In 2017 the European Court of Human Rights found, by eleven votes to six, that Romania's courts had not protected an engineer whose employer had read his messages; its six factors are a test for any monitoring. In 2024, 7% of EU workplaces reported systems that monitor workers' performance or behaviour. In Germany, the EU Court's reading of Article 88 of the GDPR led the Federal Labour Court in 2025 to leave the general rule on employee data unapplied. An impact assessment and a one-page card close the issue.
Management Review · Second series · November 2026 · No. 71
Employee monit oring and personal data
Forty-five pages of private messages and the Court's six questions, how many workplaces report monitoring systems, what Article 88 asks of national law, when an impact assessment is due, and a card for one measure.
- No.
- 71
- Pages
- 10
- Sources
- 8
- Topics
- AI
Management Review · No. 71
The figures of the issue
The charts of the printed pages, with their sources.
Source: European Agency for Safety and Health at Work (EU-OSHA), 2025
The whole text Read the issue as text For reading on a small screen, searching or a screen reader. The same words, without the page design.
In this issue
E-mail, internet use, location, screens: an employer can now record them for a fraction of what it cost a few years ago. Whether a manager may do so depends less on the tool than on the questions asked before it starts. This issue sets out those questions as European courts and regulators put them. It describes the law; it is not legal advice.
In 2017 the European Court of Human Rights found, by eleven votes to six, that Romania's courts had not protected an engineer whose employer had read his messages; its six factors are a test for any monitoring. In 2024, 7% of EU workplaces reported systems that monitor workers' performance or behaviour. In Germany, the EU Court's reading of Article 88 of the GDPR led the Federal Labour Court in 2025 to leave the general rule on employee data unapplied. An impact assessment and a one-page card close the issue.
Stiven Janaqi, Editor
Cover story
For t y-five pages
In July 2007 a private company in Bucharest recorded, in real time, the Yahoo Messenger account that a sales engineer had opened at its request to answer customers. When he said he had used it only for work, he was shown 45 pages of his messages with his brother and his fiancée. On 1 August he was dismissed.
- The rules. banned personal use of company computers; said nothing about monitoring
- Romanian cou
r ts. upheld the dismissal: he had been warned not to use company resources - Chamber, 2016. no violation of Article 8, by six votes to one
On 5 September 2017 the Grand Chamber found, by eleven votes to six, a violation of the right to respect for private life and correspondence. The courts had not established whether he had been told in advance that he might be monitored, or of its nature and extent, nor the reasons, whether lighter means would have served, or whether content had been read without his knowledge.
Our reading
A ban on private use is not notice of monitoring. People have to know beforehand that they may be watched, and how.
Bărbulescu v. Romania [GC], no. 61496/08, 5 September 2017. The case was brought against the Romanian state, not the employer, and the Court did not decide whether the dismissal was justified: it found that the courts had not weighed the interests at stake.
Source: European Court of Human Rights, Grand Chamber, 2017
The numbers
One workplace in four teen
ESENER 2024, EU-OSHA's survey of 41,458 workplaces with at least five employees in the EU, Iceland, Norway and Switzerland, asked which digital technologies they use. At each workplace, the person who knows best about health and safety answered.
Workplaces using each technology, EU-27, 2024: Computers at fixed workplaces 87%, Laptops, tablets, smartphones 83%, AI that performs work tasks 7%, Monitoring performance or behaviour 7%, The same, transport and storage 15%.
Of the workplaces that use at least one such technology, 35% had consulted employees about its possible effects on their health and safety, up from 24% in 2019.
Our reading
One in fourteen is not a fringe. And where digital tools are in use, about two workplaces in three did not say they had asked their staff.
Shares of workplaces, not of workers, as reported by one person per workplace. 87%, 83% and both 7% are EU-27 averages; 15% is transport and storage. The report shows the other technologies only as bars, so we leave them out.
Source: European Agency for Safety and Health at Work (EU-OSHA), 2025
The model
Six questions before you wat ch
In Bărbulescu the Grand Chamber listed six factors that courts must weigh when an employer monitors communications (§ 121). Asked before a measure starts, they also work as a test for the manager:
- Were people
t old in advance?. Clearly, about the nature of the monitoring, before it begins. - How far does it go?. Flow or content, all or part, how long, where, and who sees the results.
- What is the legitimate reason?. Reading content needs a weightier reason.
- Is there a less intrusive way?. Could the aim be reached without opening the content?
- What are the consequences?. For the person; and are results used only for the stated aim?
- What safeguards are there?. Above all, no access to content without prior notice.
One more guarantee: an employee who was monitored must be able to have a court review all of this (§ 122).
The factors are the Court's, written for communications; using them as questions for any measure is the editors' reading.
Source: European Court of Human Rights, Grand Chamber, 2017
More in the essay: Leading people without losing the person
What the rules say
A rule that said t oo lit tle
Article 88 of the GDPR lets Member States set more specific rules for employee data. Under paragraph 2 they must include suitable and specific measures to safeguard dignity, legitimate interests and fundamental rights, with particular regard to transparency and monitoring systems at work.
- 2018 § 26(1) BDSG: employee data may be processed where necessary for the employment relationship.
- 2023 EU Court, C-34/21: a near-identical Hessian rule appears only to repeat the GDPR; such rules are set aside unless they are a valid legal basis.
- 2025 Federal Labour Court, 8 AZR 209/21: § 26(1) sentence 1 BDSG lacks the measures of Article 88(2) and remains unapplied.
What applies instead is the GDPR itself: a legal basis under Article 6 and the principles of Article 5. In the same case, testing new HR software with real staff data could rest on the employer's legitimate interests, but only if dummy data would not do. Consent rarely helps: employees are seldom free to give or refuse it (Article 29 Working Party).
Our reading
Without a specific law, the general test applies: a clear purpose, real necessity, the lighter option first.
§ 26 BDSG is still in the statute book. The 2025 case concerned an HR system, not monitoring. A description of the law, not legal advice.
Sources: European Parliament and Council of the European Union, Official Journal L 119, 2016; Court of Justice of the European Union, First Chamber, 2023; Bundesarbeitsgericht (Federal Labour Court, Germany), Eighth Senate, 2025; Article 29 Data Protection Working Party, 2017
How it is measured
Two criteria, one assessment
Article 35 of the GDPR requires a data protection impact assessment (DPIA) before processing likely to result in a high risk. The Article 29 Working Party's guidelines list nine criteria; in most cases two are enough. Their own example, a company systematically monitoring its employees' work stations and internet use, meets two: systematic monitoring and vulnerable data subjects.
- Descri
p tion. what is processed, why, and the interest pursued - Necessi
t y. necessity and proportionality in relation to the purpose - Risks. to the rights and freedoms of the people concerned
- Measures. safeguards and security that address those risks
Hypothe tical example, a suppor t team working from home
- Proposal: a screenshot every ten minutes
- Criteria: systematic monitoring, employees: DPIA
- Lighter o
p tion: ticket counts the system already keeps
The DPIA is where the lighter option is written down before the heavier one starts. The case is invented.
The four cards are the minimum content set by Article 35(7). The WP29 guidelines of 2017 were endorsed by the EDPB in 2018.
Sources: European Parliament and Council of the European Union, Official Journal L 119, 2016; Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017
Tool of the issue
The card for one monit oring measure
One card per measure, filled in before it starts and kept with the records. If a line stays empty, the measure is not ready.
- Measure and purpose what is recorded, about whom, and the problem it solves
- Legal basis Article 6 GDPR; consent only if people can freely refuse
- Necessi
t y and the lighter op tion what would prevent the problem without watching anyone - Who was
t old, and how in advance and in writing; in Germany, the works council (§ 87 BetrVG) - Access and r
e tention who sees the results; when they are deleted - DPIA needed? two of the nine criteria? Systematic monitoring of staff usually means yes
A practice proposed by the editors, after Bărbulescu, GDPR Articles 5, 6 and 35, the WP29 texts and § 87(1) no. 6 BetrVG. The diagnostic asks why a number turned red before anyone asks whom to watch. Not legal advice.
Sources: European Court of Human Rights, Grand Chamber, 2017; European Parliament and Council of the European Union, Official Journal L 119, 2016; Article 29 Data Protection Working Party, 2017; Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017; Federal Republic of Germany, Bundesgesetzblatt I p. 2518, 2001
Open the tool: KPI Diagnostic
Sources and method
Every figure has a source.
The figures in this issue come from the sources below. The year shows how recent each one is.
- European Court of Human Rights, Grand Chamber, “Bărbulescu v. Romania [GC], no. 61496/08, judgment of 5 September 2017”, 2017. https://hudoc.echr.coe.int/eng?i=001-177082
- European Agency for Safety and Health at Work (EU-OSHA), “First findings of the Fourth European Survey of Enterprises on New and Emerging Risks (ESENER 2024)”, 2025. https://osha.europa.eu/en/publications/first-findings-fourth-european-survey-enterprises-new-and-emerging-risks-esener-2024
- European Parliament and Council of the European Union, Official Journal L 119, “Regulation (EU) 2016/679, General Data Protection Regulation, Articles 5, 6, 35 and 88”, 2016. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Court of Justice of the European Union, First Chamber, “Hauptpersonalrat der Lehrerinnen und Lehrer, Case C-34/21, judgment of 30 March 2023”, 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0034
- Bundesarbeitsgericht (Federal Labour Court, Germany), Eighth Senate, “Urteil vom 8. Mai 2025, 8 AZR 209/21”, 2025. https://www.bundesarbeitsgericht.de/entscheidung/8-azr-209-21/
- Article 29 Data Protection Working Party, “Opinion 2/2017 on data processing at work (WP 249)”, 2017. https://ec.europa.eu/newsroom/article29/items/610169
- Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, “Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” (WP 248 rev.01)”, 2017. https://ec.europa.eu/newsroom/article29/items/611236
- Federal Republic of Germany, Bundesgesetzblatt I p. 2518, “Betriebsverfassungsgesetz (Works Constitution Act), § 87(1) no. 6, as published on 25 September 2001”, 2001. https://www.gesetze-im-internet.de/betrvg/__87.html
Edit orial me thod
Each figure was checked for its year, its publisher and what exactly it measures. Where the publisher's page could not be opened, the figure was checked against independent summaries and is marked “via”. The editors' interpretation is marked “Our reading”. Figures that could not be confirmed are not in the issue.
Management Review · Monthly edition
