Before you switch on staff monitoring

· · Security Commentary

Your productivity suite probably offers you dashboards showing who is active, when, and for how long. Your security tooling can likely log keystrokes. Somebody may have suggested an AI tool that scores how much work each person is getting through. Turning any of it on is a few clicks and a licence fee.

The clicks are the easy part. The UK government has just started asking whether they should also require a conversation with your staff first.

What is being proposed

The Department for Business and Trade has opened a consultation on workplace monitoring technology, reported by The Register, asking whether the current rules still make sense now that software routinely tracks activity, measures performance, and feeds decisions affecting people's working lives.

Ministers have not settled on an approach. They are asking whether guidance would be enough, whether a statutory code of practice is needed, or whether employers should be legally required to consult recognised trade unions or elected employee representatives before introducing monitoring technology. The consultation forms part of the Make Work Pay reforms and runs until 30 September.

The proposed definition is deliberately broad, covering CCTV and access control, biometrics, location tracking, keystroke monitoring, productivity software, and systems using automated decision-making or AI. The consultation asks whether that scope is about right, which is an admission that defining the thing may be harder than deciding what to do about it.

One number in it is worth holding on to. The consultation cites research in which one in three UK organisations said they actively monitored employees' digital activity. Two years earlier, ICO research put it at one in five.

Why this is not just a compliance story

It would be easy to file this under "watch this space" and wait to see whether anything becomes law. That would miss the useful part.

Nothing in the consultation changes your existing obligations, and those obligations already bite. Monitoring staff means processing their personal data, so UK GDPR applies today: you need a lawful basis, you need to tell people, and for anything intrusive you need a data protection impact assessment. The ICO has published employment practices guidance on monitoring workers that sets out what it expects. Plenty of businesses that switched something on because it came bundled have not done any of that.

Stephanie Lees, a data protection specialist at Pinsent Masons, noted that a statutory consultation duty would add a further layer of oversight for employers already managing UK GDPR, employment law, and the EU AI Act. The direction is clear even if the destination is not.

The questions to settle first

Whatever the consultation concludes, these are worth answering before you enable anything. They are also, not coincidentally, close to what a regulator would ask.

What specific problem are you solving? "Visibility" is not a problem, it is a feeling. If you cannot name the thing you would do differently with the data, you are collecting it for its own sake, and that is precisely what fails a necessity test.

Could you get there with less? Aggregate numbers usually answer a business question that individual-level surveillance was reached for out of habit. Less data is less risk, less cost, and less to explain.

Have you told people plainly? Not a clause in a handbook nobody has opened since induction. If you would be uncomfortable describing the monitoring in a team meeting, that discomfort is telling you something.

Who sees it, and what decisions can it drive? Monitoring feeding a performance process is a materially different proposition from a security log nobody reads unless there is an incident. If AI is scoring people, someone needs to be accountable for what it gets wrong, and it will get things wrong.

What does it cost you in trust? This one is not legal. Staff who feel watched behave differently, and not usually better. The productivity gain from a monitoring tool is easy to put in a business case, and the cost of people quietly disengaging never appears in one.

The security angle

Some monitoring is genuinely security work: logging administrative access, alerting on data leaving the business, keeping records that let you reconstruct an incident. That is defensible, proportionate, and usually easy to explain.

The problems start when security is used as the justification for something else. If a tool was bought to check whether people are working and the security value was added to the business case afterwards, be honest internally about which it is. Regulators are good at spotting the difference, and so are staff.

How Steelwise can help

If you are weighing up monitoring or AI tooling that touches your people, working out what is proportionate, what needs a data protection impact assessment, and what you would struggle to defend is a short, defined piece of work. Get in touch if that is on your desk.

Further reading

← All filings