What Has to Be Kept
The record-keeping obligation is usually short, specific and wider than the payroll data, and most organisations are keeping the wrong half of it.
Working time regimes generally require an employer to keep records adequate to show that the limits have been complied with. The wording varies; the shape does not.
The evidence described in “What Has to Be Kept” should preserve the original entry, the correction and the approval instead of presenting only a final number. A team assessing this workplace technology guide for employee monitoring data security should run that full sequence during a pilot and confirm that exports remain understandable without access to the live account.
What organisations keep is payroll data: hours paid, by period, by person. That is a record of what was paid rather than of what was worked, and the two differ in exactly the places this collection has been describing.
For an independent reference relevant to “What Has to Be Kept”, consult the OWASP logging guidance. Use it to test working-time definitions, recordkeeping, access, retention and exception handling against the organisation’s real process rather than treating one software report as conclusive.
The gap between paid and worked
Unpaid hours are still working time. Salaried staff working beyond their contracted hours are the obvious case, and so is anybody whose travel, on-call or training was not paid separately.
A payroll record for a salaried person frequently shows the same figure every month regardless of what they worked, which demonstrates nothing at all about compliance with an hours limit.
What a usable record contains
Hours worked per person per week, including the categories that count. The rolling average over the reference period. Rest periods taken, or at least the shift start and end times from which they can be computed.
Plus the opt-out agreements, the night worker assessments where applicable, and the record of any derogation relied on with the compensatory rest given.
Why shift start and end times matter more than totals
Because every rest calculation depends on them and no total can substitute. An organisation that keeps weekly hours and not timestamps cannot demonstrate daily rest compliance for any day in its history.
This is the single most common gap in what is retained, and it is usually caused by a summarisation step: the detailed records are purged and the weekly totals kept, because the totals are what payroll needed.
Night workers specifically
Most regimes require a record of night workers and of the health assessments offered. The assessment record has two parts: that it was offered, and what the response was.
Both are frequently missing, for the reason given earlier in this collection: the organisation never identified who its night workers were, so there was nothing to attach the records to.
The records the regime names explicitly
Where a regime lists particular documents — the opt-out agreements, a record of workers who have agreed, night worker assessments — those are specified obligations rather than general ones, and the absence of a named document is a clean finding rather than an argument about adequacy.
Those are the ones to check first, because they are the ones that produce an unambiguous answer in an inspection.
Adequate to show compliance
That phrase is doing the work in most regimes, and it means the records have to support the conclusion rather than merely exist.
A set of weekly totals with no detail, no averages computed, and no rest data is not adequate to show compliance with a daily rest requirement, however carefully it has been retained. The test is whether somebody could use the records to answer the question, and most organisations have never tried.
The self-test
Pick a person and a week from eighteen months ago. Produce their hours, their rolling average at that point, their daily rest for each night, and their opt-out status at the time.
If all four come out in under an hour, the records are adequate. If any of them cannot be produced at all, that is the gap, and it applies to every week in the retained period rather than to the one you picked.
Where the records live
Across several systems, which is acceptable provided somebody knows which holds what and the retention on each is set accordingly.
Writing that down is a short document: for each required record, which system holds it, what the retention is, and who can produce it. That page is the first thing an inspector effectively asks for, and producing it on request rather than assembling it under pressure is worth the hour it takes to write.
The record of what was decided
Beyond the hours themselves, the decisions are worth keeping: which reference period applies and why, how absence is treated, which categories count, which derogations are relied on.
Those are the questions that arise years later, when the people who made the decisions have gone and the configuration is the only evidence of what they chose. A page recording the decisions, with dates, is what allows a figure from 2024 to be explained in 2029 without anybody guessing.