Employee monitoring laws in Belgium
Yes, and Belgium is unusual in having a dedicated collective agreement on the subject: CBA No. 81 sets out exactly which purposes justify monitoring electronic communications data and how the workforce must be told.
Who has to agree before you start
The fact that decides the timeline, and the one that differs most between countries.
The workforce must be consulted first
CBA No. 81 requires collective information to the works council — or, in its absence, the committee for prevention and protection at work, the union delegation, or the employees directly — before monitoring starts, followed by individual information about what is monitored and why.
Representatives must be informed and consulted, or negotiated with, before the decision is taken. They cannot block it, but doing it in the wrong order is itself the breach — and in France skipping it is a criminal offence independent of any data-protection issue.
GDPR and the Belgian Data Protection Act, plus collective bargaining agreement No. 81 of 26 April 2002 on monitoring electronic online communications data, which is binding across the private sector.
The law that applies in Belgium
Named so you can check us, and so your own counsel has somewhere to start.
| Instrument | What it requires |
|---|---|
| CBA No. 81 (26 April 2002) | Permits monitoring of electronic online communications data only for defined purposes — preventing unlawful or defamatory acts, protecting confidential economic interests, security and proper technical functioning of IT systems, and compliance with agreed usage rules — and subjects it to finality, proportionality and transparency. |
| CBA No. 81 arts. 7–9 | Prescribes the escalation: monitoring at aggregate level first, and individualisation of the data only through a defined procedure, with prior individual notice for the less serious categories of breach. |
| GDPR Arts. 6(1)(f), 13 and 35 | Legitimate interests is the practical lawful basis, with transparency obligations and a DPIA expected for systematic monitoring. |
How a rollout is done here
- Map the purpose onto one of the four CBA No. 81 grounds. If it does not fit one, the monitoring is not permitted on that basis.
- Inform the works council collectively before monitoring begins, covering the policy, the purposes, whether data is retained and for how long.
- Inform employees individually about what is monitored and why.
- Design for aggregate-first monitoring, and reserve individualisation for the defined procedure rather than as the default view.
- Record the DPIA and the legitimate-interests balancing test, and update the processing register.
What gets a rollout refused
- Going straight to individual-level monitoring. CBA No. 81's aggregate-first structure is its defining feature, and inverting it is the usual Belgian failure.
- Monitoring for a purpose outside the four permitted grounds — general performance measurement is not among them.
- Skipping the collective information step and relying on the individual notice alone.
- Reading content rather than traffic data. CBA No. 81 addresses communications data; reading the content of employee communications engages the separate and much stricter secrecy-of-communications rules.
Monitoring staff in Belgium — questions
Does CBA No. 81 apply to time-tracking software?
It applies directly to monitoring of electronic online communications data. Its principles — finality, proportionality, transparency and aggregate-first individualisation — are treated in Belgian practice as the template for workplace monitoring generally, so a rollout designed against them is on much firmer ground than one that treats the agreement as out of scope.
What if we have no works council?
CBA No. 81 provides a cascade: the committee for prevention and protection at work, then the union delegation, then the employees directly. The collective information step does not disappear; the audience for it changes.
Can monitoring data be used in a dismissal?
Only where the monitoring itself complied with CBA No. 81 and with the GDPR, including the individualisation procedure. Data gathered outside that framework is what Belgian employers most often find they cannot rely on at the point they need it.
Sources and scope
Primary source: Belgium regulator and statute references, last read 2026-09-17.
This page is a plain-English summary of published law and regulator guidance, not legal advice, and it is not a substitute for advice on your own facts. Employment and data protection law changes; each page states the date its sources were last read. Before monitoring staff anywhere, take advice from qualified counsel in that country.
See where the hours actually went
Free for up to three people. Windows and macOS. No keystroke content on any plan, and screenshots off unless an administrator turns them on.