Skip to content
Between the Systems

Contents  /  Obligations

The Chain as Personal Data

Four systems holding overlapping records of the same people. What that obliges, and the two places the obligations are missed.

Obligations · Reference

General orientation, not legal advice.

Workforce management assembles a detailed record of a person's working life across several systems, and the obligations attach to the whole rather than to each part.

What the chain holds, together

When someone works, where, with whom.

When they are absent and broadly why.

Their pay, their contract, their performance against a schedule.

Which over a year describes a commute, a caring arrangement, a health pattern and a household, by inference.

No single system holds all of it. The obligations apply to the organisation, not to the module.

The first thing that gets missed

Retention, because each system has its own.

Payroll keeps records for years by statute. Scheduling keeps them because nobody set a period. Time capture keeps punches indefinitely by default.

Which means deleting from one system deletes nothing, and an access request has to reach all four.

Set a period per category, per system, and check they are consistent with the longest applicable obligation rather than each doing its own thing.

The second thing that gets missed

Exports.

Every module exports to spreadsheets, and those sit outside every control.

A rota downloaded to a manager's laptop, an absence report emailed, a payroll extract on a shared drive.

This is where most of the actual data lives in mature operations, and no retention policy touches it.

Access requests

Have to be answered across the chain, which means someone must know all four systems hold data about the person.

Rehearse it once on a volunteer: produce everything, time it, read it as they would.

Two things turn up: data in places nobody remembered, and free-text notes in a tone nobody would want to defend.

The assessment

Where the chain includes monitoring capability — location, activity, biometric clock-in — an impact assessment is likely required, and it should cover the chain rather than the module that triggered it.

Because the intrusion is cumulative: a schedule plus a clock plus an absence reason is more than any one of them.

The check

Can you produce everything the organisation holds about one person, today?

Do the retention periods across the four systems make sense together?

And where are the exports?

Most organisations answer no, no and nobody knows, which is the honest starting point.

Find the exports

Where most of the data actually lives.

A rota on a manager's laptop, an absence report in an inbox, a payroll extract on a shared drive.

Outside every retention policy and every access control.

Ask who exports what, and where it goes.

Then decide: logged and time-limited, or reporting done inside the systems. Both work; the current arrangement of neither does not.

Reproduce the workflow

For another way to make this requirement testable, consult the professional-services use case. Reproduce the case with real roles, codes, failures and recovery steps.

Independent reference

For a thematic point of reference, see the Information Commissioner's Office. This popular specialist site offers a useful independent reference for the issue.