Is Employee Monitoring Software Legal Under GDPR? Rules for Remote Teams
Employee monitoring software can be legal under GDPR, but only under specific conditions. The problem is that most monitoring tools employers buy off the shelf are configured by default to break those conditions. The default settings on commercial monitoring software are built for maximum visibility, not for what GDPR considers necessary and proportionate.
This is the tension every employer with a distributed team eventually runs into. For instance, security teams may want visibility into any unusual account activity, managers may want confidence that hours logged match hours worked, and finance may want accurate timesheet data for clients billed by the hour. On their own, none of these needs is unreasonable. However, GDPR focuses less on the usefulness of the tool. Instead, it asks whether the specific processing involved is necessary for that purpose and proportionate to the intrusion it creates for the employee being watched.
That is the gap this article walks through: what GDPR actually permits, where most monitoring setups go wrong, and what a compliant setup looks like for a remote team.
What legal basis can employers use for monitoring employees?
Legitimate interest is the legal basis almost every employer relies on for workplace monitoring, and consent is the one to avoid. That surprises a lot of employers who assume asking staff to sign a consent form settles the matter, but under GDPR, consent from an employee to their own employer is rarely valid in the first place.
Basically, GDPR requires consent to be freely given, and free consent depends on the person being able to refuse without fear of consequence. In an employment relationship, that condition rarely holds. An employee who is asked to consent to monitoring software knows, even if nobody says it directly, that refusing could affect how they are seen at work. The Article 29 Working Party addressed this directly in its 2017 opinion on data processing at work, concluding that given the inherent power imbalance between employer and employee, consent should not be treated as the basis for workplace data processing except in unusual circumstances. That position has carried through into how EU data protection authorities apply GDPR today.
This leaves legitimate interest, under Article 6(1)(f), as the basis employers actually build their monitoring programs on. But legitimate interest is not a blank check. It comes with a built-in balancing test. Basically, to rely on legitimate interest, an employer needs to show three things:
First, that there is a real interest behind the processing, such as protecting company systems from unauthorized access or verifying billable hours on client work.
Second, that the monitoring is necessary to achieve that interest, meaning there is no less intrusive way to get the same result.
Third, that the interest is not overridden by the employee’s own rights and reasonable expectations of privacy.
That third step is where things get a little complicated. For instance, continuous webcam monitoring to confirm someone is at their desk fails the test almost immediately, because clock-in systems or activity logs achieve the same verification with far less intrusion. Keystroke logging across an entire workday, capturing personal messages and unrelated browsing, is rarely proportionate to a stated goal of security monitoring. Screen recording that runs at all times, rather than triggering on specific risk indicators, tends to collect far more than the employer’s legitimate interest actually requires. In each case, the question is always whether that specific level of monitoring is what the stated purpose genuinely calls for, and whether a less invasive option would get the employer to the same place.
Getting the legal basis right is the first hurdle, but it does not clear the employer of GDPR’s other obligations.
Do employers have to tell employees they’re being monitored?
Yes. Employers have to tell employees what monitoring is taking place, why it’s happening, and how the data will be used. In fact, this requirement is where a large share of GDPR fines against employers actually come from. It is rarely the monitoring itself that triggers enforcement action. It is employees finding out about it after the fact, or discovering that what they were told barely resembled what was actually being collected.
This obligation comes from Articles 13 and 14 of GDPR, which require controllers to give data subjects clear information before processing begins. For employees, that means knowing which tools are running, what categories of data those tools capture, the purpose behind the monitoring, and how long the data is kept.
The problems come about when employers assume that a passing mention in the employee handbook, something like ‘monitoring may occur for security purposes‘, covers this obligation. It doesn’t. Employees need to know the specific type of monitoring in use, whether that’s screen activity, keystrokes, location tracking, or video, and the actual reason the employer needs that data rather than a generic nod to productivity or compliance.
In late 2024, the French data watchdog, CNIL, fined a real estate company 40,000 euros after employees complained about monitoring software installed on their work computers during remote work. The software logged periods where employees hadn’t touched their keyboard or mouse for several minutes, treated those periods as inactivity, and reduced pay when employees didn’t make up the time. It also captured screenshots of employee screens every few minutes. Separately, the company ran two cameras that continuously recorded both video and audio across the workspace and the break room.
When the CNIL investigated, it found that employees had never been properly informed about what the tracking software actually collected or how the video system worked, beyond a sign on one door reading video monitored space. That sign said nothing about the purpose of the recordings or how long they were stored, and the verbal explanation staff had been given about the tracking software fell well short of what Article 13 requires. The CNIL treated this as its own violation, separate from the finding that the monitoring itself was excessive and had no valid legal basis under Article 6.
So, essentially, what regulators are actually looking for is whether an employee, reading what they were given, would understand what’s being collected about them and why.
Is keystroke logging and screenshot monitoring legal under GDPR?
Not in the way most monitoring software runs it by default. Continuous keystroke logging and screenshot capture across an entire workday are very hard to justify under GDPR, and in fact, data authorities treats them as presumptively unlawful unless the employer can point to a specific, serious business need that a lighter form of monitoring couldn’t meet. That’s usually a high bar to clear.
The CNIL actually addressed keylogger software directly, well before remote work tools like Hubstaff or Time Doctor became common. Its position was that keylogger software captures a permanent, ongoing record of everything an employee does on their keyboard, which inevitably sweeps up private emails, banking details, and login credentials alongside anything work-related. Because of that, the regulator said keyloggers on an employee’s computer are off limits unless the employer has a strong justification, something like preventing the leak of trade secrets in a role where that risk is real and specific, not a general interest in knowing whether someone is working. That reasoning still holds up well after GDPR came into force, because it maps directly onto the necessity and proportionality test built into Article 6(1)(f).
The December 2024 CNIL decision against the French real estate company makes the same point from a different angle. The software in that case wasn’t a traditional keylogger, but it worked on similar logic: it tracked keyboard and mouse inactivity to flag when an employee wasn’t at their desk, and it took regular screenshots as a backup check. The CNIL didn’t object to the employer wanting proof of actual working time. It objected to the method, because logging every idle moment and screenshotting the screen every few minutes captures far more than what’s needed to answer a fairly simple question, which is whether someone did their job that day. A time tracking tool that logs hours worked, or a project management system that shows task completion, gets the employer to the same answer without pulling in the contents of someone’s screen.
The pattern across these cases is quite consistent. Monitoring that captures content, whether that’s what someone typed or what was on their display, is treated far more strictly than monitoring that just confirms activity happened. If an employer’s actual goal is verifying hours or catching genuine security incidents, keystroke and screenshot tools are usually the wrong instrument for the job because the tool collects more than the goal requires.
What about screenshots specifically?
Screenshots raise a few questions of their own that don’t apply to keystroke logging in the same way, mainly around how often they’re taken, how long they’re kept, and whether anything sensitive should be masked before storage.
Frequency is usually the first thing that gets a monitoring setup into trouble. Software that captures a screenshot every three to fifteen minutes, which is roughly the default interval on a lot of commercial tools, builds up a detailed visual record of someone’s entire day. That interval was exactly what the CNIL flagged in the real estate company case as particularly intrusive, partly because screens routinely show things well outside the scope of any legitimate monitoring purpose, like a personal email left open, a medical portal, or messages from a family member. Lowering the frequency doesn’t fully solve this on its own, but it does reduce how much unrelated personal content the employer ends up storing.
Retention compounds the same problem. Screenshots kept indefinitely, or for months without a clear reason, are difficult to justify under the storage limitation principle in Article 5(1)(e), which requires personal data to be kept no longer than necessary for the purpose it was collected for. If the purpose is confirming a specific day’s work output, there’s rarely a reason to still hold that screenshot six months later.
Blurring or redacting is worth considering for employers who genuinely need visual confirmation of activity without capturing full content. Some monitoring tools can blur most of the screen while showing which application is active, which gets closer to the kind of minimal, purpose limited data collection GDPR expects, though it’s still worth checking whether a less visual method, like application usage logs, would answer the same question with even less data collected in the first place.
Is GPS or location tracking of remote employees legal?
Generally not, at least not for the purpose most employers actually want it for, which is confirming that a remote employee is working from where they said they’d be. Location tracking tied to clock-in and clock-out sounds like a reasonable attendance check on paper, but GDPR’s proportionality principle asks a more specific question: is there a less invasive way to get the same confirmation? In almost every case involving remote attendance, there is, which is why this kind of tracking is consistently ruled against even when the employer’s underlying concern was legitimate.
Italy’s Garante made this point clearly in a March 2025 decision against a regional public agency that had rolled out a remote work attendance app called Time Relax. The app required employees to enable GPS on their phone or computer and captured their coordinates every time they clocked in or out, so the employer could check whether someone working remotely was actually in the location listed in their remote work agreement. On the surface, this looks like a narrow, purpose-specific use of location data, tied to a single moment rather than continuous tracking.
The Garante still found it unlawful, and the reasoning is worth sitting with because it applies well beyond this one case. The agency had gone further than what its own labour authorisation allowed; it had no opt-out mechanism for employees who didn’t want their location recorded, and it kept the data longer than the stated purpose required. The Garante concluded that this combination of continuous-style geolocation, no way to refuse, and extended retention was excessive relative to what the employer was actually trying to confirm, which was simply whether someone was doing their job from an agreed location.
Verifying that a remote employee worked their hours doesn’t require knowing exactly where they were standing when they logged in. A time tracking system, a check-in through a work application, or even a simple confirmation email accomplishes the same goal without collecting precise geographic coordinates, which GDPR treats as more sensitive than ordinary attendance data because of how much it can reveal about a person’s movements and personal life. When a less invasive method exists and does the job just as well, continuing to collect location data anyway is very difficult to defend as necessary under Article 6(1)(f), no matter how reasonable the original business reason sounded.
There’s a narrower use case where location tracking holds up better, and that’s genuinely mobile roles, delivery drivers, field technicians, sales staff visiting multiple sites, where knowing location during working hours is tied directly to the job itself rather than to proving someone showed up. Even then, the same rules apply: employees need clear advance notice, the tracking needs to stop outside working hours, and the employer needs to be able to show the Labour Inspectorate or equivalent authority signed off on how it’s being used, which is exactly the safeguard the agency in the Garante case failed to follow even though it had asked for permission in the first place.
Is webcam or video monitoring of remote workers legal?
Not when it’s continuous, and this is one of the clearer lines GDPR draws. An always-on webcam that captures a remote employee for their entire shift is very difficult to justify, because it collects far more than any legitimate business purpose actually needs, and it puts the employee under a level of visual surveillance that would be unthinkable in most physical offices.
A Dutch court ruling from 2022 illustrates why this particular form of monitoring tends to fail even when an employer thinks it has a reasonable case for it. An employee working remotely for a software company was dismissed after he refused to keep his webcam on for the entire working day, a requirement his employer wanted so a manager could visually confirm he was at his desk. The employee was already sharing his screen for the same purpose, so the camera added a layer of visual monitoring on top of activity that was already being tracked.
The court sided with the employee, finding that the constant camera requirement was not a reasonable instruction, and it pointed to the European Court of Human Rights’ own position that video surveillance of an employee, whether hidden or done openly, interferes with the right to private life protected under Article 8 of the European Convention on Human Rights. That reasoning lines up closely with how GDPR treats the same situation. If screen sharing already answers the question of whether someone is working, a webcam running on top of it isn’t adding a necessary layer of verification. It’s adding intrusion without adding proportional value.
The tools being marketed to remote team managers right now mostly fall into two categories, and they don’t hold up equally well under this standard. Software that takes a periodic photo through the webcam, often every few minutes alongside a screenshot, is functionally the same problem as continuous video, just sampled instead of constant. It still captures someone in their home, potentially with family members visible, personal items in the background, or moments that have nothing to do with work, and it does this on a recurring schedule regardless of whether anything unusual is actually happening. Software that only activates the camera during scheduled video calls sits in a completely different category, because that use is tied to an activity the employee already expects and has agreed to as part of doing their job, not a standing surveillance mechanism running in the background of their day.
The practical test an employer should apply here is the same one that shows up throughout GDPR’s proportionality principle: does the camera reveal something a manager genuinely needs to know that couldn’t be confirmed another way. Task completion, login activity, and calendar attendance already answer most of the questions employers actually have about whether remote work is happening. A webcam pointed at someone’s home for eight hours a day answers a question nobody legitimately needed to ask in the first place.
Do employers need a DPIA before deploying employee monitoring software?
Usually yes. Systematic monitoring of employees is one of the situations GDPR treats as inherently high risk, and Article 35 requires a Data Protection Impact Assessment whenever processing is likely to result in that kind of risk to people’s rights and freedoms. Ongoing monitoring of staff activity, whether through screen tracking, keystroke logging, location data, or video, falls squarely into that category, which is why most EU data protection authorities list workplace monitoring explicitly on their published DPIA trigger lists.
Essentially, a DPIA forces an employer to work through the same proportionality questions a regulator would ask after the fact, but before the monitoring goes live rather than after employees have already complained. That sequencing is the entire point. An employer who skips this step tends to end up choosing a monitoring tool based on what it can do rather than what the situation actually requires, which is exactly the pattern behind most of the enforcement decisions already covered in this article.
A DPIA that actually holds up needs to cover a few things in specific terms. It should describe exactly what data the monitoring tool collects, down to the level of screenshots, keystrokes, or location pings, rather than a vague reference to activity data. It needs to state the specific purpose behind the monitoring, such as detecting unauthorized access to client data, and explain why that purpose requires this particular method rather than a less intrusive alternative. It should include an honest assessment of the risk to employees, covering things like the psychological effect of constant monitoring or the risk of the data being used for reasons beyond what employees were told. And it needs to document the safeguards put in place to reduce that risk, whether that’s limiting retention, restricting who can access the data, or scaling back monitoring frequency.
A documented DPIA doesn’t guarantee a monitoring program will pass regulatory scrutiny, but the absence of one is itself treated as a sign that the employer never seriously considered whether the monitoring was proportionate in the first place, and that absence tends to work against the employer when something does go wrong.
Can employees refuse to be monitored?
Sometimes, yes. Article 21 of GDPR gives individuals the right to object to processing that’s based on legitimate interest, which covers most employee monitoring programs since legitimate interest is the legal basis employers rely on. Once an employee objects, the employer can’t just continue processing as before. The employer has to either stop the monitoring for that person or demonstrate compelling legitimate grounds that override the employee’s interests, rights, and freedoms.
That second option is a genuinely high bar, and it’s worth being specific about what it means in practice. A compelling ground isn’t the same as a valid reason for monitoring in general. It has to be something specific enough to outweigh this particular employee’s objection, in this particular situation. An employer can’t simply restate the original justification for the monitoring program, since that justification already went through the balancing test when the legal basis was first established. What’s required at the objection stage is a fresh, individualized assessment of why this employee’s data still needs to be processed despite their objection, and that assessment has to be documented, not just asserted after the fact if a dispute arises.
In practice, this right plays out differently depending on what kind of monitoring is involved. An employee objecting to a security tool that scans for unauthorized data transfers across the whole organization is unlikely to succeed, because the tool’s value depends on covering everyone equally and carving out exceptions would undermine the security purpose itself. An employee objecting to a specific tracking feature, like a keystroke logger applied to their role even though their work doesn’t handle sensitive data, has a much stronger case, because the employer would struggle to explain why that particular form of monitoring is necessary for that particular employee.
Is AI-based productivity scoring or algorithmic monitoring legal?
Often not, once the score starts affecting someone’s pay, shifts, or continued work. Article 22 gives employees the right not to be subject to a decision based solely on automated processing when that decision has a legal effect or similarly significant impact on them, and a productivity score that determines who gets more shifts or gets managed out of a role clears that bar easily.
In the Garante’s 2021 decision against Foodinho, the Italian arm of delivery platform Glovo, it had used an algorithm to score riders on performance and then fed that score directly into a system that assigned work, so lower scoring riders got fewer opportunities. The Garante fined the company 2.6 million euros, finding that the process lacked meaningful human review and that riders had no real way to understand or challenge their score.
The human review point is the one that trips employers up most. A manager glancing at a score before approving it doesn’t count if they have no real ability to question or override it. For that requirement to be met, the human involved needs actual authority to change the outcome, a clear explanation of how the score works, and a real process for employees to contest it.
For remote teams, the line that matters is whether a tool just displays activity data for a manager to interpret, or whether the software’s own score is effectively making the decision. The second is where these protections apply.
What happens if employee monitoring software violates GDPR?
The consequences fall into two categories, and the financial one usually gets the attention while the practical one causes the bigger headache day to day.
On the financial side, GDPR fines scale with the type of violation. Breaches of core data protection principles, like using monitoring without a valid legal basis, can reach up to 20 million euros or 4 percent of global annual turnover, whichever is higher. That’s the tier the Amazon France Logistique case fell into, with a 32 million euro fine, and it’s also the tier most excessive monitoring violations land in since they typically involve a failure of the legal basis itself. Less severe violations, like incomplete transparency notices, sit in a lower tier capped at 10 million euros or 2 percent of turnover. In practice, the fines against employers for monitoring violations have ranged widely based on company size and the scale of the violation, from the 40,000 euro CNIL decision against the French real estate company up to the tens of millions seen in the Amazon and H&M cases.
But the fine is often not the part that actually hurts most. Data protection authorities can order an employer to stop the unlawful processing entirely, which means ripping out a monitoring system that may have taken months to roll out. They can also order the deletion of everything collected through it. For employers who tried to use monitoring data as evidence in a disciplinary action or dismissal, unlawfully obtained monitoring data is frequently thrown out by labor courts, which can turn what looked like a solid case for termination into one the employer can’t actually prove. That was effectively the outcome in the Dutch webcam case covered earlier, where the employer’s underlying justification for dismissal collapsed once the court found the monitoring requirement itself was unreasonable.
There’s also a slower moving cost that doesn’t show up in a regulator’s decision. Employees who find out they were monitored without proper notice tend to lose trust in the employer fast, and that damage rarely stays contained to the one policy that caused it. For a distributed team especially, where the working relationship already runs on more trust than a manager watching someone across an office, an employer caught secretly overreaching on monitoring is dealing with a problem no fine amount fully captures.
How to run GDPR-compliant employee monitoring
Everything covered so far points to the same handful of practical steps, and by now the reasoning behind each one should be familiar rather than arbitrary. Here’s how it comes together for an employer actually setting this up.
Start with the purpose, not the tool. Decide exactly what problem the monitoring needs to solve, whether that’s confirming billable hours or catching unauthorized data access, before choosing software. The purpose determines everything that follows, and vague goals like productivity visibility are usually where compliant monitoring programs start to fall apart.
Pick legitimate interest as the legal basis, and run the balancing test properly. Document the real interest behind the monitoring, confirm there’s no less intrusive way to achieve it, and weigh that against the employee’s reasonable expectation of privacy. Consent is almost never the right basis here given the power imbalance in an employment relationship.
Do a DPIA before deployment, not after a complaint. Since systematic employee monitoring is a standard Article 35 trigger, work through the risk assessment while the setup is still configurable, not once employees have already pushed back.
Match the monitoring method to the purpose, and nothing broader. If time tracking data answers the question, don’t add keystroke logging or screenshots on top of it. If task completion data proves the work happened, don’t add a webcam requirement. Each layer of monitoring needs its own justification, not a shared one borrowed from the overall program.
Give employees specific, advance notice. Name the tools in use, what data each one collects, why it’s collected, and how long it’s kept. A general handbook clause doesn’t meet this bar, and this is the step most fines actually trace back to.
Build in a way to handle objections. Employees have a right to object under Article 21, and a monitoring program needs an actual process for reviewing that objection individually, not a policy that assumes participation is automatic.
Set a retention limit and stick to it. Screenshots, location pings, and activity logs should be deleted once they’ve served their stated purpose, not kept indefinitely because the software defaults to storing everything.
If a score affects someone’s job, keep a human meaningfully involved. Any monitoring output that feeds into decisions about pay, shifts, or continued employment needs real human review, not a rubber stamp on whatever the algorithm produced.
None of these steps require abandoning monitoring altogether. They require matching the monitoring to what the business actually needs to know, which is the same standard GDPR has been asking employers to meet in every section above.
Conclusion
Employee monitoring under GDPR isn’t a question of whether employers are allowed to see what their remote teams are doing. It’s a question of whether they’ve actually thought about what they need to know, and chosen the smallest tool that gets them there. The employers who end up in front of a regulator are rarely the ones who monitored too little. They’re the ones who reached for the tool with the most features instead of the one that matched the problem.