Manage HR Magazine | Monday, November 20, 2023
The UK has adopted a progressive approach to workplace monitoring regulations to balance employee privacy and organisational security.
FREMONT, CA: The UK's Information Commissioner's Office (ICO) released updated workplace monitoring guidelines on October 3rd, 2023. All businesses that abide by UK data protection law must follow the guidelines. This implies that non-UK businesses will be covered if they are established in the UK, aim their products or services at UK consumers, or monitor their behaviour. Furthermore, the guidelines address monitoring of workers as well as employees.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
According to the definition of worker, a person who works for a firm does so regardless of the type of contract they have; this would include consultants and contractors who are hired directly by the business. This means that the guidelines have a very broad application.
Recommended Actions for the Companies
Employers who observe employees need to inform employees about the type, scope, and purpose of the observation. Establish a precise goal for the monitoring process. To do so, employ the least invasive method of observation. Possess a legitimate reason for handling employee personal data.
Regardless of the specific monitoring technology being used, businesses must adhere to the standards of UK data protection law. Nonetheless, the guidelines acknowledge that certain monitoring technologies may pose extraneous or distinct issues.
For instance, if a business uses monitoring data to make automated decisions that have a substantial impact on employees' legal or other matters, it must give employees access to relevant information about the reasoning behind the decisions and the ability to appeal or request human intervention.
Companies are required to perform a data protection impact assessment (DPIA) when high-risk monitoring poses a threat to the rights of employees. Even if it's not required, it's still a good idea to finish a DPIA to guarantee impartial monitoring procedures. If there isn't a good reason to keep workers or their representatives out of worker monitoring plans, data protection officers (DPOs) should lead DPIAs and participate in them.
Ways to Monitor Workers
Article 6 Legal Basis and Article 9 Permitted the Purpose
The advice highlights the need for employers to create a permitted purpose for data processing if workplace monitoring may necessitate processing special category data, even accidentally. Email monitoring, for example, may disclose such information, requiring both an Article 9 approved purpose and an Article 6 legal justification.
Although monitoring is frequently justified as a legitimate interest, the guidelines advise against doing so if workers are not informed or expect it, which may limit the use of monitoring as a valid legal justification. Though consent is generally discouraged because of power disparities, it may be appropriate in some situations as long as non-consenting workers have other options.
Companies must specify the precise legal duty or right that supports their conduct when processing special category data under Article 9, using relevant legal statutes or credible sources.
Workers Right to Object
The guidelines acknowledge an employee's ability to object to monitoring in cases where the company's legitimate interests or the accomplishment of a public job are the Article 6 legal foundation. The employee's right to object is not unqualified, and they must give a reason for doing so. If the corporation can show that it has compelling legitimate interests, that the monitoring is necessary for the creation, pursuit, or defence of legal claims, or that the complaint is baseless or disproportionate, then it may be allowed to carry on with its monitoring.
Customer-requested Monitoring
When customers request businesses to monitor workplaces, adherence to UK data protection laws remains imperative. Even with consumer approval for employee monitoring, firms must conscientiously justify such actions. The guidelines emphasise that, despite customer requests, companies are obligated to operate within the legal framework, ensuring that any workplace monitoring aligns with the principles and regulations set forth by UK data protection laws. Thus, even with customer consent, businesses must navigate the delicate balance between meeting consumer expectations and upholding the stringent requirements of data protection legislation in the UK.
Biometric Data Monitoring
A corporation must implement security measures proportional to the risks of unauthorised access or disclosure if it gathers or uses biometric data to monitor employees (e.g., by controlling access by facial recognition). The guidelines point out that biometric data is typically immutable, in contrast to other types of data like passwords, which increases the severity of the risks involved in a data breach. The guidelines specifically advise against keeping biometric templates next to other photos or lists and in a manner that permits reverse engineering into the original image.
Covert Monitoring
Covert monitoring is probably only appropriate in very certain situations, including when there is a suspicion of criminal conduct and telling employees about the monitoring would make it more difficult to stop or identify the activity. Even if businesses can defend covert surveillance in theory, it shouldn't be done in public spaces like restrooms or locker rooms where employees would reasonably expect privacy, nor should it record correspondence that they would fairly expect to be private, such as personal emails.
These approaches reflect the nation's commitment to fostering a harmonious and productive work environment in an era of increasing technological integration and data-driven decision-making.
More in News