What question should an employer ask first?
The starting point is not selecting software. The employer should define the problem: warehouse theft, risk of disclosing confidential information, misuse of vehicles, cyber-security incidents or improper use of business email. It should then consider whether training, access controls, entry records, security filters or targeted checks would solve the problem with less intrusion.
The Polish data protection authority stresses necessity and proportionality. Convenience alone is not enough. The scope should be narrowed to the places, people, data, features and time periods genuinely required.
When is CCTV permitted?
The Labour Code permits CCTV where necessary to protect employees, protect property, control production or safeguard confidential information whose disclosure could expose the employer to loss.
Cameras should not automatically cover the entire workplace. Sanitary facilities, changing rooms, canteens, smoking rooms and trade-union rooms are subject to particular restrictions. Exceptions require genuine necessity and additional safeguards, and in some cases agreement with the relevant employee representation. Audio recording is substantially more intrusive and is not generally covered by the Labour Code basis for video monitoring.
Recordings may generally be retained for no longer than three months from recording. If they constitute evidence in proceedings, or the employer learns that they may do so, they may be retained until the proceedings are finally concluded. Automatic deletion should reflect the adopted schedule.
May an employer read business email?
Monitoring business email may be introduced where necessary to organise work so that working time is fully used and to ensure proper use of the tools provided. This is not an unrestricted right to read all messages.
The monitoring must not infringe confidentiality of correspondence or other personal rights. In practice, the employer should first consider less intrusive data — security alerts, sender, recipient, time and message size — before accessing content. If incidental private use is permitted, the prospect of encountering private correspondence must be built into the control design.
During absence, an automatic reply or delegated access to defined business correspondence may be safer than unrestricted manager access to the whole mailbox. The rules should be known in advance.
What about GPS, system logs and remote-work monitoring?
The Labour Code permits other forms of monitoring where necessary for work organisation and proper use of work tools. This may include GPS in a company vehicle, access logs, application-use records or data-loss prevention controls. Each requires its own justification.
How the issue appears in practice
Practical example — hypothetical scenario
A company deploys software that takes a screenshot of each remote employee’s screen every three minutes, records the active window and calculates “productivity” from mouse movement. Employees learn about the tool after installation. The work regulations do not describe it, and no retention period or authorised-user list has been set. The company wants to reduce project delays, but the system collects far more information than necessary and can capture private content visible in the home environment. Lack of advance notice and a defined purpose increases both employment-law and GDPR exposure. A proper process would first identify why projects are delayed. If workflow is the issue, status updates in a project tool and milestone reporting may be sufficient. If there is a genuine security risk, limited event logs or DLP alerts may be considered. Only after necessity is established should the employer document the tool, minimise data and retention, assess risk and notify employees before launch.
Which documents and notices are required?
The purpose, scope and method must be set out in a collective agreement, work regulations or, where neither applies, an employer announcement. Employees must be informed through the method normally used by the employer at least two weeks before monitoring starts. A new employee should receive the information before being allowed to work.
The GDPR privacy notice is also required. The record should cover the legal basis and purpose, data categories, recipients, retention, individual rights, access controls, security and the necessity assessment. Employee consent is generally not a reliable way to “fix” monitoring because the employment relationship makes genuine freedom of choice difficult to establish.
Legal basis
- Act of 26 June 1974 — Polish Labour Code, in particular Articles 22² and 22³.
- Regulation (EU) 2016/679, in particular Articles 5, 6, 13, 24, 25, 32 and 35.
- Act of 23 April 1964 — Polish Civil Code, in particular Articles 23 and 24.
This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.
Summary
Monitoring should respond to a defined risk, not merely to the availability of technology.
