Can an Employer Monitor Remote Workers? What Your Boss Can Legally See in 2026

Photo of author
Author: Alex
Published:
Updated:

Last Updated: July 2026

Direct Answer: Yes. In the US, EU, and UK, an employer can monitor remote workers on company-owned devices but the rules differ sharply. US federal law allows broad monitoring for a business reason, and a growing list of states requires written notice first. EU and UK law go further: monitoring must be transparent, proportionate, and backed by a valid legal reason.

Can an employer monitor remote workers without telling them? Picture this: your company laptop fan spins up at random, a new “productivity agent” sits in your system tray, and HR just refreshed the acceptable use policy. Millions of remote workers have noticed the same signs. What your boss can legally see depends on where you live, whose device you use, and which privacy law applies starting with the big one, GDPR.

The Short Version

  • In the United States, monitoring company devices is legal almost everywhere under the Electronic Communications Privacy Act (ECPA) a 1986 federal law as long as there is a real business reason. Connecticut, Delaware, New York, and now California add notice or disclosure duties on top.
  • In the European Union, GDPR (2018) treats monitoring data as personal data. Employers need a lawful basis, must tell workers what they collect, and cannot track more than the job genuinely requires.
  • In the United Kingdom, employers can monitor under UK GDPR and the Data Protection Act 2018, but the regulator (the ICO) says covert monitoring and constant webcam or audio recording are almost never justified.
  • Personal devices are different everywhere. Without clear consent, an employer generally cannot install tracking software on a laptop or phone the worker owns.

What the Law Actually Says About Monitoring Remote Workers

The question “can an employer monitor remote workers” has three very different answers depending on jurisdiction. Here is how each system treats remote work surveillance in 2026.

In the United States: Broad Rights, With State-Level Limits

In the United States, the starting point is the Electronic Communications Privacy Act (ECPA) of 1986. The ECPA contains a business purpose exception a rule that lets employers intercept and review electronic communications on equipment they own, as long as there is a legitimate business reason such as security, quality control, or productivity. Federal law does not require employers to tell anyone that monitoring is happening.

That silence is why several states stepped in with their own employee monitoring software law. Connecticut, Delaware, and New York each passed statutes that require written notice before electronic monitoring begins. New York’s rule, Civil Rights Law Section 52-c (2022), is the strictest of the three. It requires written notice at hiring, a signed or electronic acknowledgment from the employee, and a posted notice that all workers can see. It covers remote employees who work from New York, even when the company is headquartered in another state.

California added a major new layer in 2026. Assembly Bill 1221, effective January 2026, requires employers to name the specific monitoring methods they use screenshots, keystroke logging, app tracking and to explain why each one is necessary, not merely useful. Separate California privacy rules that took effect the same month require businesses to run a formal risk assessment before processing sensitive data through automated employee monitoring tools.

A few more US rules matter for remote workers. Eleven states plus DC apply two-party consent a wiretap rule that means audio cannot be recorded unless everyone on the call agrees. Illinois adds the Biometric Information Privacy Act (BIPA) (2008), which requires written consent before collecting fingerprints or face scans and lets workers sue directly. One more point trips up many employers: the law of the state where the employee physically works applies, not the law of the state where the company sits.

In the European Union: Monitoring Must Be Proportionate

In the European Union, GDPR (2018) treats everything monitoring software collects screenshots, keystrokes, idle time, location as personal data (any information about an identifiable person). That triggers the full set of GDPR duties.

First, the employer needs a lawful basis a legal justification listed in Article 6 of GDPR. Consent rarely works here, because European regulators say a worker who fears for their job cannot consent freely. Most employers instead rely on legitimate interest, which requires a balancing test: the company’s interest must outweigh the worker’s privacy rights.

Second, GDPR demands data minimisation collecting only what the stated purpose genuinely requires. Constant, second-by-second tracking usually fails this test. Third, Articles 12 and 13 require clear, upfront information about what is collected, why, and for how long. Fourth, systematic monitoring usually requires a Data Protection Impact Assessment (DPIA) a documented risk review before the software is switched on.

The EU AI Act (2024) added a hard line. Since February 2025, AI systems that infer workers’ emotions reading stress or attention through webcams, for example are banned in the workplace across the EU, with narrow health and safety exceptions.

Several EU countries pile on national rules. In France, employers must consult the works council before introducing monitoring, and French courts have thrown out evidence gathered through undisclosed monitoring, even where the employee had genuinely done something wrong.

In the United Kingdom: The ICO’s Ground Rules

In the United Kingdom, monitoring falls under UK GDPR and the Data Protection Act 2018. The regulator, the Information Commissioner’s Office (ICO), finalized dedicated “Monitoring Workers” guidance in October 2023, written specifically to cover working from home and newer tracking technologies.

The UK approach mirrors the EU one: lawful basis, transparency, proportionality. Two points stand out for anyone with work from home privacy rights in mind. The ICO says privacy expectations are higher at home than in an office, and the risk of capturing family life a partner walking past the webcam, a child’s voice on a call must be weighed before monitoring starts. The ICO also warns that continuous audio and video recording is highly intrusive and unlikely to be justifiable in most circumstances.

A DPIA is required before high-risk monitoring such as keystroke logging, reading email content, or processing biometric data. Covert monitoring tracking workers without telling them is reserved for rare cases like investigating suspected crime, and even then it needs senior sign-off.

Scales of justice weighing webcam and keyboard icons against a padlock, showing limits when employers monitor remote workers

What Employer Spy Software Can Actually Record

The term employer spy software covers a wide family of tools, sometimes marketed as “productivity” or “insider risk” platforms. Knowing what each feature records makes it easier to match the software against the law of your jurisdiction.

Screenshots and screen recording. Most platforms capture the screen at set intervals or record it continuously. On a company device in the US, periodic screenshots are broadly legal with a business purpose, though California now demands a written justification for them. French and UK regulators draw a line between periodic captures and continuous recording the second is treated as excessive in most cases.

Keystroke logging. This records everything typed, including passwords and private messages typed by mistake. The ICO lists keystroke monitoring among the high-risk practices that require a DPIA before use. Under GDPR, it also runs headfirst into data minimisation, because it captures far more than any productivity goal requires.

App, website, and idle-time tracking. The most common category, and the most defensible one legally, since it records that an app was open rather than what was written inside it. Even so, the Amazon France case shows that idle-time tracking measured in seconds can cross the legal line in Europe.

Webcam and microphone access. The most intrusive tier. Continuous webcam feeds from a worker’s home capture bedrooms, family members, and private conversations. European courts and the ICO treat “camera always on” as close to indefensible, and 11 US states plus DC require everyone’s consent before audio recording.

Location tracking. Built into company phones and laptops through GPS or network data. Disclosure is required in several US states, and tracking outside working hours is one of the practices California’s 2026 rules now restrict.

One category sits apart from all of these: emotion recognition AI that claims to read stress, boredom, or attention from a worker’s face or voice. In the EU, this is no longer a gray area. The AI Act banned it in the workplace outright in February 2025.

Real-World Examples

The Amazon France case. In December 2023, France’s data protection authority (the CNIL) fined Amazon France Logistique €32 million for an excessively intrusive system that tracked warehouse workers’ activity through handheld scanners. The system flagged scanner “idle time” and even scanning items too fast. In December 2025, France’s highest administrative court cut the fine to €15 million, finding some real-time tracking justified but it upheld the finding that keeping detailed productivity data on every worker for 31 days broke GDPR’s data minimisation rule. The case remains the clearest signal in Europe: tracking every second of a worker’s day is legally risky.

The webcam refusal case. In 2022, a Dutch court ruled on a remote worker fired by a US software company after he refused to keep his webcam on for nine hours a day. The court found the demand violated his right to a private life under the European Convention on Human Rights and awarded him roughly €75,000. The lesson travels well beyond the Netherlands: in Europe, “camera always on” is close to indefensible.

The multi-state notice trap. A Texas company hires a remote customer support agent who lives in Buffalo, New York. The company installs screenshot software without a word, as Texas law allows at home. Because the agent works from New York, Section 52-c applies anyway and monitoring without written notice and a signed acknowledgment exposes the company to penalties from the state attorney general.

What People in This Situation Typically Do

Many remote workers who suspect monitoring take a version of these steps:

  1. Read the paperwork first. The acceptable use policy, employee handbook, and onboarding documents usually describe monitoring in general terms. In New York, Connecticut, Delaware, and (since January 2026) California, the disclosure must be specific.
  2. Check the rules where they live, not where the company is based. A remote worker in Illinois, California, or anywhere in the EU or UK has stronger protections than the federal US baseline.
  3. Separate work and personal life. People in this situation typically stop logging into personal email, banking, or messaging on the work laptop, and keep personal browsing on a personal device.
  4. Ask HR in writing what is collected, how long it is kept, and who sees it. In the EU and UK, individuals generally have the right to a copy of their monitoring data through a subject access request a free, formal request the employer must answer, normally within one month.
  5. Complain to the regulator if the answers don’t add up. In the UK that is the ICO; in the EU, the national data protection authority (such as the CNIL in France); in the US, the state attorney general or, for biometric issues in Illinois, a private lawsuit under BIPA.

Tools That Can Help

A quick honesty check before the tools: nothing on this list can block monitoring software your employer installed on a company-owned laptop. That machine belongs to them, and in most places the law backs that up. Where tools help is on your side of the line — your own devices and your home network.

  • NordVPN encrypts internet traffic on your personal devices. Useful when your personal phone or laptop shares a network with work equipment, or when a workplace agreement requires occasional use of your own device. It keeps your personal browsing out of any network-level logging. (Affiliate link Jovonk may earn a commission at no extra cost to readers.)
  • Your operating system’s own admin panels free. On Windows, Settings → Accounts → Access work or school shows management profiles; on a Mac, System Settings → Privacy & Security → Profiles does the same. This reveals whether a personal device is enrolled in company management.
  • The ICO’s subject access request guidance free, official, and the most direct way for UK workers to see exactly what data an employer holds.

Related Articles

Frequently Asked Questions

Can my employer take screenshots of my screen without telling me?

On a company device in most US states, yes the ECPA’s business purpose exception allows it without notice. Connecticut, Delaware, New York, and California require disclosure first, and California’s AB 1221 (2026) requires a stated justification for screenshots specifically. In the EU and UK, secret screenshots would almost certainly breach transparency rules under GDPR and UK GDPR.

Is employee monitoring software legal in all US states?

Yes monitoring software itself is legal in all 50 states on company-owned equipment. What varies is the process. Four states require advance written notice, 11 states plus DC require all-party consent before recording audio, and Illinois requires written consent before any biometric tracking. The strictest rules of the employee’s home state control, so one remote hire can change a company’s legal duties.

Does my employer need to tell me they’re monitoring me?

It depends on location. US federal law says no. New York, Connecticut, Delaware, and California say yes, in writing. In the EU and UK, transparency is mandatory: GDPR Articles 12 and 13 require clear information about what is collected and why, before collection starts. Covert monitoring in the UK is limited to rare situations, such as investigating suspected crime.

Can my employer monitor my personal phone if used for work?

Generally only with clear, documented consent and even then, only work-related activity. Under a BYOD policy (bring your own device an agreement covering personal equipment used for work), employers can usually manage the work apps and work email on the phone. Reading personal messages, photos, or browsing on a personal device is off-limits in the US, EU, and UK alike.

The Bottom Line

So, can an employer monitor remote workers? Yes on their equipment, within limits that grow tighter as you move from the US federal baseline, through state notice laws, to the EU and UK’s proportionality rules. The pattern across all three jurisdictions is the same: monitoring is legal, secret and excessive monitoring increasingly is not. Knowing which rulebook applies to your desk even when that desk is your kitchen table is the single most useful thing a remote worker can do.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Sources

Pinterest graphic asking can an employer monitor remote workers, with laptop, gavel and padlock icons on navy

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.