Employee monitoring legitimate interests is a combination that organisations reach for often and get wrong just as often. Employers have real reasons to monitor: security, fraud prevention, safety, quality, and protection of confidential information. Legitimate interests is the lawful basis most likely to fit, because employment relationships make consent unreliable. But relying on it means passing a three-part test in which the interests of workers carry particular weight, and much monitoring fails it because it is broader, more secret or more intrusive than the purpose requires.
This guide explains how to assess employee monitoring under legitimate interests: the three-part test applied to the workplace, what factors matter, when a DPIA is needed, how to be transparent and what safer alternatives exist.
Why legitimate interests, and not consent
Consent under the GDPR must be freely given. Because of the imbalance of power between employer and worker, regulators treat consent in employment as problematic in most cases: a worker who fears consequences cannot refuse freely. Employers therefore usually rely on other bases, such as legal obligation, performance of the contract or legitimate interests. For monitoring that is not required by law or necessary for the contract, legitimate interests under Article 6(1)(f) is the usual candidate. Our guide to legitimate interests vs consent explains the difference.
The three-part test for employee monitoring legitimate interests
The test asks whether you have a legitimate interest, whether the monitoring is necessary for it, and whether the balance favours you. See our explanation of the legitimate interests balancing test for the general approach. Applied to monitoring:
| Part | Question for monitoring | Evidence to record |
|---|---|---|
| Purpose | What specific problem are we trying to solve? | Incident history, legal duty, risk assessment |
| Necessity | Could we achieve it with less intrusive means? | Alternatives considered and why rejected |
| Balance | What is the effect on workers, and do safeguards reduce it? | Impact analysis, safeguards, consultation |
Free legitimate interests assessment
Can you rely on legitimate interests for this processing?
Check whether legitimate interests is available, set out the purpose, test necessity, weigh the impact on people from 25 scenarios and choose the safeguards that tip the balance. Built to GDPR Article 6(1)(f), free.
Purpose: be specific
A legitimate interest must be real and lawful. “Productivity” or “managing risk” are too vague to carry the weight. A specific purpose sounds like this: preventing loss of customer data by detecting unusual file transfers, or protecting lone workers by tracking location during shifts. State the purpose, the harm it prevents and why it matters to the organisation. If you cannot state the purpose in a sentence, the monitoring is not ready.
Necessity: ask if there is a less intrusive way
This is where most monitoring fails. Consider whether the purpose could be met by targeted rather than blanket monitoring, by monitoring systems and not people, by aggregated data rather than individual records, or by controls that prevent the problem without watching anyone. For example, blocking removable media may prevent data loss with no need to inspect employees’ messages. Record the alternatives and why they would not work.
Balance: the impact on workers
The ICO publishes guidance on monitoring workers that discusses lawful basis, transparency and impact. Note that it states it is under review following legislative changes, so check the current version. The balancing factors are familiar. Consider how private the data is, whether workers reasonably expect it, how intrusive the method is and what the consequences might be. Watching work email content is more intrusive than logging that a system was accessed. Continuous screen capture or keystroke logging are at the intrusive end, and location tracking outside working hours is very hard to justify.
Reasonable expectations at work
Workers keep a reasonable expectation of privacy at work, even on employer equipment. The European Court of Human Rights considered workplace email monitoring in Bărbulescu v Romania in 2017 and stressed that employees must generally be told in advance of the nature and extent of monitoring, and that the measures must be justified and proportionate. The case is a helpful reminder that secrecy is rarely defensible.
Effect on vulnerable or sensitive situations
Take special care with representatives, whistleblowers, health and personal communications, and with workers in a weak position. Monitoring that could reveal trade union activity, health conditions or private messages raises special category or highly personal data issues and needs a stronger justification or should be avoided.
Safeguards that improve the balance
Safeguards are what turn a borderline case into a defensible one. For employee monitoring legitimate interests, they should be concrete, documented and actually in place before the monitoring begins, not promised for later.
- Limit the monitoring to specific systems, times and risks.
- Use automated alerts on patterns, with human review only after a flag.
- Restrict who can see the data and log their access.
- Set short retention periods.
- Exclude personal accounts, private areas and union communications.
- Provide a route for workers to query or challenge results.
- Do not use monitoring data for purposes beyond those you have set out.
When a DPIA is needed
Systematic monitoring of employees is a common trigger for a data protection impact assessment because workers are vulnerable data subjects and systematic monitoring may involve a high risk. Our guide to when a DPIA is required lists the triggers. Carry out the assessment before the monitoring starts, consult representatives where appropriate, and record the residual risk; see DPIA residual risk. If high risk remains, prior consultation with the supervisory authority may be needed.
Transparency for workers
Employees must be told what is monitored, why, how, for how long and who can see it. Put this in an accessible policy and in the privacy information for workers, and make sure it is consistent with what is actually done. Covert monitoring is exceptional and should be limited to specific, serious suspicion of crime or serious misconduct, for a limited time, when other means would prejudice the investigation, and with senior legal sign-off. Routine covert monitoring is not compatible with the transparency principle.
A hypothetical example of employee monitoring legitimate interests
The following is a hypothetical example invented for illustration. A financial advisory firm wants to prevent client data leaving the company. Its first proposal is to record all employee screens continuously and read outgoing emails. The privacy lead applies the three-part test. The purpose, preventing loss of client data, is legitimate. On necessity, however, the team finds that blocking personal cloud storage, restricting USB use and alerting on bulk downloads would meet the aim with far less intrusion.
The firm adopts the targeted controls, with alerts reviewed by security staff only when triggered, a 90-day retention period and a clear policy explaining the monitoring. It completes a DPIA, consults the works council, and excludes personal messaging sites. The assessment records why the original proposal failed the necessity test. The result protects client data while respecting worker privacy.
Consulting workers and their representatives
Involving staff early improves both the legal position and the outcome. Explain the proposed monitoring, its purpose and the safeguards to employees or their representatives before deployment, and record the feedback and any changes it prompted. In some countries, works councils or unions have legal rights of consultation or co-determination over monitoring, so check local employment law as well as data protection. Monitoring that workers understand and accept is also far less likely to generate complaints or damage trust.
Reviewing employee monitoring legitimate interests over time
The balance can shift. Tools gain new features, new risks emerge and workers’ expectations change. Review each assessment at least annually and whenever the system, purpose or law changes. Check whether the monitoring still delivers the benefit you claimed; if the incidents it was meant to prevent have stopped and the alerts are never used, the necessity of the measure may have gone. Switch off what you no longer need, and record the decision.
Common mistakes in employee monitoring legitimate interests
Typical failures include vague purposes, blanket monitoring where targeted would do, no consideration of alternatives, secret monitoring, no DPIA, retention with no limit, use of data for unrelated disciplinary matters, ignoring remote workers’ homes and personal devices, poor security of monitoring data, and no review. Another is buying a monitoring tool first and assessing later, which locks in a design that may be unlawful.
Working from home and personal devices
Remote work raises the stakes because monitoring can reach into the home. Avoid webcam, microphone or continuous screen monitoring at home, limit checks to work systems and working hours, and be cautious about personal devices used for work. If you offer a bring-your-own-device scheme, separate personal and work data technically so that you do not see private content.
Templates for employee monitoring legitimate interests
Using a consistent record for employee monitoring legitimate interests decisions helps HR, legal and IT reach the same conclusions on similar tools.
A structured record helps you show that the test was applied honestly. The Legitimate Interests Assessment Report and Workbook provides a report for documenting purpose, necessity and balancing. Keep the same format for each monitoring measure, and review the assessment when the technology, the risk or the law changes.
Employee monitoring legitimate interests FAQ
Can we monitor employees under legitimate interests?
Yes, if you pass the three-part test: a specific legitimate purpose, monitoring that is necessary for it, and a balance that does not override workers’ interests, with transparency and safeguards.
Do we need employees’ consent?
Consent is generally unreliable in employment because of the power imbalance, so most employers rely on another basis, such as legitimate interests.
Is a DPIA required?
Often, because systematic monitoring of workers is likely to be high risk. Do it before starting and record the residual risk.
Can we monitor secretly?
Only in narrow cases involving specific suspicion of serious wrongdoing, for a limited time and with strong justification and legal advice. It is not acceptable as routine.
How long can monitoring data be kept?
Only as long as needed for the stated purpose. Set a short, defined period, and delete the data when it expires unless it is needed for an ongoing investigation.