How to collect personal and business Schengen travel data
A practical, privacy-conscious employee declaration for combining personal and business Schengen dates without collecting a full holiday itinerary.
By James Walsh, Founder, ComplyEur
- Published
- 07 September 2026
- Updated
- 07 September 2026
- Reading time
- 6 min read
Employers need a complete day count, but that does not justify collecting an employee's entire holiday itinerary.
Ask for dates and qualifying destinations, not holiday details
Use a short declaration that asks an in-scope employee for relevant Schengen entry and exit dates from the rolling 180-day period, including personal and business travel. Explain that the information is used to assess proposed company trips and identify who can see it, how errors are corrected, and how long it is retained.
Do not ask for companions, hotel names, photographs, booking receipts or the private reason for a holiday unless a separate, documented need applies. The day calculation normally needs only the person, dates and enough destination information to decide whether the stay belongs in the common Schengen allowance.
Before collecting anything, the employer must identify and document its own lawful basis and provide suitable privacy information. Consent is often difficult to rely on in employment because the employee may not have a free choice.
Why personal and business travel must be combined
An ordinary visa-free traveller has one Schengen short-stay allowance. A personal holiday and a company visit both use it. GOV.UK describes the limit for many British passport holders as 90 days in any 180-day period, and arrival and departure dates both count.
An employer that sees only company bookings can therefore approve a trip against an incomplete history. For example:
| Travel already recorded | Days |
|---|---|
| Customer work trips | 67 |
| Privately booked holiday | 12 |
| Proposed conference | 8 |
The company's booking system shows a projected total of 75. The complete history reaches 87. Both are still under the legal ceiling, but they support very different decisions about another trip next month.
The guide to holidays and the Schengen limit explains this shared allowance. The declaration solves the narrow information gap; it should not become a general record of an employee's private life.
Decide the purpose before designing the form
A suitable purpose might be: “to forecast whether proposed company travel fits within an employee's applicable short-stay allowance and to maintain an accurate record of approved business travel.”
That purpose sets boundaries. Information collected for a day calculation should not quietly be reused for performance monitoring, attendance decisions, employee profiling or curiosity about where somebody spends their leave.
The Information Commissioner's Office says organisations must be clear about their purpose, select the least intrusive means, collect only what they need and prevent gradual reuse for wider purposes. It also warns that consent is not usually appropriate in employment when the power imbalance means a worker cannot freely refuse.
Ask the organisation's HR or data-protection owner to document:
- the purpose;
- the lawful basis;
- whether a data protection impact assessment is required or useful;
- the employees who are in scope;
- the authorised viewers;
- the retention rule;
- how employees exercise their rights; and
- how a disputed or incomplete history affects travel approval.
This article cannot choose a lawful basis for a particular employer. That depends on the employer's circumstances and the way the process is operated.
A minimum employee declaration
The following is a working template, not a complete privacy notice or legal form:
Schengen travel declaration
I have listed the dates of my relevant personal and business travel in the Schengen Area during the period requested. I understand that the organisation uses these dates to forecast whether proposed company travel fits within the applicable short-stay allowance.
I have included arrival and departure dates and have identified the destination sufficiently for the organisation to decide whether it belongs in the common Schengen calculation. I have also included company travel already approved or booked.
I can review the dates attributed to me and report a correction through [named process]. Access is limited to [named roles]. The information is retained under [named retention schedule]. Further details, including the lawful basis and my data-protection rights, are in [employee privacy notice].
This declaration confirms the completeness of the travel information I have supplied. It does not determine whether I have permission to enter, work, live or study in a destination.
Avoid wording that asks the employee to “consent” unless the organisation has concluded that consent is genuinely freely given and can be withdrawn without detriment. A declaration of completeness and a lawful basis for processing are different things.
Fields to include
| Field | Why it may be needed | Privacy-conscious treatment |
|---|---|---|
| Employee identity | Attach dates to the right traveller | Use an existing employee identifier rather than collecting another identity document |
| Entry date | Count the first presence day | Store as a calendar date without unnecessary time or flight data |
| Exit date | Count the final presence day | Allow prompt correction after delayed travel |
| Destination | Establish whether the stay counts | Country is normally enough; avoid hotel or street address |
| Travel type | Separate company records from privately supplied dates | Use a simple business/private flag; do not demand the holiday purpose |
| Status exception | Identify cases needing manual review | Record the minimum flag and route documents to a restricted specialist process |
Passport details, residence documents and copies can be more sensitive in practice and create additional security duties. If a specialist needs them for a separate status or work-permission review, keep that workflow and access group distinct from the basic day declaration.
Build correction into the process
Travel plans change. A delayed return, cancelled trip or data-entry mistake changes later forecasts, so accuracy must be an ongoing control rather than a promise made once.
A workable process is:
- Tell employees in scope why combined travel dates are required.
- Ask only for the relevant rolling-window history.
- Let the employee enter private dates directly into a restricted view where possible.
- Show the employee the dates attributed to them.
- Recalculate when a company trip is proposed.
- Reconcile planned dates with actual dates after return.
- Provide a named correction route and record material changes.
- Delete information when the documented purpose and retention period end.
The company should never imply that its internal record is the official EU border record. ComplyEur does not connect to the Entry/Exit System (EES); it forecasts from the information supplied. If an employee disputes an official EES record, direct them to the authority's access or correction process.
Give managers the result they need
Most line managers need an approval outcome and explanation, not access to private trip details. Separate roles can let a small travel, HR or compliance group maintain qualifying dates while managers see whether a proposed trip is within the organisation's threshold.
Avoid automated refusal without a route for human review. A warning could result from an omitted status exception, a duplicate trip or a wrong date. Employees should be able to challenge the source information and provide context before a consequential decision is made.
For the arithmetic, the free Schengen calculator runs locally in the browser. Teams should pair the calculation with the wider pre-trip compliance checklist, because day availability does not establish permission to work.
If an employee declines to provide personal dates
First check whether the request is broader than necessary and whether the privacy information is clear. An employee may reasonably resist sharing an itinerary when dates and countries are sufficient.
If the minimum history remains necessary for company travel approval, explain that the forecast cannot be treated as complete. A proportionate process may pause the proposed company booking or ask the employee to confirm independently that it fits, depending on the employer's documented policy and advice. Do not improvise disciplinary consequences through a line-manager conversation.
Sources and review date
- GOV.UK guidance on travel to the EU and Schengen Area (opens in a new tab)
- ICO guidance on data minimisation (opens in a new tab)
- ICO guidance on monitoring workers (opens in a new tab)
- ICO guidance on the right to be informed (opens in a new tab)
Sources last checked: 2026-09-07.
This is a general operational template, not legal advice or a substitute for an employee privacy notice. Obtain data-protection and employment advice for the process your organisation will actually use.
Request private beta access for privacy-conscious team tracking or read how personal holidays affect the day count.
Read next
About the author
Founder, ComplyEur
Founder of ComplyEur. Built the deterministic 90/180-day calculation engine behind the product.
Put the guidance into practice
Review ComplyEur options or speak with the team about your travel process.