Employment & HR · Workplace privacy
IT monitoring policy for employees and remote work
Companies may have legitimate reasons to protect data, accounts and infrastructure, including when staff work remotely. Monitoring is not lawful merely because it is technically possible. The purpose, tools, affected persons, data collected, access and retention must be assessed before activation and explained to employees.
Security is not a blank cheque
The employer must define specific purposes: preventing exfiltration, investigating incidents, service continuity or system protection. Statements such as ‘for any company interest’ do not allow a genuine necessity assessment.
Law No. 190/2018 sets special conditions for electronic-communications monitoring or video surveillance based on legitimate interests: justified interest, explicit information, consultation, assessment of less intrusive alternatives and proportionate storage duration.
What data are collected and who sees them
The policy must describe tools — login logs, EDR, web filtering, DLP, business email, VPN or equipment location — without ambiguities that would surprise employees.
- each tool’s purpose and data categories;
- events triggering human review;
- authorised roles and access logging;
- retention periods and criteria for exceptions;
- external recipients, transfers and providers used;
- data subject rights and contact channel.
Proportionality, DPIA and investigations
Continuous content monitoring, screenshots, keylogging, cameras or precise location are highly intrusive and require exceptionally strong justification. Alternatives often exist: access controls, data segregation, event-based alerts or targeted audits.
Where processing is likely to result in high risk, an impact assessment must precede implementation. Subsequent investigations must respect purpose, restricted access, evidence integrity and the right of defence.
Remote work: security without invading privacy
The policy must separate professional use from private life: approved devices, accounts, updates, VPN, Wi-Fi, local storage, paper documents and incident reporting. BYOD requires special rules on containerisation and deletion of company data.
Employees must know what the company can see, when it may intervene remotely and what happens when employment ends. Technical measures must align with telework, occupational health and safety and working-time records.
How we work together
- 01Assessment of the situation
We clarify the organisation’s structure, existing documents, internal practice and risks relevant to the monitoring and remote-security policy.
- 02Designing the solution
We establish the appropriate legal mechanism and align it with actual workflows, responsibilities and systems.
- 03Drafting documents
We prepare the main document, schedules and implementation instructions coherently and accessibly.
- 04Implementation and handover
We review comments, deliver the final version and explain signing, communication, registration or application steps.
Frequently asked questions
Can I read an employee’s business email?+
Access should not be treated as implicit. Purpose, conditions, information, authorised persons and a proportionate procedure must be defined, including for absences or investigations.
Does employee consent solve the problem?+
Generally, the imbalance in employment makes consent a fragile legal basis. The employer must identify the appropriate basis and respect every applicable safeguard.
Is screenshot-based productivity monitoring permitted?+
This is highly intrusive. It must be shown why it is necessary, why less intrusive alternatives do not work and how frequency, access and retention are restricted.
Need a proportionate IT monitoring policy?
Send relevant information and documents for a legal assessment and a solution tailored to your organisation.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
