Yes, employers in the UK can use workplace-monitoring technology, including keystroke logging, screenshots, productivity software and some AI-assisted systems. But there is no blanket right to monitor everything simply because a device belongs to the company.

Current data-protection rules require monitoring to be lawful and fair. The Information Commissioner's Office (ICO) says employers should be clear about the purpose, use the least intrusive means that can achieve it, identify a lawful basis, minimise the information collected and tell workers about monitoring. High-risk monitoring can require a Data Protection Impact Assessment (DPIA).

The important new development is that the UK government is now considering whether those existing rules are enough. A public consultation opened on 8 July 2026 and closes at 11:59pm on 30 September 2026. It covers England, Scotland and Wales and explicitly includes digital activity monitoring, biometric systems, location tracking, automated performance evaluation and AI-driven or algorithmic management.

Rules check: 10 August 2026. The consultation is not new law. The government says the options are still under consideration and that it will develop a final policy proposal after reviewing responses.

The quick answer: what can an employer monitor today?

The ICO's current worker-monitoring guidance gives a useful starting point: data-protection law does not prohibit workplace monitoring, but the monitoring must comply with data-protection requirements.

The technology itself is not the deciding factor. Purpose, intrusiveness, data collected, worker expectations and how the information is used all matter.

Monitoring methodAutomatically illegal?Why scrutiny rises
Login and access recordsNoUsually easier to justify for security or access control if collection is limited to the purpose
Website or application usageNoCan reveal much more than the stated productivity or security purpose if collected broadly
Random screenshotsNoMay capture personal messages, health information, union activity or unrelated private material
Keystroke loggingNoThe ICO specifically lists keystroke monitoring as an example of processing that can be high risk
Webcam monitoringNoHighly intrusive, especially in a home where family or private life may be captured
GPS or location trackingNoContext matters: location may be necessary for some field roles but difficult to justify for ordinary office work
Biometric access systemsNoBiometric data used for identification or authentication is special-category data and receives extra protection
AI productivity or performance scoringNoRisk rises sharply when outputs influence pay, discipline, promotion, dismissal, shifts or other significant decisions

This is why a simple question such as “Can my employer monitor my laptop?” has no useful yes-or-no answer. A security log showing when a corporate laptop connects to a network is very different from continuously capturing its webcam, keys and screen.

The five tests that matter more than the software name

1. What is the actual purpose?

An employer needs a defined reason for processing personal information. Security, fraud prevention, regulatory compliance, health and safety, timekeeping and performance management can all create legitimate monitoring use cases, but naming a business objective does not automatically make every monitoring technique proportionate.

The ICO gives a particularly clear example. If an employer wants to check whether remote staff start work on time, automatically taking webcam images is likely to be disproportionate when computer login records can answer the same question less intrusively.

That gives a useful general rule:

The stronger the mismatch between the problem and the surveillance method, the harder the monitoring is to justify.

2. Is there a lawful basis for using the data?

Employers must identify a lawful basis for processing personal information. The ICO warns against treating consent as the default answer in employment because the power imbalance can make genuinely free consent difficult.

If monitoring is likely to capture special-category information — for example health data, trade-union membership, religious beliefs or biometric data used for identification — an additional condition for processing is required.

A clause buried in an employment contract is not a magic permission slip for unlimited surveillance.

3. Is the monitoring proportionate and data-minimised?

The availability of a monitoring feature does not mean it should be switched on.

A product may offer screenshots every 30 seconds, application histories, web logs, keystrokes, location, webcam captures and an AI-generated productivity score. A company still has to assess which information is actually necessary for its stated purpose.

This matters because commercial monitoring suites often bundle many functions together. The ICO says the employer generally remains responsible for deciding how and why the information is processed even when a third-party monitoring service provides the technology.

4. Have workers been told what is happening?

Transparency is a central part of the current framework. ICO guidance says workers should receive information about monitoring before it starts when an employer decides to proceed after its assessment.

Acas similarly advises employers to tell employees about monitoring arrangements and their purpose, with covert monitoring reserved for extremely limited circumstances such as suspected criminal activity.

A vague sentence saying “company systems may be monitored” is very different from explaining what is collected, when collection happens, who can see it, how long it is retained and whether it affects employment decisions.

5. Does the monitoring feed an automated decision?

This is increasingly the most important distinction.

A system that measures activity and produces a dashboard for a manager is not the same as one that automatically changes pay, allocates shifts, issues sanctions or makes another significant decision without meaningful human involvement.

The UK's Data (Use and Access) Act 2025 changed the automated-decision framework, and all of its data-protection provisions were in force by June 2026. The ICO says the changes allow significant solely automated decisions in a wider range of circumstances for non-special-category data, provided the organisation has an appropriate lawful basis and safeguards.

Those safeguards include giving the affected person information about the decision and enabling them to make representations, obtain human intervention and contest the decision. Restrictions remain tighter when special-category information is involved.

This is also an area where some older ICO worker-monitoring pages are explicitly marked under review because of the Data (Use and Access) Act. For a live employment decision, the latest ICO material and professional legal advice matter more than an older summary page.

Home working changes the privacy calculation

Remote work does not make employer monitoring impossible, but it can make the same monitoring technique more intrusive.

The ICO says workers' privacy expectations are likely to be higher at home and that remote monitoring creates a greater risk of accidentally capturing family and private-life information. It recommends considering that risk as part of a DPIA.

That distinction is easy to miss when monitoring software runs identically everywhere.

A camera pointed at a warehouse entrance and a webcam taking periodic pictures inside a worker's bedroom may technically collect images, but they create very different privacy risks. The same is true for always-on audio, screen capture and software installed on a personal device used for work.

When is a DPIA especially important?

A DPIA is a structured assessment of what personal information is being processed, why, the risks created and how those risks will be reduced.

The ICO says a DPIA must be carried out before processing that is likely to create a high risk to workers or other people. Its worker-monitoring guidance gives examples that can include:

  • biometric processing;
  • keystroke monitoring;
  • monitoring that could lead to financial loss, including some performance-management uses;
  • profiling or special-category data used in consequential decisions.

Even where a DPIA is not clearly mandatory, the ICO recommends it as a practical way to test whether the monitoring is necessary and proportionate.

What the 2026 consultation could actually change

The government's consultation is important because it is not asking only whether workplace monitoring is good or bad. It is comparing different ways to make worker voice and employer obligations clearer.

The consultation document presents three main intervention models, while explicitly leaving no intervention as a possible outcome.

Option being consideredWhat it would doIs it law today?
Statutory code of practice + guidanceSet higher-level standards for responsible monitoring. Employment tribunals could take the code into account in relevant cases, supported by more detailed non-statutory guidance.No
Legislative duty to consult and negotiateCreate a mandatory worker-engagement requirement when monitoring technology is introduced or materially changed, with the exact trigger and scope still to be decided.No
Non-statutory guidanceTranslate existing duties into practical examples, toolkits and sector-specific guidance without creating a new binding duty.No
No additional interventionLeave the present legal framework in place without a new workplace-monitoring regime.Still a possible outcome

The government says the inclusion of these options does not indicate a settled preference.

That sentence matters. Headlines saying the UK “will force employers to negotiate before using surveillance” go further than the consultation currently does. A legal consultation-and-negotiate duty is one option, not an enacted requirement.

Why AI makes ordinary employee monitoring more consequential

Traditional monitoring often answers a narrow question: Was a badge used? Was a vehicle at a location? Was a corporate account accessed?

AI and algorithmic management can turn the same raw signals into judgments:

activity data → inferred behaviour → score or recommendation → employment decision

That creates three additional failure points.

The measurement can be wrong

Low keyboard activity does not necessarily mean low productivity. A designer sketching, an engineer reading documentation, a salesperson on a call and a manager in a meeting can all produce very different digital footprints while doing valuable work.

The inference can be wrong

Even if the input data is accurate, the model can draw an unreliable conclusion from it. A system can correctly record that someone was inactive in one application and still be wrong to infer that they were not working.

The decision can become difficult to challenge

An opaque score becomes much more consequential if a manager treats it as objective truth. That is why meaningful human involvement is more than simply putting a manager's name at the end of an automated workflow.

The 2026 government consultation specifically identifies algorithmic management and AI as part of the workplace-monitoring landscape and asks how systems that influence performance, work allocation and other decisions should be governed.

A seven-question monitoring checklist

Anyone evaluating a workplace-monitoring system — whether as a worker, manager, buyer or policy owner — can reduce a complicated product to seven concrete questions:

  1. What exactly is collected? Keystrokes, screenshots, URLs, location, messages, webcam images, biometrics, activity time or something else?
  2. Why is each data point needed? “Productivity” or “security” is too broad if the data does not logically serve that purpose.
  3. Could the same goal be achieved less intrusively? Compare the proposed method with simpler alternatives.
  4. Who receives the data? Include managers, HR, security teams, software vendors and any other processors.
  5. How long is the data retained? Continuous monitoring becomes a much larger privacy system when months or years of detailed behaviour are stored.
  6. Does it influence a significant decision? Pay, discipline, promotion, dismissal, shifts and task allocation deserve much more scrutiny than an aggregate system-health dashboard.
  7. How can a person challenge an error? If an algorithm influences an important outcome, there should be a genuine path to explanation, human intervention and correction where the law requires it.

A product that cannot answer these questions clearly is not made safe merely by adding an “AI” label — or by removing one.

What to watch next

Three dates and developments matter now.

First, the workplace-monitoring consultation remains open until 30 September 2026. After it closes, the Department for Business and Trade says it will analyse responses and develop a final policy proposal.

Second, the ICO is updating some employment-monitoring guidance following the Data (Use and Access) Act. That matters because older pages can describe the pre-DUAA automated-decision rules even while displaying a warning that the guidance is under review.

Third, the real dividing line is likely to shift from whether monitoring exists to what the monitoring is allowed to decide. Basic security telemetry, invasive surveillance and an AI system that can materially affect someone's working life are not the same risk category, even when they sit inside the same software package.

Bottom line

UK employers can monitor workers, including through sophisticated digital tools, but monitoring is not a legal blank cheque. Purpose, proportionality, transparency, data minimisation, sensitivity of the information and the consequences of automated decisions all matter.

The 2026 consultation could eventually add a statutory code, a legal worker-consultation duty or new non-binding guidance. None of those options is law simply because it appears in the consultation.

For now, the most useful test is simple: identify exactly what the system observes, why it needs that information, what decisions the data feeds, and whether a less intrusive route would achieve the same goal.

This article is general information, not legal advice. Employment and data-protection outcomes depend on the facts, jurisdiction and current law.

Sources

Written and reviewed by /lico

Just writing down my thoughts, interests, and the things I learn along the way.