An employer may monitor employees, but not without limits. Monitoring needs a specific purpose, a legal basis and must be proportionate. Employees must be informed in advance, against signature or in another way that proves they were informed, with all the information listed in Article 13(1) and (2) GDPR (Article 5(4) ADTAĮ; Article 13(1) GDPR). The Lithuanian supervisory authority (VDAI) requires a data protection impact assessment for employee monitoring. The secrecy of personal correspondence stays protected on a work computer or phone as well (Article 27(2) of the Labour Code, DK).
The line usually runs through the purpose, not the technology. A camera that protects a warehouse and a camera a manager uses to check in real time where an employee is are two different processing operations. The same goes for GPS, call data and e-mail. Below: what the law requires, where the line is and what follows if it is crossed.
What the law requires
The Labour Code sets the base: the employer must respect employees’ rights to private life and to the protection of personal data (Article 27(1) DK). When the employer exercises its rights over the information and electronic communications technologies used at work, it may not breach the secrecy of employees’ personal correspondence (Article 27(2) DK). This applies to remote work too: the remote work arrangements must not breach the employee’s data protection or right to private life (Article 52(6) DK).
The GDPR allows Member States to set more specific rules for employee data (Article 88(1) GDPR). Such rules must pay particular attention to transparency and to monitoring systems at the workplace (Article 88(2) GDPR). In Lithuania, monitoring is covered by Article 5(4) ADTAĮ. It covers video and audio data at the workplace and in premises or areas where employees work, as well as monitoring of employees’ behaviour, location or movement. The same rule applies to people working under relationships equivalent to employment (Article 5(5) ADTAĮ).
The GDPR adds four more requirements:
- Purpose. Data is collected for specified, explicit purposes and not further processed in a manner incompatible with them (Article 5(1)(b) GDPR).
- Quantity. Only what the purpose needs is collected (Article 5(1)(c) GDPR).
- Legal basis. An employee’s consent almost never works here. The EDPB Guidelines 3/2019 on video devices state that employers should in most cases not rely on consent, because it is unlikely to be freely given. In practice the basis is legitimate interest (Article 6(1)(f) GDPR) or, where a law requires the monitoring, a legal obligation. Public authorities performing their tasks cannot rely on legitimate interest (Article 6(1), last subparagraph, GDPR). Why consent fails, we explained in the article on employee consent.
- Impact assessment. The VDAI list has a separate item: processing of employee data for monitoring or control purposes, including video and audio data at the workplace and monitoring of employees’ communication, behaviour, location or movement (item 10 of the list approved by VDAI order No 1T-35). Telephone call recording (item 7) and video surveillance combined with audio recording (item 6.3) are listed separately. The assessment is carried out before processing starts (Article 35(1) GDPR). If it shows a high risk that cannot be reduced, the employer must consult VDAI before starting (Article 36(1) GDPR).
An employer with an average of twenty or more employees must inform and consult the works council when it approves or changes the procedure for monitoring and control of employees at the workplace, or sets measures that may affect the protection of employees’ private life (Article 206(1) DK). The works council is informed ten working days in advance (Article 206(2) DK). Where there is neither a works council nor an employee trustee, the information goes to the trade union operating at employer level (Article 206(4) DK).
Where the line is: four forms of monitoring
Video cameras. Protecting property and people is usually a legitimate purpose. Continuous watching of an employee’s work is not: the Article 29 Working Party says monitoring should be selective rather than continuous (WP 249, section 3.1.1). The EDPB Guidelines 3/2019 note that an employee in most cases does not expect to be monitored by the employer at the workplace, and that monitoring in sanitary facilities is a serious restriction of rights. A camera installed to protect a warehouse cannot become a tool to check whether an employee works fast enough: that is a different purpose. The longer recordings are kept, the more justification is needed. The guidelines say that keeping them longer than 72 hours requires more argument. On signage, see our article on where to place video surveillance signs. Who must get what when CCTV footage is requested is covered in Requests for CCTV footage: who must get what.
GPS and vehicles. The Article 29 Working Party, in Opinion 2/2017 on data processing at work (WP 249), repeating its earlier Opinion 13/2011, states that vehicle tracking devices are not staff tracking devices: employers should not use them to track the behaviour or whereabouts of drivers. This is a 2017 Working Party opinion adopted before the GDPR applied. It is not among the documents the EDPB endorsed on 25 May 2018 (Endorsement 1/2018). Like other supervisory guidance, it is not binding: it is interpretive guidance. Where a car may also be used privately, the employee should in principle be able to switch tracking off temporarily when special circumstances justify it, such as a visit to a doctor. According to the opinion, there is unlikely to be a legal basis for tracking a vehicle’s location outside agreed working time. If it is nevertheless necessary, for example against theft, the measures must be proportionate to the risk: the opinion gives the example of recording the location outside working hours only when the car leaves a widely defined area (a region or even the country). Informing needs particular attention: the purposes and retention periods for GPS may be set out in the records of processing activities while the employees have not been made aware of them. The records are an internal document, made available to VDAI on request (Article 30(4) GDPR). They inform nobody. Article 5(4) ADTAĮ requires informing the employee directly and being able to prove it.
Calls. Call recording requires an impact assessment, even if only customer service calls are recorded. Monitoring can also happen without recordings: a company may want to assess productivity by the number, length and numbers of calls. When one client planned such a project, we prepared these first questions:
- is the purpose a set of specific indicators, or a general “productivity assessment”;
- are the actual numbers really needed, or would the count and length of calls be enough;
- how are private calls separated if the work phone may also be used privately;
- is the data assessed per person or at team level;
- what will the consequences be for the employee, and will a human take the decision.
The last question is not a formality. The employee has the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them (Article 22(1) GDPR). If the consequences are not yet defined, proportionality cannot be assessed either.
E-mail and IT systems. A work mailbox and computer belong to the employer, but the secrecy of personal correspondence remains (Article 27(2) DK). WP 249 gives an example: monitoring all of employees’ online activity, even to protect the network, is a disproportionate response. Where misuse can be prevented, for example with internet filters, the employer has no general right to monitor. Prevention first, checking second. It must be clear in advance who may open an employee’s mailbox or logs, when and on what basis. What happens to an employee’s mailbox and files after they leave is covered in When an employee leaves: mailbox, files, accounts and their data.
What happens when the line is crossed
Monitoring starts before informing. Employees are told after the system is already running, or told orally, or the notice lacks the Article 13 GDPR information. That breaches Article 5(4) ADTAĮ and Article 13 GDPR. For breaches of data subject rights under Articles 12–22 and of the basic principles, the GDPR provides for fines of up to twenty million euros or, for an undertaking, up to 4 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5) GDPR). Public authorities and bodies in Lithuania face lower caps (Article 33(2) ADTAĮ), unless they carry on commercial activity (Article 33(3) ADTAĮ). What employees must be told, and when, is covered in Informing employees about data processing: what to say and when.
No impact assessment. The Article 35 GDPR obligation falls in the fine tier of up to ten million euros or, for an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). Public bodies face a lower cap (Article 33(1) ADTAĮ). An assessment written after an inspection does not show that the risks were assessed before processing started.
The purpose has grown. Security cameras or GPS data start being used for performance reviews or disciplinary action. That is a different purpose, which needs its own basis and its own information (Article 5(1)(b) GDPR). A disciplinary case built on such recordings becomes open to challenge.
Claims by the employee. Unlawful surveillance of a person and breach of the confidentiality of telephone conversations or correspondence count as a violation of private life (Article 2.23(2) of the Civil Code, CK). This is a ground to claim compensation for pecuniary and non-pecuniary damage (Article 2.23(4) CK). Under the GDPR, a person who suffered damage also has a right to compensation (Article 82(1) GDPR).
A ban on processing. VDAI may order that processing be brought into compliance (Article 58(2)(d) GDPR) or impose a temporary or definitive limitation, including a ban (Article 58(2)(f) GDPR). A system already installed is then simply switched off.
When to call a lawyer
- before introducing a new monitoring tool: cameras at workstations, GPS, call recording or analysis, e-mail or computer monitoring;
- when you want to use monitoring data for performance reviews, bonuses or disciplinary action;
- when work equipment may also be used privately;
- when you need an impact assessment or a consultation with the works council;
- when an employee complains, asks for their recordings or has gone to VDAI.
Frequently asked questions
May an employer watch employees through cameras in real time?
Only if it is necessary for a specific legitimate purpose, such as security, and only as far as needed. Continuous real-time watching of employees’ work to check where they are and what they do is usually disproportionate. In any case, employees must be informed in advance, against signature or in another way that proves it (Article 5(4) ADTAĮ; Article 13(1) GDPR), and an impact assessment is needed before starting.
May an employer read an employee’s work e-mail?
Only on a specific basis that employees were told about in advance, for example when investigating a specific incident. The secrecy of personal correspondence is protected on work equipment too (Article 27(2) DK). The procedure for who may access the mailbox and when must be set in advance, not invented when a dispute arises.
Does an employee have to consent to GPS tracking?
No. Consent in employment is usually not valid, because it is not free. Another basis is needed, most often legitimate interest with a written assessment, plus informing against signature or in another way that proves it, with all the Article 13(1) and (2) GDPR information (Article 5(4) ADTAĮ). The employee’s signature here means they were told, not that they agreed.
Does call recording require an impact assessment?
Yes. Telephone call recording is a separate item on the VDAI list. The assessment is carried out before recording starts. If recordings or call data are also used to assess employees, that is employee monitoring as well, and the assessment must cover it.
How to start
List the monitoring tools you use or plan: cameras, GPS, call recording or analysis, e-mail and computer controls. Send us the notices given to employees and any assessments already made. We will tell you where the line has been crossed, what is missing and which processing needs an impact assessment.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: Data protection impact assessment.