Those are two different questions, and organisations that only ask the first one tend to find out about the second from their own workforce.

Most monitoring proposals are assessed only against the left column. The right column is where the actual cost usually lands.
Employee monitoring covers a wide range: access logs, email and file activity, device management, productivity software, location tracking, video, and increasingly analysis of communications content. The technical capability is now broad and cheap, which is precisely why the governing questions matter more than they used to.
There are two of them and they are frequently collapsed into one. Is it lawful, and is it wise. An organisation can answer the first correctly and still cause itself serious damage.
The lawfulness test, in general terms
We are not going to summarise any jurisdiction's rules as though they applied everywhere, because they differ substantially and change. Take advice for the places you employ people. But the analysis in most data protection regimes runs along a common line.
A lawful basis. Consent is generally a weak basis in the employment context, because the imbalance of power makes it hard to argue it was freely given. Most monitoring therefore rests on a legitimate interest or a legal obligation, which brings its own balancing requirement.
Necessity. Is monitoring genuinely required for the stated purpose, or merely useful? A purpose defined broadly enough to justify anything will not survive scrutiny.
Proportionality. Is this the least intrusive means of achieving the purpose? Continuous monitoring of everyone to address a risk presented by a few is the classic failure.
Transparency. People must know what is monitored, why, and what happens to the data. Covert monitoring is exceptional and narrowly justified.
Assessment. Higher-risk processing usually requires a documented impact assessment before it starts.
Consultation. In several jurisdictions works councils or employee representatives must be consulted, and in some their agreement is required. This is a common and expensive oversight for organisations deploying globally from a single decision.
One additional point is worth flagging. Where monitoring output feeds a decision about an individual, such as performance management or termination, it may attract obligations relating to automated decision-making, and where a system used in worker management is classified as high risk under the European Union's AI Act it carries a documentation and oversight regime of its own. Those obligations were to apply from 2 August 2026. Regulation (EU) 2026/1744 defers them to 2 December 2027 and enters into force on 27 July 2026.
Monitoring for security is a different processing purpose from monitoring for productivity. Systems installed for the first and quietly used for the second are where most organisations create their exposure.
The prudence test, which nobody schedules
The second question is not legal and it is usually the one that determines the outcome.
What behaviour will this produce. Measurement changes what is measured. Activity monitoring produces activity. Keystroke and application metrics produce keystrokes and application switching. If the metric is a poor proxy for the work, the organisation will get the proxy at the expense of the work, and it will look like an improvement in the dashboard.
What does it signal. Monitoring communicates an assumption about the workforce. Introducing it broadly, particularly without a specific triggering problem, tells people what the organisation believes about them. That message is received accurately and it is difficult to withdraw.
Who has access, and what will they do with it. Data collected for one purpose becomes available for others. A manager who can see activity data will use it in performance conversations whether or not the policy contemplates that. Access design is the control, and it is usually an afterthought.
What happens the first time it is wrong. It will be wrong about somebody. A person with a disability, a carer with an unusual pattern, someone whose work is thinking rather than typing. The handling of that first case establishes what the system means, and it is worth deciding the handling before rather than during.
Can you ever switch it off. Monitoring is very hard to remove once installed, because removal reads as a loss of control. Deploy on the assumption it is permanent.
A workable approach
Start from a specific problem, not from a capability. Monitoring introduced because a tool was available is the hardest kind to defend.
Define the narrowest processing that addresses it, and write down what you decided not to do and why. That record is the proportionality argument.
Separate purposes explicitly. Security monitoring and productivity monitoring should be different systems, different access and different retention.
Tell people plainly, in advance, in language that does not require a lawyer. If the explanation is uncomfortable to write, that is information.
Restrict access by role and log the access itself.
Set retention short and enforce it. Data that no longer exists cannot be repurposed.
Review after six months against the original problem. If the problem is unchanged, the monitoring is not working and should stop.
The organisations that handle this well tend to share one habit. They can state, in a sentence, the specific problem the monitoring exists to solve, and they can point to the narrower options they rejected. Organisations that cannot do that are usually monitoring because they could.
This is reporting, not legal advice. Employment and data protection obligations differ significantly by jurisdiction and change frequently. Take qualified legal advice on your specific circumstances.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
European Union, Regulation (EU) 2016/679, the GDPR, including Article 22 and the data protection impact assessment requirement. https://eur-lex.europa.eu/eli/reg/2016/679/oj
European Union, Regulation (EU) 2024/1689, the AI Act, Annex III on worker management systems. https://artificialintelligenceact.eu/annex/3/
European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
Information Commissioner's Office, Guide to PECR, under review following the Data (Use and Access) Act 2025, page dated 20 August 2025. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/
Government of India, The Digital Personal Data Protection Act, 2023. https://www.meity.gov.in/data-protection-framework
How we work. This article was researched and written by the HR Hubs Media editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@hrhubsmedia.com and tell us what and why.
Filed under Compliance & Workplace Law · Get The Weekly Brief
