1. Home
  2. Knowledge Base
  3. Privacy & Trust
  4. Is it Legal to Track Staff Productivity in the UK? (GDPR Explained)

Is it Legal to Track Staff Productivity in the UK? (GDPR Explained)

The Short Answer

Yes — it is legal to monitor staff productivity in the UK, including with software like mi.team. But “yes, if…” is a more honest answer than a flat “yes.”

UK data protection law does not ban employee monitoring. What it does is set out, in real detail, exactly how you have to do it. Get the fundamentals right — a proper legal basis, real transparency with your staff, and a purpose you can defend — and you are on solid ground. Skip any of those, and you are exposed, regardless of which software you use.

This guide walks through what the Information Commissioner’s Office (ICO) actually says about monitoring workers, not the watered-down version that gets repeated on software marketing pages. Where it’s useful, we’ll link straight to the ICO’s own guidance so you can check it for yourself — that’s the whole point of this article.

One note before we start: the ICO has flagged that this guidance is currently under review following the Data (Use and Access) Act, so some detail may be updated. We’ll keep this article current, but always check the ICO’s live guidance for anything you’re relying on directly.

Who Actually Regulates This?

Employee monitoring in the UK sits under UK GDPR and the Data Protection Act 2018, and it’s regulated by the ICO. For over a decade, the ICO’s position on workplace monitoring lived inside its 2011 Employment Practices Code. That code was written before hybrid working, AI categorisation, or software like mi.team existed, so in 2023 the ICO replaced it with dedicated guidance called “Data protection and monitoring workers.”

It’s worth reading because it’s genuinely practical — it uses “must,” “should,” and “could” deliberately, so you can tell the difference between a hard legal requirement and good practice. We’ll use the same distinction below.

Step 1: You Need a Lawful Basis — And “Because We’re Paying Them” Isn’t One

Before you collect a single data point about how your staff use their computers, you have to identify a lawful basis under UK GDPR. There are six available: consent, contract, legal obligation, vital interests, public task, and legitimate interests.

For almost every business reading this, only one of those genuinely applies: legitimate interests.

Here’s why the others usually fall away:

  • Consent is the one most businesses assume they need, and it’s usually the wrong choice. The ICO is explicit that consent isn’t freely given if there’s a power imbalance between the person asking and the person agreeing — and an employment relationship is the textbook example. If your staff would feel they had no real choice but to say yes, it isn’t valid consent.
  • Contract only applies if monitoring is genuinely necessary to fulfil your side of the employment contract. The ICO’s own example is a business that tried to justify video surveillance this way — and it didn’t hold up, because there were less intrusive ways to achieve the same goal.
  • Legal obligation, vital interests, and public task apply to specific, narrow situations (regulatory record-keeping, life-safety monitoring, public sector functions) that don’t cover general productivity tracking.

That leaves legitimate interests — the basis the ICO itself flags as most likely to apply to workplace monitoring. But it comes with a catch: unlike the other five bases, legitimate interests requires you to actively weigh your business need against your employees’ rights, not just tick a box. The ICO sets this out as a three-part test:

  1. Purpose test — Is there a real, legitimate business reason behind the monitoring?
  2. Necessity test — Is monitoring actually necessary to achieve that purpose, or is there a less intrusive way to get there?
  3. Balancing test — Does your interest in monitoring outweigh the impact on your employees’ privacy?

If you can’t honestly answer all three, legitimate interests doesn’t apply — and neither does anything else. That’s the point at which a lot of “Big Brother” monitoring setups fall apart before they’ve even started.

Step 2: Watch Out for Special Category Data

This is the trap that catches out most businesses using traditional screenshot or keystroke-logging tools, and it’s rarely explained clearly.

UK GDPR gives extra protection to what it calls “special category data” — information revealing things like health conditions, trade union membership, religious belief, or sexual orientation. If your monitoring is likely to capture any of this, even by accident, you need a specific legal condition on top of your lawful basis, before you start monitoring — not after.

Think about what a screenshot tool actually captures: a browser tab about a medical appointment, an email thread with a union rep, a WhatsApp message about a pregnancy. None of that was the point of installing the software — but if your tool takes indiscriminate screenshots or logs every keystroke, you’re processing special category data whether you intended to or not, and the law doesn’t care that it was accidental.

This is exactly why the ICO names keystroke monitoring specifically as an example of high-risk processing later in its guidance. It isn’t a footnote — it’s called out because it routinely sweeps up sensitive personal data that has nothing to do with productivity.

Step 3: Work Out If You Need a DPIA

A Data Protection Impact Assessment (DPIA) is a structured process for identifying and reducing the risks of a data processing activity before you start it. It isn’t optional busywork — the ICO requires one before you begin any monitoring likely to be high-risk, and gives four examples directly relevant to productivity software:

  • Processing biometric data
  • Keystroke monitoring
  • Monitoring that could lead to financial loss for a worker (e.g. performance management decisions)
  • Using profiling or special category data to decide who gets access to something

If your monitoring touches any of those, a DPIA isn’t a “should” — it’s a “must,” and if the DPIA turns up a risk you can’t reduce, you’re required to consult the ICO before going ahead. Even outside those categories, the ICO recommends doing one anyway, because it’s a useful way to catch problems before your staff do.

Step 4: Tell People — Properly

This is the one most businesses get instinctively right and then quietly water down. The ICO’s position is unambiguous: outside a small number of exceptional circumstances, you must tell workers about monitoring before it happens, in a way that’s clear and genuinely easy to understand — not buried in page 14 of a staff handbook nobody reads.

Transparency isn’t just a legal box to tick. The ICO’s guidance repeatedly ties it directly to trust: monitoring carried out without transparency is treated as unfair by definition, and unfair processing is non-compliant regardless of how good your lawful basis looked on paper.

Practically, that means workers should know:

  • That monitoring is happening
  • What is actually being collected
  • Why you’re collecting it
  • What you do with it

The ICO also recommends — though doesn’t strictly require — that you involve staff or their representatives in the decision to introduce monitoring in the first place, and document that conversation as part of your DPIA. Businesses that skip this step tend to be the ones that get the “quiet rollout over the weekend” wrong, and end up with a morale problem on Monday morning that a five-minute conversation the week before would have avoided.

Step 5: Covert Monitoring Is Not the Shortcut It Looks Like

Covert monitoring — watching staff without telling them — is not illegal outright, but the ICO is blunt that it’s very difficult to justify in ordinary circumstances. It’s really only defensible where you have genuine grounds to suspect criminal activity or gross misconduct, and even then, strict conditions apply: it has to be authorised at senior management level, backed by a DPIA, tightly time-limited to the investigation, and stopped the moment the investigation ends. You also can’t use it to snoop on places or communications staff would reasonably expect to be private — changing rooms, personal emails, and so on.

If your reason for wanting monitoring is “I think someone might be underperforming,” that’s not covert-monitoring territory — that’s a performance conversation, backed by transparent data everyone already knows you’re collecting.

Step 6: Your Staff Have Rights Over the Data You Collect

Two rights matter most in practice:

Subject access requests. If a worker asks to see the personal data you’ve collected about them through monitoring, you generally have to provide it. This is worth thinking about at the buying stage — if your monitoring tool dumps everything into an unstructured pile of screenshots, honouring a request like this becomes a genuine headache. Tools where employees already have their own dashboard sidestep this problem almost entirely.

The right to object. Where you’re relying on legitimate interests (which, as above, is most productivity monitoring), workers can object to being monitored on grounds specific to their situation. You can only refuse if you can demonstrate a compelling interest that overrides theirs, or if it’s needed for a legal claim — and you have to tell them your decision and their right to complain to the ICO either way.

The “Fairness” Test the ICO Keeps Coming Back To

Running through all of the above is a simpler idea: even if something is technically permitted, it still has to be fair, and fair means proportionate. The ICO’s own guidance includes an example of an employer who, after discovering a few remote staff were starting later than their timesheets said, rolled out webcam checks for the whole team. The ICO’s view: disproportionate, because there was a far less intrusive option available — simply checking system login times and giving staff the chance to explain any gaps.

That’s the mindset worth applying to your own monitoring decisions. The question isn’t “can this software see it?” — it’s “do I need to see this to achieve my actual purpose, or is there a less intrusive way to get there?”

A Practical Compliance Checklist

Based on the ICO’s own checklist, here’s what “doing this properly” looks like in practice:

  • You’ve identified a genuine purpose for monitoring, and confirmed there isn’t a less intrusive way to achieve it.
  • You’ve worked out whether you need a DPIA, and either done one or documented why you didn’t.
  • You’ve identified your lawful basis (for most businesses, legitimate interests) and, if relevant, a special category condition.
  • You’ve documented exactly what data you collect and why.
  • Your staff have been told, clearly, that monitoring is happening, what it covers, and why — before it starts.
  • You’ve thought about data minimisation: you’re not collecting more than you need “just in case.”
  • You have a retention schedule, so data doesn’t sit around indefinitely.
  • If you’re using third-party software, you haven’t assumed it’s compliant by default — you’ve checked.

None of this is about finding a clever workaround. It’s about being able to defend, in plain English, exactly what you’re doing and why — to your staff, and to the ICO if it ever asks.

Frequently Asked Questions

Can I monitor staff without telling them?

In almost all circumstances, no. The ICO treats undisclosed monitoring as unfair by default. Covert monitoring is only defensible in narrow situations involving suspected criminal activity or gross misconduct, and it comes with strict conditions attached.

Usually not, and in most cases you shouldn’t rely on consent at all. Because of the power imbalance in an employment relationship, the ICO doesn’t consider workplace consent freely given in most circumstances. Legitimate interests is the basis most monitoring actually relies on.

Is it illegal for monitoring software to take screenshots?

Screenshots themselves aren’t illegal, but they carry high compliance risk because they routinely capture special category data — health information, union activity, and similar — that requires extra legal protection. This is one of the main reasons many businesses are moving toward tools that track activity patterns rather than capturing raw screen content.

What happens if I get this wrong?

Non-compliant monitoring is a data protection breach like any other, and can result in an ICO investigation, enforcement action, and reputational damage with your own staff — who now have documented grounds to distrust how the business handles their data.

Does this apply to small businesses too?

Yes. The ICO’s guidance doesn’t set a size threshold — it applies to any organisation processing workers’ personal data through monitoring, whether that’s two people or two thousand.

Where This Leaves You

Employee monitoring in the UK isn’t a legal minefield to be avoided — it’s a legal framework to be followed. Most of what trips businesses up isn’t malicious; it’s assuming a software vendor’s marketing claim of “GDPR compliant” does the legal thinking for them. It doesn’t. Compliance sits with you as the employer, regardless of which tool you use.

If you want to see what a genuinely transparent rollout looks like in practice, we’ve written up exactly how we approach this at mi.team, stage by stage. And if you’re weighing up whether monitoring software is the right call for your business at all, our honest breakdown of who it’s built for — and who it isn’t — is a good next read.

Was this article helpful?

Related Articles