Tracking & policies
Compliance profiles and regional rules
Standard, GDPR-safe, HIPAA-safe and GLBA-safe profiles, score-only capture, and the rules that apply in the EU, Germany, the UK, US states, India and Australia.
Two things sit above every tracking policy: the workspace’s compliance profile and the regional rules for where people work. Both only ever remove collection — they never add it. A policy setting that breaks one of them can’t be saved, and some settings are switched off automatically for the people a rule covers.
Compliance profiles#
The profile is set for the whole workspace. Every policy is checked against it.
| Profile | What it means |
|---|---|
| Standard | Your policies apply as configured. Key content is never captured, under any profile. |
| GDPR-safe | For teams in the EU/EEA and the UK. No silent agent, no webcam, no search queries; at most 4 screenshots an hour, blurred at least lightly; the capture window can’t be “always”; people always see their own data; media kept 90 days at most. |
| HIPAA-safe | For teams handling protected health information. No screenshots, no websites, no window titles, no silent agent, no webcam and no media retained. |
| GLBA-safe | For financial institutions handling customer data. No screenshots, no webcam, no silent agent, and websites recorded as domains only. |
Score-only (non-invasive) capture#
Separately from the workspace profile, any policy can use the Non-invasive (score-only) capture profile in its Mode & variant section. It forces screenshots, webcam and live view off, keeps websites at domain level and turns off search queries. Activity and productivity scores still work — with zero images. The demo workspace uses it for the Platform team.
Change the compliance profile#
Open Settings
Go to WorkspaceSettings and find the Compliance profile card.
Pick a profile and give a reason
Choose the profile. A Reason for the change field appears; it’s recorded in the audit log.
Save
Choose Save settings. Every policy is re-resolved straight away. Settings the new profile doesn’t allow are switched off and shown as forced changes on each policy.
Regional rules#
Some laws depend on where people work. TimeLogger works this out from the workspace’s country and, where it matters, a state or territory that the owner enters — never from IP addresses or device location. People who work somewhere else can have their own jurisdiction set on their member page (Works in (for regional rules) in Edit…).
| Where | What it means |
|---|---|
| EU / EEA (GDPR) | Silent Mode is blocked. A disclosure notice and consent record are required before capture. |
| Germany (BetrVG) | Automatic and hybrid capture need a works agreement reference on the workspace. Until one is recorded, capture falls back to the manual timer. |
| United Kingdom (UK GDPR) | A disclosure notice is required. Complete a DPIA before systematic capture. |
| Connecticut, New York, Delaware | Written-notice states: capture is blocked until each person acknowledges the written notice. |
| Illinois (BIPA) | Webcam capture needs each person’s stored written consent. |
| India (DPDP Act) | A disclosure notice is required before capture. |
| Australia | A disclosure notice is required; collection increases are scheduled 14 days ahead by default. |
| New South Wales and ACT | Silent Mode is blocked, and collection increases need at least 14 days’ notice. |
Set the state or territory and the works agreement#
In WorkspaceSettings, the Regional rules card has State or territory (for example IL or NSW; leave it blank if no state rules apply) and Works agreement reference (Germany). Enter a Reason for the change and choose Save regional settings.
The rules in force are also listed in a Regional rules panel next to every policy in the editor, grouped by jurisdiction.
When a save is blocked#
If a policy setting breaks the profile or a regional rule, the editor’s Compliance check lists it and Review & save stays disabled. Integrations that write policies directly get the same answer as a 422 response naming each rule:
{
"error": "blocked_by_compliance",
"message": "This change conflicts with the workspace compliance profile.",
"details": {
"violations": [
{ "field": "screenshots.per_hour", "rule": "gdpr_safe",
"message": "GDPR-safe profile allows at most 4 screenshots per hour" }
]
}
}What the member sees
Questions#
We’re in Germany and automatic capture stopped. Why?
Can an admin switch the workspace back to Standard?
Does TimeLogger use IP addresses to work out where someone is?
Is live view blocked under GDPR-safe?
Related: Tracking policies · Workspace settings
Something unclear or out of date? Tell your workspace admin, or write to the TimeLogger team from Settings — we update these guides with every release.