← All posts
How-to Guides

Is a pre-send writing check employee monitoring? GDPR, works councils, and what actually decides it

September 18, 2026 · 7 min read

A compliance team selects a tool, security reviews it, procurement clears it, and the rollout stops in a meeting nobody scheduled at the start. Someone asks whether this counts as employee monitoring, and whether the works council has to agree.

That question ends more deployments in Europe than pricing does. It deserves a proper answer rather than reassurance, so here is the structure of the rules, what actually decides the outcome, and the cases where the honest answer is no.

Two layers, and the second one is where deployments fail

The GDPR sets the baseline. Processing employee data needs a lawful basis, and in an employment context consent is generally unreliable because the power imbalance undermines whether it is freely given. Most workplace processing therefore runs on legitimate interests or on a legal obligation, with the proportionality assessment doing the real work.

Article 88 then lets each member state add more specific rules for the employment context, and most have. Germany, France, Italy, the Netherlands and Austria each layer national employment law on top of the GDPR baseline. That second layer is where a rollout that looked compliant runs into a requirement nobody costed.

The practical consequence: a tool can be lawful under the GDPR and still be undeployable in a given country until a separate process completes.

What the second layer looks like in practice

Germany. Where a works council exists, the introduction of technical systems capable of monitoring employee performance or behaviour falls under co-determination. The works council has to agree, and agreement is negotiated rather than notified. German case law has also been clear that a works agreement cannot make otherwise inadmissible processing lawful, so the agreement is a necessary step and not a cure.

Italy. The Workers’ Statute distinguishes two categories, and the distinction matters more than anything else in this article. Systems installed specifically to monitor work activity require a prior trade union agreement or authorisation from the labour inspectorate. Tools provided to the employee to perform their work are treated differently and do not carry the same requirement.

France. Employee representatives must be informed and consulted before a monitoring system is introduced, and employees must be individually informed. A system deployed without that process produces evidence that cannot be used.

Across all of them the same three obligations recur: tell the representatives what the system does, tell the employees before it runs, and be able to show the processing is proportionate to a real purpose.

The distinction that actually decides it

Read those rules together and a line appears. The line follows what the system produces rather than what technology it uses.

A system that builds a record of what individual employees did, available to management, is monitoring in the sense all of these rules are aimed at. The whole apparatus of consultation, co-determination and proportionality exists for that.

A system that shows an employee something on their own screen, stores no message content, and reports only aggregate patterns above a group threshold is doing something different, and the assessment reflects that. It still involves personal data processing and still needs a lawful basis, transparency and a proportionality assessment. What changes is that the intrusion being weighed is far smaller, which makes the proportionality argument straightforward instead of strained.

Four questions establish where a given tool sits. They are worth asking any vendor before the works council does.

Question What a defensible answer looks like
Who sees the result of a check? The writer, on their own screen, before sending. Nobody else receives an alert.
What is stored? The event, the rule, the outcome. Not the message, not the flagged sentence.
What attribution do the records carry? Department or team. No user identifier on the event record.
What happens with a small team? Reporting is withheld below a participant threshold, so a team of three cannot be read as one person.

A vendor who cannot answer the second and third questions precisely is selling a monitoring product, whatever the marketing says. That is not disqualifying, and it does mean the full consultation route applies.

The Italian distinction, generalised

The work-tool point deserves more space, because the reasoning behind it travels beyond Italy even where the statute does not.

A system installed to observe employees is aimed at the employer’s interest in knowing what staff are doing. A tool given to employees so they can do their work better is aimed at the employee’s own task, and any information the employer derives from it is a by-product rather than the purpose.

Regulators and representatives across Europe reason in similar terms even where no equivalent provision exists, because the distinction tracks the proportionality question directly. A system whose primary output goes to the person using it is easier to justify than one whose primary output goes to their manager.

This is worth surfacing early in a works council conversation. The first thing representatives usually want to establish is who the system serves, and being able to answer with a configuration rather than an assurance shortens the discussion considerably.

When a DPIA is required

A data protection impact assessment is required where processing is likely to result in a high risk, and systematic monitoring of employees is one of the listed triggers. The practical answer for most firms is to do one regardless of whether the trigger is clearly met.

The reason is procedural rather than legal. The DPIA is the document that answers the works council’s questions, the employee’s questions, and the regulator’s questions, and producing it early converts an adversarial conversation into a review of a document. Teams that skip it spend longer explaining themselves than the assessment would have taken.

The assessment should record what is processed, why a less intrusive option was rejected, what is not collected, and what the retention period is with its reasoning.

Where the answer is no

Some deployments should not proceed, and a vendor telling you otherwise is worth distrusting.

If the intended use is identifying which individuals generate the most flags, for performance management, that is employee monitoring in the plainest sense and it needs the full route: consultation, co-determination where applicable, individual notice, and a proportionality argument that survives contact with a regulator. It may still be lawful. It will not be quick.

If a works council exists in Germany and has not agreed, the deployment does not happen there, whatever the DPIA says. If employees have not been told before the system runs, the transparency obligation has already been missed and no later disclosure repairs it.

Deploying quietly and explaining later is the one approach that converts a manageable process into an enforcement matter.

How to run it in the right order

  1. Establish what the tool stores and who sees it, in writing, from the vendor.
  2. Write the DPIA, including the less-intrusive alternatives you considered.
  3. Take it to employee representatives before configuration, not after.
  4. Inform employees individually, describing what is shown to them and what is recorded.
  5. Keep the configuration matching the description. Divergence between the two is the finding that follows.

Where a pre-send check fits

Our own answers to the four questions are the reason this article can be written honestly. The check runs in the writer’s editor and the result appears on their screen alone. No message content is stored. Event records carry the department rather than the person, and reporting is withheld below a participant threshold. Our compliance reporting is built at department level for exactly this reason.

None of that removes the process. It changes what you are asking a works council to approve, which is usually the difference between a short conversation and a long one.

The takeaway

Ask the four questions in the table before you shortlist, not after. The answers determine which regulatory route you are on, and the route determines whether this is a four-week deployment or a six-month one. For what the resulting records need to contain, see our piece on what counts as an audit trail.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← Client confidentiality in private banking: the four moments it breaks