Back to Blog

How to Implement a Digital Time Clock in Your SME (2026)

How to roll out a digital time clock in your SME in 5 steps: market options, GDPR and Article 202. A practical 2026 guide, no hardware, no complications.

13 min read
Partilhar:
Worker clocking in on a phone

Most Portuguese SMEs already know that recording working time is mandatory. What few people realise is that, in 2026, almost nobody needs to buy a physical time clock terminal to comply with the law. A phone is enough.

This guide is for those who have already read what Article 202 says and want to know, in concrete terms, how to move from paper or Excel to a digital system without complications. Five steps, clear GDPR rules, and what to choose between biometrics, software with geolocation, and magnetic cards.

If you are not yet familiar with the legal obligation in detail, start with Time Clock Records Are Mandatory in Portugal (2026). This post focuses on practical implementation.

Quick recap of Article 202

Article 202 of the Portuguese Labour Code (Law 7/2009) requires every employer to keep a record of employees’ working time, in an accessible place and in a format that allows immediate consultation. The rule applies to companies of any size, from the first worker.

The record must include the start and end times of work, along with breaks and interruptions. It must cover all workers, including those exempt from fixed hours and those working remotely. The data must be retained for five years (Article 202(4)).

For workers performing work away from the company, Article 202(3) gives a 15-day window to make the record available. In practice, this makes it mandatory to give remote employees a digital way to record their hours. Paper filled in after the fact does not comply.

Breaching Article 202 is a serious administrative offence, with fines calculated in Units of Account (UC). In 2026, the UC value remains at €102 (Article 242 of Law 73-A/2025, which approved the 2026 State Budget).

Fines in 2026: what you are risking

Fines vary with the company’s turnover and the degree of fault (negligence or intent). For an SME with turnover below €500,000, the amounts set out in Article 554 of the Labour Code are:

Degree of fault Fine (serious administrative offence)
Negligence €612 to €1,224 (6 to 12 UC)
Intent €1,326 to €2,652 (13 to 26 UC)

Calculated on UC 2026 = €102, set by Article 242 of Law 73-A/2025 (2026 State Budget).

The ranges rise with turnover. For companies with turnover above €10 million, the fine for intent can approach €9,690. The fine can also be applied per affected worker. If you have ten people without adequate records, the amount multiplies.

In 2026, ACT enforcement is reinforced by Regulatory Decree 2/2026, and the Authority now cross-references data with Social Security and the Tax Authority. Rather than relying on complaints, it turns up when the databases do not tally. The 2026 national inspection campaigns include working time as one of their priorities, alongside the right to disconnect and psychosocial risks.

Watch out

Having no time clock records is not only a fine risk. In a dispute over overtime, the absence of records reverses the burden of proof: the presumption runs in the worker’s favour. You can end up paying uplifts for hours you were never able to verify.

Options on the market: biometrics, software or cards

In 2026, there are essentially three families of time clock solutions. Each has clear trade-offs.

Physical biometric terminal

These are terminals with a fingerprint, facial or iris reader, installed at the company entrance. The worker presses a finger or presents their face and the system records the clock-in and clock-out.

Advantages: they make fraud difficult (no clocking in for a colleague), they work without a network, and they are robust enough for industrial settings.

Disadvantages: an upfront cost of €300 to €1,500 per terminal, plus installation and maintenance. They do not work for remote work. They require a DPIA (Data Protection Impact Assessment) and strict compliance with Article 28 of Law 58/2019, with important restrictions I detail below. In distributed companies, you need one terminal per location.

Software with geolocation (mobile-first)

The worker installs an app on a personal or company phone. When clocking in, the app captures the GPS coordinate to confirm they are at the right location. The entry is recorded in the cloud with a timestamp.

Advantages: no hardware, low cost per employee, works for remote work, on site, and in the field. Setup in minutes. Auditable, immutable logs. It does not collect biometric data, which drastically reduces the regulatory burden.

Disadvantages: it depends on the worker having a phone with GPS and mobile data. It requires informed consent and clear rules about when GPS is captured (only during working hours, only at the moment of clocking). It implies an internal policy on the use of personal phones (BYOD) if the company does not provide the device.

Magnetic card or fob

The classic card system the worker swipes on a reader. Cheaper than biometrics, but functionally similar for on-site work.

Advantages: low upfront cost, no GDPR impact (no biometric data).

Disadvantages: cards get lent out and lost. It does not cover remote work. It still requires a terminal per location.

For most Portuguese SMEs mixing on-site and remote work, time clock software with geolocation is the sweet spot between cost, flexibility and compliance. Biometrics only pays off in industrial environments with high turnover and a real risk of fraud.

Rolling out a digital time clock in 5 steps

This is the checklist I recommend to any SME moving from paper or Excel to a digital system.

Step 1: Choose a vendor

Before signing a contract, confirm these points:

  • The system records start, end, breaks and interruptions (the legal minimum).
  • It allows monthly reports to be exported as PDF and CSV or Excel.
  • It retains data for five years at no additional cost.
  • The logs are immutable (nobody in the company can edit records retroactively without leaving a trace).
  • The vendor is based or represented in Portugal, or at least uses sub-processors in the European Union, to ensure GDPR compliance on data transfers.
  • There is a free trial of at least 14 days.

Step 2: Configure the team

Before asking employees to start using it, get organised:

  • A list of employees with their expected schedule and rest day.
  • Departments and workplaces.
  • Shift types where applicable (rotating, split, night).
  • Relevant national and municipal public holidays.

The cleaner this initial configuration, the fewer corrections you will have to make later.

Step 3: Short training for the team

Despite everything being called “training” these days, for a digital time clock five minutes per employee is enough. Show them how to open the app, clock in and out, and what to do when they forget. A short video or an in-person demo. You do not need a room or a certificate.

What does need to be recorded is the formal communication to workers about the purpose of the data processing, especially where geolocation is involved. More on that in the next section.

Step 4: A one-week trial period

Launch as a pilot for a week, ideally with one department or team, before rolling out broadly. Objectives:

  • Spot workflows you had not anticipated (multiple breaks, lunches off-site, and so on).
  • Confirm the monthly reports come out as you need them.
  • Gather feedback from the team on friction in the daily flow.

At the end of the week, adjust the configuration and roll out to everyone.

Step 5: Integration with accounting

The big operational gain comes here. At month end, export the time sheet and send it straight to your accountant. If the system is any good, the file already comes in the format accounting accepts, with no reformatting.

If the vendor does not do this, you are missing one of the biggest advantages of going digital. Manually reformatted spreadsheets remain an enormous source of error.

GDPR and biometric data: the essentials

This is the section most people underestimate. GDPR rules on attendance data are not complicated, but failing one of them can wipe out the whole advantage of the digital system.

The difference between geolocation and biometrics

These are two completely different regimes.

Geolocation (a GPS coordinate at the moment of clocking) is ordinary personal data under the GDPR. It can be processed on the basis of the employer’s legitimate interest (complying with Article 202), but the CNPD (Portugal’s data protection authority) is clear: it must be proportionate, with a specific purpose, fully transparent to the worker, and only during working hours. Geolocation cannot be used to monitor performance or to track people outside working hours, on pain of being treated as unlawfully obtained evidence.

Biometrics (fingerprint, facial recognition, iris) are a special category of data under Article 9 of the GDPR, with a general prohibition on processing. Article 28(6) of Law 58/2019 opens an exception for attendance control and access control, but under strict conditions: you may only use biometric representations (templates) and the process must not allow the data to be reversed.

When you need a DPIA

A Data Protection Impact Assessment is mandatory whenever the processing involves workers (vulnerable data subjects) at scale or new technologies, and in particular where it includes biometrics. For a software solution with geolocation, most SMEs fit a simplified DPIA model. For biometrics, one is almost always required.

Data retention

Time clock records must be retained for five years (Article 202(4)). But note: that period applies to the working time record. Raw biometric data (fingerprints, facial data) cannot be retained indefinitely and cannot be used for other purposes. When an employee leaves, biometric templates must be deleted.

What you have to communicate to workers

Before implementing, communicate in writing:

  • The purpose of the processing (complying with Article 202, managing attendance).
  • The legal basis (legitimate interest or compliance with a legal obligation).
  • The data collected (timestamp, GPS, identifier).
  • The retention period (five years).
  • The worker’s rights (access, rectification, objection).
  • The data protection officer, where applicable.

This can go in an addendum to the contract or in an internal privacy policy. Without this step, the processing is vulnerable to challenge.

Practical recommendation

For most SMEs, geolocation beats biometrics on almost every practical criterion: cost, flexibility, compliance. Only move to biometrics if you have a real fraud risk and a use case that justifies the regulatory burden.

Special cases

Some situations come up repeatedly during implementation. It is worth settling them before you start, not after.

Remote work

Article 202(3) requires the record to be made available within 15 days for workers performing work away from the company. In practice, for permanent remote work, the mobile or web app has to be available to the employee from home, with cloud sync. A local spreadsheet emailed at month end does not comply.

Interns

Curricular internships (part of initial education) and professional internships (after qualification) follow different regimes. A curricular intern is not an employee, but keeping an attendance record is good practice for the purposes of the protocol with the education provider. A professional intern, under many contracts, is treated as an employee for working time recording purposes. When in doubt, record.

Workers exempt from fixed hours

An exemption from fixed hours releases the worker from the maximum working time limits, but not from the recording obligation. Article 202 is explicit: the employer must keep working time records for workers who are exempt from fixed hours.

Temporary agency work

For temporary agency work, the record is the responsibility of the user company, not the temporary work agency. If you take on agency workers, your system has to cover them.

Frequently asked questions

Can I carry on using Excel?

Technically yes. The law does not require a specific system. But Excel fails on three important points: it can be edited retroactively without leaving a trace, it is hard to audit during an inspection, and it does not cover remote work well. The ACT increasingly recommends formats with traceability. Excel is acceptable in very small, stable companies, and weak at almost everything else.

Do interns have to clock in?

Professional internships generally yes, on terms close to those of an employee. Curricular internships are not required by law, but it is recommended for the purposes of the protocol with the education provider. When in doubt, always record.

Can I ask employees to use the app on a personal phone?

You can, with transparency and proportionality. You have to explain the purpose of the processing, ensure the app only collects data at the moment of clocking (not in the background), and ideally provide an alternative for those who do not want to use a personal phone. A written BYOD policy helps a great deal.

How long does implementation take?

With off-the-shelf software, anywhere from a few hours to a week, depending on team size. Initial configuration, short training, a trial week. Physical biometric systems take longer because of the installation.

What do I do when an employee forgets to clock in?

A decent system lets the employee request a manual correction with a justification, subject to manager approval. The correction is recorded in the logs along with the name of whoever approved it. Never edit the record directly without leaving a trace, as that destroys the system's reliability in an inspection.

Conclusion

In 2026, a digital time clock has stopped being an optional upgrade and become the reasonable minimum. Portuguese SMEs still relying on paper or Excel risk fines, lose hours every month reformatting data for their accountant, and are left exposed in disputes over overtime.

The choice of system matters less than the discipline of the rollout: a vendor with auditable logs, a clean team configuration, short training, a trial week, integration with accounting. Five steps. One week, in most cases.

On GDPR: geolocation covers almost every need an SME has, with minimal regulatory burden. Biometrics only where there is a clear use case, and always with a DPIA and non-reversible templates.

For the full legal detail, see Time Clock Records Are Mandatory in Portugal (2026). For the operational side, this guide is enough.

Comply with Article 202 in 5 minutes.

Your employees clock in from their phones. You export the time sheet for accounting in one click. Free up to 5 employees.

Request a free account

About the author

Andre Nabais

Andre Nabais

Co-founder of TeamYo. Passionate about simplifying HR processes for small and medium businesses.

Want to simplify leave management?

Try TeamYo free for teams up to 5 employees.

Start Free

Related Posts