United Kingdom

Employee monitoring laws in United Kingdom

Yes, and the UK is among the more straightforward jurisdictions in Europe: there is no works council consent to obtain, but the ICO expects a lawful basis, a DPIA for systematic monitoring, and genuine transparency with workers.

Who has to agree before you start

The fact that decides the timeline, and the one that differs most between countries.

Staff must be told, in a prescribed way

There is no statutory works council consent requirement. The ICO nonetheless expects employers to consult workers and, where they exist, their representatives when assessing the impact of monitoring — and treats a DPIA carried out without seeking workers' views as weaker for it.

No representative body has to agree, but the notice has a required form and timing — Poland's two weeks, New York's written notice on hiring, the ICO's expectation of genuine transparency. These rollouts move fastest, and the notice is the thing most often got wrong.

UK GDPR and the Data Protection Act 2018, interpreted through the ICO's employment practices guidance on monitoring workers.

The law that applies in United Kingdom

Named so you can check us, and so your own counsel has somewhere to start.

Instruments governing employee monitoring in United Kingdom
InstrumentWhat it requires
UK GDPR Art. 6(1)(f)Legitimate interests is the usual lawful basis for monitoring workers, requiring a documented three-part assessment of purpose, necessity and balance. The ICO's position is that consent will rarely be valid in an employment relationship.
UK GDPR Art. 35 and DPA 2018A data protection impact assessment is required for systematic monitoring; the ICO lists monitoring of employees' behaviour or communications among the processing likely to require one.
ICO guidance: Employment practices and data protection — monitoring workersSets out the regulator's expectations in detail: be clear about the purpose, choose the least intrusive means, tell workers what is happening, and do not monitor covertly outside narrow circumstances.
UK GDPR Art. 22Restricts decisions producing legal or similarly significant effects taken solely by automated means, which matters if monitoring output is fed into performance management or disciplinary processes.

How a rollout is done here

  1. State the purpose and test it. The ICO's first question is what problem the monitoring solves and whether something less intrusive would solve it.
  2. Complete a DPIA before deployment and seek workers' views as part of it; document them and your response.
  3. Record the legitimate-interests assessment separately from the DPIA.
  4. Tell workers clearly what is monitored, why, what is done with the output and how long it is kept — in a document they can actually find.
  5. Set retention limits and apply them, and make sure subject access requests can be answered against the monitoring data.
  6. Keep automated output out of significant decisions unless you have addressed Art. 22.

What gets a rollout refused

  • Monitoring first, assessing later. A DPIA written after deployment is evidence of the failure it was meant to prevent.
  • Covert monitoring outside genuinely exceptional circumstances; the ICO's position is that it should be rare, targeted and time-limited.
  • Boilerplate transparency. A line in a contract is not the clear information the guidance expects.
  • Feeding monitoring data into automated performance decisions without addressing Art. 22 and without telling workers it happens.

Monitoring staff in United Kingdom — questions

Do we need employee consent to monitor in the UK?

No, and relying on it is usually a mistake. The ICO's position is that consent is rarely valid in employment because of the imbalance of power, and that employers should identify a different lawful basis — in practice legitimate interests, supported by a documented assessment.

Is a DPIA mandatory?

For systematic monitoring of workers, treat it as mandatory. The ICO lists monitoring of employees' behaviour or communications among the processing likely to result in high risk, which triggers the Art. 35 requirement.

Does the UK still follow EU data protection law after Brexit?

The UK GDPR closely mirrors the EU GDPR and is supplemented by the Data Protection Act 2018. The practical divergence for monitoring is procedural rather than substantive: there is no UK equivalent of the works council consent rights found in Germany, Austria or the Netherlands, which makes UK rollouts materially faster.

Can we monitor staff working from home?

The obligations are the same, and the ICO expects the increased intrusion into domestic life to be weighed in the DPIA. Monitoring bounded to working hours, capturing metadata rather than screen content, is substantially easier to justify than continuous capture in someone's home.

Sources and scope

Primary source: United Kingdom regulator and statute references, last read 2026-09-17.

This page is a plain-English summary of published law and regulator guidance, not legal advice, and it is not a substitute for advice on your own facts. Employment and data protection law changes; each page states the date its sources were last read. Before monitoring staff anywhere, take advice from qualified counsel in that country.

See where the hours actually went

Free for up to three people. Windows and macOS. No keystroke content on any plan, and screenshots off unless an administrator turns them on.