---
title: How Companies Spy on Their Employees
description: "So here's something fun to think about. If you're reading this on a work laptop, your employer might be watching you right now. Not metaphorically. Not in some vague, \"oh they can probably see my browser history\" kind of way. Actually watching you. Like from your webcam. So maybe get back to work and stop procrastinating? (Just joking — you're probably fine. Please don't leave).\n\nThere's a category of software that digital rights groups have started calling \"bossware.\" It sits quietly on your device, logs everything you do, and sends all of that data back to a dashboard where your manager can see exactly how \"productive\" you've been — down to the minute.\n\nSome of these tools can activate your webcam without telling you. Some record every single key you press, including passwords. Some take a photo of your face every few minutes just to make sure you're the one sitting there.\n\nThis isn't fringe. This isn't some dystopian pilot programme at one weird company. Surveys suggest that somewhere between 60 and 70 percent of medium to large employers now use some form of digital monitoring on their workers. That number has roughly doubled since the start of 2020. And it's still climbing.\n\nEmployers will tell you this is about security. Compliance. Protecting company data. And sure, sometimes it is. But when the software can see what you're typing in a private message, or flag you for getting up to make a cup of tea, or quietly score your worth based on how often you wiggle your mouse — is that really still about security?\n\nIn this article, we're opening up the black box of workplace monitoring. How it works. How far it goes. What it does to people. And what happens when your boss stops managing you and starts watching you.\n\n## The Scale of the Watching\n\nSo let's break those numbers down.\n\nThe 60 to 70 percent figure comes from a few different places. Gartner, the big tech research firm, tracked the share of large employers using digital monitoring tools. In early 2020, it sat around 30 percent. By 2022, it had doubled to roughly 60. And Gartner projected it would keep climbing toward 70 percent within a few years.\n\nIDC, another major research outfit, ran their own survey in mid-2022. They focused specifically on North American companies with 500 or more employees. The result: 67.6 percent were running monitoring software.\n\nThen ExpressVPN, the VPN company, polled employers and workers separately. Their number was higher — 78 percent of bosses said they used some form of online tracking. Now, that one was an opt-in internet survey, not a randomised sample, so take it with a grain of salt. But even the most conservative estimates land around 60 percent.\n\nAnd \"monitoring\" covers a lot of ground here. Some companies just log which websites and apps you use. Others record every keystroke. Others take periodic screenshots of your desktop, track your GPS location, or use biometrics like facial recognition for time clocks. Some do all of the above.\n\nExpressVPN also surveyed workers directly. The majority reported increased stress and anxiety. Nearly half said they'd consider quitting if their employer ramped up surveillance. And a significant number said they didn't even know they were being tracked until they found the software themselves — their employer never mentioned it. Which sounds super ethical.\n\n## From Punch Clocks to Bossware\n\nSo bosses watching workers — that's not exactly new.\n\nBack in the early 1900s, a guy named Frederick Winslow Taylor made a career out of standing behind factory workers with a stopwatch. He'd time every movement. How long it took to pick up a tool, turn a bolt, walk to the next station.\n\nHis whole thing was breaking jobs into tiny measurable steps and then squeezing out anything he considered wasted time. They called it \"scientific management.\" Workers didn't call it that.\n\nBy the mid-20th century, call centres were recording phone calls and timing how long each agent spent per customer. Factories installed CCTV. Warehouses used punch clocks that logged you to the minute.\n\nThen the 1990s hit and everyone got email. Almost immediately, companies started scanning it. Web monitoring software followed — tracking which sites employees visited and for how long. By the 2000s, keystroke loggers, screen capture tools, and electronic badge tracking were spreading across offices, especially in finance and government.\n\nBut here's where it accelerates. In 2021, the EU's Joint Research Centre published a massive review of 398 studies on workplace monitoring. Their finding: the technology had moved beyond just tracking what workers do and where they go. It was now targeting, in their words, \"thoughts, feelings and physiology.\" Mood detection. Attention scoring. Stress indicators through wearables.\n\nAnd then March 2020 happened. Millions of people started working from their kitchen tables overnight. And employers panicked. Sales of monitoring software spiked. Webcam tools, keystroke trackers, screenshot grabbers — all marketed as the solution to managing a workforce you could no longer physically see.\n\nThat's when the Electronic Frontier Foundation, the digital rights group, gave it a name: \"Bossware.\" Software that sits on your device and captures whatever your employer tells it to.\n\n## How Bossware Actually Works\n\nSo how does this stuff actually work?\n\nMost bossware runs as a small program on your laptop or phone. Once it's installed, it sits in the background and logs what you do. Which apps you open. Which websites you visit. How long you spend on each one. Whether your keyboard and mouse are active or idle, and for exactly how many minutes.\n\nThat's the basic layer.\n\nYour employer sees a timeline of your day broken into \"productive\" and \"unproductive\" blocks, colour-coded on a dashboard. Checked LinkedIn for six minutes at 2pm? Logged. Opened Spotify? Logged. Sat still for ten minutes while you read a printed document at your desk? That shows up as \"idle time.\"\n\nThen there's keystroke logging. Some of these tools record every single key you press. Every email you type. Every Slack message — including the ones you delete before sending. Even every password you enter. The EFF flagged this back in 2020: several major vendors advertise full keystroke capture as a feature. They market it as \"insider threat detection\" or \"data loss prevention.\" But the software doesn't know the difference between a confidential client email and your bank password. It just records everything.\n\nScreen capture goes a step further. Tools like Time Doctor take screenshots of your desktop at set intervals — every few minutes, sometimes more often. Some offer continuous screen recording. Your manager can scroll through your day frame by frame.\n\nAll of this data feeds into dashboards. Managers get charts, graphs, risk scores, and productivity rankings — sometimes updated in real time. Individual workers get rated, compared to their team, and flagged if they fall below whatever threshold the company sets.\n\nNot every employer switches on every feature. Some only track app usage. Others go the full distance. The point is that these tools can do all of this, and the person being monitored usually has no way of knowing which settings are turned on.\n\n## The Webcam is Watching\n\nSo that's keystrokes and screenshots. Now let's talk about cameras.\n\nIn 2020, the EFF reviewed the feature lists of major monitoring vendors. Two products stood out: StaffCop Enterprise and CleverControl. Both advertised the ability to silently activate a worker's webcam and microphone. No notification. No light. The software just turns your camera on, captures what it sees, and sends it back to the employer.\n\nAnd those aren't the only ones.\n\nA tool called Sneek launched during the early pandemic as a way to keep remote teams \"connected.\" Here's how it worked: every few minutes, it snapped a photo through each employee's webcam and posted it to a shared screen — a live grid of faces. The company marketed it as building \"human contact\" for distributed teams. Business Insider covered it in March 2020. The interface looked like a wall of CCTV monitors — except every camera was inside someone's home.\n\nOther tools take a slightly different approach. Instead of a constant feed, they snap random webcam photos alongside desktop screenshots. The idea is to verify that the right person is sitting at the keyboard. If your face doesn't match, or nobody's there, it gets flagged.\n\nNow think about where these cameras are pointing. In a call centre, the webcam shows a desk in a shared office. At home, it shows your kitchen. Your living room. Your kids walking past in their pyjamas. Your partner in the background.\n\nSome employers say they only activate webcams during clocked-in hours. Others have pushed for always-on camera access throughout the working day. And since most of these tools run silently, the worker often has no way to confirm which policy is actually in effect.\n\n## And Then There Are the Other Ways of Watching\n\nA company called Hubstaff sells GPS time-tracking software aimed at businesses with mobile workers — delivery drivers, field technicians, cleaning crews. The app runs on the worker's phone and logs their location, route, and timestamps throughout the shift. Managers can set up \"geofences,\" virtual boundaries around job sites. If a worker leaves the zone or takes a route the system doesn't expect, it flags it. Hubstaff markets this as payroll accuracy and safety compliance.\n\nThen there's biometrics. Fingerprint scanners and facial recognition cameras are replacing old-fashioned swipe cards at warehouse doors and factory entrances. The pitch is simple: you can't buddy-punch a fingerprint. One ExpressVPN survey reported that around 67 percent of employers now use some biometric method for timekeeping or access control. That number comes with the same methodology caveats as their other surveys, but the direction is clear. Biometrics are spreading fast.\n\nThe US Government Accountability Office published a taxonomy of workplace surveillance tools in 2024. The list included cameras, microphones, GPS trackers, badge systems, vehicle telematics, and wearables — wristbands and body-mounted sensors that can track movement speed, heart rate, and physical location inside a building down to the aisle. Because your employer should know your heartbeat?\n\nSome of these tools have genuine safety applications. GPS tracking on a lone worker in a remote area can be the difference between a quick rescue and a long search. But the same GPS app that protects a field engineer at 2pm also logs where they stopped for lunch and how long they sat in their car.\n\nA handful of US states, including Illinois, Texas, and Washington, have passed biometric privacy laws requiring employers to get consent before collecting fingerprints or face scans. Enforcement has been uneven — but the lawsuits are piling up.\n\n## Case Study: Teleperformance and the AI Webcam\n\nSo let's look at a specific company.\n\nTeleperformance is one of the largest call-centre operators on the planet. Headquartered in France, operating in dozens of countries, employing hundreds of thousands of people — many of them working from home since 2020.\n\nIn March 2021, the Guardian reported that Teleperformance had told some of its home-based staff to expect AI-powered webcam monitoring. The system would watch for what the company called \"infractions.\" Eating at your desk. Looking at your phone. Leaving your workstation. The camera would flag these behaviours automatically.\n\nPrivacy International picked up the story the same day. Their summary added more detail: workers in certain countries outside the UK were told that AI webcams would be installed in their homes to detect rule violations in real time. Keyboard and mouse activity would be tracked, and idle periods would trigger alerts to managers.\n\nUnions pushed back hard. The UNI Global Union accused Teleperformance of crossing a line — collecting biometric data, monitoring workers inside their own homes, and creating conditions where people felt they couldn't step away from their screens without being penalised. The Business and Human Rights Resource Centre documented these complaints in August 2021, noting allegations that the company had also gathered medical information from some workers.\n\nTeleperformance responded publicly. The company said it complied with GDPR and all applicable local laws. It said webcams were used primarily for collaboration and data protection, not punitive monitoring. And it pointed to internal surveys showing that staff feedback on remote working arrangements was largely positive.\n\nAfter the media coverage and union pressure, the company appeared to scale back some of the more visible monitoring — at least in the UK. What changed in other countries is harder to pin down.\n\n## Amazon's Productivity Machine\n\nSo Teleperformance was cameras in the home. Pretty bad, in our opinion.\n\nAmazon is something else.\n\nAmazon built the system that turns productivity data into automatic consequences — warnings, discipline, and sometimes termination, with minimal human involvement.\n\nIn April 2019, The Verge obtained internal documents through a Freedom of Information request. They came from a labour dispute filed with the National Labor Relations Board. In a signed letter, an Amazon attorney described how the company's tracking system worked. Every warehouse employee carries a handheld scanner. The system logs each scan, measures the time between scans, and tracks something Amazon calls \"time off task\" — TOT. If a worker stops scanning for too long, the system generates a warning. If the pattern continues, it generates a termination notice. The attorney's exact words: the system \"automatically generates any warnings or terminations regarding quality or productivity without input from supervisors.\"\n\nThe same letter revealed that at a single Baltimore warehouse, Amazon had fired hundreds of workers between August 2017 and September 2018 for failing to meet productivity rates. Around 300 people at one facility in roughly one year. That was about 10 percent of the site's workforce.\n\nAmazon pushed back, of course. A spokesperson said it was \"absolutely not true\" that employees are terminated by an automated system alone, and that managers can intervene. But the documents showed the system was designed to operate without that input as a default.\n\nThen, in January 2024, French data-protection authority CNIL announced it had fined Amazon France Logistique €32 million. CNIL's investigators found that the scanner system tracked workers down to the second. It flagged any pause longer than ten minutes. It flagged pauses under ten minutes. It even flagged items scanned less than 1.25 seconds apart — too fast, in the regulator's view, to have properly checked the product. CNIL's ruling was blunt: the system \"potentially required employees to justify every break or interruption.\" Amazon said the findings were \"factually incorrect\" and appealed. In December 2025, a French court reduced the fine to €15 million and overturned some of the findings.\n\nMeanwhile in California, the state had passed a law in 2021 called AB 701, specifically targeting undisclosed warehouse quotas. In 2024, the California Labor Commissioner's Office fined Amazon $5.9 million after investigating two warehouses in Riverside and San Bernardino counties. The investigators found 59,017 violations over a six-month period. The core issue: Amazon hadn't given workers written notice of the productivity targets they were expected to hit, or the consequences of missing them.\n\nUnions and labour researchers have long argued that these kinds of quota systems drive injury rates up. OSHA data analysed by the Strategic Organizing Center found that in 2022, Amazon's serious injury rate was 6.6 per 100 workers. At non-Amazon warehouses, it was 3.2. Amazon accounted for over half of all serious injuries in the warehousing industry that year, while employing about a third of its workers. Amazon has said it plans to invest hundreds of millions in safety initiatives and that injury rates have been improving.\n\n## How Common is All This?\n\nSo we covered the headline numbers earlier. Roughly 60 to 70 percent of large employers, depending on the survey. But those numbers deserve a closer look — because the story underneath them is a bit messier than you might think.\n\nStart with who's doing the asking. The IDC figure came from a survey of North American companies with 500 or more employees. That's a specific slice: big firms, one continent. The ExpressVPN numbers, which run higher at around 78 percent, came from an opt-in online panel. People who volunteer for internet surveys aren't a random sample of all employers. And Gartner's projections are exactly that — projections, based on their own client data and modelling.\n\nThe US Government Accountability Office flagged this gap directly in its 2024 report. No federal agency systematically tracks how many employers use digital surveillance tools, what kinds they deploy, or how intensively they use them. The data we have comes from a patchwork of vendor-funded research, academic surveys, and regulator investigations. And that is useful — but it's not really that precise.\n\nThen there's the disclosure problem. ExpressVPN's survey found that a significant number of employers said they might not inform staff when new monitoring tools are rolled in. The GAO noted similar concerns: workers often don't know what's being collected until something goes wrong. So when surveys ask employees whether they're monitored, the real number could be higher than what gets reported, because some people genuinely don't know.\n\nAnd \"monitoring\" itself covers an enormous range. One company might log which applications are open during work hours — basically an IT security measure. Another might be recording every keystroke, taking webcam photos, and scoring each employee's productivity minute by minute. Both count as \"monitoring\" in these surveys. They're definitely not the same thing though.\n\nWhat is consistent across every source — the GAO, the ICO, Gartner, the academic reviews — is that adoption is climbing, not falling. More tools, more employers, more data being collected.\n\n## What Surveillance Does to People\n\nSo that's the technology and the numbers. Now: what does all of this actually do to the people on the other end of it?\n\nIn 2024, sociologist Paul Glavin at McMaster University in Canada ran a national survey of workers. He wasn't asking about one company or one tool. He wanted to know whether the perception of being surveilled at work, across industries, correlated with measurable psychological outcomes. It did. Workers who reported higher levels of perceived surveillance also reported more psychological distress and lower job satisfaction. Surprising, we know.\n\nGlavin's model traced the pathway: surveillance increased job pressure, reduced workers' sense of autonomy, and made them feel their privacy had been violated. Those three stressors, in turn, drove the distress. One national sample, one country — but the pattern was really rather clear.\n\nThe EU's Joint Research Centre found something similar across a much wider evidence base. Their 2021 review of 398 studies linked excessive monitoring to increased stress, lower commitment to the organisation, higher intentions to quit, and what researchers call \"resistance behaviours\" — people finding ways to game or avoid the system rather than engage with it.\n\nThe GAO's 2025 report added a physical dimension. Stakeholders told the GAO that productivity metrics push workers to move faster, skip breaks, and avoid reporting injuries for fear of falling behind on their scores. The same report flagged another problem: emotional AI tools that try to gauge worker mood or attentiveness through facial analysis or voice tone. The GAO noted concerns that these systems misidentify people, particularly workers of colour and those with accents, as negative or non-compliant. A false reading from one of those tools could affect scheduling, performance reviews, or disciplinary action.\n\nExpressVPN's worker surveys backed up the behavioural side. A majority of monitored employees said they took fewer breaks. Nearly half said they'd consider quitting, or even accepting a pay cut, to work somewhere with less surveillance.\n\n## What is Actually Allowed?\n\nAlright then, big question: is any of this actually legal?\n\nIn the United States, the short answer is: mostly, yes. The Electronic Communications Privacy Act, passed in 1986, and the Stored Communications Act both allow employers to monitor activity on company-provided systems as long as it happens in the \"ordinary course of business.\" That phrase does a lot of heavy lifting. In practice, it means that if you're using a company laptop, company email, or company network, almost everything you do on those systems is fair game.\n\nBrookings highlighted a case that shows how far this can go. A woman named Rene worked at a store where her employer had installed keylogger software on the company computers. Nobody told her. She used that computer to check her personal email and her bank account. The keylogger captured her passwords. Another employee used those passwords to access her private accounts and read through her emails and financial records. When Rene found out and confronted her colleagues, she was fired for \"poor performance.\" The federal court ruled that the keylogger itself didn't violate the Federal Wiretap Act. Her claim under the Stored Communications Act, for the actual use of her passwords to read her private accounts, survived — but the keylogger capture was arguably legal because it happened on a company system.\n\nA handful of states have added notice requirements on top of federal law. Connecticut passed one in 1998. Delaware followed in 2001. New York's took effect in May 2022 — requiring every private-sector employer to give written notice to new hires if it monitors phone calls, email, or internet usage. Penalties for non-compliance in New York range from $500 to $3,000 per offence. But notice requirements only mean your employer has to tell you they're watching. They don't limit what they can watch.\n\nIn Europe, the picture is different. Under GDPR, any monitoring has to be necessary, proportionate, and limited to a specific purpose. The EU's Article 29 Working Party, which advises on data protection, issued an opinion in 2017 saying that employee consent to monitoring is usually not valid — because the power imbalance between employer and worker means it's not freely given. Employers are expected to use the least intrusive method available and to justify why alternatives wouldn't work.\n\nThe UK's Information Commissioner's Office landed somewhere in between. Its 2023 guidance tells employers to be transparent, conduct impact assessments before rolling out monitoring, and avoid anything disproportionate. But \"disproportionate\" isn't defined by a hard line — it's a judgement call, reviewed case by case.\n\n## The Illusion of Choice\n\nSo here's a question worth sitting with. When your employer asks you to install monitoring software on your laptop, and the alternative is losing your job, do you consent?\n\nThe EU's Article 29 Working Party addressed this directly in 2017. Their opinion was straightforward. In an employment relationship, consent is almost never valid as a legal basis for data collection. The reason: workers depend on their employer for income. That dependency creates a power imbalance. If saying \"no\" means risking your livelihood, then saying \"yes\" doesn't mean much. The Working Party told employers to stop relying on consent altogether and instead justify any monitoring through necessity and proportionality.\n\nGo back to the Teleperformance case. Unions alleged that home-based workers were told to accept AI webcams in their houses. The company said participation was voluntary and pointed to positive staff survey results. But the UNI Global Union argued that workers in countries with weak labour protections felt they had no real option to refuse. When your contract renewal depends on cooperation, \"voluntary\" isn't really voluntary, is it? Allegedly.\n\nThen there's the problem the EU's Joint Research Centre calls \"function creep.\" Their 2021 review found a recurring pattern across industries. An employer introduces monitoring for one stated purpose — security, say, or health and safety training. Over time, that same data quietly migrates into performance management, disciplinary processes, or scheduling decisions. Workers who originally agreed to a safety check find their break times being scored. The JRC flagged this as one of the most common ways trust breaks down between employers and staff: data collected under one justification gets repurposed without fresh notice or consultation.\n\nAnd in most US jurisdictions, none of this requires consent at all. If it's a company device on a company network, the employer doesn't need to ask.\n\n## When Surveillance Backfires\n\nSo the tools are supposed to make workers more productive. But the GAO's 2025 report flagged a problem with that assumption: the metrics often can't tell the difference between working and looking like you're working.\n\nMost monitoring software measures activity. Keystrokes, mouse movements, apps open, time between actions. What it can't measure is thinking. Reading a printed document. Mentoring a colleague. Sketching out a plan on paper. Staring at a whiteboard.\n\nThe GAO noted that workers whose jobs involve research, problem-solving, or collaboration routinely show up as \"idle\" or \"unproductive\" on dashboards — even when they're doing exactly what they were hired to do. And because managers sometimes treat those dashboards as gospel, the result is reprimands, lower performance ratings, or worse, aimed at people whose only offence was doing work the software couldn't see.\n\nAnd then there's what happens when workers figure out the system is watching.\n\nExpressVPN's surveys found that a significant proportion of monitored employees had adopted countermeasures. Mouse-jigglers — small devices or software scripts that simulate cursor movement so the dashboard never shows \"idle.\" Pre-scheduled emails sent at strategic times to create the appearance of late-night productivity. Tabs left open on work-related sites while the person does something else entirely.\n\nThe GAO's term for this dynamic was more clinical. They warned that employers risk placing \"too much trust\" in automated outputs, treating them as objective when the underlying data is incomplete or biased. Microsoft's own research coined a punchier label: \"productivity paranoia.\" Managers convinced their teams aren't working hard enough. Workers convinced they're being watched too closely. Both sides responding to the tools rather than to each other. Both sides having a bad time.\n\n## The Pushback\n\nSo far this has been mostly about what's happening to workers. But there's a counter-story building — and it's coming from multiple directions at once.\n\nIn the US Senate, Senators Bob Casey, Cory Booker, and Brian Schatz introduced the Stop Spying Bosses Act in February 2023. A companion version was introduced in the House in March 2024 by Representatives Chris Deluzio and Suzanne Bonamici. The bill would apply to any employer with more than ten workers. It would require them to publicly disclose what surveillance they conduct, what data they collect, and how that data is used in performance assessments or employment decisions. It would ban monitoring of workers who are off duty, in sensitive areas like bathrooms and break rooms, or engaged in union activity. And it would restrict the use of automated systems to make employment decisions without human oversight.\n\nThe bill didn't pass. It expired with the 118th Congress. But it established a framework that labour groups and advocacy organisations are still pushing.\n\nCalifornia tried to go further. AB 1331, introduced in the 2025 session by Assembly member Elhawary, would have banned employers from using surveillance tools in employee-only areas like break rooms, changing rooms, and lounges. Workers would have had the right to leave monitoring devices behind during off-duty time, including meal breaks. The California Labor Federation backed it. The Chamber of Commerce fought it, arguing the language was too broad and would undermine workplace safety. In September 2025, the bill was moved to the inactive file in the state Senate — so effectively shelved.\n\nNone of these efforts have produced a comprehensive federal law in the US. No single regulator has been given the job of tracking how many employers surveil their workers or how intensively. But the proposals keep coming, the fines keep landing, and the unions keep on pushing.\n\n## Drawing the Line\n\nSo where does that leave you?\n\nIf you're working on a company laptop, company phone, or company network, assume it's being logged. That's really just the baseline reality across most industries in most countries right now. The safest move is to keep personal accounts, personal messages, and personal browsing on your own devices. Don't check your bank account on your work computer. Don't draft personal emails in your company inbox.\n\nBeyond that, ask questions. Ask HR what monitoring tools are in use. Ask what data is being collected, who can see it, and how long it's kept. In the EU and UK, your employer may be legally required to conduct a data-protection impact assessment before deploying monitoring. You can ask for it. In the US, a few states require written notice.\n\nIf something feels wrong — if you're being penalised for metrics you can't see, or monitored in ways that seem disproportionate — talk to a union rep, a privacy regulator, or an employment lawyer before trying to fight it alone.\n\nOne last thing. If anyone's thinking, after learning about it today, of using consumer-grade monitoring software to covertly track a partner, a housemate, or anyone else: don't. In many jurisdictions, that's a criminal offence.\n\n## Key Takeaways\n\n- 60-70% of medium to large employers now use digital monitoring tools, roughly doubling since 2020.\n- Bossware can silently activate webcams, log every keystroke including passwords, and capture periodic screenshots.\n- Amazon's warehouse scanner system automatically generated warnings and terminations without supervisor input.\n- Surveillance correlates with increased worker stress, lower job satisfaction, and higher intentions to quit.\n- US federal law largely permits employer monitoring on company systems; Europe's GDPR requires proportionality and necessity.\n\n## Frequently Asked Questions\n\n### What is 'bossware' and what does it do?\n\nBossware is a category of software that sits quietly on an employee's device, logs everything they do, and sends that data back to a dashboard where managers can see employee productivity. Some tools can activate webcams without telling users, record every keystroke including passwords, take photos of faces every few minutes to verify identity, capture screenshots, track GPS location, and use biometrics like facial recognition.\n\n### How common is workplace digital monitoring among medium to large employers?\n\nSurveys suggest that somewhere between 60 and 70 percent of medium to large employers now use some form of digital monitoring on their workers. Gartner tracked this at around 30 percent in early 2020, doubling to roughly 60 percent by 2022, with projections toward 70 percent. IDC's 2022 survey of North American companies with 500+ employees found 67.6 percent running monitoring software. ExpressVPN's survey found 78 percent of bosses said they used some form of online tracking, though this was an opt-in internet survey.\n\n### What happened with Teleperformance and AI webcam monitoring?\n\nIn March 2021, the Guardian reported that Teleperformance, one of the largest call-centre operators globally, told some home-based staff to expect AI-powered webcam monitoring that would watch for 'infractions' like eating at your desk, looking at your phone, or leaving your workstation. Privacy International added that workers in certain countries outside the UK were told AI webcams would be installed in their homes to detect rule violations in real time, with keyboard and mouse activity tracked and idle periods triggering alerts to managers. Unions pushed back, and after media coverage and union pressure, the company appeared to scale back some visible monitoring at least in the UK.\n\n### How does Amazon's warehouse productivity tracking system work?\n\nAmazon's system uses handheld scanners that log each scan, measure time between scans, and track 'time off task' (TOT). If a worker stops scanning for too long, the system generates a warning; if the pattern continues, it generates a termination notice. Internal documents obtained by The Verge in 2019 revealed that at a single Baltimore warehouse, Amazon fired around 300 workers between August 2017 and September 2018 for failing to meet productivity rates—about 10 percent of that facility's workforce. In 2024, French regulator CNIL fined Amazon France Logistique €32 million (later reduced to €15 million on appeal) for a system that tracked workers down to the second and flagged pauses under ten minutes.\n\n### What psychological effects does workplace surveillance have on employees?\n\nA 2024 national survey by sociologist Paul Glavin at McMaster University found that workers who reported higher levels of perceived surveillance also reported more psychological distress and lower job satisfaction. Surveillance increased job pressure, reduced workers' sense of autonomy, and made them feel their privacy had been violated. The EU's Joint Research Centre's 2021 review of 398 studies linked excessive monitoring to increased stress, lower commitment to the organisation, higher intentions to quit, and 'resistance behaviours' where workers find ways to game or avoid the system. ExpressVPN surveys found a majority of monitored employees took fewer breaks, and nearly half would consider quitting or accepting a pay cut to work somewhere with less surveillance.\n\n### Is workplace monitoring legal in the United States?\n\nIn the United States, workplace monitoring is mostly legal. The Electronic Communications Privacy Act of 1986 and the Stored Communications Act allow employers to monitor activity on company-provided systems as long as it happens in the 'ordinary course of business.' A federal court ruled that keylogger software capturing passwords on a company computer didn't violate the Federal Wiretap Act. A few states have added notice requirements: Connecticut (1998), Delaware (2001), and New York (2022), which requires written notice to new hires about monitoring of phone calls, email, or internet usage. However, notice requirements only mean employers must tell you they're watching—they don't limit what they can watch.\n\n### How does European law differ from US law on workplace monitoring?\n\nUnder GDPR, any monitoring must be necessary, proportionate, and limited to a specific purpose. The EU's Article 29 Working Party stated in 2017 that employee consent to monitoring is usually not valid because the power imbalance between employer and worker means it's not freely given. Employers must use the least intrusive method available and justify why alternatives wouldn't work. The UK's Information Commissioner's Office 2023 guidance tells employers to be transparent, conduct impact assessments before rolling out monitoring, and avoid anything disproportionate. This contrasts with the US where the 'ordinary course of business' standard allows broad monitoring on company systems.\n\n### What is 'productivity paranoia' and how does surveillance backfire?\n\nMicrosoft's research coined the term 'productivity paranoia' to describe a dynamic where managers become convinced their teams aren't working hard enough, while workers become convinced they're being watched too closely, with both sides responding to the tools rather than to each other. The GAO's 2025 report noted that monitoring software measures activity (keystrokes, mouse movements, apps open) but cannot measure thinking, reading printed documents, mentoring colleagues, or collaborative work—so workers doing exactly what they were hired to do may show up as 'idle' or 'unproductive.' Workers also adopt countermeasures like mouse-jigglers, pre-scheduled emails, and leaving work-related tabs open while doing other things.\n\n### What legislative efforts have been made to restrict workplace surveillance in the US?\n\nIn February 2023, Senators Bob Casey, Cory Booker, and Brian Schatz introduced the Stop Spying Bosses Act, with a House companion in March 2024. It would require employers with 10+ workers to publicly disclose surveillance, data collection, and how data is used in employment decisions; ban monitoring of off-duty workers, in bathrooms and break rooms, or during union activity; and restrict automated employment decisions without human oversight. The bill expired with the 118th Congress. California's AB 1331 (2025) would have banned surveillance in employee-only areas and allowed workers to leave monitoring devices behind during breaks, but was shelved in September 2025.\n\n### What practical advice does the article give to workers concerned about monitoring?\n\nThe article advises: assume any company laptop, phone, or network is being logged; keep personal accounts, messages, and browsing on your own devices; don't check bank accounts or draft personal emails on work computers; ask HR what monitoring tools are in use, what data is collected, who can see it, and how long it's kept; in the EU and UK, ask for the data-protection impact assessment employers may be legally required to conduct; in the US, a few states require written notice; and if something feels wrong—being penalized for unseen metrics or disproportionate monitoring—talk to a union rep, privacy regulator, or employment lawyer before fighting it alone.\n\n## Sources\n\n- [Original Scandal video: How Companies Spy on Their Employees](https://www.youtube.com/watch?v=nFJxM3Vc-Cw)\n- [Hero image source](https://images.rawpixel.com/editor_1024/czNmcy1wcml2YXRlL3Jhd3BpeGVsX2ltYWdlcy93ZWJzaXRlX2NvbnRlbnQvbHIvcHg4Mzk4NzMtaW1hZ2Uta3d2eGV0bTYuanBn.jpg) by openverse, cc0.\n\n## Related Coverage"
url: https://scandal.pub/article/how-companies-spy-on-their-employees.md
canonical: https://scandal.pub/article/how-companies-spy-on-their-employees
datePublished: 2026-06-26
dateModified: 2026-06-26
author:
  - name: Scandal Editorial
    url: https://scandal.pub
publisher: Scandal
image: "https://media.scandal.pub/cdn-cgi/image/width=1200,height=675,fit=cover,quality=80,format=auto/articles/nFJxM3Vc-Cw/hero.jpg"
type: NewsArticle
contentHash: b1355b020535c63bdfdd4373db71fd36e3e5946802013af59c1a437ba3aad68d
tokens: 9623
summaryUrl: https://scandal.pub/article/how-companies-spy-on-their-employees.md.summary.md
---

<!-- aeo:section start="lede" -->
So here's something fun to think about. If you're reading this on a work laptop, your employer might be watching you right now. Not metaphorically. Not in some vague, "oh they can probably see my browser history" kind of way. Actually watching you. Like from your webcam. So maybe get back to work and stop procrastinating? (Just joking — you're probably fine. Please don't leave).

There's a category of software that digital rights groups have started calling "bossware." It sits quietly on your device, logs everything you do, and sends all of that data back to a dashboard where your manager can see exactly how "productive" you've been — down to the minute.

Some of these tools can activate your webcam without telling you. Some record every single key you press, including passwords. Some take a photo of your face every few minutes just to make sure you're the one sitting there.

This isn't fringe. This isn't some dystopian pilot programme at one weird company. Surveys suggest that somewhere between 60 and 70 percent of medium to large employers now use some form of digital monitoring on their workers. That number has roughly doubled since the start of 2020. And it's still climbing.

Employers will tell you this is about security. Compliance. Protecting company data. And sure, sometimes it is. But when the software can see what you're typing in a private message, or flag you for getting up to make a cup of tea, or quietly score your worth based on how often you wiggle your mouse — is that really still about security?

In this article, we're opening up the black box of workplace monitoring. How it works. How far it goes. What it does to people. And what happens when your boss stops managing you and starts watching you.

<!-- aeo:section end="lede" -->
<!-- aeo:section start="the-scale-of-the-watching" -->
## The Scale of the Watching

So let's break those numbers down.

The 60 to 70 percent figure comes from a few different places. Gartner, the big tech research firm, tracked the share of large employers using digital monitoring tools. In early 2020, it sat around 30 percent. By 2022, it had doubled to roughly 60. And Gartner projected it would keep climbing toward 70 percent within a few years.

IDC, another major research outfit, ran their own survey in mid-2022. They focused specifically on North American companies with 500 or more employees. The result: 67.6 percent were running monitoring software.

Then ExpressVPN, the VPN company, polled employers and workers separately. Their number was higher — 78 percent of bosses said they used some form of online tracking. Now, that one was an opt-in internet survey, not a randomised sample, so take it with a grain of salt. But even the most conservative estimates land around 60 percent.

And "monitoring" covers a lot of ground here. Some companies just log which websites and apps you use. Others record every keystroke. Others take periodic screenshots of your desktop, track your GPS location, or use biometrics like facial recognition for time clocks. Some do all of the above.

ExpressVPN also surveyed workers directly. The majority reported increased stress and anxiety. Nearly half said they'd consider quitting if their employer ramped up surveillance. And a significant number said they didn't even know they were being tracked until they found the software themselves — their employer never mentioned it. Which sounds super ethical.

<!-- aeo:section end="the-scale-of-the-watching" -->
<!-- aeo:section start="from-punch-clocks-to-bossware" -->
## From Punch Clocks to Bossware

So bosses watching workers — that's not exactly new.

Back in the early 1900s, a guy named Frederick Winslow Taylor made a career out of standing behind factory workers with a stopwatch. He'd time every movement. How long it took to pick up a tool, turn a bolt, walk to the next station.

His whole thing was breaking jobs into tiny measurable steps and then squeezing out anything he considered wasted time. They called it "scientific management." Workers didn't call it that.

By the mid-20th century, call centres were recording phone calls and timing how long each agent spent per customer. Factories installed CCTV. Warehouses used punch clocks that logged you to the minute.

Then the 1990s hit and everyone got email. Almost immediately, companies started scanning it. Web monitoring software followed — tracking which sites employees visited and for how long. By the 2000s, keystroke loggers, screen capture tools, and electronic badge tracking were spreading across offices, especially in finance and government.

But here's where it accelerates. In 2021, the EU's Joint Research Centre published a massive review of 398 studies on workplace monitoring. Their finding: the technology had moved beyond just tracking what workers do and where they go. It was now targeting, in their words, "thoughts, feelings and physiology." Mood detection. Attention scoring. Stress indicators through wearables.

And then March 2020 happened. Millions of people started working from their kitchen tables overnight. And employers panicked. Sales of monitoring software spiked. Webcam tools, keystroke trackers, screenshot grabbers — all marketed as the solution to managing a workforce you could no longer physically see.

That's when the Electronic Frontier Foundation, the digital rights group, gave it a name: "Bossware." Software that sits on your device and captures whatever your employer tells it to.

<!-- aeo:section end="from-punch-clocks-to-bossware" -->
<!-- aeo:section start="how-bossware-actually-works" -->
## How Bossware Actually Works

So how does this stuff actually work?

Most bossware runs as a small program on your laptop or phone. Once it's installed, it sits in the background and logs what you do. Which apps you open. Which websites you visit. How long you spend on each one. Whether your keyboard and mouse are active or idle, and for exactly how many minutes.

That's the basic layer.

Your employer sees a timeline of your day broken into "productive" and "unproductive" blocks, colour-coded on a dashboard. Checked LinkedIn for six minutes at 2pm? Logged. Opened Spotify? Logged. Sat still for ten minutes while you read a printed document at your desk? That shows up as "idle time."

Then there's keystroke logging. Some of these tools record every single key you press. Every email you type. Every Slack message — including the ones you delete before sending. Even every password you enter. The EFF flagged this back in 2020: several major vendors advertise full keystroke capture as a feature. They market it as "insider threat detection" or "data loss prevention." But the software doesn't know the difference between a confidential client email and your bank password. It just records everything.

Screen capture goes a step further. Tools like Time Doctor take screenshots of your desktop at set intervals — every few minutes, sometimes more often. Some offer continuous screen recording. Your manager can scroll through your day frame by frame.

All of this data feeds into dashboards. Managers get charts, graphs, risk scores, and productivity rankings — sometimes updated in real time. Individual workers get rated, compared to their team, and flagged if they fall below whatever threshold the company sets.

Not every employer switches on every feature. Some only track app usage. Others go the full distance. The point is that these tools can do all of this, and the person being monitored usually has no way of knowing which settings are turned on.

<!-- aeo:section end="how-bossware-actually-works" -->
<!-- aeo:section start="the-webcam-is-watching" -->
## The Webcam is Watching

So that's keystrokes and screenshots. Now let's talk about cameras.

In 2020, the EFF reviewed the feature lists of major monitoring vendors. Two products stood out: StaffCop Enterprise and CleverControl. Both advertised the ability to silently activate a worker's webcam and microphone. No notification. No light. The software just turns your camera on, captures what it sees, and sends it back to the employer.

And those aren't the only ones.

A tool called Sneek launched during the early pandemic as a way to keep remote teams "connected." Here's how it worked: every few minutes, it snapped a photo through each employee's webcam and posted it to a shared screen — a live grid of faces. The company marketed it as building "human contact" for distributed teams. Business Insider covered it in March 2020. The interface looked like a wall of CCTV monitors — except every camera was inside someone's home.

Other tools take a slightly different approach. Instead of a constant feed, they snap random webcam photos alongside desktop screenshots. The idea is to verify that the right person is sitting at the keyboard. If your face doesn't match, or nobody's there, it gets flagged.

Now think about where these cameras are pointing. In a call centre, the webcam shows a desk in a shared office. At home, it shows your kitchen. Your living room. Your kids walking past in their pyjamas. Your partner in the background.

Some employers say they only activate webcams during clocked-in hours. Others have pushed for always-on camera access throughout the working day. And since most of these tools run silently, the worker often has no way to confirm which policy is actually in effect.

<!-- aeo:section end="the-webcam-is-watching" -->
<!-- aeo:section start="and-then-there-are-the-other-ways-of-watching" -->
## And Then There Are the Other Ways of Watching

A company called Hubstaff sells GPS time-tracking software aimed at businesses with mobile workers — delivery drivers, field technicians, cleaning crews. The app runs on the worker's phone and logs their location, route, and timestamps throughout the shift. Managers can set up "geofences," virtual boundaries around job sites. If a worker leaves the zone or takes a route the system doesn't expect, it flags it. Hubstaff markets this as payroll accuracy and safety compliance.

Then there's biometrics. Fingerprint scanners and facial recognition cameras are replacing old-fashioned swipe cards at warehouse doors and factory entrances. The pitch is simple: you can't buddy-punch a fingerprint. One ExpressVPN survey reported that around 67 percent of employers now use some biometric method for timekeeping or access control. That number comes with the same methodology caveats as their other surveys, but the direction is clear. Biometrics are spreading fast.

The US Government Accountability Office published a taxonomy of workplace surveillance tools in 2024. The list included cameras, microphones, GPS trackers, badge systems, vehicle telematics, and wearables — wristbands and body-mounted sensors that can track movement speed, heart rate, and physical location inside a building down to the aisle. Because your employer should know your heartbeat?

Some of these tools have genuine safety applications. GPS tracking on a lone worker in a remote area can be the difference between a quick rescue and a long search. But the same GPS app that protects a field engineer at 2pm also logs where they stopped for lunch and how long they sat in their car.

A handful of US states, including Illinois, Texas, and Washington, have passed biometric privacy laws requiring employers to get consent before collecting fingerprints or face scans. Enforcement has been uneven — but the lawsuits are piling up.

<!-- aeo:section end="and-then-there-are-the-other-ways-of-watching" -->
<!-- aeo:section start="case-study-teleperformance-and-the-ai-webcam" -->
## Case Study: Teleperformance and the AI Webcam

So let's look at a specific company.

Teleperformance is one of the largest call-centre operators on the planet. Headquartered in France, operating in dozens of countries, employing hundreds of thousands of people — many of them working from home since 2020.

In March 2021, the Guardian reported that Teleperformance had told some of its home-based staff to expect AI-powered webcam monitoring. The system would watch for what the company called "infractions." Eating at your desk. Looking at your phone. Leaving your workstation. The camera would flag these behaviours automatically.

Privacy International picked up the story the same day. Their summary added more detail: workers in certain countries outside the UK were told that AI webcams would be installed in their homes to detect rule violations in real time. Keyboard and mouse activity would be tracked, and idle periods would trigger alerts to managers.

Unions pushed back hard. The UNI Global Union accused Teleperformance of crossing a line — collecting biometric data, monitoring workers inside their own homes, and creating conditions where people felt they couldn't step away from their screens without being penalised. The Business and Human Rights Resource Centre documented these complaints in August 2021, noting allegations that the company had also gathered medical information from some workers.

Teleperformance responded publicly. The company said it complied with GDPR and all applicable local laws. It said webcams were used primarily for collaboration and data protection, not punitive monitoring. And it pointed to internal surveys showing that staff feedback on remote working arrangements was largely positive.

After the media coverage and union pressure, the company appeared to scale back some of the more visible monitoring — at least in the UK. What changed in other countries is harder to pin down.

<!-- aeo:section end="case-study-teleperformance-and-the-ai-webcam" -->
<!-- aeo:section start="amazon-s-productivity-machine" -->
## Amazon's Productivity Machine

So Teleperformance was cameras in the home. Pretty bad, in our opinion.

Amazon is something else.

Amazon built the system that turns productivity data into automatic consequences — warnings, discipline, and sometimes termination, with minimal human involvement.

In April 2019, The Verge obtained internal documents through a Freedom of Information request. They came from a labour dispute filed with the National Labor Relations Board. In a signed letter, an Amazon attorney described how the company's tracking system worked. Every warehouse employee carries a handheld scanner. The system logs each scan, measures the time between scans, and tracks something Amazon calls "time off task" — TOT. If a worker stops scanning for too long, the system generates a warning. If the pattern continues, it generates a termination notice. The attorney's exact words: the system "automatically generates any warnings or terminations regarding quality or productivity without input from supervisors."

The same letter revealed that at a single Baltimore warehouse, Amazon had fired hundreds of workers between August 2017 and September 2018 for failing to meet productivity rates. Around 300 people at one facility in roughly one year. That was about 10 percent of the site's workforce.

Amazon pushed back, of course. A spokesperson said it was "absolutely not true" that employees are terminated by an automated system alone, and that managers can intervene. But the documents showed the system was designed to operate without that input as a default.

Then, in January 2024, French data-protection authority CNIL announced it had fined Amazon France Logistique €32 million. CNIL's investigators found that the scanner system tracked workers down to the second. It flagged any pause longer than ten minutes. It flagged pauses under ten minutes. It even flagged items scanned less than 1.25 seconds apart — too fast, in the regulator's view, to have properly checked the product. CNIL's ruling was blunt: the system "potentially required employees to justify every break or interruption." Amazon said the findings were "factually incorrect" and appealed. In December 2025, a French court reduced the fine to €15 million and overturned some of the findings.

Meanwhile in California, the state had passed a law in 2021 called AB 701, specifically targeting undisclosed warehouse quotas. In 2024, the California Labor Commissioner's Office fined Amazon $5.9 million after investigating two warehouses in Riverside and San Bernardino counties. The investigators found 59,017 violations over a six-month period. The core issue: Amazon hadn't given workers written notice of the productivity targets they were expected to hit, or the consequences of missing them.

Unions and labour researchers have long argued that these kinds of quota systems drive injury rates up. OSHA data analysed by the Strategic Organizing Center found that in 2022, Amazon's serious injury rate was 6.6 per 100 workers. At non-Amazon warehouses, it was 3.2. Amazon accounted for over half of all serious injuries in the warehousing industry that year, while employing about a third of its workers. Amazon has said it plans to invest hundreds of millions in safety initiatives and that injury rates have been improving.

<!-- aeo:section end="amazon-s-productivity-machine" -->
<!-- aeo:section start="how-common-is-all-this" -->
## How Common is All This?

So we covered the headline numbers earlier. Roughly 60 to 70 percent of large employers, depending on the survey. But those numbers deserve a closer look — because the story underneath them is a bit messier than you might think.

Start with who's doing the asking. The IDC figure came from a survey of North American companies with 500 or more employees. That's a specific slice: big firms, one continent. The ExpressVPN numbers, which run higher at around 78 percent, came from an opt-in online panel. People who volunteer for internet surveys aren't a random sample of all employers. And Gartner's projections are exactly that — projections, based on their own client data and modelling.

The US Government Accountability Office flagged this gap directly in its 2024 report. No federal agency systematically tracks how many employers use digital surveillance tools, what kinds they deploy, or how intensively they use them. The data we have comes from a patchwork of vendor-funded research, academic surveys, and regulator investigations. And that is useful — but it's not really that precise.

Then there's the disclosure problem. ExpressVPN's survey found that a significant number of employers said they might not inform staff when new monitoring tools are rolled in. The GAO noted similar concerns: workers often don't know what's being collected until something goes wrong. So when surveys ask employees whether they're monitored, the real number could be higher than what gets reported, because some people genuinely don't know.

And "monitoring" itself covers an enormous range. One company might log which applications are open during work hours — basically an IT security measure. Another might be recording every keystroke, taking webcam photos, and scoring each employee's productivity minute by minute. Both count as "monitoring" in these surveys. They're definitely not the same thing though.

What is consistent across every source — the GAO, the ICO, Gartner, the academic reviews — is that adoption is climbing, not falling. More tools, more employers, more data being collected.

<!-- aeo:section end="how-common-is-all-this" -->
<!-- aeo:section start="what-surveillance-does-to-people" -->
## What Surveillance Does to People

So that's the technology and the numbers. Now: what does all of this actually do to the people on the other end of it?

In 2024, sociologist Paul Glavin at McMaster University in Canada ran a national survey of workers. He wasn't asking about one company or one tool. He wanted to know whether the perception of being surveilled at work, across industries, correlated with measurable psychological outcomes. It did. Workers who reported higher levels of perceived surveillance also reported more psychological distress and lower job satisfaction. Surprising, we know.

Glavin's model traced the pathway: surveillance increased job pressure, reduced workers' sense of autonomy, and made them feel their privacy had been violated. Those three stressors, in turn, drove the distress. One national sample, one country — but the pattern was really rather clear.

The EU's Joint Research Centre found something similar across a much wider evidence base. Their 2021 review of 398 studies linked excessive monitoring to increased stress, lower commitment to the organisation, higher intentions to quit, and what researchers call "resistance behaviours" — people finding ways to game or avoid the system rather than engage with it.

The GAO's 2025 report added a physical dimension. Stakeholders told the GAO that productivity metrics push workers to move faster, skip breaks, and avoid reporting injuries for fear of falling behind on their scores. The same report flagged another problem: emotional AI tools that try to gauge worker mood or attentiveness through facial analysis or voice tone. The GAO noted concerns that these systems misidentify people, particularly workers of colour and those with accents, as negative or non-compliant. A false reading from one of those tools could affect scheduling, performance reviews, or disciplinary action.

ExpressVPN's worker surveys backed up the behavioural side. A majority of monitored employees said they took fewer breaks. Nearly half said they'd consider quitting, or even accepting a pay cut, to work somewhere with less surveillance.

<!-- aeo:section end="what-surveillance-does-to-people" -->
<!-- aeo:section start="what-is-actually-allowed" -->
## What is Actually Allowed?

Alright then, big question: is any of this actually legal?

In the United States, the short answer is: mostly, yes. The Electronic Communications Privacy Act, passed in 1986, and the Stored Communications Act both allow employers to monitor activity on company-provided systems as long as it happens in the "ordinary course of business." That phrase does a lot of heavy lifting. In practice, it means that if you're using a company laptop, company email, or company network, almost everything you do on those systems is fair game.

Brookings highlighted a case that shows how far this can go. A woman named Rene worked at a store where her employer had installed keylogger software on the company computers. Nobody told her. She used that computer to check her personal email and her bank account. The keylogger captured her passwords. Another employee used those passwords to access her private accounts and read through her emails and financial records. When Rene found out and confronted her colleagues, she was fired for "poor performance." The federal court ruled that the keylogger itself didn't violate the Federal Wiretap Act. Her claim under the Stored Communications Act, for the actual use of her passwords to read her private accounts, survived — but the keylogger capture was arguably legal because it happened on a company system.

A handful of states have added notice requirements on top of federal law. Connecticut passed one in 1998. Delaware followed in 2001. New York's took effect in May 2022 — requiring every private-sector employer to give written notice to new hires if it monitors phone calls, email, or internet usage. Penalties for non-compliance in New York range from $500 to $3,000 per offence. But notice requirements only mean your employer has to tell you they're watching. They don't limit what they can watch.

In Europe, the picture is different. Under GDPR, any monitoring has to be necessary, proportionate, and limited to a specific purpose. The EU's Article 29 Working Party, which advises on data protection, issued an opinion in 2017 saying that employee consent to monitoring is usually not valid — because the power imbalance between employer and worker means it's not freely given. Employers are expected to use the least intrusive method available and to justify why alternatives wouldn't work.

The UK's Information Commissioner's Office landed somewhere in between. Its 2023 guidance tells employers to be transparent, conduct impact assessments before rolling out monitoring, and avoid anything disproportionate. But "disproportionate" isn't defined by a hard line — it's a judgement call, reviewed case by case.

<!-- aeo:section end="what-is-actually-allowed" -->
<!-- aeo:section start="the-illusion-of-choice" -->
## The Illusion of Choice

So here's a question worth sitting with. When your employer asks you to install monitoring software on your laptop, and the alternative is losing your job, do you consent?

The EU's Article 29 Working Party addressed this directly in 2017. Their opinion was straightforward. In an employment relationship, consent is almost never valid as a legal basis for data collection. The reason: workers depend on their employer for income. That dependency creates a power imbalance. If saying "no" means risking your livelihood, then saying "yes" doesn't mean much. The Working Party told employers to stop relying on consent altogether and instead justify any monitoring through necessity and proportionality.

Go back to the Teleperformance case. Unions alleged that home-based workers were told to accept AI webcams in their houses. The company said participation was voluntary and pointed to positive staff survey results. But the UNI Global Union argued that workers in countries with weak labour protections felt they had no real option to refuse. When your contract renewal depends on cooperation, "voluntary" isn't really voluntary, is it? Allegedly.

Then there's the problem the EU's Joint Research Centre calls "function creep." Their 2021 review found a recurring pattern across industries. An employer introduces monitoring for one stated purpose — security, say, or health and safety training. Over time, that same data quietly migrates into performance management, disciplinary processes, or scheduling decisions. Workers who originally agreed to a safety check find their break times being scored. The JRC flagged this as one of the most common ways trust breaks down between employers and staff: data collected under one justification gets repurposed without fresh notice or consultation.

And in most US jurisdictions, none of this requires consent at all. If it's a company device on a company network, the employer doesn't need to ask.

<!-- aeo:section end="the-illusion-of-choice" -->
<!-- aeo:section start="when-surveillance-backfires" -->
## When Surveillance Backfires

So the tools are supposed to make workers more productive. But the GAO's 2025 report flagged a problem with that assumption: the metrics often can't tell the difference between working and looking like you're working.

Most monitoring software measures activity. Keystrokes, mouse movements, apps open, time between actions. What it can't measure is thinking. Reading a printed document. Mentoring a colleague. Sketching out a plan on paper. Staring at a whiteboard.

The GAO noted that workers whose jobs involve research, problem-solving, or collaboration routinely show up as "idle" or "unproductive" on dashboards — even when they're doing exactly what they were hired to do. And because managers sometimes treat those dashboards as gospel, the result is reprimands, lower performance ratings, or worse, aimed at people whose only offence was doing work the software couldn't see.

And then there's what happens when workers figure out the system is watching.

ExpressVPN's surveys found that a significant proportion of monitored employees had adopted countermeasures. Mouse-jigglers — small devices or software scripts that simulate cursor movement so the dashboard never shows "idle." Pre-scheduled emails sent at strategic times to create the appearance of late-night productivity. Tabs left open on work-related sites while the person does something else entirely.

The GAO's term for this dynamic was more clinical. They warned that employers risk placing "too much trust" in automated outputs, treating them as objective when the underlying data is incomplete or biased. Microsoft's own research coined a punchier label: "productivity paranoia." Managers convinced their teams aren't working hard enough. Workers convinced they're being watched too closely. Both sides responding to the tools rather than to each other. Both sides having a bad time.

<!-- aeo:section end="when-surveillance-backfires" -->
<!-- aeo:section start="the-pushback" -->
## The Pushback

So far this has been mostly about what's happening to workers. But there's a counter-story building — and it's coming from multiple directions at once.

In the US Senate, Senators Bob Casey, Cory Booker, and Brian Schatz introduced the Stop Spying Bosses Act in February 2023. A companion version was introduced in the House in March 2024 by Representatives Chris Deluzio and Suzanne Bonamici. The bill would apply to any employer with more than ten workers. It would require them to publicly disclose what surveillance they conduct, what data they collect, and how that data is used in performance assessments or employment decisions. It would ban monitoring of workers who are off duty, in sensitive areas like bathrooms and break rooms, or engaged in union activity. And it would restrict the use of automated systems to make employment decisions without human oversight.

The bill didn't pass. It expired with the 118th Congress. But it established a framework that labour groups and advocacy organisations are still pushing.

California tried to go further. AB 1331, introduced in the 2025 session by Assembly member Elhawary, would have banned employers from using surveillance tools in employee-only areas like break rooms, changing rooms, and lounges. Workers would have had the right to leave monitoring devices behind during off-duty time, including meal breaks. The California Labor Federation backed it. The Chamber of Commerce fought it, arguing the language was too broad and would undermine workplace safety. In September 2025, the bill was moved to the inactive file in the state Senate — so effectively shelved.

None of these efforts have produced a comprehensive federal law in the US. No single regulator has been given the job of tracking how many employers surveil their workers or how intensively. But the proposals keep coming, the fines keep landing, and the unions keep on pushing.

<!-- aeo:section end="the-pushback" -->
<!-- aeo:section start="drawing-the-line" -->
## Drawing the Line

So where does that leave you?

If you're working on a company laptop, company phone, or company network, assume it's being logged. That's really just the baseline reality across most industries in most countries right now. The safest move is to keep personal accounts, personal messages, and personal browsing on your own devices. Don't check your bank account on your work computer. Don't draft personal emails in your company inbox.

Beyond that, ask questions. Ask HR what monitoring tools are in use. Ask what data is being collected, who can see it, and how long it's kept. In the EU and UK, your employer may be legally required to conduct a data-protection impact assessment before deploying monitoring. You can ask for it. In the US, a few states require written notice.

If something feels wrong — if you're being penalised for metrics you can't see, or monitored in ways that seem disproportionate — talk to a union rep, a privacy regulator, or an employment lawyer before trying to fight it alone.

One last thing. If anyone's thinking, after learning about it today, of using consumer-grade monitoring software to covertly track a partner, a housemate, or anyone else: don't. In many jurisdictions, that's a criminal offence.

<!-- aeo:section end="drawing-the-line" -->
<!-- aeo:section start="key-takeaways" -->
## Key Takeaways

- 60-70% of medium to large employers now use digital monitoring tools, roughly doubling since 2020.
- Bossware can silently activate webcams, log every keystroke including passwords, and capture periodic screenshots.
- Amazon's warehouse scanner system automatically generated warnings and terminations without supervisor input.
- Surveillance correlates with increased worker stress, lower job satisfaction, and higher intentions to quit.
- US federal law largely permits employer monitoring on company systems; Europe's GDPR requires proportionality and necessity.

<!-- aeo:section end="key-takeaways" -->
<!-- aeo:section start="frequently-asked-questions" -->
## Frequently Asked Questions

### What is 'bossware' and what does it do?

Bossware is a category of software that sits quietly on an employee's device, logs everything they do, and sends that data back to a dashboard where managers can see employee productivity. Some tools can activate webcams without telling users, record every keystroke including passwords, take photos of faces every few minutes to verify identity, capture screenshots, track GPS location, and use biometrics like facial recognition.

### How common is workplace digital monitoring among medium to large employers?

Surveys suggest that somewhere between 60 and 70 percent of medium to large employers now use some form of digital monitoring on their workers. Gartner tracked this at around 30 percent in early 2020, doubling to roughly 60 percent by 2022, with projections toward 70 percent. IDC's 2022 survey of North American companies with 500+ employees found 67.6 percent running monitoring software. ExpressVPN's survey found 78 percent of bosses said they used some form of online tracking, though this was an opt-in internet survey.

### What happened with Teleperformance and AI webcam monitoring?

In March 2021, the Guardian reported that Teleperformance, one of the largest call-centre operators globally, told some home-based staff to expect AI-powered webcam monitoring that would watch for 'infractions' like eating at your desk, looking at your phone, or leaving your workstation. Privacy International added that workers in certain countries outside the UK were told AI webcams would be installed in their homes to detect rule violations in real time, with keyboard and mouse activity tracked and idle periods triggering alerts to managers. Unions pushed back, and after media coverage and union pressure, the company appeared to scale back some visible monitoring at least in the UK.

### How does Amazon's warehouse productivity tracking system work?

Amazon's system uses handheld scanners that log each scan, measure time between scans, and track 'time off task' (TOT). If a worker stops scanning for too long, the system generates a warning; if the pattern continues, it generates a termination notice. Internal documents obtained by The Verge in 2019 revealed that at a single Baltimore warehouse, Amazon fired around 300 workers between August 2017 and September 2018 for failing to meet productivity rates—about 10 percent of that facility's workforce. In 2024, French regulator CNIL fined Amazon France Logistique €32 million (later reduced to €15 million on appeal) for a system that tracked workers down to the second and flagged pauses under ten minutes.

### What psychological effects does workplace surveillance have on employees?

A 2024 national survey by sociologist Paul Glavin at McMaster University found that workers who reported higher levels of perceived surveillance also reported more psychological distress and lower job satisfaction. Surveillance increased job pressure, reduced workers' sense of autonomy, and made them feel their privacy had been violated. The EU's Joint Research Centre's 2021 review of 398 studies linked excessive monitoring to increased stress, lower commitment to the organisation, higher intentions to quit, and 'resistance behaviours' where workers find ways to game or avoid the system. ExpressVPN surveys found a majority of monitored employees took fewer breaks, and nearly half would consider quitting or accepting a pay cut to work somewhere with less surveillance.

### Is workplace monitoring legal in the United States?

In the United States, workplace monitoring is mostly legal. The Electronic Communications Privacy Act of 1986 and the Stored Communications Act allow employers to monitor activity on company-provided systems as long as it happens in the 'ordinary course of business.' A federal court ruled that keylogger software capturing passwords on a company computer didn't violate the Federal Wiretap Act. A few states have added notice requirements: Connecticut (1998), Delaware (2001), and New York (2022), which requires written notice to new hires about monitoring of phone calls, email, or internet usage. However, notice requirements only mean employers must tell you they're watching—they don't limit what they can watch.

### How does European law differ from US law on workplace monitoring?

Under GDPR, any monitoring must be necessary, proportionate, and limited to a specific purpose. The EU's Article 29 Working Party stated in 2017 that employee consent to monitoring is usually not valid because the power imbalance between employer and worker means it's not freely given. Employers must use the least intrusive method available and justify why alternatives wouldn't work. The UK's Information Commissioner's Office 2023 guidance tells employers to be transparent, conduct impact assessments before rolling out monitoring, and avoid anything disproportionate. This contrasts with the US where the 'ordinary course of business' standard allows broad monitoring on company systems.

### What is 'productivity paranoia' and how does surveillance backfire?

Microsoft's research coined the term 'productivity paranoia' to describe a dynamic where managers become convinced their teams aren't working hard enough, while workers become convinced they're being watched too closely, with both sides responding to the tools rather than to each other. The GAO's 2025 report noted that monitoring software measures activity (keystrokes, mouse movements, apps open) but cannot measure thinking, reading printed documents, mentoring colleagues, or collaborative work—so workers doing exactly what they were hired to do may show up as 'idle' or 'unproductive.' Workers also adopt countermeasures like mouse-jigglers, pre-scheduled emails, and leaving work-related tabs open while doing other things.

### What legislative efforts have been made to restrict workplace surveillance in the US?

In February 2023, Senators Bob Casey, Cory Booker, and Brian Schatz introduced the Stop Spying Bosses Act, with a House companion in March 2024. It would require employers with 10+ workers to publicly disclose surveillance, data collection, and how data is used in employment decisions; ban monitoring of off-duty workers, in bathrooms and break rooms, or during union activity; and restrict automated employment decisions without human oversight. The bill expired with the 118th Congress. California's AB 1331 (2025) would have banned surveillance in employee-only areas and allowed workers to leave monitoring devices behind during breaks, but was shelved in September 2025.

### What practical advice does the article give to workers concerned about monitoring?

The article advises: assume any company laptop, phone, or network is being logged; keep personal accounts, messages, and browsing on your own devices; don't check bank accounts or draft personal emails on work computers; ask HR what monitoring tools are in use, what data is collected, who can see it, and how long it's kept; in the EU and UK, ask for the data-protection impact assessment employers may be legally required to conduct; in the US, a few states require written notice; and if something feels wrong—being penalized for unseen metrics or disproportionate monitoring—talk to a union rep, privacy regulator, or employment lawyer before fighting it alone.

<!-- aeo:section end="frequently-asked-questions" -->
<!-- aeo:section start="sources" -->
## Sources

- [Original Scandal video: How Companies Spy on Their Employees](https://www.youtube.com/watch?v=nFJxM3Vc-Cw)
- [Hero image source](https://images.rawpixel.com/editor_1024/czNmcy1wcml2YXRlL3Jhd3BpeGVsX2ltYWdlcy93ZWJzaXRlX2NvbnRlbnQvbHIvcHg4Mzk4NzMtaW1hZ2Uta3d2eGV0bTYuanBn.jpg) by openverse, cc0.

<!-- aeo:section end="sources" -->
<!-- aeo:section start="related-coverage" -->
## Related Coverage
<!-- aeo:section end="related-coverage" -->