Blog
Privacy and compliance

Employee monitoring and data protection: what companies need to know

Monitoring tools can be legitimate, but they need purpose, necessity, transparency and access control. What to define before switching collection on.

31. Juli 2026Vigilioo Team3 min read

Monitoring a corporate computer almost always means processing personal data. That does not make monitoring forbidden — it makes it a data processing activity that needs a legal basis, a purpose and safeguards.

This article is informational material, not legal advice. Decisions about legal basis and internal policy should be validated with your legal team or data protection officer.

What data shows up in a monitoring tool

It depends on what the company enables, but the typical set includes:

  • User and device identification
  • Applications used and time spent
  • Websites visited
  • Activity and idle hours
  • Equipment location
  • Screen captures, when the feature is on

Some of that is unambiguously personal data. The rest becomes personal once tied to an identifiable person — which, in a corporate context, is almost always the case.

Can a company monitor corporate computers?

Owning the equipment is a relevant argument, but it is not an automatic, unlimited authorisation. What the law requires is a legal basis, and that the processing be adequate, necessary and proportionate to the declared purpose.

In practice, that is what separates defensible monitoring from monitoring that will not hold up.

Purpose: why is this data collected?

Every enabled feature needs a specific answer. "To have control" is not one.

  • Application logging → identify unauthorised software
  • Activity hours → verify working time and shifts
  • Location → asset management and response to loss or theft
  • Screen capture → investigation of a specific incident

If a feature has no purpose that fits in a sentence, it should not be switched on.

Necessity: could the goal be met with less?

This is the test that eliminates the most unnecessary collection.

If the goal is to know whether unauthorised software exists, an application inventory answers it — continuous screen capture is not necessary. If the goal is to verify working time, activity logging is enough.

Collecting more "because it might be useful someday" is exactly what the necessity test exists to stop.

Balancing and safeguards

Where the legal basis is legitimate interest, Brazil's data protection authority guides companies to assess purpose, necessity and the balance between the organisation's interests and the rights and freedoms of the data subject — adopting safeguards where processing goes beyond a person's reasonable expectation.

Concrete safeguards include: restricting collection to working hours, aggregating instead of detailing, limiting access, setting short retention and logging who consulted what.

Transparency is not optional

The team needs to know, clearly and accessibly: what is collected, for what purpose, who has access, how long it is kept and how to exercise their rights.

Covert monitoring is the highest-risk scenario — legally and for trust.

Access must be controlled

Collected data cannot be available to the whole company. Minimum rules:

  • Access by role, not by person
  • A recorded justification for sensitive queries
  • A log of who accessed what, and when
  • Periodic review of who still needs that access

Retention: how long to keep it

Data kept indefinitely is accumulated risk with no upside. Set a deadline per record type and implement disposal — a retention policy only counts if it is automatic.

Proportionality in practice

A concrete example:

A company wants to reduce data leakage. The proportionate response is to block removable storage for the group handling sensitive data and log attempts. The disproportionate response is to enable continuous screen capture company-wide. Both "address" the problem; only one survives a necessity test.

How to structure the rollout

  1. 1Map what the tool is able to collect
  2. 2Choose only what has a declared purpose
  3. 3Define the legal basis with your legal team
  4. 4Record the assessment, including the balancing test
  5. 5Communicate with the team before switching on
  6. 6Configure access, retention and query logging
  7. 7Review periodically

How Vigilioo fits this context

Vigilioo's features are configurable per group, which lets a company enable only what matches its written policy instead of everything at once. Data is encrypted in transit and at rest, and administrative actions are logged.

The tool makes the policy enforceable — but the policy remains the company's decision.

Conclusion

The relevant question is not "can we monitor?". It is "what exactly do we need to know, why, who will see it and for how long?".

A company that answers those four questions before switching collection on has a defensible programme. Those that answer afterwards usually answer to someone else.

Sources

Share