Compliance

Employee Monitoring Law UK: What the ICO Actually Requires

10 min read

Record hours, not keystrokes

TimeTally records submitted and approved hours — no screenshots, no keystroke logging, no biometrics. Data is held in UK data centres.

Abstract network of connected data points representing workplace data

Ask a room of UK business owners whether they can track their employees' hours and about half will say "not since GDPR". They are wrong, but the instinct is not silly — the rules genuinely have teeth, and a few well-publicised enforcement actions have made everyone nervous.

The confusion comes from collapsing two very different things into one word. Employee monitoring — continuous surveillance of what someone is doing — sits at one end. Recording the hours somebody worked so you can pay them correctly and meet your statutory record-keeping duties sits at the other. The law treats them very differently, and getting the distinction right removes most of the anxiety.

The Distinction That Matters

Recording hours workedMonitoring activity
ExamplesTimesheets, clock in and out, leave recordsScreenshots, keystroke logging, continuous location, webcam checks
Typical lawful basisContract, and legal obligation for statutory recordsLegitimate interests, with a documented balancing test
Privacy intrusionLowHigh
DPIAGood practiceExpected, and often mandatory

You are in fact required to keep certain records. The Working Time Regulations 1998 require adequate records of hours worked to demonstrate compliance with the 48-hour limit, and the National Minimum Wage Regulations 2015 require records sufficient to establish that workers have been paid the minimum. An employer who kept no record of hours would be in breach of both. Our guides to tracking employee hours legally and HMRC timesheet requirements set those duties out.

"We can't record hours because of GDPR" is not a data protection position. It is a compliance failure wearing a data protection costume.

The ICO's Guidance on Monitoring Workers

In October 2023 the Information Commissioner's Office published dedicated guidance, Employment practices and data protection: monitoring workers. It is the single most useful document for any UK employer thinking about this, and it is written for non-lawyers.

Its central requirements:

1. Identify a Lawful Basis

You need one of the Article 6 bases. In practice:

Consent is almost always the wrong answer. For consent to be valid it must be freely given, and an employee who cannot get paid without agreeing is not free to refuse. If your data protection policy relies on employee consent for time recording, that is a red flag rather than a reassurance.

2. Be Transparent

Workers must know what is being collected, why, how long it is kept, who it is shared with, and what their rights are. This belongs in a privacy notice that people have actually seen — not buried in a handbook annex.

Transparency is also the practical difference between a system staff tolerate and one they resent. Most resistance to time recording is not about privacy in the abstract; it is about not knowing what the data will be used for.

3. Necessary and Proportionate

The test is whether the monitoring is necessary for the stated purpose and proportionate to it — and crucially, whether a less intrusive method would achieve the same aim. This is where most enforcement turns.

If your aim is to stop people clocking in for each other, and a phone-based clock-in achieves that, then fingerprint scanning is not necessary. That was precisely the ICO's reasoning when, in February 2024, it ordered Serco Leisure and associated trusts to stop using facial recognition and fingerprint scanning to monitor the attendance of more than 2,000 staff, and to destroy the biometric data they had gathered.

4. Do a DPIA Where the Risk Is High

A data protection impact assessment is mandatory where processing is likely to result in a high risk to people's rights. The ICO treats systematic monitoring of workers as falling squarely within that. A DPIA is not a formality — done properly it is the document that demonstrates you considered less intrusive options, which is exactly what a regulator will ask for.

5. Minimise and Retain Sensibly

Collect the minimum needed. Keep it only as long as necessary — which for minimum wage records means six years, and for Working Time Regulations records two. Delete monitoring data that no longer serves the purpose it was collected for.

The app is simple to use, reliable, and makes managing holidays, absences, and staff records straightforward. The system has saved us a significant amount of administration time.

CLI ManchesterJordan Ingoe, CLI Manchester
TimeTallyTimeTally

The Records You Need. Nothing You Don't.

Hours submitted, hours approved, leave taken — with a full audit trail for compliance reviews. No screenshots, no keystroke logging, no biometric data.

UK data centres
Role-based access control
Complete audit trail

Free for 14 days • No credit card required

Specific Situations

Location and GPS

Location data is not off limits, but it is high-impact and the proportionality test bites hard. Verifying that a care worker was at the right address when they clocked in is a narrow, purpose-limited use with an obvious justification. Tracking the same worker's position every two minutes throughout the day is a different proposition and needs a much stronger case.

The absolute line: do not track workers outside working hours. If your system can, it should be configured so that it does not, and you should be able to demonstrate that.

Biometrics

Biometric data used to identify an individual is special category data. You need both an Article 6 lawful basis and an Article 9 condition, plus a DPIA. Given the Serco outcome, the practical question to answer first is: what does biometric identification achieve here that a personal-device clock-in does not? If you cannot answer that crisply, do not deploy it. The alternatives are covered in our guide to time theft and buddy punching.

Remote and Hybrid Workers

Home is a domestic space, and monitoring that reaches into it — webcam checks, ambient screenshots, always-on activity trackers — is far harder to justify than the same measure in an office. Output-based management is not just less intrusive, it is easier to defend. See our guide to timesheet software for remote teams.

Covert Monitoring

Reserved for exceptional cases — typically suspected criminal activity or serious malpractice where notifying people would defeat the purpose. It should be authorised at senior level, tightly scoped, time-limited, and stopped as soon as the investigation concludes. Covert monitoring as a general management tool is not lawful.

Workers' Rights You Need to Be Ready For

A Practical Compliance Checklist

  1. Write down what you collect and why, in one page.
  2. Identify the lawful basis for each purpose — and do not use consent.
  3. Where you rely on legitimate interests, do the balancing assessment and keep it.
  4. Complete a DPIA for anything beyond straightforward hours recording.
  5. Publish a worker-facing privacy notice and make sure people have read it.
  6. Ask the proportionality question honestly: is there a less intrusive way?
  7. Set retention periods — six years for minimum wage records, two for working time.
  8. Restrict access by role, so a line manager sees their team and not the whole organisation.
  9. Check where your provider stores the data, and confirm it in the processing agreement.
  10. Review annually, and whenever you add a new monitoring capability.

Key Takeaways

Frequently Asked Questions

Is employee monitoring legal in the UK?

Yes, within limits. You need a lawful basis under UK GDPR, you must tell workers what you are doing and why, and the monitoring must be necessary and proportionate to a genuine aim. Excessive or covert monitoring is where employers get into trouble.

Do I need consent to track employee working hours?

Usually not, and consent is a poor choice in employment because the power imbalance means it is rarely freely given. Recording hours for payroll and statutory record-keeping is normally justified under contract, legal obligation or legitimate interests instead.

Do I need a DPIA for time tracking?

A data protection impact assessment is required where processing is likely to result in a high risk to individuals. The ICO treats systematic monitoring of workers as falling into that category, so anything beyond simple hours recording should have one.

Can employers track employee location?

Location data can be processed where it is necessary and proportionate — verifying a clock-in at a site is far easier to justify than continuous tracking. You must never track workers outside working hours.

Is fingerprint or facial recognition clocking allowed?

Biometric data used to identify someone is special category data, requiring an Article 9 condition and a DPIA. In 2024 the ICO ordered Serco Leisure to stop using facial recognition and fingerprint scanning for attendance monitoring.

Can employers monitor staff covertly?

Only in exceptional circumstances, such as investigating suspected criminal activity where telling people would prejudice the investigation. It must be targeted, time-limited and authorised at senior level.

Sources