Built into how work gets done
People & HR teams
A rollout that skips a consent step or a notice requirement comes back later as a claim. Consent and policy rules apply inside your workflows, per country, so the gap is flagged before anyone is tracked rather than after.
IT & security teams
Answer the audit sample without a fire drill. Monitoring signals centralise across devices, apps and teams, and every governance action, data access and staff action lands on a trail you can re-verify yourself.
Leadership
Run a distributed workforce without fragmenting the numbers. One view of activity, hours and policy status across every country you operate in, so a decision is not held up while four sources are reconciled.
Knowledge hub
The law where your people actually sit
32 jurisdictions written up in full: the instruments that govern monitoring there, the duties they put on an employer, and the steps we cannot take for you. Reviewed and dated, and updated as the law moves.
By jurisdiction
Where you can switch it on, and what each place asks for first
A works council can stop a rollout after the contract is signed, and one country holding out holds up the plan for all of them. The question is never whether monitoring is legal. It is what each place makes you do first.
4 of these stop you outright until a works council, union or regulator agrees. 3 put specific practices off the table whatever anyone signs. In the other 25 it is paperwork, done in the right order, before the first agent is installed.
- 32jurisdictions, each written up on its own page
- 55primary sources cited across them
- 5regions, Europe to Asia Pacific
Every entry cited to a primary source and dated. All reviewed August 22, 2026.
What stands in the way, hardest first
Pick one to filter the tableAll 32, grouped by region. Every row opens the write-up for that jurisdiction.
Europe16
- DEGermanyStance: Prior approvalThe works council holds a veto, and a productivity dashboard is enough to trigger it.
- ATAustriaStance: Prior approvalA works council veto with no workaround, and no council means individual consent.
- ITItalyStance: Prior approvalUnion agreement or a labour inspectorate authorisation, a filing, not a policy.
- NLNetherlandsStance: Prior approvalWorks council consent, and the regulator treats screenshots as disproportionate by default.
- PTPortugalStance: RestrictedThe Labour Code prohibits remote means used to monitor employee performance.
- CHSwitzerlandStance: RestrictedSystems for monitoring worker behaviour are prohibited by the labour ordinance.
- FRFranceStance: ConsultationConsult the CSE first. Skipping it is the criminal offence of obstruction.
- BEBelgiumStance: ConsultationCBA 81 governs electronic monitoring and binds every private-sector employer.
- ESSpainStance: ConsultationDigital rights are written into the data protection act, and reps must be involved.
- FIFinlandStance: ConsultationA dedicated working-life privacy act, and a necessity test read very narrowly.
- PLPolandStance: NoticeThe Labour Code lists the permitted purposes, and productivity is not one of them.
- UKUnited KingdomStance: NoticeThe ICO's 2023 monitoring guidance is the operative document, and it expects a DPIA.
- IEIrelandStance: NoticeThe DPC accepts a legitimate business interest, and then tests proportionality hard.
- SESwedenStance: ConsultationCo-determination negotiation before any significant change, including this one.
- NONorwayStance: ConsultationControl measures need discussion with employee representatives and periodic review.
- DKDenmarkStance: NoticeSix weeks' notice under the collective agreement framework, and a strict purpose test.
North America7
- USUnited States (federal)Stance: NoticeFederal law is permissive; the real constraints are state law and the NLRA.
- NYNew YorkStance: NoticeWritten notice on hire, signed acknowledgement, and a posted notice, all three.
- CACaliforniaStance: NoticeEmployees have full CCPA rights since 2023, including deletion and correction.
- ILIllinoisStance: RestrictedBIPA carries a private right of action. This is the state where monitoring gets sued.
- CA-FCanada (federal)Stance: NoticeReasonableness is the statutory test, and the OPC applies a four-part necessity analysis.
- ONOntarioStance: NoticeA written electronic monitoring policy is mandatory at 25+ employees, refreshed annually.
- QCQuebecStance: NoticeLaw 25 adds privacy by default, impact assessments and a right to explanation.
Latin America2
Asia Pacific5
- AUAustraliaStance: NoticeIn NSW and the ACT: 14 days' written notice, with prescribed content, before you start.
- INIndiaStance: NoticeDPDP gives employment a legitimate use, but automated monitoring is argued to sit outside it.
- PHPhilippinesStance: NoticeTransparency, legitimate purpose and proportionality: the three-part NPC test.
- JPJapanStance: NoticeSpecify the purpose of use, publish it, and do not exceed it.
- SGSingaporeStance: NoticeEmployment data has a deemed-consent route, but notification is still mandatory.
Not seeing where you operate? Only jurisdictions that have been researched and sourced are listed. A plausible-sounding summary of a labour code nobody checked is worse than no page, so the rest are not filled in with guesses. Tell us which country you are rolling out in and we will tell you what we know and what we do not.
This is a summary of how employee-monitoring rules generally work in this jurisdiction, written to help you scope a rollout and brief your own advisers. It is not legal advice, it is not a substitute for it, and law changes. Verify against the primary sources listed and take local counsel before you deploy.
Inside one country page
Four things your counsel can check, on every one
- 1
What actually governs
The statutes, collective agreements and regulator guidance that apply there, each one named and cited. Your counsel checks the source rather than taking our word for it.
- 2
What it obliges you to do
The duties that follow, written as steps a rollout has to clear: the notice, the consultation, the lawful basis, the proportionality test that has to survive a question.
- 3
Which control answers each duty
Every requirement mapped to the setting that meets it, linked to the page describing it. Where the answer is your policy rather than our product, the page says so.
- 4
What no vendor can do for you
The works council, the impact assessment, the union agreement, and what a regulator there can impose if you skip them. Named above the call to action, not under it.
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- AKAria K. viewed screenshotsLena M. · 3 capturesScreen capturemacOS · London09:42a91f…4c023d7b…91ee
- JMJon M. exported time reportDesign team · CSVmacOS · Berlin09:313d7b…91ee77c5…0ba4
- SDSara D. opened capture reviewRavi P. · one flagged frameWindows · Manchester09:1877c5…0ba4e208…5f13
- wm_live_7f2… read /v1/deliverablesScoped key · read onlyPublic API · allowlisted IP08:57e208…5f13b64a…2d90
- LMLena M. viewed her own recordWhat We SeemacOS · London08:44b64a…2d901cf9…8e77
- AKAria K. changed capture policyBlur set to alwaysmacOS · London08:261cf9…8e7705d2…ae31
Compliance
Stay compliant before monitoring becomes a risk
WorkMonitor continuously checks your monitoring setup against local labor and privacy laws, flagging consent and data-handling risks early. Security teams get clear signals, documentation, and guidance without chasing facts across systems or regions.
What to read next
The documents a rollout gets stopped for
A works council, a regulator or your own legal team will ask for these by name. Each one is published rather than promised.
- Trust & ComplianceRecorded consent, capture policy enforced on the device, and a hash-chained access log the controls above are mapped to.
- How the platform is securedThe control inventory and the open gap list, published in full, down to the certifications we do not yet hold.
- Data Processing AddendumThe processor terms your legal team will want in front of them before the pilot, not after it.
- Sub-processorsWho processes what, and where. The list an impact assessment asks for and a works council will ask about.
- Worker privacy noticeThe notice most of these jurisdictions require you to serve, already drafted, so the rollout is not held up writing one.
- A country that is not hereName the country you are deploying into. We will say what we know, what we do not, and what we would check first.
Straight answers
The questions we would ask in your position
Every answer here is the one you would get on a call. Open as many as you like; they stay open, so two can be held side by side.
Automatic time and activity tracking for every worker type, on every device, turned into hours, focus, idle time and app mix per person, team and project — with the controls to decide what is captured for whom.
Yes, and that is what makes the rollout hold up if it is ever questioned. Transparent mode gives clear indicators, consent prompts and per-person visibility settings, and what was shown and agreed to is recorded rather than remembered.
You decide what is captured and who can see it: consent controls, field redaction, configurable retention and full audit logs are built in. When someone asks what is held about them, or a regulator does, the answer comes out of the product rather than out of a spreadsheet.
Hours, active and idle time, apps and websites, attendance, optional screenshots and risk signals — each switched on per team, so a group under stricter rules is configured once instead of exempted by hand.
One lightweight agent covers Windows, macOS and Linux, with a browser extension for work that happens in a tab. There is no mobile or deskless app yet, so a deskless workforce is outside what we can measure today — which matters for a policy that has to describe its own scope accurately.
On both sides of capture. Before it, regional rules and consent requirements apply automatically. After it, every governance action, data access and staff action appends to a tamper-evident hash chain you can re-verify yourself — the evidence an auditor asks for, whichever framework you are audited against.
Deploy the agent, set your policy and consent rules per team, and data starts arriving as the first agents check in. There is no data migration to wait on.
Yes. Okta, Azure AD, Slack, Teams, and common HRIS platforms sync out of the box, so joiners and leavers follow your directory instead of a seat list somebody maintains by hand.
The answers a security review needs are published rather than promised. Traffic is TLS 1.2+ with AEAD-only ciphers and preloaded HSTS; credentials and secrets are sealed with AES-256-GCM; access is role-based and scoped to your organisation by the credential itself. We are pre-launch and hold no certifications. SOC 2 and ISO 27001 are in preparation, and our control inventory and open gap list are published in full.
From one team to tens of thousands of seats across regions, without a rebuild or a second workspace to reconcile. Your organisation is a boundary in the schema, not a filter someone has to remember to apply.
Point it at one team for a week.
Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.
Free for two seats. No card, and no sales call to sit through.