We want to monitor employees’ laptops. Has a regulator already decided on this, and what did it cost?
Yes, many times. Regulators accept some monitoring, for example for IT security or to protect company property, if it is limited, explained to staff in advance, and no more than the purpose needs. What gets fined is monitoring that is constant or hidden: screenshots every few minutes, recording “inactivity”, reading staff email, tracking people around the clock. The biggest fine in Fino is €35.3 million, against H&M in Germany.
The core rule: only what you need
Most monitoring decisions turn on one line of the GDPR. Article 5(1)(c) says personal data must be
“adequate, relevant and limited to what is necessary”
Regulators apply it by asking whether a less intrusive method would reach the same goal. Blocking risky websites protects the network as well as recording every screen does, so recording every screen is too much. Occasional, targeted checks with a clear reason hold up far better than continuous tracking.
The legal basis: legitimate interests, rarely consent
Employers usually rely on Article 6(1)(f), legitimate interests: the monitoring must be necessary, and your interest must not be outweighed by your staff’s rights. Consent rarely works at work. Recital 43 explains that consent “should not provide a valid legal ground” where there is “a clear imbalance” between the two sides, and an employee can hardly refuse their employer freely.
Tell staff, and assess the risk first
Article 13 requires you to tell staff before you start: what you monitor, why, on what legal basis, and how long you keep it. Systematic monitoring of staff is also a typical case for a data protection impact assessment under Article 35: a written risk assessment done before the monitoring starts.
Check the national employment law
Article 88 lets countries add their own rules for staff data, and several do. In Italy, Article 4 of the Workers’ Statute requires an agreement with staff representatives, or an authorisation from the labour inspectorate, for tools that make remote monitoring of staff possible. The ordinary tools staff use to do their job are exempt, but monitoring software added to them is not. In Germany, the works council has a say in any technical system that can be used to monitor staff. Several Italian fines cite both the GDPR and these national rules.
What regulators decided
The closest decisions in Fino, biggest fine first. Each line opens the decision with its source.
- Oct 2020H&M Hennes & Mauritz Online Shop A.B. & Co. KGManagers recorded details of staff’s private lives (holidays, illnesses, family matters) after return-to-work talks and kept them on a shared drive.Data Protection Authority of Hamburg · Germany€35,258,708
- Jun 2026PiaggioKept and examined staff emails and system logs for a long time, which made unlawful monitoring possible.Garante per la protezione dei dati personali (Italy) · Italy€460,000
- Mar 2026ARES CAPITAL, S.A.Required staff to install four tracking apps on their own phones for work.Spanish Data Protection Authority (aepd) · Spain€200,000
- Apr 2025Regione LombardiaKept staff’s web-browsing logs and email metadata without a valid reason.Italian Data Protection Authority (Garante) · Italy€50,000
- Dec 2024Not named in the sourceSoftware took regular screenshots of staff screens and recorded presumed “inactivity”; staff were also filmed all the time.CNIL (France) · France€40,000
- Jan 2021Not named in the sourceSet up automatic forwarding of an employee’s email during her sick leave, without telling her.Norwegian Supervisory Authority (Datatilsynet) · Norway€38,600
See every decision in Fino and search for “employee”.
Check before you start
- Is it occasional and targeted, or continuous? Constant screen or keystroke recording is almost always too much.
- Were staff told clearly, before it started?
- Is there a less intrusive way to reach the same goal?
- How long is the data kept, and who can see it?
- Is there a written impact assessment, and were staff representatives involved where national law requires it?
Related explainers
Sources. GDPR text on Fino. Decisions from GDPRhub (noyb) and the CMS Enforcement Tracker, CC BY-NC-SA 4.0; descriptions rewritten in plain words by Fino.
Not legal advice. National rules can add to what is described here.