Employee Monitoring Law Planner
Laws

Employee monitoring laws UK: what applies

What Employee Monitoring Law Planner sets out for a monitoring practice at a site in the United Kingdom: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.

Location
The United Kingdom
Laws placed
UK GDPR; Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018
Guidance placed
ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law; ICO guidance: employment practices and data protection, monitoring workers 2023 official guidance, not law; ICO guidance on video surveillance, including CCTV 2022 official guidance, not law
Read on
30 Sep 2026

What each practice needs here

20 practice classes
PracticeRepresentative stepNotice and policyRecording consentNot allowedPaperwork
AI emotion or sentiment detectionnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementDPIA before startArt. 6 basis
Keystroke loggingnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldofficial guidance, not lawwebcam rarely justifiedstatutory requirementDPIA before startArt. 6 basis
Screenshots or screen recordingnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldofficial guidance, not lawwebcam rarely justifiedstatutory requirementDPIA before startArt. 6 basis
Productivity or activity scoringnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldofficial guidance, not lawwebcam rarely justifiedstatutory requirementDPIA before startArt. 6 basisofficial guidance, not lawhuman review
Idle-time trackingnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldofficial guidance, not lawwebcam rarely justifiedstatutory requirementDPIA before startArt. 6 basis
Webcam or presence checksnone heldstatutory requirementArt. 13 informationofficial guidance, not lawsignsmonitoring policynone heldofficial guidance, not lawtoilets, changing rooms: exceptional only (where it covers toilets or washrooms, change or locker rooms and showers or bathing areas)webcam rarely justifiedstatutory requirementDPIA before startArt. 6 basis
Email and messaging reviewnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
DLP and email content filteringnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
Website or email blockingnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
Web and app usage loggingnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
Biometric time clocknone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 9 condition, alternativeDPIA before startArt. 6 basis
Access control logsnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
CCTV (break, change or wash rooms)none heldstatutory requirementArt. 13 informationofficial guidance, not lawsignsmonitoring policynone heldofficial guidance, not lawtoilets, changing rooms: exceptional only (where it covers toilets or washrooms, change or locker rooms and showers or bathing areas)statutory requirementArt. 6 basis
CCTV (work areas)none heldstatutory requirementArt. 13 informationofficial guidance, not lawsignsmonitoring policynone heldofficial guidance, not lawtoilets, changing rooms: exceptional only (where it covers toilets or washrooms, change or locker rooms and showers or bathing areas)statutory requirementArt. 6 basis
GPS or vehicle telematicsnone heldstatutory requirementArt. 13 informationofficial guidance, not lawdrivers toldmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
Mobile device locationnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
Call or speech analyticsnone heldstatutory requirementArt. 13 informationofficial guidance, not lawcallers toldmonitoring policystatutory requirementpurpose, users toldnone heldstatutory requirementArt. 6 basis
Call recordingnone heldstatutory requirementArt. 13 informationofficial guidance, not lawcallers toldmonitoring policystatutory requirementpurpose, users toldnone heldstatutory requirementArt. 6 basis
Social media monitoringnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basis
Background checks as ongoing monitoringnone heldstatutory requirementArt. 13 informationofficial guidance, not lawmonitoring policynone heldnone heldstatutory requirementArt. 6 basisofficial guidance, not lawoffence data condition

Every requirement held here

Findings a line here can raise

12 of 13

Named, not quoted

Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.

The provisions cited here

50 provisions
ILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not law

Where workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.

What a reviewer asks to see: Consultation record for each monitoring system, dated before introduction, with the representatives' views and the employer's response
Where monitoring plans usually fall short: Monitoring tool piloted without consulting the representatives
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.18Seek and document the views of workers or their representatives (such as trade unions) before introducing monitoring official guidance, not law

When planning monitoring the employer should ask for, and record, what workers or their representatives (trade unions, for example) think, unless it has good reason not to, and if it decides not to it should record that decision with a clear explanation; workers should be involved early in planning, as part of the DPIA.

What a reviewer asks to see: record of consultation with workers or trade union representatives; DPIA section recording their views and responses; documented reason where consultation was not held
Where monitoring plans usually fall short: no consultation and no recorded reason; consultation after the decision; representatives' concerns not answered
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO video guidance P.7(a)Workplace surveillance: consult the workforce (staff or trade unions) in the DPIA, notify employees, and inform visitors and customers official guidance, not law

Employers may use overt surveillance for safety, public health or security reasons, but employees do not always expect video or audio monitoring in their daily roles, so it should be used rarely. The employer must consult its workforce (staff, trade unions or both), above all as part of the DPIA; give adequate notice to employees of the nature, extent and purposes of the surveillance; make others caught by it, such as visitors and customers, aware of it and why; and respect staff rights, giving staff a direct route to take complaints or concerns to the employer.

What a reviewer asks to see: consultation record with staff or trade union representatives in the DPIA; employee notice describing cameras, extent and purposes; visitor and customer signage; staff complaint route for surveillance concerns
Where monitoring plans usually fall short: cameras installed with no workforce consultation; staff learn of cameras by seeing them; no route for staff concerns
Source: ICO guidance on video surveillance, including CCTV 2022 (official guidance, not law), read 30 Sep 2026
UK GDPR Art. 13Information to be provided where personal data are collected from the data subject

At the time of collection the controller must give its identity and contact details (and any representative's), the data protection officer's contact details, the purposes and lawful basis, the legitimate interests where Article 6(1)(f) is relied on, the recipients, and any intended transfer abroad with whether transfer regulations under Article 45A cover it or which safeguards are relied on and how to get a copy. It must also give the retention period or criteria, the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent, the right to complain to the controller and to the Commissioner, whether provision of the data is required and the consequences of not providing it, and the existence of automated decision-making subject to Article 22C safeguards with meaningful information about the logic and consequences. Before further processing for a new purpose the data subject must be told of it, unless the further processing is for research, archiving or statistics under Article 84B and telling them is impossible or disproportionate, in which case the controller must protect their interests, including by publishing the information.

What a reviewer asks to see: Privacy notices at each collection point with every Article 13 item; Version history of notices; Assessment and public statement where the Article 13(5) research exception is used
Where monitoring plans usually fall short: Notice missing the right to complain to the controller; Transfer information still citing adequacy decisions instead of transfer regulations; No notice update before a new purpose starts
Source: UK GDPR, read 30 Sep 2026
ICO monitoring guidance para 1.9Transparency: tell workers about monitoring in an accessible way, except where covert monitoring is exceptionally justified official guidance, not law

Transparency is tied to fairness and trust: workers are entitled to be informed, and the employer must tell them about monitoring in an accessible, easily understood way; apart from very exceptional cases where covert monitoring is justified, it must inform workers of any monitoring.

What a reviewer asks to see: worker privacy notice covering monitoring; accessibility review of the notice (plain language, formats); log of exceptional covert monitoring decisions
Where monitoring plans usually fall short: monitoring disclosed only in legal jargon; notice not accessible to all staff; covert monitoring treated as routine
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO video guidance P.4Signs before the field of view: visible, readable, sized for the setting, naming operator, purpose and contact, backed by fuller information official guidance, not law

People must be told when they are in an area under surveillance, and Article 13 information provided. Signs should be clearly visible and readable, sized for pedestrians or drivers, placed prominently before the entrance to the field of vision and reinforced inside, far enough away that people see them before being captured, and should state the operator (unless obvious), the purpose and at least a website, telephone number or email for queries; signs should be bigger and more numerous in places where monitoring is unexpected. A website notice alone is not enough, but signs can link to it as a layered notice; audio announcements can reinforce them, and staff should know how to handle enquiries.

What a reviewer asks to see: signage plan showing placement before each monitored zone; sign text with operator, purpose and contact; layered online notice; staff enquiry procedure
Where monitoring plans usually fall short: signs only inside the monitored area; signs with no contact details; reliance on a website notice alone
Source: ICO guidance on video surveillance, including CCTV 2022 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.3(b)Call monitoring: tell callers the call is recorded and why official guidance, not law

Call monitoring also captures callers' information: the employer must tell them the call is being recorded and why, a recorded message being good practice; where that is not possible it must instruct workers to tell callers and explain the reason, with the rest of the privacy information given by other means such as email or a website link. Recordings are likely personal data disclosable on a subject access request, and workers should know recordings may be released.

What a reviewer asks to see: recorded announcement script; worker script for manual notice where no announcement exists; published call-recording privacy information
Where monitoring plans usually fall short: no announcement to callers; reason for recording not given; no route to fuller privacy information
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.6Vehicle monitoring: inform workers and passengers, rarely during private use, DPIA for driver behaviour or analytics official guidance, not law

Work vehicles may be monitored, but monitoring during permitted private use will rarely be justified (a driver-operated privacy switch outside working hours is the ICO's example), and the employer must tell workers and any passengers that the vehicle is monitored. Tachograph monitoring required by drivers' hours rules can rest on legal obligation; insurance telematics data is personal data. Monitoring driving behaviour and style, or using cameras or audio, is high risk and needs a DPIA considering less intrusive methods, as does any analytics making inferences or decisions about drivers.

What a reviewer asks to see: in-vehicle notices and driver policy; privacy switch configuration for private use; DPIA for driver behaviour monitoring and analytics
Where monitoring plans usually fall short: tracking during private use; passengers not informed; driver scoring without a DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not law

Before any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.

What a reviewer asks to see: Monitoring notice per system stating reasons, schedule, methods and data collected, issued before monitoring starts; Proportionality assessment showing less intrusive options considered
Where monitoring plans usually fall short: Notice states only that monitoring may occur, without schedule or methods; Screenshots captured continuously when sampling would serve the purpose
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.8Keep workers and representatives informed official guidance, not law

Workers and their representatives should be told about every data collection process, the rules governing it and their rights.

What a reviewer asks to see: Worker privacy notice covering each collection process, its rules and workers' rights; Record of the information given to worker representatives
Where monitoring plans usually fall short: Notice covers HR records but not monitoring systems
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.12(b)Monitoring policies set out nature, purpose and extent, are brought to workers' attention, and match practice official guidance, not law

Where monitoring enforces organisational rules, those rules should be clearly set out and regularly brought to workers' attention, and the policy should describe the nature, purpose and extent of monitoring; the ICO's example is an acceptable use policy linked to privacy information explaining how the rules are monitored, how the information is used and the safeguards. Workers form expectations from what actually happens, not only from policy: excessive monitoring is not made lawful by being written down, and a tolerated practice (some personal calls) cannot be policed by pointing to a policy that bans it. Blocking sites or requiring acceptance of conditions can reduce the need to monitor.

What a reviewer asks to see: acceptable use and monitoring policy with nature, purpose and extent; evidence of regular reminders (training, log-on banners, intranet); comparison of policy against actual practice
Where monitoring plans usually fall short: policy bans personal use but managers tolerate it; policy never re-communicated; monitoring extent not stated
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.19(a)Covert monitoring only exceptionally, for suspected crime or gross misconduct, authorised by senior management after a DPIA official guidance, not law

Covert monitoring, designed so workers do not know it happens, is unlikely to be justified in usual circumstances; it may be justified exceptionally where it is needed to stop or uncover suspected crime or gross misconduct. Policies should say which behaviours are unacceptable and when covert monitoring may occur; it should be authorised only by senior management, the employer must carry out a DPIA, and it should be satisfied there are grounds for suspicion and that telling workers would prejudice prevention or detection. Every decision should be justifiable.

What a reviewer asks to see: senior management authorisation for each covert operation; DPIA for the covert monitoring; record of the grounds for suspicion and why notice would prejudice the investigation; policy stating when covert monitoring may occur
Where monitoring plans usually fall short: covert monitoring on a hunch; authorised by a line manager; no DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.19(b)Covert monitoring: tightly targeted and time-limited, never in toilets or changing rooms, and not of private communications official guidance, not law

Covert monitoring should be strictly targeted at obtaining evidence within the shortest possible set period and should stop when the investigation is complete; covert audio or video should not be used where workers can reasonably expect privacy, toilets and changing rooms among them, and in most cases covert monitoring should leave alone communications workers would reasonably treat as private, personal email for instance.

What a reviewer asks to see: covert monitoring plan with scope, targets and end date; evidence that equipment was removed or disabled at the end; placement record excluding private areas
Where monitoring plans usually fall short: open-ended covert monitoring; hidden cameras in washrooms or changing rooms; personal email captured in covert operations
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not law

Covert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.

What a reviewer asks to see: Authorization record for each covert monitoring exercise with the suspicion and grounds, or the legal provision relied on; End date and review of each exercise
Where monitoring plans usually fall short: Covert monitoring used for general performance concerns
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ICO video guidance P.3Fairness: meet reasonable expectations; cameras in toilets and changing rooms only in the most exceptional circumstances official guidance, not law

Processing that is lawful can still be unfair: people should only be recorded in ways they would reasonably expect, judged objectively in the circumstances, and without unjustified adverse effects. Places with heightened privacy expectations, such as private property, public toilets and changing rooms, should be monitored only in the most exceptional circumstances to deal with very serious concerns (cameras in school toilets are unlikely to be proportionate). The organisation should weigh new or unexpected technology, intrusion where behaviour is not modified and the chilling effect on how people behave and move, and reflect this in a DPIA before deployment.

What a reviewer asks to see: fairness and reasonable-expectations assessment in the DPIA; placement plan excluding toilets and changing rooms, or the documented exceptional justification; review of chilling effects in public spaces
Where monitoring plans usually fall short: cameras in changing rooms; new analytics added without reassessing expectations; no fairness analysis
Source: ICO guidance on video surveillance, including CCTV 2022 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.1Remote and home working: factor higher privacy expectations and family capture into the DPIA official guidance, not law

When monitoring remote workers, and especially those at home, the employer should remember that privacy expectations are higher at home and that family and private life is more easily captured by accident, and should build this risk into any monitoring through a DPIA.

What a reviewer asks to see: DPIA section on home-working capture of household members; configuration limiting monitoring to work hours and work systems; guidance to home workers on camera and microphone settings
Where monitoring plans usually fall short: webcam or audio capture in homes; monitoring outside working hours; DPIA silent on household members
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
UK interception regulations reg 3(1)(a)Interception effected by, or with the express consent of, the system controller

The interception must be of a communication while it is being transmitted over a telecommunication system, and it must be carried out by the system controller (the person entitled to control the system's operation or use) or with that person's express consent. A vendor, outsourced call centre or IT provider that monitors on the business's behalf needs the controller's explicit authority; implied acquiescence is not enough for this route. Regulation 3(1)(b) and (c) add that the conduct must also fit a purpose in paragraphs (2) to (4) and satisfy regulation 4.

What a reviewer asks to see: written authorisation from the system controller naming the monitoring or recording tool, the channels covered and the provider operating it; contract or statement of work with any monitoring vendor that records it acts on the controller's express instruction; register of telecommunication systems (telephony, email, collaboration, network) showing who holds the right to control each
Where monitoring plans usually fall short: monitoring switched on by a vendor or a team without any recorded decision by the system controller; a customer or parent company runs interception on a system it does not control; the controller of a shared or hosted platform is never identified, so express consent cannot be shown
Source: Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, read 30 Sep 2026
UK interception regulations reg 3(2)(c)Purpose: to ascertain or demonstrate standards achieved or to be achieved by users in the course of their duties

Monitoring or recording is authorised to find out or show the standards that people reach, or should reach, when they use the system for their work, which covers quality assurance and training on business calls, emails and messages. It does not extend to communications that are not made in the course of duties.

What a reviewer asks to see: quality monitoring procedure defining the standards assessed, sampling method and who reviews; training and coaching records referencing the sampled communications; scorecards or QA forms linked to the recordings reviewed
Where monitoring plans usually fall short: personal communications swept into quality sampling; standards never written down, so the purpose cannot be shown; QA sampling extended into continuous surveillance of every communication
Source: Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, read 30 Sep 2026
UK interception regulations reg 4(1)(c)All reasonable efforts to inform every user that communications may be intercepted

The system controller must have made all reasonable efforts to tell each person who might use the system that communications carried on it can be intercepted. This covers workers and anyone else who may use the system (contractors, visitors on guest networks); the Regulations do not require the consent of the other party to a call or message, but the users of the controller's own system must be told. Informing external callers is a separate data protection transparency duty.

What a reviewer asks to see: monitoring notice in the employee handbook, acceptable use policy and system log-on banners; acknowledgement records or intranet publication history showing when users were told; notices for non-employee users such as contractors and guest network users; recorded announcement or script where external parties use the controller's system
Where monitoring plans usually fall short: notice given to employees but not to contractors, agency staff or guest users; notice buried in a contract signed years before the monitoring started; new monitoring channel introduced with no updated notice; no record showing when and how users were informed
Source: Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, read 30 Sep 2026
ICO monitoring guidance para 3.3(a)Call monitoring: not all calls by default, itemised records first, workers told, personal calls not routinely monitored official guidance, not law

Monitoring or recording the content of all calls is not usually proportionate; business calls could be monitored for evidence of transactions or for training and quality, or where a regulator's rules require recording (limited to what the rules require). Itemised call records could meet a usage purpose and narrow any further monitoring, and any increase in call monitoring should trigger a DPIA review. Workers must be told of call monitoring in privacy information, and it should also appear in the handbook, codes and guidance; personal calls should not be routinely monitored, with a personal-calls policy workers know about, and a tolerated practice cannot be policed by a ban that is not applied.

What a reviewer asks to see: call recording scope statement (which lines, why); privacy information and handbook section on call monitoring; personal calls policy; DPIA review after any expansion
Where monitoring plans usually fall short: all calls recorded by default; personal calls recorded routinely; workers told only in a contract clause
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
UK GDPR Art. 9Processing of special categories of personal data

Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.

What a reviewer asks to see: Article 9 condition and, where required, the Schedule 1 condition of the 2018 Act recorded per processing; Appropriate policy document where Schedule 1 requires one; Explicit consent records where that is the condition
Where monitoring plans usually fall short: Biometric processing for identification without an Article 9 condition; Relying on substantial public interest without the Schedule 1 condition and policy document; Health data processed outside the professional-secrecy safeguard
Source: UK GDPR, read 30 Sep 2026
ICO monitoring guidance para 4.1Biometric access and time control: document why biometrics are necessary and why alternatives are inadequate, in the DPIA official guidance, not law

Biometric identification carries far more sensitive information than cards and PINs and is harder to fix if inaccurate or breached, so the employer should consider alternatives, should document why it relies on biometrics and why less intrusive means are inadequate, should be able to justify not using a reasonable alternative, and must record all of this in the DPIA; extra security may be needed.

What a reviewer asks to see: DPIA section justifying biometrics over cards, PINs or passwords; evidence base for the necessity decision; security assessment for biometric data
Where monitoring plans usually fall short: biometric clocks chosen for convenience; no alternatives analysis; necessity not documented in the DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 4.2Biometric access: a lawful basis and a special category condition, and a non-biometric alternative without disadvantage official guidance, not law

Using biometrics to identify workers is special category processing, so a lawful basis and a condition are both needed and must be documented in the DPIA. The employer should offer an alternative such as swipe cards or PINs to those who do not want biometric access and should not disadvantage them; without an alternative, biometric access control is very hard to justify and consent is not appropriate, whereas with a genuine, penalty-free alternative consent and explicit consent become likely options.

What a reviewer asks to see: lawful basis and condition record in the DPIA; alternative access method available to all workers; consent and withdrawal records
Where monitoring plans usually fall short: no opt-out from fingerprint or face scanning; workers using the alternative penalised; consent relied on without an alternative
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 4.3Biometric identification of workers always needs a DPIA before processing, discussed with workers official guidance, not law

The employer must carry out and complete a DPIA before processing biometrics that single out an individual worker, because it is high risk; the process also lets it discuss the proposal with workers and their representatives beforehand.

What a reviewer asks to see: DPIA completed and signed before biometric enrolment; record of discussion with workers and representatives; measures traced to DPIA findings
Where monitoring plans usually fall short: enrolment before the DPIA; no worker discussion; DPIA not updated for new sites
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
UK GDPR Art. 35Data protection impact assessment

Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.

What a reviewer asks to see: DPIA screening records for new processing; Completed DPIAs with the four required elements and DPO advice; Review records when processing changes
Where monitoring plans usually fall short: DPIA done after launch; Screening not documented; Commissioner's list of high-risk processing ignored
Source: UK GDPR, read 30 Sep 2026
ICO monitoring guidance para 1.11DPIA before high-risk monitoring, DPO advice recorded, workers informed before start, ICO consulted if high risk remains official guidance, not law

A DPIA must precede any processing that probably poses high risk to workers or others, such as biometric processing, keystroke monitoring, monitoring that may cause financial loss (performance management) or profiling to decide access to services; it should also consider customers, the public and household members captured. Where there is a DPO, the employer must seek and record the DPO's independent advice before deciding; if it goes ahead it must inform workers before monitoring begins; if high risk cannot be reduced it must consult the ICO first. The ICO expects a DPIA even without high risk, or a documented decision not to do one.

What a reviewer asks to see: DPIA completed before deployment; DPO advice recorded in the DPIA; decision record where no DPIA was done; prior consultation file where residual risk stayed high
Where monitoring plans usually fall short: keystroke or biometric monitoring without a DPIA; DPO advice not recorded; workers told only after monitoring started
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.11(a)Device activity monitoring: document the justification, use less intrusive means if they work, identify a basis and condition, and do a DPIA official guidance, not law

Device monitoring (web browsing, emails, documents, applications, screenshots, webcam captures, keystrokes) is likely to capture excessive information including special category data. The employer must be clear about its purpose and fully document its justification, including the less intrusive options considered, and must use a less intrusive way if one achieves the aim; it must identify a lawful basis and any special category condition; it must carry out a DPIA where high risk is likely and should do one anyway.

What a reviewer asks to see: written justification for device monitoring with alternatives considered; lawful basis and condition record; DPIA
Where monitoring plans usually fall short: employee monitoring software deployed without justification; no alternatives considered; no DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.11(c)Device activity monitoring: webcam capture rarely justified, keystroke logging is behavioural biometric data, and private use of own devices kept out official guidance, not law

Capturing webcam shots or footage is particularly unlikely to be justified; keystroke monitoring counts as behavioural biometric data when typing rhythm can identify a worker. Barring personal use of company devices and blocking problem websites could reduce risk, but even then accessing personal communications is hard to justify, and when workers use their own devices for work the employer should make sure it does not capture their private use.

What a reviewer asks to see: configuration showing webcam capture disabled; biometric assessment for any keystroke dynamics feature; BYOD configuration limiting capture to work containers
Where monitoring plans usually fall short: random webcam snapshots; keystroke logging treated as ordinary data; personal device use captured
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 2.1Solely automated decisions with legal or similarly significant effects on workers: only on a ground the law lists, without disadvantaging those who ask for a human official guidance, not law

Decisions made by automated means with no meaningful human involvement that have legal or similarly significant effects on workers (pay changes from productivity data, dismissal) were, under the Article 22 the guidance describes, allowed only where necessary for a contract, authorised by law, or based on explicit consent, and workers who ask for a human to intervene must not end up worse off than those who accept the automated decision. A decision taken by a manager who reviewed tracking data and spoke to the worker is not solely automated. Law since the guidance: the Data (Use and Access) Act 2025, s 80, replaced UK GDPR Article 22 with Articles 22A to 22D (fully in force 5 February 2026): solely automated significant decisions are now restricted only where they rest on special category data (explicit consent, or contract or law plus Article 9(2)(g)) or on recognised legitimate interests, and in every case the controller must provide safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. The ICO flags this guidance as under review.

What a reviewer asks to see: inventory of automated decisions affecting workers with their ground; safeguards: information, representations, human intervention and contest routes; record showing no detriment to workers who request human review
Where monitoring plans usually fall short: pay or discipline set solely by productivity software; no human intervention route; special category data feeding automated decisions without explicit consent
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not law

Monitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.

What a reviewer asks to see: Register of continuous monitoring (CCTV, telematics, always-on tracking) with the health, safety or property ground for each
Where monitoring plans usually fall short: Always-on webcam or activity tracking for remote staff justified by productivity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not law

Output from electronic surveillance should never be the sole input when a worker's performance is judged.

What a reviewer asks to see: Appraisal procedure listing the evidence sources considered besides monitoring data; Sample appraisals showing other inputs (manager review, outputs, feedback)
Where monitoring plans usually fall short: Productivity scores from activity tracking used as the whole appraisal
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
UK GDPR Art. 5Principles relating to processing of personal data

Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What a reviewer asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
Where monitoring plans usually fall short: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR, read 30 Sep 2026
ICO monitoring guidance para 1.15Retention schedule for monitoring data, justified by business need and reviewed official guidance, not law

Monitoring information must not be kept longer than the purpose needs; the employer must have a retention schedule and delete in line with it, should base periods on business need, professional guidelines and legal duties, review them regularly, be able to justify them against the reasons for collection, and should not keep information in case a use turns up.

What a reviewer asks to see: retention schedule entries for each monitoring data set; deletion logs or automated purge configuration; justification for each period
Where monitoring plans usually fall short: no retention period for monitoring data; schedule not applied; footage and logs kept indefinitely
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO video guidance P.11Retention: the shortest period for the purpose, not the recorder's capacity or default, documented, securely deleted and checked official guidance, not law

No fixed retention period applies; the purpose sets it, and the period should be the shortest the purpose needs, after which footage should be deleted. It should not be set by storage capacity or the manufacturer's default (six months merely because the system allows it) or kept in case it proves useful; the policy should be documented and understood by operators, deletion should be permanent and secure, and adherence should be checked. Longer retention can be justified for a specific purpose, such as preserving footage at the request of police investigating a crime.

What a reviewer asks to see: retention policy stating the period and its reasoning; recorder configuration matching the policy; deletion checks and incident preservation log
Where monitoring plans usually fall short: retention equal to disk capacity; manufacturer default left unchanged; no check that overwriting happens
Source: ICO guidance on video surveillance, including CCTV 2022 (official guidance, not law), read 30 Sep 2026
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not law

Keep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.

What a reviewer asks to see: Retention schedule for worker data including monitoring records, citing purpose, legal requirement or proceedings; Deletion logs
Where monitoring plans usually fall short: Monitoring recordings kept indefinitely; Unsuccessful applicants' data kept without their agreement
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
UK GDPR Art. 6Lawfulness of processing

Processing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.

What a reviewer asks to see: Lawful basis recorded per processing purpose; Legitimate interests assessments for Article 6(1)(f) processing; Annex 1 condition and the requesting body's written statement kept for each recognised legitimate interest disclosure
Where monitoring plans usually fall short: Treating the Article 6(11) examples as automatically lawful without a balancing test; Public authorities relying on legitimate interests for their core tasks; Recognised legitimate interest claimed where no Annex 1 condition fits
Source: UK GDPR, read 30 Sep 2026
ICO monitoring guidance para 1.4(a)Choose the lawful basis for the specific purpose, document it from the start and do not switch later official guidance, not law

The basis depends on the purpose and context; the employer must think about why it wants to monitor and pick the basis that best fits, must not use a one-size-fits-all approach, should identify and document every basis that applies from the outset, and should keep to it unless a good reason arises. A DPIA or the ICO's interactive tool can help.

What a reviewer asks to see: lawful basis record dated at design stage for each monitoring purpose; privacy information stating the basis; change log with reasons if a basis was revised
Where monitoring plans usually fall short: one basis claimed for every monitoring activity; basis chosen after deployment; basis swapped when challenged
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.4(b)Consent is rarely valid for monitoring at work; where used it must be withdrawable without detriment and recorded official guidance, not law

Consent must be freely given, which the power imbalance usually rules out, so it is not usually appropriate for employers; it works only where workers truly choose and control whether they are monitored. Where it is used it must be unambiguous with an affirmative act, and the employer must let workers withdraw without detriment as easily as they gave it, and record the date, method and exact scope of each consent.

What a reviewer asks to see: consent records showing when, how and to what each worker agreed; withdrawal mechanism and log; evidence of an alternative for workers who decline
Where monitoring plans usually fall short: consent clause in the employment contract; no withdrawal route; workers who decline treated differently
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.4(d)Legitimate interests: pass the purpose, necessity and balancing tests, record a legitimate interests assessment, and respect reasonable expectations official guidance, not law

Legitimate interests is the most flexible basis, but the employer must weigh its interests, and how necessary the monitoring is, against what workers stand to lose in rights and freedoms in the particular case, and should run the purpose, necessity and balancing tests before starting and record the result in a legitimate interests assessment. It may not be appropriate where workers would not understand or reasonably expect the monitoring or would likely object if told; expectations vary with the job (a miner expects a tracker, an office worker does not).

What a reviewer asks to see: legitimate interests assessment per monitoring purpose with the three tests; evidence of what workers were told and their reasonable expectations; review date for the assessment
Where monitoring plans usually fall short: LIA missing or written after deployment; balancing test ignores role-specific expectations; monitoring kept secret because workers would object
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.7Check other laws beyond data protection before monitoring official guidance, not law

Monitoring must be lawful and fair overall, so the employer should consider laws outside data protection, including the Human Rights Act 1998, the Equality Act 2010 and section 75 of the Northern Ireland Act 1998, and the interception rules (SI 2018/356 on interception by businesses and their predecessor, the Telecommunications (Lawful Business Practice) Regulations 2000).

What a reviewer asks to see: legal review covering human rights, equality and interception rules; equality impact assessment for monitoring affecting protected groups; interception compliance record for call and message monitoring
Where monitoring plans usually fall short: interception regulations never checked; equality effects of monitoring unassessed; reasonable adjustments ignored in monitoring metrics
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law

5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.

What a reviewer asks to see: Register of worker data processing activities, each with its employment-related reason and legal basis
Where monitoring plans usually fall short: Data collected for reasons unrelated to the job, such as off-duty social media activity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.6Criminal offence data from monitoring needs official authority or a Schedule 1 condition official guidance, not law

Information about offences, allegations, investigations or proceedings concerning workers may only be processed under official authority or where domestic law authorises it; monitoring to detect criminal activity needs a specific Schedule 1 DPA 2018 condition.

What a reviewer asks to see: Schedule 1 condition recorded for fraud or theft monitoring; appropriate policy document where Schedule 1 requires it; access restrictions on investigation files
Where monitoring plans usually fall short: fraud monitoring with no Article 10 analysis; allegations logged in general HR systems; no appropriate policy document
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not law

Employers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.

What a reviewer asks to see: Data inventory confirming these categories are not collected, or the documented exception and legal basis where they are
Where monitoring plans usually fall short: Criminal record checks for every role regardless of relevance
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.6No data on union membership or activities unless required official guidance, not law

Employers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.

What a reviewer asks to see: Review of HR and monitoring systems confirming union data are not collected except under a stated legal or agreement basis
Where monitoring plans usually fall short: Monitoring tools flag union-related email or chat
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.4(a)Email and message monitoring: a clear, necessary purpose, workers told, and a DPIA official guidance, not law

Monitoring emails and messages (including chat in collaboration tools) to protect information, for security, to spot suspicious activity or to enforce acceptable use requires a clear purpose, necessity and proportionality, and informing workers of the purpose; the employer must complete a DPIA because it is high risk and likely to capture special category data.

What a reviewer asks to see: DPIA for email and message monitoring; purpose statement and notice to workers; acceptable use policy regularly brought to attention
Where monitoring plans usually fall short: email monitoring without a DPIA; chat monitoring not disclosed; purpose unstated
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.4(b)Email and message content only exceptionally, with a clear policy and advance notice; network data first official guidance, not law

Content monitoring is hard to justify where network traffic data would meet the purpose; the employer must notify workers in advance (in policy documents) if content may be monitored in exceptional circumstances and must not access content without a clear policy stating when that can happen. Before monitoring it should consider narrowing checks using network data (emails to rival firms, for instance), the duty of confidence to workers and customers, excluding lines such as union representatives, that even a ban on personal use does not justify reading personal messages (investigate breaches through network data first), letting workers mark messages personal, and the reliability of the records.

What a reviewer asks to see: policy defining exceptional circumstances for content access; content access log with authorisations; exclusion rules for union and occupational health correspondence; personal-marking feature configuration
Where monitoring plans usually fall short: routine content review; content accessed with no written policy; union emails captured
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.10Data loss prevention and traffic monitoring: least invasive means, a DPIA, and blocking with review as an alternative official guidance, not law

For security tools such as firewalls and data loss prevention, the employer should choose the least invasive means and complete a DPIA; network traffic monitoring can be high risk, especially with inferences about workers, and blocking suspicious traffic or sending the worker to a portal to request a review could replace more detailed monitoring.

What a reviewer asks to see: DPIA for DLP and traffic monitoring; block-and-review configuration; record of less invasive options assessed
Where monitoring plans usually fall short: full traffic inspection without assessment; no review route for blocked traffic; DLP alerts analysed for worker profiling
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.5(a)Video monitoring of workers: DPIA, targeted at risk areas with low privacy expectations, workers and others informed, footage redactable official guidance, not law

Before using video monitoring the employer must complete a DPIA, consider why it is necessary, inform workers of its extent, nature and reasons, and make visitors, customers and others caught by it aware too; a DPIA is needed where special category capture is likely. Cameras should be aimed at particular risk areas where privacy expectations are low, continuous monitoring of workers is justified only rarely, covert use is unlikely to be justified, and footage may need redacting for subject access requests.

What a reviewer asks to see: DPIA for workplace CCTV; camera placement plan targeting risk areas; signage and worker notice; redaction capability for SARs
Where monitoring plans usually fall short: cameras trained continuously on desks; no signage for visitors; no DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO video guidance A.4DPIA before surveillance likely to be high risk (most cases), evidence-based, with alternatives considered; consult the ICO if high risk remains official guidance, not law

A DPIA is a legal requirement before processing likely to result in high risk, which covers most video surveillance, including large-scale systematic monitoring of publicly accessible places. It must set out what the processing is, its scope, context and purposes, weigh necessity and proportionality and the compliance measures, identify and rate the risks to people, and set out further measures to reduce them; a decision not to do one must be documented and justified. The organisation should consider lawfulness and transparency, whether the system is necessary and proportionate and actually solves the problem on reliable evidence, and less intrusive alternatives; if high residual risk remains it must consult the ICO and not proceed until it has. Failing to do a required DPIA is itself an infringement.

What a reviewer asks to see: DPIA completed before installation (the SCC and ICO template or equivalent); evidence base for the problem and the system's effectiveness; documented reasons where no DPIA was done; prior consultation file where residual risk stayed high
Where monitoring plans usually fall short: cameras installed first, DPIA later or never; no evidence the problem exists; alternatives not considered
Source: ICO guidance on video surveillance, including CCTV 2022 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.5(c)Facial recognition in worker monitoring: special category data, a lawful basis and condition, and a DPIA official guidance, not law

Facial recognition carries higher risks than ordinary video, especially when used to infer behaviour, emotion or intention, and raises accuracy concerns for ethnic minority groups; using it to identify workers is processing biometric special category data needing a lawful basis and a condition, and the employer must carry out a DPIA because it is high risk.

What a reviewer asks to see: DPIA for facial recognition; lawful basis and Article 9 condition record; accuracy and bias testing results across demographic groups
Where monitoring plans usually fall short: emotion analysis of staff; facial recognition without a condition; no bias testing
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026

See the specimen plan run Plan your own list