Summary of regulatory guidance. This article summarizes the guidance on monitoring the activity of employed persons published by the CNIL, France's data protection authority.

France's data protection authority, CNIL, published guidance on monitoring employee activity and the use of professional equipment. Employers may verify that tasks are being performed and protect people and property under their responsibility, but they may not exercise this power excessively.

According to CNIL, any monitoring device must meet three cumulative conditions: it must be justified and proportionate to the objective, submitted in advance to staff representative bodies when applicable, and disclosed to the people affected. The rules cover, among other tools, computers, telephones, vehicles, access control, time recording, video surveillance, geolocation, and telephone recordings.

The authority considers constant surveillance excessive and emphasizes that employers must assess, on a case-by-case basis, the purpose, scope, risks to rights, and the existence of less intrusive means. A keylogger installed to monitor remote work is cited as disproportionate, while quarterly measurement of the number of cases handled may be compatible with this requirement.

Before installing or modifying a system, the organization must document its assessment of necessity and proportionality, the data life cycle, authorized access, retention periods, and the measures for informing people and enabling them to exercise their rights.


With information from the CNIL.

This post was summarized from the original publication using artificial intelligence, with human review.