Employee Monitoring: What’s Legal and What Isn’t
A small business owner installs software to track company laptops after a data scare, tells nobody, and three months later a departing employee’s solicitor’s letter mentions it. Nothing about the software was necessarily illegal. The way it was rolled out is what created the problem.
Whether employee monitoring is legal is not a single yes-or-no question — it depends on what you’re monitoring, whose device it’s on, whether staff were told, and critically, where you and your employees are located. This article sets out the principles that recur across most frameworks discussing employee monitoring law, so you know the right questions to ask. It is general information, not legal advice, and you should get local employment law advice before rolling monitoring out — the specifics genuinely vary by country and, within the US, by state.

- The core principles, wherever you are
- Consent and notice
- Legitimate interest and proportionality
- Company-owned devices vs. BYOD
- Working hours vs. personal time
- Vehicle and location tracking
- A rough comparison: GDPR-style vs. US at-will norms
- What getting it wrong tends to look like
- Questions people ask
The core principles, wherever you are
Employment and privacy law differs enormously between countries, and even between states within the same country. What’s more consistent is the set of questions regulators, courts and tribunals tend to come back to, regardless of the specific statute involved: did the employee have reasonable notice, was the monitoring proportionate to a genuine business need, and whose device and whose time was actually involved.
That consistency is useful, because it means you can build a defensible starting position on principle, even before you know the exact rule in your jurisdiction — and then take that starting position to someone who does know the exact rule.

Consent and notice
“Consent” in an employment context is a more complicated concept than it sounds. An employee generally cannot freely refuse something their employer requires without risking their job, which is why many frameworks treat employment consent cautiously as a legal basis on its own — it can look coerced even when nobody intends it that way.
Notice is usually the more meaningful concept in practice: telling staff, clearly and in advance, what is monitored, how, and why. Many places treat clear notice — through a written policy, an acknowledgement at onboarding, or both — as a central factor in whether monitoring is considered fair, even in places where notice isn’t a strict legal requirement.

What “clear” notice actually looks like
Vague language in an employee handbook (“the company may monitor systems as needed”) tends to carry less weight than something specific: which tools, which data, retained for how long, and who can access it. The level of specificity that holds up varies by jurisdiction, but specificity itself is rarely a mistake.
Timing matters too. Notice given at the point someone signs an employment contract, before any monitoring tool is switched on, is treated differently from notice added retroactively after a tool has already been running for months. If you’re introducing something new to an existing team, the safer approach almost everywhere is to treat it the same as a brand-new hire would be treated — told in advance, with time to ask questions, rather than informed after the fact that something has already been logging their activity.
Legitimate interest and proportionality
Even with notice given, monitoring generally needs a genuine business reason behind it — security, regulatory compliance, protecting company property, or a documented performance concern are common examples. “We wanted to see what people were doing” is not usually treated as sufficient on its own.
Proportionality is the companion idea: the monitoring should be scoped to what the stated reason actually requires. If the concern is data leaving the company through email attachments, monitoring attachment metadata is more defensible than reading the full content of every email sent, including personal correspondence sent from a work account during a lunch break.

Proportionate
Scoped to the specific risk, time-limited where possible, and the least invasive option that actually addresses the stated concern.
Disproportionate
Broader than the stated reason requires, indefinite in scope, or capturing content (message text, keystrokes, screen recordings) when metadata would answer the same question.
The test worth applying
Could you explain, out loud, to the employee being monitored, exactly why this specific tool is switched on? If not, it’s probably not proportionate yet.
Company-owned devices vs. BYOD
This is one of the clearest dividing lines across most frameworks. Monitoring a device the company owns, issued for work, used primarily for work, is the least contested category almost everywhere — it’s treated similarly to monitoring any other company asset.
Bring-your-own-device arrangements are meaningfully different. An employee’s personal phone with a work email app installed is still their phone. The generally safer approach is a “work profile” or “container” model — the operating system keeps work apps and data in a separate, managed space, and monitoring is scoped to that container only, leaving personal apps, photos, and messages untouched and invisible to the employer.

Monitoring a personal device beyond its work container — or without a separate written BYOD agreement covering exactly what’s monitored — is where employers run into the most trouble, both legally and in terms of staff trust. If BYOD is part of your setup, a specific BYOD policy, agreed to separately from the general monitoring policy, is worth the extra step.
There’s also a practical, non-legal reason to prefer the container model even where the law would allow more: staff who own the device tend to resent full-device management far more than a scoped work profile, regardless of what’s technically permitted. A policy that’s legally sound but widely resented still costs you something — usually trust, sometimes staff turnover — so it’s worth choosing the less invasive option even when a broader one is available to you.
Working hours vs. personal time
Monitoring that’s scoped to work hours, work accounts and work purposes travels much further, legally and culturally, than monitoring that follows an employee into their personal time. A company vehicle tracked during business deliveries is a different proposition from the same vehicle tracked on a Saturday grocery run, even if the tracking hardware never changes.
Where a device or account is used for both work and personal purposes — which is common with phones especially — the practical answer is usually to draw the line at the account or profile, not the clock. Monitoring the work email account, at any hour it’s used, is more defensible than monitoring a personal social media account during declared “working hours,” because the former is scoped by purpose and the latter only by time, which is a weaker boundary.

Vehicle and location tracking
Fleet and vehicle tracking is common and, for company vehicles used for business purposes, broadly well accepted — many frameworks treat it similarly to other asset-tracking tools, provided staff are told it exists. The friction usually comes from two places: tracking continuing after hours or during personal use of a company vehicle, and tracking through a personal phone rather than dedicated vehicle hardware.
A commonly seen approach that tends to reduce friction: tracking switches on with a work trip (e.g. clocking in, or starting a delivery run) and off at the end of it, rather than running continuously regardless of whether the vehicle is being used for business or personal purposes.
A separate question worth thinking through in advance: what happens to the location data once it’s collected. A policy that states a retention period — thirty days, ninety days, a full year for audit purposes — is generally viewed more favourably than one that says nothing, which tends to be read as indefinite retention by default. Being explicit here costs little and closes off one of the more common points of challenge.
A rough comparison: GDPR-style vs. US at-will norms
It’s worth understanding, in broad strokes, that two different starting assumptions exist around the world, because the same monitoring tool can be well within the rules in one and legally risky in the other.
| Aspect | GDPR-style / notice-based regimes | Typical US at-will norms |
|---|---|---|
| Baseline assumption | Monitoring restricted unless justified and proportionate | Employer generally has wide latitude on company equipment |
| Notice | Often expected or required, in writing | Best practice; not universally required, and varies by state |
| Covert monitoring | Restricted to narrow, serious circumstances, often with extra safeguards | More state-dependent; some states restrict specific methods (e.g. audio recording) more than general monitoring |
| Personal devices | Strongly protected outside a documented BYOD agreement | Also protected, though the mechanism (contract vs. statute) varies by state |
| Enforcement | Data protection authorities and employment tribunals | State labor agencies, courts, and sector-specific regulators |
Treat this table as orientation, not a rulebook — actual obligations depend on the specific country, and within the US, the specific state, plus any sector-specific rules (healthcare and finance, for instance, often carry extra layers). A remote team spread across several states or countries can genuinely be subject to several different rule sets for the same monitoring programme.
This is where many small businesses first realise their monitoring approach can’t be a single, one-size-fits-all decision. A company with a single office in one state or country can generally apply one policy uniformly. A distributed team hired across state lines, or across borders, often needs the policy to flex — the underlying tools might stay the same, but the notice period, the retention rules, or even whether a specific feature is switched on at all can reasonably differ by where a given employee is based. Building that flexibility into the policy from the outset is considerably easier than retrofitting it after a complaint from one location surfaces a gap that was already there for everyone.

What getting it wrong tends to look like
The pattern that recurs across cases and complaints isn’t usually “the company used an illegal tool.” It’s monitoring introduced without notice, scoped more broadly than the stated reason justified, or applied to a personal device without a clear agreement — any one of which turns an otherwise defensible tool into a source of genuine legal exposure and, just as damaging, a workplace where people no longer trust what they’re told.
There’s also a quieter version of this that rarely ends up in a tribunal but does real damage anyway: monitoring that technically complies with every rule but is applied inconsistently — strictly enforced against some staff and quietly ignored for others. Even where the underlying policy is legally sound, uneven enforcement is one of the fastest ways to turn a reasonable monitoring programme into a source of genuine grievance, because it stops looking like oversight of the work and starts looking like scrutiny of specific people.

The practical fix is almost always process, not technology: define the need, consult where you can, confirm the specifics locally, and give notice before switching anything on. Putting that into a clear written policy — and getting your team to actually accept it rather than merely sign it — is its own skill, and one worth getting right before rollout.
Questions people ask
Is it legal to monitor employee email at all?
In most places, yes, for company email accounts used for work, provided there’s a legitimate business reason and staff have reasonable notice. The details — how much notice, what counts as legitimate, whether personal emails sent from a work account get extra protection — vary enough by jurisdiction that this is worth a direct check with local counsel.
Do I need employees to sign something before monitoring starts?
A written acknowledgement is common practice and strengthens your position almost everywhere, even where it isn’t strictly mandated by law. It also tends to reduce disputes later, since there’s a clear record of what was communicated and when.
Can I monitor a personal phone if an employee checks work email on it?
Generally not the whole device, and not without a specific BYOD agreement. The more defensible approach is a managed work profile that keeps monitoring scoped to work apps and data, leaving the rest of the personal phone untouched.
Is covert monitoring ever legal?
In some places, in narrow circumstances — usually tied to a specific, serious suspicion (like ongoing theft or fraud) rather than general oversight — with extra safeguards attached. It is far more restricted than open monitoring almost everywhere, and getting this wrong carries real legal and reputational risk, so treat it as a question for a lawyer before acting, not a default option.
Does this apply the same way to contractors and freelancers?
Not automatically — contractors are often governed by a different legal relationship (contract law rather than employment law), and monitoring arrangements need their own explicit agreement, typically in the contract itself, rather than an assumption that the employee policy extends to them.
What’s the single most common mistake small businesses make here?
Rolling monitoring out quietly and explaining it only if someone asks. Notice given upfront, even briefly, resolves the majority of disputes before they start — it’s consistently the cheapest and most effective step available.

Where to go from here
Treat this article as a map of the questions worth asking, not a finished answer for your business. The next practical step is usually two things in parallel: get specific local legal advice for your jurisdiction, and put the principles above into a written policy your team can actually read and agree to. If you’re evaluating tools, our features page sets out what transparent, consent-based monitoring looks like in practice, and our FAQ covers the questions we’re asked most often.

