Employee Monitoring Law UK: What the ICO Actually Requires
Ask a room of UK business owners whether they can track their employees' hours and about half will say "not since GDPR". They are wrong, but the instinct is not silly — the rules genuinely have teeth, and a few well-publicised enforcement actions have made everyone nervous.
The confusion comes from collapsing two very different things into one word. Employee monitoring — continuous surveillance of what someone is doing — sits at one end. Recording the hours somebody worked so you can pay them correctly and meet your statutory record-keeping duties sits at the other. The law treats them very differently, and getting the distinction right removes most of the anxiety.
The Distinction That Matters
| Recording hours worked | Monitoring activity | |
|---|---|---|
| Examples | Timesheets, clock in and out, leave records | Screenshots, keystroke logging, continuous location, webcam checks |
| Typical lawful basis | Contract, and legal obligation for statutory records | Legitimate interests, with a documented balancing test |
| Privacy intrusion | Low | High |
| DPIA | Good practice | Expected, and often mandatory |
You are in fact required to keep certain records. The Working Time Regulations 1998 require adequate records of hours worked to demonstrate compliance with the 48-hour limit, and the National Minimum Wage Regulations 2015 require records sufficient to establish that workers have been paid the minimum. An employer who kept no record of hours would be in breach of both. Our guides to tracking employee hours legally and HMRC timesheet requirements set those duties out.
"We can't record hours because of GDPR" is not a data protection position. It is a compliance failure wearing a data protection costume.
The ICO's Guidance on Monitoring Workers
In October 2023 the Information Commissioner's Office published dedicated guidance, Employment practices and data protection: monitoring workers. It is the single most useful document for any UK employer thinking about this, and it is written for non-lawyers.
Its central requirements:
1. Identify a Lawful Basis
You need one of the Article 6 bases. In practice:
- Contract — processing necessary to pay someone under their employment contract
- Legal obligation — records required by working time and minimum wage law
- Legitimate interests — the usual basis for anything beyond the above, and it requires a documented balancing assessment
Consent is almost always the wrong answer. For consent to be valid it must be freely given, and an employee who cannot get paid without agreeing is not free to refuse. If your data protection policy relies on employee consent for time recording, that is a red flag rather than a reassurance.
2. Be Transparent
Workers must know what is being collected, why, how long it is kept, who it is shared with, and what their rights are. This belongs in a privacy notice that people have actually seen — not buried in a handbook annex.
Transparency is also the practical difference between a system staff tolerate and one they resent. Most resistance to time recording is not about privacy in the abstract; it is about not knowing what the data will be used for.
3. Necessary and Proportionate
The test is whether the monitoring is necessary for the stated purpose and proportionate to it — and crucially, whether a less intrusive method would achieve the same aim. This is where most enforcement turns.
If your aim is to stop people clocking in for each other, and a phone-based clock-in achieves that, then fingerprint scanning is not necessary. That was precisely the ICO's reasoning when, in February 2024, it ordered Serco Leisure and associated trusts to stop using facial recognition and fingerprint scanning to monitor the attendance of more than 2,000 staff, and to destroy the biometric data they had gathered.
4. Do a DPIA Where the Risk Is High
A data protection impact assessment is mandatory where processing is likely to result in a high risk to people's rights. The ICO treats systematic monitoring of workers as falling squarely within that. A DPIA is not a formality — done properly it is the document that demonstrates you considered less intrusive options, which is exactly what a regulator will ask for.
5. Minimise and Retain Sensibly
Collect the minimum needed. Keep it only as long as necessary — which for minimum wage records means six years, and for Working Time Regulations records two. Delete monitoring data that no longer serves the purpose it was collected for.
“The app is simple to use, reliable, and makes managing holidays, absences, and staff records straightforward. The system has saved us a significant amount of administration time.”
Jordan Ingoe, CLI Manchester
TimeTallyThe Records You Need. Nothing You Don't.
Hours submitted, hours approved, leave taken — with a full audit trail for compliance reviews. No screenshots, no keystroke logging, no biometric data.
Free for 14 days • No credit card required
Specific Situations
Location and GPS
Location data is not off limits, but it is high-impact and the proportionality test bites hard. Verifying that a care worker was at the right address when they clocked in is a narrow, purpose-limited use with an obvious justification. Tracking the same worker's position every two minutes throughout the day is a different proposition and needs a much stronger case.
The absolute line: do not track workers outside working hours. If your system can, it should be configured so that it does not, and you should be able to demonstrate that.
Biometrics
Biometric data used to identify an individual is special category data. You need both an Article 6 lawful basis and an Article 9 condition, plus a DPIA. Given the Serco outcome, the practical question to answer first is: what does biometric identification achieve here that a personal-device clock-in does not? If you cannot answer that crisply, do not deploy it. The alternatives are covered in our guide to time theft and buddy punching.
Remote and Hybrid Workers
Home is a domestic space, and monitoring that reaches into it — webcam checks, ambient screenshots, always-on activity trackers — is far harder to justify than the same measure in an office. Output-based management is not just less intrusive, it is easier to defend. See our guide to timesheet software for remote teams.
Covert Monitoring
Reserved for exceptional cases — typically suspected criminal activity or serious malpractice where notifying people would defeat the purpose. It should be authorised at senior level, tightly scoped, time-limited, and stopped as soon as the investigation concludes. Covert monitoring as a general management tool is not lawful.
Workers' Rights You Need to Be Ready For
- Subject access. An employee can ask for a copy of the personal data you hold, including their time and monitoring records, and you generally have one month to respond.
- Objection. Where you rely on legitimate interests, workers can object, and you must stop unless you can show compelling grounds that override their interests.
- Rectification. Inaccurate records must be corrected — which is a good reason to have a proper timesheet dispute process rather than an argument by email.
- Complaint to the ICO. Workers can complain directly, and disgruntled ex-employees frequently do.
A Practical Compliance Checklist
- Write down what you collect and why, in one page.
- Identify the lawful basis for each purpose — and do not use consent.
- Where you rely on legitimate interests, do the balancing assessment and keep it.
- Complete a DPIA for anything beyond straightforward hours recording.
- Publish a worker-facing privacy notice and make sure people have read it.
- Ask the proportionality question honestly: is there a less intrusive way?
- Set retention periods — six years for minimum wage records, two for working time.
- Restrict access by role, so a line manager sees their team and not the whole organisation.
- Check where your provider stores the data, and confirm it in the processing agreement.
- Review annually, and whenever you add a new monitoring capability.
Key Takeaways
- Recording hours and monitoring activity are different things with different risk profiles
- You are legally required to keep working time and minimum wage records — GDPR does not prevent this
- Consent is the wrong lawful basis in employment; use contract, legal obligation or legitimate interests
- The decisive test is usually proportionality: could a less intrusive method achieve the same aim?
- Systematic monitoring needs a DPIA, and the DPIA is your evidence that you considered alternatives
- Biometrics are special category data — the ICO acted against Serco Leisure in February 2024
- Never monitor workers outside working hours
Frequently Asked Questions
Is employee monitoring legal in the UK?
Yes, within limits. You need a lawful basis under UK GDPR, you must tell workers what you are doing and why, and the monitoring must be necessary and proportionate to a genuine aim. Excessive or covert monitoring is where employers get into trouble.
Do I need consent to track employee working hours?
Usually not, and consent is a poor choice in employment because the power imbalance means it is rarely freely given. Recording hours for payroll and statutory record-keeping is normally justified under contract, legal obligation or legitimate interests instead.
Do I need a DPIA for time tracking?
A data protection impact assessment is required where processing is likely to result in a high risk to individuals. The ICO treats systematic monitoring of workers as falling into that category, so anything beyond simple hours recording should have one.
Can employers track employee location?
Location data can be processed where it is necessary and proportionate — verifying a clock-in at a site is far easier to justify than continuous tracking. You must never track workers outside working hours.
Is fingerprint or facial recognition clocking allowed?
Biometric data used to identify someone is special category data, requiring an Article 9 condition and a DPIA. In 2024 the ICO ordered Serco Leisure to stop using facial recognition and fingerprint scanning for attendance monitoring.
Can employers monitor staff covertly?
Only in exceptional circumstances, such as investigating suspected criminal activity where telling people would prejudice the investigation. It must be targeted, time-limited and authorised at senior level.
Sources
- Employment practices and data protection: monitoring workers — Information Commissioner's Office
- Data protection impact assessments — Information Commissioner's Office
