Employee monitoring laws UK: what applies
What Employee Monitoring Law Planner sets out for a monitoring practice at a site in the United Kingdom: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.
- Location
- The United Kingdom
- Laws placed
- UK GDPR; Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018
- Guidance placed
- ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law; ICO guidance: employment practices and data protection, monitoring workers 2023 official guidance, not law; ICO guidance on video surveillance, including CCTV 2022 official guidance, not law
- Read on
- 30 Sep 2026
What each practice needs here
20 practice classes| Practice | Representative step | Notice and policy | Recording consent | Not allowed | Paperwork |
|---|---|---|---|---|---|
| AI emotion or sentiment detection | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementDPIA before startArt. 6 basis |
| Keystroke logging | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | official guidance, not lawwebcam rarely justified | statutory requirementDPIA before startArt. 6 basis |
| Screenshots or screen recording | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | official guidance, not lawwebcam rarely justified | statutory requirementDPIA before startArt. 6 basis |
| Productivity or activity scoring | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | official guidance, not lawwebcam rarely justified | statutory requirementDPIA before startArt. 6 basisofficial guidance, not lawhuman review |
| Idle-time tracking | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | official guidance, not lawwebcam rarely justified | statutory requirementDPIA before startArt. 6 basis |
| Webcam or presence checks | none held | statutory requirementArt. 13 informationofficial guidance, not lawsignsmonitoring policy | none held | official guidance, not lawtoilets, changing rooms: exceptional only (where it covers toilets or washrooms, change or locker rooms and showers or bathing areas)webcam rarely justified | statutory requirementDPIA before startArt. 6 basis |
| Email and messaging review | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| DLP and email content filtering | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| Website or email blocking | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| Web and app usage logging | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| Biometric time clock | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 9 condition, alternativeDPIA before startArt. 6 basis |
| Access control logs | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| CCTV (break, change or wash rooms) | none held | statutory requirementArt. 13 informationofficial guidance, not lawsignsmonitoring policy | none held | official guidance, not lawtoilets, changing rooms: exceptional only (where it covers toilets or washrooms, change or locker rooms and showers or bathing areas) | statutory requirementArt. 6 basis |
| CCTV (work areas) | none held | statutory requirementArt. 13 informationofficial guidance, not lawsignsmonitoring policy | none held | official guidance, not lawtoilets, changing rooms: exceptional only (where it covers toilets or washrooms, change or locker rooms and showers or bathing areas) | statutory requirementArt. 6 basis |
| GPS or vehicle telematics | none held | statutory requirementArt. 13 informationofficial guidance, not lawdrivers toldmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| Mobile device location | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| Call or speech analytics | none held | statutory requirementArt. 13 informationofficial guidance, not lawcallers toldmonitoring policy | statutory requirementpurpose, users told | none held | statutory requirementArt. 6 basis |
| Call recording | none held | statutory requirementArt. 13 informationofficial guidance, not lawcallers toldmonitoring policy | statutory requirementpurpose, users told | none held | statutory requirementArt. 6 basis |
| Social media monitoring | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basis |
| Background checks as ongoing monitoring | none held | statutory requirementArt. 13 informationofficial guidance, not lawmonitoring policy | none held | none held | statutory requirementArt. 6 basisofficial guidance, not lawoffence data condition |
Every requirement held here
- Noticestatutory requirementThe Art. 13 information at collection, and tell workers about monitoring in an accessible way. UK GDPR Art. 13ICO monitoring guidance para 1.9
- Noticeofficial guidance, not lawSigns before the field of view, readable and sized for the setting, naming the operator, purpose and a contact. ICO video guidance P.4 official guidance, not law
- Noticeofficial guidance, not lawTell callers the call is recorded and why. ICO monitoring guidance para 3.3(b) official guidance, not law
- Noticeofficial guidance, not lawTell workers, and any passengers, that the vehicle is monitored. ICO monitoring guidance para 3.6 official guidance, not law
- Written policyofficial guidance, not lawMonitoring policies that set out the nature, purpose and extent of monitoring, brought to workers' attention and matching what happens. ICO monitoring guidance para 1.12(b) official guidance, not law
- Recording consentstatutory requirementInterception by or with the express consent of the system controller, for a listed purpose (such as standards achieved in the course of duties), and all reasonable efforts to tell every user of the system that calls may be intercepted. UK interception regulations reg 3(1)(a)UK interception regulations reg 3(2)(c)UK interception regulations reg 4(1)(c)ICO monitoring guidance para 3.3(a)
- Limitsofficial guidance, not lawContent only exceptionally, under a clear policy notified in advance; network data first. ICO monitoring guidance para 3.4(a)ICO monitoring guidance para 3.4(b)ICO monitoring guidance para 3.10 official guidance, not law
- Limitsofficial guidance, not lawTargeted at risk areas with low privacy expectations, workers and others informed, an assessment first. ICO monitoring guidance para 3.5(a)ICO video guidance A.4 official guidance, not law
- Biometric datastatutory requirementA lawful basis and an Art. 9 condition, a documented reason why biometrics are necessary, an assessment before processing, and a non-biometric alternative without disadvantage. UK GDPR Art. 9ICO monitoring guidance para 4.1ICO monitoring guidance para 4.2ICO monitoring guidance para 4.3
- Covert monitoringofficial guidance, not lawCovert monitoring only exceptionally, for suspected crime or gross misconduct, authorised by senior management after an assessment, tightly targeted and time-limited, never in toilets or changing rooms. ICO monitoring guidance para 1.19(a)ICO monitoring guidance para 1.19(b) Human Rights Act, Article 8, named, not quoted official guidance, not law
- Outside workofficial guidance, not lawMonitoring a vehicle while it is used privately, with the employer's leave, is rarely justified; a driver-operated privacy switch outside working hours is the ICO's example. (if it runs outside work) ICO monitoring guidance para 3.6 Human Rights Act, Article 8, named, not quoted official guidance, not law
- Personal devicesofficial guidance, not lawWhen workers use their own devices, make sure private use is not captured. (if personal devices are monitored) ICO monitoring guidance para 3.11(c) Human Rights Act, Article 8, named, not quoted official guidance, not law
- Lawful basisstatutory requirementAn Art. 6 basis chosen for the specific purpose and documented from the start; consent rarely valid; legitimate interests with a recorded assessment. UK GDPR Art. 6ICO monitoring guidance para 1.4(a)ICO monitoring guidance para 1.4(b)ICO monitoring guidance para 1.4(d)
- Lawful basisofficial guidance, not lawOffence data only under official authority or a specific condition in domestic law. ICO monitoring guidance para 1.6 official guidance, not law
- Assessmentstatutory requirementAn assessment before high-risk monitoring, the DPO's advice recorded, workers told before it starts; device monitoring needs its justification documented and a less intrusive way used if one works. UK GDPR Art. 35ICO monitoring guidance para 1.11ICO monitoring guidance para 3.11(a)
- Assessmentofficial guidance, not lawSolely automated decisions with significant effects on workers need one of the grounds the law lists and a route to a human. ICO monitoring guidance para 2.1 official guidance, not law
- Assessmentofficial guidance, not lawContinuous monitoring only for health and safety or the protection of property; monitoring output never the sole basis of a performance judgement. ILO code para 6.14(3)ILO code para 5.6 official guidance, not law
- Retentionstatutory requirementA retention schedule justified by business need, reviewed, and not kept in case a use turns up. UK GDPR Art. 5ICO monitoring guidance para 1.15
- Retentionofficial guidance, not lawThe shortest period the purpose needs, never the recorder's default. ICO video guidance P.11 official guidance, not law
- Retentionofficial guidance, not lawKept only as long as the purpose justifies. ILO code para 8.5 official guidance, not law
Findings a line here can raise
12 of 13- 1 Representative step before start not recorded
- 2 Notice not recorded, or its period not met
- 3 Written policy not recorded where the law asks for one
- 4 Covert monitoring
- 5 Monitoring a place the law keeps private
- 6 Monitoring outside work
- 7 Call recording consent
- 8 Biometric data
- 10 Continuous, keystroke or screenshot monitoring with no assessment recorded
- 11 Retention not set, or above the period you set
- 12 Personal devices monitored
- 13 Lawful basis not recorded for an EU or UK line
Named, not quoted
- Human Rights Act, Article 8: the right to respect for private and family life (the United Kingdom; named, not quoted)
Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.
The provisions cited here
50 provisionsILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not lawWhere workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.
ICO monitoring guidance para 1.18Seek and document the views of workers or their representatives (such as trade unions) before introducing monitoring official guidance, not lawWhen planning monitoring the employer should ask for, and record, what workers or their representatives (trade unions, for example) think, unless it has good reason not to, and if it decides not to it should record that decision with a clear explanation; workers should be involved early in planning, as part of the DPIA.
ICO video guidance P.7(a)Workplace surveillance: consult the workforce (staff or trade unions) in the DPIA, notify employees, and inform visitors and customers official guidance, not lawEmployers may use overt surveillance for safety, public health or security reasons, but employees do not always expect video or audio monitoring in their daily roles, so it should be used rarely. The employer must consult its workforce (staff, trade unions or both), above all as part of the DPIA; give adequate notice to employees of the nature, extent and purposes of the surveillance; make others caught by it, such as visitors and customers, aware of it and why; and respect staff rights, giving staff a direct route to take complaints or concerns to the employer.
UK GDPR Art. 13Information to be provided where personal data are collected from the data subject At the time of collection the controller must give its identity and contact details (and any representative's), the data protection officer's contact details, the purposes and lawful basis, the legitimate interests where Article 6(1)(f) is relied on, the recipients, and any intended transfer abroad with whether transfer regulations under Article 45A cover it or which safeguards are relied on and how to get a copy. It must also give the retention period or criteria, the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent, the right to complain to the controller and to the Commissioner, whether provision of the data is required and the consequences of not providing it, and the existence of automated decision-making subject to Article 22C safeguards with meaningful information about the logic and consequences. Before further processing for a new purpose the data subject must be told of it, unless the further processing is for research, archiving or statistics under Article 84B and telling them is impossible or disproportionate, in which case the controller must protect their interests, including by publishing the information.
ICO monitoring guidance para 1.9Transparency: tell workers about monitoring in an accessible way, except where covert monitoring is exceptionally justified official guidance, not lawTransparency is tied to fairness and trust: workers are entitled to be informed, and the employer must tell them about monitoring in an accessible, easily understood way; apart from very exceptional cases where covert monitoring is justified, it must inform workers of any monitoring.
ICO video guidance P.4Signs before the field of view: visible, readable, sized for the setting, naming operator, purpose and contact, backed by fuller information official guidance, not lawPeople must be told when they are in an area under surveillance, and Article 13 information provided. Signs should be clearly visible and readable, sized for pedestrians or drivers, placed prominently before the entrance to the field of vision and reinforced inside, far enough away that people see them before being captured, and should state the operator (unless obvious), the purpose and at least a website, telephone number or email for queries; signs should be bigger and more numerous in places where monitoring is unexpected. A website notice alone is not enough, but signs can link to it as a layered notice; audio announcements can reinforce them, and staff should know how to handle enquiries.
ICO monitoring guidance para 3.3(b)Call monitoring: tell callers the call is recorded and why official guidance, not lawCall monitoring also captures callers' information: the employer must tell them the call is being recorded and why, a recorded message being good practice; where that is not possible it must instruct workers to tell callers and explain the reason, with the rest of the privacy information given by other means such as email or a website link. Recordings are likely personal data disclosable on a subject access request, and workers should know recordings may be released.
ICO monitoring guidance para 3.6Vehicle monitoring: inform workers and passengers, rarely during private use, DPIA for driver behaviour or analytics official guidance, not lawWork vehicles may be monitored, but monitoring during permitted private use will rarely be justified (a driver-operated privacy switch outside working hours is the ICO's example), and the employer must tell workers and any passengers that the vehicle is monitored. Tachograph monitoring required by drivers' hours rules can rest on legal obligation; insurance telematics data is personal data. Monitoring driving behaviour and style, or using cameras or audio, is high risk and needs a DPIA considering less intrusive methods, as does any analytics making inferences or decisions about drivers.
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not lawBefore any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.
ILO code para 5.8Keep workers and representatives informed official guidance, not lawWorkers and their representatives should be told about every data collection process, the rules governing it and their rights.
ICO monitoring guidance para 1.12(b)Monitoring policies set out nature, purpose and extent, are brought to workers' attention, and match practice official guidance, not lawWhere monitoring enforces organisational rules, those rules should be clearly set out and regularly brought to workers' attention, and the policy should describe the nature, purpose and extent of monitoring; the ICO's example is an acceptable use policy linked to privacy information explaining how the rules are monitored, how the information is used and the safeguards. Workers form expectations from what actually happens, not only from policy: excessive monitoring is not made lawful by being written down, and a tolerated practice (some personal calls) cannot be policed by pointing to a policy that bans it. Blocking sites or requiring acceptance of conditions can reduce the need to monitor.
ICO monitoring guidance para 1.19(a)Covert monitoring only exceptionally, for suspected crime or gross misconduct, authorised by senior management after a DPIA official guidance, not lawCovert monitoring, designed so workers do not know it happens, is unlikely to be justified in usual circumstances; it may be justified exceptionally where it is needed to stop or uncover suspected crime or gross misconduct. Policies should say which behaviours are unacceptable and when covert monitoring may occur; it should be authorised only by senior management, the employer must carry out a DPIA, and it should be satisfied there are grounds for suspicion and that telling workers would prejudice prevention or detection. Every decision should be justifiable.
ICO monitoring guidance para 1.19(b)Covert monitoring: tightly targeted and time-limited, never in toilets or changing rooms, and not of private communications official guidance, not lawCovert monitoring should be strictly targeted at obtaining evidence within the shortest possible set period and should stop when the investigation is complete; covert audio or video should not be used where workers can reasonably expect privacy, toilets and changing rooms among them, and in most cases covert monitoring should leave alone communications workers would reasonably treat as private, personal email for instance.
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not lawCovert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.
ICO video guidance P.3Fairness: meet reasonable expectations; cameras in toilets and changing rooms only in the most exceptional circumstances official guidance, not lawProcessing that is lawful can still be unfair: people should only be recorded in ways they would reasonably expect, judged objectively in the circumstances, and without unjustified adverse effects. Places with heightened privacy expectations, such as private property, public toilets and changing rooms, should be monitored only in the most exceptional circumstances to deal with very serious concerns (cameras in school toilets are unlikely to be proportionate). The organisation should weigh new or unexpected technology, intrusion where behaviour is not modified and the chilling effect on how people behave and move, and reflect this in a DPIA before deployment.
ICO monitoring guidance para 3.1Remote and home working: factor higher privacy expectations and family capture into the DPIA official guidance, not lawWhen monitoring remote workers, and especially those at home, the employer should remember that privacy expectations are higher at home and that family and private life is more easily captured by accident, and should build this risk into any monitoring through a DPIA.
UK interception regulations reg 3(1)(a)Interception effected by, or with the express consent of, the system controller The interception must be of a communication while it is being transmitted over a telecommunication system, and it must be carried out by the system controller (the person entitled to control the system's operation or use) or with that person's express consent. A vendor, outsourced call centre or IT provider that monitors on the business's behalf needs the controller's explicit authority; implied acquiescence is not enough for this route. Regulation 3(1)(b) and (c) add that the conduct must also fit a purpose in paragraphs (2) to (4) and satisfy regulation 4.
UK interception regulations reg 3(2)(c)Purpose: to ascertain or demonstrate standards achieved or to be achieved by users in the course of their duties Monitoring or recording is authorised to find out or show the standards that people reach, or should reach, when they use the system for their work, which covers quality assurance and training on business calls, emails and messages. It does not extend to communications that are not made in the course of duties.
UK interception regulations reg 4(1)(c)All reasonable efforts to inform every user that communications may be intercepted The system controller must have made all reasonable efforts to tell each person who might use the system that communications carried on it can be intercepted. This covers workers and anyone else who may use the system (contractors, visitors on guest networks); the Regulations do not require the consent of the other party to a call or message, but the users of the controller's own system must be told. Informing external callers is a separate data protection transparency duty.
ICO monitoring guidance para 3.3(a)Call monitoring: not all calls by default, itemised records first, workers told, personal calls not routinely monitored official guidance, not lawMonitoring or recording the content of all calls is not usually proportionate; business calls could be monitored for evidence of transactions or for training and quality, or where a regulator's rules require recording (limited to what the rules require). Itemised call records could meet a usage purpose and narrow any further monitoring, and any increase in call monitoring should trigger a DPIA review. Workers must be told of call monitoring in privacy information, and it should also appear in the handbook, codes and guidance; personal calls should not be routinely monitored, with a personal-calls policy workers know about, and a tolerated practice cannot be policed by a ban that is not applied.
UK GDPR Art. 9Processing of special categories of personal data Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.
ICO monitoring guidance para 4.1Biometric access and time control: document why biometrics are necessary and why alternatives are inadequate, in the DPIA official guidance, not lawBiometric identification carries far more sensitive information than cards and PINs and is harder to fix if inaccurate or breached, so the employer should consider alternatives, should document why it relies on biometrics and why less intrusive means are inadequate, should be able to justify not using a reasonable alternative, and must record all of this in the DPIA; extra security may be needed.
ICO monitoring guidance para 4.2Biometric access: a lawful basis and a special category condition, and a non-biometric alternative without disadvantage official guidance, not lawUsing biometrics to identify workers is special category processing, so a lawful basis and a condition are both needed and must be documented in the DPIA. The employer should offer an alternative such as swipe cards or PINs to those who do not want biometric access and should not disadvantage them; without an alternative, biometric access control is very hard to justify and consent is not appropriate, whereas with a genuine, penalty-free alternative consent and explicit consent become likely options.
ICO monitoring guidance para 4.3Biometric identification of workers always needs a DPIA before processing, discussed with workers official guidance, not lawThe employer must carry out and complete a DPIA before processing biometrics that single out an individual worker, because it is high risk; the process also lets it discuss the proposal with workers and their representatives beforehand.
UK GDPR Art. 35Data protection impact assessment Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.
ICO monitoring guidance para 1.11DPIA before high-risk monitoring, DPO advice recorded, workers informed before start, ICO consulted if high risk remains official guidance, not lawA DPIA must precede any processing that probably poses high risk to workers or others, such as biometric processing, keystroke monitoring, monitoring that may cause financial loss (performance management) or profiling to decide access to services; it should also consider customers, the public and household members captured. Where there is a DPO, the employer must seek and record the DPO's independent advice before deciding; if it goes ahead it must inform workers before monitoring begins; if high risk cannot be reduced it must consult the ICO first. The ICO expects a DPIA even without high risk, or a documented decision not to do one.
ICO monitoring guidance para 3.11(a)Device activity monitoring: document the justification, use less intrusive means if they work, identify a basis and condition, and do a DPIA official guidance, not lawDevice monitoring (web browsing, emails, documents, applications, screenshots, webcam captures, keystrokes) is likely to capture excessive information including special category data. The employer must be clear about its purpose and fully document its justification, including the less intrusive options considered, and must use a less intrusive way if one achieves the aim; it must identify a lawful basis and any special category condition; it must carry out a DPIA where high risk is likely and should do one anyway.
ICO monitoring guidance para 3.11(c)Device activity monitoring: webcam capture rarely justified, keystroke logging is behavioural biometric data, and private use of own devices kept out official guidance, not lawCapturing webcam shots or footage is particularly unlikely to be justified; keystroke monitoring counts as behavioural biometric data when typing rhythm can identify a worker. Barring personal use of company devices and blocking problem websites could reduce risk, but even then accessing personal communications is hard to justify, and when workers use their own devices for work the employer should make sure it does not capture their private use.
ICO monitoring guidance para 2.1Solely automated decisions with legal or similarly significant effects on workers: only on a ground the law lists, without disadvantaging those who ask for a human official guidance, not lawDecisions made by automated means with no meaningful human involvement that have legal or similarly significant effects on workers (pay changes from productivity data, dismissal) were, under the Article 22 the guidance describes, allowed only where necessary for a contract, authorised by law, or based on explicit consent, and workers who ask for a human to intervene must not end up worse off than those who accept the automated decision. A decision taken by a manager who reviewed tracking data and spoke to the worker is not solely automated. Law since the guidance: the Data (Use and Access) Act 2025, s 80, replaced UK GDPR Article 22 with Articles 22A to 22D (fully in force 5 February 2026): solely automated significant decisions are now restricted only where they rest on special category data (explicit consent, or contract or law plus Article 9(2)(g)) or on recognised legitimate interests, and in every case the controller must provide safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. The ICO flags this guidance as under review.
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not lawMonitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not lawOutput from electronic surveillance should never be the sole input when a worker's performance is judged.
UK GDPR Art. 5Principles relating to processing of personal data Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
ICO monitoring guidance para 1.15Retention schedule for monitoring data, justified by business need and reviewed official guidance, not lawMonitoring information must not be kept longer than the purpose needs; the employer must have a retention schedule and delete in line with it, should base periods on business need, professional guidelines and legal duties, review them regularly, be able to justify them against the reasons for collection, and should not keep information in case a use turns up.
ICO video guidance P.11Retention: the shortest period for the purpose, not the recorder's capacity or default, documented, securely deleted and checked official guidance, not lawNo fixed retention period applies; the purpose sets it, and the period should be the shortest the purpose needs, after which footage should be deleted. It should not be set by storage capacity or the manufacturer's default (six months merely because the system allows it) or kept in case it proves useful; the policy should be documented and understood by operators, deletion should be permanent and secure, and adherence should be checked. Longer retention can be justified for a specific purpose, such as preserving footage at the request of police investigating a crime.
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not lawKeep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.
UK GDPR Art. 6Lawfulness of processing Processing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.
ICO monitoring guidance para 1.4(a)Choose the lawful basis for the specific purpose, document it from the start and do not switch later official guidance, not lawThe basis depends on the purpose and context; the employer must think about why it wants to monitor and pick the basis that best fits, must not use a one-size-fits-all approach, should identify and document every basis that applies from the outset, and should keep to it unless a good reason arises. A DPIA or the ICO's interactive tool can help.
ICO monitoring guidance para 1.4(b)Consent is rarely valid for monitoring at work; where used it must be withdrawable without detriment and recorded official guidance, not lawConsent must be freely given, which the power imbalance usually rules out, so it is not usually appropriate for employers; it works only where workers truly choose and control whether they are monitored. Where it is used it must be unambiguous with an affirmative act, and the employer must let workers withdraw without detriment as easily as they gave it, and record the date, method and exact scope of each consent.
ICO monitoring guidance para 1.4(d)Legitimate interests: pass the purpose, necessity and balancing tests, record a legitimate interests assessment, and respect reasonable expectations official guidance, not lawLegitimate interests is the most flexible basis, but the employer must weigh its interests, and how necessary the monitoring is, against what workers stand to lose in rights and freedoms in the particular case, and should run the purpose, necessity and balancing tests before starting and record the result in a legitimate interests assessment. It may not be appropriate where workers would not understand or reasonably expect the monitoring or would likely object if told; expectations vary with the job (a miner expects a tracker, an office worker does not).
ICO monitoring guidance para 1.7Check other laws beyond data protection before monitoring official guidance, not lawMonitoring must be lawful and fair overall, so the employer should consider laws outside data protection, including the Human Rights Act 1998, the Equality Act 2010 and section 75 of the Northern Ireland Act 1998, and the interception rules (SI 2018/356 on interception by businesses and their predecessor, the Telecommunications (Lawful Business Practice) Regulations 2000).
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.
ICO monitoring guidance para 1.6Criminal offence data from monitoring needs official authority or a Schedule 1 condition official guidance, not lawInformation about offences, allegations, investigations or proceedings concerning workers may only be processed under official authority or where domestic law authorises it; monitoring to detect criminal activity needs a specific Schedule 1 DPA 2018 condition.
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not lawEmployers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.
ILO code para 6.6No data on union membership or activities unless required official guidance, not lawEmployers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.
ICO monitoring guidance para 3.4(a)Email and message monitoring: a clear, necessary purpose, workers told, and a DPIA official guidance, not lawMonitoring emails and messages (including chat in collaboration tools) to protect information, for security, to spot suspicious activity or to enforce acceptable use requires a clear purpose, necessity and proportionality, and informing workers of the purpose; the employer must complete a DPIA because it is high risk and likely to capture special category data.
ICO monitoring guidance para 3.4(b)Email and message content only exceptionally, with a clear policy and advance notice; network data first official guidance, not lawContent monitoring is hard to justify where network traffic data would meet the purpose; the employer must notify workers in advance (in policy documents) if content may be monitored in exceptional circumstances and must not access content without a clear policy stating when that can happen. Before monitoring it should consider narrowing checks using network data (emails to rival firms, for instance), the duty of confidence to workers and customers, excluding lines such as union representatives, that even a ban on personal use does not justify reading personal messages (investigate breaches through network data first), letting workers mark messages personal, and the reliability of the records.
ICO monitoring guidance para 3.10Data loss prevention and traffic monitoring: least invasive means, a DPIA, and blocking with review as an alternative official guidance, not lawFor security tools such as firewalls and data loss prevention, the employer should choose the least invasive means and complete a DPIA; network traffic monitoring can be high risk, especially with inferences about workers, and blocking suspicious traffic or sending the worker to a portal to request a review could replace more detailed monitoring.
ICO monitoring guidance para 3.5(a)Video monitoring of workers: DPIA, targeted at risk areas with low privacy expectations, workers and others informed, footage redactable official guidance, not lawBefore using video monitoring the employer must complete a DPIA, consider why it is necessary, inform workers of its extent, nature and reasons, and make visitors, customers and others caught by it aware too; a DPIA is needed where special category capture is likely. Cameras should be aimed at particular risk areas where privacy expectations are low, continuous monitoring of workers is justified only rarely, covert use is unlikely to be justified, and footage may need redacting for subject access requests.
ICO video guidance A.4DPIA before surveillance likely to be high risk (most cases), evidence-based, with alternatives considered; consult the ICO if high risk remains official guidance, not lawA DPIA is a legal requirement before processing likely to result in high risk, which covers most video surveillance, including large-scale systematic monitoring of publicly accessible places. It must set out what the processing is, its scope, context and purposes, weigh necessity and proportionality and the compliance measures, identify and rate the risks to people, and set out further measures to reduce them; a decision not to do one must be documented and justified. The organisation should consider lawfulness and transparency, whether the system is necessary and proportionate and actually solves the problem on reliable evidence, and less intrusive alternatives; if high residual risk remains it must consult the ICO and not proceed until it has. Failing to do a required DPIA is itself an infringement.
ICO monitoring guidance para 3.5(c)Facial recognition in worker monitoring: special category data, a lawful basis and condition, and a DPIA official guidance, not lawFacial recognition carries higher risks than ordinary video, especially when used to infer behaviour, emotion or intention, and raises accuracy concerns for ethnic minority groups; using it to identify workers is processing biometric special category data needing a lawful basis and a condition, and the employer must carry out a DPIA because it is high risk.