You can monitor employees under GDPR, but rarely on the basis most employers reach for first. Consent is almost never valid in an employment relationship because of the imbalance of power, so monitoring usually stands or falls on legitimate interests — and that requires the monitoring to be necessary, proportionate, and the least intrusive option that achieves the purpose. Continuous surveillance almost never clears that bar. Targeted, disclosed monitoring often does.
This article covers why consent fails at work and what replaces it, how the proportionality test is actually applied, the monitoring practices that are usually defensible and the ones that usually are not, why Article 88 means there is no single European answer, and what has to be in place before you switch anything on.
Why Consent Fails In The Employment Relationship
The Article 29 Working Party's Opinion 2/2017 on data processing at work (WP249), adopted on 23 June 2017 and still the reference point for European regulators, is direct about this: for the majority of data processing at work, employees cannot give valid consent, because the dependency inherent in the employment relationship means consent is not freely given. An employee asked to agree to monitoring by the person who controls their income and their reference is not in a position to refuse.
That is not a technicality to be drafted around. Consent obtained under those conditions is invalid, which means the processing has no lawful basis at all, which means every subsequent argument about proportionality is moot.
So employers rely on one of the other bases. Legal obligation covers monitoring you are required to perform — certain regulated sectors, certain record-keeping duties. Performance of the employment contract covers processing genuinely necessary to pay and manage someone. Most workplace monitoring, though, sits under legitimate interests, and that is the basis this article is really about, because it is the one that comes with a test you can fail.
The Opinion works through nine scenarios, including monitoring of ICT usage inside and outside the workplace, time and attendance, video systems, vehicles used by employees, and disclosure of employee data to third parties. If you are doing any of those, someone has already written down what the concerns are.
How The Proportionality Test Is Actually Applied
Legitimate interests under Article 6(1)(f) is a three-part test, and each part does independent work.
First, is the interest legitimate? Protecting company assets, preventing fraud, meeting a regulatory duty, securing systems — these qualify without difficulty. "Understanding productivity" is vaguer and gets weaker scrutiny only until someone asks what decision the data informs.
Second, is the processing necessary for that interest? Necessity means there is no less intrusive way to achieve the same end. This is where most surveillance programmes fail, and they fail on a specific pattern: the employer identifies a real risk, then selects a monitoring method far broader than the risk requires. If the concern is exfiltration of customer records, logging access to the customer database addresses it. Recording every keystroke on every machine does not address it better; it addresses a great many other things nobody was worried about.
Third, is the interest overridden by the employee's rights and interests? Recital 47 introduces the concept that matters here — the reasonable expectations of the data subject. An employee expects their access to a production database to be logged. They do not expect their webcam to activate periodically, their personal messages on a company laptop to be read, or their location to be tracked at the weekend. The further you travel from reasonable expectation, the more the balance tips.
Two practical points follow. Covert monitoring sits at the far end of this scale and is generally lawful only in narrow circumstances — a specific, articulable suspicion, where notifying the individual would defeat the investigation, and where national law permits it. It is not a standing operating mode. And where monitoring feeds decisions about people rather than merely informing humans, a separate regime applies on top: automated performance scoring or automated disciplinary triggers engage Article 22 and the rules on automated decision-making, which has its own prohibition and its own safeguards.
What Is Usually Defensible
The line is not drawn around technologies. It is drawn around specificity, disclosure and proportion. But some patterns recur.
Generally defensible, with disclosure and a documented purpose: authentication and access logging; audit trails on systems holding personal or financial data; endpoint management on company-issued devices; monitoring aggregate network traffic for security purposes; recording who accessed which customer record and when; retention of email for defined business and legal purposes.
What these share is that each attaches to a named risk, captures only what that risk requires, and would not surprise the person being monitored.
One caveat on the logs themselves. A record of who accessed what is personal data about the person who accessed it, and stripping the username to a token reduces exposure without taking the log out of scope — the line between the two is set out in our guide to anonymisation versus pseudonymisation. Monitoring data is subject to the same retention limits and access rights as anything else you hold.
What Usually Is Not
Generally difficult: continuous screen capture; keystroke logging across all activity; always-on webcam or microphone; reading the content of personal communications; tracking location outside working hours; monitoring personal devices under a bring-your-own-device arrangement, where the employer's interest stops at the boundary of the corporate container and the employee's private life begins on the other side of it.
Two further constraints deserve naming. Broad-capture monitoring will collect special category data by accident — a keystroke log picks up a message about a health condition, a screen recording captures union correspondence — and Article 9 restricts that processing regardless of your Article 6 basis. And the Working Party took the view that data from wearables should be accessible to the employee rather than the employer, and that facial recognition in workplace video analytics is likely to be disproportionate.
One scoping note: cameras covering physical premises raise a distinct set of questions about signage, footage retention and who may view it, which sit outside this article. The broader question of what employee data you may collect across the employment lifecycle is covered in our HR data collection compliance guide. This article is about watching people work.
Article 88 Means There Is No Single European Answer
This is the part that catches distributed teams, and it is structural rather than incidental.
Article 88 permits member states to provide more specific rules for processing employees' personal data in the employment context, by law or by collective agreement. Several have. The result is that identical monitoring can be lawful in one member state and unlawful in another, and that the GDPR itself will not tell you which.
The most common form this takes is worker representation. In jurisdictions with statutory works councils, the introduction of technical systems capable of monitoring employees typically triggers a consultation or co-determination right, meaning you cannot lawfully deploy the tool until that process concludes — irrespective of how strong your legitimate interests assessment is. Several national supervisory authorities have also published their own workplace guidance, which is where the practical detail on specific technologies tends to live.
For a SaaS company with employees in three countries, the workable approach is to design to the strictest applicable standard rather than run three monitoring regimes, and to check the local position before deployment rather than after. The question to ask is not "is this GDPR compliant" but "is this lawful in each country where someone will be monitored, and does anyone have to be consulted first."
Common Mistakes With Employee Monitoring Under GDPR
Putting monitoring consent in the employment contract. Consent signed as a condition of employment is not freely given and does not become valid because it is countersigned. Worse, relying on it means you never identified a lawful basis that works.
Deploying first and disclosing later. Articles 13 and 14 require you to tell people what you are doing with their data. Monitoring introduced quietly and explained after discovery converts a defensible security measure into a transparency breach and a trust problem simultaneously.
Skipping the DPIA. The WP29 DPIA guidelines (WP248 rev.01) set out nine indicators of likely high-risk processing and treat a combination of any two as generally pointing to a DPIA. Employee monitoring hits two by itself: systematic monitoring, and vulnerable data subjects — employees qualify precisely because the power imbalance means they cannot freely consent or object. Its absence is one of the first things a regulator asks about.
Treating a personal device as company territory. Under a bring-your-own-device arrangement your interest extends to corporate data and the container holding it, not to the device. Monitoring that cannot distinguish between the two is monitoring an employee's private life.
Collecting continuously because storage is cheap. Data minimisation applies to monitoring exactly as it applies to everything else. Capture aimed at a defined purpose is defensible; capture retained indefinitely in case a purpose emerges is the definition of what the principle prohibits.
FAQ
Can we read employees' emails on company accounts?
Sometimes, narrowly. A blanket right to read correspondence is very hard to justify. What is defensible is a defined process — access limited to specific circumstances such as a documented investigation or genuine business continuity, disclosed in advance in a policy, restricted to named roles, logged, and excluding anything marked or evidently personal. The account being company-owned does not by itself settle it.
Is keystroke logging ever lawful under GDPR?
Rarely, and never as a default. Continuous keystroke capture across all activity fails the necessity limb almost automatically, because a narrower measure will address the underlying risk. It also collects special category data incidentally, engaging Article 9. In a specific, time-limited investigation with national law permitting it, the analysis can come out differently.
Do we need works council approval to monitor employees?
In several member states, yes — the introduction of systems capable of monitoring staff commonly triggers consultation or co-determination rights, and deployment before that process concludes is unlawful regardless of your legitimate interests assessment. Article 88 allows these national rules, so check each country where a monitored employee sits.
Can we track company vehicles used by employees?
Usually yes for a defined operational purpose such as fleet management, safety or asset protection, with clear notice. The difficulty is private use. Where a vehicle may be used personally, continuous tracking outside working hours is generally disproportionate, and a common resolution is a privacy mode that suspends location capture outside those hours.
Closing Thought
Most monitoring programmes are not built from a risk assessment. They are built from a product demo, which arrives with capabilities already bundled, and the legal analysis is then reverse-engineered to fit whatever the tool happens to do. That order is what produces the failures — not malice, just a default configuration nobody chose deliberately and a legitimate interests assessment written to justify a purchase already made.
The uncomfortable part is that monitoring is also visible to the people being monitored, and they talk. A programme that survives regulatory scrutiny but tells your team you do not trust them has still cost you something the assessment did not measure.
ComplyDog does not monitor anyone. It handles the documentation side of the obligations that surround this — records of processing, subprocessor tracking, DPAs and data subject requests, hosted as a portal on your own domain, including requests from employees exercising their rights over monitoring data. You can try it free for 14 days, no credit card required.