When an owner asks whether employee monitoring is legal, the word legal is doing too much work.
A company may be allowed to record working time and still be prohibited from recording a call. It may give a valid monitoring notice and still collect far more data than the purpose justifies. It may own the laptop and still capture a private message, a union conversation, health information, or activity inside an employee's home.
So the honest answer is: employee monitoring is often legal, but only under conditions that depend on the worker's location, the monitoring method, the purpose, and what the employer does with the result. Company ownership of a device is not blanket permission. Neither is a handbook acknowledgment.
This guide was checked against current law and regulator guidance on July 22, 2026. It is general information, not legal advice. Have qualified employment and privacy counsel review the exact locations and methods in your rollout.
The short answer by monitoring method
The first question is not “Which country?” It is “What exactly are we collecting?” A timer, a screenshot, a recorded call, and a face scan do not enter the same legal analysis.
Table: a screening view of common employee-monitoring methods. “Higher risk” means pause for method-specific legal review, not automatically illegal.
| Monitoring method | Often legal when | Main reasons to pause |
|---|---|---|
| Time and attendance records | The purpose is clear, records are accurate, workers are informed where required, and access and retention are limited | Off-hours collection, inaccurate deductions, hidden edits, or using activity as a substitute for hours worked |
| Periodic screenshots | Workers receive clear notice, capture is limited to work devices and hours, sensitive content is reduced, and the method is proportionate | Personal messages, passwords, health or union information, home privacy, constant capture, or silent mode |
| App, URL, and activity logs | The employer names the business purpose and collects only the fields needed for it | Content capture, vague “productivity” scoring, personal use, disability effects, or automated discipline |
| Email and message review | Access is authorized, expected, purpose-limited, and consistent with communications and labor law | Interception in transit, personal accounts, privileged content, union activity, or a promise of privacy |
| Audio and call recording | Every applicable consent rule is satisfied and the recording purpose is disclosed | Interstate calls, all-party consent rules, continuous microphones, home conversations, or covert capture |
| Video and webcams | Cameras serve a specific safety or security need, avoid private spaces, and operate within notice and proportionality rules | Bedrooms, homes, bathrooms, changing areas, continuous observation, audio, or performance scoring |
| GPS and location | Collection is tied to a work and safety purpose, a work vehicle or device, and working hours | Personal vehicles or phones, off-hours tracking, home addresses, family movements, or secondary use |
| Biometrics | A specific law permits the use and the employer meets notice, consent, retention, deletion, and security duties | Face or fingerprint templates, no alternative method, indefinite storage, vendor reuse, or no deletion schedule |
| AI scores and automated decisions | Data is accurate, the purpose is disclosed, discrimination is tested, and a person reviews consequential decisions | Black-box scores, no correction path, disability bias, or automated pay, promotion, discipline, or termination |
The pattern is plain. The closer a tool gets to content, identity, location, private space, or an employment decision, the weaker a broad “business purpose” explanation becomes.
What surprised me while reading the primary law was how often vendor guides collapse five different duties into one word: consent. That is a mistake. Notice tells a worker what will happen. Consent asks for a legally meaningful choice. A lawful basis justifies processing under a data-protection regime. Consultation gives a union or works council a voice. Proportionality asks whether the same purpose can be met with less intrusion.
One checkbox cannot perform all five jobs.
(Not even a very polished checkbox.)
What US federal law actually says
US employers often hear a simple rule: monitoring is legal on company equipment for a business purpose. That is too broad.
The federal Wiretap Act, amended by the Electronic Communications Privacy Act, starts by prohibiting intentional interception of wire, oral, and electronic communications. It then provides specific exceptions, including prior consent by one party in many circumstances. Read the structure of 18 U.S.C. § 2511 carefully. It does not say every employer may inspect every communication on every company device.
Timing matters too. Intercepting a live communication and accessing a stored message can trigger different federal rules. Audio can trigger both federal and state recording law. A screenshot may collect information from several services at once, including information the employer never intended to request.
Federal labor law creates another boundary. An employer may not spy on union activity, create the impression that it is spying, or photograph or film peaceful protected activity. That matters even in a nonunion workplace because workers can have protected rights when they act together about pay or working conditions.
Disability law matters when monitoring becomes evaluation. A keystroke or activity rule may penalize a worker who uses assistive technology, takes an accommodation-related break, or completes work outside the system being scored. A human should review the surrounding work before an activity signal affects pay, promotion, discipline, or termination.
My first version of this map put “federal law” in one tidy box. I removed it. Communications, stored data, labor rights, discrimination, wage records, sector rules, and state privacy claims do not behave like one federal permission slip.
Employee monitoring laws in all 50 US states
Four states now have dedicated employer electronic-monitoring notice laws that deserve their own rollout step: Connecticut, Delaware, Maine, and New York. That list changed in 2026 because Maine added a broader employer-surveillance law.
Reading the current code pages changed my checklist from “Did we give notice?” to “Which notice, at what time, for which method?”
Connecticut
Connecticut section 31-48d generally requires prior written notice describing the types of electronic monitoring that may occur. A conspicuous posting can constitute notice. There is an exception when the employer has reasonable grounds to suspect specified misconduct and monitoring may produce evidence.
There is a scope detail many summaries miss: the statutory definition concerns collection on the employer's premises. Do not assume that one paragraph answers a Connecticut remote-work rollout. Separate communications, privacy, and recording rules may still apply.
Delaware
Delaware section 705 covers monitoring or intercepting telephone conversations, email or other electronic communications, and internet access or use. Before monitoring, an employer can give an electronic notice at least once each day or give a one-time notice acknowledged in writing or electronically. That is a notice regime. Calling it “employee consent” blurs what the statute requires and what other recording law may require.
Maine
Maine's new employer-surveillance law requires notice before covered surveillance begins. Employers using surveillance must disclose it during the interview process and provide written notice to current employees at least once each calendar year.
The law also lets an employee decline an employer request to install surveillance data-collection or transmission apps on the employee's personal electronic device. It restricts audiovisual monitoring in an employee's residence, personal vehicle, or property unless that monitoring is required for the job duties. Security cameras and employer-vehicle safety or GPS systems have stated exclusions, so the exact method still matters.
This was the detail I nearly missed because several “2026” guides still repeated the old three-state notice list.
New York
New York Civil Rights Law section 52-c requires covered private employers to give prior written notice upon hiring to employees subject to monitoring of telephone, email, or internet activity. The employee must acknowledge it, and the employer must also post a conspicuous notice. The statute has a systems-maintenance and protection exception for processes not targeted at a particular person. It does not turn an acknowledgment into permission for unrelated uses.
The 50-state action map
For a practical first pass, place every state into the action group below. This is a screening map. Cities, sectors, contracts, common-law privacy claims, and facts can add another rule.
Dedicated employer-notice review: Connecticut, Delaware, Maine, and New York.
Stricter or special audio-recording review: California, Florida, Hawaii, Illinois, Maryland, Massachusetts, Michigan, Missouri, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington. Connecticut, Delaware, and Maine also need audio analysis, but they already appear in the notice group above.
The current 50-state recording guide from the Reporters Committee identifies 11 states that primarily require all parties' consent, several states that split telephone and in-person conversations, and special private-place rules in Hawaii and Maine. Those labels are a starting point, not a software setting. For a call crossing state lines, review the stricter applicable rule rather than assuming the recorder's location controls.
Additional biometric, privacy, or automated-decision review: Colorado and Texas. California, Illinois, and Washington also have major privacy or biometric overlays, but they already appear in the audio group. Colorado's revised automated-decision law is scheduled for January 1, 2027, so employers using monitoring data for consequential decisions should prepare before it takes effect.
No dedicated general employer electronic-monitoring notice statute identified in this review: Alabama, Alaska, Arizona, Arkansas, Georgia, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Minnesota, Mississippi, Nebraska, New Jersey, New Mexico, North Carolina, North Dakota, Ohio, Oklahoma, Rhode Island, South Carolina, South Dakota, Tennessee, Utah, Vermont, Virginia, West Virginia, Wisconsin, and Wyoming.
That last group is not a permission list. Federal interception law, state audio and hidden-camera law, privacy torts, biometric rules, anti-discrimination law, labor rights, sector rules, and local ordinances can still restrict the rollout. The District of Columbia needs its own local review too.
Worker location can matter more than company headquarters. A Texas company with employees in New York, France, and Ontario does not get one Texas answer for all three people.
European Union: legal, but rarely casual
The EU does not impose a simple ban on employee monitoring. The GDPR requires the employer to identify a lawful basis, tell workers what is collected and why, collect only what is needed, keep it no longer than justified, secure it, and honor applicable access, correction, objection, and other rights. High-risk monitoring may require a data-protection impact assessment before collection begins.
Employee consent is often weak because the employment relationship makes a freely given refusal difficult. An employer may instead examine legitimate interests, legal obligation, or another basis, but each basis has its own test. “We put it in the contract” is not an automatic lawful basis.
National employment law sits beside GDPR. In Germany, a works council can have co-determination rights when technical devices are designed to monitor behavior or performance. In France, worker representatives and proportionality rules matter, and the privacy regulator has treated broad screenshot, inactivity, and continuous video practices as excessive.
The Bărbulescu messaging case is a useful correction to policy-first thinking. The worker had been told not to use a work messaging account for personal purposes. The European Court of Human Rights still examined the clarity of notice, the monitoring's scope, the employer's reasons, less-intrusive alternatives, consequences, and safeguards. A rule against personal use did not end the privacy analysis.
And this is where I take a firm view: if a European rollout cannot survive a written necessity and proportionality test, it should not be switched on while someone searches for a better legal phrase.
United Kingdom: explain the purpose and test the intrusion
UK monitoring is also conditionally legal. The ICO's worker-monitoring guidance says employers should choose a lawful basis, define the purpose, use the least intrusive means, inform workers except in exceptional covert cases, control access and retention, and complete a DPIA when the processing is likely to create high risk.
The home changes the balance. Screenshots or webcams can capture family members, private correspondence, health details, and parts of a residence that never enter an office. A company laptop does not make the room around it company property.
The UK opened a consultation on workplace-monitoring technologies on July 8, 2026, focused on transparency and worker voice. It is a consultation, not a new monitoring law. Employers should follow it because the rules may change, but they should not describe a proposal as a current duty.
Canada: federal, provincial, and Ontario rules overlap
Canada does not have one private-sector employee-monitoring rule for every employer. PIPEDA's employee provisions focus on federal works, undertakings, and businesses. Alberta, British Columbia, and Quebec have provincial private-sector privacy laws, while other provinces can leave employers with a different mix of employment standards, common law, sector rules, and collective agreements.
Ontario adds a clear policy duty. An employer with 25 or more Ontario employees on January 1 must have a written electronic-monitoring policy in place before March 1. The Ontario government guide says the policy must describe whether monitoring occurs, how and in what circumstances it occurs, and the purposes for which the information may be used.
One important limit: that requirement does not itself create a right not to be monitored. It is a disclosure duty, not a complete privacy code.
The Canadian decisions gave me the clearest example of purpose creep. A security camera installed for safety may become a performance-management camera when a manager reuses the footage for discipline. The second use needs its own analysis. Same camera, different legal question.
Australia: check the state before switching it on
Australia's federal Privacy Act does not specifically regulate workplace surveillance as one subject. State and territory surveillance law does much of the work, and the federal employee-records exemption has limits.
New South Wales has one of the clearest systems. Under the Workplace Surveillance Act 2005, an employer generally gives at least 14 days' prior written notice. Computer surveillance must follow a notified policy. Camera and tracking surveillance have their own notice and visibility rules, and surveillance in private areas is restricted.
The Australian Capital Territory also has a dedicated workplace privacy law with notice and consultation requirements. Elsewhere, surveillance devices, listening devices, privacy, and employment rules still require local review.
Other common hiring locations
New Zealand and Singapore
New Zealand's Privacy Act 2020 does not forbid ordinary work-computer monitoring, but collection must be necessary, open, fair, and not unreasonably intrusive. Covert monitoring needs a particularly strong reason. Once data is collected, security, accuracy, retention, access, correction, use, and disclosure duties follow.
Singapore's PDPA can allow personal-data processing without employee consent when it is reasonable for entering into, managing, or terminating the employment relationship. The employer still has to notify employees of the purposes. Monitoring company network resources can fall within the employment purpose, but unrelated secondary uses need a separate basis.
India, Brazil, and South Africa
India requires a date check in 2026. The core processing duties in the Digital Personal Data Protection Act are scheduled to come into force on May 13, 2027, based on the staged commencement notification. That does not create a free year for employers. Existing IT, employment, contract, constitutional, and sector rules can still apply.
Brazil's LGPD and South Africa's POPIA both regulate the processing of employee personal data. A monitoring program needs a lawful justification, purpose limits, security, retention controls, and rights handling under the applicable regime. Communications interception, labor law, collective rights, and sensitive-data rules can add another layer. Get local counsel before audio, biometrics, location, or automated employment decisions.
Screenshots are not automatically illegal
Employers ask about screenshots because they sit in an awkward middle. A screenshot is not a microphone, but it can capture a live conversation. It is not a biometric scanner, but it can capture a face. It is not a medical form, but it can capture a diagnosis in a browser tab.
Periodic screenshots are easier to defend when the employer can answer all of these questions: Why is an image needed instead of a timer or task record? Which screen is captured? Can sensitive apps or fields be excluded? Does capture stop outside working time? Who can view the image? When is it deleted? Can the employee see and challenge it? Will any person review context before it affects an employment decision?
When I see a field-service team add location or screenshots because the app offers them, the legal question has already arrived late. The better sequence starts with the decision the manager needs to make. If the decision is “Was this job visited?”, a customer sign-off or work-order event may answer it with less intrusion than continuous location. If the decision is “Which project should be billed?”, a worker-selected project timer may answer it without a desktop image.
France's regulator made the risk concrete when it fined a company €40,000 for a monitoring setup that included inactivity measurement, regular screenshots, and continuous video. The problem was not one magic forbidden feature. It was the combined scale and disproportionality of the system.
This is also why an activity score should not become a wage or discipline score by convenience. Activity is not productivity, and a legally collected signal can still be an unfair or inaccurate basis for a decision.
Build a Jurisdiction by Method Decision Record
Do not send counsel the question “Can we monitor employees?” Send a completed record for each method and worker group.
Table: the decision record to complete before an employee-monitoring rollout.
| Field | What to record |
|---|---|
| Worker location | Country, state or province, city, remote-work address, and travel pattern |
| Monitoring method | Exact data fields, capture frequency, whether content is recorded, and whether the system runs silently |
| Purpose | The specific business problem and the decision that will change because of the data |
| Less-intrusive option | The narrower method considered, tested, or rejected, with the reason |
| Scope | People, roles, devices, apps, locations, and working hours included and excluded |
| Legal step | Notice, acknowledgment, consent, lawful basis, impact assessment, union or works-council consultation, and counsel review |
| Access | Manager, HR, IT, vendor, and subprocessor roles that can view raw or derived data |
| Retention | How long each record and backup remains, why, and what triggers deletion |
| Worker rights | How a worker sees, corrects, explains, objects to, or challenges the record and resulting decision |
| Decision control | Which consequential uses are prohibited and which named human reviews exceptions |
| Approval | Internal owner, counsel owner, approval date, evidence location, and the event that triggers re-review |
One record per method. Not one policy for an entire product.
The research changed my own rule here. I used to think a detailed policy was the main artifact. It is not. The decision record comes first because it forces the employer to prove necessity and scope. The policy is what workers should receive after those decisions are made in language they can understand.
For the vendor side of this review, use the 12 workforce-data questions to document support access, subprocessors, export, retention, and deletion. For the purchase decision itself, the time-tracking software buying checklist covers policy controls, employee access, corrections, and exit tests.
Compliance checklist before launch
- List every worker's actual work location, not only the employing company's address.
- Separate time logs, screenshots, app or URL data, communications, audio, video, location, biometrics, and automated scores.
- Name the purpose and the management decision each data type supports.
- Document why a narrower method cannot meet that purpose.
- Have local employment and privacy counsel review the method and locations.
- Complete every required notice, acknowledgment, consent, lawful-basis assessment, DPIA, union process, or works-council consultation before collection.
- Limit monitoring to work devices, work accounts, work locations where appropriate, and working hours. Exclude private spaces and sensitive apps.
- Give workers a plain-language policy that states what is collected, why, when, who sees it, how long it remains, and how to challenge an error.
- Keep monitoring data out of automated pay, discipline, and termination decisions unless counsel approves the use and a trained person reviews context.
- Test vendor access, security, retention, deletion, export, and incident duties with evidence, not a sales answer.
- Recheck the record when a worker moves, a method changes, a vendor adds AI, the purpose expands, or the law changes.
I would pause any rollout that cannot complete items three and four. If the business cannot name the decision or explain why a less-intrusive record fails, the collection is not ready for a legal review, much less an employee's screen.
Once counsel clears the policy and method, compare Kordano Time pricing against the narrower record the team actually needs.
The company may own the laptop. It does not own everything the laptop can see.
Companies with teams of 6 or more can lock $3 per person per month for 24 months.
Claim your spot
Haris Ali D. is the Founder of Kordano, a workforce operating system for modern teams. He focuses on building practical tools for time tracking, attendance, productivity visibility, and team operations.
He also brings experience in branding, digital strategy, and software development through FullStop, a company he co-founded in 2012.