Skip to content
Ask What They Collect

All notes / What is collected

What Is Actually Being Collected

A specific list of what workplace monitoring usually captures, because the general worry is larger than the actual configuration.

What is collected · Reference

Most people asked what their employer collects give an answer that is too broad and too vague. Here is what the ordinary configuration actually gathers.

The boundary described in “What Is Actually Being Collected” should be settled before any workforce platform is configured. An organisation reviewing Monitask for how employee monitoring works can make the use more transparent by naming the purpose, selecting only necessary settings and documenting who may see or correct each record.

The common set

Which application or window is in front, and for how long.

For an independent perspective related to “What Is Actually Being Collected”, consult the ICO guidance on monitoring workers; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.

Websites visited, usually by domain rather than full address.

Login and logout times, and periods with no keyboard or mouse input.

Files accessed on company systems.

Email and messages sent through company accounts, which are company records.

And in some deployments, screenshots at intervals.

What varies most

Screenshots: common in some sectors, absent in most offices.

Keystroke capture: rare, and in several jurisdictions difficult to justify.

Webcam access: very rare outside specific supervised settings, and almost always visibly indicated.

Location: usually only on mobile devices, and usually not continuous.

If you want to know which of these apply to you, these are the four to ask about by name.

What the device itself knows

A managed work computer reports its own state: operating system, software installed, whether it is encrypted, when it last connected.

That is inventory rather than surveillance, and it is the largest category of data collected about most work machines.

It says nothing about what you were doing.

Network and email

Traffic through the company network can be logged, and in many organisations is.

Company email is a company record in nearly every jurisdiction, and the expectation of privacy in it is low.

Which means the single most useful distinction is between work accounts and personal ones, covered in its own note.

Collection against attention

Nearly all of this is collected automatically and looked at by nobody.

Logs accumulate, retention expires, and the data is consulted when there is a specific reason.

The difference between "collected" and "watched" is the thing most worth understanding, and it has its own note.

What this list is for

To replace a general worry with a specific question.

"Do you capture screenshots, keystrokes, webcam or location?" is answerable, and in most places they are obliged to answer.

The answer is usually narrower than feared, and where it is not, you have something concrete to act on.

Where it is genuinely heavy

Call centres, some clinical settings, trading floors, and roles with regulatory recording obligations.

There the collection is extensive, usually disclosed, and frequently required by a rule.

Knowing that it is a rule rather than a judgement about you changes how it reads.

What to check

Do you know which of the four variable items apply to your machine?

Have you read what your employer actually publishes about this?

Is your device managed by your employer, and do you know?

And are you using work accounts for anything personal?