Monitoring a corporate computer almost always means processing personal data. That does not make monitoring forbidden — it makes it a data processing activity that needs a legal basis, a purpose and safeguards.
This article is informational material, not legal advice. Decisions about legal basis and internal policy should be validated with your legal team or data protection officer.
What data shows up in a monitoring tool
It depends on what the company enables, but the typical set includes:
- User and device identification
- Applications used and time spent
- Websites visited
- Activity and idle hours
- Equipment location
- Screen captures, when the feature is on
Some of that is unambiguously personal data. The rest becomes personal once tied to an identifiable person — which, in a corporate context, is almost always the case.
Can a company monitor corporate computers?
Owning the equipment is a relevant argument, but it is not an automatic, unlimited authorisation. What the law requires is a legal basis, and that the processing be adequate, necessary and proportionate to the declared purpose.
In practice, that is what separates defensible monitoring from monitoring that will not hold up.
Purpose: why is this data collected?
Every enabled feature needs a specific answer. "To have control" is not one.
- Application logging → identify unauthorised software
- Activity hours → verify working time and shifts
- Location → asset management and response to loss or theft
- Screen capture → investigation of a specific incident
If a feature has no purpose that fits in a sentence, it should not be switched on.
Necessity: could the goal be met with less?
This is the test that eliminates the most unnecessary collection.
If the goal is to know whether unauthorised software exists, an application inventory answers it — continuous screen capture is not necessary. If the goal is to verify working time, activity logging is enough.
Collecting more "because it might be useful someday" is exactly what the necessity test exists to stop.
Balancing and safeguards
Where the legal basis is legitimate interest, Brazil's data protection authority guides companies to assess purpose, necessity and the balance between the organisation's interests and the rights and freedoms of the data subject — adopting safeguards where processing goes beyond a person's reasonable expectation.
Concrete safeguards include: restricting collection to working hours, aggregating instead of detailing, limiting access, setting short retention and logging who consulted what.
Transparency is not optional
The team needs to know, clearly and accessibly: what is collected, for what purpose, who has access, how long it is kept and how to exercise their rights.
Covert monitoring is the highest-risk scenario — legally and for trust.
Access must be controlled
Collected data cannot be available to the whole company. Minimum rules:
- Access by role, not by person
- A recorded justification for sensitive queries
- A log of who accessed what, and when
- Periodic review of who still needs that access
Retention: how long to keep it
Data kept indefinitely is accumulated risk with no upside. Set a deadline per record type and implement disposal — a retention policy only counts if it is automatic.
Proportionality in practice
A concrete example:
A company wants to reduce data leakage. The proportionate response is to block removable storage for the group handling sensitive data and log attempts. The disproportionate response is to enable continuous screen capture company-wide. Both "address" the problem; only one survives a necessity test.
How to structure the rollout
- 1Map what the tool is able to collect
- 2Choose only what has a declared purpose
- 3Define the legal basis with your legal team
- 4Record the assessment, including the balancing test
- 5Communicate with the team before switching on
- 6Configure access, retention and query logging
- 7Review periodically
How Vigilioo fits this context
Vigilioo's features are configurable per group, which lets a company enable only what matches its written policy instead of everything at once. Data is encrypted in transit and at rest, and administrative actions are logged.
The tool makes the policy enforceable — but the policy remains the company's decision.
Conclusion
The relevant question is not "can we monitor?". It is "what exactly do we need to know, why, who will see it and for how long?".
A company that answers those four questions before switching collection on has a defensible programme. Those that answer afterwards usually answer to someone else.