Workplace Monitoring DPIAs
What the Government's Consultation Doesn't Tell You
Written by Phil Brining
The government has opened a consultation on workplace monitoring technology. Philip Brining looks at what your Data Protection Impact Assessment already needs to prove, regardless of what the consultation decides.
Around one in three UK organisations now monitor employees’ digital activity, up from one in five just a few years ago. The government has opened a consultation on whether that growth needs new rules around it, a statutory code, a duty to consult workers, or just better guidance. It runs until the end of September, and it’s not proposing to change the law yet.
Here’s the bit that matters right now, though, regardless of what the consultation eventually decides: if your monitoring is likely to be high-risk (and, let’s face it, monitoring is likely to be deemed to be intrusive, a potential abuse of power, and difficult to effectively object to), you already need a Data Protection Impact Assessment. That obligation isn’t new and isn’t waiting on this consultation.
What I want to talk about isn’t the consultation itself, there’ll be plenty written about its eight principles and three options for intervention. It’s the DPIA employers are already required to do, and how often, in my experience, it ends up being a document written to justify a decision that’s already been made rather than one that tested it.
Here are a few honest questions your own workplace monitoring DPIA should be able to answer.
Is there real human involvement, or a rubber stamp?
The law already requires meaningful human oversight where monitoring feeds into decisions with a significant effect on someone. In practice, “human involvement” too often means a manager clicking approve on whatever the system flagged, without the time, training or genuine authority to disagree with it. If the person signing off couldn’t tell you why the system flagged what it flagged, that’s not oversight, it’s a signature.
Could you explain this to the people it monitors, in a sentence, without reaching for a privacy notice?
The consultation itself makes a good point here: a privacy notice isn’t the same as workers actually understanding what’s being collected and why. If your explanation only exists in a document nobody reads, you don’t have transparency, you have a compliance artefact. The test I’d apply is simpler: could someone on the team explain, in plain terms, what’s being monitored and what it’s used for, without looking anything up?
Was “least intrusive” actually tested, or decided after the tool was already chosen?
This is the one I see skipped most often. The tool gets picked first, usually because it’s already been bought, or IT already uses it for something else, and the DPIA gets written afterwards to justify it. A genuine assessment asks what you’re actually trying to achieve and works backwards to the least intrusive way of achieving it, not the other way round.
What actually happens when the system’s wrong about someone?
Every monitoring tool will misread someone eventually, a slow week that wasn’t laziness, a flagged message that wasn’t what it looked like. The question worth answering honestly is whether there’s a real route for someone to challenge that, or whether the data just sits there as fact once it’s been recorded.
None of this needs to wait for the consultation to conclude. If anything, this is a good moment to go back through the DPIAs already sitting in a folder somewhere and ask whether they’d survive being read properly, by a regulator, an employment tribunal, or the people they’re actually about.
I was asked to review a DPIA only this week about a fingerprint scanning system installed in a medium-sized workplace for the purpose of fire evacuation roll calls. Crikey, talk about a sledgehammer to crack a nut. “Why” was the obvious question to ask, but I seemed to be the only person interested in pursuing this line of enquiry.
I’m often told that the reason for using biometrics for time and attendance management in a workplace is to stop people clocking in or out for someone else. A typical scenario is that Billy knocks off early for a round of golf, and Frank clocks him out using his physical RFID pass hours after Billy has teed off. So in that scenario, Billy is alleging to remain in the workplace when he’s actually on the fairway. But that scenario doesn’t work for fire evacuation. Billy is hardly going to say, “Hey Frank, is that the fire alarm I hear? Listen, I’m going to stay here and sit it out. Do me a favour, take my pass and pretend I’ve left the building for the roll call!” Who in their right mind would do that?
So what’s the justification for using such advanced biometric technology to automate fire evacuation roll call information. Where is the risk assessment? In addition to the technical risk, you know how it is trying to unlock your phone. One, two, three, or more attempts is often the way it works. Imagine the queue to clock out.
Then there’s the risk of scope creep. What’s stopping the clocking data being used for monitoring time and attendance more generally? And that brings me to another conversation I had this week. “Hey Phil, I’m worried that Billy is going AWOL when he’s working from home as his Teams availability flag is set to unavailable which means his laptop is not active.” But a Teams flag isn’t there for monitoring productivity and presenteeism, for a start, Billy could be doing paperwork, or by contrast, he could be on the fairway with his Teams active on his mobile phone.
I guess the point I am rambling about is that DPIAs are a mechanism that has been around in the UK for almost 20 years and still, the vast majority of those I read fail to describe and explain the envisaged processing and are extremely weak in the risk identification section.
If it’s been a while since your monitoring DPIAs were properly stress-tested, that’s exactly the kind of thing we help clients work through.
Written by Phil Brining