Skip to content
What the Dashboard Cannot See

All notes / Obligations

What Must Be Disclosed

The minimum that has to be told to employees, and the larger amount that is worth telling anyway.

Obligations · Reference

General orientation, not legal advice; disclosure requirements differ by jurisdiction.

The safeguards described in “What Must Be Disclosed” should be decided before a workforce platform is configured. A team evaluating this workplace platform for employee monitoring software with screenshots can make the deployment more credible by stating its purpose, selecting only necessary settings and explaining exactly what managers may review.

Transparency obligations set a floor. Meeting only the floor produces a notice nobody reads and a workforce that feels informed about nothing.

For an independent reference relevant to “What Must Be Disclosed”, consult the ICO employment-practices guidance; it provides a useful external check on scope, terminology, governance and the claims made during procurement or review.

The usual legal minimum

That monitoring takes place.

What categories of data are collected.

The purpose.

The legal basis.

How long it is kept.

Who it is shared with.

Rights, including access.

Typically delivered in a privacy notice.

Why the minimum is insufficient

It is written in the language of compliance and read by nobody.

It describes categories rather than specifics: "activity data" rather than "screenshots every ten minutes".

And it answers none of the questions people actually have, which the telling-people note lists.

What is worth disclosing beyond it

The specific list: these signals, at this frequency.

What is not collected, which is the part that gets read.

Who can see individual data, if anybody, and under what process.

Whether it is used in performance or disciplinary processes — stated plainly either way.

What the software could do that you have disabled, and who can change that.

The configuration-change commitment

A statement that any change to what is collected will be announced before it takes effect.

Cheap to give, and it is what makes everything else credible, because the obvious worry is that the scope expands quietly.

Delivery

Not only in a notice.

A short page people can find, a conversation at induction, and a mention when anything changes.

And available to candidates who ask, which they increasingly do and which is better answered openly than evasively.

The access right

People can usually ask what you hold about them.

The answer includes their activity records and, if captured, their screenshots.

Producing that is an obligation and the experience of reading it is informative for the organisation too, which the access-request note covers.

What not to do

Describe screenshots as activity data.

Say monitoring is "anonymous" when individual records exist.

Promise limits the configuration does not enforce.

Or disclose only in a document signed at hiring, which is legally weak and practically invisible.

The test

Could an employee, from what you have published, predict what their own data contains?

If not, the disclosure has not done its job, whatever the notice says.

What to check

Is there a disclosure beyond the privacy notice?

Does it list specifics or categories?

Does it say whether the data is used in performance processes?

And could somebody predict the contents of their own record from it?