Compliance

GDPR-compliant employee monitoring: a practical checklist

What European data protection law expects from workplace monitoring — lawful basis, proportionality, transparency, DPIAs, retention and data subject rights.

Monicrew Team 9 min read

Monitoring employees in Europe is lawful. Doing it without preparation is not. This is a working checklist of what regulators consistently expect, aimed at the person who has to configure the tool and write the policy.

It is general guidance rather than legal advice. Requirements vary by member state, and works council rules in particular can be stricter than the GDPR baseline.

Consent rarely works in an employment relationship, because regulators do not accept it as freely given when one party controls the other’s income. If refusing monitoring is career-limiting, the consent is not valid.

Most employers rely on legitimate interests, and some on contractual necessity or legal obligation for specific narrow cases. Legitimate interests requires you to document a balancing test: your interest, why monitoring is necessary to serve it, and why it does not override the employee’s rights.

2. Apply proportionality seriously

This is where most deployments fail. The question is not "may we monitor?" but "is this specific monitoring the least intrusive way to achieve a legitimate aim?"

  • Continuous screenshots to verify attendance is disproportionate — login records answer it
  • Full URL histories to bill clients is disproportionate — project time entries answer it
  • Keystroke logging is almost never proportionate outside narrowly defined high-risk roles
  • Monitoring personal devices or outside working hours is very difficult to justify

Being able to disable modules per team is not just a convenience feature here. It is how you evidence that you applied only the monitoring each role actually needed.

3. Be genuinely transparent

Employees must be told before monitoring starts, in clear language. Burying it in an employment contract annexe does not satisfy this. Your notice should state:

  • Exactly what is collected, and what is not
  • Why, and the lawful basis relied on
  • Who can access it internally, and any processors involved
  • How long it is retained
  • How to exercise access, correction, objection and erasure rights
  • Whether it feeds into any automated decision-making

4. Run a DPIA

Systematic monitoring of employees is explicitly listed as high-risk processing by most supervisory authorities, so a Data Protection Impact Assessment is generally required. Do it before deployment — a DPIA written afterwards to justify a live system defeats its purpose and looks exactly like what it is.

It should cover the processing description, necessity and proportionality assessment, risks to individuals, and the mitigations you applied.

5. Consult, where consultation is required

In Germany, the Netherlands, France and elsewhere, works councils or employee representatives have consultation or co-determination rights over monitoring systems. Deploying first and consulting later can invalidate the whole deployment. Check the requirement in every country you employ people in, not just where the company is registered.

6. Set retention periods and enforce them

Storage limitation is a principle, not a suggestion. Decide what you need and for how long, then configure automatic deletion:

  • Screenshots — typically 30 days or less, if collected at all
  • Activity and application data — commonly 90 days for operational use
  • Timesheets and attendance — often longer, driven by payroll and tax obligations

Different categories can and usually should have different periods.

7. Be ready for data subject requests

Employees can request access to their monitoring data, and they do — most often during a grievance or exit process. You need to be able to export one person’s data within a month, and to explain how any productivity score about them was derived.

If you cannot explain to an employee how their productivity score was calculated, you have an Article 15 problem as well as a management problem.

8. Get the processor relationship right

Your monitoring vendor is a processor acting on your instructions. You need a Data Processing Agreement covering security measures, sub-processors, international transfers, breach notification and deletion on termination. If your vendor cannot produce one, that is your answer about them.

9. Keep humans in consequential decisions

Article 22 restricts decisions with legal or similarly significant effects made solely by automated processing. Do not let a productivity score trigger disciplinary action on its own. A human must review the underlying data and be able to reach a different conclusion.

A short pre-launch checklist

  • Lawful basis documented, with a legitimate interests balancing test if relied on
  • DPIA completed and signed off before rollout
  • Employee notice published and acknowledged
  • Works council consulted where applicable
  • Only the necessary modules enabled, per role
  • Retention periods configured and automated
  • DPA signed with the vendor
  • A tested process for handling access requests
  • Human review required before any consequential decision

Monicrew supports this posture directly: modules are opt-in per team, retention is configurable, productivity scores drill down to their source data, employees can see their own records, and a Data Processing Agreement is available to every customer.

Get started

See where the working day actually goes

Start a full-featured trial, invite your team, and get your first real report inside a week. No card required to begin.

  • Free trial on every plan
  • Cancel any time
  • 24/7 human support