Employee Monitoring Law Planner
Sources

GDPR (the EU General Data Protection Regulation)

Law. Placed at EU and EEA locations. Read 30 Sep 2026; 8 provisions cited by the planner.

GDPR Art. 13Information to be provided where personal data are collected

Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What a reviewer asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
Where monitoring plans usually fall short: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 5Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where monitoring plans usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 9Processing of special categories of personal data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where monitoring plans usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 35Data protection impact assessment

Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What a reviewer asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
Where monitoring plans usually fall short: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 22Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.

What a reviewer asks to see: An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects; The exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument; The human intervention process, showing the reviewer has the authority and the information to change the outcome; Records of contested decisions and the outcome of each review; Confirmation of whether special category data, including proxies for it, enters the model, and the safeguards applied where it does
Where monitoring plans usually fall short: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance; Necessity for a contract asserted where a manual or hybrid process would work and is merely more expensive; Special category data entering the model through proxies such as postcode, name or purchase history with no assessment; No route for the data subject to contest the decision, only a route to complain about service
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 6Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What a reviewer asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
Where monitoring plans usually fall short: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 88Processing in the context of employment

Article 88 is addressed to Member States: it lets national law or collective agreements set more specific rules for handling workers' personal data across the employment relationship, from hiring through the running of the contract, work organisation, equality, health and safety, protection of property and the exercise of employment rights, to its end. An employer therefore identifies, for every country in which it employs people, which national employment-context rules made under this article apply, and applies the safeguards those rules must contain for dignity, legitimate interests and fundamental rights: openness about the processing, data passed between companies in the same group, and any system used to monitor people at work. The article is not itself a lawful basis; the Article 6 basis, and an Article 9 condition where special category data is involved, is still needed (CJEU C-34/21 found that a national rule which only restates the general conditions of the Regulation is not a more specific rule under this article).

What a reviewer asks to see: A per-country register of the national employment data rules and collective agreements the employer relies on, each cited to its provision; Works agreements or collective agreements covering monitoring systems, with their scope, date and signatories; Employee privacy notices that name each monitoring system, its purpose and its retention; Records of intra-group transfers of HR data with the group arrangement that governs them; The Article 6 basis (and Article 9 condition where relevant) recorded for each HR processing activity alongside the national rule
Where monitoring plans usually fall short: A national employment data provision cited as the lawful basis on its own, with no Article 6 basis recorded; Monitoring tools introduced in one country under a policy written for another country's law; No record of which works agreement covers which monitoring system; HR data shared across group companies with no documented arrangement
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026
GDPR Art. 10Processing of personal data relating to criminal convictions

Process personal data relating to criminal convictions and offences, or related security measures, only under the control of official authority or where Union or Member State law authorises the processing and provides appropriate safeguards for the rights and freedoms of data subjects. A comprehensive register of criminal convictions may be kept only under the control of official authority. An Article 6 lawful basis is required in addition.

What a reviewer asks to see: Identification of where conviction and offence data is processed, including screening and vetting results and incident records; The Union or Member State provision authorising the processing, and the safeguards that provision requires; Evidence the required safeguards are actually implemented rather than merely cited; Access restriction and retention applied specifically to this data, tighter than for ordinary personal data; Confirmation that no comprehensive register of convictions is maintained outside official authority
Where monitoring plans usually fall short: Background screening results retained on the personnel file indefinitely after the hiring decision is made; Reliance on the candidate's consent where national law, not consent, is the authorisation the Article requires; Offence data captured in incident reports or free text fields and never treated as Article 10 data; The authorising law identified but the specific safeguards it mandates never mapped to a control
Source: GDPR (the EU General Data Protection Regulation), read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list