Compliance for remote monitoring is decided by where the employee sits, not where the company is registered. A single team spread across three states and two countries can face three different disclosure regimes at once, and the tool cannot resolve that for you.

What the tool can do is make compliance practical or impossible. Remote employee monitoring software that captures only between clock-in and clock-out, keeps keystroke content out of scope, and lets employees see their own records is straightforward to disclose; a platform that records continuously and hides its agent creates obligations most organisations cannot meet. The configuration decisions made at deployment determine the legal position more than the vendor's compliance page does.

This guide summarises publicly reported requirements as a starting point for planning. It is not legal advice, requirements change frequently, and you should confirm specifics with counsel in each jurisdiction where you employ people.

The rule that governs everything: employee location decides

The rule that governs everything

Monitoring law follows the worker. A company headquartered in Florida with an employee working from Connecticut applies Connecticut's rules to that employee. The same company's employee in Berlin falls under GDPR.

This has three practical consequences.

Hiring remotely expands your compliance surface. Every new jurisdiction adds a rule set. Organisations that hire "anywhere" rarely map this before the first hire.

A single policy must satisfy the strictest applicable standard. Most organizations write one policy at the highest bar rather than maintaining a matrix, then configure tools per region where the tool allows it.

Relocation changes obligations silently. An employee who moves from Texas to California during a hybrid arrangement may shift your requirements without anyone updating the policy.

United States: federal baseline

The Electronic Communications Privacy Act permits employers to monitor communications and activity on company-owned systems, with a business-purpose justification. Federal law does not itself require notifying employees about monitoring on company devices.

Two federal-level points matter for remote work specifically.

One-party consent applies to recordings. In one-party consent states, only one participant in a conversation needs to consent, which generally allows recording of calls the employer is party to. Several states require all-party consent, which changes the analysis for call recording entirely.

Personal devices sit outside the baseline. ECPA's permissiveness attaches to company-owned systems. Monitoring an employee's own laptop requires explicit written consent and should be scoped narrowly to work applications and data.

United States: state requirements

Several states impose notification obligations beyond the federal baseline. Reporting varies on the exact list, which is itself a reason to verify locally.

Consistently reported as requiring written notice: Connecticut, Delaware, and New York. New York additionally requires posting the notice visibly.

Also reported in 2026 sources: Colorado under its privacy act, and Texas in some listings. Sources disagree here, so confirm before relying on either.

Biometric statutes: Illinois BIPA is the strictest, requiring written consent and documented handling for facial recognition, fingerprint scanning, and similar — including where biometrics are used only for login. Texas and Washington have their own regimes.

Reported 2026 developments: California and Maine have both been reported as tightening requirements around continuous capture and screenshot-based monitoring, with data minimisation, employee access rights, and limits on non-working-hours monitoring appearing in coverage. Analysts project roughly 15 states will have specific disclosure laws by 2028, up from a handful today.

The direction of travel is consistent even where the details are contested: more disclosure, more minimisation, more employee access rights.

GDPR: why consent does not solve it

GDPR: why consent does not solve it

The most common mistake in EU-facing deployments is treating employee consent as the legal basis.

Consent is generally invalid in the employment context. The power imbalance between employer and employee means consent is not considered freely given. Regulators expect employers to rely on legitimate interest instead — which requires demonstrating the business need and balancing it against employee rights, documented in advance.

A Data Protection Impact Assessment is required for systematic monitoring. This is a document you produce before deployment, not a form filed afterwards.

Data minimisation is a legal obligation, not a preference. If productivity insight can be obtained from application usage, capturing screenshots is difficult to justify. Every additional capture layer must be defended on necessity.

Employees have access rights. They can view, correct, and request deletion of data held about them. A tool that cannot show an individual their own records makes this obligation expensive to meet manually.

Purpose limitation binds you afterwards. Data collected for productivity cannot later be repurposed for an unrelated use without a new lawful basis. Collecting for capacity planning and then using it in a disciplinary process is exactly the pattern regulators penalise.

Article 22 restricts automated decisions. Any process where monitoring output significantly affects an employee needs a genuine human review step, not a rubber stamp.

Cross-border transfer rules apply when data leaves the EU. Where monitoring data is stored matters.

Enforcement is not theoretical: Amazon France was fined €32 million over excessively intrusive warehouse monitoring where workers were unaware of its scope.

Country-specific rules within the EU

GDPR is a floor, and several member states build higher.

  • Germany — works council approval is typically required before monitoring is deployed, and councils can block it.
  • Portugal — reported to prohibit surveillance tools for remote workers.
  • Greece — reported to ban webcam monitoring of remote employees.
  • France — CNIL applies proportionality strictly; the Amazon fine illustrates the standard.

Any EU-facing deployment needs country-level checking rather than a single GDPR posture.

Other jurisdictions

Other jurisdictions

Canada. Ontario's Employment Standards Act requires employers with 25 or more employees to maintain a written electronic monitoring policy stating what is monitored, how, in what circumstances, and for what purposes the data may be used. PIPEDA applies federally to commercial handling of personal data.

United Kingdom. UK GDPR mirrors EU requirements; ICO guidance emphasises impact assessment and proportionality.

Australia. Workplace surveillance legislation in New South Wales and the ACT requires advance written notice, typically 14 days.

Asia-Pacific generally. Requirements vary widely and several jurisdictions treat biometric and location data as sensitive with separate consent rules.

Capture layers ranked by legal exposure

Not every monitoring feature carries the same risk. This is the most useful lens for configuration decisions. 

Layer Exposure Why 
Time and attendance Low Minimal personal data, clear business purpose 
Application usage Low Aggregate patterns, easy to justify 
Activity levels (input occurred) Low No content captured 
Domain-level web logs Low–medium Justifiable; avoid full URLs where possible 
Interval screenshots Medium–high Captures incidental personal content; under scrutiny in several states 
Full URL and page titles High Reveals health, financial, and political interests 
Continuous screen recording High Difficult to justify under minimisation 
Keystroke content Very high Captures passwords, personal messages, regulated data 
Biometrics Very high Dedicated statutes in several states and countries 
Location tracking High Sensitive category in many jurisdictions; hard to justify for desk work 

The practical read: the top four layers cover most legitimate business needs and carry the lightest obligations. Organizations implementing these practices can also benefit from Employee Time Tracking Apps to improve productivity while maintaining transparent and compliant workforce management. Everything below the midpoint requires a documented, specific justification. 

Tools differ meaningfully here. Monitask does not record keystroke content — activity levels derive from whether keyboard and mouse input occurred within each ten-minute window — and captures only while an employee is clocked in, with location tracking gated to its Business Premium tier rather than enabled by default. Teramind, Veriato, and Controlio capture keystroke content at upper tiers, which is appropriate for insider-risk programs and problematic for productivity ones. 

Configuration checklist for a defensible deployment

Configuration checklist for a defensible deployment

Nine settings determine whether a deployment survives scrutiny. Choosing the right remote employee monitoring software makes it easier to configure monitoring that aligns with legal requirements while reducing compliance risks across different jurisdictions.

☐ Company devices only, or explicit written consent for personal ones. The cleanest position is issuing company hardware to remote staff and restricting monitoring to it.

☐ Visible mode by default. A visible agent satisfies notification expectations in most jurisdictions. Stealth capability exists in most tools; using it needs specific legal advice.

☐ Session-based capture. Monitoring that stops at clock-out avoids collecting off-hours activity — the category most likely to create problems, particularly on devices used personally.

☐ Minimum viable layers. Enable only what the stated purpose requires. Every additional layer must be defensible on necessity.

☐ Role-based access. Only named roles should see individual data. Aggregate views for everyone else.

☐ Defined retention with automatic deletion. Set a window, document why, and let the system delete. Indefinite retention is indefensible under minimisation.

☐ Employee self-view. Directly supports GDPR access rights and reduces the manual burden of subject access requests.

☐ Encryption in transit and at rest. Standard on paid tools; verify rather than assume.

☐ Audit logs of who viewed what. Protects employees from casual access and demonstrates governance.

What the policy must say

Distribute before activating monitoring, not after.

  1. What is captured, layer by layer, in plain language
  2. When capture runs — working hours only, or continuously
  3. What is not captured — the clause employees most want and most policies omit
  4. The lawful basis or business purpose
  5. Who can access individual data, by role
  6. Retention period and what happens at expiry
  7. Permitted uses — and explicitly excluded uses
  8. How employees access, correct, or contest their own data
  9. Who to contact with questions

Ontario mandates most of this in writing for larger employers. GDPR requires the substance regardless of format.

Common compliance failures

One policy for a multi-state team. A policy written for headquarters does not cover the employee in Connecticut or the contractor in Lisbon.

Treating consent as the GDPR basis. It generally is not valid in employment. Legitimate interest with documented balancing is the workable route.

Monitoring personal devices without scoped consent. Scanning personal browsing, photos, or messages on employee-owned hardware is indefensible regardless of what a consent form says.

Repurposing data. Collected for billing, used for discipline. This breaches purpose limitation and destroys trust in the same move.

Retaining indefinitely. Every month of unnecessary retention is exposure without benefit.

Deploying before disclosing. Even where lawful, discovery converts a compliance question into an employee-relations crisis.

Ignoring offboarding. Departing employees retain access rights to their data. Decide in advance what happens to their records at exit.

Conclusion

Remote work has made employee monitoring more common, but compliance depends on how thoughtfully it is implemented. Clear policies, transparent communication, and careful configuration matter far more than enabling every available feature. Organizations can also benefit from following Best Tips for Remote Work to build a productive, transparent, and compliant remote workforce. The best remote employee monitoring software supports these goals by giving organizations the flexibility to monitor responsibly while respecting employee privacy. As regulations continue to evolve, businesses that balance accountability with trust will be better prepared to maintain compliance and build stronger relationships with their remote teams.

Frequently asked questions

Q1. Which laws apply if my remote team is in multiple states?

The law of each employee's work location applies to that employee, regardless of where the company is headquartered. Most organisations write a single policy meeting the strictest applicable standard rather than maintaining separate ones.

Q2. Do I need employee consent to monitor remote workers?

In the US, consent is generally not required on company-owned devices, though several states require written notice. Under GDPR, consent is usually an invalid basis because of the employment power imbalance — employers typically rely on documented legitimate interest instead.

Q3. Are screenshots legal for remote monitoring?

Generally yes in the US with proper notice, though some states have been reported to tighten requirements around necessity and continuous capture. Under GDPR, screenshots must survive a minimisation test: if application-level data answers the question, screenshots are hard to justify.

Q4. Can I monitor an employee's personal laptop?

Only with explicit written consent, scoped narrowly to work applications and data. Personal browsing, photos, and private messages remain out of scope regardless of consent language. Issuing company hardware is the cleaner solution.

Q5. What is a Data Protection Impact Assessment?

A documented assessment of privacy risk that GDPR requires before deploying systematic monitoring. It records what you collect, why, the risks to employees, and the mitigations applied. It is produced before deployment, not after.

Q6. How long can monitoring data be retained?

There is no universal figure; the requirement is that retention be no longer than necessary for the stated purpose and documented. Entry-tier tools often retain one to two months by default, which is frequently shorter than organisations expect.

Q7. Can monitoring data be used in disciplinary proceedings?

Only if the policy states that purpose in advance. Data collected for productivity or billing and later used for discipline breaches GDPR purpose limitation, and under Article 22 any significant automated decision requires genuine human review.

Q8. What happens to monitoring data when an employee leaves?

They retain access and deletion rights over their personal data in GDPR jurisdictions. Define the offboarding process in advance: what is deleted, what is retained for legitimate reasons such as billing records, and for how long.