ICO guidance: employment practices and data protection, monitoring workers 2023
Official guidance, not law. Placed at UK locations. Read 30 Sep 2026; 27 provisions cited by the planner.
ICO monitoring guidance para 1.18Seek and document the views of workers or their representatives (such as trade unions) before introducing monitoring official guidance, not lawWhen planning monitoring the employer should ask for, and record, what workers or their representatives (trade unions, for example) think, unless it has good reason not to, and if it decides not to it should record that decision with a clear explanation; workers should be involved early in planning, as part of the DPIA.
ICO monitoring guidance para 1.9Transparency: tell workers about monitoring in an accessible way, except where covert monitoring is exceptionally justified official guidance, not lawTransparency is tied to fairness and trust: workers are entitled to be informed, and the employer must tell them about monitoring in an accessible, easily understood way; apart from very exceptional cases where covert monitoring is justified, it must inform workers of any monitoring.
ICO monitoring guidance para 3.3(b)Call monitoring: tell callers the call is recorded and why official guidance, not lawCall monitoring also captures callers' information: the employer must tell them the call is being recorded and why, a recorded message being good practice; where that is not possible it must instruct workers to tell callers and explain the reason, with the rest of the privacy information given by other means such as email or a website link. Recordings are likely personal data disclosable on a subject access request, and workers should know recordings may be released.
ICO monitoring guidance para 3.6Vehicle monitoring: inform workers and passengers, rarely during private use, DPIA for driver behaviour or analytics official guidance, not lawWork vehicles may be monitored, but monitoring during permitted private use will rarely be justified (a driver-operated privacy switch outside working hours is the ICO's example), and the employer must tell workers and any passengers that the vehicle is monitored. Tachograph monitoring required by drivers' hours rules can rest on legal obligation; insurance telematics data is personal data. Monitoring driving behaviour and style, or using cameras or audio, is high risk and needs a DPIA considering less intrusive methods, as does any analytics making inferences or decisions about drivers.
ICO monitoring guidance para 1.12(b)Monitoring policies set out nature, purpose and extent, are brought to workers' attention, and match practice official guidance, not lawWhere monitoring enforces organisational rules, those rules should be clearly set out and regularly brought to workers' attention, and the policy should describe the nature, purpose and extent of monitoring; the ICO's example is an acceptable use policy linked to privacy information explaining how the rules are monitored, how the information is used and the safeguards. Workers form expectations from what actually happens, not only from policy: excessive monitoring is not made lawful by being written down, and a tolerated practice (some personal calls) cannot be policed by pointing to a policy that bans it. Blocking sites or requiring acceptance of conditions can reduce the need to monitor.
ICO monitoring guidance para 1.19(a)Covert monitoring only exceptionally, for suspected crime or gross misconduct, authorised by senior management after a DPIA official guidance, not lawCovert monitoring, designed so workers do not know it happens, is unlikely to be justified in usual circumstances; it may be justified exceptionally where it is needed to stop or uncover suspected crime or gross misconduct. Policies should say which behaviours are unacceptable and when covert monitoring may occur; it should be authorised only by senior management, the employer must carry out a DPIA, and it should be satisfied there are grounds for suspicion and that telling workers would prejudice prevention or detection. Every decision should be justifiable.
ICO monitoring guidance para 1.19(b)Covert monitoring: tightly targeted and time-limited, never in toilets or changing rooms, and not of private communications official guidance, not lawCovert monitoring should be strictly targeted at obtaining evidence within the shortest possible set period and should stop when the investigation is complete; covert audio or video should not be used where workers can reasonably expect privacy, toilets and changing rooms among them, and in most cases covert monitoring should leave alone communications workers would reasonably treat as private, personal email for instance.
ICO monitoring guidance para 3.1Remote and home working: factor higher privacy expectations and family capture into the DPIA official guidance, not lawWhen monitoring remote workers, and especially those at home, the employer should remember that privacy expectations are higher at home and that family and private life is more easily captured by accident, and should build this risk into any monitoring through a DPIA.
ICO monitoring guidance para 3.3(a)Call monitoring: not all calls by default, itemised records first, workers told, personal calls not routinely monitored official guidance, not lawMonitoring or recording the content of all calls is not usually proportionate; business calls could be monitored for evidence of transactions or for training and quality, or where a regulator's rules require recording (limited to what the rules require). Itemised call records could meet a usage purpose and narrow any further monitoring, and any increase in call monitoring should trigger a DPIA review. Workers must be told of call monitoring in privacy information, and it should also appear in the handbook, codes and guidance; personal calls should not be routinely monitored, with a personal-calls policy workers know about, and a tolerated practice cannot be policed by a ban that is not applied.
ICO monitoring guidance para 4.1Biometric access and time control: document why biometrics are necessary and why alternatives are inadequate, in the DPIA official guidance, not lawBiometric identification carries far more sensitive information than cards and PINs and is harder to fix if inaccurate or breached, so the employer should consider alternatives, should document why it relies on biometrics and why less intrusive means are inadequate, should be able to justify not using a reasonable alternative, and must record all of this in the DPIA; extra security may be needed.
ICO monitoring guidance para 4.2Biometric access: a lawful basis and a special category condition, and a non-biometric alternative without disadvantage official guidance, not lawUsing biometrics to identify workers is special category processing, so a lawful basis and a condition are both needed and must be documented in the DPIA. The employer should offer an alternative such as swipe cards or PINs to those who do not want biometric access and should not disadvantage them; without an alternative, biometric access control is very hard to justify and consent is not appropriate, whereas with a genuine, penalty-free alternative consent and explicit consent become likely options.
ICO monitoring guidance para 4.3Biometric identification of workers always needs a DPIA before processing, discussed with workers official guidance, not lawThe employer must carry out and complete a DPIA before processing biometrics that single out an individual worker, because it is high risk; the process also lets it discuss the proposal with workers and their representatives beforehand.
ICO monitoring guidance para 1.11DPIA before high-risk monitoring, DPO advice recorded, workers informed before start, ICO consulted if high risk remains official guidance, not lawA DPIA must precede any processing that probably poses high risk to workers or others, such as biometric processing, keystroke monitoring, monitoring that may cause financial loss (performance management) or profiling to decide access to services; it should also consider customers, the public and household members captured. Where there is a DPO, the employer must seek and record the DPO's independent advice before deciding; if it goes ahead it must inform workers before monitoring begins; if high risk cannot be reduced it must consult the ICO first. The ICO expects a DPIA even without high risk, or a documented decision not to do one.
ICO monitoring guidance para 3.11(a)Device activity monitoring: document the justification, use less intrusive means if they work, identify a basis and condition, and do a DPIA official guidance, not lawDevice monitoring (web browsing, emails, documents, applications, screenshots, webcam captures, keystrokes) is likely to capture excessive information including special category data. The employer must be clear about its purpose and fully document its justification, including the less intrusive options considered, and must use a less intrusive way if one achieves the aim; it must identify a lawful basis and any special category condition; it must carry out a DPIA where high risk is likely and should do one anyway.
ICO monitoring guidance para 3.11(c)Device activity monitoring: webcam capture rarely justified, keystroke logging is behavioural biometric data, and private use of own devices kept out official guidance, not lawCapturing webcam shots or footage is particularly unlikely to be justified; keystroke monitoring counts as behavioural biometric data when typing rhythm can identify a worker. Barring personal use of company devices and blocking problem websites could reduce risk, but even then accessing personal communications is hard to justify, and when workers use their own devices for work the employer should make sure it does not capture their private use.
ICO monitoring guidance para 2.1Solely automated decisions with legal or similarly significant effects on workers: only on a ground the law lists, without disadvantaging those who ask for a human official guidance, not lawDecisions made by automated means with no meaningful human involvement that have legal or similarly significant effects on workers (pay changes from productivity data, dismissal) were, under the Article 22 the guidance describes, allowed only where necessary for a contract, authorised by law, or based on explicit consent, and workers who ask for a human to intervene must not end up worse off than those who accept the automated decision. A decision taken by a manager who reviewed tracking data and spoke to the worker is not solely automated. Law since the guidance: the Data (Use and Access) Act 2025, s 80, replaced UK GDPR Article 22 with Articles 22A to 22D (fully in force 5 February 2026): solely automated significant decisions are now restricted only where they rest on special category data (explicit consent, or contract or law plus Article 9(2)(g)) or on recognised legitimate interests, and in every case the controller must provide safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. The ICO flags this guidance as under review.
ICO monitoring guidance para 1.15Retention schedule for monitoring data, justified by business need and reviewed official guidance, not lawMonitoring information must not be kept longer than the purpose needs; the employer must have a retention schedule and delete in line with it, should base periods on business need, professional guidelines and legal duties, review them regularly, be able to justify them against the reasons for collection, and should not keep information in case a use turns up.
ICO monitoring guidance para 1.4(a)Choose the lawful basis for the specific purpose, document it from the start and do not switch later official guidance, not lawThe basis depends on the purpose and context; the employer must think about why it wants to monitor and pick the basis that best fits, must not use a one-size-fits-all approach, should identify and document every basis that applies from the outset, and should keep to it unless a good reason arises. A DPIA or the ICO's interactive tool can help.
ICO monitoring guidance para 1.4(b)Consent is rarely valid for monitoring at work; where used it must be withdrawable without detriment and recorded official guidance, not lawConsent must be freely given, which the power imbalance usually rules out, so it is not usually appropriate for employers; it works only where workers truly choose and control whether they are monitored. Where it is used it must be unambiguous with an affirmative act, and the employer must let workers withdraw without detriment as easily as they gave it, and record the date, method and exact scope of each consent.
ICO monitoring guidance para 1.4(d)Legitimate interests: pass the purpose, necessity and balancing tests, record a legitimate interests assessment, and respect reasonable expectations official guidance, not lawLegitimate interests is the most flexible basis, but the employer must weigh its interests, and how necessary the monitoring is, against what workers stand to lose in rights and freedoms in the particular case, and should run the purpose, necessity and balancing tests before starting and record the result in a legitimate interests assessment. It may not be appropriate where workers would not understand or reasonably expect the monitoring or would likely object if told; expectations vary with the job (a miner expects a tracker, an office worker does not).
ICO monitoring guidance para 1.7Check other laws beyond data protection before monitoring official guidance, not lawMonitoring must be lawful and fair overall, so the employer should consider laws outside data protection, including the Human Rights Act 1998, the Equality Act 2010 and section 75 of the Northern Ireland Act 1998, and the interception rules (SI 2018/356 on interception by businesses and their predecessor, the Telecommunications (Lawful Business Practice) Regulations 2000).
ICO monitoring guidance para 1.6Criminal offence data from monitoring needs official authority or a Schedule 1 condition official guidance, not lawInformation about offences, allegations, investigations or proceedings concerning workers may only be processed under official authority or where domestic law authorises it; monitoring to detect criminal activity needs a specific Schedule 1 DPA 2018 condition.
ICO monitoring guidance para 3.4(a)Email and message monitoring: a clear, necessary purpose, workers told, and a DPIA official guidance, not lawMonitoring emails and messages (including chat in collaboration tools) to protect information, for security, to spot suspicious activity or to enforce acceptable use requires a clear purpose, necessity and proportionality, and informing workers of the purpose; the employer must complete a DPIA because it is high risk and likely to capture special category data.
ICO monitoring guidance para 3.4(b)Email and message content only exceptionally, with a clear policy and advance notice; network data first official guidance, not lawContent monitoring is hard to justify where network traffic data would meet the purpose; the employer must notify workers in advance (in policy documents) if content may be monitored in exceptional circumstances and must not access content without a clear policy stating when that can happen. Before monitoring it should consider narrowing checks using network data (emails to rival firms, for instance), the duty of confidence to workers and customers, excluding lines such as union representatives, that even a ban on personal use does not justify reading personal messages (investigate breaches through network data first), letting workers mark messages personal, and the reliability of the records.
ICO monitoring guidance para 3.10Data loss prevention and traffic monitoring: least invasive means, a DPIA, and blocking with review as an alternative official guidance, not lawFor security tools such as firewalls and data loss prevention, the employer should choose the least invasive means and complete a DPIA; network traffic monitoring can be high risk, especially with inferences about workers, and blocking suspicious traffic or sending the worker to a portal to request a review could replace more detailed monitoring.
ICO monitoring guidance para 3.5(a)Video monitoring of workers: DPIA, targeted at risk areas with low privacy expectations, workers and others informed, footage redactable official guidance, not lawBefore using video monitoring the employer must complete a DPIA, consider why it is necessary, inform workers of its extent, nature and reasons, and make visitors, customers and others caught by it aware too; a DPIA is needed where special category capture is likely. Cameras should be aimed at particular risk areas where privacy expectations are low, continuous monitoring of workers is justified only rarely, covert use is unlikely to be justified, and footage may need redacting for subject access requests.
ICO monitoring guidance para 3.5(c)Facial recognition in worker monitoring: special category data, a lawful basis and condition, and a DPIA official guidance, not lawFacial recognition carries higher risks than ordinary video, especially when used to infer behaviour, emotion or intention, and raises accuracy concerns for ethnic minority groups; using it to identify workers is processing biometric special category data needing a lawful basis and a condition, and the employer must carry out a DPIA because it is high risk.