4.2. When and what monitoring activities are permissible?
Modern technologies enable employees to be tracked over time, across workplaces and their homes, through many different devices such as smartphones, desktops, tablets, vehicles, and wearables.255
Monitoring activities are forms of personal data processing that can occur during the recruitment process (e.g. if an employer checks data of aspirant employees on social media), for the length of the contractual relationship (e.g. video surveillance, GPS on vehicles used by employees) and even after the end of the working relationship (e.g. if an employer monitors former employees’ LinkedIn profiles to ensure that they are not infringing a non-competition clause).256
In certain situations, the employer may be legally obliged to perform certain forms of tracking (e.g. install tracking technologies in vehicles to be sure that a driver does not exceed a certain number of driving hours per day).
In other cases, the employers may have a legitimate interest in monitoring employees (e.g. for security reasons; for safety reasons; to prove unlawful conduct of an employee). However, monitoring employees poses risks from a fundamental rights perspective. Systematic or occasional monitoring can infringe upon the privacy rights of an employee, and limit employees’ channels by which they could inform employers about irregularities or illegal actions of superiors and/ or colleagues threatening to damage the business or workplace.257
An employer, who seeks to install a GPS in a company car to control the progress and circumstances of work of the employees, may invoke the legitimate interest as a legal basis.
However, the employer must first evaluate whether the data processing is necessary for the purposes designated, and whether its implementation by a GPS device is proportionate to the limitations imposed on the rights of the employees.
Employers must inform their employees of the installation of tracking devices in the company cars and must make clear that, while the employees use the vehicle, their movements are recorded.
The situation would be different if the employees were allowed to use company cars for private purposes, too. In this case, the employer could not invoke the legitimate interest because the implementation of a GPS device that would track a company car at all times would be disproportionate.
Whilst there are national differences concerning whether an employer can monitor their employees, the common traits are that: » policies and rules concerning legitimate monitoring must be clear and readily accessible, ideally elaborated by the employer together with the representatives of the employees; and » privacy-friendly organizational solutions have to be preferred to the monitoring of the employees. For example, an employer may opt for the introduction of filters upon websites accessible from the workplace rather than monitoring all the web activities of the employees. Consider what other options are available to achieve the same goal.
Annex I – National laws
The General Data Protection Regulation replaced the Data Protection Directive on 25 May 2018. While it harmonized data protection rules and became ‘directly applicable’ across the EU/EEA, some differences remain among national laws specifying data protection rules. For this reason, when adhering to data protection rules, national laws implementing the GDPR must be consulted. Below is an overview of such laws, prepared by VUB-LSTS.258
About the editors
Lina Jasmontaitė-Zaniewicz is a doctoral candidate at the Vrije Universiteit Brussel. Her PhD research concerns primarily the data breach notification obligations foreseen in the General Data Protection Regulation. Lina is a Certified Information Privacy Professional (CIPP/E, IAPP). She has served as an advisor for European projects on regulatory and ethical questions concerning the use of personal data. After obtaining an LLM in Law and Technology (cum laude) at Tilburg University, she completed the traineeship program at the European Data Protection Supervisor. She worked as a legal intern in a Brussels-based European privacy and data security practice in 2013. She worked as a legal researcher at the Leuven University (CiTiP) in 2014-2016.
Alessandra Calvi is a doctoral candidate at the Vrije Universiteit Brussel (VUB). Alessandra holds an LLM in International and European law – Data law (summa cum laude) awarded by the Institute of European Studies of the VUB. After obtaining a law degree from the Università Cattolica del Sacro Cuore of Milan (2015), she completed a law clerkship at the Tribunal of Pavia, in the Labour law section in 2016-2017). She also completed traineeships in a criminal law firm and at the European Data Protection Supervisor. Her research interests include the interrelationships between law and technology, in particular between data protection and the circular economy.
Renáta Nagy has been working at the Hungarian DPA (NAIH) since 2017. She has been responsible for the administrative management of the STAR II project, as well as for liaising between Hungarian SMEs and SME associations. She coordinated the operationalization of the SME hotline set up at NAIH’s premises, also being actively involved in replying to the enquiries received. She has delivered presentations about the SME hotline and the most common enquiries received during the awareness-raising and informational events for SMEs organized by NAIH in partnership with the Chambers of Commerce and Industry.
David Barnard-Wills has over a decade’s experience in research on privacy and data protection. He has designed and delivered GDPR training for multiple clients, and his research work has explored the way in which data protection authorities work together; how data protection can best be communicated to different audiences; cyber security; and practical ways to undertake privacy-by-design. He is a Senior Research Manager in the Policy, Ethics and Emerging Technologies team at Trilateral Research. David holds a PhD in Politics from the University of Nottingham and has previously been a Research Fellow at the University of Birmingham, Cranfield University, and the UK’s Parliamentary Office of Science and Technology.