On a company laptop, your employer can technically see almost everything: the apps and websites you use, your keystrokes, periodic screenshots, and sometimes webcam or microphone input. Whether they are allowed to use those capabilities depends heavily on where you work. US law mostly requires notice, while UK and EU data protection law demands that monitoring be necessary, proportionate and transparent. In every case, a VPN does nothing to hide your activity from software installed on the device itself.
What employee monitoring software can capture
“Bossware” is a loose term for software that tracks employees’ computer activity. A 2020 review of ten commercial products by the Electronic Frontier Foundation (EFF, 2020) found that the typical feature set goes well beyond time tracking.
| Capability | What it records | Source |
|---|---|---|
| Keystroke logging | Every key pressed, including drafts never sent | EFF, 2020 |
| Screenshots / screen video | Frequent captures or live feeds of the screen, organized as a timeline | EFF, 2020 |
| App and web activity | Applications, sites, email, chat and social media use | EFF, 2020 |
| “Productivity” scoring | Minute-by-minute keyboard and mouse input used as a proxy for work | EFF, 2020 |
| Webcam and microphone | At least two reviewed products could activate them covertly | EFF, 2020 |
| Location | GPS data from company phones | EFF, 2020 |
| Warehouse task timing | Seconds between barcode scans, idle periods | EDPB, 2024 |
The EFF also noted that several products can run in a hidden “stealth” mode, so the absence of a visible icon does not mean a device is unmonitored.
How common workplace monitoring is
There is no official government count of monitored workers in the US, UK or EU, so the best data comes from surveys and investigations.
United States
A YouGov survey of 1,273 US workers conducted in July 2024 for the Washington Center for Equitable Growth found that 68% reported at least one form of electronic monitoring (Equitable Growth, 2024). Exposure rose sharply with employer size: 88% at organizations with 1,000 or more employees versus 43% at firms with fewer than ten. Black workers (82%) and Hispanic workers (73%) reported monitoring more often than white workers (65%).
The same study linked intense monitoring to worse outcomes. Among workers under constant productivity tracking, 46% said they felt pressure to work too fast, compared with 15% of unmonitored workers. The author cautioned that monitoring used for discipline showed stronger links to harm than monitoring used for safety.
Earlier, a 2022 examination by The New York Times found that 8 of the 10 largest private US employers track individual productivity metrics, many in real time, and that tracking was spreading from warehouses into white-collar roles (The New York Times, 2022).
United Kingdom
Research commissioned by the Information Commissioner’s Office found that 70% of the public would consider monitoring by an employer intrusive, and 19% believe they have been monitored (ICO, 2023). The second figure measures belief, not verified monitoring.
What the law allows in the US, UK and EU
United States
US federal law places few limits on monitoring company-owned devices. Some states add notice duties. New York’s Civil Rights Law § 52-c, in force since May 2022, requires private employers to notify new hires in writing of electronic monitoring of phone, email and internet use, obtain an acknowledgment, and post the notice; penalties start at $500 for a first violation (Justia, 2021). The law requires notice but sets no limit on what is collected.
United Kingdom
The ICO’s October 2023 guidance sets these conditions for monitoring (ICO, 2023):
- Employers must tell workers what is monitored and why.
- High-risk monitoring, explicitly including keystroke logging and biometrics, requires a Data Protection Impact Assessment first.
- Covert monitoring should be limited to exceptional cases such as suspected crime, authorized by senior management and time-limited.
- Monitoring at home is covered by data protection law, and the ICO stresses that workers have greater privacy expectations there.
European Union and Germany, where the rules are strictest
Under the GDPR, monitoring needs a lawful basis and must respect data minimization. The European Court of Human Rights added a human rights layer in Bărbulescu v. Romania (2017), ruling 11 to 6 that a worker’s Article 8 rights were violated because courts had not checked whether he was told in advance about the nature and extent of the monitoring of his messages (ECHR, 2017).
Germany goes further. Under Section 87(1) No. 6 of the Works Constitution Act, a works council has a co-determination right over introducing technical systems intended to monitor employees’ behavior or performance (Gesetze im Internet). In practice, a company with a works council cannot simply roll out monitoring software unilaterally. In 2017 the Federal Labor Court ruled that covertly logging an employee’s keystrokes without concrete suspicion of a serious breach was unlawful, and the resulting evidence could not be used to justify his dismissal (BAG, 2017).
Since February 2, 2025, the EU AI Act has also prohibited AI systems that infer the emotions of people in the workplace, unless used for medical or safety reasons (European Commission, 2024).
Notable enforcement cases
| Year | Country | Employer | Outcome | Source |
|---|---|---|---|---|
| 2020 | Germany (Hamburg DPA) | H&M service center, Nuremberg | €35.3 million fine for recording details of staff’s private lives, including health information gathered in “welcome back” talks | Hunton Andrews Kurth, 2020 |
| 2023 | France (CNIL) | Amazon France Logistique | €32 million fine over warehouse scanner indicators, 31-day retention of all data, and video surveillance shortcomings | EDPB, 2024 |
| 2025 | France (Conseil d’État) | Amazon France Logistique (appeal) | Fine reduced to €15 million; performance indicators found lawful, data minimization breach upheld | Portail RGPD, 2025 |
The Amazon France case in detail
Amazon’s French warehouse staff used handheld scanners that logged each task. According to the EDPB summary of the CNIL decision, one indicator flagged an error when an item was scanned less than 1.25 seconds after the previous one, and others measured idle time (EDPB, 2024). The CNIL considered these indicators excessive.
On December 23, 2025, France’s highest administrative court partly disagreed (decision no. 492830). It held that the three performance indicators had a valid legal basis, but it confirmed that keeping every employee’s detailed scan data for 31 days breached data minimization. Breaches of information and security duties were not contested. The fine was cut to €15 million (Portail RGPD, 2025). Under this ruling, real-time productivity metrics are not automatically unlawful in the EU, and how long and how broadly the data is kept matters as much.
Why a VPN does not hide activity from your employer
Monitoring software runs on the device itself and records activity before any traffic is encrypted, so a VPN cannot hide keystrokes, screenshots or application use from it. On a managed work device, installing your own VPN may also violate IT policy, and corporate network or endpoint tools can often detect that one is running. A VPN protects traffic in transit from networks you do not control, but it offers no protection from software controlled by the device’s owner.
What employees can do
- Assume a work device is monitored. Keep personal browsing, banking, health searches and private messages on your own phone or computer.
- Ask for the policy in writing. In the UK and EU you are entitled to know what is monitored and why; you can also file a data subject access request to see data held about you.
- Watch for personal-device enrollment. Mobile device management profiles or “bring your own device” agents can give an employer visibility into a personal phone, so read what you are agreeing to.
- Check for a works council or union. In Germany and several other EU countries, employee representatives have a say before monitoring tools are introduced.
- In the US, check state law. New York and a few other states require notice; most do not limit what can be collected on company equipment.
- Report overreach. UK workers can complain to the ICO, EU workers to their national data protection authority.
Methodology
Sources are primary legal texts (the German Works Constitution Act, New York Civil Rights Law, the EU AI Act), regulator publications (ICO, EDPB), court decisions (ECHR, German Federal Labor Court, French Conseil d’État as reported by Portail RGPD), one policy-research survey (Equitable Growth/YouGov) and two investigative or advocacy sources (The New York Times, EFF).
Prevalence figures come from surveys of self-reported monitoring and may undercount covert tracking. The EFF product review dates from 2020, and specific feature sets change frequently. The enforcement cases are examples, not a complete list of fines. Vendor-commissioned market surveys are excluded because their methods are rarely published. This article is general information, not legal advice.