Legal position last verified: 1 September 2026.
An employer may monitor email, devices, CCTV or security logs for legitimate business purposes, but monitoring is not unlimited. It requires a defined purpose, legal basis, necessity, proportionality, prior transparency, access controls and retention limits. Intrusion into personal communications or continuous location tracking may be unlawful where a less intrusive method would achieve the purpose.123
This is a policy and investigation guide for HR, legal, DPO, CISO, internal-investigation and remote-work teams.
Core conclusion: Workforce monitoring should be designed through a purpose–data–access–retention–evidence chain, not the assumption that company ownership of a device permits unrestricted access.
Who is this guide for?
This is a policy and investigation guide for HR, legal, DPO, CISO, internal-investigation and remote-work teams.
Decision summary in one minute
| Tool | Legitimate purpose example | High risk | Control |
|---|---|---|---|
| Email/logs | Security/continuity | Content and private messages | Metadata-first, authorised access |
| CCTV | Security | Audio, rest areas, continuous tracking | Location and retention limits |
| Location | Field safety/routing | Off-hours tracking | Working-time limitation |
| DLP/EDR | Leak/malware prevention | Excessive content capture | Incident-based review |
| BYOD | Corporate access | Mixing personal and business data | Container/MDM separation |
| Productivity tools | Resource planning | Continuous scoring and pressure | Aggregated/anonymous metrics |
1. The legal test: purpose, necessity and proportionality
An employer may invoke security, continuity, performance, legal duty or investigation, but each purpose needs a tailored data set and method. Security is not a universal justification.45
Where a less intrusive measure works, content review or continuous surveillance is difficult to justify. An impact assessment should record purpose, alternatives, risk, access, retention and challenge routes.67
2. Email and device review
Employees should be told that corporate email is monitored, the limit of personal use and when content may be accessed. Routine governance should use metadata and security signals before full content.89
Investigations should limit persons, dates, keywords and reviewers, with filters for legal privilege, union, health and private-life information. Evidential use requires lawful collection and integrity records.1011
3. CCTV, audio and location
CCTV may support security at entrances, warehouses or production zones; changing/rest areas or continuous desk surveillance are far more intrusive. Audio recording generally requires a distinct and stronger necessity case.12
Vehicle or mobile location should be limited to work and working time, with off-hours tracking disabled. Turning location into performance scoring requires separate transparency and proportionality.13
4. BYOD and remote access
Business and personal data should be separated on personal devices. MDM, containers, remote wipe, operating-system baseline, encryption, backup and support access require policy and technical limits.14
Remote wipe should not erase all personal content. At exit, corporate data should be removed without copying personal material, and incident review should target the business container.15
5. DLP, EDR and productivity analytics
DLP and EDR are powerful for malware and leakage, but continuous collection of screens, keystrokes, files and communications can become workforce profiling. Threshold- and incident-based review is preferable.16
Productivity scores should not reduce work quality and collaboration to clicks or active time. Human review and challenge should precede disciplinary or dismissal decisions.17
6. Policy, transparency and evidence chain
Policy should identify tools, purposes, data, reviewers, retention, employee rights and incident process. Generic notice that “all monitoring may occur” is insufficient.1819
A disciplinary file records source, timestamp, user, hash, reviewers and interpretation. A technical alert does not itself prove intent or fault; employee explanation and context matter.2021
Documents and evidence the company should prepare
- Monitoring-tool inventory
- Purpose/legal-basis/proportionality matrix
- Employee notice and policy
- Email/CCTV/location procedure
- BYOD and MDM settings
- DLP/EDR incident workflow
- Investigation and evidence chain
- Retention and access records
Contract and governance controls
- Business and limited personal use
- Monitoring tools and purposes
- BYOD security requirements
- Remote access/wipe
- Investigation cooperation
- Confidentiality and data security
- Employee rights/challenge
- Exit device and data handling
Red flags and recurring mistakes
- Unlimited content access because device is company-owned
- Unjustified CCTV audio
- Off-hours location tracking
- Wiping entire BYOD device
- Automatic dismissal from productivity scores
- Using undisclosed tools
- No log-integrity evidence
Three practical scenarios
1. Email review after suspected data leakage
After a DLP alert, review is limited to relevant dates, user and file movements; content access is confined to authorised legal/security reviewers with chain-of-custody records.
2. Location tracking for field personnel
Location is active only during shifts for routing and safety, disabled off-hours, retained briefly and not used as the sole performance source.
3. BYOD exit process
The corporate container is removed remotely without accessing personal photos or messages, with evidence that business data and tokens are deleted.
A 30–60–90-day implementation plan
Days 1–30 — scope and visibility
- Build the employee monitoring and BYOD scope and role matrix.
- Collect the relevant contracts, permissions, data and decision records.
- Assign owners to urgent gaps and threshold questions.
Days 31–60 — evidence and contracting
- Complete missing permissions, policies, schedules and records.
- Obtain management approval for the decision matrix.
- Test group-company and supplier flows against the chosen model.
Days 61–90 — testing and governance
- Run a practical scenario or tabletop exercise.
- Report open risks with owners and closure dates.
- Establish annual and event-driven review triggers.
Frequently asked questions
May an employer read employee email?
A limited review may be possible for a specific legitimate purpose with prior transparency, necessity and proportionality.
Can personal use of company devices be banned?
Policy may set limits, but the rule should be clear and consistently applied.
Can CCTV record audio?
Audio is more intrusive and requires a separate, strong necessity and proportionality case.
May location be tracked off-hours?
Usually not; tracking should be confined to working time absent an exceptional justification.
Can an entire BYOD device be wiped?
Corporate-container deletion is preferable; erasing personal content creates serious risk.
Does employee consent permit any monitoring?
No. Power imbalance and proportionality mean consent is not a universal solution.
Can unlawfully obtained logs support dismissal?
Lawfulness, integrity and employment-law requirements must be assessed.
When should monitoring policy be updated?
On new tools, purposes, work models or regulatory/judicial developments, and periodically.
Conclusion
A strong monitoring programme collects the minimum data needed for the purpose and preserves it as reliable evidence. Aligning policy, technical settings and investigations protects both security and workforce privacy.
Legal information notice
This article provides general information only. It is not a legal opinion for a particular company, transaction, tax position, licence application or dispute. Applicable sector, tax, employment and regulatory rules require a fact-specific review.
Bibliography
- Kişisel Verilerin Korunması Kanunu No 6698 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf
- İş Kanunu No 4857 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf
- Big Data in the Workplace: Privacy Due Diligence — https://doi.org/10.1177/20539517211013051
- Regulation (EU) 2016/679 (GDPR) — https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB Guidelines 07/2020 on Controller and Processor — https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en
- Türk Borçlar Kanunu No 6098 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6098.pdf
- Uluslararası İşgücü Kanunu No 6735 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6735.pdf
- Why a Right to Explanation of Automated Decision-Making Does Not Exist in the GDPR — https://doi.org/10.1093/idpl/ipx005
Footnotes
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
-
Big Data in the Workplace: Privacy Due Diligence https://doi.org/10.1177/20539517211013051 accessed 1 September 2026. A process-based privacy due-diligence model for employee monitoring.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Big Data in the Workplace: Privacy Due Diligence https://doi.org/10.1177/20539517211013051 accessed 1 September 2026. A process-based privacy due-diligence model for employee monitoring.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Big Data in the Workplace: Privacy Due Diligence https://doi.org/10.1177/20539517211013051 accessed 1 September 2026. A process-based privacy due-diligence model for employee monitoring.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Big Data in the Workplace: Privacy Due Diligence https://doi.org/10.1177/20539517211013051 accessed 1 September 2026. A process-based privacy due-diligence model for employee monitoring.↩︎
-
Big Data in the Workplace: Privacy Due Diligence https://doi.org/10.1177/20539517211013051 accessed 1 September 2026. A process-based privacy due-diligence model for employee monitoring.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
