Records Held by Somebody Else
When the time data, the payroll or the workforce belongs to a third party: four questions to settle, and who answers when somebody asks.
Where a third party holds the records, the employer still has to be able to produce them — and that depends entirely on what the contract says. Outsourced payroll, a time system run as a service, an agency supplying the workers, a subcontractor on site: in each case the data that proves what somebody worked and what they were paid sits with somebody else.
The recordkeeping discipline in “Records Held by Somebody Else” should also apply to workforce technology. When a team evaluates how employees cheat time trackers in relation to how employees cheat time trackers, it should document purpose, access, retention and deletion, then preserve the source entry, approvals and correction history needed to explain the final figure.
The questions below are cheap to settle at the point of contracting and expensive to resolve afterwards, when the answer depends on a provider's goodwill or on a relationship that has ended.
For an independent reference relevant to “Records Held by Somebody Else”, consult the NIST Privacy Framework. Use it to test record quality, working-time definitions, access, retention and exception handling against the organisation’s real payroll process.
Four things to settle up front
- What is retained, in what form, and for how long?
- How quickly can it be produced, and in what format?
- What happens to it when the contract ends?
- Who may ask for it, and does a request have to go through an account manager?
The third is the one that gets omitted and the one that matters most. A provider's obligation to hold data frequently ends when the contract does, which is exactly when the employer still needs it.
Outsourced payroll
The provider holds the payroll outputs and often the configuration. The employer usually holds nothing beyond reports.
That is workable while the relationship continues and becomes a problem at transition. Taking a periodic export — payroll outputs, configuration, the rate build — in an open format, held by the employer, costs almost nothing and removes the dependency entirely.
Time systems run as a service
The vendor sets retention defaults, frequently short, for storage reasons. The employer discovers the period when it needs data older than it.
Ask the question explicitly: how long are raw punch records retained, can that be extended, and at what cost. The answer is often that it can be extended for very little, and nobody has ever asked.
Agency and supplied workers
Where workers are supplied by an agency, the agency usually holds the time records and does the paying, and the hirer holds the booking data and the site access logs.
Neither party has the complete picture, which means that when a question arises about a particular week it can only be answered by joining two record sets, and nothing in either contract usually requires that to be possible.
The questions that cross the boundary
- Who records the hours, and from what source?
- Who approves them, and is that record kept?
- Who holds the rate, and does the hirer know what it is?
- Who answers if a supplied worker asks about their pay?
- What does each party keep, and for how long?
- What happens to all of it at the end of the arrangement?
Question four is worth settling explicitly, because the person will ask whoever they see every day, which is the hirer, and the hirer usually has no information and no mechanism.
What the hirer should keep regardless
Site access logs, booking records, the shifts requested and the shifts worked, and any approval the hirer gave.
Those are the hirer's own records, they cost nothing to retain, and they are what allows the hirer to check an agency invoice or answer a question without depending on the agency's cooperation.
Subcontractors on site
A subcontractor's workers are the subcontractor's responsibility and the hirer's reputational exposure, and the hirer frequently has site access data that is more complete than anything the subcontractor holds.
Keep your own site access records whether or not the people on site are your employees. They cost nothing, they answer questions nobody can otherwise answer, and they are the only record the hirer controls.
When the provider changes
Transitions between providers are where third-party records disappear, for the same reason as internal migrations: the old system is switched off before anybody has established what it held.
Make the export an obligation that bites before termination rather than after. A clause requiring data to be provided "on request following termination" depends on a company that no longer has a commercial reason to help.
Checking what the provider actually does
Contracts describe retention; configurations implement it. The two diverge, and the employer usually has no visibility of the second.
Ask once a year for confirmation of what is actually retained, in what form, and test it by requesting something old. A provider that can produce a two-year-old raw record in a week is doing what the contract says; one that takes a month and sends a summary is not, and finding that out during an inspection is the expensive way.
Writing it into the contract
Four clauses: what is retained and for how long, the production timescale and format, the position at termination, and who may request.
Those clauses are unremarkable, providers agree to them routinely, and almost no contract contains them — because they are drafted by people thinking about service levels rather than about a question that might arrive in three years.