Writing a Monitoring Policy: What to Put In and What to Tell People
- Section
- Monitoring & Privacy
- Written
- 2026-08-06
- Last checked
- 2026-08-06
A monitoring policy does two jobs. It satisfies notice requirements where they apply, and it tells employees what is happening — which is the part that determines whether the monitoring damages the workplace or not.
A product-focused treatment of stealth monitoring practices is available in learn more.
Policy design can be informed by the NIST Privacy Framework.
Most policies do the first badly and skip the second entirely.
General information, not legal advice. Notice requirements are state-specific. Have the policy reviewed by employment counsel.
What the policy must contain
What is monitored
Specifically, by category. Not "electronic communications and systems usage," which tells nobody anything.
List each type: email content, email metadata, internet browsing, application usage, active and idle time, screenshots, keystrokes, file access, network traffic, video surveillance, audio recording, location, badge access, telephone calls.
For each, state whether it is monitored or not. A policy that lists only what you do monitor invites the assumption that everything else happens too.
On what equipment
Company-owned devices, company accounts on personal devices, personal devices accessing company systems, company premises.
The personal device case needs its own treatment and is much narrower. See monitoring on personal devices.
Where and when
Working hours only, or continuously. On premises, or anywhere.
State explicitly where monitoring does not happen: break areas, changing areas, restrooms. Some states prohibit these specifically; naming them is reassuring everywhere.
Why
A stated purpose per category. Security, regulatory obligation, safety, billing accuracy, investigation.
"Because the system collects it" is not a purpose. If you cannot state one, that is a reason to reconsider collecting it rather than a reason to leave the section vague.
Who can access it
Named roles, not "authorised personnel." Under what circumstances — routine review, incident, investigation. Whether managers can see their team's data or only HR and security can.
This section does more for trust than any other, and it is the one most often written as a blank cheque.
How long it is kept
A retention period per data type, and what happens at the end of it.
Data kept indefinitely is data you will eventually have to explain, produce, or defend.
What it will and will not be used for
The section employees actually read.
If activity data will not be used in performance reviews, say so — and then make it true. A single instance of the contrary will end the credibility of the entire policy.
Employee rights
How to see your own data. How to raise a concern. Who to ask.
Legal basis and jurisdiction notes
Where you employ across states, the policy may need state-specific supplements. Building one master notice to the strictest applicable standard is usually simpler than maintaining several.
Meeting the notice requirements
Where a statute applies, the policy alone may not be enough.
Connecticut requires prior written notice describing the types of monitoring, plus a notice posted conspicuously — and from October 2026 a plain-language statement for new hires.
Delaware requires prior written notice and allows a choice between daily notice on access, or one-time notice with an acknowledgement.
New York requires written or electronic notice on hire, plus a conspicuously displayed notice.
Details differ, and sources disagree about whether other states belong on this list. See employee monitoring: what is lawful, and check your states with counsel.
Practical approach: give written notice with acknowledgement in every state, and add the posted notice where required. It is cheaper than tracking which state requires what, and it removes the question if you later hire somewhere new.
Three commitments worth making
These are not legally required. They are what determines whether the policy is believed.
1. We will not use monitoring data for individual performance evaluation.
If you can make this commitment, make it explicitly. It is the fear underneath everything else, and addressing it directly does more than any amount of reassurance about security purposes.
If you cannot make it, do not imply it. Say what the data will be used for.
2. We will tell you if the monitoring changes.
Policies change quietly. A commitment to notify before adding a category is cheap and it prevents the discovery-by-accident that destroys trust.
3. You can see your own data.
A right in some jurisdictions and good practice everywhere. It is also the cheapest error-detection mechanism available — employees will find inaccuracies nobody else would.
Rolling it out
Do not bury it in an updated handbook. A monitoring policy introduced as a routine handbook revision, discovered later, produces exactly the reaction you were trying to avoid.
Explain it in person, or at least in a message from a named person. Then take questions.
Brief managers first. They will be asked, and "I don't know, ask HR" is the worst available answer.
Get an acknowledgement, and keep it. Required in some states, useful everywhere.
Review annually. This area is moving, and a policy describing tools you no longer use — or omitting ones you added — is worse than none.
The test
Read the policy as an employee who has just been told it exists.
Can you tell exactly what is collected about you, who can see it, how long it is kept, and what it will be used for?
If any of those is unclear, the policy has not done its job — regardless of whether it satisfies the statute. The statute is the floor; the reaction is the outcome.