Meta's Employee Monitoring Tool: When it Becomes a GDPR Risk 

Technology has made it easier for organisations to track how their people spend their time, which applications they use, how often they type, and even where they move their mouse. The question of where lawful oversight ends and intrusive surveillance begins is one that GDPR was designed to address, but knowing what the rules actually require in practice is not always straightforward.

Recent reporting by Reuters on Meta's internal "Model Capability Initiative" has brought these questions into focus. The tool is reported to record detailed behavioural data about how employees work across their devices, capturing activity across applications and websites to help train internal AI systems. 

Meta has since revised its approach to employee activity monitoring following significant internal concerns. The company’s proposed initiative, designed to collect data on employee computer usage to help train AI models, faced criticism from staff over privacy, transparency, and its potential impact on working conditions. 

In response, Meta has introduced additional safeguards, including the ability for employees to temporarily pause data collection and request exemptions from participation. The company has also addressed concerns about the tool’s effect on device performance and internet usage. The changes come amid broader unease among employees regarding the company’s increasing focus on AI and ongoing workforce reductions, with Meta stating that it remains committed to protecting privacy while giving employees greater control over how and when data is collected.

The underlying question this raises is one that any employer using monitoring software should be asking: does what you are doing comply with data protection law?

What Does GDPR Say about Monitoring Employees?

The short answer is that employee monitoring is not prohibited, but it is strictly regulated. Under the UK GDPR and the Data Protection Act 2018, any collection of personal data about employees, including behavioural, productivity, or location data, must comply with the core data protection principles.

The ICO has published guidance on employee monitoring which makes clear that employers must have a lawful basis for any monitoring they carry out, must be transparent with staff about what is being tracked and why, and must ensure that the monitoring is proportionate to the legitimate aim being pursued. Tracking everything all the time because the technology allows it does not meet the legal standard.

What Makes Employee Monitoring Lawful?

For most employers, the most likely lawful basis for monitoring is legitimate interests, meaning there is a genuine business reason for the monitoring that is proportionate to the impact on employees. This might include monitoring email traffic for security purposes or recording calls for quality assurance. What it is unlikely to cover is pervasive, continuous surveillance of how an employee works at a granular level, particularly where that data is then used to train an AI model for purposes employees were never told about.

Transparency is a core obligation. Employees must be told, in clear and accessible terms, what data is being collected, how it is being used, how long it will be retained, and who has access to it. This information should appear in an employment contract, staff handbook, or a dedicated monitoring policy. The ICO's employment practices guidance sets out these obligations in detail and is worth reviewing carefully if your organisation uses any form of monitoring software.

Proportionality matters equally. The level of monitoring must be no more than is necessary to achieve the stated purpose. Collecting detailed behavioural data across every application an employee uses, every website they visit, and every mouse movement they make is unlikely to satisfy the proportionality test unless there is a very specific and compelling justification.

Why AI-Powered Monitoring Raises Particular Concerns

When monitoring data is used to train AI models, the GDPR risks multiply. Data minimisation, one of the core principles of UK GDPR, requires that you collect only what is genuinely necessary. Using broad employee behavioural data as training material for an AI system introduces a secondary purpose that employees almost certainly did not consent to and may not even be aware of.

The ICO's guidance on AI and data protection sets out how GDPR applies when personal data is used in AI systems, including obligations around fairness, transparency, and accountability. These principles translate into practical requirements about what data you can use, how you explain AI systems to those they affect, and how you document your decision-making.

Where monitoring captures sensitive data, such as health indicators or psychological patterns inferred from behaviour, the legal bar rises further. Special category data requires explicit consent or another specific legal gateway, and the risks of getting that wrong are significant.

What This Means for Employers Right Now

If your organisation uses monitoring software of any kind, now is a good time to review it. Check whether staff have been clearly informed, whether the monitoring is genuinely necessary for its stated purpose, and whether any data is being passed to third-party AI providers or used for purposes beyond the original reason it was collected. If employees are based in the EU, or if your organisation handles data about EU-based individuals, EU GDPR obligations apply in parallel with UK requirements.

A data protection impact assessment, or DPIA, may be required before introducing new monitoring systems, particularly those involving AI or automated analysis of employee behaviour. A DPIA is a structured review of the privacy risks associated with a new processing activity, and the ICO's guidance on DPIAs explains when one is mandatory and how to carry it out.

What if You Are an Employee Who Has Concerns?

If you believe your employer is monitoring you in ways that go beyond what you were told, or in ways that feel disproportionate or intrusive, you have rights. You can submit a subject access request to find out what personal data your employer holds about you. You can also raise a complaint with the ICO if you believe your employer is breaching data protection law.

Monitoring may be a legitimate tool in the right circumstances, but it is one that requires care, clarity, and proper legal grounding. Employers who treat it as a default rather than a justified choice risk not only regulatory scrutiny but real damage to the trust that makes workplaces function.

If you are an employer concerned about your monitoring practices, or an employee with questions about your rights, taking specialist legal advice is a practical and worthwhile step. Data protection law in this area is nuanced, and the consequences of getting it wrong can be serious.

How Can Gerrish Legal Help?

Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property. 

We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements. 

We are here to help you, get in contact with us today for more information.

Next
Next

New UK Data Protection Complaint Rules Explained