Management Review · Second series · November 2026 · No. 71

Employee monitoring and personal data

Forty-five pages of private messages and the Court's six questions, how many workplaces report monitoring systems, what Article 88 asks of national law, when an impact assessment is due, and a card for one measure.

No.
71
Pages
10
Sources
8
Topics
AI
Stiven CatalystSecond series · November 2026
ManagementReview

Management without theatre.

AI

Employee monitoringand personal data

Forty-five pages of private messages and the Court's six questions, how many workplaces report monitoring systems, what Article 88 asks of national law, when an impact assessment is due, and a card for one measure.

No.71

11–6

votes: the Grand Chamber found that Romania's courts had failed to protect an engineer whose employer had read his private messages.ECtHR, Bărbulescu v. Romania, 2017

Inside

  1. Cover storyForty-five pagesPage 03
  2. The modelSix questions before you watchPage 05
  3. Tool of the issueThe card for one monitoring measurePage 08

stivencatalyst.com

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst2

No. 71 · AI

In this issue

E-mail, internet use, location, screens: an employer can now record them for a fraction of what it cost a few years ago. Whether a manager may do so depends less on the tool than on the questions asked before it starts. This issue sets out those questions as European courts and regulators put them. It describes the law; it is not legal advice.

In 2017 the European Court of Human Rights found, by eleven votes to six, that Romania's courts had not protected an engineer whose employer had read his messages; its six factors are a test for any monitoring. In 2024, 7% of EU workplaces reported systems that monitor workers' performance or behaviour. In Germany, the EU Court's reading of Article 88 of the GDPR led the Federal Labour Court in 2025 to leave the general rule on employee data unapplied. An impact assessment and a one-page card close the issue.

  1. 03Cover storyForty-five pages
  2. 04The numbersOne workplace in fourteen
  3. 05The modelSix questions before you watch
  4. 06What the rules sayA rule that said too little
  5. 07How it is measuredTwo criteria, one assessment
  6. 08Tool of the issueThe card for one monitoring measure
  7. 09SourcesSources and method

How to read this issue

Figure

Every figure has its source and year at the foot of its page.

Our reading

Where the editors interpret rather than the research, it says so.

Practice

The steps and the card are proposals to try, not research results.

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst3

Cover story

Forty-fivepages

In July 2007 a private company in Bucharest recorded, in real time, the Yahoo Messenger account that a sales engineer had opened at its request to answer customers. When he said he had used it only for work, he was shown 45 pages of his messages with his brother and his fiancée. On 1 August he was dismissed.

01

The rules

banned personal use of company computers; said nothing about monitoring

02

Romanian courts

upheld the dismissal: he had been warned not to use company resources

03

Chamber, 2016

no violation of Article 8, by six votes to one

On 5 September 2017 the Grand Chamber found, by eleven votes to six, a violation of the right to respect for private life and correspondence. The courts had not established whether he had been told in advance that he might be monitored, or of its nature and extent, nor the reasons, whether lighter means would have served, or whether content had been read without his knowledge.

Our reading

A ban on private use is not notice of monitoring. People have to know beforehand that they may be watched, and how.

Source: European Court of Human Rights, Grand Chamber, 2017

Bărbulescu v. Romania [GC], no. 61496/08, 5 September 2017. The case was brought against the Romanian state, not the employer, and the Court did not decide whether the dismissal was justified: it found that the courts had not weighed the interests at stake.

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst4

The numbers

One workplacein fourteen

ESENER 2024, EU-OSHA's survey of 41,458 workplaces with at least five employees in the EU, Iceland, Norway and Switzerland, asked which digital technologies they use. At each workplace, the person who knows best about health and safety answered.

Workplaces using each technology, EU-27, 2024

Computers at fixed workplaces87%Laptops, tablets, smartphones83%AI that performs work tasks7%Monitoring performance or behaviour7%The same, transport and storage15%

Of the workplaces that use at least one such technology, 35% had consulted employees about its possible effects on their health and safety, up from 24% in 2019.

Our reading

One in fourteen is not a fringe. And where digital tools are in use, about two workplaces in three did not say they had asked their staff.

Source: European Agency for Safety and Health at Work (EU-OSHA), 2025

Shares of workplaces, not of workers, as reported by one person per workplace. 87%, 83% and both 7% are EU-27 averages; 15% is transport and storage. The report shows the other technologies only as bars, so we leave them out.

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst5

The model

Six questionsbefore you watch

In Bărbulescu the Grand Chamber listed six factors that courts must weigh when an employer monitors communications (§ 121). Asked before a measure starts, they also work as a test for the manager:

  1. Were people told in advance?

    Clearly, about the nature of the monitoring, before it begins.

  2. How far does it go?

    Flow or content, all or part, how long, where, and who sees the results.

  3. What is the legitimate reason?

    Reading content needs a weightier reason.

  4. Is there a less intrusive way?

    Could the aim be reached without opening the content?

  5. What are the consequences?

    For the person; and are results used only for the stated aim?

  6. What safeguards are there?

    Above all, no access to content without prior notice.

One more guarantee: an employee who was monitored must be able to have a court review all of this (§ 122).

Source: European Court of Human Rights, Grand Chamber, 2017

The factors are the Court's, written for communications; using them as questions for any measure is the editors' reading.

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst6

What the rules say

A rule thatsaid too little

Article 88 of the GDPR lets Member States set more specific rules for employee data. Under paragraph 2 they must include suitable and specific measures to safeguard dignity, legitimate interests and fundamental rights, with particular regard to transparency and monitoring systems at work.

  1. 2018§ 26(1) BDSG: employee data may be processed where necessary for the employment relationship.
  2. 2023EU Court, C-34/21: a near-identical Hessian rule appears only to repeat the GDPR; such rules are set aside unless they are a valid legal basis.
  3. 2025Federal Labour Court, 8 AZR 209/21: § 26(1) sentence 1 BDSG lacks the measures of Article 88(2) and remains unapplied.

What applies instead is the GDPR itself: a legal basis under Article 6 and the principles of Article 5. In the same case, testing new HR software with real staff data could rest on the employer's legitimate interests, but only if dummy data would not do. Consent rarely helps: employees are seldom free to give or refuse it (Article 29 Working Party).

Our reading

Without a specific law, the general test applies: a clear purpose, real necessity, the lighter option first.

Sources: European Parliament and Council of the European Union, Official Journal L 119, 2016; Court of Justice of the European Union, First Chamber, 2023; Bundesarbeitsgericht (Federal Labour Court, Germany), Eighth Senate, 2025; Article 29 Data Protection Working Party, 2017

§ 26 BDSG is still in the statute book. The 2025 case concerned an HR system, not monitoring. A description of the law, not legal advice.

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst7

How it is measured

Two criteria,one assessment

Article 35 of the GDPR requires a data protection impact assessment (DPIA) before processing likely to result in a high risk. The Article 29 Working Party's guidelines list nine criteria; in most cases two are enough. Their own example, a company systematically monitoring its employees' work stations and internet use, meets two: systematic monitoring and vulnerable data subjects.

01

Description

what is processed, why, and the interest pursued

02

Necessity

necessity and proportionality in relation to the purpose

03

Risks

to the rights and freedoms of the people concerned

04

Measures

safeguards and security that address those risks

Hypothetical example, a support team working from home
Proposal
a screenshot every ten minutes
Criteria
systematic monitoring, employees: DPIA
Lighter option
ticket counts the system already keeps

The DPIA is where the lighter option is written down before the heavier one starts. The case is invented.

Sources: European Parliament and Council of the European Union, Official Journal L 119, 2016; Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017

The four cards are the minimum content set by Article 35(7). The WP29 guidelines of 2017 were endorsed by the EDPB in 2018.

Management Review · No. 71 · November 2026AI
stivencatalyst.comStiven Catalyst8

Tool of the issue

The card for onemonitoring measure

One card per measure, filled in before it starts and kept with the records. If a line stays empty, the measure is not ready.

  1. 01Measure and purposewhat is recorded, about whom, and the problem it solves

  2. 02Legal basisArticle 6 GDPR; consent only if people can freely refuse

  3. 03Necessity and the lighter optionwhat would prevent the problem without watching anyone

  4. 04Who was told, and howin advance and in writing; in Germany, the works council (§ 87 BetrVG)

  5. 05Access and retentionwho sees the results; when they are deleted

  6. 06DPIA needed?two of the nine criteria? Systematic monitoring of staff usually means yes

Sources: European Court of Human Rights, Grand Chamber, 2017; European Parliament and Council of the European Union, Official Journal L 119, 2016; Article 29 Data Protection Working Party, 2017; Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017; Federal Republic of Germany, Bundesgesetzblatt I p. 2518, 2001

A practice proposed by the editors, after Bărbulescu, GDPR Articles 5, 6 and 35, the WP29 texts and § 87(1) no. 6 BetrVG. The diagnostic asks why a number turned red before anyone asks whom to watch. Not legal advice.

Management Review · No. 71 · November 2026Sources
stivencatalyst.comStiven Catalyst9

Sources and method

Every figurehas a source.

The figures in this issue come from the sources below. The year shows how recent each one is.

  1. Bărbulescu v. Romania [GC], no. 61496/08, judgment of 5 September 2017European Court of Human Rights, Grand Chamber, 2017https://hudoc.echr.coe.int/eng?i=001-177082
  2. First findings of the Fourth European Survey of Enterprises on New and Emerging Risks (ESENER 2024)European Agency for Safety and Health at Work (EU-OSHA), 2025https://osha.europa.eu/en/publications/first-findings-fourth-european-survey-enterprises-new-and-emerging-risks-esener-2024
  3. Regulation (EU) 2016/679, General Data Protection Regulation, Articles 5, 6, 35 and 88European Parliament and Council of the European Union, Official Journal L 119, 2016https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
  4. Hauptpersonalrat der Lehrerinnen und Lehrer, Case C-34/21, judgment of 30 March 2023Court of Justice of the European Union, First Chamber, 2023https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0034
  5. Urteil vom 8. Mai 2025, 8 AZR 209/21Bundesarbeitsgericht (Federal Labour Court, Germany), Eighth Senate, 2025https://www.bundesarbeitsgericht.de/entscheidung/8-azr-209-21/
  6. Opinion 2/2017 on data processing at work (WP 249)Article 29 Data Protection Working Party, 2017https://ec.europa.eu/newsroom/article29/items/610169
  7. Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” (WP 248 rev.01)Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017https://ec.europa.eu/newsroom/article29/items/611236
  8. Betriebsverfassungsgesetz (Works Constitution Act), § 87(1) no. 6, as published on 25 September 2001Federal Republic of Germany, Bundesgesetzblatt I p. 2518, 2001https://www.gesetze-im-internet.de/betrvg/__87.html
Editorial method

Each figure was checked for its year, its publisher and what exactly it measures. Where the publisher's page could not be opened, the figure was checked against independent summaries and is marked “via”. The editors' interpretation is marked “Our reading”. Figures that could not be confirmed are not in the issue.

ManagementReview

Management without theatre.

Every issue, one management question, checked against the best research.

All issues

stivencatalyst.com/magazine/management-review.html

Management Review · No. 71 · November 2026 · Stiven Catalyst

Management Review · No. 71

The figures of the issue

The charts of the printed pages, with their sources.

The numbersWorkplaces using each technology, EU-27, 2024
Computers at fixed workplaces87%Laptops, tablets, smartphones83%AI that performs work tasks7%Monitoring performance or behaviour7%The same, transport and storage15%
Computers at fixed workplaces87%Laptops, tablets, smartphones83%AI that performs work tasks7%Monitoring performance or behaviour7%The same, transport and storage15%

Source: European Agency for Safety and Health at Work (EU-OSHA), 2025

The whole text Read the issue as text For reading on a small screen, searching or a screen reader. The same words, without the page design.

In this issue

E-mail, internet use, location, screens: an employer can now record them for a fraction of what it cost a few years ago. Whether a manager may do so depends less on the tool than on the questions asked before it starts. This issue sets out those questions as European courts and regulators put them. It describes the law; it is not legal advice.

In 2017 the European Court of Human Rights found, by eleven votes to six, that Romania's courts had not protected an engineer whose employer had read his messages; its six factors are a test for any monitoring. In 2024, 7% of EU workplaces reported systems that monitor workers' performance or behaviour. In Germany, the EU Court's reading of Article 88 of the GDPR led the Federal Labour Court in 2025 to leave the general rule on employee data unapplied. An impact assessment and a one-page card close the issue.

Stiven Janaqi, Editor

Cover story

Forty-five pages

In July 2007 a private company in Bucharest recorded, in real time, the Yahoo Messenger account that a sales engineer had opened at its request to answer customers. When he said he had used it only for work, he was shown 45 pages of his messages with his brother and his fiancée. On 1 August he was dismissed.

  • The rules. banned personal use of company computers; said nothing about monitoring
  • Romanian courts. upheld the dismissal: he had been warned not to use company resources
  • Chamber, 2016. no violation of Article 8, by six votes to one

On 5 September 2017 the Grand Chamber found, by eleven votes to six, a violation of the right to respect for private life and correspondence. The courts had not established whether he had been told in advance that he might be monitored, or of its nature and extent, nor the reasons, whether lighter means would have served, or whether content had been read without his knowledge.

Our reading

A ban on private use is not notice of monitoring. People have to know beforehand that they may be watched, and how.

Bărbulescu v. Romania [GC], no. 61496/08, 5 September 2017. The case was brought against the Romanian state, not the employer, and the Court did not decide whether the dismissal was justified: it found that the courts had not weighed the interests at stake.

Source: European Court of Human Rights, Grand Chamber, 2017

The numbers

One workplace in fourteen

ESENER 2024, EU-OSHA's survey of 41,458 workplaces with at least five employees in the EU, Iceland, Norway and Switzerland, asked which digital technologies they use. At each workplace, the person who knows best about health and safety answered.

Workplaces using each technology, EU-27, 2024: Computers at fixed workplaces 87%, Laptops, tablets, smartphones 83%, AI that performs work tasks 7%, Monitoring performance or behaviour 7%, The same, transport and storage 15%.

Of the workplaces that use at least one such technology, 35% had consulted employees about its possible effects on their health and safety, up from 24% in 2019.

Our reading

One in fourteen is not a fringe. And where digital tools are in use, about two workplaces in three did not say they had asked their staff.

Shares of workplaces, not of workers, as reported by one person per workplace. 87%, 83% and both 7% are EU-27 averages; 15% is transport and storage. The report shows the other technologies only as bars, so we leave them out.

Source: European Agency for Safety and Health at Work (EU-OSHA), 2025

The model

Six questions before you watch

In Bărbulescu the Grand Chamber listed six factors that courts must weigh when an employer monitors communications (§ 121). Asked before a measure starts, they also work as a test for the manager:

  • Were people told in advance?. Clearly, about the nature of the monitoring, before it begins.
  • How far does it go?. Flow or content, all or part, how long, where, and who sees the results.
  • What is the legitimate reason?. Reading content needs a weightier reason.
  • Is there a less intrusive way?. Could the aim be reached without opening the content?
  • What are the consequences?. For the person; and are results used only for the stated aim?
  • What safeguards are there?. Above all, no access to content without prior notice.

One more guarantee: an employee who was monitored must be able to have a court review all of this (§ 122).

The factors are the Court's, written for communications; using them as questions for any measure is the editors' reading.

Source: European Court of Human Rights, Grand Chamber, 2017

More in the essay: Leading people without losing the person

What the rules say

A rule that said too little

Article 88 of the GDPR lets Member States set more specific rules for employee data. Under paragraph 2 they must include suitable and specific measures to safeguard dignity, legitimate interests and fundamental rights, with particular regard to transparency and monitoring systems at work.

  • 2018 § 26(1) BDSG: employee data may be processed where necessary for the employment relationship.
  • 2023 EU Court, C-34/21: a near-identical Hessian rule appears only to repeat the GDPR; such rules are set aside unless they are a valid legal basis.
  • 2025 Federal Labour Court, 8 AZR 209/21: § 26(1) sentence 1 BDSG lacks the measures of Article 88(2) and remains unapplied.

What applies instead is the GDPR itself: a legal basis under Article 6 and the principles of Article 5. In the same case, testing new HR software with real staff data could rest on the employer's legitimate interests, but only if dummy data would not do. Consent rarely helps: employees are seldom free to give or refuse it (Article 29 Working Party).

Our reading

Without a specific law, the general test applies: a clear purpose, real necessity, the lighter option first.

§ 26 BDSG is still in the statute book. The 2025 case concerned an HR system, not monitoring. A description of the law, not legal advice.

Sources: European Parliament and Council of the European Union, Official Journal L 119, 2016; Court of Justice of the European Union, First Chamber, 2023; Bundesarbeitsgericht (Federal Labour Court, Germany), Eighth Senate, 2025; Article 29 Data Protection Working Party, 2017

How it is measured

Two criteria, one assessment

Article 35 of the GDPR requires a data protection impact assessment (DPIA) before processing likely to result in a high risk. The Article 29 Working Party's guidelines list nine criteria; in most cases two are enough. Their own example, a company systematically monitoring its employees' work stations and internet use, meets two: systematic monitoring and vulnerable data subjects.

  • Description. what is processed, why, and the interest pursued
  • Necessity. necessity and proportionality in relation to the purpose
  • Risks. to the rights and freedoms of the people concerned
  • Measures. safeguards and security that address those risks

Hypothetical example, a support team working from home

  • Proposal: a screenshot every ten minutes
  • Criteria: systematic monitoring, employees: DPIA
  • Lighter option: ticket counts the system already keeps

The DPIA is where the lighter option is written down before the heavier one starts. The case is invented.

The four cards are the minimum content set by Article 35(7). The WP29 guidelines of 2017 were endorsed by the EDPB in 2018.

Sources: European Parliament and Council of the European Union, Official Journal L 119, 2016; Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017

Tool of the issue

The card for one monitoring measure

One card per measure, filled in before it starts and kept with the records. If a line stays empty, the measure is not ready.

  1. Measure and purpose what is recorded, about whom, and the problem it solves
  2. Legal basis Article 6 GDPR; consent only if people can freely refuse
  3. Necessity and the lighter option what would prevent the problem without watching anyone
  4. Who was told, and how in advance and in writing; in Germany, the works council (§ 87 BetrVG)
  5. Access and retention who sees the results; when they are deleted
  6. DPIA needed? two of the nine criteria? Systematic monitoring of staff usually means yes

A practice proposed by the editors, after Bărbulescu, GDPR Articles 5, 6 and 35, the WP29 texts and § 87(1) no. 6 BetrVG. The diagnostic asks why a number turned red before anyone asks whom to watch. Not legal advice.

Sources: European Court of Human Rights, Grand Chamber, 2017; European Parliament and Council of the European Union, Official Journal L 119, 2016; Article 29 Data Protection Working Party, 2017; Article 29 Data Protection Working Party; endorsed by the EDPB, 25 May 2018, 2017; Federal Republic of Germany, Bundesgesetzblatt I p. 2518, 2001

Open the tool: KPI Diagnostic

Sources and method

Every figure has a source.

The figures in this issue come from the sources below. The year shows how recent each one is.

Editorial method

Each figure was checked for its year, its publisher and what exactly it measures. Where the publisher's page could not be opened, the figure was checked against independent summaries and is marked “via”. The editors' interpretation is marked “Our reading”. Figures that could not be confirmed are not in the issue.

Management Review · Monthly edition

Read another issue

All issues