Know your rights around Big Brother software

Know your rights around Big Brother software

Hands using a laptop illustrating employee monitoring and workplace surveillance

By Ian Campbell and Laura Graham

Originally published in the Business Post, 27 August 2026.

Never has it been easier to imagine Big Brother watching you in the workplace. A multitude of software is available to help employers monitor employees in different ways, from IT security logs to more intrusive tools like keylogging and spyware. Some countries are already seeing the fallout.

Last year in Brazil, a high-profile case of employee surveillance saw a bank dismiss or discipline employees after correlating several sources of digital activity of people working from home and finding discrepancies between logged work time and computer activity.

Meta has hit the news more than once with plans to implement enhanced employee workplace monitoring, ostensibly for training AI models but naturally sparking concerns among staff. Last month in California, 26 employees who lost their jobs in the company’s cull of 8,000 jobs in May filed a lawsuit claiming AI tools were used unfairly to score, rank and select people for firing.

Legal and regulatory frameworks

In Ireland, an employer can legally monitor employees, but it must be carried out within a legal and regulatory framework. Laura Graham, head of the employment and regulatory team at Reddy Charlton, a Dublin-based law firm, explains that no single piece of legislation covers the issue.

“Employers will not find any express prohibition or permission to monitor employees,” she says. “The extent to which employees can be monitored lawfully needs to be assessed against the General Data Protection Regulations and the Data Protection Act 2018, the employee’s privacy rights under the EU Convention of Human Rights and the Constitution, and the trust and confidence between an employer and an employee.”

According to Graham, it is a good example of EU regulation at work, providing employees with more privacy protection than in less regulated jurisdictions.
Monitoring employees falls into the scope of GDPR because it generally involves processing the personal data of employees, where the employer is the data controller.

“The more intrusive and widespread the monitoring, the higher the risk that the surveillance may be considered unlawful,” says Graham. “Data protection legislation adopts a risk-based approach which requires data controllers to assess the risks that processing poses to the rights and freedoms of individuals and implement appropriate measures to mitigate those risks.”

Employers must have a clear legal basis for monitoring; they must tell employees why it’s happening and not stray into using it for another purpose. They must ensure that the monitoring is proportionate and necessary for a specific business reason, and always consider if there is a less intrusive way of achieving their objective.

Brian Honan of BH Consulting
Brian Honan, BH Consulting. Picture: Fergal Phillips

Proportionate monitoring

There are a number of reasons why an employer might seek to monitor employees, from productivity surveillance and protecting company property to compliance with regulatory obligations. In Ireland, security specialist Brian Honan, owner of BH Consulting, sees a little of the first and a lot of the second.

“ I’ve had a couple of companies wanting to know if it would be possible for us to deploy something onto people’s computers to make sure they’re working from home, and our immediate answer is ‘no’ because of the legal risks,” he says.

More typically, companies want advice on how to monitor an employee suspected of illegal activity that they need to investigate further. “My first reaction would be to look at the security logs from the users’ device or from the servers and see if we can back up the ir suspicions that way,” he adds.

Honan is clear that in most cases established IT security procedures – logins to systems, file access, email records – are the right way to go, rather than invasive monitoring of everything a person does. Monitoring still has to be proportionate and targeted with proper authorization and confidentiality around any investigation.

Laura Graham stresses the importance of paying attention to the law. “Whatever the reasons, employers are well advised to operate within the existing legal and regulatory framework and not simply gather data to ‘keep watch’ over their employees or to continuously monitor their performance,” she says.

Legal bases for surveillance

Monitoring means the employer would be processing the personal data of employees, the legal basis for which is set out in Article 6 of the GDPR (and Article 9 in the case of highly sensitive data). It includes obtaining the consent of employees – which Graham notes is an unstable ground given the imbalance of power between an employer and an employee – and a list of reasons why monitoring might be necessary, along with other legal bases including ‘performance of a contract’, where working hours might be recorded with a timekeeping system.

‘Legitimate interests’ of the employer is also on the list as a legal basis for processing personal data, but Graham warns that this must be balanced against the individual’s interests, fundamental rights and freedoms. Processing personal data to ensure network and information security, for example, would constitute an overriding legitimate interest of the employer, but there are caveats.

“Monitoring an individual’s network activity may be done to protect an employer’s confidential information, but it has to be strictly necessary and proportionate,” says Graham. “It will be difficult to justify looking at browser history if blocking certain sites would achieve the same aim. Similarly, monitoring content of emails and messages isdifficult to justify if less intrusive monitoring of network activity would achieve the same purpose.”

Keylogging and spyware

Where employers are likely to run into even more legal difficulties is if they attempt to use keylogging to record every keystroke of employees working from home. The impact on the employees’ privacy is likely to outweigh the legitimate interest of the business.

Brian Honan is very familiar with this challenge and sees it as a red flag. “The danger is that keyloggers or spyware will capture everything. An employee could log on to their personal email, their banking service or healthcare provider’s website, and suddenly the employer is capturing details about their personal life.”

Graham backs this up. “Constant keystroke monitoring or even intermittent screen monitoring can reveal detailed information about an employee’s behaviour and may capture highly sensitive information,” she says. “Less intrusive alternatives are likely to exist such as monitoring work outputs, time recording, project completion. This means that it may not be necessary or proportionate to continuously monitor employees’ keystrokes to achieve the business aim.”

All of this matters because risks associated with unlawfully monitoring employees in Ireland include regulatory fines of up to €20 million or four percent of annual turnover (whichever is the higher), not to mention the costs of litigation and reputational damage.

Laura Graham, Head of Employment and Regulatory at Reddy Charlton
Laura Graham, Reddy Charlton. Picture: Maura Hickey

Limits on covert monitoring

To collect personal data or monitor employees without them knowing is only considered lawful in very exceptional circumstances, for example where the data will be used to detect, prevent or investigate crime or to catch and prosecute offenders. Graham refers to a long list of assessments that need to be carried out before sanctioning it.

There has to be reasonable grounds to suspect that criminal activity or serious malpractice is taking place; less intrusive ways to tackle the issue should have been explored.

Employer written policies should be in place that outline the circumstances in which covert monitoring might take place. Even when good reason is established, execution has to be carefully controlled and documented.

“Covert monitoring should be focussed and last only for a short amount of time. If no evidence is found within a reasonable amount of time, the employer will find it difficult to justify continuing covert surveillance,” says Graham.

“Even where a legal basis is established, employers must minimise the data that they collect to the amount strictly necessary and proportionate to achieve their aim, failing which the processing may be considered unlawful.”

Putting robust policies in place

Where workplace monitoring is implemented for a specified purpose, it is against the law to repurpose it unless there is a legal basis and employees are informed. This was highlighted in a 2015 case where an employer installed CCTV for security and safety purposes that was subsequently used to show an employee taking unauthorised breaks, triggering a disciplinary process.

An appeal concluded that the employee could not have reasonably expected that the footage would be used to monitor his performance, therefore the use of the CCTV footage in the disciplinary process was unlawful. The case reinforced legal principles of data protection law, that data collected for one purpose cannot be
used for another incompatible purpose without proper notification and without informing employees about the purposes for which monitoring may be used. Ultimately, it is up to employers to be clear and honest about their usage policies –whether it’s around CCTV or software – and up to employees to read them.

“Companies should have robust acceptable usage policies in place to clearly state to staff what they are allowed and what they are not allowed to do when it comes to using company computers, but it should also state under what conditions the company can monitor their activity,” says Honan.

What he repeatably sees in the security space is companies failing to set adequate policies and employees not paying proper attention to them. There is also a need to constantly revisit them that is often ignored. “Policies are not one- and- done documents. Laws, case law, and regulatory expectations evolve and so must internal rules,” he says.

If you have any queries on this please do not hesitate to contact Laura Graham at lgraham@reddycharlton.ie

Disclaimer: This article is for general information purposes only and does not constitute legal advice. Specific legal advice should be sought before taking or refraining from any action based on its contents.



Laura Graham
Author: Laura Graham