Employee Monitoring Law Planner
Sources

Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018

Law. Placed at UK locations. Read 30 Sep 2026; 3 provisions cited by the planner.

UK interception regulations reg 3(1)(a)Interception effected by, or with the express consent of, the system controller

The interception must be of a communication while it is being transmitted over a telecommunication system, and it must be carried out by the system controller (the person entitled to control the system's operation or use) or with that person's express consent. A vendor, outsourced call centre or IT provider that monitors on the business's behalf needs the controller's explicit authority; implied acquiescence is not enough for this route. Regulation 3(1)(b) and (c) add that the conduct must also fit a purpose in paragraphs (2) to (4) and satisfy regulation 4.

What a reviewer asks to see: written authorisation from the system controller naming the monitoring or recording tool, the channels covered and the provider operating it; contract or statement of work with any monitoring vendor that records it acts on the controller's express instruction; register of telecommunication systems (telephony, email, collaboration, network) showing who holds the right to control each
Where monitoring plans usually fall short: monitoring switched on by a vendor or a team without any recorded decision by the system controller; a customer or parent company runs interception on a system it does not control; the controller of a shared or hosted platform is never identified, so express consent cannot be shown
Source: Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, read 30 Sep 2026
UK interception regulations reg 3(2)(c)Purpose: to ascertain or demonstrate standards achieved or to be achieved by users in the course of their duties

Monitoring or recording is authorised to find out or show the standards that people reach, or should reach, when they use the system for their work, which covers quality assurance and training on business calls, emails and messages. It does not extend to communications that are not made in the course of duties.

What a reviewer asks to see: quality monitoring procedure defining the standards assessed, sampling method and who reviews; training and coaching records referencing the sampled communications; scorecards or QA forms linked to the recordings reviewed
Where monitoring plans usually fall short: personal communications swept into quality sampling; standards never written down, so the purpose cannot be shown; QA sampling extended into continuous surveillance of every communication
Source: Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, read 30 Sep 2026
UK interception regulations reg 4(1)(c)All reasonable efforts to inform every user that communications may be intercepted

The system controller must have made all reasonable efforts to tell each person who might use the system that communications carried on it can be intercepted. This covers workers and anyone else who may use the system (contractors, visitors on guest networks); the Regulations do not require the consent of the other party to a call or message, but the users of the controller's own system must be told. Informing external callers is a separate data protection transparency duty.

What a reviewer asks to see: monitoring notice in the employee handbook, acceptable use policy and system log-on banners; acknowledgement records or intranet publication history showing when users were told; notices for non-employee users such as contractors and guest network users; recorded announcement or script where external parties use the controller's system
Where monitoring plans usually fall short: notice given to employees but not to contractors, agency staff or guest users; notice buried in a contract signed years before the monitoring started; new monitoring channel introduced with no updated notice; no record showing when and how users were informed
Source: Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list