Article 88 · proportionality · works councils

GDPR employee monitoring: what is actually allowed

The GDPR does not ban monitoring employees — it requires a lawful basis, proportionality and transparency. In practice that means collecting the least that answers your question, bounding it in time and scope, telling people, and writing the reasoning down. Most tools in this category fail on the first of those.

The rule is proportionality, not prohibition

The common reading — that European law forbids monitoring staff — is wrong, and it leads teams to either give up on measuring anything or to deploy something invasive and hope. Neither is necessary.

What the law actually asks is whether the intrusion is proportionate to a legitimate purpose. That turns a legal question into a design question: the narrower the collection, the easier the justification. A tool that captures application metadata to attribute hours is defending a small intrusion for a clear purpose. A tool that photographs the screen every ten minutes is defending a very large one for the same purpose, and has to explain why the smaller option would not have worked.

This is why the configuration matters more than the policy. A capability that is off by default and gated behind review is one you never have to justify; a capability that is on because it shipped that way is one you do.

What proportionality looks like in practice

Six tests a deployment should be able to pass before anyone installs anything.

  • Collect the least that answers the question. If the purpose is attributing hours, application and window metadata answers it; a screenshot does not become necessary because it is available.
  • Bound it in time. Monitoring during working hours is easier to justify than monitoring whenever the machine is on.
  • Bound it in scope. A capability nobody enabled cannot be misused, which is why defaults matter more than policies.
  • Make it visible. A person who can see what is captured about them is being informed, not surveilled.
  • Keep it for a stated period. Indefinite retention is difficult to justify against any purpose.
  • Write down the reasoning. A legitimate interest assessment that exists is worth more than a compliant configuration nobody documented.

Works councils and Article 88

In Germany, the Netherlands, Austria and elsewhere, a works council has to agree to a monitoring system before it is deployed — a co-determination right, not a consultation. That body is not assessing your intentions; it is assessing what the software is capable of.

Which is why "we won't use that feature" is a weak answer and "the product cannot do that" is a strong one. The questions that decide these conversations are consistent: does it record keystrokes, does it capture the screen, does it score individuals, can the person see what is collected, and can it be limited to working hours.

Our answers to those, and the design decisions behind them, are on the compliance page.

How ActivityPulse is built for this

no-keystroke-logging
Keystroke content is never captured — there is no code path that records what a person types.
sensitive-capture-off-by-default
Screenshots and input-activity capture are off by default, and a narrower scope can never widen what a broader one allows.
no-productivity-score
ActivityPulse reports what happened and does not grade the person it happened to — there is no productivity score.
rtbf
An erasure deletes the person's captured activity and the raw archive it came from, and anonymises the account itself — name, address, devices and memberships go with it; approved timesheets are kept as payroll evidence unless the organisation turns that off.
audited-config
Every change to what an organisation captures is written to an audit log with who changed it and when.
transparent-agent
By default the person being monitored can see what is being captured on their own machine and can pause capture. The one exception is a covert investigation, which is Enterprise-only, unavailable in the EU, capped at 90 days, and audited.

What this page is not

This is not legal advice, and no vendor page is. Article 88 means the rules differ by country, your lawful basis depends on your circumstances, and a works council agreement is negotiated rather than downloaded. Take it as an accurate map of the questions, and get the answers from someone who can be accountable for them.

Frequently asked questions

Does the GDPR ban employee monitoring?

No. The GDPR does not prohibit monitoring employees; it regulates it. Monitoring needs a lawful basis, it must be proportionate to a legitimate purpose, and the people affected must be informed. What it effectively rules out is monitoring that collects more than the purpose requires — which is where most tools in this category run into trouble.

What is the lawful basis for monitoring employees?

In most employment contexts it is legitimate interest or performance of a contract. Consent is generally a weak basis at work, because an employee cannot freely refuse an employer — regulators have said so repeatedly. Whichever basis you rely on, a legitimate interest assessment weighing your purpose against the intrusion is the document that has to exist.

What does Article 88 add?

Article 88 lets each member state set its own rules for employment data, and most set them tighter than the GDPR baseline. That is why a deployment that is straightforward in one country needs a works council agreement in another, and why 'GDPR compliant' alone is never the whole answer in Europe.

Are screenshots allowed under the GDPR?

Not prohibited, but hard to justify. A screenshot captures whatever happened to be on screen — personal messages, a colleague's data, a browser tab nobody meant to share — so it collects far more than a time-attribution purpose requires. That makes proportionality difficult to argue and is a common reason a works council refuses.

Is keystroke logging allowed?

It is extremely difficult to justify for time tracking, because the purpose can be met without it. Recording what someone types is close to the most intrusive thing a workplace tool can do, and the gap between that intrusion and the stated purpose is exactly what a proportionality test examines.

Do we need a DPIA?

Almost certainly. Systematic monitoring of employees is listed as high risk, and a data protection impact assessment is required before you start rather than after. As the processor we assist with it; the assessment itself is the employer's obligation as controller.

Do employees have to be told?

Yes. Transparency is not optional: employees must know what is collected, why, and for how long it is kept. Covert monitoring is lawful only in narrow, specific circumstances — a suspected offence you cannot investigate any other way — and rolling out time tracking is not one of them.

Does ActivityPulse support covert monitoring?

In one narrow form, and we would rather tell you plainly than let the question sit unanswered. Outside the EU, on the Enterprise plan, an organisation admin can authorise a time-boxed covert investigation aimed at the organisation, a team or one person — with a stated purpose, a DPIA reference and their attestation, capped at 90 days, reverting to visible automatically, revocable early, and audited at both ends. It hides the agent's on-screen presence; it never collects more than the capture policy already allows. It is switched off entirely for EU-region organisations, and our terms require that the possibility be disclosed in the monitoring notice you give staff: unannounced as to timing, never secret as to existence.

See where the hours actually went

Free for up to three people. Windows and macOS. No keystroke content on any plan, and screenshots off unless an administrator turns them on.