An employee monitoring policy tells staff exactly what you collect, why, who sees it, and how long you keep it. It's the document that turns monitoring from something done to people into something done openly — and in most jurisdictions, giving notice before monitoring begins is a legal requirement, not a courtesy.
Below is a template you can copy and adapt. It's deliberately written in plain language, because a policy nobody reads provides very little of the protection it's meant to.
The template
Replace everything in [square brackets]. Delete any section that doesn't apply — an accurate short policy beats a comprehensive inaccurate one.
1. Purpose and scope
[Company name] uses workplace analytics software to [state the specific purpose — e.g. understand team capacity and workload, improve how we plan work, and meet our security obligations]. This policy explains what we collect, why, and what your rights are.
This policy applies to [all employees / specified teams] using [company-owned devices only / company-owned devices and approved BYOD devices]. It takes effect on [date] and is reviewed [annually].
2. What we collect
We collect:
- [Application and website usage — which applications and sites are active, and for how long]
- [Active and idle time during working hours]
- [Aggregate focus time and meeting load]
- [Device and login metadata — device name, operating system, login times]
3. What we do not collect
We do not collect:
- [The content of your screen — no screenshots or screen recording]
- [Keystrokes or anything you type]
- [Personal messages, email content, or content of documents]
- [Camera, microphone or location data]
- [Any activity outside configured working hours, or on personal devices]
[Adjust honestly. If you do take screenshots, say so plainly, state the frequency, and say who can view them. An inaccurate policy is worse than none.]
4. When monitoring is active
Monitoring runs [during configured working hours only — e.g. 09:00–18:00, Monday to Friday, in your local time zone]. It does not run [on weekends, public holidays, or approved leave]. You can [pause monitoring / see monitoring status] at any time via [method].
5. Why we collect it — legal basis
Our purpose is [specific purpose from section 1]. We rely on [legitimate interests / consent / legal obligation] as our lawful basis. We have assessed that this monitoring is proportionate: we collect the minimum data needed for the purpose, and we have considered less intrusive alternatives. [Where required: a Data Protection Impact Assessment was completed on [date] and is available on request.]
6. Who can see your data
- You can see all of your own data at any time via [tool/dashboard].
- [Your manager / team lead] can see [team-level aggregates / your individual data].
- [IT and security] can see [scope] for [purpose].
- No one else has access. Access is logged.
7. How long we keep it
We retain monitoring data for [e.g. 90 days], after which it is permanently deleted. [Aggregated, anonymised statistics may be retained longer for trend analysis.]
8. What we will not use it for
We will not use monitoring data:
- As a direct input to performance reviews, pay or promotion decisions
- To discipline employees for individual activity levels
- To rank or compare employees against one another
- For any purpose not stated in this policy, without updating it and telling you first
9. Your rights
You can:
- Access all data we hold about you, at any time
- Request an explanation of any metric
- Request correction of inaccurate data
- Raise a concern or objection with [named person / role] at [contact]
- [Request deletion, subject to our legal obligations]
10. Changes to this policy
We will notify all affected employees at least [14 days] before any change takes effect.
Acknowledgement: I confirm I have read and understood this policy. Name: ______________ Signature: ______________ Date: __________
How to roll it out
The document matters less than how you introduce it.
- Share it before you deploy anything. Discovering monitoring after installation is the single fastest way to lose trust, and no policy repairs that.
- Hold a session, not an email. Let people ask questions and record the answers. The questions you get will improve the policy.
- Lead with the problem. "We need to know whether to hire or fix our meeting load" is a reason. "Visibility" is not.
- Give everyone their own dashboard on day one. Section 6 is the part employees care about most — make it real immediately.
- Honour section 8 visibly. The first time monitoring data is used in a performance conversation after you promised it wouldn't be, the policy becomes worthless.
Choosing tooling that matches the policy
Sections 2 and 3 are much easier to write honestly if your tool collects less to begin with. A metadata-only tool lets you write "we do not capture your screen" as a statement of fact about the product rather than a configuration you must maintain. See ethical employee monitoring for the principles, and the buyer's guide for the collection models.
Where ProdView fits
ProdView is built so that the restrictive version of this policy is simply true: activity and app metadata only, no keystroke logging, no OCR, no screen recording, screenshots optional and off by default, configurable working hours, and every employee sees the same dashboard their manager does. SOC 2 Type II, native Windows, macOS and Linux, free for 3 seats.
When not to pick us: you have a compliance mandate requiring session recording or DLP — in which case sections 2 and 3 will look different, and your policy needs to say so honestly.
Try before you commit
Draft the policy first, then choose tooling that lets you keep it. Three seats are free forever — start there, or model the payback with the ROI calculator.
This template is general information and not legal advice. Have counsel review before use.