Employee Monitoring Law Planner
Sources

ICO guidance: employment practices and data protection, monitoring workers 2023

Official guidance, not law. Placed at UK locations. Read 30 Sep 2026; 27 provisions cited by the planner.

ICO monitoring guidance para 1.18Seek and document the views of workers or their representatives (such as trade unions) before introducing monitoring official guidance, not law

When planning monitoring the employer should ask for, and record, what workers or their representatives (trade unions, for example) think, unless it has good reason not to, and if it decides not to it should record that decision with a clear explanation; workers should be involved early in planning, as part of the DPIA.

What a reviewer asks to see: record of consultation with workers or trade union representatives; DPIA section recording their views and responses; documented reason where consultation was not held
Where monitoring plans usually fall short: no consultation and no recorded reason; consultation after the decision; representatives' concerns not answered
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.9Transparency: tell workers about monitoring in an accessible way, except where covert monitoring is exceptionally justified official guidance, not law

Transparency is tied to fairness and trust: workers are entitled to be informed, and the employer must tell them about monitoring in an accessible, easily understood way; apart from very exceptional cases where covert monitoring is justified, it must inform workers of any monitoring.

What a reviewer asks to see: worker privacy notice covering monitoring; accessibility review of the notice (plain language, formats); log of exceptional covert monitoring decisions
Where monitoring plans usually fall short: monitoring disclosed only in legal jargon; notice not accessible to all staff; covert monitoring treated as routine
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.3(b)Call monitoring: tell callers the call is recorded and why official guidance, not law

Call monitoring also captures callers' information: the employer must tell them the call is being recorded and why, a recorded message being good practice; where that is not possible it must instruct workers to tell callers and explain the reason, with the rest of the privacy information given by other means such as email or a website link. Recordings are likely personal data disclosable on a subject access request, and workers should know recordings may be released.

What a reviewer asks to see: recorded announcement script; worker script for manual notice where no announcement exists; published call-recording privacy information
Where monitoring plans usually fall short: no announcement to callers; reason for recording not given; no route to fuller privacy information
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.6Vehicle monitoring: inform workers and passengers, rarely during private use, DPIA for driver behaviour or analytics official guidance, not law

Work vehicles may be monitored, but monitoring during permitted private use will rarely be justified (a driver-operated privacy switch outside working hours is the ICO's example), and the employer must tell workers and any passengers that the vehicle is monitored. Tachograph monitoring required by drivers' hours rules can rest on legal obligation; insurance telematics data is personal data. Monitoring driving behaviour and style, or using cameras or audio, is high risk and needs a DPIA considering less intrusive methods, as does any analytics making inferences or decisions about drivers.

What a reviewer asks to see: in-vehicle notices and driver policy; privacy switch configuration for private use; DPIA for driver behaviour monitoring and analytics
Where monitoring plans usually fall short: tracking during private use; passengers not informed; driver scoring without a DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.12(b)Monitoring policies set out nature, purpose and extent, are brought to workers' attention, and match practice official guidance, not law

Where monitoring enforces organisational rules, those rules should be clearly set out and regularly brought to workers' attention, and the policy should describe the nature, purpose and extent of monitoring; the ICO's example is an acceptable use policy linked to privacy information explaining how the rules are monitored, how the information is used and the safeguards. Workers form expectations from what actually happens, not only from policy: excessive monitoring is not made lawful by being written down, and a tolerated practice (some personal calls) cannot be policed by pointing to a policy that bans it. Blocking sites or requiring acceptance of conditions can reduce the need to monitor.

What a reviewer asks to see: acceptable use and monitoring policy with nature, purpose and extent; evidence of regular reminders (training, log-on banners, intranet); comparison of policy against actual practice
Where monitoring plans usually fall short: policy bans personal use but managers tolerate it; policy never re-communicated; monitoring extent not stated
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.19(a)Covert monitoring only exceptionally, for suspected crime or gross misconduct, authorised by senior management after a DPIA official guidance, not law

Covert monitoring, designed so workers do not know it happens, is unlikely to be justified in usual circumstances; it may be justified exceptionally where it is needed to stop or uncover suspected crime or gross misconduct. Policies should say which behaviours are unacceptable and when covert monitoring may occur; it should be authorised only by senior management, the employer must carry out a DPIA, and it should be satisfied there are grounds for suspicion and that telling workers would prejudice prevention or detection. Every decision should be justifiable.

What a reviewer asks to see: senior management authorisation for each covert operation; DPIA for the covert monitoring; record of the grounds for suspicion and why notice would prejudice the investigation; policy stating when covert monitoring may occur
Where monitoring plans usually fall short: covert monitoring on a hunch; authorised by a line manager; no DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.19(b)Covert monitoring: tightly targeted and time-limited, never in toilets or changing rooms, and not of private communications official guidance, not law

Covert monitoring should be strictly targeted at obtaining evidence within the shortest possible set period and should stop when the investigation is complete; covert audio or video should not be used where workers can reasonably expect privacy, toilets and changing rooms among them, and in most cases covert monitoring should leave alone communications workers would reasonably treat as private, personal email for instance.

What a reviewer asks to see: covert monitoring plan with scope, targets and end date; evidence that equipment was removed or disabled at the end; placement record excluding private areas
Where monitoring plans usually fall short: open-ended covert monitoring; hidden cameras in washrooms or changing rooms; personal email captured in covert operations
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.1Remote and home working: factor higher privacy expectations and family capture into the DPIA official guidance, not law

When monitoring remote workers, and especially those at home, the employer should remember that privacy expectations are higher at home and that family and private life is more easily captured by accident, and should build this risk into any monitoring through a DPIA.

What a reviewer asks to see: DPIA section on home-working capture of household members; configuration limiting monitoring to work hours and work systems; guidance to home workers on camera and microphone settings
Where monitoring plans usually fall short: webcam or audio capture in homes; monitoring outside working hours; DPIA silent on household members
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.3(a)Call monitoring: not all calls by default, itemised records first, workers told, personal calls not routinely monitored official guidance, not law

Monitoring or recording the content of all calls is not usually proportionate; business calls could be monitored for evidence of transactions or for training and quality, or where a regulator's rules require recording (limited to what the rules require). Itemised call records could meet a usage purpose and narrow any further monitoring, and any increase in call monitoring should trigger a DPIA review. Workers must be told of call monitoring in privacy information, and it should also appear in the handbook, codes and guidance; personal calls should not be routinely monitored, with a personal-calls policy workers know about, and a tolerated practice cannot be policed by a ban that is not applied.

What a reviewer asks to see: call recording scope statement (which lines, why); privacy information and handbook section on call monitoring; personal calls policy; DPIA review after any expansion
Where monitoring plans usually fall short: all calls recorded by default; personal calls recorded routinely; workers told only in a contract clause
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 4.1Biometric access and time control: document why biometrics are necessary and why alternatives are inadequate, in the DPIA official guidance, not law

Biometric identification carries far more sensitive information than cards and PINs and is harder to fix if inaccurate or breached, so the employer should consider alternatives, should document why it relies on biometrics and why less intrusive means are inadequate, should be able to justify not using a reasonable alternative, and must record all of this in the DPIA; extra security may be needed.

What a reviewer asks to see: DPIA section justifying biometrics over cards, PINs or passwords; evidence base for the necessity decision; security assessment for biometric data
Where monitoring plans usually fall short: biometric clocks chosen for convenience; no alternatives analysis; necessity not documented in the DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 4.2Biometric access: a lawful basis and a special category condition, and a non-biometric alternative without disadvantage official guidance, not law

Using biometrics to identify workers is special category processing, so a lawful basis and a condition are both needed and must be documented in the DPIA. The employer should offer an alternative such as swipe cards or PINs to those who do not want biometric access and should not disadvantage them; without an alternative, biometric access control is very hard to justify and consent is not appropriate, whereas with a genuine, penalty-free alternative consent and explicit consent become likely options.

What a reviewer asks to see: lawful basis and condition record in the DPIA; alternative access method available to all workers; consent and withdrawal records
Where monitoring plans usually fall short: no opt-out from fingerprint or face scanning; workers using the alternative penalised; consent relied on without an alternative
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 4.3Biometric identification of workers always needs a DPIA before processing, discussed with workers official guidance, not law

The employer must carry out and complete a DPIA before processing biometrics that single out an individual worker, because it is high risk; the process also lets it discuss the proposal with workers and their representatives beforehand.

What a reviewer asks to see: DPIA completed and signed before biometric enrolment; record of discussion with workers and representatives; measures traced to DPIA findings
Where monitoring plans usually fall short: enrolment before the DPIA; no worker discussion; DPIA not updated for new sites
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.11DPIA before high-risk monitoring, DPO advice recorded, workers informed before start, ICO consulted if high risk remains official guidance, not law

A DPIA must precede any processing that probably poses high risk to workers or others, such as biometric processing, keystroke monitoring, monitoring that may cause financial loss (performance management) or profiling to decide access to services; it should also consider customers, the public and household members captured. Where there is a DPO, the employer must seek and record the DPO's independent advice before deciding; if it goes ahead it must inform workers before monitoring begins; if high risk cannot be reduced it must consult the ICO first. The ICO expects a DPIA even without high risk, or a documented decision not to do one.

What a reviewer asks to see: DPIA completed before deployment; DPO advice recorded in the DPIA; decision record where no DPIA was done; prior consultation file where residual risk stayed high
Where monitoring plans usually fall short: keystroke or biometric monitoring without a DPIA; DPO advice not recorded; workers told only after monitoring started
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.11(a)Device activity monitoring: document the justification, use less intrusive means if they work, identify a basis and condition, and do a DPIA official guidance, not law

Device monitoring (web browsing, emails, documents, applications, screenshots, webcam captures, keystrokes) is likely to capture excessive information including special category data. The employer must be clear about its purpose and fully document its justification, including the less intrusive options considered, and must use a less intrusive way if one achieves the aim; it must identify a lawful basis and any special category condition; it must carry out a DPIA where high risk is likely and should do one anyway.

What a reviewer asks to see: written justification for device monitoring with alternatives considered; lawful basis and condition record; DPIA
Where monitoring plans usually fall short: employee monitoring software deployed without justification; no alternatives considered; no DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.11(c)Device activity monitoring: webcam capture rarely justified, keystroke logging is behavioural biometric data, and private use of own devices kept out official guidance, not law

Capturing webcam shots or footage is particularly unlikely to be justified; keystroke monitoring counts as behavioural biometric data when typing rhythm can identify a worker. Barring personal use of company devices and blocking problem websites could reduce risk, but even then accessing personal communications is hard to justify, and when workers use their own devices for work the employer should make sure it does not capture their private use.

What a reviewer asks to see: configuration showing webcam capture disabled; biometric assessment for any keystroke dynamics feature; BYOD configuration limiting capture to work containers
Where monitoring plans usually fall short: random webcam snapshots; keystroke logging treated as ordinary data; personal device use captured
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 2.1Solely automated decisions with legal or similarly significant effects on workers: only on a ground the law lists, without disadvantaging those who ask for a human official guidance, not law

Decisions made by automated means with no meaningful human involvement that have legal or similarly significant effects on workers (pay changes from productivity data, dismissal) were, under the Article 22 the guidance describes, allowed only where necessary for a contract, authorised by law, or based on explicit consent, and workers who ask for a human to intervene must not end up worse off than those who accept the automated decision. A decision taken by a manager who reviewed tracking data and spoke to the worker is not solely automated. Law since the guidance: the Data (Use and Access) Act 2025, s 80, replaced UK GDPR Article 22 with Articles 22A to 22D (fully in force 5 February 2026): solely automated significant decisions are now restricted only where they rest on special category data (explicit consent, or contract or law plus Article 9(2)(g)) or on recognised legitimate interests, and in every case the controller must provide safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. The ICO flags this guidance as under review.

What a reviewer asks to see: inventory of automated decisions affecting workers with their ground; safeguards: information, representations, human intervention and contest routes; record showing no detriment to workers who request human review
Where monitoring plans usually fall short: pay or discipline set solely by productivity software; no human intervention route; special category data feeding automated decisions without explicit consent
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.15Retention schedule for monitoring data, justified by business need and reviewed official guidance, not law

Monitoring information must not be kept longer than the purpose needs; the employer must have a retention schedule and delete in line with it, should base periods on business need, professional guidelines and legal duties, review them regularly, be able to justify them against the reasons for collection, and should not keep information in case a use turns up.

What a reviewer asks to see: retention schedule entries for each monitoring data set; deletion logs or automated purge configuration; justification for each period
Where monitoring plans usually fall short: no retention period for monitoring data; schedule not applied; footage and logs kept indefinitely
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.4(a)Choose the lawful basis for the specific purpose, document it from the start and do not switch later official guidance, not law

The basis depends on the purpose and context; the employer must think about why it wants to monitor and pick the basis that best fits, must not use a one-size-fits-all approach, should identify and document every basis that applies from the outset, and should keep to it unless a good reason arises. A DPIA or the ICO's interactive tool can help.

What a reviewer asks to see: lawful basis record dated at design stage for each monitoring purpose; privacy information stating the basis; change log with reasons if a basis was revised
Where monitoring plans usually fall short: one basis claimed for every monitoring activity; basis chosen after deployment; basis swapped when challenged
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.4(b)Consent is rarely valid for monitoring at work; where used it must be withdrawable without detriment and recorded official guidance, not law

Consent must be freely given, which the power imbalance usually rules out, so it is not usually appropriate for employers; it works only where workers truly choose and control whether they are monitored. Where it is used it must be unambiguous with an affirmative act, and the employer must let workers withdraw without detriment as easily as they gave it, and record the date, method and exact scope of each consent.

What a reviewer asks to see: consent records showing when, how and to what each worker agreed; withdrawal mechanism and log; evidence of an alternative for workers who decline
Where monitoring plans usually fall short: consent clause in the employment contract; no withdrawal route; workers who decline treated differently
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.4(d)Legitimate interests: pass the purpose, necessity and balancing tests, record a legitimate interests assessment, and respect reasonable expectations official guidance, not law

Legitimate interests is the most flexible basis, but the employer must weigh its interests, and how necessary the monitoring is, against what workers stand to lose in rights and freedoms in the particular case, and should run the purpose, necessity and balancing tests before starting and record the result in a legitimate interests assessment. It may not be appropriate where workers would not understand or reasonably expect the monitoring or would likely object if told; expectations vary with the job (a miner expects a tracker, an office worker does not).

What a reviewer asks to see: legitimate interests assessment per monitoring purpose with the three tests; evidence of what workers were told and their reasonable expectations; review date for the assessment
Where monitoring plans usually fall short: LIA missing or written after deployment; balancing test ignores role-specific expectations; monitoring kept secret because workers would object
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.7Check other laws beyond data protection before monitoring official guidance, not law

Monitoring must be lawful and fair overall, so the employer should consider laws outside data protection, including the Human Rights Act 1998, the Equality Act 2010 and section 75 of the Northern Ireland Act 1998, and the interception rules (SI 2018/356 on interception by businesses and their predecessor, the Telecommunications (Lawful Business Practice) Regulations 2000).

What a reviewer asks to see: legal review covering human rights, equality and interception rules; equality impact assessment for monitoring affecting protected groups; interception compliance record for call and message monitoring
Where monitoring plans usually fall short: interception regulations never checked; equality effects of monitoring unassessed; reasonable adjustments ignored in monitoring metrics
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 1.6Criminal offence data from monitoring needs official authority or a Schedule 1 condition official guidance, not law

Information about offences, allegations, investigations or proceedings concerning workers may only be processed under official authority or where domestic law authorises it; monitoring to detect criminal activity needs a specific Schedule 1 DPA 2018 condition.

What a reviewer asks to see: Schedule 1 condition recorded for fraud or theft monitoring; appropriate policy document where Schedule 1 requires it; access restrictions on investigation files
Where monitoring plans usually fall short: fraud monitoring with no Article 10 analysis; allegations logged in general HR systems; no appropriate policy document
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.4(a)Email and message monitoring: a clear, necessary purpose, workers told, and a DPIA official guidance, not law

Monitoring emails and messages (including chat in collaboration tools) to protect information, for security, to spot suspicious activity or to enforce acceptable use requires a clear purpose, necessity and proportionality, and informing workers of the purpose; the employer must complete a DPIA because it is high risk and likely to capture special category data.

What a reviewer asks to see: DPIA for email and message monitoring; purpose statement and notice to workers; acceptable use policy regularly brought to attention
Where monitoring plans usually fall short: email monitoring without a DPIA; chat monitoring not disclosed; purpose unstated
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.4(b)Email and message content only exceptionally, with a clear policy and advance notice; network data first official guidance, not law

Content monitoring is hard to justify where network traffic data would meet the purpose; the employer must notify workers in advance (in policy documents) if content may be monitored in exceptional circumstances and must not access content without a clear policy stating when that can happen. Before monitoring it should consider narrowing checks using network data (emails to rival firms, for instance), the duty of confidence to workers and customers, excluding lines such as union representatives, that even a ban on personal use does not justify reading personal messages (investigate breaches through network data first), letting workers mark messages personal, and the reliability of the records.

What a reviewer asks to see: policy defining exceptional circumstances for content access; content access log with authorisations; exclusion rules for union and occupational health correspondence; personal-marking feature configuration
Where monitoring plans usually fall short: routine content review; content accessed with no written policy; union emails captured
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.10Data loss prevention and traffic monitoring: least invasive means, a DPIA, and blocking with review as an alternative official guidance, not law

For security tools such as firewalls and data loss prevention, the employer should choose the least invasive means and complete a DPIA; network traffic monitoring can be high risk, especially with inferences about workers, and blocking suspicious traffic or sending the worker to a portal to request a review could replace more detailed monitoring.

What a reviewer asks to see: DPIA for DLP and traffic monitoring; block-and-review configuration; record of less invasive options assessed
Where monitoring plans usually fall short: full traffic inspection without assessment; no review route for blocked traffic; DLP alerts analysed for worker profiling
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.5(a)Video monitoring of workers: DPIA, targeted at risk areas with low privacy expectations, workers and others informed, footage redactable official guidance, not law

Before using video monitoring the employer must complete a DPIA, consider why it is necessary, inform workers of its extent, nature and reasons, and make visitors, customers and others caught by it aware too; a DPIA is needed where special category capture is likely. Cameras should be aimed at particular risk areas where privacy expectations are low, continuous monitoring of workers is justified only rarely, covert use is unlikely to be justified, and footage may need redacting for subject access requests.

What a reviewer asks to see: DPIA for workplace CCTV; camera placement plan targeting risk areas; signage and worker notice; redaction capability for SARs
Where monitoring plans usually fall short: cameras trained continuously on desks; no signage for visitors; no DPIA
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026
ICO monitoring guidance para 3.5(c)Facial recognition in worker monitoring: special category data, a lawful basis and condition, and a DPIA official guidance, not law

Facial recognition carries higher risks than ordinary video, especially when used to infer behaviour, emotion or intention, and raises accuracy concerns for ethnic minority groups; using it to identify workers is processing biometric special category data needing a lawful basis and a condition, and the employer must carry out a DPIA because it is high risk.

What a reviewer asks to see: DPIA for facial recognition; lawful basis and Article 9 condition record; accuracy and bias testing results across demographic groups
Where monitoring plans usually fall short: emotion analysis of staff; facial recognition without a condition; no bias testing
Source: ICO guidance: employment practices and data protection, monitoring workers 2023 (official guidance, not law), read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list