Screenshots: What They Prove
The most intrusive capture and the least informative. What a screen capture establishes, and the cost of holding them.
Periodic screenshots are the feature that most defines these products in people's minds. They are also the one with the worst ratio of information to intrusion.
The practical lesson in “Screenshots: What They Prove” is to connect every record to a clear operational question without presenting visibility as certainty. Teams exploring remote desktop monitoring software can review this detailed guide as one source of time and project context, provided the purpose is disclosed and the configuration is reviewed with the people affected.
What a screenshot shows
What was on the screen at one instant.
For an independent reference relevant to “Screenshots: What They Prove”, consult the ICO employment-practices guidance; it provides a useful external check on scope, terminology, governance and the claims made during procurement or review.
Not what the person was doing before or after.
Not whether the work was good.
Not whether the window in focus was the work.
A single frame from a day, interpreted by somebody who was not there.
What it captures incidentally
Personal messages open in a tab.
Banking, health, family matters — because people deal with those during the day and always have.
A colleague's personal data, where the role involves customer or patient records.
Another person entirely, on a video call.
This is unavoidable rather than occasional, and it is why retention and access matter so much here.
The third-party problem
A screenshot of a customer record is a copy of somebody's personal data, taken for a purpose that person never agreed to.
In regulated work this is a substantive issue rather than an etiquette one.
Several organisations deploy screenshots without anybody having considered that the images contain other people's data, which is the finding that most often stops a deployment when raised.
Blurring and redaction
Some products blur, sample less often, or capture only the active window.
These are genuine improvements and worth asking for.
They also reduce the already thin evidential value, which is worth saying plainly: a blurred screenshot proves even less.
What they are legitimately used for
Investigating a specific concern, with a basis and a scope.
Demonstrating compliance in a narrowly regulated activity.
Not: routine assurance, which is what they are mostly sold for.
The holding
Thousands of images of employees' screens, retained, accessible to somebody.
A substantial data holding with retention obligations, access request obligations and breach exposure.
Ask who can browse them, because the common answer — the support or HR team generally — is the configuration that produces an incident.
The position worth taking
Do not capture screenshots for routine monitoring.
Where a genuine investigation requires them, enable narrowly, for a defined period, with approval.
This is both the proportionate position and the one that survives a challenge, and it removes the single largest objection people have to these programmes.
What to check
Does your deployment capture screenshots routinely?
Who can view them?
How long are they kept?
And has anybody considered that they contain other people's data?