Skip to content
Ask What They Collect

All notes / Finding out

Asking: the Question That Works

Most of what you want to know is available for the asking, and in many places they are obliged to answer. How to ask so you get a real answer.

Finding out · Procedure

The fastest route to knowing what is collected is to ask. It is also the one almost nobody takes.

The process in “Asking: the Question That Works” also applies to workforce software: the purpose and rules should be clear before the first record is collected. For teams considering explore Monitask in relation to employee time tracking, the rollout should include written notice, access limits, a correction route and a scheduled review.

Who to ask

IT or the service desk, for what the software does.

For an independent perspective related to “Asking: the Question That Works”, consult the ILO working-time resources; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.

HR, for what the policy says and how the data is used.

The data protection contact, where there is one, for what is collected and retained — which is the question they exist to answer.

Any of the three is reasonable; the third gets the most precise answer.

How to ask so it works

Specifically. "What does the monitoring collect" invites a vague answer. "Does the software on my laptop capture screenshots, keystrokes, webcam or location?" does not.

In writing. You get a more careful answer and you have it afterwards.

As a question rather than a complaint, which changes who replies and how.

And one question at a time.

The four worth asking by name

What is collected — the actual list.

Who can see it at individual level, including whether my manager can.

How long it is kept.

Whether it is used in performance or disciplinary processes.

Those four cover nearly everything anybody actually wants to know.

What a good answer looks like

Specific: names the categories rather than describing them.

Checkable against a published notice.

And it says what is not collected, which is the part that indicates somebody has thought about it.

What a poor answer looks like

"Standard security monitoring."

"Nothing you need to worry about."

A refusal to say, which in several jurisdictions is not a position they can hold.

If you get one of these, the next note covers what the policy should contain and the one after covers the formal route.

Why they usually answer

Because transparency obligations exist in most places and because the answer is usually unremarkable.

Most organisations collect less than employees assume and are happy to say so once asked.

The question is rare, which is why it feels confrontational and is not.

Asking at the right time

At induction, when it is a normal question.

When something changes and is announced.

Before a dispute rather than during one, because asking during looks like preparing a position even when it is not.

What to do with the answer

Write it down with the date.

If it later turns out to be inaccurate, that is a materially different situation from never having asked.

And if the answer is reassuring, believe it and stop auditing yourself, which is the whole point of asking.

What to check

Have you ever asked, in writing?

Do you know who the data protection contact is where you work?

Could you name the four questions?

And if you got a vague answer, did you follow it up or let it go?