We’ve updated our Subprocessor List, effective September 17, 2026. Please review the update to our Data Processing Addendum

Compliance

GDPR Compliance in Employee Monitoring Software DPIA & Lawful Bases Guide (2026 Review)

GDPR Compliance in Employee Monitoring Software DPIA & Lawful Bases Guide (2026 Review)
Tony Lynn
Chief Operating Officer of CurrentWare
Updated on 5 min read
Share this article

When using employee computer monitoring software across the European Union (EU), companies have to find a balance between two legitimate, yet conflicting, aims: the safeguarding of corporate networks, know-how and confidential data on the one hand, and the preservation of employees’ privacy and fundamental rights on the other.

That balance has become increasingly crucial as an ever larger share of business activity has moved to laptops, cloud applications, virtual desktops and corporate networks with hybrid and remote work. While monitoring tools may offer helpful security and operational insights, more granular telemetry collection doesn’t necessarily make it legal.

Under the General Data Protection Regulation (GDPR), employee monitoring shall be designed based on lawfulness, fairness, transparency, purpose limitation, data minimisation, storage limitation, security, and accountability. European countries’ legislation may require certain other aspects of employee monitoring, such as consultation or co-determination of employee representatives. The outcome is a very different approach to workforce monitoring than unselective surveillance. The question to ask is not, “how much can we record?” but, “What minimum information do we need to collect to meet a narrowly defined business objective?”

This blueprint describes how enterprise IT, security, HR, legal, and Data Protection teams can build an employee-monitoring program that is based on legal grounds, proportionality, DPIAs, transparency, technical controls, and engaging with Works Councils.

What Is GDPR-Compliant Employee Monitoring?

GDPR compliant employee monitoring refers to the regulated collection and use of employee, endpoint, application, network or security telemetry where the processing is based on a valid legal basis and fulfils the GDPR criteria of necessity, proportionality, transparency, minimization, security and accountability.

Employee monitoring may involve minimal intrusion data including:

  • Application usage
  • Website or domain activity
  • Logon and logoff events
  • Network or bandwidth utilization
  • Security events
  • Access attempts
  • Removable-media activity
  • Device and endpoint status
  • Aggregated workforce trends
  • Software utilization

Collecting information from a company-owned device is also not automatically removed from the sphere of data protection law. Any information about an identifiable worker may be considered to be personal data.

This difference between security telemetry and behavioural surveillance is therefore significant.

For instance, there may be a clear information security benefit in catching that an endpoint sent a restricted file to a USB device. Recording each keystroke over the course of a workday is far more intrusive, because it can log passwords, private IM messages, financial info, access codes, and other unintended content.

In a press release of July 9, 2026, the French Data Protection Agency (CNIL) clarified the regulations applicable when an employer is proposing to monitor the activities of its employees. In the course of a number of fines imposed in 2025 for failure to use monitoring tools, the CNIL felt it necessary to recall that any monitoring of the activity of employees must be relevant and proportional.

For example, other than for some professional applications, video surveillance, GPS, and certain IT monitoring tools may be used, but some tools are considered unreasonable in nature, such as the use of software like a “Keylogger” for homeworkers. The CNIL also emphasized that the Works Council must be consulted and each employee informed before the implementation of such a tool.

Lawful Bases to Monitor Computer Use Under GDPR

Before deploying employee monitoring software, an organization should identify the precise processing activities involved and determine the appropriate lawful basis under GDPR Article 6. There is no universal “employee monitoring” lawful basis. Different activities may rely on different legal grounds depending on the purpose, national employment legislation, regulatory obligations, and circumstances.

Commonly considered bases include:

1. Legitimate Interests: Article 6(1)(f):

The organization must demonstrate why the processing is necessary and why employee rights and interests do not override the organization’s legitimate interest. Legitimate interests can be relevant where an organization has a genuine and clearly defined interest, such as:

  • Protecting confidential information
  • Detecting cyber threats
  • Preventing unauthorized access
  • Investigating security incidents
  • Protecting IT infrastructure
  • Managing certain operational risks
  • Preventing misuse of corporate systems

2. Legal Obligation: Article 6(1)(c)

Certain monitoring activities may be connected to a legal obligation imposed on the employer. This requires an actual legal requirement rather than a general business preference. Organizations should identify the specific EU or national legal provision supporting the processing.

Some types of monitoring can be tied to a legal obligation imposed on the employer. This must be a legal requirement, not simply something like the organisation’s general business decision. The organisation should identify the relevant EU or national legal provision.

3. Contractual Necessity: Article 6(1)(b)

Contractual necessity is even more limited than organizations tend to think. It should not be invoked just because a term on monitoring has been included somewhere in the employment contract, or because it would make things easier for management. It must actually be necessary to perform the employment contract.

4. Employment-Specific National Law

GDPR Article 88 permits EU Member States to establish more specific rules concerning employee data processing in an employment context. This is why an organization operating in Germany, France, Austria, the Netherlands, or another EU jurisdiction cannot rely solely on a generic pan-European GDPR policy.

Why Employee Consent Often Fails

Consent is one of the most common concepts misinterpreted when it comes to employee surveillance. Consent for GDPR must be given freely, be specific, informed and unambiguous. If you have a relationship where one person has power over the other employer/employee, it can be difficult to show that there will be no negative consequences if they refuse.

A stronger compliance strategy is to identify the appropriate lawful basis independently of employee consent and then provide employees with the required privacy information.

A monitoring notice should explain:

  • What information is collected
  • Why it is collected
  • The lawful basis
  • Who can access it
  • How long it is retained
  • Whether it is shared with third parties
  • Whether international transfers occur
  • How employees can exercise their rights
  • Whether automated decision-making is involved
  • How complaints can be raised

The Primary Defensible Basis: Legitimate Interests

Where legitimate interests are being considered, organizations should document a Legitimate Interest Assessment (LIA). A practical LIA can be organized around three questions.

1. Purpose Test: Is There a Genuine Legitimate Interest?

The organization should define the objective precisely.

Weak purpose: “We want to know what employees are doing.”

Stronger purpose: “We need to identify unauthorized transfers of confidential files from managed endpoints to removable storage devices.”

The second statement identifies a specific security objective that can be tested against necessity and proportionality.

Potential legitimate interests may include:

  • Cybersecurity
  • Protection of trade secrets
  • Prevention of unauthorized data transfers
  • Security incident investigation
  • Protection of regulated information
  • Network protection
  • Business continuity

2. Necessity Test: Is Monitoring Actually Necessary?

The organization should investigate whether the same objective can be achieved using less intrusive methods.

Objective: Reduce unauthorized USB data transfers.

Potential controls could include:

  1. USB device allowlisting
  2. File-type restrictions
  3. DLP alerts
  4. Access controls
  5. Security-event logging
  6. Targeted investigation
  7. Continuous recording of every employee action

3. Balancing Test: Do Employee Rights Override the Interest?

The final assessment considers the impact on employees. The higher the intrusion, the stronger the justification and safeguards need to be.

Relevant factors include:

  • Sensitivity of the data
  • Frequency of monitoring
  • Whether monitoring is continuous
  • Whether employees are informed
  • Whether monitoring occurs outside working hours
  • Whether personal use is permitted
  • Whether individual-level profiling occurs
  • Whether data is used for disciplinary decisions
  • Whether the employee reasonably expects the processing
  • Whether less intrusive alternatives exist

Proportionality Red Lines: Keylogging & Continuous Video

Some monitoring mechanisms create significantly greater privacy risks than others. Here are some striking red lines giving clarity on safeguarding employee privacy:

1. Keystroke Logging

Keyloggers can capture every character typed by an employee. Depending on configuration, this can expose:

  • Passwords
  • Authentication credentials
  • Personal communications
  • Financial information
  • Private searches
  • Confidential business information
  • Security tokens

The German Federal Labour Court (case 2 AZR 681/16) defined in its judgment that software, which monitored ‘every keystroke on the keyboard and made a screenshot’ of the computer, could not be justified in the present case. There was no specific, employee-related suspicion of a serious breach of obligation that would justify the monitoring of the data in such an intensive manner. The Court also viewed the continuous monitoring of keystrokes as one of the most intensive possible interference with information self-determination.

Organizations considering alternatives to keylogging can also examine CurrentWare’s discussion of the security and privacy risks associated with capturing individual keystrokes.

2. Continuous Screen Recording

Screen recording is an equal intrusion since screens are often filled with other personal or sensitive information. A specific screenshot taken as part of a narrowly scoped security investigation is not the same thing as having a machine capture your desktop every three seconds as you go through your workday.

3. Continuous productivity scoring

A system that assigns a second-by-second “productivity score” can create another proportionality problem.

A notable example of this regulatory action can be seen in the CNIL’s case against Amazon France Logistique. In December 2023, the regulator issued a EUR 32m fine related to employee monitoring measures targeting use of warehouse scanners. The CNIL found that some indicators amounted to too much surveillance, and storing all of the data it gathered was excessive since some of the same purposes could be achieved by using a summary.

Structuring the Data Protection Impact Assessment (DPIA) and Legitimate Interest Assessment

A DPIA should be viewed more as an engineering and governance document than a legal form that is completed after the fact. Where processing is likely to result in a high risk to an individual’s rights and freedoms, Article 35 GDPR states that a DPIA should be conducted. Systematic monitoring is likely to be a high-risk activity.

A robust DPIA should contain at least the following sections:

1. Describe the Processing

Document:

  • Devices monitored
  • Users included
  • Data categories
  • Collection frequency
  • Processing locations
  • Storage systems
  • Administrators with access
  • Third-party processors
  • Data retention periods
  • International transfers
  • Integration with HR or security systems

Collected:

  • Domain-level web activity
  • Application names
  • Logon/logoff timestamps
  • Security events

Excluded:

  • Keystroke content
  • Ambient audio
  • Webcam feeds
  • Biometric data
  • Private communications

2. Identify the Purpose

Each data category should map to a defined purpose. Avoid vague purposes such as “employee productivity” where the actual use could encompass multiple unrelated activities.

Data Potential purpose
Application name Software governance
Domain activity Security and acceptable-use enforcement
Logon/logoff Access auditing
USB events Data-loss prevention
Bandwidth usage Network security and capacity planning
Screenshot Narrowly defined security investigation

3. Evaluate Necessity and Proportionality

For every telemetry type, ask:

  • Is it necessary?
  • Can the objective be achieved with less data?
  • Can the data be aggregated?
  • Can collection be restricted to work hours?
  • Can monitoring be limited to specific systems?
  • Can identifiers be pseudonymized?
  • Can individual-level data be avoided until a security event occurs?

4. Identify Risks

The DPIA should assess risks such as:

  • Unauthorized access
  • Excessive employee profiling
  • Insider misuse of monitoring records
  • Secondary use
  • Function creep
  • Excessive retention
  • Re-identification
  • International transfers
  • Disciplinary misuse
  • Security compromise of monitoring databases

5. Document Mitigations

Possible controls include:

  • Role-based access control
  • Multi-factor authentication
  • Encryption
  • Pseudonymization
  • Data aggregation
  • Automated deletion
  • Restricted administrator access
  • Audit logs
  • Segregation of HR and security data
  • Working-hours collection
  • Privacy notices
  • Periodic necessity reviews

Retention also needs to be purpose-oriented. A general rule of retaining everything employees do forever is unmanageable with storage constraints. A company could have varying retention periods for security alerts, summarized report details, investigation data and daily activity telemetry instead of a single duration.

Works Council and Employee-Representative Approval

In certain European countries, employee representatives may have consultation, information or co-determination rights related to technology in the workplace.Germany provides one of the clearest examples.

Under Section 87(1) No. 6 of the German Works Constitution Act, the Works Council has co-determination rights concerning the introduction and use of technical devices designed to monitor employee behavior.

However, do not assume Germany is the blueprint for all EU countries. Works Council structures and employee-representation obligations vary per jurisdiction. Legal teams should create country matrices in advance of the EDP roll-out for one Europe-wide monitoring policy.

Depending on the negotiated framework, the agreement may restrict or prohibit:

  • Continuous screen surveillance
  • Ambient audio
  • Webcam monitoring
  • Keylogging
  • Monitoring outside working hours
  • Individual productivity scoring

Workplace Transparency: Empirical Research Insights

Legal compliance and employee acceptance are closely linked.
Harvard Business Review has explored studies showing that covert employee monitoring erodes trust and can lead to unintended negative consequences. A 2022 HBR article looked at the research on employee monitoring and rule-breaking behavior, but past HBR advice for companies to do nothing more than inform employees of monitoring programs and their objectives.

The practical implication is that an employee-monitoring program should answer three questions clearly:

Why are we monitoring?
Explain the business or security problem.

What are we monitoring?
Identify the categories of data collected.

How will the information be used?
Explain access, retention, investigation, and disciplinary boundaries.

Privacy by Design: Build the Controls Into the Architecture

Privacy should not depend exclusively on an administrator remembering to change a setting. A privacy-by-design architecture should make excessive monitoring difficult. Useful architectural controls include:

  • Data minimization: Collect only the fields necessary for the documented purpose.
  • Collection scheduling: Restrict monitoring to working hours where appropriate.
  • Granularity controls: Prefer domain-level or application-level information when exact URLs or content are unnecessary.
  • Role-based access: Separate permissions for security, IT, HR, and management.
  • Automated retention: Automatically delete information after the approved retention period.
  • Audit logging: Record who accessed monitoring information and what actions they performed.
  • Segmentation: Keep employee monitoring databases separated from unrelated HR systems where practical.
  • Incident-triggered escalation: Use lower-intrusion telemetry as the baseline and reserve highly intrusive investigative techniques for narrowly defined, legally justified circumstances.

Where CurrentWare Can Fit Into a Privacy-First Monitoring Architecture

CurrentWare offers employee activity, application, network, and endpoint-control tools that can be part of a larger GDPR governance initiative. The GDPR documentation available today covers what can be monitored, minimization, access, retention, and organizational measures. It also states explicitly that it is not GDPR compliant to install the software alone and then assume it is, the lawful basis, configuration, transparency, governance framework, and laws of jurisdiction still need to be managed.

For organizations wanting even less intrusion into the workforce, CurrentWare’s BrowseReporter provides application and web-usage data, active/idle data, logon/logoff data, bandwidth data, and associated reporting. The existing product documentation describes the privacy settings and configurable options for tracking.

For endpoint protection and removable-media governance, CurrentWare’s AccessPatrol offers device and file transfer controls for your USB devices, file permissions and device permissions, and audit reporting of device and file activity.

Conclusion: Move From Surveillance to Defensible Workforce Intelligence

GDPR compliant employee monitoring is not about removing organizational awareness. It is about the balance and defensible construct between business purpose, what is collected, legal grounds, employee rights and technical safeguards. The most effective architecture starts with the purpose and not the monitoring tool.

  • If the objective is cybersecurity, collect security-relevant telemetry.
  • If the objective is software optimization, collect application-use information.
  • If the objective is data-loss prevention, monitor relevant transfer events.
  • If the objective can be achieved using aggregated information, avoid unnecessary individual-level surveillance.

And if a monitoring technique results in a behavioral fingerprint, organizations should anticipate a much sharper focus on necessity, proportionality, transparency, and legal basis.

Frequently asked

Frequently Asked Questions:

Employee monitoring software does not log keystrokes, but tracks metadata (website domain names, application names, telemetry from network traffic, etc.) So how can an employer monitor employee computer usage without logging keystrokes? Solutions such as BrowseReporter from CurrentWare allow you to monitor employee computer activity, time working versus being idle, and what applications are being used without tracking keystrokes and risking a costly GDPR tax penalty.

GDPR compliant employee monitoring software is designed explicitly with Data Protection by Design and by Default (GDPR Article 25) to minimize collecting an excessive amount of personally identifiable information (PII).

Privacy-compliant software ensures GDPR compliance with on-premises server installations, placing telemetry inside the enterprise firewall, fine-grained role-based access control (RBAC) with the four-eyes principle and efficient triggers avoiding recording desktop screens all the time.

GDPR compliant employee monitoring software is fully reliable based on the Legitimate Interests (Article 6(1)(f)) legal ground and is subject to a formal DPIA before implementation. With the purpose of the monitoring not to micro-surveil or data-mine employee performance, GDPR compliant monitoring tools must limit data collection (Article 5(1)(c)), as they offer aggregated, audit-proof reports for IT security and software metering.

Privacy-respecting employee monitoring software emphasizes on corporate cybersecurity and endpoint protection rather than seeking to conduct secret, blanket employee surveillance in the workplace.

Compliant with typical behavioral sciences, the monitoring software employs visible desktop operation modes where the desktop can be seen through clear desktop notifications and live client indicators in strict compliance with EU collective bargaining and Works Council agreements.

Still have questions?

Talk to a CurrentWare specialist who has deployed monitoring at 200+ law firms.

Keep reading

More articles
Start Free Trial Book a Demo
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Privacy Policy