Is Employee Monitoring Legal? Consent, Scope, and Records
The conditions that decide whether monitoring is defensible, why covert monitoring is the risky category everywhere, and the record you should be able to produce on request.

Overview
Is employee monitoring legal? In most jurisdictions, yes — but only under conditions, and the conditions are the whole story. Monitoring that has a genuine business purpose, is proportionate to that purpose, is disclosed to the people being monitored, and is retained for a defined period is broadly defensible. Monitoring that is covert, open-ended in scope, or kept indefinitely because nobody decided otherwise is where organisations get into trouble.
This article is not legal advice, and it cannot be: employment and privacy law differ sharply between countries, and in federal systems between states and provinces. What follows is the set of questions your counsel or data protection adviser will ask you, framed so you can answer them before the meeting rather than during it.

- Write down the business purpose before you evaluate any tool, because the purpose constrains the scope.
- Tell people, in writing, in specific terms — vague policy language is the most common failure.
- Keep a record of what you capture, who can see it, and when it is deleted.
Is it legal to monitor employees without their knowledge?
This is the version of the question people actually search for, and it has the sharpest answer: covert monitoring is the highest-risk category in essentially every regime that regulates it at all. Some jurisdictions permit it narrowly — typically for a specific, documented investigation into suspected serious misconduct, for a limited period, where less intrusive means have been considered and rejected, and often with sign-off requirements. That is a long way from "we quietly turned on screenshots for the whole company."
Two consequences follow. Covert monitoring is almost never lawful as a standing practice; where permitted at all it is time-boxed and case-specific. And in several jurisdictions evidence gathered covertly is inadmissible in the disciplinary process you collected it for — you carry the exposure and get none of the benefit.
The practical test is simple. If you would be uncomfortable telling your team exactly what the tool captures, you have a policy problem that no software setting fixes.
The four questions that decide whether monitoring is defensible
What is the purpose? "Productivity" is not a purpose; it is a category. A purpose is specific: billing clients accurately for time worked, meeting a contractual obligation to a customer about handling of their data, complying with a sector rule that requires record-keeping, or investigating a specific incident. Write it down first, because everything downstream is judged against it.
Is the scope proportionate to that purpose? If the purpose is accurate client billing, then capturing which project a person is working on and for how long is proportionate. Capturing keystrokes, or screenshotting the browser on a lunch break, is not. Proportionality is the test regulators apply most often and the one organisations fail most often, usually because they enabled everything a tool offered rather than only what they needed.
Have you told people, specifically? A line in a handbook saying the company "may monitor use of its systems" is not specific notice. Specific notice says what is captured, when capture is active, what is not captured, who can view it, how long it is kept, and who to contact with questions. Note also that in some regimes — the EU in particular — employee consent is treated with suspicion as a lawful basis precisely because the employment relationship is unequal, so notice plus a documented legitimate-interest assessment is the more common route. Which basis applies to you is exactly the question to put to counsel.
How long do you keep it, and who can see it? Retention is where most programmes quietly become indefensible: data collected for a purpose should be deleted once that purpose expires. Access matters just as much — a manager seeing their own team's hours is a different proposition from every administrator being able to browse anyone's activity.
What an employee monitoring notice usually contains
Whether your jurisdiction calls it a consent form, a notice, a fair-processing statement, or an addendum to the employee handbook, the content is broadly the same. Draft it with counsel, but expect it to cover:
- Scope and mechanics:
- Exactly what is captured — hours, application or window titles, screenshots, idle detection — item by item, not as a category.
- When capture runs: working hours only, only while a task timer is active, or continuously while the machine is on.
- What is explicitly not captured, which is often the most reassuring part of the document.
- Whether the capture applies to company devices only, or to personal devices used for work.
- Access and use:
- Which roles can view the data, and whether an individual can see their own record.
- What the data will and will not be used for — for instance, billing and capacity planning but not automated performance ranking.
- Whether any automated decision-making is applied to it, which carries additional obligations in several regimes.
- Retention and rights:
- How long each category of data is retained and what happens at the end of that period.
- How an employee raises a question, requests their data, or objects.
- The date the notice takes effect and the date it will next be reviewed.

What to document internally
The notice faces your employees. Separately, keep an internal record that faces your regulator, your client's security reviewer, and your future self: the written business purpose; the proportionality reasoning, including which more intrusive options you rejected and why; the exact configuration you deployed, captured as settings rather than as intent; who has access and since when; the retention schedule per data category; and a review date, because a programme nobody has revisited in three years has almost certainly drifted from its purpose.
If you operate in the EU or UK, ask counsel whether your programme requires a data protection impact assessment. Systematic monitoring of employees frequently triggers that threshold, and the assessment is substantially the document described above.
What to ask a time-tracking or monitoring vendor
Vendors vary enormously in how much they capture and how much of that capture you control. Ask concretely rather than accepting a compliance badge as an answer. What is the complete list of data types that can be captured, and which can be switched off independently? Who controls those settings — your administrator, or the vendor? Who can view an individual's data, and is that access itself logged? What can be exported, and can one person's data be deleted on request? And plainly: does the product disclose anything to the employee, or is that entirely your responsibility?
That last question deserves an honest answer from us as well as from anyone else. Pace, our desktop time capture and timesheet product, is admin-controlled: your administrators decide what is captured. It does not ship an in-product consent flow or an employee-facing disclosure screen, and our consent and retention documentation is still in progress. The notice, the internal record, and the legal basis are yours to run — a tool cannot discharge them for you, and any vendor implying otherwise is overselling. Our security page sets out what we do and do not claim, including where the answer today is "not yet".
Questions we get asked
In most jurisdictions it is lawful where there is a legitimate business purpose, the scope is proportionate to that purpose, employees have been informed, and data is retained for a defined period. The specific rules vary by country and often by state or province, so confirm your position with qualified counsel before deploying.
Where to go next
If your reason for looking at capture tools is commercial rather than investigative — you need defensible hours because you bill by them — the narrower question is what data your invoicing actually requires, which is usually much less than a monitoring suite collects. We wrote about that path in closing the gap from timesheet to invoice.
If you are in a procurement or security review and want direct answers about isolation, access, and data export, read what we publish on security — it includes the certifications we do not hold — and see what Pace captures and who controls it. Send us your review questionnaire and you will get the same plain answers this page gives.
Related reading
Want to see how this works in practice?
Tell us how your team runs today and we'll walk you through the parts of Workefy that apply.
Prefer email? Write to contact@workefy.io


