HomeGuides › Data Ethics and Privacy

Workplace Surveillance and Employee Monitoring: Where the Line Sits

The hard question in employee monitoring ethics is not whether you may watch. It is whether you can explain, to the person being watched, why this particular data, collected this way, for this long, is necessary. Most monitoring programmes fail that test long before they fail a legal one, and they fail it quietly, because the tool was bought for one reason and is now used for three.

Panel setting out the four tests the ICO applies to monitoring workers
Four tests, all of which have to hold. Graphic by E-Business Ethics.

What counts as monitoring

Wider than most policies assume. The Information Commissioner's Office published its final guidance on monitoring workers on 3 October 2023, written in response to remote working and the tools that came with it, and the category it describes covers:

  • device and endpoint monitoring, including screen capture, application and URL logging;
  • keystroke and idle-time tracking, and the "activity score" dashboards built on them;
  • email and message content scanning, including automated content classification;
  • camera and audio recording, including always-on video in home working;
  • vehicle telematics and location tracking on phones or vans;
  • access control, door and badge logs used for attendance;
  • biometric systems for entry or time recording.

All of it is personal data, and some of it is special category data the moment it reveals health, union membership or beliefs. A door badge log that shows who used the accessible entrance is not neutral information.

The legal floor: four tests, all of which must hold

1. A lawful basis, chosen before you switch anything on

You need one of the Article 6 bases, and in practice it is legitimate interests. That is not a free pass: it obliges you to run and record a three-part balancing test covering the purpose, whether the monitoring is necessary to achieve it, and whether the intrusion is outweighed by the workers' rights. Consent is a poor fit, because the ICO treats it as rarely freely given where there is an imbalance of power between employer and employee. If your policy says staff consented by signing the handbook, you do not have consent.

2. Tell people first

Transparency is the default and the exceptions are narrow. Workers should know what is monitored, why, who sees the output, how long it is kept and what decisions it feeds. That means a specific notice, not a line in a contract nobody reads, and it means telling people when the monitoring changes.

3. A DPIA where the risk is high

Where processing is likely to cause a high risk to workers' interests, a data protection impact assessment is mandatory. The ICO's examples are pointed: keystroke monitoring, workers' biometric data, and monitoring that may result in financial loss, such as performance management. That last one catches most productivity tools sold on the promise of ranking staff. Our guide on how to run a DPIA covers the process.

4. Covert monitoring is an exception, not a tier

Secret monitoring is permissible only in very limited circumstances, and the ICO frames these as the investigation of suspected criminal activity or serious malpractice. Practically: authorised at senior level, tightly scoped to the suspicion, time-limited, documented, and ended when the investigation ends. Covert monitoring that runs indefinitely because it was once justified is no longer covert monitoring; it is unlawful surveillance.

Where compliance stops and ethics starts

A monitoring programme can clear all four tests and still be a bad decision. Four questions separate the defensible from the merely lawful.

Is the thing you are measuring the thing you care about? Keystrokes, mouse movement and time in an application measure activity, not contribution. Measure activity and you get activity: mouse jigglers, meeting attendance for its own sake, work reshaped to be visible rather than useful. The metric becomes the job.

Would you accept this being done to you, and would you say so out loud? The reluctance to tell staff is usually the most reliable signal that monitoring has gone too far. If the plan requires people not to fully understand it, the plan is the problem.

What does it do to the people who have nothing to hide? Surveillance changes behaviour in the compliant majority, not just the deviant few. It suppresses the informal conversations where problems get raised early, and it converts discretionary effort into defensive effort. Any honest business case has to weigh that against the risk being managed.

Does home working change the calculation? Yes. The same webcam that is unremarkable in an open-plan office points into somebody's bedroom, and the household members it captures never entered any relationship with you. Proportionality is context-dependent, and the context moved.

The failure mode to design against is scope creep. Endpoint software is bought for security, then produces productivity reports because it can, then informs a promotion round, then gets quoted in a disciplinary. No single step looked like a decision. Purpose limitation exists precisely to stop this, and the control is a rule that new uses require a fresh assessment, not a fresh dashboard.

Automated decisions and scoring

Once monitoring output feeds a score, and that score affects pay, shifts, ranking or continued employment, Article 22 of the UK GDPR comes into play: solely automated decisions with legal or similarly significant effects are restricted and require safeguards, including meaningful human involvement and a route to contest the outcome. "A manager looked at the dashboard" is not meaningful involvement if the manager has neither the time nor the information to disagree with it. Our page on algorithmic bias covers why these scores are rarely as neutral as they appear.

What a defensible programme looks like on paper

  1. A stated purpose, narrow enough to fail. "Detect exfiltration of client data from managed laptops" can be tested. "Improve productivity" cannot.
  2. A documented lawful basis, with the legitimate interests assessment attached.
  3. A DPIA for anything on the ICO's high-risk list, reviewed when the tooling changes.
  4. Data minimisation by configuration. Metadata rather than content where metadata answers the question; sampling rather than continuous capture; no capture of personal accounts on a work device.
  5. A retention period that bites, with automatic deletion, because indefinitely retained logs are the thing that turns a small incident into a large one.
  6. A published worker-facing notice in plain language, and a named owner.
  7. An access and challenge route, so a worker can see what was recorded about them and dispute a conclusion drawn from it.
  8. An annual review asking the only question that matters: has this monitoring actually prevented anything?

If you are writing this into policy for the first time, our guides to writing a code of conduct and data ethics for business give the surrounding structure, and UK GDPR explained covers the legal basics.

Frequently Asked Questions

Is employee monitoring legal in the UK?

Yes, within limits. Monitoring workers is lawful if you have identified a lawful basis under the UK GDPR, told workers about it, kept it proportionate to a clearly stated purpose, and carried out a data protection impact assessment where the monitoring is high risk. Monitoring without those steps is unlawful, whatever the employment contract says.

Do employees have to consent to being monitored?

Almost never, and asking for consent usually makes things worse. Consent has to be freely given, and the imbalance of power between employer and worker means the ICO treats it as rarely valid in this context. Most employers rely on legitimate interests instead, documented in a legitimate interests assessment.

When is a DPIA required for monitoring?

Whenever the processing is likely to result in a high risk to people's rights. The ICO gives keystroke monitoring, the use of workers' biometric data, and any monitoring that could cause financial loss, such as performance management, as examples that qualify.

Can an employer monitor staff covertly?

Only exceptionally. Transparency is the default, and the ICO expects covert monitoring to be limited to the investigation of suspected criminal activity or serious malpractice, authorised at a senior level, targeted, and stopped once the investigation ends.

Is productivity scoring an automated decision?

It can be. If a score materially affects someone's pay, shifts or continued employment with no meaningful human involvement, you are in the territory of Article 22 of the UK GDPR, which restricts solely automated decisions with legal or similarly significant effects and requires safeguards.

What is the biggest ethical risk in workplace monitoring?

Scope creep. A tool installed to secure devices starts producing productivity league tables, then informs promotion, with no fresh assessment at any point. The ethical failure is rarely the original decision; it is using the data for a purpose nobody agreed to.

Sources: ICO, Employment practices and data protection: monitoring workers, final guidance published 3 October 2023.

Related: an ethical decision-making framework, building an ethical culture and what business ethics means.