Fino

Explainer No. 2 · Staff · Updated 6 Oct 2026 · 3 min read

We want to monitor employees’ laptops. Has a regulator already decided on this, and what did it cost?

Yes, many times. Regulators accept some monitoring, for example for IT security or to protect company property, if it is limited, explained to staff in advance, and no more than the purpose needs. What gets fined is monitoring that is constant or hidden: screenshots every few minutes, recording “inactivity”, reading staff email, tracking people around the clock. The biggest fine in Fino is €35.3 million, against H&M in Germany.

The core rule: only what you need

Most monitoring decisions turn on one line of the GDPR. Article 5(1)(c) says personal data must be

“adequate, relevant and limited to what is necessary”

Regulators apply it by asking whether a less intrusive method would reach the same goal. Blocking risky websites protects the network as well as recording every screen does, so recording every screen is too much. Occasional, targeted checks with a clear reason hold up far better than continuous tracking.

The legal basis: legitimate interests, rarely consent

Employers usually rely on Article 6(1)(f), legitimate interests: the monitoring must be necessary, and your interest must not be outweighed by your staff’s rights. Consent rarely works at work. Recital 43 explains that consent “should not provide a valid legal ground” where there is “a clear imbalance” between the two sides, and an employee can hardly refuse their employer freely.

Tell staff, and assess the risk first

Article 13 requires you to tell staff before you start: what you monitor, why, on what legal basis, and how long you keep it. Systematic monitoring of staff is also a typical case for a data protection impact assessment under Article 35: a written risk assessment done before the monitoring starts.

Check the national employment law

Article 88 lets countries add their own rules for staff data, and several do. In Italy, Article 4 of the Workers’ Statute requires an agreement with staff representatives, or an authorisation from the labour inspectorate, for tools that make remote monitoring of staff possible. The ordinary tools staff use to do their job are exempt, but monitoring software added to them is not. In Germany, the works council has a say in any technical system that can be used to monitor staff. Several Italian fines cite both the GDPR and these national rules.

What regulators decided

The closest decisions in Fino, biggest fine first. Each line opens the decision with its source.

See every decision in Fino and search for “employee”.

Check before you start

  1. Is it occasional and targeted, or continuous? Constant screen or keystroke recording is almost always too much.
  2. Were staff told clearly, before it started?
  3. Is there a less intrusive way to reach the same goal?
  4. How long is the data kept, and who can see it?
  5. Is there a written impact assessment, and were staff representatives involved where national law requires it?

Related explainers

Sources. GDPR text on Fino. Decisions from GDPRhub (noyb) and the CMS Enforcement Tracker, CC BY-NC-SA 4.0; descriptions rewritten in plain words by Fino.

Not legal advice. National rules can add to what is described here.