There is a persistent belief among UK employers that leaving the EU made monitoring easier. It didn't. UK GDPR retained the substance of the regime, the Data Protection Act 2018 sits alongside it, and the Information Commissioner's Office has been more specific about workplace monitoring than most EU regulators have.
The ICO published its final guidance on monitoring workers in October 2023. It is worth reading in full if this is your decision to make, but if you want the short version: the regulator is not asking whether you can monitor. It assumes you can. It is asking whether what you have deployed is necessary and proportionate to a purpose you can actually name — and whether the people being monitored would have expected it.
Those two things decide almost every case.
The question the ICO actually asks
Most compliance write-ups present monitoring as a checklist with a pass mark. That is not how a complaint plays out. What gets tested is narrower and more awkward:
You said the purpose was X. Does the thing you deployed serve X? Could you have served X with less? Did the workers know?
A concrete version. If your stated purpose is "understanding capacity so we know whether to hire", then activity and app metadata serve that purpose. Screen recording does not serve it any better — it just collects more. That gap between what you needed and what you took is exactly the space a proportionality assessment lives in, and it is where poorly-specified deployments fall over.
So the first piece of work is not choosing a tool. It is writing down, in one sentence, the decision you intend to make with the data. If you cannot write that sentence, nothing downstream will hold up.
Reasonable expectations, and why they move
UK GDPR requires you to consider what workers would reasonably expect. This is not the same as what you told them — it is a broader test that takes account of context.
Some things are within most people's expectations in 2026: that a company laptop is company property, that access to systems is logged, that a security team can investigate an incident. Other things are not: that a webcam might be sampled, that keystrokes are captured, that an algorithm produces a score used in a performance conversation nobody mentioned.
The line moves with context. The same tool can be within expectations on a trading floor handling regulated communications and well outside them in a marketing team. And it moves with how you introduced it — the same collection announced in advance with a policy sits very differently from the same collection discovered by an employee reading a release note.
Transparency is not a paragraph in the handbook
The ICO expects workers to be told clearly what is being monitored, why, and what happens to the data. In practice, employers get this wrong in two recognisable ways.
The first is burial: a monitoring clause inside a twelve-page acceptable use policy, signed on day one, never mentioned again. Technically disclosed. Not meaningfully transparent.
The second is vagueness — "we may monitor use of company systems" — which covers everything and therefore communicates nothing. If it would cover both an access log and a screen recorder, it is not doing the job the guidance asks of it.
What works is boring and specific: a short document naming the categories of data collected, who can see them, how long they are kept, and what the data will not be used for. Our monitoring policy template is written to that shape, and the rollout checklist covers sequencing.
Purpose creep is the most common failure
This is the one that catches otherwise careful employers. You deploy monitoring for security. Eighteen months later a manager asks whether the same data can settle a dispute about who was working late. It can, technically. That is not the question.
Using data collected for one stated purpose to serve a materially different one requires you to go back to the beginning: new purpose, new assessment, new notice. The ICO is explicit that monitoring methods should not simply be repurposed. The practical control is to write the excluded uses into the policy at deployment, because once the data exists the pressure to use it only ever increases.
Covert monitoring: exceptional, not discretionary
Covert monitoring — surveillance workers are not told about — is treated as exceptional. The realistic scenario is a specific suspicion of serious wrongdoing where telling people would defeat the investigation, authorised at senior level, narrowly scoped, time-limited, and documented at each step.
It is not a management style. If covert monitoring runs for months, covers a whole team, or has no defined end condition, it is not the exceptional case the guidance contemplates, whatever it was called internally when it was approved.
Home working raises the bar
Monitoring someone in their home is not the same act as monitoring them in an office, and UK law does not treat it as such. A worker's home engages their private and family life directly, which means it carries greater weight when you weigh business need against individual rights.
The practical consequences for a distributed UK team:
- Anything that captures the environment rather than the work — camera, ambient audio, continuous screen capture — is very difficult to justify for productivity purposes.
- Working-hours data needs care. Knowing when someone is active is reasonable; treating deviation from 9-to-5 as a performance signal in a role sold as flexible is not.
- Household members are not your data subjects, and any collection that can incidentally capture them needs a specific answer.
Our work-from-home monitoring guide covers the operational side; the wider EU/UK checklist covers lawful basis and DPIA mechanics in more depth.
What this means for what you buy
UK law does not name approved products, but it does make some architectures much easier to defend than others. Read the requirements backwards and the buying criteria are fairly clear:
Prefer metadata to content. Activity and application data answers capacity and workflow questions perfectly well; screen content, keystrokes and recordings answer them no better while raising the assessment bar sharply. Prefer tools that aggregate by default too — if the dashboard answers a team question without anyone opening an individual's record, minimisation is a property of the design rather than a promise in a policy.
Then there are the three questions you will actually be asked if a complaint arrives. How long do you keep it? "Indefinitely, it's in the vendor's cloud" is not an answer, so retention needs to be something you control. Can a worker see their own data? Subject access is far easier when the answer is yes, and a tool built so they can is usually a tool built without a hidden layer. And can you demonstrate that the invasive features are off, rather than assert it? Being able to show a setting is what an assessment needs; being able to describe one is not.
Where ProdView fits
ProdView measures activity and application metadata — focus time, meeting load, capacity, working patterns — and never captures screen content or keystrokes. Screenshots are optional and off by default. Employees see the same dashboard their manager does, which makes both the transparency requirement and subject access considerably simpler. Retention is configurable, SOC 2 Type II, one agent across Windows, macOS and Linux.
When not to pick us: you have a genuine regulatory mandate for session recording or DLP — FCA-regulated communications capture, for example. That is a legitimate purpose, and a UAM tool is the honest answer for the seats it applies to. Do not buy it for the whole company because one team needs it.
Try before you commit
Three seats are free forever, which is enough to run the DPIA against a real deployment rather than a datasheet. Model the payback with the ROI calculator while you are at it.
General information about UK data protection law as of August 2026, not legal advice. The ICO's guidance on monitoring workers is the primary source and worth reading directly before you deploy.