ComplianceLegalPrivacyEmployee monitoring

Employee Monitoring and UK Law: What the ICO Expects

Brexit didn't loosen the rules. What UK GDPR and the ICO expect, and the test that decides whether your monitoring survives a complaint.

There is a persistent belief among UK employers that leaving the EU made monitoring easier. It didn't. UK GDPR retained the substance of the regime, the Data Protection Act 2018 sits alongside it, and the Information Commissioner's Office has been more specific about workplace monitoring than most EU regulators have.

The ICO published its final guidance on monitoring workers in October 2023. It is worth reading in full if this is your decision to make, but if you want the short version: the regulator is not asking whether you can monitor. It assumes you can. It is asking whether what you have deployed is necessary and proportionate to a purpose you can actually name — and whether the people being monitored would have expected it.

Those two things decide almost every case.

The question the ICO actually asks

Most compliance write-ups present monitoring as a checklist with a pass mark. That is not how a complaint plays out. What gets tested is narrower and more awkward:

You said the purpose was X. Does the thing you deployed serve X? Could you have served X with less? Did the workers know?

A concrete version. If your stated purpose is "understanding capacity so we know whether to hire", then activity and app metadata serve that purpose. Screen recording does not serve it any better — it just collects more. That gap between what you needed and what you took is exactly the space a proportionality assessment lives in, and it is where poorly-specified deployments fall over.

So the first piece of work is not choosing a tool. It is writing down, in one sentence, the decision you intend to make with the data. If you cannot write that sentence, nothing downstream will hold up.

Reasonable expectations, and why they move

UK GDPR requires you to consider what workers would reasonably expect. This is not the same as what you told them — it is a broader test that takes account of context.

Some things are within most people's expectations in 2026: that a company laptop is company property, that access to systems is logged, that a security team can investigate an incident. Other things are not: that a webcam might be sampled, that keystrokes are captured, that an algorithm produces a score used in a performance conversation nobody mentioned.

The line moves with context. The same tool can be within expectations on a trading floor handling regulated communications and well outside them in a marketing team. And it moves with how you introduced it — the same collection announced in advance with a policy sits very differently from the same collection discovered by an employee reading a release note.

Transparency is not a paragraph in the handbook

The ICO expects workers to be told clearly what is being monitored, why, and what happens to the data. In practice, employers get this wrong in two recognisable ways.

The first is burial: a monitoring clause inside a twelve-page acceptable use policy, signed on day one, never mentioned again. Technically disclosed. Not meaningfully transparent.

The second is vagueness — "we may monitor use of company systems" — which covers everything and therefore communicates nothing. If it would cover both an access log and a screen recorder, it is not doing the job the guidance asks of it.

What works is boring and specific: a short document naming the categories of data collected, who can see them, how long they are kept, and what the data will not be used for. Our monitoring policy template is written to that shape, and the rollout checklist covers sequencing.

Purpose creep is the most common failure

This is the one that catches otherwise careful employers. You deploy monitoring for security. Eighteen months later a manager asks whether the same data can settle a dispute about who was working late. It can, technically. That is not the question.

Using data collected for one stated purpose to serve a materially different one requires you to go back to the beginning: new purpose, new assessment, new notice. The ICO is explicit that monitoring methods should not simply be repurposed. The practical control is to write the excluded uses into the policy at deployment, because once the data exists the pressure to use it only ever increases.

Covert monitoring: exceptional, not discretionary

Covert monitoring — surveillance workers are not told about — is treated as exceptional. The realistic scenario is a specific suspicion of serious wrongdoing where telling people would defeat the investigation, authorised at senior level, narrowly scoped, time-limited, and documented at each step.

It is not a management style. If covert monitoring runs for months, covers a whole team, or has no defined end condition, it is not the exceptional case the guidance contemplates, whatever it was called internally when it was approved.

Home working raises the bar

Monitoring someone in their home is not the same act as monitoring them in an office, and UK law does not treat it as such. A worker's home engages their private and family life directly, which means it carries greater weight when you weigh business need against individual rights.

The practical consequences for a distributed UK team:

  • Anything that captures the environment rather than the work — camera, ambient audio, continuous screen capture — is very difficult to justify for productivity purposes.
  • Working-hours data needs care. Knowing when someone is active is reasonable; treating deviation from 9-to-5 as a performance signal in a role sold as flexible is not.
  • Household members are not your data subjects, and any collection that can incidentally capture them needs a specific answer.

Our work-from-home monitoring guide covers the operational side; the wider EU/UK checklist covers lawful basis and DPIA mechanics in more depth.

What this means for what you buy

UK law does not name approved products, but it does make some architectures much easier to defend than others. Read the requirements backwards and the buying criteria are fairly clear:

Prefer metadata to content. Activity and application data answers capacity and workflow questions perfectly well; screen content, keystrokes and recordings answer them no better while raising the assessment bar sharply. Prefer tools that aggregate by default too — if the dashboard answers a team question without anyone opening an individual's record, minimisation is a property of the design rather than a promise in a policy.

Then there are the three questions you will actually be asked if a complaint arrives. How long do you keep it? "Indefinitely, it's in the vendor's cloud" is not an answer, so retention needs to be something you control. Can a worker see their own data? Subject access is far easier when the answer is yes, and a tool built so they can is usually a tool built without a hidden layer. And can you demonstrate that the invasive features are off, rather than assert it? Being able to show a setting is what an assessment needs; being able to describe one is not.

Where ProdView fits

ProdView measures activity and application metadata — focus time, meeting load, capacity, working patterns — and never captures screen content or keystrokes. Screenshots are optional and off by default. Employees see the same dashboard their manager does, which makes both the transparency requirement and subject access considerably simpler. Retention is configurable, SOC 2 Type II, one agent across Windows, macOS and Linux.

When not to pick us: you have a genuine regulatory mandate for session recording or DLP — FCA-regulated communications capture, for example. That is a legitimate purpose, and a UAM tool is the honest answer for the seats it applies to. Do not buy it for the whole company because one team needs it.

Try before you commit

Three seats are free forever, which is enough to run the DPIA against a real deployment rather than a datasheet. Model the payback with the ROI calculator while you are at it.

General information about UK data protection law as of August 2026, not legal advice. The ICO's guidance on monitoring workers is the primary source and worth reading directly before you deploy.

P
ProdView Team

The ProdView team builds privacy-first workforce analytics for engineering managers. We write about measuring productivity without surveillance, the laws that govern monitoring, and how the best teams run their week.

Frequently asked questions

Is employee monitoring legal in the UK?
Yes, and it is common. But it is regulated processing under UK GDPR and the Data Protection Act 2018, which means you need a lawful basis, a documented necessity and proportionality assessment, transparency with workers, and in most cases a DPIA. Legality is not the interesting question — proportionality is, because that is where complaints are actually decided.
What does the ICO say about monitoring workers?
The ICO published final guidance on monitoring workers in October 2023. Its central themes are that monitoring must be necessary and proportionate to a specified purpose, that workers must be told about it clearly, that it must not be excessive, and that you have to consider workers' reasonable expectations rather than only your own business rationale.
Do I need a DPIA to monitor employees in the UK?
In most cases yes. Systematic monitoring of workers is treated as likely-high-risk processing, and the heavier the collection — screen recording, keystrokes, continuous capture — the more clearly a DPIA is required. Doing one properly also tends to reduce what you deploy, which is usually a good outcome.
Can UK employers monitor staff working from home?
They can, but the bar is higher. Monitoring in a worker's home engages their private and family life more directly than monitoring at a workplace does, so it carries greater weight in the proportionality assessment. Continuous capture of a home environment is very hard to justify.
Does an employee have to consent to being monitored?
Consent is rarely the right basis in employment because the power imbalance means it cannot be freely given. Most UK employers rely on legitimate interests, which requires a documented balancing test, or on legal obligation for specific regulated purposes.
Related reading

Make the policy easy to keep

ProdView collects activity metadata only — no screen content, no keystrokes — so the restrictive version of your monitoring policy is simply true about the product, not a setting you have to maintain.

Get the policy templateStart free — 3 seats