Skip to content
Ask What They Collect

All notes / Finding out

What the Policy Should Tell You

A workplace monitoring policy has a minimum content. Knowing it lets you see what yours is missing.

Finding out · Reference

Most organisations have a policy. Reading it against what it should contain tells you as much by its gaps as by its text.

The process in “What the Policy Should Tell You” also applies to workforce software: the purpose and rules should be clear before the first record is collected. For teams considering time tracking software for accountable teams in relation to time tracking software, the rollout should include written notice, access limits, a correction route and a scheduled review.

What should be in it

What is monitored: the categories, named.

For an independent perspective related to “What the Policy Should Tell You”, consult the NIST Privacy Framework; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.

Why: the purpose, specifically rather than "security and business efficiency".

The legal basis.

Who has access, at what level.

How long data is kept.

Whether it is used in performance or disciplinary processes.

the rights you have, including how to request your own data.

And who to contact.

The three that are usually missing

What is not collected, which is the most reassuring possible content and appears almost nowhere.

Whether line managers can see individual data, which is the question people most want answered.

And what happens if monitoring is used in a decision about you — the process, the right to respond.

Their absence is not sinister; it usually means the policy was adapted from a template.

Reading the purpose statement

A specific purpose supports specific collection.

"To protect company data and comply with regulatory obligations" is a real purpose.

"To improve productivity and ensure appropriate use" is broad enough to cover anything, which is the drafting to notice.

The word "may"

Policies are written permissively: the company may monitor email, may capture screenshots.

Which describes what is allowed rather than what happens.

A policy saying "may" about six things and a configuration doing two of them is normal, and the gap is why asking directly is still worth doing.

Where to find it

Staff handbook, intranet policy library, or attached to your contract.

If you cannot find it, asking for it is a reasonable request and the asking is itself informative.

In several jurisdictions the privacy notice is a separate and more specific document, covered in the next note.

When it was last updated

Check the date.

A policy from before remote working describes a different situation, and one from before your current tooling describes different software.

An out-of-date policy is common and worth raising, because it means nobody has checked what is actually running.

Policy against practice

The policy is what they are permitted to do. The configuration is what they do.

Both matter and they are different questions.

Which is why the previous note recommends asking as well as reading.

What to check

Have you read yours?

Does it say what is not collected?

Does it say whether managers see individual data?

And when was it last updated?