Employee Monitoring Law Planner
Sources

Article 29 Working Party Opinion on data processing at work (WP249) 2/2017

Official guidance, not law. Placed at EU and EEA locations. Read 30 Sep 2026; 17 provisions cited by the planner.

WP249 para 3.1.2Tell workers that monitoring exists, why, and what else fairness requires official guidance, not law

Workers must be told that monitoring exists, the purposes for which their data will be processed and any other information needed for fair processing; covert-capable technology makes this more pressing. Section 6.3 adds that communication should be effective and cover the circumstances of monitoring and how workers can prevent their data being captured, and that monitoring policies and rules should be clear and readily accessible.

What a reviewer asks to see: worker privacy notice section describing each monitoring activity, purpose and circumstances; monitoring policy published on the intranet with version history; guidance to workers on how to keep private use out of monitoring
Where monitoring plans usually fall short: notice mentions 'IT monitoring' without saying what or why; policy stored where workers cannot find it; no explanation of how to avoid capture of private use
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(b)Tell drivers a tracker is fitted and that movements, and possibly driving behaviour, are recorded; notice in the vehicle official guidance, not law

The employer must clearly tell employees that a tracking device is installed in the company vehicle they drive, that their movements are recorded while they use it and, depending on the technology, that their driving behaviour may be recorded too; ideally this notice is shown clearly inside each vehicle where the driver can see it.

What a reviewer asks to see: in-vehicle notice sticker or display placed in the driver's line of sight; vehicle policy and driver acknowledgement; fleet register confirming notices fitted in every vehicle
Where monitoring plans usually fall short: notice only in the fleet policy, none in the vehicle; driving behaviour recorded without telling drivers; pool and hire vehicles missing notices
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(d)Limits on monitoring: places, data and time official guidance, not law

To keep the balance under legitimate interest, the employer should put limits on monitoring suited to its form: geographical limits (monitoring only in specific places, and never in sensitive areas such as places of worship, sanitary facilities and break rooms), data limits (no monitoring of personal electronic files and communications) and time limits (sampling rather than continuous monitoring).

What a reviewer asks to see: camera and sensor placement plan excluding toilets, changing, rest and worship areas; technical exclusion of personal folders and communications from monitoring; sampling schedule showing monitoring is periodic, not continuous
Where monitoring plans usually fall short: cameras covering break rooms or washroom entrances; monitoring that reads personal files; always-on monitoring where sampling would do
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(c)No location monitoring outside agreed working hours, save a proportionate theft safeguard official guidance, not law

Given how sensitive location data is, a lawful basis for following where employees' vehicles are beyond agreed working hours will rarely exist. If there is a real need, such as theft prevention, the implementation should be proportionate: no location registered outside hours unless the vehicle leaves a broadly defined region, and location revealed only on a break-glass basis when it does.

What a reviewer asks to see: telematics schedule suppressing location outside working hours; geofence and break-glass configuration with access logs; record of any out-of-hours location access and its reason
Where monitoring plans usually fall short: 24-hour tracking of vehicles taken home; managers able to view weekend locations; no log of break-glass access
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.6Video monitoring: no video analytics of expressions or movements, no facial recognition official guidance, not law

Video analytics that read workers' facial expressions automatically or flag deviations from set movement patterns are disproportionate to employees' rights and generally unlawful, and are likely to involve profiling and automated decisions; employers should refrain from facial recognition technology, and marginal exceptions cannot justify its general use. Under the GDPR, biometric identification also needs an Article 9(2) exception.

What a reviewer asks to see: CCTV system specification showing analytics and facial recognition disabled; DPIA for any video analytics considered; Article 9(2) exception record if biometric identification is used
Where monitoring plans usually fall short: emotion or attention analytics on staff cameras; facial recognition for staff monitoring; movement-pattern alerts on production lines
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.2.2Data protection impact assessment for high-risk monitoring and prior consultation if residual risk stays high official guidance, not law

Where monitoring, particularly with new technology, probably carries high risk, such as systematic and extensive automated evaluation with significant effects, the employer must assess its impact on data protection (a DPIA), and if the residual risk remains high it must consult the supervisory authority before starting. EDPB Opinion 12/2018 later confirmed that employee monitoring can meet the vulnerable data subjects and systematic monitoring criteria for a DPIA.

What a reviewer asks to see: DPIA for each high-risk monitoring activity, dated before deployment; residual risk decision and, where high, the prior consultation file; DPO advice recorded on the DPIA
Where monitoring plans usually fall short: DPIA completed after go-live; residual high risk accepted without consulting the authority; a single generic DPIA covering unrelated monitoring tools
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1(b)Proportionality and subsidiarity, whatever the legal ground, tested before monitoring starts official guidance, not law

Whatever legal ground is used, the employer should apply proportionality and subsidiarity and should run a proportionality test before processing begins: whether the processing is needed for a legitimate purpose, whether it is fair, proportionate to the concern and transparent, and which measures keep any intrusion into private life and the secrecy of communications to the minimum. The test can sit inside a data protection impact assessment, and section 6.2 repeats it for every monitoring tool before deployment.

What a reviewer asks to see: documented proportionality test per monitoring tool, dated before go-live; record of less intrusive alternatives considered and why rejected; sign-off by the accountable manager and DPO where one exists
Where monitoring plans usually fall short: proportionality assessed only after a complaint; no alternatives considered; assessment copied from the vendor's marketing material
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.4.1Home and remote working: no keystroke, mouse, screen or webcam capture official guidance, not law

Software that logs keystrokes and mouse movements, captures screens at random or set intervals, logs applications used and for how long, or switches on webcams to collect footage is disproportionate, and a legitimate interest ground for it will very rarely exist, recording keystrokes and mouse movements being the Opinion's example. The risks of remote working should be met proportionately, whatever the technology, especially where business and private use blur.

What a reviewer asks to see: remote-working security design relying on access controls and endpoint protection rather than activity capture; inventory confirming no keystroke, screenshot or webcam capture features are enabled; proportionality record for any remote monitoring used
Where monitoring plans usually fall short: bossware with screenshots and keystroke logging on home devices; webcam capture to verify presence; activity analytics switched on by default in a collaboration suite
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1(d)Accurate data kept no longer than needed, with a set retention period official guidance, not law

Employers should keep monitoring data accurate and retain it only as long as necessary; section 6.4 adds that data from monitoring should be stored for the shortest time needed, under a specified retention period, and deleted once no longer needed.

What a reviewer asks to see: retention schedule with a period for each monitoring data set; automated deletion configuration or purge logs; accuracy checks on monitoring outputs used in decisions
Where monitoring plans usually fall short: logs retained indefinitely by default; retention period set but never enforced; inaccurate monitoring outputs relied on without checks
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.4.2(a)Bring your own device: separate private from business use and keep out of private areas official guidance, not law

Where employees use their own devices, the employer must have measures to tell private from business use so that private information is not monitored; security scanning tools can reach all data on a device and must be carefully managed, and parts of the device presumed private (such as the photo folder) should in principle stay closed to the employer. Tracking where a personal device is and what traffic it carries may be unlawful if it captures private and family life. Section 6.1 adds that employees should be able to shield private communications from work monitoring.

What a reviewer asks to see: BYOD policy defining work and private partitions; mobile security configuration limited to the work container; record that private areas are excluded from scans and location tracking
Where monitoring plans usually fall short: full-device scans on personal phones; location of personal devices tracked; no container or partition separating work data
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 6.1Owning the equipment does not remove employees' secrecy of communications; location tracking only where strictly necessary official guidance, not law

Electronic communications from work premises, their content and traffic data, may fall within private life and correspondence under Article 8 of the European Convention on Human Rights and deserve the same protection as analogue communications. Employer ownership of the devices does not take away employees' right to confidentiality of their communications, correspondence and the location data tied to them, and tracking employees' location through their own or company devices should go no further than a legitimate purpose strictly requires.

What a reviewer asks to see: legal assessment of monitoring against Article 8 ECHR and the secrecy of communications; location tracking justification per device class; policy stating that personal communications on company devices remain protected
Where monitoring plans usually fall short: policy asserting that company ownership removes any expectation of privacy; location tracking enabled fleet-wide by default; no Article 8 analysis
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(a)Consent is not the legal ground for most processing at work; default settings are not consent official guidance, not law

For most processing at work the employer cannot and should not rely on workers' consent, because the relationship makes refusal costly and consent must be freely given, specific, informed and revocable; where a real or possible prejudice follows from refusing, the consent is invalid. Even where consent could be free, pre-set device settings or installing monitoring software do not amount to consent, which requires an active expression of will. Section 6.2 limits free consent to exceptional cases where acceptance or refusal carries no consequence at all.

What a reviewer asks to see: legal basis record per monitoring purpose naming a ground other than consent, or evidence that refusal has no consequence; withdrawal mechanism where consent is genuinely used; configuration evidence that no monitoring relies on default device settings as agreement
Where monitoring plans usually fall short: consent clause in the employment contract used as the basis for monitoring; tick-box acceptance at log-on treated as consent; no alternative for workers who refuse
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 3.1.1(c)Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance official guidance, not law

An employer relying on legitimate interest must show that the purpose is legitimate, that the chosen method or technology is necessary for it and proportionate to the business need, and that it runs in the least intrusive way, aimed at the specific area of risk. It must be able to show the measures that balance its interest against workers' rights, and the worker keeps the right to object on compelling legitimate grounds. Section 6.2 adds that this ground works only where the processing is strictly needed.

What a reviewer asks to see: legitimate interests assessment per monitoring purpose (purpose, necessity, balancing); record of the mitigating measures adopted; objection handling procedure and log
Where monitoring plans usually fall short: assessment that names the interest but never tests necessity; no mitigating measures recorded; objections refused without balancing
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.2(a)No generalised screening of employees' social media during employment official guidance, not law

Employers should not screen employees' social media profiles on a generalised basis. Targeted observation may be lawful under legitimate interest only where it is shown to be necessary (the Opinion's example is checking former employees' professional profiles during a non-compete period), no less invasive means exist, and those concerned have been told how far the observation goes.

What a reviewer asks to see: policy prohibiting routine social media screening of staff; case record for any targeted observation with necessity reasoning; notice to the individuals observed
Where monitoring plans usually fall short: brand-monitoring tools configured to track named employees; screening of all staff profiles; targeted observation without notice
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.3(f)Data loss prevention: transparent rules and a warning before an email is blocked official guidance, not law

Deploying a data loss prevention tool on outgoing email must be fully justified to balance the employer's interest with employees' rights, because false positives expose legitimate and personal messages. The rules the system uses to flag an email should be fully transparent to users, and when an email is flagged the sender should be warned before it is sent, with the option to cancel.

What a reviewer asks to see: DLP justification record; published description of DLP rule categories; configuration showing sender warning and cancel option before transmission
Where monitoring plans usually fall short: silent DLP holds with investigators reading flagged mail; rules undisclosed to staff; no false-positive handling procedure
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.5Time and attendance and access control: informed, necessary, and not reused for performance evaluation official guidance, not law

Access and attendance systems, including those using biometrics or device tracking, can give an invasive view of workers' activity. A system recording who enters a secure area can rest on legitimate interest if necessary and if workers are adequately informed, but constantly watching how often and exactly when each worker enters and leaves cannot be justified once the same records serve a second purpose such as appraising performance.

What a reviewer asks to see: access control purpose statement and worker notice; report and access configuration preventing attendance data reaching performance reviews; biometric condition record where biometrics are used
Where monitoring plans usually fall short: badge data used to rank punctuality in appraisals; biometric clocks with no Article 9 condition; workers not told what access logs record
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026
WP249 para 5.7(a)Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers official guidance, not law

Telematics collect data about the driver as well as the vehicle. Even with a legitimate interest or legal duty, the employer should first assess necessity, proportionality and subsidiarity. If a work vehicle may also be used privately, the key safeguard is letting the employee switch off location tracking temporarily when circumstances justify it (a doctor's visit, for example). The data must not be reused illegitimately, for example to follow and assess staff: vehicle trackers are for vehicles, not staff (Opinion 13/2011).

What a reviewer asks to see: telematics necessity and proportionality assessment; privacy switch configuration and driver instructions; rule barring use of telematics for driver performance ranking
Where monitoring plans usually fall short: speed alerts used for disciplinary scoring; no privacy switch on vehicles allowed for private use; telematics reports routinely reviewed by line managers
Source: Article 29 Working Party Opinion on data processing at work (WP249) 2/2017 (official guidance, not law), read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list