
Workplace Monitoring Policies - Employer Guide to the ICO Rules
Employee monitoring has expanded rapidly since the shift to hybrid and remote working. Tools that log keystrokes, capture screenshots, score productivity and scan faces at the door are now cheap and simple to deploy. The law that governs them is strict, and getting it wrong carries regulatory and employment risk.
The Information Commissioner's Office (ICO) published its guidance, Employment practices and data protection: monitoring workers, on 3 October 2023. It applies to anyone who performs work for your organisation, including gig workers and contractors, and it covers monitoring at home as well as on your premises.
The rules moved again when the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D from 5 February 2026, changing how automated decision-making rules apply to AI-driven monitoring.
This guide sets out what a lawful monitoring policy looks like, from lawful basis and data protection impact assessment (DPIA) through worker notification and proportionality to the rules for AI tools and covert monitoring.
Primary sources: the ICO's employment practices guidance on monitoring workers, the ICO's DPIA guidance, and section 80 of the Data (Use and Access) Act 2025 on legislation.gov.uk.
Why This Matters
Almost every employer monitors workers in some form, whether through CCTV, email security filters, door access logs or call recording. Each involves processing personal data, so UK GDPR obligations apply in full and monitoring must be lawful, fair, transparent and proportionate.
Hybrid and remote working raises the stakes. The ICO states that workers' expectations of privacy are significantly higher at home, and monitoring a home worker risks capturing family life, private correspondence and household members. Remote monitoring therefore needs a stronger justification than the same tool in an office.
The regulator has already acted, ordering Serco Leisure in February 2024 to stop using facial recognition and fingerprint scanning to monitor worker attendance.
1. What Counts as Workplace Monitoring
The ICO defines monitoring workers as any form of monitoring of people who carry out work on your behalf. That includes monitoring on work premises or elsewhere, during or outside working hours, whether systematic or occasional.
The guidance lists examples that go well beyond CCTV: webcams and screenshots, keystroke logging, productivity tools that record how workers spend their time, internet and email tracking, timekeeping and access control systems, body-worn location devices and audio recording.
Two points catch employers out. Homeworking is not private household activity, so monitoring remote staff is fully covered. And keystroke monitoring can amount to behavioural biometric data where a worker is identifiable from their typing pattern, pushing it into special category territory.
2. The Lawful Basis Question
Before any monitoring starts you must identify and document a lawful basis under Article 6 of the UK GDPR. Of the six available bases, most workplace monitoring rests on legitimate interests, which requires a three-part test: a legitimate purpose, necessity, and a balancing exercise against workers' rights and freedoms.
Consent is rarely valid in employment; the ICO is explicit that the imbalance of power means workers seldom have a genuine free choice. Contract is also hard to rely on, since a surveillance clause in the employment contract does not make monitoring necessary. Legal obligation works where a statute requires the monitoring, such as tachographs recording drivers' hours.
If monitoring is likely to capture special category data, you also need an Article 9 condition before you start. Email monitoring is the classic example: scanning all traffic will foreseeably pick up messages to trade union representatives or occupational health, even if that was never the aim, and the ICO expects a condition to cover that incidental capture.
3. DPIAs and When One Is Required
A DPIA is mandatory before any processing likely to result in high risk to workers or others. The ICO's monitoring guidance lists examples that cover most modern tools: biometric data, keystroke monitoring, and monitoring that may lead to financial loss such as performance management. It also states that you must complete a DPIA before monitoring emails and messages.
A proper DPIA describes the processing, assesses necessity and proportionality, identifies risks to workers and anyone else captured (customers, household members of remote staff), and sets out mitigations. You should seek the views of workers or their representatives, or document why you did not, and record your data protection officer's independent advice if you have one.
If the DPIA leaves a high risk you cannot reduce, you must consult the ICO before going ahead. Even where a DPIA is not strictly required, the ICO says you should do one anyway, or document the decision not to.
4. Transparency and Worker Notification
Workers have the right to be informed. Except in the exceptional covert cases discussed below, you must tell workers what monitoring is taking place, why, what information is collected, how it is used and who sees it. The information must be accessible and easy to understand.
The practical vehicle is a monitoring policy plus updated privacy information. The ICO expects the policy to set out the nature, purpose and extent of monitoring, and expects employers to bring it to workers' attention regularly rather than once at induction. When you change what you monitor, you must tell workers before the change takes effect.
Expectations are set by practice as well as policy. The guidance gives the example of an employer whose policy bans personal calls but who tolerates them in practice; that employer cannot rely on the written ban to justify monitoring.
5. Proportionality and Less Intrusive Alternatives
Proportionality runs through the whole guidance. You must be clear about your purpose and select the least intrusive means of achieving it. Just because a monitoring product is available does not mean using it is lawful.
In the ICO's own example, an employer worried about timesheet accuracy rolled out webcam monitoring so managers could check staff were at their desks. The ICO says this is likely to infringe data protection law, because checking system log-on times achieves the same purpose with far less intrusion.
The same logic applies tool by tool: itemised call records instead of recorded call content, network traffic data instead of email content, blocking problematic websites instead of monitoring browsing, and aggregated team reports instead of individual productivity scores. The guidance also states that employers are particularly unlikely to be able to justify capturing webcam shots or footage of workers.
6. AI-Driven Monitoring and Automated Decisions
Many monitoring products now include AI that profiles workers, infers performance or wellbeing, and flags people for action. Where a tool makes decisions with legal or similarly significant effects, such as pay adjustments based on productivity scores or dismissal triggers, automated decision-making rules apply.
Under the framework in force since 5 February 2026, solely automated significant decisions are generally permitted, but only if safeguards under new Article 22C are in place: workers must be given information about the decision, be able to make representations, obtain human intervention and contest the outcome. Tighter restrictions remain where the decision is based on special category data, where you still need explicit consent or a specific legal footing.
Human involvement must be meaningful to take a decision outside these rules. The ICO warns against token oversight: a manager who routinely rubber-stamps whatever the system recommends does not count. Reviewers need the authority, competence and information to disagree with the tool, and you must not disadvantage workers who ask for human intervention.
7. Covert Monitoring
Covert monitoring means monitoring designed so workers do not know it is happening. The ICO says it is unlikely to be justified in normal circumstances. The exception is narrow: grounds for suspecting criminal activity or equivalent gross misconduct, where telling workers would prejudice its prevention or detection.
Even then, strict conditions apply. Senior management must authorise it, a DPIA is mandatory, and the monitoring must be targeted, time-limited and stopped once the investigation ends. Covert audio or video must not be used in areas where workers reasonably expect privacy, such as toilets or changing rooms, and personal communications remain largely off limits.
Information gathered covertly can only be used for the intended purpose; incidental findings should normally be disregarded and destroyed. Workers retain their data protection rights, including subject access.
Lawful Monitoring at a Glance
| Requirement | What it means | Evidence |
|---|---|---|
| Lawful basis | An Article 6 basis identified before monitoring starts; consent rarely valid at work | Documented basis, legitimate interests assessment where relied on |
| Special category condition | An Article 9 condition where monitoring may capture health, union or biometric data | Documented condition, appropriate policy document where required |
| DPIA | Mandatory before high-risk monitoring (biometrics, keystrokes, email content, performance tools) | Completed DPIA with DPO advice and worker consultation recorded |
| Transparency | Workers told what is monitored, why, and how information is used, before it starts | Monitoring policy, updated privacy notice, communication records |
| Proportionality | Least intrusive method that achieves the stated purpose | DPIA section comparing alternatives considered and rejected |
| ADM safeguards | Information, representations, human intervention and a route to contest automated decisions | Documented Article 22C safeguards and human review procedure |
What Employers Must Do
- Audit your current monitoring. List every tool that observes workers, including built-in functions of collaboration platforms, security software, CCTV, vehicle trackers and access systems, recording the purpose, the data collected and who sees it.
- Run DPIAs on anything high risk. Biometric attendance, keystroke or screenshot tools, email content monitoring and productivity analytics all need one before use. Consult workers or their representatives as part of the assessment.
- Write or update your monitoring policy. Set out the nature, purpose and extent of each type of monitoring, the rules it enforces, retention periods and who has access. Make sure practice matches the policy.
- Tell workers before monitoring starts. Update privacy information, brief staff in plain language, and notify them again whenever the scope of monitoring changes.
- Review your AI and analytics tools. Identify any solely automated decisions with significant effects, put Article 22C safeguards in place, and make human review genuinely meaningful rather than a rubber stamp.
- Set a review cycle. Check regularly for function creep, delete data in line with your retention schedule, and revisit DPIAs when tools or purposes change.
Common Errors to Avoid
- Relying on employee consent. The ICO treats consent as invalid where workers cannot realistically refuse, which is most employment situations, so monitoring built on consent alone usually has no lawful basis at all.
- Treating a contract clause as authorisation. A contract clause saying staff may be monitored does not make monitoring necessary or proportionate, and excessive monitoring does not become lawful because it was written down.
- Monitoring content when traffic data would do. Reading emails or messages where network data, log-on times or itemised records would achieve the purpose fails the proportionality test and risks capturing special category data unlawfully.
- Deploying biometrics with no alternative. Requiring face or fingerprint scans to clock in, with no fallback such as a card or PIN, was exactly what led to the Serco Leisure enforcement notices in February 2024.
- Assuming the vendor handled compliance. You are the controller; the ICO is clear that buying a commercial monitoring tool does not transfer responsibility or make the product compliant out of the box.
- Keeping monitoring data indefinitely. Holding recordings, logs and screenshots just in case breaches the storage limitation principle and inflates the impact of any future breach.
Enforcement and What Happens When Monitoring Goes Wrong
The ICO can issue assessment notices, enforcement notices and fines of up to 17.5 million pounds or 4 per cent of annual worldwide turnover, whichever is higher. The Serco Leisure enforcement action of 23 February 2024 applied those powers to workplace monitoring directly: Serco and seven leisure trusts had to stop processing biometric attendance data and destroy what they held, because less intrusive options such as fobs existed and staff had no real choice.
Employment tribunals are the second front. Evidence obtained through unlawful or unfair monitoring can be challenged in disciplinary proceedings and litigation, and heavy-handed surveillance can breach the implied term of trust and confidence, supporting constructive dismissal claims. Public sector employers also face arguments under the Human Rights Act 1998, which gives effect to the Article 8 right to respect for private life and correspondence.
How Policy Pros Can Help
Policy Pros writes monitoring policies that stand up to ICO scrutiny. We draft the full framework: the monitoring policy itself, the DPIA documentation behind it, and the data protection policies that anchor your lawful basis, retention and access rules. Everything is written for your actual tools and working patterns rather than copied from a template.
If your monitoring involves analytics, productivity scoring or automated flags, our AI governance policies cover the automated decision-making safeguards the Data (Use and Access) Act 2025 now requires, including human review procedures your managers can actually follow. For distributed teams, our remote and hybrid working policies address the higher privacy expectations that apply when staff work from home.
Monitoring and data security are closely linked, so you may also find our employee data breaches in hybrid working guide useful reading. Get in touch and we will scope what your organisation needs.
Frequently Asked Questions
Is employee monitoring legal in the UK?
Yes, but only within data protection law. The ICO's October 2023 guidance confirms employers can monitor workers if they identify a lawful basis, act proportionately, tell workers what is happening and complete a DPIA where the monitoring is high risk. Monitoring that is excessive, secret without justification, or done without a lawful basis is unlawful.
Can my employer monitor my emails in the UK?
Employers can monitor work email accounts for defined purposes such as security, but the ICO expects them to complete a DPIA first, tell staff in advance and prefer less intrusive checks such as network traffic data over reading content. Blanket reading of email content is very hard to justify, partly because it risks capturing sensitive messages to union representatives or occupational health.
Do employers have to tell you they are monitoring you?
Almost always, yes. Workers have the right to be informed, so employers must explain what is monitored, why, and how the information is used before monitoring starts. Covert monitoring is only permitted in exceptional cases, such as investigating suspected crime or gross misconduct, and even then it must be authorised by senior management, time-limited and supported by a DPIA.
Can my employer watch me through my webcam when I work from home?
Almost certainly not lawfully. The ICO says privacy expectations are significantly higher at home and that employers are particularly unlikely to be able to justify capturing webcam images or footage. Its guidance gives webcam checking of home workers as an example of disproportionate monitoring where log-on data would achieve the same purpose.
Can employers use fingerprint or facial recognition scanners to clock staff in?
Only with a strong justification, a DPIA and a genuine alternative for staff who object, because biometric data used for identification is special category data. In February 2024 the ICO ordered Serco Leisure to stop using facial recognition and fingerprint scanning for attendance because less intrusive options like fobs existed and workers had no real choice.