Is Employee Monitoring Legal? GDPR Rules for Workplace Tracking
Last updated: 18 August 2026
The short answer: yes, it is legal — but conditionally. No European data protection law bans an employer from monitoring work carried out on company equipment. But everything collected from an employee’s computer is personal data under Article 4(1) GDPR, and the whole regulation applies to it.
What separates lawful monitoring from unlawful monitoring is not the software. It is how it is set up. The same tool can be entirely compliant in one company and a breach in another.
Which rules apply
Workplace monitoring is not governed by one instrument. At least four layers apply at once.
| Layer | Source | What it adds |
|---|---|---|
| Human rights | ECHR Article 8 (private life, correspondence) | Any interference must be lawful, necessary and proportionate |
| Data protection | GDPR (EU) 2016/679 | Lawful basis, transparency, minimisation, rights, security |
| Employment | GDPR Article 88 + national employment law | Member States may impose stricter workplace rules |
| Guidance | Article 29 WP Opinion 2/2017 (WP249), endorsed by the EDPB | How the above applies specifically at work |
Article 88 is the one most often missed: GDPR sets the floor, not the ceiling. In several Member States, works council consultation or a collective agreement is a precondition for introducing monitoring at all.
Three conditions
Monitoring is lawful when three conditions hold at the same time. Satisfying two does not compensate for missing the third.
1. A lawful basis (Article 6)
- Legitimate interests — Article 6(1)(f). The most common basis. It requires a documented balancing test: the employer’s interest in continuity, security and resource management weighed against the employee’s rights and freedoms. The accountability principle in Article 5(2) means the test must exist in writing, not just in someone’s head.
- Contractual necessity — Article 6(1)(b). For processing genuinely required by the employment contract: attendance, timekeeping, payroll.
- Legal obligation — Article 6(1)(c). Where law requires records to be kept.
- Consent — Article 6(1)(a). Possible in theory, weak in practice. See below.
Different data categories may rest on different bases. What is not optional is recording which basis covers which category before processing starts.
2. Transparency (Articles 12–14)
Before processing begins, employees must know the controller’s identity, the purposes and legal basis, the legitimate interests pursued where Article 6(1)(f) applies, recipients, retention periods, and how to exercise their rights.
A clause in the employment contract does not discharge this. It takes a separate privacy notice, a record of delivery, and an accessible processing policy. Transparency is independent of consent: relying on legitimate interests does not remove the duty to inform.
3. Data minimisation and proportionality — Article 5(1)(c)
Data must be adequate, relevant and limited to what is necessary. The decisive question: could the same purpose have been achieved with less data? If yes, the excess is unlawful.
Measuring how long someone spends in an application does not require a screenshot every few seconds. The application name and a duration are enough.
Article 5(1)(e) travels with it: data is kept no longer than necessary. Indefinite retention is a breach in itself.
What the ECtHR says: the Barbulescu criteria
The Grand Chamber of the European Court of Human Rights in Bărbulescu v. Romania (5 September 2017, application no. 61496/08) set out what national authorities must weigh. The list works well as a balancing-test template:
- Was the employee notified in advance of the possibility of monitoring and of its nature?
- What was the extent of the monitoring and the degree of intrusion? (Is it the flow or the content of communications, is it time-limited, how many people have access to the results?)
- Did the employer give legitimate reasons justifying the monitoring and its extent? (Monitoring content requires weightier justification.)
- Was a less intrusive method possible?
- What consequences did the monitoring have for the employee, and how were the results used?
- Were adequate safeguards provided?
Criterion four maps exactly onto Article 5(1)(c) — and in practice it is where most monitoring programmes fail.
Why consent is not the answer
Counter-intuitive but important: consent obtained in an employment relationship is usually invalid.
Article 4(11) requires consent to be freely given. Recital 43 says consent is not a valid legal basis where there is a clear imbalance between the data subject and the controller. The Article 29 Working Party applied this directly to employment in Opinion 2/2017 on data processing at work: employees are almost never in a position to give or refuse consent freely.
The consequence is worse than it sounds. A consent-based system does not merely collapse when consent is withdrawn under Article 7(3); it may never have had a valid basis at all. A documented legitimate interests assessment is the sounder route.
Automated decisions and productivity scores
A frequently overlooked provision that lands squarely on this product category: Article 22 gives people the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them. Dismissal, promotion, and bonus decisions sit in that range.
A productivity score can be an input. What is required around it:
- Meaningful human involvement in the decision, recorded as such
- An explanation of the logic involved, under Articles 13(2)(f) and 15(1)(h)
- A route for the employee to express a view and contest the decision, under Article 22(3)
Systematic monitoring on this scale also triggers Article 35: a data protection impact assessment is required where processing involves systematic and extensive evaluation of personal aspects based on automated processing.
What is off the table entirely
The following do not reach the proportionality discussion.
- Recording keystroke content. It captures passwords, private messages and form data, engaging ECHR Article 8 on correspondence and, in several jurisdictions, criminal confidentiality-of-communications law.
- Accessing private communications. An employee’s personal email, messaging apps and social media remain out of bounds even when opened on a work machine.
- Monitoring outside working hours. Anything collected outside the work schedule, or from an employee’s own device, cannot be justified by a work purpose.
- Monitoring without notice. Watching an employee who does not know the system exists breaches Articles 12–14 no matter how little data is collected.
- Collecting special category data. Health, religion or trade union membership inferred through monitoring engages Article 9 and its far narrower conditions.
Is hidden mode unlawful?
Frequently asked and frequently answered wrongly. What matters is not whether the software is visible on screen, but whether the employee knows they are monitored — which is the first Barbulescu criterion.
- Notice issued, policy communicated, employee aware of what is monitored — an agent that does not display an icon is not by itself a breach.
- No notice issued — there is a breach even if the application is plainly visible.
What makes hidden mode lawful is not a technical setting. It is the paperwork behind it.
Practical checklist
Have these in place before the system goes live:
- An employee privacy notice (Articles 13–14) and a record that it was delivered
- A record of processing activities (Article 30) with defined retention periods
- A documented legitimate interests assessment, if relying on Article 6(1)(f)
- A data protection impact assessment (Article 35) for systematic monitoring
- Technical and organisational measures (Article 32): access control, encryption, access logging
- Deletion once the retention period expires (Article 5(1)(e))
- A process to answer access, objection and erasure requests within one month (Article 12(3))
- Human involvement and a contest route wherever a score feeds a decision (Article 22)
- Works council consultation where national law under Article 88 requires it
How Berqun fits
By default Berqun collects application name, website domain, window title, and the start and end time of use — the minimum needed to measure productivity. In the Barbulescu distinction, that stays at the level of the flow of activity rather than the content of communications.
Two more sensitive features are off by default and run only when the customer organisation turns them on under its own responsibility:
- Screenshots — the organisation sets the resolution, and enabling them is a deliberate choice.
- Keystroke statistics — volume only. What was typed, form contents, passwords and message bodies are never recorded under any configuration.
Monitoring can be bounded by the work calendar, so nothing is collected outside working hours at all. Data is encrypted with AES-256 and access is authorisation controlled, as Article 32 requires.
The privacy notice, the record of processing and the balancing test remain your obligations as controller. Berqun does not discharge them for you; it provides the technical settings that make proportionality achievable.
Provisions referenced
- Regulation (EU) 2016/679 (GDPR) — Art. 4 (definitions), 5 (principles), 6 (lawfulness), 7 (consent), 9 (special categories), 12–15 (transparency and access), 22 (automated decisions), 30 (records), 32 (security), 35 (DPIA), 88 (employment context); Recital 43 (imbalance of power)
- European Convention on Human Rights — Article 8 (private life and correspondence)
- ECtHR — Bărbulescu v. Romania, Grand Chamber, 5 September 2017, no. 61496/08
- Article 29 Working Party — Opinion 2/2017 on data processing at work (WP249), adopted 8 June 2017
This page is general information, not legal advice. Consult your own counsel for your record of processing, your balancing test and your privacy notice.