The legal framework: what Royal Decree-Law 8/2019 says and what changes with the 2025 law
The starting point is Royal Decree-Law 8/2019, of 8 March. It amended article 34.9 of the Workers' Statute (Estatuto de los Trabajadores) to make clear that every organisation, however small, must keep a daily record of each employee's working day. The record must reflect the specific start and finish times; a total hours count is not enough.
Before 2019, the Labour Inspectorate could only require the record for part-time workers or for overtime. The Supreme Court judgment of 23 March 2017 confirmed this. The 2019 amendment extended the obligation to the entire workforce, including full-time contracts.
What changes in 2025 is the format. The draft law on reducing the working day, processed in the Spanish Congress throughout 2024 and 2025, introduces a structural novelty: the record can no longer be kept on paper or in spreadsheets. It must be produced through a digital, personal, tamper-proof system, accessible in real time, both by the worker and by the Labour Inspectorate.
The change is not cosmetic. It responds to two problems identified by the Inspectorate itself during 2022 and 2023: how easy it is to reconstruct working days a posteriori when the record is analogue, and the inability to audit the hours actually worked in real time.
What the system must record exactly
The requirements have not changed in essence from what the Labour Inspectorate has been demanding since 2019, but they have become stricter on the technical side. The record must contain, for each worker and for each day actually worked:
- Exact start time of the working day.
- Exact end time of the working day.
- Relevant breaks, where the collective agreement or the individual contract provide for them (main meal break, rest periods that do not count as effective working time, etc.).
- Individual identification of the worker. Collective annotations of the type "the whole team came in at 9" are not enough.
- Data integrity. The system must guarantee that a recorded clock-in cannot be modified without leaving a trace.
To this are added requirements that were not explicit in 2019 but that the 2025 law formalises:
- Minimum retention of 4 years. This matches the limitation period for social-order infringements under article 4.1 of the LISOS (Law on Social-Order Infringements and Penalties).
- Real-time accessibility for the worker (to consult their own record) and for the Labour Inspectorate when requested, without the organisation having to prepare it manually.
- Interoperable format. The system must allow the record to be exported to a format readable by other tools, typically CSV or signed PDF.
Clock-in methods: what is allowed and what the AEPD recommends
Labour law does not impose a specific method. It leaves the organisation to decide how each worker is identified for the record. However, the AEPD (Spain's data protection authority) published in 2024 a specific guide on the use of biometrics for attendance control that severely restricts some of the most popular methods.
Clock-in with PIN or personal card
This is the option recommended by the AEPD and the most widespread in SMEs. The worker identifies themselves with a private numeric code or with a card only they use. It does not process biometric data, does not require reinforced consent and complies without friction. The trade-off is that the worker may lend their PIN to a colleague: for this reason it is common to combine it with supervision by the manager or with geolocation of the device from which the clock-in is made.
Clock-in with fingerprint
Following the AEPD's 2024 technical note, its use is severely restricted. The Agency considers this to be high-risk special-category data and that its processing is only justified when no less intrusive alternative exists. Since a PIN serves the same purpose, the AEPD has been ruling against organisations that use fingerprint and imposing penalties. In 2024, resolutions were issued against municipal companies, a healthcare entity (IVASS) and a football club.
Facial recognition
Same criterion as fingerprint: special-category biometric data. The AEPD also restricts it. It is especially risky if deployed without a prior Data Protection Impact Assessment (DPIA) and without the worker's free consent. A worker's consent within the employment relationship is generally considered vitiated by the employer-employee power imbalance, so the legal basis stands with difficulty.
Geolocation
This is an increasingly common option for mobile workers (sales staff, technicians, site work). It is legal provided the principle of proportionality is respected: data collected only at the moment of the clock-in, no continuous tracking of the worker, and clear prior information. The AEPD penalises severely those organisations that carry out continuous tracking without justification.
Exceptions to the record-keeping obligation
The following are excluded from article 34.9 of the Workers' Statute, a short but relevant list:
- Senior executives subject to the special employment relationship of RD 1382/1985 (art. 1.3.c of the Workers' Statute).
- Self-employed workers, including economically dependent self-employed workers (TRADE). They have no employer for the purposes of the Workers' Statute.
- Working members of cooperatives, where their relationship with the cooperative is cooperative rather than employment-based.
- Certain special employment relationships: domestic service, artists in public performances, professional athletes, prisoners in penitentiary institutions, among others. They are listed in article 2 of the Workers' Statute.
Interns and people on paid placements are required to keep a record, since the hours of their training plan are subject to control by the educational institution and by the host organisation.
One point that raises questions: remote workers. Law 10/2021 clarified that they are subject to the record in exactly the same way as on-site workers. The fact that the worker is at home does not exempt them from the obligation of article 34.9. What is more, the remote-work law refers to the record-keeping system in article 34.9 for the calculation of time worked.
Penalties for non-compliance
Penalties are set out in the Law on Social-Order Infringements and Penalties (LISOS), Royal Legislative Decree 5/2000. The amounts were last updated by Law 12/2022. The brackets are:
- Minor infringement (article 6.6 LISOS): between 70 and 750 euros. Applies when the non-compliance is one-off or formal.
- Serious infringement (article 7.5 LISOS): between 751 and 7,500 euros. Applies when the failure affects several workers or the entire record-keeping system. It is the most common bracket in infringement notices.
- Very serious infringement (article 8.1 LISOS): between 7,501 and 225,018 euros. Applies when the non-compliance occurs alongside another more serious breach (for example, concealment of undeclared overtime).
The Labour Inspectorate confirmed in its 2023 Report a 40% increase in actions on working-time records compared to 2022. The sectors with the highest incidence are hospitality, retail, construction and road transport. The average penalty imposed in 2023 was around 4,500 euros per notice.
It is important to know that penalties are imposed per affected organisation, not per worker with non-compliance. A single inspection can result in a single penalty for general non-compliance of the record-keeping system, and that penalty can go directly to the serious bracket if it affects the entire workforce.
How to choose time-tracking software that complies with the 2025 law
Setting aside each vendor's marketing, there is a concrete checklist worth going through before signing. It boils down to five points:
1. Record integrity
The system must prevent clock-ins from being modified retroactively without leaving a trace. Ask the vendor how corrections are handled: if the worker forgets a clock-in, they must be able to request it, but the system has to record who approved it, when and why. Silent modification is what the Inspectorate considers documentary falsehood.
2. Auditable export
It must allow generating a signed PDF or a complete CSV with the record of a worker, a site or the entire organisation for any given period. The Inspectorate typically requests the last 90 days of records for all workers; if the system takes more than a few minutes to produce that export, there is a problem.
3. AEPD-compatible clock-in method
If the vendor proposes fingerprint or facial recognition as the default option, review why. The AEPD has ruled against these systems when a less intrusive alternative exists. The safe option is clock-in with PIN or personal card, optionally combined with geolocation of the device.
4. Retention and backups
Four years is the minimum. Ask how data is stored, where the servers are located (if they are in the EU you comply with GDPR with less complication), and what guarantees there are if the vendor disappears or shuts down the service. A regular export under your control is a sensible precaution.
5. Support and onboarding
This is the point that most often fails. Many vendors sell the software and leave you alone with the manual. If your HR team is not familiar with this kind of system, bear in mind that real go-live involves loading the workforce, defining schedules and shifts per worker, configuring collective agreements and training the person who will run day-to-day operations. A good vendor walks you through that process.
How we do it at etempus
We have spent 12 years implementing time tracking in Spanish SMEs. Over those years we have learned that the problem is not the law, it is the friction of change. That is why we operate with three fixed rules.
We onboard your organisation for you. We don't leave you with a manual and a clock-in button. We gather the workforce, define the schedules with you, configure agreements and shifts, and train the person who will run the system. The first monthly close with etempus is done together.
No setup fee and no lock-in. If after three months you are not convinced, you cancel and that's it. We trust that the product sells itself once the client has seen the month close without a single incident.
PIN by default as the clock-in method, aligned with the AEPD's recommendations. We can combine it with geolocation, card or web portal for mixed workforces (office, mobile, on-site). No biometrics by default: if the Inspectorate questions it, you don't have to argue.
Frequently asked questions
Since when has recording the working day been mandatory in Spain?
Since 12 May 2019, following the entry into force of Royal Decree-Law 8/2019. Before then it was only mandatory for part-time contracts and for overtime. From that date it applies to the entire workforce, including full-time contracts and ordinary working days.
What changes with the 2025 digital time-tracking law?
The system can no longer be kept on paper or in a spreadsheet. It must be digital, personal, tamper-proof and accessible in real time by the worker and by the Labour Inspectorate. It is introduced by the draft law on reducing the working day processed during 2024 and 2025.
How long do the records have to be kept?
A minimum of 4 years, matching the limitation period for social-order infringements under article 4.1 of the LISOS. Many collective agreements require longer periods for pay-related reasons, so in practice some organisations keep the record for between 5 and 6 years.
Can fingerprint still be used to clock in in 2025?
It can, but it is very restricted. In 2024 the AEPD published a technical note considering fingerprint as special-category biometric data. It is only permitted where no less intrusive alternative exists. Since PIN clock-in serves the same purpose, the AEPD has been ruling against organisations that opt for fingerprint. In 2024 there were multiple resolutions with penalties.
And with facial recognition?
The same criterion applies: it is special-category biometric data and is only permitted where no less intrusive alternative exists. In addition, a worker's consent within the employment relationship is generally considered vitiated by the employer-employee power imbalance. In practice, the AEPD has been imposing penalties when facial recognition is deployed without a prior impact assessment.
What happens if a worker forgets to clock in?
The system must allow the worker to request a correction and the manager to approve it. What the Inspectorate does not accept is that a clock-in is modified without traceability. A good time-tracking system records who requested the correction, when, who approved it and at what moment, keeping the history available for consultation.
Do remote workers have to clock in?
Yes. Law 10/2021 on remote working clarified this: the working-time record of article 34.9 applies to remote workers exactly the same as to on-site workers. The system must allow clock-ins from home, typically via a mobile app or a web portal.
Do self-employed workers who work for an organisation have to clock in?
No, if they are genuinely self-employed. Self-employed workers, including TRADE, have no employer for the purposes of the Workers' Statute and are outside article 34.9. It is a different matter if they are in reality bogus self-employed, in which case the Inspectorate may require the record and impose penalties both for bogus self-employment and for lack of record.
What penalty can I face if I do not keep a record?
It depends on the scope. As a serious infringement, between 751 and 7,500 euros per organisation. If in addition there is concealment of overtime, it can escalate to very serious with penalties of up to 225,018 euros. The average penalty imposed in 2023 was around 4,500 euros per notice, according to the Labour Inspectorate Report.
Can I keep the record in an Excel file?
Under the legal framework prior to 2025, a well-maintained and signed Excel could serve, though always with risk. Under the 2025 law it is no longer acceptable, because it does not allow automatic auditing or real-time access, and because it can be modified retroactively without traceability. In practice, any organisation still using Excel today is exposing itself to an infringement notice if inspected.
How does etempus differ from Factorial or Sesame?
Factorial and Sesame are HR suites. They cover clock-in, payroll, onboarding, performance evaluation and several other modules. They are designed for organisations with an established HR department, and their commercial model involves minimum monthly fees. etempus specialises in time tracking. We onboard the organisation ourselves, with no minimum fee and no lock-in, and support is handled by a person with a name. It fits well with SMEs of 20 to 150 employees that want to comply with the law without complicating themselves with a suite.
How long does it take to get etempus up and running?
It depends on the size of the workforce. In an organisation of 20 employees with a single site, between 3 and 5 working days from the first call. In organisations of 100 employees with several sites or complex shifts, between one and two weeks. We handle onboarding, configuration and training of the person in charge. The first monthly close with the system is done alongside an etempus consultant.
If you run an SME and want to comply with the time-tracking law without complications, we onboard your organisation this same week. No setup fee and no lock-in.
Talk to us