Holding the Purpose Limitation
Time data collected for pay and billing will be requested for other things. The written limit, and what happens the first time it is tested.
Procedure
Every time tracking deployment eventually faces a request to use the data for something it was not collected for. What happens then is the real policy.
The requests that arrive
"Can we see who is consistently under target hours?"
"Can we use the timesheets in this performance review?"
"Can we check whether someone was working when they said they were?"
"Can we compare the team's billable percentages?"
"Can we see what she was doing on the fourteenth?"
Each sounds reasonable and each is a different purpose from the one the data was collected for.
Why drift is costly here
The record depends on cooperation. Unlike a sensor, a timesheet is written by the person it describes.
People who believe the record is evidence against them write it accordingly: padded, rounded, reconciled to expectations, with the unbillable work omitted.
Which destroys the accuracy that billing, costing and the statutory record all depend on.
So the purpose limitation is not only an obligation. It is what keeps the data worth having, and that is the argument that persuades people unmoved by the obligation.
Writing it
What the data is for, listed: pay, statutory record, client billing, project costing.
What it is not for, listed explicitly: individual performance assessment, disciplinary matters absent a specific investigation, comparison between individuals.
Who may see individual-level data, by role.
What triggers an exception, and who authorises it.
Published to everyone, not filed with the policy set.
The first hard case
It will come within a year, usually from a manager with a genuine concern.
Decide in advance who decides, because deciding under pressure produces the wrong answer and sets the precedent.
If the answer is yes, everyone learns what the system is for within a week, and the data quality follows.
If the answer is no, and the reason is given publicly, the limitation becomes credible in a way no document achieves.
Record the decision either way.
Where an exception is legitimate
Some are, and pretending otherwise makes the policy unusable.
A specific investigation into a specific allegation, authorised, scoped to a period, logged, with the person informed unless there is a stated reason not to.
A wage dispute, where the record is the evidence and the worker is generally the one invoking it.
A regulatory request.
In each case: narrow scope, named authoriser, recorded reason, and the access logged.
Detecting drift
Audit access to individual records against the stated purposes, quarterly.
Look for browsing: access without a recorded reason, managers looking at people outside their team, repeated access to one person.
Look for derived reports that rank individuals, which tend to appear in spreadsheets rather than in the system.
Report the audit result, including a clean one, which is what makes the control visible to the people it protects.
Auditing for drift
The check that detects purpose creep while it is still small.
Log every access to individual-level data with a reason.
Review quarterly, mapping each access to a stated purpose.
Look for browsing: managers outside their team, repeated access to one person, out-of-hours access.
Look for derived reports ranking individuals, which appear in spreadsheets rather than in the system.
Report the result, including a clean one, which is what makes the control visible to the people it protects.
The legitimate exception
Some requests are proper, and a policy that admits none becomes unusable.
A specific investigation into a specific allegation: authorised, scoped to a period, logged, with the person informed unless there is a stated reason not to.
A wage dispute, where the record is the evidence and the worker is usually the one invoking it.
A regulatory or court request.
In each: narrow scope, named authoriser, recorded reason, logged access, and the access revoked afterwards.
Write these down alongside the limitation, so the policy survives the first genuine case.
A concrete product reference
When translating this principle into a buying test, view this scope example provides a concrete feature and workflow reference. Verify the relevant behaviour in a trial, retain the exported evidence and judge it against the purpose and limits described above.