Employee Data Privacy UK: Workplace Monitoring & GDPR Rights
We're not a law firm — we help you find the right legal support. For advice on your situation, speak to a legal adviser or find a solicitor.
Part ofUK Employment Law Advice
At a glance
- Employers are data controllers. Any processing of employee personal data — payroll, HR files, emails, monitoring software, CCTV — needs a lawful basis under Article 6 UK GDPR; consent is rarely relied on in the employment context because of the power imbalance between employer and staff.
- Special category data needs extra permission. Health data, sickness records, trade union membership and similar sensitive categories require an Article 9 UK GDPR condition plus a matching condition in Schedule 1 to the Data Protection Act 2018 — commonly with an "appropriate policy document" in place.
- Subject access requests (SARs) let staff see the personal data an employer holds about them, under Article 15 UK GDPR. Following reforms in the Data (Use and Access) Act 2025 that took effect on 5 February 2026, employers only need to make "reasonable and proportionate" searches and the response deadline runs from a defined "relevant time" rather than the date the request was simply received.
- Monitoring must be necessary, proportionate and — wherever possible — transparent. More intrusive or systematic monitoring, such as covert surveillance or continuous productivity tracking, will often need a Data Protection Impact Assessment under Article 35 UK GDPR.
- A new internal complaints right is now in force. Since 19 June 2026, the Data (Use and Access) Act 2025 requires employers to operate a formal complaints process for data protection issues, acknowledging complaints within 30 days.
- Human rights law can also be engaged. The Human Rights Act 1998, and the right to respect for private life it incorporates, is most directly relevant to public-sector employers but informs how tribunals and courts think about privacy at work generally.
- Size is not a defence. The core duties under UK GDPR and the Data Protection Act 2018 apply to every employer, regardless of headcount.
What is employee data privacy and who is responsible for it?
Employee data privacy covers the way personal information about workers is collected, used, stored and shared by an employer. That includes obvious things like payroll and HR records, but also extends to emails sent on company systems, internet browsing history, CCTV footage, location tracking in company vehicles, keystroke or productivity software, biometric entry data, and recordings from work calls or video meetings.
For almost all of this, the employer is the data controller — the organisation that decides why and how the data is processed — and carries the legal responsibility for getting it right. Where an employer uses a third-party payroll provider, monitoring vendor or HR system, that provider is usually a data processor, acting only on the employer's instructions, but the employer remains accountable for the overall lawfulness of the processing.
The legal framework
In the UK, this area sits at the intersection of the UK GDPR, the Data Protection Act 2018, and — for public authorities in particular — the Human Rights Act 1998. Unusually, the version of the GDPR that applies in the UK omits Article 88, the provision that in the EU lets member states set more specific employment-processing rules. The UK instead relies on the general UK GDPR framework (Articles 6 and 9 in particular) together with the employment-specific conditions set out in Schedule 1 to the Data Protection Act 2018.
Employers are generally entitled to monitor staff for legitimate reasons, such as security, regulatory compliance or protecting business interests, but they are expected to be transparent about it, keep monitoring proportionate to the issue at hand, and avoid going further than is genuinely necessary. When those boundaries are crossed, or when employees feel they have been watched without warning, disputes often follow.
Lawful bases most commonly used for employee data
Employers cannot process personal data — including through monitoring — without identifying a lawful basis under Article 6 UK GDPR. In an employment setting, the bases relied on are usually:
- Performance of a contract (Article 6(1)(b)) — for data needed to run the employment relationship itself, such as salary, hours worked and holiday records.
- Legal obligation (Article 6(1)(c)) — for data an employer must collect or keep to comply with the law, such as right-to-work checks or PAYE records.
- Legitimate interests (Article 6(1)(f)) — the basis most often relied on for monitoring, provided the employer's interest is balanced fairly against the impact on staff.
Consent (Article 6(1)(a)) is technically available but is rarely a safe basis in the employment context, because consent must be freely given, and an employee is not usually in a position to refuse a request from their employer without consequence. Employers who rely on "consent" for monitoring without a genuine free choice risk that basis being found invalid.
Special category data at work
Some employee data falls into the narrower category of special category data under Article 9 UK GDPR — health information, sickness records, biometric data used to identify someone, trade union membership, and data revealing racial or ethnic origin, religion or sexual orientation. Processing this data is prohibited unless a specific Article 9 condition applies, and UK law requires that condition to be matched to one of the grounds in Schedule 1 to the Data Protection Act 2018. The employment condition is the one most employers rely on, and section 10 of the Act additionally requires an appropriate policy document to be in place describing how the data will be handled and retained. Occupational health reports, sickness absence records and disability-related adjustments data all typically fall into this stricter category.
Employees' data protection rights
The subject access request
The most commonly used right is the subject access request (SAR) under Article 15 UK GDPR, which lets an employee ask their employer for a copy of the personal data held about them, along with information about why it is processed, who it is shared with, and how long it is kept. Reforms introduced by the Data (Use and Access) Act 2025 and in force since 5 February 2026 changed the mechanics slightly: the response period now runs from a defined "relevant time" (broadly, when the employer has everything it reasonably needs to deal with the request), the clock can be paused if the employer genuinely needs clarification from the employee, and employers are only required to make "reasonable and proportionate" searches rather than an exhaustive search of every system. In practice this still generally means a response within one month, extendable by a further two months for complex or numerous requests, and there is usually no fee.
Other rights
Employees also have rights to rectification of inaccurate data, erasure in some circumstances (though this is limited where the employer has a continuing legal reason to keep records, such as tax or litigation risk), restriction of processing while a dispute is resolved, and objection to processing based on legitimate interests. None of these rights are absolute, and an employer can usually justify continuing to hold core employment records for as long as they are needed for payroll, tax, pension or potential litigation purposes.
Workplace monitoring: what the law expects
Whatever form monitoring takes, the underlying test is the same: is it necessary and proportionate for a legitimate aim, and has the employer been transparent about it through a privacy notice or policy, as required by Articles 13 and 14 UK GDPR? Where monitoring is likely to result in high risk to staff — for example, systematic covert surveillance, large-scale location tracking, or intrusive productivity software — Article 35 UK GDPR expects the employer to carry out a documented Data Protection Impact Assessment before starting.
Common monitoring methods
- Email and internet monitoring. Usually lawful if flagged in policy and proportionate to a stated purpose such as security; blanket reading of personal messages with no justification is harder to defend.
- CCTV. Generally lawful for security or safety purposes with visible signage; covert use is exceptional and usually requires a documented justification.
- Location tracking (company vehicles, phones). Needs a clear purpose, should generally stop or be limited outside working hours, and should not sweep up more data than necessary.
- Productivity and keystroke software. Increasingly common with remote and hybrid working, and one of the areas most likely to attract regulatory scrutiny if it is continuous, undisclosed, or disproportionate to the role.
- Covert monitoring. Reserved for exceptional circumstances, typically suspected serious wrongdoing where advance notice would defeat the purpose. This is the category most likely to need a Data Protection Impact Assessment and the closest legal scrutiny if challenged.
If a disciplinary or dismissal decision is later based on evidence gathered through disproportionate or covert monitoring, an employment tribunal can take the way that evidence was obtained into account — including in claims that overlap with disability discrimination where health-related monitoring data was mishandled, or where mishandling of sickness records fed into a flawed capability dismissal process.
Worked example: a covert monitoring dispute
Priya, a fictional retail supervisor, is suspected by her employer of falsifying till records. Rather than raising the concern directly or seeking advice first, her manager installs covert recording software on her till terminal for three weeks, without a policy, a Data Protection Impact Assessment, or any staff notice covering this kind of monitoring. Priya is later dismissed based largely on the covert footage.
Because the monitoring went well beyond what the employer's existing privacy notice described, was not assessed for proportionality in advance, and was not limited to the minimum necessary to investigate the specific concern, Priya would have a reasonable basis both to complain to the Information Commissioner's Office about the data handling and to argue at an employment tribunal that the manner of the investigation undermined the fairness of her dismissal — separately from whatever the till records themselves show. This is the kind of case where the "how" of monitoring can matter as much as the "what" it uncovers.
Recent changes: the Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and its data protection provisions have been commenced in stages. Two changes are directly relevant to employee data privacy and are now in force:
- From 5 February 2026: the subject access request mechanics changed, with a new "applicable time period" replacing the old flat one-month rule, a formal "stop-the-clock" provision, and confirmation that only "reasonable and proportionate" searches are required (see above).
- From 19 June 2026: employers must operate a formal internal complaints process for data protection complaints — providing an accessible way to complain, acknowledging complaints within 30 days, and responding without undue delay.
The Act also introduces a new "recognised legitimate interests" lawful basis for specific purposes such as crime prevention and safeguarding, and reforms to automated decision-making safeguards, though these are less commonly relevant to day-to-day employee monitoring. Because commencement has happened in phases, and further detail is expected in regulator guidance, always check current GOV.UK guidance before relying on the fine detail of any of these reforms.
Where data issues cross into other employment claims
Data privacy problems rarely stay contained to a data protection complaint. A serious, unjustified breach of trust — such as covert surveillance well beyond what was disclosed — can support a constructive dismissal claim if it undermines the implied duty of trust and confidence. Where monitoring or data handling differs depending on a protected characteristic, it can also feed into an age discrimination claim or a disability discrimination claim. And the same data protection duties apply whether someone is a direct employee or an agency worker — agency status does not reduce an organisation's obligations as a data controller.
What to do if you are concerned about how your data is being handled
- Check the workplace privacy notice and policies. Employers are expected to tell staff, in plain terms, what personal data is collected, why, how long it is kept and who sees it. Start by reading the privacy notice, staff handbook, IT acceptable use policy and any monitoring policy, as these documents usually set the framework for what is and is not permitted.
- Identify what monitoring is actually taking place. Think through the systems you interact with day to day, including email, messaging platforms, CCTV, access cards, vehicle trackers and productivity tools. Understanding the full picture matters because concerns about privacy are often about the combined effect of several systems, not just one.
- Assess whether the monitoring looks proportionate. The key test under UK data protection law is whether the monitoring is necessary and proportionate for a legitimate aim. Covert surveillance, blanket recording of private messages, or intrusive productivity tracking with no clear justification are the kinds of practices that tend to attract regulatory scrutiny.
- Raise concerns internally before escalating. If something feels wrong, a written question to HR or your line manager is usually the sensible first step. You can also make a subject access request to see what personal data the employer holds about you. Keep copies of what you send and what you receive, as this paper trail can matter later.
- Use the formal complaints route if internal raising doesn't resolve it. Since 19 June 2026, employers must run a proper internal complaints process for data protection issues — use it, and keep a note of dates and responses.
- Consider formal external routes if issues are not resolved. Where internal steps do not work, options may include a complaint to the Information Commissioner's Office about data handling, or in more serious cases a tribunal claim linked to discrimination, detriment or constructive dismissal. The right route depends heavily on the facts, and getting guidance early tends to save time and stress.
This guide provides general information about employee data privacy and workplace monitoring under UK data protection law. It is not legal advice and is not a substitute for advice tailored to your specific circumstances. The law described was accurate as at July 2026 and is subject to change — always check GOV.UK and legislation.gov.uk for the most current position.
Last reviewed: July 2026 by a non-practising solicitor · Next review due: July 2027 or on legislative change.
Common questions
Sources
This guide is based on primary UK law and official guidance.
- LegislationUK GDPR, Article 6 — lawfulness of processinglegislation.gov.uk
- LegislationUK GDPR, Article 9 — processing of special categories of personal datalegislation.gov.uk
- LegislationUK GDPR, Article 15 — right of access by the data subjectlegislation.gov.uk
- LegislationUK GDPR, Article 35 — data protection impact assessmentlegislation.gov.uk
- LegislationData Protection Act 2018legislation.gov.uk
- LegislationData Protection Act 2018, Schedule 1 — special categories and criminal offence data conditionslegislation.gov.uk
- LegislationData Protection Act 2018, section 10 — special categories of personal data: supplementarylegislation.gov.uk
- LegislationHuman Rights Act 1998legislation.gov.uk
- LegislationData (Use and Access) Act 2025legislation.gov.uk
- Guidance · UK GovData (Use and Access) Act 2025: data protection and privacy changes — GOV.UKgov.uk
- Guidance · UK GovData protection: the UK's data protection legislation — GOV.UKgov.uk
