Before the myths
Workplace monitoring is not new. Supervisors watched factory lines long before dashboards watched clicks. What has changed is scale. Cameras, GPS, badge logs, chat exports, keystroke tools, biometric clocks, delivery apps, warehouse scanners, call scoring, and remote-work software can turn the whole working day into data.
The law does not start from “the employer bought the tool, so the employer may use it.” In Germany and the EU, data protection rules require a lawful basis, a clear purpose, transparency, necessity, proportionality, and limits. Employment relationships also have a power imbalance, so “consent” is often weak. If refusal would risk your job, it is not free in the normal sense.
This is general information, not case advice. The worker rule stays practical: check, document, don’t sign, don’t go alone. Surveillance works best when each worker thinks they are the only one who feels watched.
Myth 1: “If it happens at work, the employer can monitor it.”
Reality: Work is not a privacy-free zone. Employers may have legitimate reasons to protect safety, secure property, organize work, investigate specific misconduct, or meet legal obligations. But each purpose must be concrete. “Efficiency,” “quality,” or “security” cannot become a blank cheque for permanent watching.
Ask what is being monitored, why, for how long, who sees it, what decisions are made from it, and what less intrusive option was considered. A camera at a dangerous loading bay is different from a camera pointed at break tables. A system that logs access to confidential files is different from one that records every active minute of a remote worker’s screen.
If the explanation keeps changing, write that down. A tool installed for safety should not quietly become a discipline machine.
Myth 2: “A sign on the wall is enough transparency.”
Reality: A sign may be part of transparency, but it is rarely enough. Workers should be told in plain language what data is collected, the purpose, the legal basis, retention period, who receives the data, whether automated evaluation is used, and what rights workers have. For productivity monitoring, workers should understand which metrics exist and how they affect warnings, bonuses, scheduling, promotion, or dismissal.
If management says “the software just supports planning,” ask whether reports are used in performance reviews. If they are, workers need to know. Hidden scoring is not fair management. It is discipline without a visible rulebook.
Myth 3: “I clicked accept, so I agreed.”
Reality: Consent at work is complicated because the employer holds power over pay, shifts, promotion, contract extension, and dismissal risk. GDPR consent must be freely given, specific, informed, and withdrawable. In many employment situations, an employer should rely on another lawful basis and still prove necessity and proportionality.
Do not treat a clicked box as the end of the matter. Save the consent screen, policy, email, or app notice. If refusal was impossible or punished, record what happened. If a new monitoring tool appears with “accept by tomorrow or lose access,” do not sign or click without saving the text and seeking advice.
Myth 4: “Location tracking is normal for mobile work.”
Reality: Sometimes location data is needed to dispatch workers, protect lone workers, coordinate deliveries, or verify arrival at a site. That does not justify tracking every movement all day, during breaks, after shifts, or outside work. Purpose and limits matter.
Workers should know when tracking is active, whether it can be turned off after work, how precise it is, who can see live location, how long logs are kept, and whether location affects pay or discipline. If the employer uses private phones, ask what data the app can access beyond work location. Contacts, photos, private messages, and off-duty movement are not automatically available just because the phone also receives work instructions.
Platform and delivery workers should also keep independent records. If GPS is later used to accuse you of delay, route deviation, or absence, you need your own timeline: traffic, waiting time, unsafe address, client delay, broken equipment, or app failure.
Myth 5: “Private messages are private only if sent on a private device.”
Reality: Device and account matter, but the answer is not that simple. Employers can set rules for work systems, protect business data, and investigate specific risks. But broad reading of messages, private chats, union conversations, health information, or personal communications raises serious concerns.
Workers should separate private and work communication where possible. Do not use work accounts for personal matters if you can avoid it. At the same time, employers should not use “company device” as a magic phrase to search everything without purpose, limits, and process. If you are told private use is allowed, monitoring must match that reality.
If messages with colleagues about pay, safety, or organizing are being monitored or chilled, involve others quickly. A surveillance problem becomes a collective-rights problem when it stops workers from speaking to each other.
Myth 6: “Biometric time clocks are just another badge.”
Reality: Biometric data is more sensitive than an ordinary badge. Fingerprints, facial templates, iris scans, or voiceprints are linked to the body. If compromised, you cannot replace them like a password. Under GDPR, biometric processing for identification is a special category and needs strong justification.
Ask why a badge, PIN, supervisor sign-in, or other less intrusive method is not enough. Ask what template is stored, whether raw images are kept, who operates the system, how long data is retained, and what happens if you refuse. A workplace convenience argument is not the same as necessity.
Myth 7: “Remote workers can be watched more because nobody sees them.”
Reality: Remote work does not erase privacy. Keystroke logging, webcam snapshots, screen recording, mouse-movement scoring, idle-time alerts, and automatic productivity rankings can be highly intrusive. Employers may manage work and measure outputs, but permanent digital presence checks can become disproportionate.
The better question is: what work result needs to be assessed, and why is intrusive monitoring necessary to assess it? If the job can be managed by deadlines, team communication, case completion, service quality, or agreed availability windows, constant tracking may be excessive. Workers should not have to perform busyness for software.
Myth 8: “If the system says you are unproductive, that is objective.”
Reality: Metrics are designed by people. They can miss invisible work: helping colleagues, calming customers, cleaning up errors, waiting for approvals, documenting safety issues, translating, mentoring, accessibility needs, care interruptions, bad equipment, or system downtime. A scanner count may punish the worker assigned to complex items. A call-time target may punish the worker who resolves difficult cases properly.
Challenge the metric, not only the score. Ask what the system measures, what it ignores, and how errors are corrected. Keep examples where the metric misrepresents reality. One worker saying “the number is unfair” may be dismissed. A team showing repeated distortions is harder to ignore.
Myth 9: “The works council or union only needs to know after installation.”
Reality: Where a Betriebsrat exists, monitoring technology often raises consultation and co-determination issues, especially when systems can assess behaviour or performance. Management should not quietly install a tool and present it as finished. A union can also help workers compare experiences, demand limits, and negotiate rules even where there is no works council.
Good workplace rules should cover purpose, data categories, access, retention, prohibited uses, error correction, worker access, discipline limits, and review dates. They should also stop function creep: safety camera today, productivity discipline tomorrow.
Myth 10: “Complaining means you have something to hide.”
Reality: Asking for limits is not suspicious. It is normal rights work. You can request information and access to your personal data at a high level under GDPR. You can ask how automated or algorithmic evaluations are used. You can raise concerns internally, with a works council, union, data protection officer where available, or a data protection authority. If the problem is mainly technical rights and platform evidence, Digital Dignity Lab is a useful sibling handoff.
Before complaining, gather the documents: policy, screenshots, tool name, notices, emails, consent forms, examples of decisions made from the data, and who was affected. Do not secretly take data that exposes customers, patients, clients, or colleagues unless advised; protect third-party privacy. Move as a group where possible. Surveillance isolates workers by making everyone feel personally watched. Collective records turn the camera back toward the rule.










