Skip to content
Workly
Compliance

Monitoring employees: what GDPR allows and where abuse begins

Guide to employee monitoring: the conditions set by the Labour Code and GDPR, the proportionality test, prior notice, video cameras, work email and geolocation.

by Echipa Workly5 min read

Translated from Romanian. This article covers Romanian labour and tax law; the Romanian version is canonical and is updated first.

Cameras in the warehouse, GPS on company cars, checking work email, software that measures activity — monitoring has become commonplace, and the legal framework is often ignored. The underlying rule is simple: you may monitor, but not in any way you like and not anything you like. Here are the limits.

The basis in the Labour Code

The Labour Code (Codul Muncii) recognises the employer’s right to determine the organisation and functioning of the business and to check how work duties are carried out. Monitoring is therefore not prohibited in principle.

But the same code provides that the internal rules must contain provisions on protection, hygiene and safety at work, on observing the principle of non-discrimination and on respect for employees’ dignity — and any form of control must stay within those limits.

The conditions under GDPR

These are the rules that matter in practice. Monitoring employees is processing of personal data, so it requires:

1. A legal ground. The one most often invoked is the employer’s legitimate interest. The employee’s consent is not a solid ground in an employment relationship, because it cannot be regarded as freely given — there is a relationship of subordination.

2. The proportionality test. You must be able to demonstrate that:

  • the purpose is legitimate (security of assets, data protection, safety of persons);
  • the measure is necessary — there is no less intrusive alternative;
  • the effect on private life is proportionate to the benefit pursued.

3. Prior notice. Employees must be informed beforehand, clearly and fully: what is monitored, how, why, who has access, how long the data is kept. Covert monitoring is, as a rule, unlawful.

4. Minimisation. You collect only what is necessary for the purpose.

5. Retention. A defined period, with deletion at expiry.

The practical recommendation: document the decision through a legitimate interest assessment, and, for systematic large-scale monitoring, through a data protection impact assessment (DPIA).

By type of monitoring

Video cameras. Permitted for the security of assets and persons. Prohibited in changing rooms, toilets and rest areas. They cannot be used for continuous surveillance of individual productivity. They require visible signage and notice.

Work email and internet. The employer may set rules of use and may check that they are observed, but access to the content of communications is the last resort, not the first. European case law has established that the employee retains a reasonable expectation of privacy even on work equipment, if they were not clearly informed in advance. Correspondence marked as personal enjoys enhanced protection.

Geolocation (GPS). Legitimate for company vehicles and logistics. It must be switched off outside working hours — tracking an employee in their free time is a clear breach. It cannot be used to assess personal behaviour.

Biometric time tracking. Biometric data is a special category under GDPR, with strict conditions. For simply recording attendance there are less intrusive alternatives (card, code, app), which makes it difficult to justify the necessity of a fingerprint or facial recognition.

Productivity software. Permanent screenshots, keystroke logging or “activity” scores are hard to justify as proportionate. Monitor the outcome and the working time, not every gesture.

What the notice must contain

  • what data is collected and by what means;
  • the specific purpose of each form of monitoring;
  • the legal ground;
  • who has access to the data;
  • the storage period;
  • the employee’s rights (access, rectification, objection, complaint to ANSPDCP, the Romanian data protection authority);
  • the contact details of the data protection officer, if there is one.

The notice is given at hiring and updated on any change. A vague mention in the contract is not enough.

Penalties

Non-compliant processing of employee data may attract GDPR penalties applied by ANSPDCP, calculated by reference to turnover. Separately, the employee may claim damages in court, and evidence obtained through unlawful monitoring may be excluded from an employment dispute — including in a disciplinary procedure you were relying on.

That last point is the most costly in practice: a disciplinary dismissal supported exclusively by unlawfully obtained evidence is annulled.

Frequently asked questions

Can I install cameras in the company? Yes, for the security of assets and persons, with notice and signage. Not in changing rooms, toilets or rest areas, and not for continuous surveillance of productivity.

Can I read an employee’s work email? You can check compliance with the rules of use, but access to content is the last resort and requires clear prior notice. Personal correspondence has enhanced protection.

Does the employee’s consent solve the problem? No. In an employment relationship, consent is not regarded as freely given because of the relationship of subordination. The usual ground is legitimate interest, with a documented proportionality test.

Can I track the GPS of a company car? Yes, for business purposes, but with tracking switched off outside working hours. Tracking in free time is a breach.

Is fingerprint time tracking lawful? Biometric data has a special regime. The existence of less intrusive alternatives (card, code, app) makes it difficult to justify the necessity.

See also GDPR in HR, telework vs. work from home, and the internal rules of procedure.

How Workly helps

Workly is built on the principle of minimisation: for attendance records it collects what is necessary — the moment of the clock-in and, where the arrangement requires it, whether the person is within a perimeter — not biometric data and not continuous tracking. Clocking in through a kiosk with a rotating QR code or an NFC card solves the identification problem without fingerprints, and therefore without the special category of data.

Geolocation, where it is enabled, works as a perimeter check at the moment of clocking in, not as permanent tracking — an essential difference in the proportionality test. Data has a configured retention period with automatic purging at expiry, and access is role-based, so that information reaches only those with an operational need for it. And the notice given to employees, together with proof that they have read it, is kept in the digital file.


Informational article, accurate at the date of publication. Not legal advice. Employee monitoring requires an individual proportionality assessment — consult a data protection specialist before implementing a monitoring solution.

Want to see Workly in action?

We'll show you how time tracking, payroll and the rest of the modules work for your company, in a short demo.

Request a demo