Employee Monitoring Law Planner
Laws

Employee monitoring laws in the Netherlands

What Employee Monitoring Law Planner sets out for a monitoring practice at a site in the Netherlands: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.

Location
The Netherlands
Laws placed
GDPR (the EU General Data Protection Regulation); EU AI Act; Works Councils Act (WOR), Netherlands; GDPR Implementation Act (UAVG), Netherlands
Guidance placed
ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law; Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 official guidance, not law; EDPB Guidelines on processing personal data through video devices 3/2019 official guidance, not law
Read on
30 Sep 2026
Representative body
You set whether a works council exists: yes, no or not sure. On not sure, its requirements read as questions.

What each practice needs here

20 practice classes
PracticeRepresentative stepNotice and policyRecording consentNot allowedPaperwork
AI emotion or sentiment detectionstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldstatutory requirementemotion recognition: medical or safety onlyofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementDPIA before startArt. 6 basis
Keystroke loggingstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basis
Screenshots or screen recordingstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basis
Productivity or activity scoringstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startno solely automated decisionArt. 6 basis
Idle-time trackingstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basis
Webcam or presence checksstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationofficial guidance, not lawsignsnone heldofficial guidance, not lawnot in sanitary or rest areas (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)not in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)rarely proportionatestatutory requirementDPIA before startArt. 6 basisofficial guidance, not lawDPIA oftena few daysnot consent
Email and messaging reviewstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
DLP and email content filteringstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
Website or email blockingstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
Web and app usage loggingstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
Biometric time clockstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldstatutory requirementnot for time registrationofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 9 conditionDPIA before startArt. 6 basis
Access control logsstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
CCTV (break, change or wash rooms)statutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationofficial guidance, not lawsignsnone heldofficial guidance, not lawnot in sanitary or rest areas (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)not in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisofficial guidance, not lawDPIA oftena few daysnot consent
CCTV (work areas)statutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationofficial guidance, not lawsignsnone heldofficial guidance, not lawnot in sanitary or rest areas (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms and break rooms or staff lounges)not in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basisofficial guidance, not lawDPIA oftena few daysnot consent
GPS or vehicle telematicsstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationofficial guidance, not lawnotice in vehiclenone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not outside hours (if it runs outside work)statutory requirementArt. 6 basis
Mobile device locationstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)not outside hours (if it runs outside work)statutory requirementArt. 6 basis
Call or speech analyticsstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
Call recordingstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)statutory requirementArt. 6 basis
Social media monitoringstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)no generalised screeningstatutory requirementArt. 6 basis
Background checks as ongoing monitoringstatutory requirementworks council consent (where a works council exists)statutory requirementArt. 13 informationnone heldofficial guidance, not lawnot in sanitary, break or prayer rooms (where it covers toilets or washrooms, showers or bathing areas, change or locker rooms, break rooms or staff lounges and prayer rooms)no generalised screeningstatutory requirementArt. 6 basisArt. 10 authority

Every requirement held here

Findings a line here can raise

11 of 13

The provisions cited here

49 provisions
WOR Art. 27(1)(l)Obtain the works council's consent to a staff arrangement: personnel tracking systems (monitoring of presence, behaviour or performance)

The entrepreneur needs the consent of the works council for every proposed decision to adopt, amend or withdraw an arrangement on facilities aimed at, or suitable for, observing or checking the presence, behaviour or performance of the persons working in the undertaking (personnel tracking systems: camera surveillance, email and internet monitoring, keystroke and screenshot tools, GPS and vehicle telematics, access badges and biometric time clocks, call recording, productivity scoring), insofar as it concerns all or a group of the persons working in the undertaking. The proposal is submitted in writing with reasons and expected consequences, consent follows at least one consultation meeting, and the entrepreneur states in writing which decision he took and from when he will implement it (27(2)); without consent or the cantonal court's permission the decision is void if the council invokes nullity in writing within one month (27(4) and (5)). The test is suitability, not intent: a facility capable of monitoring staff needs consent even if bought for another purpose. The Autoriteit Persoonsgegevens' 'OR-privacyboekje' gives test questions for personnel tracking systems; the GDPR (lawful basis, proportionality, transparency, a DPIA where the AP list requires one, such as covert camera surveillance by employers) applies on top of consent.

What a reviewer asks to see: Written consent request on the arrangement (personnel tracking systems (monitoring of presence, behaviour or performance)) with reasons and expected consequences; Consultation meeting minutes and the council's reasoned written consent; Entrepreneur's written notice of the decision taken and its implementation date; Inventory of every system suitable for observing presence, behaviour or performance, per site, with the consent decision covering it
Where monitoring plans usually fall short: Tools bought for security or IT management that are suitable for checking staff, assumed outside 27(1)(l) because monitoring is not their purpose; Covert or incidental monitoring arranged without any arrangement put to the council
Source: Works Councils Act (WOR), Netherlands, read 30 Sep 2026
WOR Art. 27(2)Submit consent matters in writing with reasons and consequences, and notify the decision and its start date

For each decision within art. 27(1), the entrepreneur submits the decision to be taken in writing to the works council with an overview of the reasons and of the consequences it is expected to have for the workforce; the council decides only after at least one consultation meeting and communicates its reasoned decision in writing; after that decision the entrepreneur informs the council as soon as possible in writing which decision he has taken and from which date he will implement it.

What a reviewer asks to see: Written consent request with reasons and consequences; Council's written reasoned decision; Entrepreneur's written notice of the decision and its implementation date, which starts the one-month nullity period
Where monitoring plans usually fall short: No written decision notice, so the one-month nullity period never starts and the decision stays open to challenge
Source: Works Councils Act (WOR), Netherlands, read 30 Sep 2026
WOR Art. 27(4)Seek the cantonal court's permission rather than act without consent

Where the entrepreneur has not obtained the council's consent, he may ask the cantonal court for permission to take the decision; the court grants it only if the council's refusal is unreasonable or the decision is required by compelling organisational, economic or social reasons. A decision taken without consent or permission is void if the council invokes nullity in writing within one month after the decision notice or after it became apparent that the decision was being applied (27(5)); the council may ask the court to bar the entrepreneur from applying it (27(6)). Any extra consent rights agreed under art. 32 follow the same rules.

What a reviewer asks to see: Cantonal court petition and order where consent was refused; Register of consent matters with status (consented, refused, court permission, withdrawn)
Where monitoring plans usually fall short: Monitoring started after the council refused consent, making data collected under it vulnerable once nullity is invoked
Source: Works Councils Act (WOR), Netherlands, read 30 Sep 2026
WOR Art. 27(1)(k)Obtain the works council's consent to a staff arrangement: processing and protection of staff personal data

The entrepreneur needs the consent of the works council for every proposed decision to adopt, amend or withdraw an arrangement on the processing and protection of the personal data of the persons working in the undertaking (for example a staff privacy regulation, retention periods, access to HR data, sharing with processors), insofar as it concerns all or a group of the persons working in the undertaking. The proposal is submitted in writing with reasons and expected consequences, consent follows at least one consultation meeting, and the entrepreneur states in writing which decision he took and from when he will implement it (27(2)); without consent or the cantonal court's permission the decision is void if the council invokes nullity in writing within one month (27(4) and (5)). The Autoriteit Persoonsgegevens explains the route in its 'OR-privacyboekje' (the works council's role in privacy at work): an arrangement is any set of rules on processing staff data, including a privacy regulation. Art. 33(3) UAVG adds that criminal-offence data about staff may be processed only under rules adopted through this WOR procedure.

What a reviewer asks to see: Written consent request on the arrangement (processing and protection of staff personal data) with reasons and expected consequences; Consultation meeting minutes and the council's reasoned written consent; Entrepreneur's written notice of the decision taken and its implementation date; Staff privacy regulation approved by the council, with its version history
Where monitoring plans usually fall short: HR privacy statement treated as information only, although it sets rules on processing and needs consent; New cloud HR or payroll processor adopted without consent to the changed processing arrangement
Source: Works Councils Act (WOR), Netherlands, read 30 Sep 2026
ILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not law

Where workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.

What a reviewer asks to see: Consultation record for each monitoring system, dated before introduction, with the representatives' views and the employer's response
Where monitoring plans usually fall short: Monitoring tool piloted without consulting the representatives
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
EU AI Act Art. 26Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What a reviewer asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
Where monitoring plans usually fall short: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act, read 30 Sep 2026
GDPR Art. 13Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What a reviewer asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
Where monitoring plans usually fall short: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 3.1.2Tell workers that monitoring exists, why, and what else fairness requires official guidance, not law

Workers must be told that monitoring exists, the purposes for which their data will be processed and any other information needed for fair processing; covert-capable technology makes this more pressing. Section 6.3 adds that communication should be effective and cover the circumstances of monitoring and how workers can prevent their data being captured, and that monitoring policies and rules should be clear and readily accessible.

What a reviewer asks to see: worker privacy notice section describing each monitoring activity, purpose and circumstances; monitoring policy published on the intranet with version history; guidance to workers on how to keep private use out of monitoring
Where monitoring plans usually fall short: notice mentions 'IT monitoring' without saying what or why; policy stored where workers cannot find it; no explanation of how to avoid capture of private use
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 7.1.1Warning signs at about eye level before the monitored area, making clear what is covered official guidance, not law

The sign should be placed so that people notice the surveillance before they walk into the covered zone, at roughly eye level. Camera positions need not be revealed so long as there is no doubt which areas are monitored and the context is unambiguous; people must be able to judge what a camera captures so they can avoid it or adapt their behaviour.

What a reviewer asks to see: signage plan showing each sign at eye level ahead of the monitored zone; photographs of installed signs; coverage description on or near the sign
Where monitoring plans usually fall short: signs placed inside the monitored area or above head height; no sign at staff-only entrances; ambiguous signs that do not show what is covered
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(b)Tell drivers a tracker is fitted and that movements, and possibly driving behaviour, are recorded; notice in the vehicle official guidance, not law

The employer must clearly tell employees that a tracking device is installed in the company vehicle they drive, that their movements are recorded while they use it and, depending on the technology, that their driving behaviour may be recorded too; ideally this notice is shown clearly inside each vehicle where the driver can see it.

What a reviewer asks to see: in-vehicle notice sticker or display placed in the driver's line of sight; vehicle policy and driver acknowledgement; fleet register confirming notices fitted in every vehicle
Where monitoring plans usually fall short: notice only in the fleet policy, none in the vehicle; driving behaviour recorded without telling drivers; pool and hire vehicles missing notices
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not law

Before any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.

What a reviewer asks to see: Monitoring notice per system stating reasons, schedule, methods and data collected, issued before monitoring starts; Proportionality assessment showing less intrusive options considered
Where monitoring plans usually fall short: Notice states only that monitoring may occur, without schedule or methods; Screenshots captured continuously when sampling would serve the purpose
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.8Keep workers and representatives informed official guidance, not law

Workers and their representatives should be told about every data collection process, the rules governing it and their rights.

What a reviewer asks to see: Worker privacy notice covering each collection process, its rules and workers' rights; Record of the information given to worker representatives
Where monitoring plans usually fall short: Notice covers HR records but not monitoring systems
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
GDPR Art. 5Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where monitoring plans usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
UAVG Art. 33(3)Process criminal-offence data about staff only under rules adopted through the works council procedure

Criminal-offence data about personnel in the controller's service may be processed only in accordance with rules adopted following the procedure of the Works Councils Act, that is with the works council's consent under WOR art. 27(1)(k) (or the equivalent employee representation route). This covers internal fraud and theft investigations, covert camera footage used to establish an offence and incident registers about employees; the Autoriteit Persoonsgegevens' DPIA list names covert camera surveillance by employers against theft or fraud (a DPIA is required even in incidental cases) and staff blacklists (art. 33(4)(c) permit).

What a reviewer asks to see: Internal investigations or incident protocol covering criminal-offence data about staff, with the works council's consent; Register of internal investigations showing the protocol applied; DPIA for covert surveillance used in investigations
Where monitoring plans usually fall short: Internal fraud investigation carried out with no protocol ever put to the works council; Findings from covert cameras stored in personnel files outside the protocol
Source: GDPR Implementation Act (UAVG), Netherlands, read 30 Sep 2026
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not law

Covert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.

What a reviewer asks to see: Authorization record for each covert monitoring exercise with the suspicion and grounds, or the legal provision relied on; End date and review of each exercise
Where monitoring plans usually fall short: Covert monitoring used for general performance concerns
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 3.1.3.2Reasonable expectations: no cameras where people expect privacy, including most workplaces, washrooms and rest areas official guidance, not law

Reasonable expectations are judged objectively, by whether a neutral third party would expect monitoring in that situation. An employee at the workplace in most cases does not expect to be monitored by the employer; monitoring is not expected in private gardens, living areas, examination and treatment rooms, and it is an intense intrusion in sanitary or sauna facilities, where no surveillance should take place. People can also expect freedom from monitoring in publicly accessible areas used for rest, recovery and leisure or where they sit and talk (restaurant tables, parks, cinemas, fitness facilities). A sign announcing cameras does not change what people can objectively expect.

What a reviewer asks to see: camera placement plan excluding toilets, changing, sauna, rest, treatment and seating areas; workplace-specific justification for any camera covering staff; periodic walk-through confirming no cameras point into excluded areas
Where monitoring plans usually fall short: cameras in or facing washrooms or changing rooms; cameras over staff rest or break areas; signage relied on as making monitoring expected
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(d)Limits on monitoring: places, data and time official guidance, not law

To keep the balance under legitimate interest, the employer should put limits on monitoring suited to its form: geographical limits (monitoring only in specific places, and never in sensitive areas such as places of worship, sanitary facilities and break rooms), data limits (no monitoring of personal electronic files and communications) and time limits (sampling rather than continuous monitoring).

What a reviewer asks to see: camera and sensor placement plan excluding toilets, changing, rest and worship areas; technical exclusion of personal folders and communications from monitoring; sampling schedule showing monitoring is periodic, not continuous
Where monitoring plans usually fall short: cameras covering break rooms or washroom entrances; monitoring that reads personal files; always-on monitoring where sampling would do
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(c)No location monitoring outside agreed working hours, save a proportionate theft safeguard official guidance, not law

Given how sensitive location data is, a lawful basis for following where employees' vehicles are beyond agreed working hours will rarely exist. If there is a real need, such as theft prevention, the implementation should be proportionate: no location registered outside hours unless the vehicle leaves a broadly defined region, and location revealed only on a break-glass basis when it does.

What a reviewer asks to see: telematics schedule suppressing location outside working hours; geofence and break-glass configuration with access logs; record of any out-of-hours location access and its reason
Where monitoring plans usually fall short: 24-hour tracking of vehicles taken home; managers able to view weekend locations; no log of break-glass access
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 9Processing of special categories of personal data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where monitoring plans usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
EDPB video guidelines para 5.1(a)Biometrics: assess first, and know when Article 9 applies official guidance, not law

Facial recognition and other biometrics carry heightened risks and must respect lawfulness, necessity, proportionality and minimisation; the controller should first weigh the effect on fundamental rights and look at less intrusive means. Article 9 applies when three criteria meet: physical, physiological or behavioural characteristics, a specific technical processing, and the purpose of uniquely identifying a person. Classifying people by age or gender without templates to identify them is outside Article 9, but storing templates to recognise someone again (re-entry, repeat targeting) is inside it from the start. Biometric recognition that private organisations install for their own ends will in most cases need explicit consent from everyone concerned.

What a reviewer asks to see: fundamental rights impact assessment and alternatives analysis before biometric deployment; classification of the system against the three Article 9 criteria; explicit consent records for enrolled persons
Where monitoring plans usually fall short: face matching deployed without an alternatives analysis; re-identification analytics treated as mere classification; explicit consent assumed from signage
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
UAVG Art. 29Use biometric identification (fingerprint or face) only where necessary for authentication or security for a weighty public-interest access need

Under GDPR art. 9(2)(g), biometric data for uniquely identifying a person may be processed only where necessary for authentication or for security purposes, and (since the Verzamelwet gegevensbescherming, in force 1 September 2026) only insofar as necessary because of a weighty public interest in lawful access to particular places, buildings, services, products, information systems or work process systems. Convenience, cost saving and time registration are not such an access need (the AP has fined an employer for fingerprint-based time registration); outside this exception, explicit consent under art. 22(2)(a), rarely freely given by employees, is the only route. The Autoriteit Persoonsgegevens' DPIA list (Staatscourant 2019, 64418) requires a DPIA for large-scale or systematic biometric processing.

What a reviewer asks to see: Necessity assessment for each biometric system showing the access interest (for example a high-security area) and why non-biometric means do not suffice; DPIA for the biometric system; Works council consent under WOR art. 27(1)(k) or (l) where staff are enrolled
Where monitoring plans usually fall short: Fingerprint or face-recognition time clocks justified by payroll accuracy or buddy-punching prevention, which is not the access-security need art. 29 requires; Biometric access extended from a secure server room to the whole office
Source: GDPR Implementation Act (UAVG), Netherlands, read 30 Sep 2026
EU AI Act Art. 5The practices listed in Article 5

Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education (except where the AI system is intended for medical or safety reasons, Art. 5(1)(f)), biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).

What a reviewer asks to see: Pre-deployment screening against the Art.5 prohibition list; Documented assessment that the system does not fall under a prohibited category
Where monitoring plans usually fall short: Deploying an Art.5-prohibited practice; Treating exceptions as routine basis
Source: EU AI Act, read 30 Sep 2026
WP249 para 5.6Video monitoring: no video analytics of expressions or movements, no facial recognition official guidance, not law

Video analytics that read workers' facial expressions automatically or flag deviations from set movement patterns are disproportionate to employees' rights and generally unlawful, and are likely to involve profiling and automated decisions; employers should refrain from facial recognition technology, and marginal exceptions cannot justify its general use. Under the GDPR, biometric identification also needs an Article 9(2) exception.

What a reviewer asks to see: CCTV system specification showing analytics and facial recognition disabled; DPIA for any video analytics considered; Article 9(2) exception record if biometric identification is used
Where monitoring plans usually fall short: emotion or attention analytics on staff cameras; facial recognition for staff monitoring; movement-pattern alerts on production lines
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 35Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What a reviewer asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
Where monitoring plans usually fall short: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 3.2.2Data protection impact assessment for high-risk monitoring and prior consultation if residual risk stays high official guidance, not law

Where monitoring, particularly with new technology, probably carries high risk, such as systematic and extensive automated evaluation with significant effects, the employer must assess its impact on data protection (a DPIA), and if the residual risk remains high it must consult the supervisory authority before starting. EDPB Opinion 12/2018 later confirmed that employee monitoring can meet the vulnerable data subjects and systematic monitoring criteria for a DPIA.

What a reviewer asks to see: DPIA for each high-risk monitoring activity, dated before deployment; residual risk decision and, where high, the prior consultation file; DPO advice recorded on the DPIA
Where monitoring plans usually fall short: DPIA completed after go-live; residual high risk accepted without consulting the authority; a single generic DPIA covering unrelated monitoring tools
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1(b)Proportionality and subsidiarity, whatever the legal ground, tested before monitoring starts official guidance, not law

Whatever legal ground is used, the employer should apply proportionality and subsidiarity and should run a proportionality test before processing begins: whether the processing is needed for a legitimate purpose, whether it is fair, proportionate to the concern and transparent, and which measures keep any intrusion into private life and the secrecy of communications to the minimum. The test can sit inside a data protection impact assessment, and section 6.2 repeats it for every monitoring tool before deployment.

What a reviewer asks to see: documented proportionality test per monitoring tool, dated before go-live; record of less intrusive alternatives considered and why rejected; sign-off by the accountable manager and DPO where one exists
Where monitoring plans usually fall short: proportionality assessed only after a complaint; no alternatives considered; assessment copied from the vendor's marketing material
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.4.1Home and remote working: no keystroke, mouse, screen or webcam capture official guidance, not law

Software that logs keystrokes and mouse movements, captures screens at random or set intervals, logs applications used and for how long, or switches on webcams to collect footage is disproportionate, and a legitimate interest ground for it will very rarely exist, recording keystrokes and mouse movements being the Opinion's example. The risks of remote working should be met proportionately, whatever the technology, especially where business and private use blur.

What a reviewer asks to see: remote-working security design relying on access controls and endpoint protection rather than activity capture; inventory confirming no keystroke, screenshot or webcam capture features are enabled; proportionality record for any remote monitoring used
Where monitoring plans usually fall short: bossware with screenshots and keystroke logging on home devices; webcam capture to verify presence; activity analytics switched on by default in a collaboration suite
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 22Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.

What a reviewer asks to see: An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects; The exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument; The human intervention process, showing the reviewer has the authority and the information to change the outcome; Records of contested decisions and the outcome of each review; Confirmation of whether special category data, including proxies for it, enters the model, and the safeguards applied where it does
Where monitoring plans usually fall short: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance; Necessity for a contract asserted where a manual or hybrid process would work and is merely more expensive; Special category data entering the model through proxies such as postcode, name or purchase history with no assessment; No route for the data subject to contest the decision, only a route to complain about service
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
EDPB video guidelines para 10DPIA for large-scale monitoring of public areas and large-scale special category processing; consult if high risk remains official guidance, not law

A DPIA is required where processing is likely to result in high risk, including large-scale systematic monitoring of areas open to the public (Article 35(3)(c)) and large-scale processing of special categories (Article 35(3)(b)); national DPIA lists must be consulted, and since typical surveillance purposes often call for one, many video surveillance cases will need a DPIA, whose outcome should drive the measures chosen. If high risk remains despite planned measures, the supervisory authority must be consulted before processing starts.

What a reviewer asks to see: DPIA screening against the national list for each video deployment; completed DPIA with measures traced to its findings; prior consultation file where residual risk is high
Where monitoring plans usually fall short: no screening for workplace or public-area cameras; DPIA done after installation; residual high risk accepted without consultation
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not law

Monitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.

What a reviewer asks to see: Register of continuous monitoring (CCTV, telematics, always-on tracking) with the health, safety or property ground for each
Where monitoring plans usually fall short: Always-on webcam or activity tracking for remote staff justified by productivity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not law

Output from electronic surveillance should never be the sole input when a worker's performance is judged.

What a reviewer asks to see: Appraisal procedure listing the evidence sources considered besides monitoring data; Sample appraisals showing other inputs (manager review, outputs, feedback)
Where monitoring plans usually fall short: Productivity scores from activity tracking used as the whole appraisal
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1(d)Accurate data kept no longer than needed, with a set retention period official guidance, not law

Employers should keep monitoring data accurate and retain it only as long as necessary; section 6.4 adds that data from monitoring should be stored for the shortest time needed, under a specified retention period, and deleted once no longer needed.

What a reviewer asks to see: retention schedule with a period for each monitoring data set; automated deletion configuration or purge logs; accuracy checks on monitoring outputs used in decisions
Where monitoring plans usually fall short: logs retained indefinitely by default; retention period set but never enforced; inaccurate monitoring outputs relied on without checks
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 8Storage: a few days, deleted automatically; beyond 72 hours needs stronger justification official guidance, not law

Footage may not be kept longer than the purpose needs, subject to any national storage periods. Since damage is usually noticed within a day or two, footage should in most cases be erased after a few days, ideally automatically, and the longer the period, especially beyond 72 hours, the more justification is needed. Where the controller stores footage, storage must be shown to be necessary and the period must be clearly defined for each purpose; retaining specific footage longer to pursue an identified incident remains possible.

What a reviewer asks to see: retention setting per system with the period for each purpose; justification for any period over 72 hours; incident hold procedure for footage needed for legal action
Where monitoring plans usually fall short: 30-day default retention with no reasoning; no automatic overwrite; footage kept indefinitely on local recorders
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not law

Keep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.

What a reviewer asks to see: Retention schedule for worker data including monitoring records, citing purpose, legal requirement or proceedings; Deletion logs
Where monitoring plans usually fall short: Monitoring recordings kept indefinitely; Unsuccessful applicants' data kept without their agreement
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
WP249 para 5.4.2(a)Bring your own device: separate private from business use and keep out of private areas official guidance, not law

Where employees use their own devices, the employer must have measures to tell private from business use so that private information is not monitored; security scanning tools can reach all data on a device and must be carefully managed, and parts of the device presumed private (such as the photo folder) should in principle stay closed to the employer. Tracking where a personal device is and what traffic it carries may be unlawful if it captures private and family life. Section 6.1 adds that employees should be able to shield private communications from work monitoring.

What a reviewer asks to see: BYOD policy defining work and private partitions; mobile security configuration limited to the work container; record that private areas are excluded from scans and location tracking
Where monitoring plans usually fall short: full-device scans on personal phones; location of personal devices tracked; no container or partition separating work data
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 6.1Owning the equipment does not remove employees' secrecy of communications; location tracking only where strictly necessary official guidance, not law

Electronic communications from work premises, their content and traffic data, may fall within private life and correspondence under Article 8 of the European Convention on Human Rights and deserve the same protection as analogue communications. Employer ownership of the devices does not take away employees' right to confidentiality of their communications, correspondence and the location data tied to them, and tracking employees' location through their own or company devices should go no further than a legitimate purpose strictly requires.

What a reviewer asks to see: legal assessment of monitoring against Article 8 ECHR and the secrecy of communications; location tracking justification per device class; policy stating that personal communications on company devices remain protected
Where monitoring plans usually fall short: policy asserting that company ownership removes any expectation of privacy; location tracking enabled fleet-wide by default; no Article 8 analysis
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
GDPR Art. 6Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What a reviewer asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
Where monitoring plans usually fall short: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 88Processing in the context of employment

Article 88 is addressed to Member States: it lets national law or collective agreements set more specific rules for handling workers' personal data across the employment relationship, from hiring through the running of the contract, work organisation, equality, health and safety, protection of property and the exercise of employment rights, to its end. An employer therefore identifies, for every country in which it employs people, which national employment-context rules made under this article apply, and applies the safeguards those rules must contain for dignity, legitimate interests and fundamental rights: openness about the processing, data passed between companies in the same group, and any system used to monitor people at work. The article is not itself a lawful basis; the Article 6 basis, and an Article 9 condition where special category data is involved, is still needed (CJEU C-34/21 found that a national rule which only restates the general conditions of the Regulation is not a more specific rule under this article).

What a reviewer asks to see: A per-country register of the national employment data rules and collective agreements the employer relies on, each cited to its provision; Works agreements or collective agreements covering monitoring systems, with their scope, date and signatories; Employee privacy notices that name each monitoring system, its purpose and its retention; Records of intra-group transfers of HR data with the group arrangement that governs them; The Article 6 basis (and Article 9 condition where relevant) recorded for each HR processing activity alongside the national rule
Where monitoring plans usually fall short: A national employment data provision cited as the lawful basis on its own, with no Article 6 basis recorded; Monitoring tools introduced in one country under a policy written for another country's law; No record of which works agreement covers which monitoring system; HR data shared across group companies with no documented arrangement
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 3.1.1(a)Consent is not the legal ground for most processing at work; default settings are not consent official guidance, not law

For most processing at work the employer cannot and should not rely on workers' consent, because the relationship makes refusal costly and consent must be freely given, specific, informed and revocable; where a real or possible prejudice follows from refusing, the consent is invalid. Even where consent could be free, pre-set device settings or installing monitoring software do not amount to consent, which requires an active expression of will. Section 6.2 limits free consent to exceptional cases where acceptance or refusal carries no consequence at all.

What a reviewer asks to see: legal basis record per monitoring purpose naming a ground other than consent, or evidence that refusal has no consequence; withdrawal mechanism where consent is genuinely used; configuration evidence that no monitoring relies on default device settings as agreement
Where monitoring plans usually fall short: consent clause in the employment contract used as the basis for monitoring; tick-box acceptance at log-on treated as consent; no alternative for workers who refuse
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(c)Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance official guidance, not law

An employer relying on legitimate interest must show that the purpose is legitimate, that the chosen method or technology is necessary for it and proportionate to the business need, and that it runs in the least intrusive way, aimed at the specific area of risk. It must be able to show the measures that balance its interest against workers' rights, and the worker keeps the right to object on compelling legitimate grounds. Section 6.2 adds that this ground works only where the processing is strictly needed.

What a reviewer asks to see: legitimate interests assessment per monitoring purpose (purpose, necessity, balancing); record of the mitigating measures adopted; objection handling procedure and log
Where monitoring plans usually fall short: assessment that names the interest but never tests necessity; no mitigating measures recorded; objections refused without balancing
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
EDPB video guidelines para 3.3(b)Employers should not rely on consent; employment-specific rules may come from national law or works agreements official guidance, not law

Because of the imbalance of power between employer and employee, employers should in most cases not rely on consent for video processing, since staff consent will rarely be free. National law or collective agreements (works agreements included) may set specific rules for processing employees' data in the employment context under Article 88.

What a reviewer asks to see: legal basis record for workplace cameras using a ground other than consent; copy of any works agreement or collective agreement governing cameras; register of national employment rules on video monitoring
Where monitoring plans usually fall short: staff consent forms used as the basis for CCTV; works agreement required by national law not concluded; national workplace camera rules not identified
Source: EDPB Guidelines on processing personal data through video devices 3/2019 (official guidance, not law), read 30 Sep 2026
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law

5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.

What a reviewer asks to see: Register of worker data processing activities, each with its employment-related reason and legal basis
Where monitoring plans usually fall short: Data collected for reasons unrelated to the job, such as off-duty social media activity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
GDPR Art. 10Processing of personal data relating to criminal convictions

Process personal data relating to criminal convictions and offences, or related security measures, only under the control of official authority or where Union or Member State law authorises the processing and provides appropriate safeguards for the rights and freedoms of data subjects. A comprehensive register of criminal convictions may be kept only under the control of official authority. An Article 6 lawful basis is required in addition.

What a reviewer asks to see: Identification of where conviction and offence data is processed, including screening and vetting results and incident records; The Union or Member State provision authorising the processing, and the safeguards that provision requires; Evidence the required safeguards are actually implemented rather than merely cited; Access restriction and retention applied specifically to this data, tighter than for ordinary personal data; Confirmation that no comprehensive register of convictions is maintained outside official authority
Where monitoring plans usually fall short: Background screening results retained on the personnel file indefinitely after the hiring decision is made; Reliance on the candidate's consent where national law, not consent, is the authorisation the Article requires; Offence data captured in incident reports or free text fields and never treated as Article 10 data; The authorising law identified but the specific safeguards it mandates never mapped to a control
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
WP249 para 5.2(a)No generalised screening of employees' social media during employment official guidance, not law

Employers should not screen employees' social media profiles on a generalised basis. Targeted observation may be lawful under legitimate interest only where it is shown to be necessary (the Opinion's example is checking former employees' professional profiles during a non-compete period), no less invasive means exist, and those concerned have been told how far the observation goes.

What a reviewer asks to see: policy prohibiting routine social media screening of staff; case record for any targeted observation with necessity reasoning; notice to the individuals observed
Where monitoring plans usually fall short: brand-monitoring tools configured to track named employees; screening of all staff profiles; targeted observation without notice
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not law

Employers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.

What a reviewer asks to see: Data inventory confirming these categories are not collected, or the documented exception and legal basis where they are
Where monitoring plans usually fall short: Criminal record checks for every role regardless of relevance
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.6No data on union membership or activities unless required official guidance, not law

Employers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.

What a reviewer asks to see: Review of HR and monitoring systems confirming union data are not collected except under a stated legal or agreement basis
Where monitoring plans usually fall short: Monitoring tools flag union-related email or chat
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
WP249 para 5.3(f)Data loss prevention: transparent rules and a warning before an email is blocked official guidance, not law

Deploying a data loss prevention tool on outgoing email must be fully justified to balance the employer's interest with employees' rights, because false positives expose legitimate and personal messages. The rules the system uses to flag an email should be fully transparent to users, and when an email is flagged the sender should be warned before it is sent, with the option to cancel.

What a reviewer asks to see: DLP justification record; published description of DLP rule categories; configuration showing sender warning and cancel option before transmission
Where monitoring plans usually fall short: silent DLP holds with investigators reading flagged mail; rules undisclosed to staff; no false-positive handling procedure
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.5Time and attendance and access control: informed, necessary, and not reused for performance evaluation official guidance, not law

Access and attendance systems, including those using biometrics or device tracking, can give an invasive view of workers' activity. A system recording who enters a secure area can rest on legitimate interest if necessary and if workers are adequately informed, but constantly watching how often and exactly when each worker enters and leaves cannot be justified once the same records serve a second purpose such as appraising performance.

What a reviewer asks to see: access control purpose statement and worker notice; report and access configuration preventing attendance data reaching performance reviews; biometric condition record where biometrics are used
Where monitoring plans usually fall short: badge data used to rank punctuality in appraisals; biometric clocks with no Article 9 condition; workers not told what access logs record
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(a)Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers official guidance, not law

Telematics collect data about the driver as well as the vehicle. Even with a legitimate interest or legal duty, the employer should first assess necessity, proportionality and subsidiarity. If a work vehicle may also be used privately, the key safeguard is letting the employee switch off location tracking temporarily when circumstances justify it (a doctor's visit, for example). The data must not be reused illegitimately, for example to follow and assess staff: vehicle trackers are for vehicles, not staff (Opinion 13/2011).

What a reviewer asks to see: telematics necessity and proportionality assessment; privacy switch configuration and driver instructions; rule barring use of telematics for driver performance ranking
Where monitoring plans usually fall short: speed alerts used for disciplinary scoring; no privacy switch on vehicles allowed for private use; telematics reports routinely reviewed by line managers
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026

See the specimen plan run Plan your own list