Employee monitoring is lawful in the Netherlands only where the employer has a specific, legitimate purpose that outweighs the privacy of the workforce, where no less intrusive means would achieve that purpose, and where staff have been told in advance what is monitored and why. The rules come from the AVG (the Dutch name for the General Data Protection Regulation), from the Uitvoeringswet AVG, and from the Wet op de ondernemingsraden, which in most cases requires the works council to agree before any monitoring system is introduced. Monitoring introduced without those steps is unlawful, whatever the employment contract says.

Which rules govern employee monitoring in the Netherlands
Four bodies of law apply at once, and employers who look only at the first of them run into trouble. The AVG governs every processing of personal data, and monitoring is processing by definition. The Uitvoeringswet AVG (UAVG) fills in the national choices the Regulation leaves open and is the statute that gives the Autoriteit Persoonsgegevens its supervisory powers. Article 8 of the European Convention on Human Rights protects private life, and the European Court of Human Rights has confirmed that this protection does not stop at the office door: correspondence and communications at work fall within it, and an employer must give prior notice of the nature and extent of any monitoring of them.
Dutch employment law adds a layer of its own. Article 7:611 of the Burgerlijk Wetboek obliges the employer to behave as a good employer, and a court will apply that standard to monitoring that is technically defensible under data protection law but disproportionate in the employment relationship. Finally, the criminal law sets an outer boundary: recording a conversation you are not party to, and filming people covertly with a concealed device in a private or enclosed space, are criminal offences in their own right, and neither the employment contract nor a privacy policy can authorise them.
Together these produce a single practical rule. Monitoring is not forbidden, but it is never a management prerogative that can simply be announced. It is a processing operation that has to be designed, justified, documented and agreed before the first byte is collected. Our overview of Dutch privacy laws sets out how those obligations fit together across an organisation.
The lawful basis: why consent almost never works

Every monitoring measure needs a lawful basis under article 6 of the AVG, and in the employment context there is effectively only one workable option: legitimate interest. Consent is not it. The Autoriteit Persoonsgegevens and the European data protection supervisors take the consistent position that an employee is rarely in a position to refuse freely, because the relationship of authority makes the refusal costly. Consent obtained in that setting is not freely given and therefore not valid, and an employer who builds a monitoring programme on signed consent forms has built it on nothing.
Necessity for the performance of the employment contract is equally weak as a basis. Paying wages requires an administration; it does not require keystroke logging. Compliance with a legal obligation does justify certain forms of registration, for instance working time records or the checks required of financial institutions, but only to the extent the obligation actually reaches.
That leaves the legitimate interest test, and it has three steps that must be worked through in that order and recorded. First, identify the interest concretely: not general oversight, but preventing theft from a specific warehouse, protecting a named category of confidential data, or meeting a specific safety duty. Second, show necessity: the monitoring must actually be capable of serving that interest, and no less intrusive measure must be available. Third, weigh the interest against the privacy of the employees, taking into account how intrusive the measure is, how long it lasts, how many people it affects and what they could reasonably expect.
The reason so many monitoring programmes fail is that the first step is skipped. An employer who cannot say precisely what problem the monitoring solves will not survive the second and third steps either, and a court reviewing a dismissal built on that evidence will say so. The same test underpins the rules on employee privacy in every other part of the employment relationship.
Necessity, proportionality and the limits of the technology
Necessity and proportionality are separate questions and both must be answered. Necessity asks whether the measure is suitable and whether a lighter alternative exists. Proportionality asks whether the intrusion is in reasonable relation to the interest served, even where no lighter alternative exists at all. A measure can be necessary and still be disproportionate, and in that case it is unlawful.
In practice the assessment turns on a small number of variables. Continuous monitoring is treated far more strictly than periodic or sample-based checks. Monitoring aimed at a concrete suspicion against an identified individual is easier to justify, for a limited period, than blanket monitoring of the whole workforce. Aggregated or pseudonymised data that shows a pattern without identifying a person is almost always the lighter alternative that must be tried first. And monitoring that reaches into an area where the employee legitimately expects privacy, such as rest areas, sanitary facilities or the home, will not pass.
Two further limits deserve naming. Monitoring may not be used in a way that produces indirect discrimination, for instance by applying a system in practice only to a group defined by origin, age or health; that engages the anti-discrimination laws alongside data protection law. And monitoring may not process special categories of data, including health data, unless one of the narrow exceptions in the AVG applies. An occupational health system that registers absence dates is lawful; a manager who records the reason for the absence is not.
Transparency: what staff must be told before monitoring starts

Information must be given in advance, and it must be specific enough to be useful. Articles 13 and 14 of the AVG require the employer to state which data are collected, for what purpose, on what basis, who has access, how long the data are kept and what rights the employee has. In an employment setting that information belongs in a written monitoring protocol or code of conduct, not in a clause buried in the contract, and it should be repeated when the system changes.
A workable protocol answers four questions plainly. What conduct is expected and what is prohibited, so that employees know the standard against which they are measured. Which systems are in place, in concrete terms: logging of internet traffic, camera positions, vehicle tracking, access control. Who may look at the data, under what trigger, and with what authorisation, because unrestricted access by line managers is one of the most common failures. And how long each category is retained before automatic deletion.
Alongside the protocol sit two documents the Autoriteit Persoonsgegevens will ask for first in any investigation. The register of processing activities under article 30 of the AVG must list the monitoring operations. And where the monitoring is systematic and extensive, or involves large-scale processing, a Data Protection Impact Assessment must be carried out before the system goes live. Where the DPIA shows a high residual risk that cannot be mitigated, the employer must consult the Autoriteit Persoonsgegevens in advance under article 36; the authority then has eight weeks to respond, extendable by six weeks, and the system may not be deployed in the meantime. A Data Protection Officer, where one is appointed, must be involved in the assessment from the start.
Transparency also has a limit that cuts the other way. Employees keep a degree of confidentiality in their communications even on company equipment. An employer may set rules on private use, and may switch private use off entirely, but may not simply read messages that are evidently personal. Our article on whether confidential communications at work may be inspected sets out how that boundary is drawn in practice.
The works council: consent under article 27 WOR
This is the step employers most often miss, and it is the one with the sharpest consequences. Under article 27 paragraph 1 of the Wet op de ondernemingsraden the employer needs the consent of the works council for two categories that both bite here: a regulation on the processing and protection of the personal data of the people working in the undertaking, and a regulation on facilities that are aimed at, or suitable for, the observation of or control over the attendance, conduct or performance of those people. A camera plan, a tracking system, monitoring software and an internet and email protocol all fall within one or both.
Note the wording: suitable for. The employer does not have to intend to monitor performance. A system installed for security that is capable of producing data about individual conduct triggers the right of consent all the same. The test is objective, and it is the reason why access control systems, ticketing tools and productivity dashboards regularly turn out to require consent that was never asked for.
If the employer takes the decision anyway, the works council can invoke the nullity of that decision in writing, within one month of being informed of it or of discovering that it has been implemented. The decision is then void and the employer must undo it. Where consent is refused but the employer considers the refusal unreasonable, the route is not to proceed regardless but to ask the subdistrict court for substitute consent, which is granted only where the refusal is unreasonable or the decision is justified by compelling business reasons. Involving the works council early, before the system is bought, is invariably faster than litigating afterwards.
Cameras, vehicle tracking, software and social media
Camera surveillance is permitted for a concrete purpose such as protecting property, preventing theft or ensuring safety, provided the presence of cameras is clearly signposted at the entrance and in the monitored areas. Cameras may not be placed where employees are entitled to expect privacy, which rules out sanitary facilities, changing rooms and rest areas. The Autoriteit Persoonsgegevens takes the position that footage should be kept no longer than four weeks unless a specific incident is recorded and needs to be retained for that reason. Access to the recordings must be restricted to named people and logged. The detailed rules, including those for shops and public-facing premises, are set out in our article on CCTV in the workplace and in retail.
Hidden cameras are a category apart. They are permissible only in exceptional circumstances: a concrete suspicion of serious wrongdoing, no realistic alternative, a limited period and a limited scope, and a general announcement beforehand that the employer may use covert cameras where such a suspicion arises. Even then the criminal law limits remain: filming people covertly with a concealed device in a private or enclosed space is an offence, and so is recording a conversation to which you are not a party. Where an employer wants to go down this route, the assessment should be made in advance and in writing, not reconstructed afterwards. The wider limits on technical intrusion are set out in our article on monitoring systems and the criminal law.
Vehicle tracking is lawful where it serves route planning, security of the vehicle, or a statutory registration duty, and where employees know it is fitted. Tracking outside working hours needs its own justification; if the vehicle may be used privately, the system must allow private journeys to be excluded, typically by a switch that suppresses location logging. Using tracking data to assess individual driving performance is a separate purpose and needs its own basis and its own justification.
Monitoring of email and internet traffic is best organised at the level of traffic data rather than content: which categories of site, how much traffic, which volumes of outbound data. Reading content should be reserved for a concrete incident, under a documented authorisation, and with an established procedure for setting aside evidently private messages. Keystroke logging, periodic screenshots and always-on webcam software fail the necessity test in ordinary circumstances, and an employer relying on them will usually be unable to explain what lighter measure was tried first. Systematic screening of employees personal social media accounts is not permitted at all; looking at a public post because a concrete reputational issue has arisen is a different and much narrower matter. These constraints sit within the broader framework of data protection obligations that apply to any use of analytics and automated tooling.
Monitoring people who work from home
Homeworking does not create a separate legal regime, but it changes the outcome of the balancing test, because the workplace is now a home. Continuous camera or webcam observation of a home worker is disproportionate in ordinary circumstances and Dutch courts have said so. Software that photographs the desk at intervals, or that requires the camera to stay on, intrudes into the household of the employee and of everyone else living there, and that intrusion cannot be justified by a general wish to know whether someone is at their desk.
The workable approach is to measure output and agreed availability rather than activity. Where devices are supplied by the employer, the policy should state plainly whether private use is allowed, what is logged, and what is not. Monitoring should be confined to agreed working hours; a logging system that runs day and night on a device the employee also uses privately will not survive scrutiny. The wider set of obligations that apply when staff work from home, including the duty to provide a safe workstation, is set out in our article on remote work. Practical guidance on drafting the accompanying rules is covered in our overview of monitoring policies and staff regulations.
Enforcement, evidence and what employees can do
Employees have the rights the AVG gives every data subject, and in an employment dispute they use them. A subject access request obliges the employer to provide a copy of the personal data it holds, including logging, camera images in which the employee is identifiable and monitoring reports, in principle within one month. Employees can require inaccurate data to be corrected, can object to processing based on legitimate interest, and can complain to the Autoriteit Persoonsgegevens, which can investigate, order the processing to stop and impose a fine under the AVG. Article 82 of the Regulation also gives a right to compensation for damage, including non-material damage, caused by unlawful processing. The broader catalogue is set out in our article on worker rights and in our guide to employee rights for international staff.
The sharpest consequence, however, tends to arise inside the employment case rather than before the regulator. Where an employer builds a summary dismissal or a request to terminate on material gathered through monitoring, the lawfulness of that monitoring becomes an issue in the proceedings. Dutch civil procedure does not automatically exclude unlawfully obtained evidence, and courts frequently admit it, but they can and do attach consequences: a reduced or refused reimbursement of costs, an additional award to the employee, or a finding that the employer acted in a seriously culpable manner. An employer who monitors without a basis therefore risks losing a case it would otherwise have won, as happened in the case we discuss in our note on a summary dismissal built on monitoring data that breached the GDPR.
Employers should also expect the works council, and where relevant the trade union, to raise monitoring at the point of introduction rather than afterwards. That is the moment at which the design can still be adjusted at low cost. Our overview of employee monitoring and of the general legal requirements for employers explains how the consultation fits into the wider employment framework.
What to put in place before you monitor
Work in a fixed order. Define the problem in one sentence and in concrete terms. Establish whether a lighter measure would solve it, and record why it would not. Choose the least intrusive system that does solve it, and configure it to collect the minimum, retain for the shortest period and restrict access to named roles. Carry out the DPIA where the scale or the systematic character requires it, involve the Data Protection Officer, and consult the Autoriteit Persoonsgegevens if a high residual risk remains.
Then put the paperwork in place before, not after, deployment: a monitoring protocol that staff can actually read, an entry in the register of processing activities, a processing agreement with the supplier of the system, and a written request for consent to the works council covering both the data protection regulation and the monitoring facility itself. Announce the system, give people time to ask questions, and evaluate it after the first period against the purpose you defined at the start. Monitoring that no longer serves the purpose it was introduced for should be switched off, and that decision also belongs in the file.
Law and More advises employers on the design and introduction of monitoring systems, on works council consent and substitute consent proceedings, and on the use of monitoring material in dismissal cases. We also act for employees and works councils confronted with monitoring that was introduced without a proper basis. If you are considering a monitoring system, or you have been told that your conduct at work has been recorded, contact us before the next step is taken. Our monitoring practices team works together with our privacy lawyers on these files.
Frequently asked questions
What are the legal limitations on employee surveillance in Dutch workplaces?
You cannot monitor employees without meeting specific legal requirements under the GDPR and the GDPR Implementation Act. Your organisation must have a legitimate interest that outweighs your employees’ privacy rights. You must be able to clearly justify why monitoring is necessary. The monitoring must be the least intrusive method available to achieve your goal. If you can accomplish your objective through other means that are less invasive, you must use those alternatives instead. You are not allowed to ignore your employees’ right to confidential communications. This means you cannot read emails that are clearly private or monitor personal conversations without proper justification.
How does the General data Protection Regulation (GDPR) impact employee monitoring in the Netherlands?
The GDPR requires you to conduct a data protection impact assessment (DPIA) before implementing large-scale monitoring systems. This applies when you plan to systematically track personal data through email monitoring, GPS trackers, or camera surveillance. During a DPIA, you must identify privacy risks and take measures to reduce them. If your organisation has a Data Protection Officer, you must ask them for advice on conducting the assessment. When the DPIA shows that your planned monitoring creates a high risk and you cannot find ways to reduce it, you must consult with the Autoriteit Persoonsgegevens before starting. This requirement is called prior consultation and serves as an additional safeguard for employee privacy.
Are Dutch employers allowed to read workers’ emails if the workers have been informed?
You can only read employee emails under strict conditions, even if you have informed your staff about monitoring. You must have a legitimate interest and the monitoring must be necessary to achieve a specific, justifiable goal. You cannot read emails that are evidently private. Employees retain their right to confidential communications, which means purely personal messages remain protected even when sent from work accounts. If your organisation has a works council, you must obtain its consent before implementing any email monitoring system. Without this consent, you are not allowed to proceed with the monitoring.
What measures must Dutch employers take to ensure employee privacy when implementing monitoring software?
You must inform your employees about all aspects of the monitoring before you begin. This includes what activities are allowed and prohibited, why and when monitoring will occur, how it will be conducted, and what data will be collected. Your organisation should create internal guidelines such as codes of conduct or protocols that clearly explain the monitoring policy. These documents help ensure transparency and give employees a clear understanding of their rights and obligations. You need to ensure that the monitoring software only collects data that is necessary for your legitimate purpose. Collecting more information than needed violates the necessity principle under Dutch privacy law.
To what extent can video surveillance be used in the workplace under Netherlands law?
You can use camera surveillance in the workplace only when you have a legitimate interest such as preventing theft or fraud. The surveillance must be necessary and proportionate to the goal you want to achieve. You must inform your employees that cameras are present, where they are located, and why you are using them. Hidden cameras are only permitted under additional strict conditions for covert monitoring. Cameras cannot be placed in areas where employees have a reasonable expectation of privacy, such as toilets or changing rooms. You must conduct a DPIA before implementing systematic camera surveillance in your workplace.
What rights do employees in the Netherlands have to access data collected through monitoring by their employer?
Employees have the right to access personal data you collect through monitoring. This right stems from the GDPR and allows workers to request copies of information you hold about them. You must respond to access requests within one month. The information must be provided free of charge in most cases. The data must be delivered in a clear and understandable format. Employees can also request corrections to inaccurate data. Under certain circumstances, employees may ask for deletion of their personal information. These rights apply to all forms of monitoring data, including tracking software records, GPS data, and surveillance footage.
Looking for something else? Our index of Dutch employment law guides lists everything we have written on this subject, ordered by topic.


