Employee Monitoring Law Planner
Laws

Employee monitoring laws in France

What Employee Monitoring Law Planner sets out for a monitoring practice at a site in France: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.

Location
France
Laws placed
GDPR (the EU General Data Protection Regulation); EU AI Act; Labour Code (Code du travail), France: monitoring and CSE consultation
Guidance placed
ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law; Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 official guidance, not law; EDPB Guidelines on processing personal data through video devices 3/2019 official guidance, not law; CNIL guidance on employee monitoring and workplace video surveillance official guidance, not law
Read on
30 Sep 2026
Representative body
You set whether a CSE exists: yes, no or not sure. On not sure, its requirements read as questions.

What each practice needs here

20 practice classes
PracticeRepresentative stepNotice and policyRecording consentNot allowedPaperwork
AI emotion or sentiment detectionstatutory requirementCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldstatutory requirementemotion recognition: medical or safety onlyofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementDPIA before startArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Keystroke loggingstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldstatutory requirementno keyloggers, no constant watchofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Screenshots or screen recordingstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldstatutory requirementno keyloggers, no constant watchofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Productivity or activity scoringstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsevaluation methods toldnone heldstatutory requirementno keyloggers, no constant watchofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startno solely automated decisionArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Idle-time trackingstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldstatutory requirementno keyloggers, no constant watchofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Webcam or presence checksstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsofficial guidance, not lawsignsnone heldstatutory requirementno keyloggers, no constant watchofficial guidance, not lawnot in sanitary or rest areas (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)not in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not in break rooms or toilets (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)rarely proportionatestatutory requirementDPIA before startArt. 6 basisjustified, proportionateofficial guidance, not lawDPIA oftena few daysone monthnot consent
Email and messaging reviewstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
DLP and email content filteringstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Website or email blockingstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Web and app usage loggingstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six months
Biometric time clockstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not for working hoursstatutory requirementArt. 9 conditionDPIA before startArt. 6 basisjustified, proportionate
Access control logsstatutory requirementCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionate
CCTV (break, change or wash rooms)statutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsofficial guidance, not lawsignsnone heldofficial guidance, not lawnot in sanitary or rest areas (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)not in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not in break rooms or toilets (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawDPIA oftena few daysone monthnot consent
CCTV (work areas)statutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsofficial guidance, not lawsignsnone heldofficial guidance, not lawnot in sanitary or rest areas (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)not in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not in break rooms or toilets (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawDPIA oftena few daysone monthnot consent
GPS or vehicle telematicsstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsofficial guidance, not lawnotice in vehiclenone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not outside hours (if it runs outside work)off outside work time (if it runs outside work)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawtwo months
Mobile device locationstatutory requirementCSE consulted (where a CSE exists)official guidance, not lawCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not outside hours (if it runs outside work)off outside work time (if it runs outside work)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawtwo months
Call or speech analyticsstatutory requirementCSE consulted (where a CSE exists)verification requiredCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsverification requiredcallers told, not systematicofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six monthsverification requiredsix months
Call recordingstatutory requirementCSE consulted (where a CSE exists)verification requiredCSE consulted (where a CSE exists)statutory requirementArt. 13 informationtold before it runsverification requiredcallers told, not systematicofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisjustified, proportionateofficial guidance, not lawlogs six monthsverification requiredsix months
Social media monitoringnone heldstatutory requirementArt. 13 informationtold before it runsnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)no generalised screeningstatutory requirementArt. 6 basisjustified, proportionate
Background checks as ongoing monitoringnone heldstatutory requirementArt. 13 informationtold before it runsdisclosed to candidatesnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)no generalised screeningstatutory requirementArt. 6 basisjustified, proportionateArt. 10 authority

Every requirement held here

Findings a line here can raise

12 of 13

The provisions cited here

73 provisions
Code du travail L2312-38 al3Inform and consult the CSE before deciding to implement any means or technique for controlling employees' activity

The CSE is informed and consulted, before the decision to implement them in the undertaking, on the means or techniques allowing control of employees' activity; L2312-37 item 1 lists the implementation of such means among the one-off consultations. This covers video surveillance, geolocation and vehicle telematics, badge and time clocks, call listening and recording, email and internet logging, screen capture, activity or keystroke software and productivity indicators. A device implemented without this consultation is unlawful, and failure to consult can constitute the offence of obstruction (L2317-1).

What a reviewer asks to see: CSE consultation file and opinion for each activity-control device, dated before the decision; Inventory of monitoring devices mapped to the consultation in which each was presented; Re-consultation records when a device's purpose or scope changes
Where monitoring plans usually fall short: Badge or video systems installed without prior CSE consultation; Security tools later used for activity control without new consultation; Consultation of the CSE after deployment
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
Code du travail L2312-8 II 4Inform and consult the CSE on the introduction of new technologies and major changes to working conditions

In undertakings of at least 50 employees, the CSE is informed and consulted on matters concerning the organisation, management and general running of the undertaking, including the introduction of new technologies and any significant change to health and safety or working conditions (item 4 of L2312-8 II), and on the environmental consequences of those measures (L2312-8 III). The CSE may appoint an expert on such projects (L2315-94 item 2, costs shared 80 percent employer and 20 percent CSE under L2315-80).

What a reviewer asks to see: CSE consultation file and minutes for each new technology or significant change affecting working conditions; CSE opinion and the employer's reasoned response
Where monitoring plans usually fall short: Rollout of monitoring-capable software (collaboration suites, telematics, AI tools) treated as an IT upgrade without CSE consultation
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
Code du travail L2312-14Consult the CSE before the decision is taken

The employer's decisions are preceded by the consultation of the CSE (except before a public takeover bid under L2312-49). Draft collective agreements are not submitted to consultation. A monitoring project must therefore be presented to the CSE while it can still influence the decision, before any contract signature or deployment.

What a reviewer asks to see: Dated CSE agenda and minutes showing consultation before the decision, contract signature or deployment date; Project plan showing the consultation step ahead of go-live
Where monitoring plans usually fall short: Devices purchased or installed before the CSE is consulted; Consultation on a decision already implemented
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
CNIL guidance ACT-6Submit the device to the staff representative bodies before implementation official guidance, not law

Before any monitoring device is implemented, the employer consults the CSE in private undertakings of 50 employees or more (and EPIC and EPA employing private-law staff), or the CSA, CST or CSE and their specialised formations in public bodies. Installing a badge reader or video surveillance of staff without prior CSE consultation in an undertaking of 50 or more is given as an unlawful implementation.

What a reviewer asks to see: CSE (or CSA) consultation file, minutes and opinion dated before implementation
Where monitoring plans usually fall short: Consultation after go-live; Public bodies not consulting the CSA formation
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance VID-10Inform and consult the staff representative bodies before deciding to install cameras official guidance, not law

Staff representative bodies must be informed and consulted before any decision to install cameras.

What a reviewer asks to see: CSE consultation minutes and opinion on the camera project, dated before the installation decision
Where monitoring plans usually fall short: Cameras replaced or added without new consultation
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance GEO-7Inform or consult the representative bodies and inform each driver before installing geolocation official guidance, not law

Staff representative bodies must be informed or consulted before any decision to install geolocation in vehicles provided to employees. Each employee is informed of the controller's identity, the purposes, the legal basis, the recipients, the right to object on legitimate grounds, the retention period, the rights of access and rectification and the right to complain to the CNIL, for example by a contract amendment or a service note. The DPO, if any, is involved and the system is entered in the record of processing.

What a reviewer asks to see: CSE consultation record on the telematics project; Driver notice or contract amendment with the listed items; Record of processing entry
Where monitoring plans usually fall short: Drivers learn of trackers only after a disciplinary case
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance CALL-6Consult the representative bodies and inform employees and callers, including the periods when employees may be recorded official guidance, not law The CNIL marks the page this comes from as out of date and being updated.

Staff representative bodies are informed and consulted before any decision to install call listening or recording. Employees and callers are informed of the device, the controller, the purposes, the legal basis, the recipients, the retention, the right to object, access and rectification and the right to complain to the CNIL; callers are told orally at the start of the call (existence, purpose, possibility to object before the end of the call) with a pointer to full information. Under labour case law, employees must be told the periods during which they may be listened to or recorded. The DPO is involved and the system entered in the record of processing.

What a reviewer asks to see: CSE consultation record; Employee notice stating recording periods; Call opening script and full notice; Record of processing entry
Where monitoring plans usually fall short: Employees not told when recording is active; No caller announcement
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance NET-5Consult the representative bodies, inform staff through a charter, record the processing and involve the DPO official guidance, not law

Staff representative bodies are informed or consulted before an activity-control device on IT tools is implemented. Each employee is informed of the purposes, legal basis, recipients, retention, rights of objection, access and rectification and the right to complain to the CNIL, through a charter (annexed or not to the internal rules), an individual note or a service note. The DPO is involved and each IT control system is entered in the record of processing.

What a reviewer asks to see: IT charter with the listed information and its CSE record; Record of processing entries for filtering, logging and email controls; DPO opinion
Where monitoring plans usually fall short: DLP or monitoring suite deployed with no charter update
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance ACC-6Inform the representative bodies and give each employee clear information on the access or time system official guidance, not law

Staff representative bodies should be informed or consulted before any decision to install a time or access control device. Each employee is informed clearly, concisely and accessibly of the purposes, the legal basis, the recipients, the retention period, how to exercise rights (access, rectification, erasure, objection where applicable, restriction) and the right to complain to the CNIL, for example through an IT charter or a service note.

What a reviewer asks to see: CSE information or consultation record; Charter or service note with the listed information
Where monitoring plans usually fall short: Notice missing retention or rights information
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
ILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not law

Where workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.

What a reviewer asks to see: Consultation record for each monitoring system, dated before introduction, with the representatives' views and the employer's response
Where monitoring plans usually fall short: Monitoring tool piloted without consulting the representatives
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
EU AI Act Art. 26Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What a reviewer asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
Where monitoring plans usually fall short: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act, read 30 Sep 2026
GDPR Art. 13Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What a reviewer asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
Where monitoring plans usually fall short: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 3.1.2Tell workers that monitoring exists, why, and what else fairness requires official guidance, not law

Workers must be told that monitoring exists, the purposes for which their data will be processed and any other information needed for fair processing; covert-capable technology makes this more pressing. Section 6.3 adds that communication should be effective and cover the circumstances of monitoring and how workers can prevent their data being captured, and that monitoring policies and rules should be clear and readily accessible.

What a reviewer asks to see: worker privacy notice section describing each monitoring activity, purpose and circumstances; monitoring policy published on the intranet with version history; guidance to workers on how to keep private use out of monitoring
Where monitoring plans usually fall short: notice mentions 'IT monitoring' without saying what or why; policy stored where workers cannot find it; no explanation of how to avoid capture of private use
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 7.1.1Warning signs at about eye level before the monitored area, making clear what is covered official guidance, not law

The sign should be placed so that people notice the surveillance before they walk into the covered zone, at roughly eye level. Camera positions need not be revealed so long as there is no doubt which areas are monitored and the context is unambiguous; people must be able to judge what a camera captures so they can avoid it or adapt their behaviour.

What a reviewer asks to see: signage plan showing each sign at eye level ahead of the monitored zone; photographs of installed signs; coverage description on or near the sign
Where monitoring plans usually fall short: signs placed inside the monitored area or above head height; no sign at staff-only entrances; ambiguous signs that do not show what is covered
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(b)Tell drivers a tracker is fitted and that movements, and possibly driving behaviour, are recorded; notice in the vehicle official guidance, not law

The employer must clearly tell employees that a tracking device is installed in the company vehicle they drive, that their movements are recorded while they use it and, depending on the technology, that their driving behaviour may be recorded too; ideally this notice is shown clearly inside each vehicle where the driver can see it.

What a reviewer asks to see: in-vehicle notice sticker or display placed in the driver's line of sight; vehicle policy and driver acknowledgement; fleet register confirming notices fitted in every vehicle
Where monitoring plans usually fall short: notice only in the fleet policy, none in the vehicle; driving behaviour recorded without telling drivers; pool and hire vehicles missing notices
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
Code du travail L1222-4Collect no personal information on an employee through a device not previously disclosed

No information concerning an employee personally may be collected by a device ("dispositif") that has not first been brought to the employee's knowledge. This is the individual notice duty for every monitoring technology: video, geolocation, badge systems, call recording, IT and email logging, screen capture, keystroke or activity software. Evidence gathered through an undisclosed device is, in principle, not usable to justify a sanction.

What a reviewer asks to see: Individual information notice for each monitoring device, dated and acknowledged or published before the device goes live (charter, service note, contract amendment, signage); Inventory of all devices that collect data on employees, with the date each was disclosed; Change log showing new notices issued when a device's purpose or scope changed
Where monitoring plans usually fall short: Devices installed for one purpose (security) later used to monitor staff without new notice; Monitoring software on laptops never mentioned in the IT charter; Notice given to the CSE but not to the employees themselves
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
CNIL guidance ACT-7Inform the people concerned before the device is put in place official guidance, not law

The device must be brought to the knowledge of the persons concerned before it is put in place, to meet the employer's duties of loyalty and information (Code du travail L1222-4 and GDPR article 13).

What a reviewer asks to see: Dated individual information (charter, note, notice) issued before go-live; GDPR article 13 content check of the notice
Where monitoring plans usually fall short: Notice issued only to the CSE, not to staff
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
Code du travail L1222-3Tell employees beforehand how they are evaluated, keep results confidential and use relevant methods

An employee is expressly informed, before they are used, of the professional evaluation methods and techniques applied to them. The results are confidential. Evaluation methods and techniques must be relevant to the purpose pursued. Productivity scoring, call evaluation and dashboard indicators used to evaluate staff fall under this duty.

What a reviewer asks to see: Written description of each evaluation method, indicator and scoring tool, given to employees before use; Access controls limiting evaluation results to those entitled; Relevance review of each indicator against the evaluation purpose
Where monitoring plans usually fall short: Productivity indicators introduced mid-year without prior notice; Individual scores visible to colleagues on shared dashboards
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
Code du travail L1221-9Collect no personal information on a candidate through an undisclosed device

No information concerning a job candidate personally may be collected by a device ("dispositif") that has not first been brought to the candidate's knowledge. Covert collection, for example undisclosed background scraping, recorded interviews or tracking tools, is prohibited.

What a reviewer asks to see: Inventory of tools that collect candidate data (ATS, video interview, background checks, social-media screening); Candidate privacy notice naming each tool before collection starts; Contracts with recruitment vendors prohibiting undisclosed collection
Where monitoring plans usually fall short: Social-media or background screening by an agency not disclosed to the candidate; Recording of interviews without prior notice
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
CNIL guidance VID-8Post permanent visible signs with the required information and give full information by other means official guidance, not law

Employees and visitors are informed by permanently displayed, visible signs in the areas concerned carrying at least a camera pictogram, the purposes, the retention period, the name or role and telephone number of the controller or DPO, the existence of data protection rights, and the right to complain to the CNIL with its contact details. The rest of the article 13 information (legal basis, recipients including those outside the EU, automated decision-making or profiling if any) may be given by other means such as a website.

What a reviewer asks to see: Photographs of signs at each filmed area; Second-layer notice (intranet or website) with full article 13 content
Where monitoring plans usually fall short: Pictogram only, with no controller contact or retention period; No sign at staff-only entrances
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not law

Before any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.

What a reviewer asks to see: Monitoring notice per system stating reasons, schedule, methods and data collected, issued before monitoring starts; Proportionality assessment showing less intrusive options considered
Where monitoring plans usually fall short: Notice states only that monitoring may occur, without schedule or methods; Screenshots captured continuously when sampling would serve the purpose
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.8Keep workers and representatives informed official guidance, not law

Workers and their representatives should be told about every data collection process, the rules governing it and their rights.

What a reviewer asks to see: Worker privacy notice covering each collection process, its rules and workers' rights; Record of the information given to worker representatives
Where monitoring plans usually fall short: Notice covers HR records but not monitoring systems
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
GDPR Art. 5Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where monitoring plans usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not law

Covert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.

What a reviewer asks to see: Authorization record for each covert monitoring exercise with the suspicion and grounds, or the legal provision relied on; End date and review of each exercise
Where monitoring plans usually fall short: Covert monitoring used for general performance concerns
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 3.1.3.2Reasonable expectations: no cameras where people expect privacy, including most workplaces, washrooms and rest areas official guidance, not law

Reasonable expectations are judged objectively, by whether a neutral third party would expect monitoring in that situation. An employee at the workplace in most cases does not expect to be monitored by the employer; monitoring is not expected in private gardens, living areas, examination and treatment rooms, and it is an intense intrusion in sanitary or sauna facilities, where no surveillance should take place. People can also expect freedom from monitoring in publicly accessible areas used for rest, recovery and leisure or where they sit and talk (restaurant tables, parks, cinemas, fitness facilities). A sign announcing cameras does not change what people can objectively expect.

What a reviewer asks to see: camera placement plan excluding toilets, changing, sauna, rest, treatment and seating areas; workplace-specific justification for any camera covering staff; periodic walk-through confirming no cameras point into excluded areas
Where monitoring plans usually fall short: cameras in or facing washrooms or changing rooms; cameras over staff rest or break areas; signage relied on as making monitoring expected
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(d)Limits on monitoring: places, data and time official guidance, not law

To keep the balance under legitimate interest, the employer should put limits on monitoring suited to its form: geographical limits (monitoring only in specific places, and never in sensitive areas such as places of worship, sanitary facilities and break rooms), data limits (no monitoring of personal electronic files and communications) and time limits (sampling rather than continuous monitoring).

What a reviewer asks to see: camera and sensor placement plan excluding toilets, changing, rest and worship areas; technical exclusion of personal folders and communications from monitoring; sampling schedule showing monitoring is periodic, not continuous
Where monitoring plans usually fall short: cameras covering break rooms or washroom entrances; monitoring that reads personal files; always-on monitoring where sampling would do
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
CNIL guidance VID-3Do not film break or rest areas, toilets, or union and staff representative premises official guidance, not law

Cameras must not film staff break or rest areas or toilets; where vending machines are damaged, the camera films only the machines, not the whole room. They must not film union or staff representative premises, nor the access to them where it leads only to those premises.

What a reviewer asks to see: Field-of-view images for each camera showing excluded areas; Site survey confirming no coverage of rest areas, toilets or representative offices
Where monitoring plans usually fall short: Break-room cameras justified by theft; Corridor cameras whose only destination is the union office
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(c)No location monitoring outside agreed working hours, save a proportionate theft safeguard official guidance, not law

Given how sensitive location data is, a lawful basis for following where employees' vehicles are beyond agreed working hours will rarely exist. If there is a real need, such as theft prevention, the implementation should be proportionate: no location registered outside hours unless the vehicle leaves a broadly defined region, and location revealed only on a break-glass basis when it does.

What a reviewer asks to see: telematics schedule suppressing location outside working hours; geofence and break-glass configuration with access logs; record of any out-of-hours location access and its reason
Where monitoring plans usually fall short: 24-hour tracking of vehicles taken home; managers able to view weekend locations; no log of break-glass access
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
CNIL guidance GEO-2Do not use geolocation to check speed, to monitor continuously, for free-roaming staff, staff representatives or outside working time official guidance, not law

A geolocation device in a vehicle provided to an employee may not be used to check speed limits or to monitor the employee permanently; in particular not in the vehicle of an employee free to organise their own travel (such as a sales representative), not to follow staff representatives in their mandate, not to collect location outside working time (commute, breaks), even against theft or to check vehicle-use rules, and not to calculate working time where another device already exists.

What a reviewer asks to see: Telematics configuration showing no speed reporting and privacy windows; List of drivers excluded (free travel organisation, representatives)
Where monitoring plans usually fall short: Speeding alerts sent to managers; 24-hour tracking of vehicles taken home
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance GEO-3Let employees switch off location collection outside working time official guidance, not law

Employees must be able to deactivate the collection or transmission of location outside working time. The employer may check the number or duration of deactivations, ask the driver for explanations and sanction abuse. Employees are informed of the installation and can access their location data on request.

What a reviewer asks to see: Privacy switch in vehicles or app; Deactivation reports and the rule for reviewing them; Handling records for access requests
Where monitoring plans usually fall short: No privacy mode in company cars used privately; Access requests for telematics data refused
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance CALL-1Listen to or record calls only occasionally, for training, evaluation, service quality or legally provided proof, collecting only what is needed official guidance, not law The CNIL marks the page this comes from as out of date and being updated.

Real-time listening and recording of calls at work are possible where the need is recognised and proportionate: occasional listening or recording to train or evaluate employees, to improve service quality, or in limited cases provided by law as proof of a contract or transaction. Only the data needed are processed (identification of the employee and evaluator, technical call data, the professional evaluation).

What a reviewer asks to see: Documented purpose and sampling rule for call recording; Data fields captured by the recording and evaluation tools
Where monitoring plans usually fall short: All calls recorded 'for quality' with no sampling
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance CALL-2Do not record calls permanently or systematically unless a law requires it official guidance, not law The CNIL marks the page this comes from as out of date and being updated.

The employer may not set up permanent or systematic listening or recording save where a legal text provides for it (emergency services, for example), and may not record all calls to deal with abusive callers: a less intrusive means is chosen, such as a system letting the employee trigger recording when a problem arises.

What a reviewer asks to see: Recording configuration (sampled or employee-triggered); Legal text relied on where recording is systematic
Where monitoring plans usually fall short: Blanket recording of every call
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
GDPR Art. 9Processing of special categories of personal data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where monitoring plans usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
EDPB video guidelines para 5.1(a)Biometrics: assess first, and know when Article 9 applies official guidance, not law

Facial recognition and other biometrics carry heightened risks and must respect lawfulness, necessity, proportionality and minimisation; the controller should first weigh the effect on fundamental rights and look at less intrusive means. Article 9 applies when three criteria meet: physical, physiological or behavioural characteristics, a specific technical processing, and the purpose of uniquely identifying a person. Classifying people by age or gender without templates to identify them is outside Article 9, but storing templates to recognise someone again (re-entry, repeat targeting) is inside it from the start. Biometric recognition that private organisations install for their own ends will in most cases need explicit consent from everyone concerned.

What a reviewer asks to see: fundamental rights impact assessment and alternatives analysis before biometric deployment; classification of the system against the three Article 9 criteria; explicit consent records for enrolled persons
Where monitoring plans usually fall short: face matching deployed without an alternatives analysis; re-identification analytics treated as mere classification; explicit consent assumed from signage
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
CNIL guidance ACC-1Do not use biometric or photo-taking time clocks to control working hours official guidance, not law

Devices for managing working hours and presence must be proportionate. Controlling hours with biometric devices (fingerprint, facial recognition) or with systematic photographs at each clock-in appears excessive and contrary to data minimisation for the purpose of time control.

What a reviewer asks to see: Time-clock specification showing no biometric capture or photographs; Minimisation assessment for the time system
Where monitoring plans usually fall short: Face-recognition or photo badge clocks deployed for attendance
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
EU AI Act Art. 5The practices listed in Article 5

Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education (except where the AI system is intended for medical or safety reasons, Art. 5(1)(f)), biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).

What a reviewer asks to see: Pre-deployment screening against the Art.5 prohibition list; Documented assessment that the system does not fall under a prohibited category
Where monitoring plans usually fall short: Deploying an Art.5-prohibited practice; Treating exceptions as routine basis
Source: EU AI Act, read 30 Sep 2026
WP249 para 5.6Video monitoring: no video analytics of expressions or movements, no facial recognition official guidance, not law

Video analytics that read workers' facial expressions automatically or flag deviations from set movement patterns are disproportionate to employees' rights and generally unlawful, and are likely to involve profiling and automated decisions; employers should refrain from facial recognition technology, and marginal exceptions cannot justify its general use. Under the GDPR, biometric identification also needs an Article 9(2) exception.

What a reviewer asks to see: CCTV system specification showing analytics and facial recognition disabled; DPIA for any video analytics considered; Article 9(2) exception record if biometric identification is used
Where monitoring plans usually fall short: emotion or attention analytics on staff cameras; facial recognition for staff monitoring; movement-pattern alerts on production lines
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 35Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What a reviewer asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
Where monitoring plans usually fall short: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 3.2.2Data protection impact assessment for high-risk monitoring and prior consultation if residual risk stays high official guidance, not law

Where monitoring, particularly with new technology, probably carries high risk, such as systematic and extensive automated evaluation with significant effects, the employer must assess its impact on data protection (a DPIA), and if the residual risk remains high it must consult the supervisory authority before starting. EDPB Opinion 12/2018 later confirmed that employee monitoring can meet the vulnerable data subjects and systematic monitoring criteria for a DPIA.

What a reviewer asks to see: DPIA for each high-risk monitoring activity, dated before deployment; residual risk decision and, where high, the prior consultation file; DPO advice recorded on the DPIA
Where monitoring plans usually fall short: DPIA completed after go-live; residual high risk accepted without consulting the authority; a single generic DPIA covering unrelated monitoring tools
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1(b)Proportionality and subsidiarity, whatever the legal ground, tested before monitoring starts official guidance, not law

Whatever legal ground is used, the employer should apply proportionality and subsidiarity and should run a proportionality test before processing begins: whether the processing is needed for a legitimate purpose, whether it is fair, proportionate to the concern and transparent, and which measures keep any intrusion into private life and the secrecy of communications to the minimum. The test can sit inside a data protection impact assessment, and section 6.2 repeats it for every monitoring tool before deployment.

What a reviewer asks to see: documented proportionality test per monitoring tool, dated before go-live; record of less intrusive alternatives considered and why rejected; sign-off by the accountable manager and DPO where one exists
Where monitoring plans usually fall short: proportionality assessed only after a complaint; no alternatives considered; assessment copied from the vendor's marketing material
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.4.1Home and remote working: no keystroke, mouse, screen or webcam capture official guidance, not law

Software that logs keystrokes and mouse movements, captures screens at random or set intervals, logs applications used and for how long, or switches on webcams to collect footage is disproportionate, and a legitimate interest ground for it will very rarely exist, recording keystrokes and mouse movements being the Opinion's example. The risks of remote working should be met proportionately, whatever the technology, especially where business and private use blur.

What a reviewer asks to see: remote-working security design relying on access controls and endpoint protection rather than activity capture; inventory confirming no keystroke, screenshot or webcam capture features are enabled; proportionality record for any remote monitoring used
Where monitoring plans usually fall short: bossware with screenshots and keystroke logging on home devices; webcam capture to verify presence; activity analytics switched on by default in a collaboration suite
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 22Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.

What a reviewer asks to see: An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects; The exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument; The human intervention process, showing the reviewer has the authority and the information to change the outcome; Records of contested decisions and the outcome of each review; Confirmation of whether special category data, including proxies for it, enters the model, and the safeguards applied where it does
Where monitoring plans usually fall short: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance; Necessity for a contract asserted where a manual or hybrid process would work and is merely more expensive; Special category data entering the model through proxies such as postcode, name or purchase history with no assessment; No route for the data subject to contest the decision, only a route to complain about service
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
EDPB video guidelines para 10DPIA for large-scale monitoring of public areas and large-scale special category processing; consult if high risk remains official guidance, not law

A DPIA is required where processing is likely to result in high risk, including large-scale systematic monitoring of areas open to the public (Article 35(3)(c)) and large-scale processing of special categories (Article 35(3)(b)); national DPIA lists must be consulted, and since typical surveillance purposes often call for one, many video surveillance cases will need a DPIA, whose outcome should drive the measures chosen. If high risk remains despite planned measures, the supervisory authority must be consulted before processing starts.

What a reviewer asks to see: DPIA screening against the national list for each video deployment; completed DPIA with measures traced to its findings; prior consultation file where residual risk is high
Where monitoring plans usually fall short: no screening for workplace or public-area cameras; DPIA done after installation; residual high risk accepted without consultation
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
CNIL guidance ACT-3Do not place staff under constant or permanent surveillance official guidance, not law

Placing staff under permanent surveillance is in general an excessive interference with their rights. Exceptions are limited to cases justified by the nature of the task where the device does not serve to watch how staff perform (for example permanent geolocation of an emergency vehicle so the nearest crew can be dispatched).

What a reviewer asks to see: Assessment showing the device is not continuous, or the task-based justification for continuous operation; Configuration showing sampling, triggers or time limits
Where monitoring plans usually fall short: Continuous screen, camera or activity streams to managers; Idle-time or scan-speed indicators measured to the second
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance ACT-5Keystroke loggers are disproportionate for monitoring staff official guidance, not law

Software recording every keystroke (keylogger) to monitor an employee, including one teleworking, is disproportionate: it cannot separate professional from personal information, risks capturing private-life elements and places the person under constant surveillance. The internet and email fiche treats keyloggers as unlawful save an exceptional circumstance tied to a strong security imperative.

What a reviewer asks to see: Endpoint software inventory showing no keystroke capture; If claimed, the documented exceptional security justification and its time limit
Where monitoring plans usually fall short: Endpoint monitoring or DLP suites with keystroke capture enabled by default
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance TLW-1Do not monitor teleworkers constantly by webcam, audio, screen sharing, keyloggers or forced presence checks official guidance, not law

Telework does not change the limits on control. The following are incompatible with the principles: constant video (webcam) or audio surveillance, such as requiring an employee to stay on video all day; permanent screen sharing; keyloggers; and requiring very frequent actions to prove presence (clicking every few minutes, taking photos at intervals). Control by objectives over a period, reasonable and measurable, and regular reporting by the employee are suggested instead.

What a reviewer asks to see: Inventory of telework monitoring tools with their settings; Objectives-based supervision method documented for teleworkers
Where monitoring plans usually fall short: Mandatory all-day video presence; Mouse-jiggle or click-interval presence tools
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
Code du travail L1121-1Justify and proportion every restriction on rights and freedoms

No one may restrict the rights of persons or individual and collective freedoms unless the restriction is justified by the nature of the task to be performed and proportionate to the aim pursued. Every monitoring device, rule or practice (video, geolocation, IT logging, call recording, time clocks, productivity indicators) must therefore be justified by the task and proportionate to its purpose; the courts derive from this article the employee's right to respect for private life at the workplace and during working time. The CNIL reads it as the first of three cumulative conditions for any activity-control device.

What a reviewer asks to see: Written necessity and proportionality assessment for each monitoring device, naming the task-related justification and the less intrusive alternatives considered; Purpose statement and scope for each device (who, where, when, what data); Periodic review record showing the assessment was redone when the device or the posts changed
Where monitoring plans usually fall short: Permanent or continuous monitoring of staff justified only by general security or productivity aims; No record of alternatives considered, so proportionality cannot be shown in a dispute
Source: Labour Code (Code du travail), France: monitoring and CSE consultation, read 30 Sep 2026
CNIL guidance SCR-1Do not couple screen captures with call recording official guidance, not law

In principle there may be no screen capture coupled with call recording: a screenshot is a frozen image of an isolated action that does not faithfully reflect the work and is likely to be neither relevant nor proportionate whatever the purpose; it risks capturing private items (personal emails, instant messages, passwords, union activity).

What a reviewer asks to see: Contact-centre configuration showing screenshots disabled
Where monitoring plans usually fall short: Quality tools taking periodic screenshots during calls
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance SCR-2Couple screen video with call recording only for training, with every listed safeguard official guidance, not law

Recording a video of the screen together with the call can be proportionate only for training staff, with all of these safeguards: employees are informed; the video is limited to the business application window concerned; it runs only during a call (starting when the handset is lifted and stopping when it is replaced); it concerns only people with a real training need (inexperienced or new staff) and in volumes matched to the capacity to analyse them; employees are trained only on their own recordings unless others are anonymised; access is limited and logged; and all call-recording safeguards apply. Used for evaluation, internal fraud or any purpose other than training, the coupling is disproportionate.

What a reviewer asks to see: Written purpose limited to training; Configuration limiting capture to the application window and call duration; List of trainees covered and volume rules; Access logs
Where monitoring plans usually fall short: Screen video used for performance evaluation; Full-desktop capture
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not law

Monitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.

What a reviewer asks to see: Register of continuous monitoring (CCTV, telematics, always-on tracking) with the health, safety or property ground for each
Where monitoring plans usually fall short: Always-on webcam or activity tracking for remote staff justified by productivity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not law

Output from electronic surveillance should never be the sole input when a worker's performance is judged.

What a reviewer asks to see: Appraisal procedure listing the evidence sources considered besides monitoring data; Sample appraisals showing other inputs (manager review, outputs, feedback)
Where monitoring plans usually fall short: Productivity scores from activity tracking used as the whole appraisal
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1(d)Accurate data kept no longer than needed, with a set retention period official guidance, not law

Employers should keep monitoring data accurate and retain it only as long as necessary; section 6.4 adds that data from monitoring should be stored for the shortest time needed, under a specified retention period, and deleted once no longer needed.

What a reviewer asks to see: retention schedule with a period for each monitoring data set; automated deletion configuration or purge logs; accuracy checks on monitoring outputs used in decisions
Where monitoring plans usually fall short: logs retained indefinitely by default; retention period set but never enforced; inaccurate monitoring outputs relied on without checks
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 8Storage: a few days, deleted automatically; beyond 72 hours needs stronger justification official guidance, not law

Footage may not be kept longer than the purpose needs, subject to any national storage periods. Since damage is usually noticed within a day or two, footage should in most cases be erased after a few days, ideally automatically, and the longer the period, especially beyond 72 hours, the more justification is needed. Where the controller stores footage, storage must be shown to be necessary and the period must be clearly defined for each purpose; retaining specific footage longer to pursue an identified incident remains possible.

What a reviewer asks to see: retention setting per system with the period for each purpose; justification for any period over 72 hours; incident hold procedure for footage needed for legal action
Where monitoring plans usually fall short: 30-day default retention with no reasoning; no automatic overwrite; footage kept indefinitely on local recorders
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
CNIL guidance VID-7Set a retention period tied to the purpose, in principle not over one month, and log extractions official guidance, not law

The employer defines the retention period of images in line with the purpose; in principle it does not exceed one month, and a few days usually suffice to check an incident. Images extracted for disciplinary or criminal proceedings are logged in a dedicated register and kept for the proceedings. The maximum period may not be set by the recorder's storage capacity.

What a reviewer asks to see: Recorder retention setting; Extraction register; Retention policy stating the period and reason
Where monitoring plans usually fall short: Retention equal to disk capacity (often months); Extractions with no log
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance CALL-5Keep recordings up to six months and analysis documents up to one year official guidance, not law The CNIL marks the page this comes from as out of date and being updated.

Unless a text sets a specific period or there is a particular justification, recordings may be kept up to six months at most and analysis documents up to one year. A good practice is buffer recording: listen within days, write the analysis, then delete the recording and keep only the analysis.

What a reviewer asks to see: Recording platform retention settings; Retention of evaluation grids
Where monitoring plans usually fall short: Recordings kept for years by default
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance GEO-6Keep location data two months, one year for route optimisation or proof, five years for working time official guidance, not law

In principle location data are not kept more than two months; they may be kept one year when used to optimise rounds or to prove services performed where no other proof is possible, and five years when used to track working time.

What a reviewer asks to see: Telematics retention settings per purpose; Retention schedule entry
Where monitoring plans usually fall short: Full location history kept for the life of the vehicle
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
CNIL guidance NET-2Do not receive automatic copies of all staff email, and keep connection logs no more than six months official guidance, not law

The employer may not receive an automatic copy of all messages sent or received by employees, which is excessive. Connection logs must not be kept beyond six months.

What a reviewer asks to see: Mail system rules showing no blanket journaling to managers; Proxy and connection log retention settings
Where monitoring plans usually fall short: Transport rules copying all mail to a supervisor; Proxy logs kept for years
Source: CNIL guidance on employee monitoring and workplace video surveillance (official guidance, not law), read 30 Sep 2026
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not law

Keep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.

What a reviewer asks to see: Retention schedule for worker data including monitoring records, citing purpose, legal requirement or proceedings; Deletion logs
Where monitoring plans usually fall short: Monitoring recordings kept indefinitely; Unsuccessful applicants' data kept without their agreement
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
WP249 para 5.4.2(a)Bring your own device: separate private from business use and keep out of private areas official guidance, not law

Where employees use their own devices, the employer must have measures to tell private from business use so that private information is not monitored; security scanning tools can reach all data on a device and must be carefully managed, and parts of the device presumed private (such as the photo folder) should in principle stay closed to the employer. Tracking where a personal device is and what traffic it carries may be unlawful if it captures private and family life. Section 6.1 adds that employees should be able to shield private communications from work monitoring.

What a reviewer asks to see: BYOD policy defining work and private partitions; mobile security configuration limited to the work container; record that private areas are excluded from scans and location tracking
Where monitoring plans usually fall short: full-device scans on personal phones; location of personal devices tracked; no container or partition separating work data
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 6.1Owning the equipment does not remove employees' secrecy of communications; location tracking only where strictly necessary official guidance, not law

Electronic communications from work premises, their content and traffic data, may fall within private life and correspondence under Article 8 of the European Convention on Human Rights and deserve the same protection as analogue communications. Employer ownership of the devices does not take away employees' right to confidentiality of their communications, correspondence and the location data tied to them, and tracking employees' location through their own or company devices should go no further than a legitimate purpose strictly requires.

What a reviewer asks to see: legal assessment of monitoring against Article 8 ECHR and the secrecy of communications; location tracking justification per device class; policy stating that personal communications on company devices remain protected
Where monitoring plans usually fall short: policy asserting that company ownership removes any expectation of privacy; location tracking enabled fleet-wide by default; no Article 8 analysis
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 6Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What a reviewer asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
Where monitoring plans usually fall short: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 88Processing in the context of employment

Article 88 is addressed to Member States: it lets national law or collective agreements set more specific rules for handling workers' personal data across the employment relationship, from hiring through the running of the contract, work organisation, equality, health and safety, protection of property and the exercise of employment rights, to its end. An employer therefore identifies, for every country in which it employs people, which national employment-context rules made under this article apply, and applies the safeguards those rules must contain for dignity, legitimate interests and fundamental rights: openness about the processing, data passed between companies in the same group, and any system used to monitor people at work. The article is not itself a lawful basis; the Article 6 basis, and an Article 9 condition where special category data is involved, is still needed (CJEU C-34/21 found that a national rule which only restates the general conditions of the Regulation is not a more specific rule under this article).

What a reviewer asks to see: A per-country register of the national employment data rules and collective agreements the employer relies on, each cited to its provision; Works agreements or collective agreements covering monitoring systems, with their scope, date and signatories; Employee privacy notices that name each monitoring system, its purpose and its retention; Records of intra-group transfers of HR data with the group arrangement that governs them; The Article 6 basis (and Article 9 condition where relevant) recorded for each HR processing activity alongside the national rule
Where monitoring plans usually fall short: A national employment data provision cited as the lawful basis on its own, with no Article 6 basis recorded; Monitoring tools introduced in one country under a policy written for another country's law; No record of which works agreement covers which monitoring system; HR data shared across group companies with no documented arrangement
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 3.1.1(a)Consent is not the legal ground for most processing at work; default settings are not consent official guidance, not law

For most processing at work the employer cannot and should not rely on workers' consent, because the relationship makes refusal costly and consent must be freely given, specific, informed and revocable; where a real or possible prejudice follows from refusing, the consent is invalid. Even where consent could be free, pre-set device settings or installing monitoring software do not amount to consent, which requires an active expression of will. Section 6.2 limits free consent to exceptional cases where acceptance or refusal carries no consequence at all.

What a reviewer asks to see: legal basis record per monitoring purpose naming a ground other than consent, or evidence that refusal has no consequence; withdrawal mechanism where consent is genuinely used; configuration evidence that no monitoring relies on default device settings as agreement
Where monitoring plans usually fall short: consent clause in the employment contract used as the basis for monitoring; tick-box acceptance at log-on treated as consent; no alternative for workers who refuse
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(c)Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance official guidance, not law

An employer relying on legitimate interest must show that the purpose is legitimate, that the chosen method or technology is necessary for it and proportionate to the business need, and that it runs in the least intrusive way, aimed at the specific area of risk. It must be able to show the measures that balance its interest against workers' rights, and the worker keeps the right to object on compelling legitimate grounds. Section 6.2 adds that this ground works only where the processing is strictly needed.

What a reviewer asks to see: legitimate interests assessment per monitoring purpose (purpose, necessity, balancing); record of the mitigating measures adopted; objection handling procedure and log
Where monitoring plans usually fall short: assessment that names the interest but never tests necessity; no mitigating measures recorded; objections refused without balancing
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 3.3(b)Employers should not rely on consent; employment-specific rules may come from national law or works agreements official guidance, not law

Because of the imbalance of power between employer and employee, employers should in most cases not rely on consent for video processing, since staff consent will rarely be free. National law or collective agreements (works agreements included) may set specific rules for processing employees' data in the employment context under Article 88.

What a reviewer asks to see: legal basis record for workplace cameras using a ground other than consent; copy of any works agreement or collective agreement governing cameras; register of national employment rules on video monitoring
Where monitoring plans usually fall short: staff consent forms used as the basis for CCTV; works agreement required by national law not concluded; national workplace camera rules not identified
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law

5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.

What a reviewer asks to see: Register of worker data processing activities, each with its employment-related reason and legal basis
Where monitoring plans usually fall short: Data collected for reasons unrelated to the job, such as off-duty social media activity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
GDPR Art. 10Processing of personal data relating to criminal convictions

Process personal data relating to criminal convictions and offences, or related security measures, only under the control of official authority or where Union or Member State law authorises the processing and provides appropriate safeguards for the rights and freedoms of data subjects. A comprehensive register of criminal convictions may be kept only under the control of official authority. An Article 6 lawful basis is required in addition.

What a reviewer asks to see: Identification of where conviction and offence data is processed, including screening and vetting results and incident records; The Union or Member State provision authorising the processing, and the safeguards that provision requires; Evidence the required safeguards are actually implemented rather than merely cited; Access restriction and retention applied specifically to this data, tighter than for ordinary personal data; Confirmation that no comprehensive register of convictions is maintained outside official authority
Where monitoring plans usually fall short: Background screening results retained on the personnel file indefinitely after the hiring decision is made; Reliance on the candidate's consent where national law, not consent, is the authorisation the Article requires; Offence data captured in incident reports or free text fields and never treated as Article 10 data; The authorising law identified but the specific safeguards it mandates never mapped to a control
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 5.2(a)No generalised screening of employees' social media during employment official guidance, not law

Employers should not screen employees' social media profiles on a generalised basis. Targeted observation may be lawful under legitimate interest only where it is shown to be necessary (the Opinion's example is checking former employees' professional profiles during a non-compete period), no less invasive means exist, and those concerned have been told how far the observation goes.

What a reviewer asks to see: policy prohibiting routine social media screening of staff; case record for any targeted observation with necessity reasoning; notice to the individuals observed
Where monitoring plans usually fall short: brand-monitoring tools configured to track named employees; screening of all staff profiles; targeted observation without notice
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not law

Employers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.

What a reviewer asks to see: Data inventory confirming these categories are not collected, or the documented exception and legal basis where they are
Where monitoring plans usually fall short: Criminal record checks for every role regardless of relevance
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.6No data on union membership or activities unless required official guidance, not law

Employers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.

What a reviewer asks to see: Review of HR and monitoring systems confirming union data are not collected except under a stated legal or agreement basis
Where monitoring plans usually fall short: Monitoring tools flag union-related email or chat
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
WP249 para 5.3(f)Data loss prevention: transparent rules and a warning before an email is blocked official guidance, not law

Deploying a data loss prevention tool on outgoing email must be fully justified to balance the employer's interest with employees' rights, because false positives expose legitimate and personal messages. The rules the system uses to flag an email should be fully transparent to users, and when an email is flagged the sender should be warned before it is sent, with the option to cancel.

What a reviewer asks to see: DLP justification record; published description of DLP rule categories; configuration showing sender warning and cancel option before transmission
Where monitoring plans usually fall short: silent DLP holds with investigators reading flagged mail; rules undisclosed to staff; no false-positive handling procedure
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.5Time and attendance and access control: informed, necessary, and not reused for performance evaluation official guidance, not law

Access and attendance systems, including those using biometrics or device tracking, can give an invasive view of workers' activity. A system recording who enters a secure area can rest on legitimate interest if necessary and if workers are adequately informed, but constantly watching how often and exactly when each worker enters and leaves cannot be justified once the same records serve a second purpose such as appraising performance.

What a reviewer asks to see: access control purpose statement and worker notice; report and access configuration preventing attendance data reaching performance reviews; biometric condition record where biometrics are used
Where monitoring plans usually fall short: badge data used to rank punctuality in appraisals; biometric clocks with no Article 9 condition; workers not told what access logs record
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(a)Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers official guidance, not law

Telematics collect data about the driver as well as the vehicle. Even with a legitimate interest or legal duty, the employer should first assess necessity, proportionality and subsidiarity. If a work vehicle may also be used privately, the key safeguard is letting the employee switch off location tracking temporarily when circumstances justify it (a doctor's visit, for example). The data must not be reused illegitimately, for example to follow and assess staff: vehicle trackers are for vehicles, not staff (Opinion 13/2011).

What a reviewer asks to see: telematics necessity and proportionality assessment; privacy switch configuration and driver instructions; rule barring use of telematics for driver performance ranking
Where monitoring plans usually fall short: speed alerts used for disciplinary scoring; no privacy switch on vehicles allowed for private use; telematics reports routinely reviewed by line managers
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026

See the specimen plan run Plan your own list