Skip to main content
shield_lockData protection

GDPR-compliant Employee AppUK GDPR, EU GDPR, ICO-aligned

teamly is built for the UK and EU regulatory stack: ICO-aligned monitoring controls, EU hosting, full DPA, DUAA 2025-ready and a pre-filled DPIA template. Designed so your DPO has less to do, not more.

Made in GermanyISO 27001 data centresGDPR
The three pillars

What makes an employee app GDPR-compliant

01

Lawful basis

Processing employee data needs an Article 6 lawful basis (usually performance of contract or legitimate interest), and any special category data needs an Article 9 condition. Document this in writing.

02

DPA under Article 28

Every SaaS employee app processing personal data needs a Data Processing Agreement. teamly provides a ready-to-sign standard DPA, with TOM appendix and a public sub-processor list, no SCCs needed for EU/UK clients.

03

Technical and organisational measures

Encryption in transit and at rest, role-based access controls, backups, incident response, awareness training. teamly's data centres are ISO 27001 certified, with the certification used as evidence of TOMs to your DPO.

ICO & DPC alignment

How teamly applies regulator guidance

The ICO and the Irish DPC both expect transparency, proportionality and a clear lawful basis when monitoring staff. teamly is built around these principles.

  • Transparent staff-facing privacy notice and policy template included
  • Read receipts available for safety briefings, but never used for individual performance management
  • No covert monitoring features (no GPS tracking, no productivity scoring)
  • k-anonymity threshold of 5+ enforced on all survey and analytics aggregates
  • Configurable working-time windows to honour the upcoming Right to Switch Off
  • DPIA template aligned with ICO and DPC criteria, pre-filled and updated on each release
  • Public sub-processor list with 30-day notice of changes
  • Breach notification within 24 hours to your team, well inside the 72-hour GDPR window
Article 28 GDPR

What belongs in a complete Data Processing Agreement

A Data Processing Agreement (DPA) is only valid if it covers every mandatory element under Article 28(3) GDPR. These are the points it must include.

  • Subject matter and duration of the processing
  • Nature and purpose of the processing
  • Categories of data subjects and personal data
  • Obligations and rights of the controller
  • Processor's duty to act only on documented instructions
  • Confidentiality commitment for staff involved in processing
  • Support obligations for fulfilling data subjects' rights
  • Breach notification duty that keeps the 72-hour window achievable
  • Audit rights and evidence obligations for the controller
  • Rules on sub-processors (sub-processing arrangements)
  • Deletion or return of data at contract end

With teamly, the list of sub-processors is fully transparent: during onboarding you receive a table of every sub-processor, their role and their location. Changes to this list are announced in advance, not after the fact.

Hosting & data residency

Why EU hosting is the structurally safer choice

Hosting in the EU means EU GDPR applies directly, with no US CLOUD Act exposure, and UK-to-EU transfers benefit from the adequacy decision. For sensitive employee data, that is the cleanest path.

verified

teamly

  • Servers exclusively in German (EU) data centres
  • EU GDPR applies directly to all processing
  • No sub-processors outside the EU
  • ISO 27001 certified data centres
  • UK-EU transfers covered by the adequacy decision, no IDTA or SCCs needed
warning

US providers hosting in the EU

  • Subject to the US CLOUD Act regardless of hosting location
  • Standard Contractual Clauses (SCCs) or UK IDTA required
  • Transfer Risk Assessment (TRA) mandatory
  • Additional technical safeguards recommended
  • More complex risk documentation for your DPO
Checklist

What to check when choosing a provider

  • Where are the servers located? UK, EU or US?
  • Is there a standard DPA under Article 28 GDPR?
  • Is the provider's data centre ISO 27001 certified?
  • Who are the sub-processors, and where are they based?
  • What TOM list is attached to the DPA?
  • Is there a template consultation or works agreement for staff representatives?
  • How are read receipts and analytics technically prevented from becoming individual performance monitoring?
  • How does data deletion work after contract end?
  • What encryption is used at rest and in transit?
  • Is there a named DPO and a contact point for data breaches?
Deletion concept

When employee data gets deleted

A deletion concept sets out, for every data category, how long it is kept and when it is deleted. Without one, data tends to be kept indefinitely, which breaches the storage limitation principle (Article 5(1)(e) GDPR).

Data categoryRetention periodLegal basis
Ongoing employment relationshipAs long as necessaryEmployment contract
Payroll and salary records3 to 6 years after employment endsHMRC PAYE rules, Companies Act 2006
Rejected candidate dataTypically 6 monthsEquality Act 2010 claims window (best practice)
App messaging and usage dataShort, defined periodsteamly's deletion concept
Working time records2 yearsWorking Time Regulations 1998 (reg. 9)

teamly enforces these periods technically through automated deletion routines, rather than relying on manual housekeeping. Every automated deletion is logged with a timestamp, so evidence is always ready for your DPO.

Deletion concept

Every deletion is logged, every period is configured.

teamly enforces retention periods technically and logs every automated deletion. Evidence for your DPO is always current.

Book a demo
Articles 15 to 22 GDPR

Your employees' rights

Everyone whose data is processed has six core rights against their employer. teamly supports fulfilling these rights with structured, documented processes.

fact_check

Right of access

Art. 15 GDPR

Employees can ask at any time what data is held about them. teamly supports this with a structured data export instead of manual research.

edit_note

Right to rectification

Art. 16 GDPR

Inaccurate or outdated data must be corrected. Employees can maintain some of their own core details in their profile.

delete_forever

Right to erasure

Art. 17 GDPR

The right to be forgotten: once a retention period expires, or on request, data is deleted and logged in the deletion log.

block

Right to restriction

Art. 18 GDPR

Instead of deletion, a record can be flagged and restricted in disputed cases. The data is kept but blocked from further processing.

download

Right to data portability

Art. 20 GDPR

Employees can request their data in a structured, machine-readable format, for example when changing employer.

front_hand

Right to object

Art. 21 GDPR

Certain processing can be objected to. teamly logs the handling of every objection so it stays traceable.

Article 32 GDPR

Technical and organisational measures in detail

Eight classic TOM categories, each with an example measure at teamly. ISO 27001 certification of our data centres serves as external evidence to your DPO.

badge

Physical access control

Physical access to the data centres is restricted through biometric checks and CCTV monitoring.

password

Authentication control

Multi-factor authentication and strict password policies prevent unauthorised system use.

manage_accounts

Access control

A role-permission model ensures each person only sees the data they need for their role.

lock

Transfer control

All data is TLS-encrypted throughout transmission, including between the app and the server.

history_edu

Input control

Timestamped audit logs record who entered or changed which data, and when.

gavel

Processing control

Sub-processors' contractual duty to act only on instruction is set out in the DPA and made transparent in the sub-processor table.

backup

Availability control

Redundant backups and a disaster-recovery plan protect against data loss from outages.

call_split

Separation control

Data belonging to different client organisations is processed and stored in logical separation.

Personalised advice

Have our team review your DPA draft

30 minutes, specific to your organisation: we'll walk through the DPA, TOM appendix and consultation-agreement template live in the demo, no sales pressure.

Book a demo
The risk

What a non-compliant employee app costs

These four risks are routinely underestimated, until it's too late.

gavel

Fines of up to £17.5 million

UK GDPR breaches carry fines of up to £17.5 million or 4% of global annual turnover, whichever is higher (the EU GDPR equivalent is €20 million). An unprepared app provider gets expensive fast.

report_problem

Employee compensation claims

Employees can claim compensation for data protection breaches under Article 82 GDPR. Every breach risks becoming a precedent inside your own organisation.

trending_down

Reputational damage

A publicised data incident involving employee data damages staff trust and feeds straight through into recruitment and employer branding.

balance

Consultation disputes without a proper process

Without a proper information-and-consultation process under the ICE Regulations 2004, staff representatives can challenge the rollout and delay or block adoption.

What teamly delivers

Four building blocks that resolve these risks

Concrete, ready to sign, and no extra work for your IT team.

description

Ready-to-sign standard DPA

teamly provides a complete Data Processing Agreement under Article 28 GDPR during onboarding, including a TOM appendix and sub-processor table.

shield_lock

ISO 27001 certified data centres

All data sits exclusively in German (EU) data centres, with no sub-processors outside the EU.

auto_delete

Automated deletion routines

Defined retention periods are enforced technically, and every deletion is documented in the deletion log.

groups

Consultation-agreement template included

A ready-made template for staff consultation under the ICE Regulations 2004, agreed with staff representatives before rollout.

FAQ

Common GDPR questions about employee apps

What HR leadership, IT directors and DPOs ask most often.

Is the UK GDPR the same as the EU GDPR?
Largely yes. The UK GDPR is the EU GDPR retained after Brexit, modified by the Data Protection Act 2018 and the Data (Use and Access) Act 2025 (DUAA). DUAA introduced lighter cookie rules, an expanded list of "recognised legitimate interests" and changes to automated decision-making. teamly applies the stricter of the two standards by default.
Who regulates employee apps in the UK and Ireland?
The Information Commissioner's Office (ICO) in the UK and the Data Protection Commission (DPC) in Ireland. Both have issued detailed guidance on monitoring at work, employer record-keeping and DPAs.
Do I need a DPIA before rolling out teamly?
Almost always, yes. Any system capable of monitoring staff at scale should trigger a Data Protection Impact Assessment. teamly ships a pre-filled DPIA template aligned to ICO criteria during onboarding.
Can teamly handle Subject Access Requests within 30 days?
Yes. Self-service SAR export is available in the admin panel, with structured data in JSON/CSV and audit logs.
Personal. Direct. No script.

Is teamly a fit for your business?

30 minutes, your industry, your real questions. Alexander, Maximilian or Michael listen first. If it fits, the demo with all your decision-makers comes next.

schedule30-minute callblockNo sales pressureverifiedMade in Germany