Blog
Privacidad y cumplimiento

Can a company monitor an employee's computer? What Brazilian law says

The short answer is yes — with conditions. What they are, what Brazil's high labour court ruled about corporate email, and what the LGPD requires before any agent is installed.

29 de agosto de 2026Equipo Vigilioo7 min de lectura

The short answer is yes, with conditions — and it is the conditions that decide whether monitoring becomes valid evidence in a dismissal for cause or becomes a claim for moral damages.

This article explains what supports monitoring in Brazil, what limits it, what the LGPD added, and the practical checklist followed by companies that get it right. It does not replace advice from your own legal team: the final analysis depends on the specific case, on what the contracts say and on internal policy.

What authorises it: the employer's managerial authority

The employer bears the risks of the business and directs how work is performed — that is article 2 of the CLT, Brazil's consolidated labour laws. Supervision of the work, including at a distance, follows from that authority.

One provision settles the question for remote work. The sole paragraph of article 6 of the CLT, added by Law 12.551/2011, states that telematic and computerised means of command, control and supervision are equivalent, for the purposes of legal subordination, to personal and direct means.

In plain terms: supervising by software someone working from home is legally equivalent to supervising in person someone working in the next room. The tool changes; the nature of the supervision does not.

Add to that a simple fact of ownership: the laptop, the desktop and the corporate accounts belong to the company. They were provided for work, not for unrestricted personal use.

What limits it: privacy and secrecy of communications

Managerial authority is not absolute. It runs into two clauses of article 5 of the Brazilian Constitution:

  • Clause X — privacy, private life, honour and image are inviolable.
  • Clause XII — the secrecy of correspondence and communications is inviolable.

These rights do not disappear when someone is hired. What exists is a balancing exercise: on one side the company's legitimate interest in supervising work and protecting its assets; on the other, the worker's expectation of privacy. The line Brazilian labour courts have been drawing is the line of the work tool.

What Brazil's high labour court has ruled on corporate email

The most cited case involved an employee of HSBC Seguros Brasil in Brasília, dismissed for cause after sending pornographic images to colleagues through corporate email. The evidence came from monitoring of the company's mailbox.

The First Panel of the TST upheld the dismissal. The reasoning was that corporate email is a work tool and that the employer may exercise "moderate, generalised and impersonal" control over messages sent and received through it — which does not violate the employee's privacy.

Three words carry the whole decision:

TermWhat it means in practice
ModerateScope proportionate to the objective. Not scanning everything, all the time
GeneralisedA rule that applies to everyone, not the pursuit of one person
ImpersonalFocus on the use of the tool, not on the life of whoever uses it

And there is the other side, equally settled: personal email, private messengers and personal accounts may not be accessed — not even when accessed on company equipment during working hours. There, the expectation of privacy remains intact.

What the LGPD added

Monitoring generates personal data: who, when, what they did, from where. Law 13.709/2018 applies in full, and adds two requirements that the labour-law discussion alone did not resolve.

1. A lawful basis, chosen and documented

Processing must rest on one of the grounds in article 7. In corporate monitoring, two are used in practice:

  • Performance of the contract (clause V), where collection is necessary to the employment relationship itself — working-time control being the clearest example.
  • Legitimate interest (clause IX), where the company has a concrete interest — protecting assets, preventing fraud, ensuring information security — that survives a confrontation with the data subject's rights.

Consent is not a good basis here: in an employment relationship, the imbalance between the parties makes it hard to argue the "yes" was freely given.

The chosen basis must be recorded in writing, dated and justified. Without that, processing is irregular even if the purpose is legitimate.

2. The balancing test

For legitimate interest, Brazil's data protection authority (ANPD) published a guidance document in February 2024 setting out a three-phase test:

  1. 1Purpose — is it legitimate, specific and explicit?
  2. 2Necessity — is the data collected the minimum needed to achieve that purpose?
  3. 3Balancing and safeguards — do the data subject's rights hold up? What measures reduce the impact?

Most excesses fail at the second phase. A camera open all day, unrestricted capture of everything typed, reading of personal conversations: these are collections disproportionate to the stated purpose, and disproportion is what defeats legitimate interest.

Article 6 of the LGPD also applies throughout, with the principles of purpose, adequacy, necessity, free access, transparency, security, prevention and non-discrimination.

The mistake that made headlines

In September 2025, Itaú Unibanco dismissed around a thousand people citing low productivity while working from home. The assessment relied on data from monitoring software — active screen time, tabs open during the working day.

What the fallout exposed was not monitoring itself, which is lawful. It was the how: undisclosed criteria, no clear prior notice about what was being measured, no warning before mass dismissal. Unions and specialists questioned both the privacy implications and the labour-law validity of the terminations.

The lesson is direct and cheap to learn: the problem is almost never monitoring. It is monitoring without telling people, measuring what was never agreed, and deciding without a right of reply.

The defensible-monitoring checklist

Seven items. Any one left blank is risk you own.

  1. 1A written policy. An internal document stating what is monitored, for what purpose, how often, how long data is retained and who has access.
  2. 2Employee awareness. Signed at hiring, or as an addendum for the existing team. Covert monitoring survives neither test — labour law or LGPD.
  3. 3Company equipment only. If there is BYOD, the policy must clearly separate corporate from personal.
  4. 4Minimum scope. Collect what the stated purpose requires, and nothing more. A feature existing in the tool does not mean it has to be switched on.
  5. 5Restricted access. Not every manager needs to see everything. Role-based access control, with a record of who consulted what.
  6. 6Defined retention. A written retention period, and actual deletion at the end of it.
  7. 7Consistent use. Data collected for information security does not become, overnight, a dismissal metric nobody knew about.

What about working-time records?

For telework paid by output or task, the CLT sets aside working-time control. For everyone else, hours remain subject to registration — and there the general rules for electronic time records apply, under Ordinance 671/2021 of the Ministry of Labour.

Two different things that are often conflated:

  • Measuring activity — what monitoring software does: when the machine was active, which applications ran, how much actual work took place.
  • Recording time — what a certified electronic time-record system does, with its own legal requirements.

Activity data helps you understand the operation, but it does not replace a time record where one is mandatory. Treating one as the other creates labour liability.

Where Vigilioo stands

Vigilioo was built for the declared scenario, not the covert one. The agent is installed with the knowledge of the company and the team, the dashboard shows what is being collected, and each feature is enabled per group — what a company does not need to monitor, it simply leaves off.

On the controls the LGPD expects: role-based access control, an audit trail for every administrative action, AES-256 encryption at rest and TLS 1.3 in transit. On scope: policy by group, so the sales team does not inherit rules written for finance.

Compliance itself, however, remains your company's responsibility. No tool delivers it ready-made — it delivers the controls your policy needs in order to hold up in practice. See how we handle security and the guide on employee monitoring and data protection.

Conclusion

Monitoring an employee's computer is lawful in Brazil when it falls on the work tool, has a legitimate purpose, a proportionate scope and — the item most often missing — is known to the person being monitored.

A company that writes the policy, gives notice, collects the minimum and uses the data for what it said it would has a management instrument. One that installs in silence and decides afterwards has a problem waiting for a date.

Sources

Compartir