record that mechanically copies the published schedule is not a record of working time; it is a copy of a plan. Inspectors notice when every clock-in matches the roster to the minute, week after week.
It also helps to store review metadata: whether an entry has been approved, by whom, and when. When a dispute arises months later, the difference between “someone typed this” and “this was clocked, reviewed and approved by a named manager” is enormous.
Retention periods and who gets access
Retention rules vary by country, but they are measured in years, not months. Spain requires four years; other countries set their own periods, often in the two-to-six-year range depending on the type of record. Whatever your jurisdiction requires, plan for the record to outlive the employment relationship it documents.
Access matters as much as storage. In most systems that regulate time records, three groups can ask to see them: the employees themselves, their legal representatives, and the labour inspectorate. A record that exists but cannot be produced within a reasonable time is, in practice, a record that fails.
Practically, that means keeping records in a system where you can filter by employee and period, export a readable document on demand, and prove that what you export today matches what was recorded at the time.
Evidence that holds up: GPS, kiosks and selfies
A time record is stronger when it carries evidence of where and how the punch happened. But evidence collection touches personal data, so proportionality under the GDPR applies: collect what you need to achieve a stated purpose, and no more.
A GPS check at the moment of clock-in — is the employee inside the site’s geofence? — is very different from continuous location tracking during the shift. The first documents a punch; the second monitors a person. Most shift operations only need the first.
Shared kiosks with PIN or QR credentials work well where staff do not clock in from personal phones — restaurants, warehouses, clinics. Selfie capture adds value only where there is a real risk of one person clocking in for another, and it should be introduced transparently: tell employees when each control activates and why.
Corrections are normal; silent deletions are not
People forget to clock out. Devices run out of battery. A record system that pretends errors never happen forces managers into the worst possible workaround: editing or deleting entries with no trace.
The credible alternative is a correction workflow: any change stores the original value, the new value, the author, the timestamp and a reason. The employee’s day gets fixed; the history of what changed survives. That audit trail protects both sides — the employer against claims of manipulation, and the employee against unilateral rewriting of their hours.
Once a period has been formally closed or signed, ordinary editing should be locked. If something genuinely must change after signature, it should be an exceptional event that is itself recorded in the audit trail, not a quiet edit.
Monthly signed reports close the loop
Raw punch data is for machines. What employees, managers and inspectors actually read is a monthly report per person: entries, exits, daily totals, incidents, and signature blocks for both parties.
Before generating signatures, review the month’s incidents: days without punches, shifts left open, entries outside the geofence, unusually long days. Signing a month that still contains unexplained gaps converts small data problems into documented ones.
Once signed, the report becomes the artefact you can hand over — to the employee who asks for their hours, to a payroll auditor, or to an inspector. The underlying records support it; the signed document tells the story.
Case study: Spain’s daily register
Spain is the clearest example of the post-2019 model. Since Royal Decree-Law 8/2019, every company — regardless of size or sector — must keep a daily register of working time that includes the specific start and end time of each worker’s day.
How the register is organised and documented can be shaped through collective bargaining or a company-level agreement, or, failing that, by the employer’s decision after consulting worker representatives. The obligation itself is not negotiable; the implementation details are.
The records must be kept for four years and remain available to employees, their legal representatives and the Labour and Social Security Inspectorate. Failing to keep a compliant register can be sanctioned as a labour infringement — reason enough to treat the register as an operational system, not a formality.
What inspectors commonly flag
The most common finding is the simplest: no real system at all, or paper sheets filled in retrospectively at the end of the week. Both are easy to detect and hard to defend.
Next come records that are technically present but not credible: punches that mirror the schedule exactly every single day, groups of workers missing from the register entirely, or totals that never show a single deviation from contract hours.
Finally, there are process failures: employees who have never seen their own records, systems where entries can be edited without any trace, and companies that cannot produce records for a requested period. A useful self-test is to pick a random employee and month, export the record, and check whether the punches, corrections, incidents and signed report tell one consistent story.
Key takeaway
A working time record is credible when it reflects reality rather than the roster, survives corrections with a full audit trail, and can be explained end to end: what happened, who reviewed it, what changed and why, and which signed document remains as proof.
Put this guide to work in your operation
ShiftCal connects rosters, clock-in, absences, budgets, payroll, working-time records and the employee app so these rules do not live in scattered documents.
Start freePablo Almancio
Founder of ShiftCal
Building ShiftCal — AI-powered employee scheduling for shift teams.
LinkedIn