Employee Monitoring Laws in 2026: A Global Compliance Guide
Remote and hybrid work has fundamentally changed how employers try to understand what is happening within their workforce, and remote employee monitoring has grown right alongside it. Software that tracks app usage, screen activity, and productivity trends has become widespread across industries, and most employers use some kind of such software now. Regulators have not been oblivious to this growth. The legal landscape for monitoring employees is very fragmented. A policy that complies fully in Texas might violate notice requirements in Connecticut. A monitoring setup that works throughout most of the US could expose a European employer to significant GDPR fines. Hiring staff remotely in Ontario, NSW or London means satisfying three separate legal frameworks, none of which look alike.
This guide walks through major rules that govern monitoring of employees across the US, EU, UK, Canada and Australia, along with new AI regulations that are reshaping the building and deployment of tools for workforce monitoring.
Last legally reviewed: August 17, 2026. This guide summarizes selected employee monitoring and workplace AI laws as of that date. It does not cover every jurisdiction or every requirement within a jurisdiction, is not part of any agreement between Controlio and its customers, and does not guarantee that any product feature or configuration will achieve compliance. It is not legal advice, and readers should obtain advice specific to each jurisdiction where their workers are located. See the Legal Information section at the end of this guide.
Monitoring Compliance Cannot Be Treated as an Afterthought
Monitoring is legal in nearly every country discussed here. That is good news. But the tricky part is that legality depends on how monitoring is actually carried out rather than just deciding to do it. Monitoring regulations continue to tighten in nearly every jurisdiction covered in this guide, and surveillance software laws rarely stay static for long.
Regulators in nearly all jurisdictions are moving in the same direction: requiring more disclosure, more documentation and closer scrutiny of automated decisions. Connecticut, Delaware and New York and Maine already require written notice before electronic monitoring starts. Ontario's Employment Standards Act requires many employers to maintain a written electronic monitoring policy, and a separate 2026 requirement now requires certain job postings to disclose when AI is used to screen candidates. The EU AI Act classifies certain workplace monitoring tools as high risk, though the compliance deadline for most of those obligations has since moved. None of these developments makes monitoring illegal, but they do make silent and hidden monitoring much riskier compared to before.
For distributed teams, the practical challenge is building a monitoring program that can adapt to the requirements of each jurisdiction where employees work, rather than defaulting to whichever jurisdiction happens to have the loosest rules.
United States: Patchwork of Federal and State Rules for Monitoring Employees
There is no single federal law that governs how employers monitor employees. Starting with the Electronic Communications Privacy Act, employers are allowed to monitor communications on systems they own for legitimate business reasons, and generally consent from one party is sufficient. Most states follow this default federal rule.
States That Require Written Notice
Four states go further and require written notice before starting electronic monitoring:
- Connecticut
- Delaware
- New York
- Maine
New York also posts this notice prominently where employees can see it. None of these four states require employees to consent to monitoring ahead of time, they just have to be informed, though Maine's law goes further than a pure notice requirement (see below). Employee consent is a separate legal question from notice, and the two are often confused.
Connecticut's requirement comes from Conn. Gen. Stat. § 31-48d. Delaware's comes from Del. Code tit. 19, § 705. New York's comes from N.Y. Civil Rights Law § 52-c (enacted as SB S2628, effective May 7, 2022), which requires notice upon hiring and a conspicuous workplace posting and is enforced by the New York Attorney General, with civil penalties of up to $500 for a first offense, $1,000 for a second offense, and $3,000 for later offenses.
Maine's law, LD 61 ("An Act to Regulate Employer Surveillance to Protect Workers"), became law without the governor's signature on January 11, 2026, and takes effect on July 29, 2026. It requires employers to notify prospective employees during the hiring process and to give current employees written notice at least once a year. Unlike the notice-only requirements in Connecticut, Delaware and New York, Maine's law also limits audiovisual monitoring in employees' homes, personal vehicles and personal property unless the monitoring is required by the job, and it lets employees decline having surveillance software installed on their personal devices. Cameras used for workplace safety or security, and GPS or safety devices on employer-owned vehicles, are excluded.
California
California has the most complicated framework at the state level. The California Invasion of Privacy Act makes California a two-party consent state for recording conversations, so call monitoring and meetings also require agreement from everyone involved. The California Consumer Privacy Act adds separate obligations about how to collect, use and disclose employee data. A bill called AB 1221, which would have added specific workplace surveillance notice and impact assessment requirements, died in the California legislature in early 2026 despite appearing frequently in compliance guides as if it had passed. Employers should build policies based on statutes actually in force rather than bills that did not become law.
Illinois and Biometric Data
Illinois also carries risk through the Biometric Information Privacy Act (BIPA). Tools that use things like facial recognition or fingerprint scanning for routine purposes such as login authentication require written consent and documented handling policies. BIPA allows a prevailing plaintiff to recover statutory damages of $1,000 for a negligent violation or $5,000 for an intentional or reckless violation. A 2024 amendment, which the Seventh Circuit held applies retroactively in a 2026 decision, limits a plaintiff to one recovery per person for repeated collection of the same biometric identifier by the same method, rather than a separate award for every scan. Even with that cap in place, past BIPA settlements have reached into the hundreds of millions of dollars, so the underlying exposure remains significant.
Where the Rules Are Headed
Other states are actively considering expanded disclosure laws about monitoring, and several legislatures, including Massachusetts, Washington and New Jersey, have introduced bills at various points addressing AI-driven workplace decisions or impact assessments. None of these had become law as a general workplace monitoring requirement as of mid-2026. State activity in this area moves quickly, so employers should confirm current bill status with counsel or a legislative tracking service rather than relying on any fixed list.
Employers in the US should have a baseline of safety by having a written monitoring policy delivered to employees before monitoring starts. The policy should describe what data is collected, why it is collected and how that data is used.
For Employers in the European Union: GDPR and the Limits of "Just Get Consent"
GDPR monitoring rules apply the moment an employee based in the EU has personal data processed, regardless of where the employer is headquartered. Often employers think signing a consent form solves their obligations under GDPR. That is not true. The European Data Protection Board has repeatedly said that consent rarely works as a legal basis in employment relationships because if someone declines consent they risk disciplinary action or lower performance reviews. Consent given under such pressure is not considered freely given, and consent that is not freely given is not valid under GDPR.
Legitimate Interest and Proportionality
Instead, most rely on legitimate interest under Article 6 of GDPR, balanced against employees' privacy rights under the European Convention on Human Rights. A monitoring exercise needs to be necessary and proportionate to a specific business reason and no more intrusive than necessary to achieve that reason. Any data collected from monitoring employees, including website logs, application usage, email metadata and screen recordings, counts as personal data under GDPR.
Impact Assessments and Covert Monitoring
Systematic monitoring usually requires conducting a Data Protection Impact Assessment that details purpose, risks to employees and safeguards in place. Secret monitoring is allowed only in very narrow circumstances, such as an active investigation into suspected criminal behavior, and even then the justification must be strong and the scope and duration strictly limited.
Transparency and Data Minimization
Transparency is central to the whole framework. Before monitoring begins, employees should be told what is being monitored, why it is done, how long data is kept and who can access it. This approach protects employee privacy while still giving employers the visibility they need for legitimate business purposes. Employers operating in different EU member states also need to consider derogations under Article 88 of GDPR, because some countries, such as Germany, add consultation requirements on top of baseline GDPR.
Data minimization causes many monitoring tools to struggle. Features such as continuous keystroke logging, capturing continuous screenshots and reviewing full email content go beyond what is necessary for measuring productivity or safeguarding systems, and collecting more than necessary increases regulatory exposure as well as the damage from any future data breach.
United Kingdom: A Parallel Framework with Its Own Statutes
The UK left the EU, but its monitoring rules closely follow the European approach. Workplace privacy expectations in the UK closely track the EU approach even though the UK is no longer a member state. Both the UK GDPR and the Data Protection Act 2018 apply core principles:
- lawful basis
- proportionality
- transparency
The Information Commissioner's Office has published workplace monitoring guidance and expects employers to conduct a Data Protection Impact Assessment for systematic monitoring programs and to weigh the intrusiveness of monitoring against business justification.
Interception of Communications
The UK adds another layer through the Regulation of Investigatory Powers Act and related Telecommunications (Lawful Business Practice) Regulations, which regulate interception of communications including email monitoring and call recording. These rules allow interception without individual consent for specific reasons, such as regulatory compliance or system security, but only on employer-owned telecommunications systems and only if employers have made reasonable efforts to inform employees that such interceptions might happen.
The Data (Use and Access) Act 2025
The UK's data protection reform effort had a false start. The Data Protection and Digital Information Bill was abandoned when Parliament dissolved for the July 2024 general election and never became law. The replacement, the Data (Use and Access) Act 2025, received Royal Assent on June 19, 2025, with the employer-relevant provisions phased in through 2026. Among other changes, it introduces a narrow "recognised legitimate interests" basis that lets organizations skip the usual balancing test for a short list of purposes, such as crime prevention, national security and safeguarding vulnerable people. That list does not cover routine workplace monitoring, so most employers relying on legitimate interest for monitoring still need to complete a standard legitimate interest assessment. UK employers should continue the standard practice of giving notice and documenting an impact assessment before rolling out monitoring software.
Canada: Patchwork Law for Monitoring Employees
Canadian laws for monitoring employees depend a lot on where employers are based and what kind of business they run. Banks, airlines and telecom companies are federally regulated and fall under the Personal Information Protection and Electronic Documents Act (PIPEDA) no matter which province they are in. PIPEDA says monitoring should be reasonable and tied to a legitimate business purpose, and employers should inform employees beforehand.
British Columbia, Alberta and Quebec
British Columbia, Alberta and Quebec each have their own private-sector privacy statutes, considered very similar to PIPEDA, so employers regulated by those provinces follow provincial law. Quebec's Law 25 is the strictest of the group and requires employers to show that monitoring is proportionate to a legitimate goal. Continuous webcam monitoring for general productivity tends to be considered too intrusive to meet that standard.
Ontario's Electronic Monitoring Policy
Ontario and most other provinces do not have a dedicated private-sector privacy statute, so monitoring there is governed by a mix of employment standards and common law privacy torts. Since 2022, Ontario's Employment Standards Act, 2000 has required employers with 25 or more employees to maintain a written electronic monitoring policy that specifies what is monitored, how it is monitored and for what purpose, and this generally extends to covering any AI tools used for monitoring. A separate requirement, effective January 1, 2026, requires publicly advertised job postings to disclose when an employer uses AI to screen, assess or select applicants. This hiring-stage disclosure rule comes from different legislation than the electronic monitoring policy requirement and should not be confused with it.
Precisely defining what Ontario law actually does is important: the electronic monitoring policy requirement is a disclosure obligation, not a restriction on what can be monitored. Consent is not required, and the statute does not itself limit data retention. Employers can monitor extensively under Ontario law as long as the practice is described in the written policy, which must be in place by March 1 of any year in which the employer had 25 or more employees on January 1, and provided to employees within 30 days of any update.
Australia: Surveillance Laws Vary by State
Workplace surveillance laws in Australia are set primarily at the state level rather than through a single national statute. The Privacy Act includes an exemption for employee records that limits how far it reaches into monitoring practices. Most operative rules come from state legislation.
New South Wales
New South Wales has the most specific framework through the Workplace Surveillance Act 2005. This law covers separate categories of surveillance through cameras, computers and tracking. Before any of these begins, employers must give employees at least fourteen days' written notice specifying the kind of surveillance, how it works and when it starts. Surveillance in change rooms, bathrooms and other bathing facilities is prohibited outright. Secret surveillance requires court authority and is available only in limited circumstances, such as investigating suspected illegal activity.
Victoria and Other States
Victoria regulates workplace monitoring through the Surveillance Devices Act, but with a narrower scope compared to the NSW statute. Other states rely on federal surveillance device law along with general privacy principles and employment law rather than a specific workplace surveillance statute, so employer obligations can shift quite a bit depending on where employees are based.
Digital Work Systems and WHS
In February 2026, NSW passed the Work Health and Safety Amendment (Digital Work Systems) Act 2026, the first law of its kind in Australia. It amends the Work Health and Safety Act 2011 (NSW) to make clear that a digital work system, defined broadly as an algorithm, artificial intelligence, automation or online platform used to allocate, monitor or manage work, can create a health and safety risk that a business must proactively manage, alongside risks such as excessive or unreasonable workloads and excessive monitoring or performance metrics. This brings psychosocial risks related to algorithmic management and AI monitoring tools into WHS compliance discussions, beyond surveillance and notice law alone.
Emerging Layer: Regulation of AI and Workplace Monitoring
Workplace compliance teams are increasingly expected to track AI-specific obligations alongside traditional monitoring rules. Compliance for monitoring across borders used to mean data protection law. It increasingly also means AI law, and the European Union AI Act is clear evidence of this. The Act classifies recruitment, performance evaluation, task allocation, monitoring of workers and decisions about promotion or termination that use AI as high risk.
Banned Uses and High-Risk Obligations
Since February 2, 2025, certain uses have been outright banned, including AI that infers emotions from facial expressions, voice or other biometric signals in the workplace, and systems that assign social scores based on behavior or personal characteristics.
High-risk obligations, including risk assessments, human oversight, technical documentation and a requirement to inform workers and their representatives before deployment, were originally set to take full effect on August 2, 2026, under the terms set out in the European Union AI Act. The EU adopted the Digital Omnibus package (Regulation (EU) 2026/1744), published in the Official Journal on July 24, 2026 and in force since July 27, 2026, which pushed that deadline back. High-risk obligations for standalone systems, the category that covers most workplace monitoring and HR tools, now apply from December 2, 2027, and obligations for high-risk AI embedded in other regulated products move to August 2, 2028. Transparency obligations under Article 50, such as informing workers when they are interacting with or being assessed by an AI system, took effect as scheduled on August 2, 2026. Employers should treat the extra runway as time to prepare rather than a reason to deprioritize workplace AI governance, since the direction of the rules has not changed: more documentation, more human oversight and more worker notice.
Beyond the EU
This shift extends beyond the EU. Ontario's electronic monitoring policy requirement generally extends to AI tools used for monitoring, and its separate 2026 hiring-disclosure rule adds another AI-specific layer, described in the Canada section above. New South Wales now treats algorithmic monitoring tools as a workplace health and safety issue requiring risk assessment. Even in jurisdictions that do not yet have AI-specific laws, regulators are extending existing monitoring and privacy frameworks to cover automated decisions, so employers should not wait for a dedicated AI law before building appropriate oversight into how monitoring feeds performance decisions.
Building a Practical Multi-Jurisdiction Compliance Framework
Employers operating in more than one of these jurisdictions do not need a different philosophy for each jurisdiction. The considerations below are general risk-reduction practices rather than a compliance checklist or safe harbor, but building around them can lower legal risk without slowing down legitimate monitoring programs.
- Give written notice before monitoring begins, everywhere, even in locations where notice is not strictly required.
- Treat consent warily if employees are based in the EU or UK, and rely instead on documented justification specific to business purposes.
- Collect only data necessary for stated purposes. Continuous keystroke logging or unrestricted screen recording is harder to justify than data collected for measuring productivity.
- Document proportionality or impact assessments for systematic monitoring programs, even in jurisdictions that do not formally require such assessments.
- Avoid features that use AI to infer emotions or biometric traits, because this is outright prohibited in the EU and is scrutinized more and more elsewhere.
- Set limits for data retention, and give employees clear ways to request access to or deletion of monitoring data.
The section below describes optional Controlio features and how each may support a customer's compliance program. It is product information, not legal guidance, and using these features does not by itself establish compliance with any law discussed above.
Controlio's Compliance-Related Features
Controlio is designed with the reality of fragmented monitoring law across different countries in mind, rather than a single regulatory environment. The features below can support a compliance program. They are tools, not a substitute for legal advice or a jurisdiction-by-jurisdiction compliance review.
GDPR Mode and Data Minimization
Controlio's GDPR mode is a setting that turns off collection of window titles, URLs, screen recordings, keystrokes, search terms, files and email content, so companies operating under GDPR are not accumulating personal data they do not need for their stated monitoring purpose. At the start of each monitoring session, Controlio displays a pop-up notice to the employee. This is a tool employers can use as part of meeting the transparency expectations found in frameworks such as GDPR, UK GDPR, PIPEDA and Australian state surveillance laws, though the content and timing of any legally required notice still needs to match what each specific law calls for. Customers can choose to store EU data in EU-based data centers, and the dashboard includes tools to delete stored data on request, which can support a right-to-erasure process.
Accountability and Configuration
Organizations that need to document accountability have access to dashboard access controls such as two-step authentication, IP allowlisting and blocklisting, and an audit log that records who accessed monitoring data and when. These are the kinds of controls that GDPR, UK GDPR and PIPEDA generally expect to see, though whether a given configuration is sufficient depends on the organization's own risk assessment.
Because rules vary by location, Controlio allows flexible configuration at the company, department or individual level, so employers can apply a more restricted configuration, such as GDPR mode, to EU and UK staff while running a different configuration elsewhere from the same dashboard. For organizations with strict data residency needs, such as government agencies or providers subject to HIPAA, Controlio also supports deployment on premises.
Conclusion
Monitoring employees is legal in each of the jurisdictions covered in this guide, but the conditions attached to that legality keep expanding. In the US, new states are adding notice requirements. The EU is extending its data protection framework into formal regulation of AI. The UK continues running a parallel approach to that of the EU. Canada and Australia layer obligations specific to surveillance and employment standards onto laws that already required disclosure. Treating employee monitoring laws as a moving target rather than a fixed checklist is the safest posture for any workplace compliance program in 2026.
One thread that runs through every jurisdiction in this guide is clear:
- employees should know monitoring is happening
- employers should be able to justify that it is proportionate to a real business goal
- and collected data should go no further than what is required by that goal
Programs built around those three principles address risk factors that recur across most of the jurisdictions covered here. They are general risk-reduction considerations, not a compliance checklist or safe harbor, and remain a starting framework rather than a guarantee of compliance in any specific jurisdiction. That is a more durable strategy than trying to track every statute as it changes. Controlio's compliance-related features, including GDPR mode, configurable data collection and on-premises deployment, give organizations practical tools to help apply that approach across a workforce spread across different countries.
FAQ
Is monitoring employees legal?
It depends on the jurisdiction, the purpose and method of monitoring, the data collected, and the applicable notice, privacy, employment and consultation requirements. Some forms of monitoring are lawful in most of the countries covered here when those requirements are met, while other practices are restricted or prohibited.
Do employers need consent from staff to monitor?
This depends on the country. Most US states, Canada's federally regulated sector and Australia rely on notice rather than explicit consent. The EU and UK treat consent as unreliable because of the power imbalance in employment relationships, so employers there generally rely on documented legitimate interest instead.
What is the difference between notice and consent?
Notice means informing employees that monitoring is happening and what it covers. Consent means employees must actively agree before monitoring can go ahead. Connecticut, Delaware, New York, Maine and Ontario require notice. Illinois and California require consent for specific types of monitoring, such as collection of biometric data or recording calls.
Does GDPR allow monitoring of employees?
Yes, but a valid lawful basis is required, usually based on legitimate interests rather than consent, along with proportionality, data minimization and transparency. Systematic monitoring usually requires conducting a Data Protection Impact Assessment.
How does the EU AI Act impact monitoring of employees?
Most employment-related AI, including tools that feed into performance or promotion decisions, is classified as high risk under the AI Act. Following the 2026 Digital Omnibus amendments, the obligations for high-risk systems, such as documentation, human oversight and worker notice, now apply from December 2, 2027 for standalone systems rather than August 2026 as originally planned. Transparency obligations under Article 50 have applied since August 2, 2026. Emotion recognition and social scoring at work have been banned since February 2, 2025.
Can Controlio help with compliance across multiple countries?
Controlio offers a GDPR mode with reduced data collection and the option of EU data residency. Settings can be configured department by department or individually, and audit logging is available to support accountability. On-premises deployment is also available for organizations with strict requirements for where data resides. These features can support a compliance program, but they do not replace a jurisdiction-specific legal review.
Legal Information
This guide provides general information about employee monitoring and workplace AI laws in the jurisdictions it covers. It reflects publicly available legal developments as of August 2026 and does not capture every jurisdiction, every requirement within a jurisdiction, or every subsequent change in the law. Legislative and regulatory developments in this area, particularly around workplace AI, are moving quickly, and parts of this guide may be superseded by the time it is read.
Nothing in this guide is legal advice, and reading it does not create an attorney-client relationship or any other professional relationship. Employers should consult qualified legal counsel licensed in the relevant jurisdiction before designing, implementing or relying on a monitoring program.
This guide is not part of, and is not incorporated into, any agreement between Controlio and its customers. It does not modify Controlio's terms of service, order forms or any other contract, and nothing in this guide should be read as a warranty or representation about compliance with any specific law.
Version history: originally published August 2026. Last legally reviewed August 17, 2026. This guide will be reviewed on a scheduled basis and whenever a tracked bill is enacted, a law referenced above commences, a regulator issues relevant guidance, or a court changes an important interpretation of a law discussed here.