Skip to main content
Find your template →
Menu

Employee Data Privacy UK: Workplace Monitoring & GDPR Rights

We're not a law firm — we help you find the right legal support. For advice on your situation, speak to a legal adviser or find a solicitor.

Part ofUK Employment Law Advice

Updated June 2026 · England & Wales
Where employers end and employee privacy begins has become one of the most contested areas of modern workplace law. With remote working tools, email tracking, productivity software, CCTV and access logs all generating personal data, the boundaries between legitimate business oversight and unwarranted intrusion are easy to cross without realising it. For staff, this raises genuine concerns about dignity and fair treatment. For employers, it creates real exposure to grievances, tribunal claims and regulatory action. This guide walks through the main legal frameworks that shape how personal data can be handled at work in England and Wales — including the reforms introduced by the Data (Use and Access) Act 2025, most of which are now in force — the most common forms of workplace monitoring, and the kinds of disputes that tend to follow. Whether you are an employee worried about being watched or an employer trying to stay on the right side of the rules, the aim here is to give you a clear picture of what the law expects.

At a glance

  • Employers are data controllers. Any processing of employee personal data — payroll, HR files, emails, monitoring software, CCTV — needs a lawful basis under Article 6 UK GDPR; consent is rarely relied on in the employment context because of the power imbalance between employer and staff.
  • Special category data needs extra permission. Health data, sickness records, trade union membership and similar sensitive categories require an Article 9 UK GDPR condition plus a matching condition in Schedule 1 to the Data Protection Act 2018 — commonly with an "appropriate policy document" in place.
  • Subject access requests (SARs) let staff see the personal data an employer holds about them, under Article 15 UK GDPR. Following reforms in the Data (Use and Access) Act 2025 that took effect on 5 February 2026, employers only need to make "reasonable and proportionate" searches and the response deadline runs from a defined "relevant time" rather than the date the request was simply received.
  • Monitoring must be necessary, proportionate and — wherever possible — transparent. More intrusive or systematic monitoring, such as covert surveillance or continuous productivity tracking, will often need a Data Protection Impact Assessment under Article 35 UK GDPR.
  • A new internal complaints right is now in force. Since 19 June 2026, the Data (Use and Access) Act 2025 requires employers to operate a formal complaints process for data protection issues, acknowledging complaints within 30 days.
  • Human rights law can also be engaged. The Human Rights Act 1998, and the right to respect for private life it incorporates, is most directly relevant to public-sector employers but informs how tribunals and courts think about privacy at work generally.
  • Size is not a defence. The core duties under UK GDPR and the Data Protection Act 2018 apply to every employer, regardless of headcount.

What is employee data privacy and who is responsible for it?

Employee data privacy covers the way personal information about workers is collected, used, stored and shared by an employer. That includes obvious things like payroll and HR records, but also extends to emails sent on company systems, internet browsing history, CCTV footage, location tracking in company vehicles, keystroke or productivity software, biometric entry data, and recordings from work calls or video meetings.

For almost all of this, the employer is the data controller — the organisation that decides why and how the data is processed — and carries the legal responsibility for getting it right. Where an employer uses a third-party payroll provider, monitoring vendor or HR system, that provider is usually a data processor, acting only on the employer's instructions, but the employer remains accountable for the overall lawfulness of the processing.

The legal framework

In the UK, this area sits at the intersection of the UK GDPR, the Data Protection Act 2018, and — for public authorities in particular — the Human Rights Act 1998. Unusually, the version of the GDPR that applies in the UK omits Article 88, the provision that in the EU lets member states set more specific employment-processing rules. The UK instead relies on the general UK GDPR framework (Articles 6 and 9 in particular) together with the employment-specific conditions set out in Schedule 1 to the Data Protection Act 2018.

Employers are generally entitled to monitor staff for legitimate reasons, such as security, regulatory compliance or protecting business interests, but they are expected to be transparent about it, keep monitoring proportionate to the issue at hand, and avoid going further than is genuinely necessary. When those boundaries are crossed, or when employees feel they have been watched without warning, disputes often follow.

Lawful bases most commonly used for employee data

Employers cannot process personal data — including through monitoring — without identifying a lawful basis under Article 6 UK GDPR. In an employment setting, the bases relied on are usually:

  • Performance of a contract (Article 6(1)(b)) — for data needed to run the employment relationship itself, such as salary, hours worked and holiday records.
  • Legal obligation (Article 6(1)(c)) — for data an employer must collect or keep to comply with the law, such as right-to-work checks or PAYE records.
  • Legitimate interests (Article 6(1)(f)) — the basis most often relied on for monitoring, provided the employer's interest is balanced fairly against the impact on staff.

Consent (Article 6(1)(a)) is technically available but is rarely a safe basis in the employment context, because consent must be freely given, and an employee is not usually in a position to refuse a request from their employer without consequence. Employers who rely on "consent" for monitoring without a genuine free choice risk that basis being found invalid.

Special category data at work

Some employee data falls into the narrower category of special category data under Article 9 UK GDPR — health information, sickness records, biometric data used to identify someone, trade union membership, and data revealing racial or ethnic origin, religion or sexual orientation. Processing this data is prohibited unless a specific Article 9 condition applies, and UK law requires that condition to be matched to one of the grounds in Schedule 1 to the Data Protection Act 2018. The employment condition is the one most employers rely on, and section 10 of the Act additionally requires an appropriate policy document to be in place describing how the data will be handled and retained. Occupational health reports, sickness absence records and disability-related adjustments data all typically fall into this stricter category.

Employees' data protection rights

The subject access request

The most commonly used right is the subject access request (SAR) under Article 15 UK GDPR, which lets an employee ask their employer for a copy of the personal data held about them, along with information about why it is processed, who it is shared with, and how long it is kept. Reforms introduced by the Data (Use and Access) Act 2025 and in force since 5 February 2026 changed the mechanics slightly: the response period now runs from a defined "relevant time" (broadly, when the employer has everything it reasonably needs to deal with the request), the clock can be paused if the employer genuinely needs clarification from the employee, and employers are only required to make "reasonable and proportionate" searches rather than an exhaustive search of every system. In practice this still generally means a response within one month, extendable by a further two months for complex or numerous requests, and there is usually no fee.

Other rights

Employees also have rights to rectification of inaccurate data, erasure in some circumstances (though this is limited where the employer has a continuing legal reason to keep records, such as tax or litigation risk), restriction of processing while a dispute is resolved, and objection to processing based on legitimate interests. None of these rights are absolute, and an employer can usually justify continuing to hold core employment records for as long as they are needed for payroll, tax, pension or potential litigation purposes.

Workplace monitoring: what the law expects

Whatever form monitoring takes, the underlying test is the same: is it necessary and proportionate for a legitimate aim, and has the employer been transparent about it through a privacy notice or policy, as required by Articles 13 and 14 UK GDPR? Where monitoring is likely to result in high risk to staff — for example, systematic covert surveillance, large-scale location tracking, or intrusive productivity software — Article 35 UK GDPR expects the employer to carry out a documented Data Protection Impact Assessment before starting.

Common monitoring methods

  • Email and internet monitoring. Usually lawful if flagged in policy and proportionate to a stated purpose such as security; blanket reading of personal messages with no justification is harder to defend.
  • CCTV. Generally lawful for security or safety purposes with visible signage; covert use is exceptional and usually requires a documented justification.
  • Location tracking (company vehicles, phones). Needs a clear purpose, should generally stop or be limited outside working hours, and should not sweep up more data than necessary.
  • Productivity and keystroke software. Increasingly common with remote and hybrid working, and one of the areas most likely to attract regulatory scrutiny if it is continuous, undisclosed, or disproportionate to the role.
  • Covert monitoring. Reserved for exceptional circumstances, typically suspected serious wrongdoing where advance notice would defeat the purpose. This is the category most likely to need a Data Protection Impact Assessment and the closest legal scrutiny if challenged.

If a disciplinary or dismissal decision is later based on evidence gathered through disproportionate or covert monitoring, an employment tribunal can take the way that evidence was obtained into account — including in claims that overlap with disability discrimination where health-related monitoring data was mishandled, or where mishandling of sickness records fed into a flawed capability dismissal process.

Worked example: a covert monitoring dispute

Priya, a fictional retail supervisor, is suspected by her employer of falsifying till records. Rather than raising the concern directly or seeking advice first, her manager installs covert recording software on her till terminal for three weeks, without a policy, a Data Protection Impact Assessment, or any staff notice covering this kind of monitoring. Priya is later dismissed based largely on the covert footage.

Because the monitoring went well beyond what the employer's existing privacy notice described, was not assessed for proportionality in advance, and was not limited to the minimum necessary to investigate the specific concern, Priya would have a reasonable basis both to complain to the Information Commissioner's Office about the data handling and to argue at an employment tribunal that the manner of the investigation undermined the fairness of her dismissal — separately from whatever the till records themselves show. This is the kind of case where the "how" of monitoring can matter as much as the "what" it uncovers.

Recent changes: the Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and its data protection provisions have been commenced in stages. Two changes are directly relevant to employee data privacy and are now in force:

  • From 5 February 2026: the subject access request mechanics changed, with a new "applicable time period" replacing the old flat one-month rule, a formal "stop-the-clock" provision, and confirmation that only "reasonable and proportionate" searches are required (see above).
  • From 19 June 2026: employers must operate a formal internal complaints process for data protection complaints — providing an accessible way to complain, acknowledging complaints within 30 days, and responding without undue delay.

The Act also introduces a new "recognised legitimate interests" lawful basis for specific purposes such as crime prevention and safeguarding, and reforms to automated decision-making safeguards, though these are less commonly relevant to day-to-day employee monitoring. Because commencement has happened in phases, and further detail is expected in regulator guidance, always check current GOV.UK guidance before relying on the fine detail of any of these reforms.

Where data issues cross into other employment claims

Data privacy problems rarely stay contained to a data protection complaint. A serious, unjustified breach of trust — such as covert surveillance well beyond what was disclosed — can support a constructive dismissal claim if it undermines the implied duty of trust and confidence. Where monitoring or data handling differs depending on a protected characteristic, it can also feed into an age discrimination claim or a disability discrimination claim. And the same data protection duties apply whether someone is a direct employee or an agency worker — agency status does not reduce an organisation's obligations as a data controller.

What to do if you are concerned about how your data is being handled

  1. Check the workplace privacy notice and policies. Employers are expected to tell staff, in plain terms, what personal data is collected, why, how long it is kept and who sees it. Start by reading the privacy notice, staff handbook, IT acceptable use policy and any monitoring policy, as these documents usually set the framework for what is and is not permitted.
  2. Identify what monitoring is actually taking place. Think through the systems you interact with day to day, including email, messaging platforms, CCTV, access cards, vehicle trackers and productivity tools. Understanding the full picture matters because concerns about privacy are often about the combined effect of several systems, not just one.
  3. Assess whether the monitoring looks proportionate. The key test under UK data protection law is whether the monitoring is necessary and proportionate for a legitimate aim. Covert surveillance, blanket recording of private messages, or intrusive productivity tracking with no clear justification are the kinds of practices that tend to attract regulatory scrutiny.
  4. Raise concerns internally before escalating. If something feels wrong, a written question to HR or your line manager is usually the sensible first step. You can also make a subject access request to see what personal data the employer holds about you. Keep copies of what you send and what you receive, as this paper trail can matter later.
  5. Use the formal complaints route if internal raising doesn't resolve it. Since 19 June 2026, employers must run a proper internal complaints process for data protection issues — use it, and keep a note of dates and responses.
  6. Consider formal external routes if issues are not resolved. Where internal steps do not work, options may include a complaint to the Information Commissioner's Office about data handling, or in more serious cases a tribunal claim linked to discrimination, detriment or constructive dismissal. The right route depends heavily on the facts, and getting guidance early tends to save time and stress.

This guide provides general information about employee data privacy and workplace monitoring under UK data protection law. It is not legal advice and is not a substitute for advice tailored to your specific circumstances. The law described was accurate as at July 2026 and is subject to change — always check GOV.UK and legislation.gov.uk for the most current position.

Last reviewed: July 2026 by a non-practising solicitor · Next review due: July 2027 or on legislative change.

Common questions

Q Can my employer read my work emails?
In many cases yes, provided the employer has told staff — usually through a privacy notice or IT acceptable use policy — that email use may be monitored, and there is a legitimate reason for doing so, such as security, compliance or preventing misuse of systems. Employers generally rely on the 'legitimate interests' lawful basis under Article 6 UK GDPR for this kind of monitoring, which requires the monitoring to be necessary and proportionate to the stated purpose. What employers cannot usually do is secretly read private correspondence with no warning and no clear business justification — monitoring is expected to be proportionate, and blanket access to personal messages is often hard to defend.
Q Is CCTV in the workplace legal?
CCTV is generally lawful where it is used for a clear purpose, such as security or health and safety, and where staff and visitors are told about it — typically through visible signage and a privacy notice, as required by Articles 13 and 14 UK GDPR. Cameras in sensitive areas like toilets or changing rooms are very difficult to justify. Covert CCTV is only acceptable in narrow circumstances, usually linked to suspected serious wrongdoing where telling staff in advance would defeat the purpose, should be a last resort, and will often need a documented Data Protection Impact Assessment first.
Q What is a subject access request and how do I make one?
A subject access request (SAR) is your right under Article 15 UK GDPR to ask your employer for a copy of the personal data they hold about you. You can make the request in writing, by email, or even verbally — there is no set form. Since reforms in the Data (Use and Access) Act 2025 took effect on 5 February 2026, the default response window is described as an 'applicable time period' rather than a flat one month, but in practice it still runs to one month from the point the employer has what it needs to deal with the request (extendable by a further two months for complex or numerous requests). The Act also confirms employers only need to make 'reasonable and proportionate' searches, not an exhaustive search of every system. There is usually no fee, and you can ask for things like HR records, emails that mention you, and CCTV footage.
Q Can my employer track my location through a company phone or vehicle?
Location tracking is possible but needs to be justified against the same proportionality test as any other monitoring. Employers should explain why tracking is in place, what data is collected, and whether it continues outside working hours. Tracking that covers personal time, or that captures far more information than the business purpose requires, is the kind of practice most likely to lead to complaints or regulatory interest.
Q What can I do if I think my privacy at work has been breached?
Start by raising the issue internally, ideally in writing, and consider making a subject access request if you want to see what data is held. Employers are now required, from 19 June 2026, to run a formal internal complaints process for data protection complaints under a new right introduced by the Data (Use and Access) Act 2025 — they must acknowledge your complaint within 30 days and respond without undue delay. If the internal response is unsatisfactory, you can complain to the Information Commissioner's Office. Depending on the circumstances, there may also be employment law routes, for example where the breach links to discrimination or a breakdown in trust and confidence.
Q Does GDPR apply to small employers too?
Yes. The UK GDPR and the Data Protection Act 2018 apply regardless of how many staff an employer has. Smaller businesses sometimes have lighter record-keeping obligations, but the core duties around lawful processing, transparency, security and respecting individual rights still apply in full. Size is not a defence to mishandling personal data.
Q Can I be disciplined based on evidence from workplace monitoring?
Employers can use monitoring evidence in disciplinary processes, but only if the monitoring itself was lawful and the employee was reasonably aware it could happen. Employment tribunals have wide discretion over what evidence they admit and are not bound by the strict rules that apply in court, so evidence gathered through disproportionate or covert surveillance is not automatically excluded — but a tribunal can and does take the way evidence was obtained into account when deciding whether a dismissal was fair, and whether the employer breached the implied duty of trust and confidence.
Q What is special category data and does my employer need extra permission to hold it?
Special category data is a narrower set of especially sensitive information — health data, sickness records, trade union membership, biometric data used for identification, and data about racial or ethnic origin, religion or sexual orientation, among others. Article 9 UK GDPR bans processing this data unless a specific condition applies, and for most employers that condition also has to be matched to one of the grounds in Schedule 1 to the Data Protection Act 2018 — commonly the employment condition, which additionally requires the employer to have an 'appropriate policy document' in place under section 10 of the Act. In practice this means sickness absence records, occupational health reports and similar data need tighter controls than routine HR data.

Sources

This guide is based on primary UK law and official guidance.

Brad Askew, Solicitor (non-practising)

Written & reviewed by

Brad Askew Solicitor (non-practising)

Brad is on the roll of solicitors of England & Wales but does not hold a practising certificate and does not provide legal advice. LegalDocuments.co.uk is not a law firm and does not provide regulated legal advice.

Legal disclaimer
This article is for general information only. It is a tool to help you find your way — not legal advice, and not a substitute for speaking to a qualified adviser about your situation.