Under the GDPR, which lawful basis can an employer use to monitor staff laptops, and why does employee consent rarely work?
answer
- imbalance of power
- refusal without detriment
- a defined security purpose
- Recital 43, Art. 88
basics
~20 sUnder the GDPR, employee consent is rarely valid because refusing an employer is risky (Recital 43; EDPB Guidelines 05/2020). Laptop monitoring usually rests on legitimate interests such as security, after documented necessity and balancing, or on a legal obligation.
solid answer
~50 sUnder the GDPR, consent must be freely given, and Recital 43 says it is not a valid ground where there is a **clear imbalance** between data subject and controller. EDPB Guidelines 05/2020 apply that to employment: employees are unlikely to refuse without fear of detriment, so for most workplace processing the basis *cannot and should not* be consent. Monitoring laptops therefore usually rests on **legitimate interests** (`Art. 6(1)(f)`), for instance protecting the network and data (Recital 49 names network and information security), provided the employer defines a precise purpose, shows the monitoring is **necessary** with no less intrusive option, and passes the **balancing** test given staff's reasonable expectations. Where a law requires specific monitoring, **legal obligation** (`Art. 6(1)(c)`) applies. National law or collective agreements may add rules under `Art. 88`, and staff can object under `Art. 21(1)`.
go deeper
Recall that employee consent is rarely valid because of the imbalance of power, and that legitimate interests or legal obligation usually carry workplace processing.
Explain Recital 43 and the EDPB's employment reasoning, then run the three-step legitimate-interests test on a concrete monitoring control.
Grade monitoring controls by intrusiveness, justify each with necessity and balancing, account for Art. 88 national rules, and keep special-category content out of capture.
Set the organisation's position on how intrusive monitoring may be, weighing security value against trust, legal exposure and variation across the countries you employ in.
## The scenario An employer wants to install monitoring software on company laptops: logging network connections, detecting malware and data exfiltration, perhaps capturing screenshots or keystrokes. Under the GDPR (Regulation (EU) 2016/679), employees' activity data are personal data, and the employer is the controller. The first design decision is the **lawful basis** under `Art. 6(1)`. ## Why consent rarely works for employees Consent is one of six bases, but it only works when the person has a real choice: - **Recital 43** says consent should not provide a valid legal ground where there is a *clear imbalance* between the data subject and the controller. - **Recital 42** says consent is not freely given where the person *has no genuine or free choice or is unable to refuse or withdraw consent without detriment*. - **EDPB Guidelines 05/2020 on consent** (para. 21) say an imbalance of power also occurs in employment: it is unlikely an employee could refuse consent to, for example, monitoring systems *without experiencing the fear or real risk of detrimental effects*. The EDPB concludes that *for the majority of such data processing at work, the lawful basis cannot and should not be the consent of the employees*. - Para. 22 adds that this does not mean employers can **never** rely on consent: employees can give free consent in exceptional circumstances, when it has no adverse consequences at all whether or not they give it. There is also a practical problem. Consent can be withdrawn at any time, and the processing based on it must then stop. A security control that any employee can switch off by withdrawing consent is not a control. ## The bases that can carry monitoring | Basis | When it fits | |---|---| | **Legitimate interests (`6(1)(f)`)** | The usual basis: security, protection of company data and systems, preventing misuse, after a documented three-step test | | **Legal obligation (`6(1)(c)`)** | Where Union or Member State law requires specific monitoring or record-keeping | | **Contract (`6(1)(b)`)** | For processing genuinely necessary to perform the employment contract, such as paying wages; broad monitoring is rarely necessary for it | | **Consent (`6(1)(a)`)** | Only exceptional cases where refusal carries no consequence | Recital 49 supports the security purpose: processing *strictly necessary and proportionate* for ensuring network and information security constitutes a legitimate interest of the controller concerned. ## Running the legitimate-interests test for monitoring 1. **Interest.** State it precisely: detecting malware and exfiltration of customer data from company devices, not "keeping an eye on staff". 2. **Necessity.** Show which data each control needs and why less intrusive means will not do. Endpoint security alerts and connection metadata are one thing; continuous screenshots and keystroke logging are another and much harder to justify. 3. **Balancing.** Weigh the intrusion against staff's reasonable expectations (Recital 47), the power imbalance, private content on work devices, and safeguards such as limited access, short retention, and alerts reviewed rather than bulk surveillance. Document the outcome before deploying, tell staff what is monitored and why (`Art. 13(1)(c)` and `(d)`), and be ready to handle objections under `Art. 21(1)`. ## National employment rules `Art. 88(1)` lets Member States, by law or by **collective agreements**, provide more specific rules for processing employees' data, including for the management and organisation of work and the protection of the employer's property. `Art. 88(2)` requires those rules to include measures safeguarding human dignity and fundamental rights, with particular regard to transparency and **monitoring systems at the work place**. A monitoring rollout therefore has to be checked against national law, not only against the Regulation. ## Where special categories creep in Monitoring can reveal special-category data, such as health information in a browsing history or trade union activity in email. That brings the `Art. 9` prohibition into play, and legitimate interests cannot lift it. A well-designed control avoids capturing content that could reveal such data. ## Common mistakes - Adding a consent clause to the employment contract and treating monitoring as settled. - Justifying keystroke logging with a generic "security" interest and no necessity analysis. - Ignoring national law under `Art. 88`. - Treating "company device" as meaning "no personal data on it".
- Under EDPB Guidelines 05/2020, can an employer ever rely on employee consent?Yes, exceptionally. Para. 22 says employees can give free consent only in exceptional circumstances, when giving or refusing it has no adverse consequences at all. Example 5 (para. 23) is a film crew in part of an office: staff who decline are not penalised and are given equivalent desks elsewhere during filming. Monitoring used to protect systems does not fit that pattern.
- Under GDPR Art. 88, what can Member States add for workplace monitoring?More specific rules, by law or collective agreements, for processing employees' data in the employment context. `Art. 88(2)` requires those rules to include suitable and specific measures safeguarding dignity, legitimate interests and fundamental rights, with particular regard to transparency and monitoring systems at the work place, so national requirements may apply on top of the Regulation.
- Under the GDPR, why is keystroke logging harder to justify than malware detection on legitimate interests?The necessity and balancing steps weigh how much data a control captures against the interest it serves. Malware and exfiltration detection uses limited signals tied to a clear security interest (Recital 49). Keystroke logging captures everything typed, including private and possibly special-category content, so less intrusive means usually exist and staff's reasonable expectations weigh against it.
saying these in an interview costs you the question
- A consent clause in the employment contract makes monitoring lawful.
- Company devices hold no personal data, so the GDPR does not apply to them.
- A generic security interest justifies any level of monitoring.
- Employers can never rely on employee consent for anything at all.
- National employment rules cannot add anything to the GDPR's requirements.