Employers can monitor remote work, but the legal line runs through notice, proportionality and purpose. In the US, most monitoring of company devices is lawful, yet New York, Connecticut and Delaware require written notice, and several states restrict biometric or off-duty tracking. In the EU and UK, GDPR treats monitoring data as personal data: you need a lawful basis, a documented impact assessment and the least intrusive method that achieves the goal. Keystroke loggers, webcam snapshots and always-on screen capture rarely pass that test. Output-based measurement usually does.
Remote employee monitoring became a mainstream HR question the moment the office stopped being the default place of work. Software that once sat quietly on servers now takes screenshots, counts keystrokes and scores “productivity” from mouse movement. The vendors are persuasive; the law is less forgiving. This guide explains what an employer can lawfully track on remote staff in the United States, the European Union and the United Kingdom, how to choose monitoring that improves performance instead of eroding trust, and how to write a policy that will survive a regulator, a works council and an exit interview. It sits alongside our remote work policies and culture guide and our overview of managing hybrid teams.
Is it legal to monitor remote employees?
Generally yes on company-owned equipment and accounts, provided the monitoring is disclosed, proportionate and tied to a legitimate business purpose. Covert monitoring, monitoring of personal devices and biometric capture are the areas where employers most often break the law.
Which jurisdictions are strictest?
The EU and UK, because GDPR requires a lawful basis, transparency and (for high-risk monitoring) a Data Protection Impact Assessment, and because works councils in Germany, the Netherlands and Austria have co-determination rights over monitoring tools. Among US states, New York, Connecticut, Delaware, Illinois (biometrics) and California (privacy rights) carry the most obligations.
What actually works?
Measuring outputs, service levels and milestones. Activity-tracking metrics correlate poorly with results, encourage “mouse jiggler” behaviour and are the most common trigger for regulatory complaints and attrition.
What can employers legally monitor on remote employees?
Employers can lawfully monitor work accounts, company devices, network traffic, work email and collaboration tools, and time and attendance, as long as employees are told what is collected and why. The legal problems start when monitoring reaches into personal devices, personal accounts, private spaces at home or the employee’s body.
The distinction most HR teams find useful is where the data comes from. Data generated on company systems (log-ins, ticket closures, code commits, call recordings on the company phone system) sits comfortably inside the employer’s legitimate interest almost everywhere. Data generated by observing the person (webcam captures, continuous screen recording, keystroke logs, GPS on a personal phone, attention-tracking) is where consent, proportionality and human dignity arguments arrive, and where courts in Europe have repeatedly sided with employees.
| Monitoring type | US (typical) | EU / UK (GDPR) | Practical verdict |
|---|---|---|---|
| Email and chat on company accounts | Lawful with notice (NY, CT, DE require written notice) | Lawful under legitimate interest with transparency; content review must be targeted | Standard; document the purpose |
| Login, uptime, app usage on company laptop | Lawful; notice strongly advised | Lawful if proportionate; avoid continuous profiling | Acceptable for security and licensing |
| Screenshots at intervals | Lawful in most states with notice | Usually disproportionate unless narrowly justified | Avoid; use output metrics |
| Keystroke logging | Lawful in most states with notice; CA and IL scrutiny | Almost always fails necessity test | Do not deploy |
| Webcam / attention tracking | Risky; several state privacy suits | Unlawful in practice (dignity, special category data) | Do not deploy |
| GPS on company phone/vehicle | Lawful during work hours; off-duty tracking restricted in several states | Lawful for fleet safety only, off-duty tracking off | Work hours only, auto-off |
| Biometrics (fingerprint, face) | Illinois BIPA consent + retention rules; TX, WA similar | Special category data; explicit consent rarely valid at work | Avoid unless legally required |
How do US monitoring rules differ by state?
Federal law (the Electronic Communications Privacy Act) allows employers to monitor communications on their own systems for business purposes, so the real constraints are state statutes on notice, biometrics and off-duty privacy. New York’s Civil Rights Law §52-c requires written notice and a signed acknowledgment before monitoring email, internet or phone use; Connecticut and Delaware have similar notice statutes. Illinois’s Biometric Information Privacy Act (BIPA) requires informed written consent, a public retention schedule and destruction rules for any biometric identifier, and its private right of action produced settlements large enough to change vendor behaviour nationally.
California adds two layers. The California Consumer Privacy Act (as amended) gives employees notice-at-collection and access rights over the personal information an employer holds, and the state’s constitutional privacy right has supported claims against intrusive home surveillance. A growing set of states (including Colorado, Virginia, Connecticut and Texas through their privacy acts, and states with “lawful off-duty conduct” statutes) limit what an employer can do with location or social-media data collected outside working hours. Multi-state employers should apply the strictest applicable rule across the whole workforce rather than maintaining state-by-state policies, a principle we also recommend in our multi-state payroll compliance guide.
What does GDPR require before monitoring remote staff in the EU and UK?
GDPR requires a lawful basis (almost always legitimate interest, not consent), a transparency notice describing the monitoring, a Data Protection Impact Assessment for systematic monitoring, data minimisation, and a documented retention period. Employee consent is rarely valid because of the power imbalance, so the employer must be able to show necessity and proportionality.
The European Data Protection Board’s guidance and national regulators (the ICO in the UK, the CNIL in France, the Dutch AP, Germany’s state DPAs) converge on a three-question test: is there a specific, documented purpose; is this the least intrusive way to achieve it; and have employees been told in plain language? The ICO’s 2023 monitoring guidance explicitly warns against continuous recording, covert monitoring except in serious misconduct investigations, and using monitoring data for purposes other than those disclosed. In Germany, the Works Constitution Act gives works councils co-determination over any technical system capable of monitoring performance, which in practice means a works agreement before rollout. Employers with staff across the 28 countries covered in our Expat HR & Global Mobility hub should treat the strictest European rule as the baseline design constraint.
Article 22 also matters: fully automated decisions with legal or similarly significant effects, such as an algorithm that flags someone for dismissal based on activity scores, require human review and an explanation. The EU AI Act layers on top of this by classifying AI systems used for monitoring and evaluating workers as high-risk, with obligations for the deploying employer as well as the vendor; see our EU AI Act HR compliance guide.
Which monitoring tools are proportionate, and which cross the line?
Proportionate tools capture business signals that already exist (ticket systems, CRM activity, code repositories, call outcomes, time entries) and aggregate them into service-level or output views. Disproportionate tools create new surveillance signals about the person: screenshots, keystrokes, webcam frames, idle-time scores and attention analytics.
A useful heuristic is the “line manager test”: would a reasonable manager sitting in the same office collect this? A manager sees whether work is delivered and whether the person is reachable during core hours. They do not photograph the screen every ten minutes or count keystrokes. Tools that replicate what an office manager could see are defensible; tools that exceed it need a specific justification, usually security or regulatory (for example, recording trading-desk communications under MiFID II or FINRA rules).
When teams do need time data, for client billing, statutory working-time records in the EU or overtime under the US Fair Labor Standards Act, choose time-tracking that records duration and task, not activity. Our time tracking software comparison flags which products offer activity-free modes, and our workforce management software comparison covers scheduling and attendance for shift-based remote roles.
How should HR write a remote monitoring policy?
A remote monitoring policy should state what is monitored, why, on which devices, who can see the data, how long it is kept, and how employees can question a decision based on it. It should be short, specific and acknowledged in writing, and it should be reviewed whenever a tool or purpose changes.
A structure that works across jurisdictions:
- Scope: company devices, company accounts and company networks only; personal devices only under a separate BYOD agreement with containerised apps.
- Purposes: information security, legal and regulatory compliance, service quality, working-time records. Do not list “productivity” unless you can define how it is measured.
- Data collected: a plain table of data types and tools by name.
- Access: which roles can view raw data and under what approval; aggregated reports for managers.
- Retention: fixed periods, with legal-hold exceptions.
- Employee rights: access, correction, challenge, and the right not to be subject to solely automated decisions.
- Investigations: when targeted monitoring can be escalated, who authorises it, and how the employee is informed afterwards.
Link the policy to your broader remote framework, covered in our remote work explained for organisations guide, and to disciplinary procedures so that monitoring data is never the sole basis for action.
Does monitoring actually improve remote productivity?
The evidence says activity monitoring does not improve output and frequently reduces it. Studies from Gartner, Microsoft’s Work Trend Index and academic work on “productivity paranoia” find that monitored employees report lower trust, more rule-breaking to game metrics, and higher intent to leave, while managers gain little decision-useful information.
What improves remote performance is clarity: written goals, visible priorities, explicit response-time norms and regular short feedback loops. These are the same levers described in our goals and OKRs guide and in managing underperformance. Monitoring tools are at best a security control and at worst a substitute for management. The organisations that have the strongest remote performance data (software companies with mature engineering metrics, customer-service operations with service-level dashboards) measure the work, not the worker.
There is also a retention cost. Employees who discover undisclosed monitoring, or who find screenshot folders of their own screens, rarely stay. Given that replacing a mid-level professional typically costs between half and two times annual salary, the retention arithmetic alone argues for restraint; see our employee retention strategies guide for the full cost model.
How do you handle monitoring for contractors, EORs and cross-border teams?
Contractors should not be monitored like employees, both because it undermines their independent status in misclassification tests and because their own privacy law applies. Employees engaged through an employer of record (EOR) are employees of the EOR, so the EOR’s policies and the local law of the employee’s country govern monitoring, regardless of where the client company sits.
For cross-border teams, map every worker to the country whose law protects them (usually the place they habitually work), apply that country’s rule, and make sure data transfers of monitoring logs out of the EU or UK are covered by standard contractual clauses or an adequacy decision. Our guides to contractor management platforms and Deel vs Rippling for global payroll discuss which platforms surface local compliance requirements, including monitoring and working-time rules, by country.
What should you do if monitoring reveals misconduct?
Follow the investigation procedure in your policy: preserve the data, limit access to those who need it, tell the employee what was found and give them a chance to respond before any decision. Monitoring evidence gathered outside the disclosed purpose, or covertly without a documented serious-misconduct justification, may be inadmissible in European employment tribunals and can convert a fair dismissal into an unfair one.
Keep in mind that most “misconduct” surfaced by activity monitors is trivial (a long lunch, a personal call) and that acting on it damages the credibility of the whole programme. Reserve investigations for security incidents, harassment, data theft and fraud, and use the performance process, not the monitoring log, for output problems.
Frequently Asked Questions
Can my employer see my screen when I work from home?
On a company device with monitoring software installed and disclosed, yes, though in the EU and UK continuous screen capture is usually unlawful as disproportionate. On a personal device without agreed software, no.
Do employees have to sign a monitoring notice?
In New York, Connecticut and Delaware written acknowledgment is required. Elsewhere it is best practice, and in the EU/UK transparency is mandatory even if a signature is not.
Can employers use AI to score remote productivity?
Only with human review of any consequential decision. In the EU, AI used to evaluate workers is high-risk under the AI Act and subject to GDPR Article 22 limits on automated decisions.
Is monitoring data discoverable by employees?
Yes. Under GDPR and the CCPA employees can request the personal data held about them, including monitoring logs, so assume everything collected will eventually be read by the person it describes.
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.


