Guide
GDPR in commercial cleaning
Short answer. Cleaning operators must process personal data such as timestamps, location and photos in a compliant way. Core requirements are purpose limitation, retention rules and a data processing agreement with the software vendor.
GDPR affects every operator that captures staff data digitally. In cleaning, that meets crew data, client data and photo protocols. This guide walks through the practical requirements and how Taskey handles them.
What data is generated
Timestamps, locations, photo and video, ID data, tax attributes. Depending on operations also safety protocols and access rights.
Legal basis
For time tracking, statutory duty is the basis. For photo protocols, proportionality and documented purpose are needed.
Data minimization
Only capture what the process needs. No continuous GPS if NFC suffices. Photos only where they are actually needed for proof.
Data processing agreement
Every software vendor requires a DPA. Taskey includes the standard DPA in onboarding.
Common questions
- Is NFC time tracking GDPR compliant?
- Yes, if purpose, retention and access are documented. Taskey provides standard processes for all of these.
- Where is data stored?
- Only on servers in Germany. Encrypted transport. GDPR compliant.
- How long may timestamps be retained?
- Retention is set by commercial and tax law duties and by individual client requirements. Taskey lets you set retention per operator.
Related
Data protection with one contact
We ship the DPA and the record of processing activities as part of onboarding.
Start onboarding