Notice, in advance and in writing
Several US states and most EU member states require employees to be told before endpoint monitoring begins. Retroactive disclosure does not cure a deployment that started quietly.
Answers
Generally yes on company-owned devices and accounts, subject to conditions that vary considerably by jurisdiction: advance written notice in many US states and EU member states, purpose limitation, data minimisation, and works council consultation in several EU countries.
The four conditions
The details differ everywhere. The shape does not.
This is not legal advice. It is a summary of the considerations that come up repeatedly, written to help you ask your counsel better questions. The answer genuinely differs by country, by US state, and by whether you have a works council. Reviewer to be named
Several US states and most EU member states require employees to be told before endpoint monitoring begins. Retroactive disclosure does not cure a deployment that started quietly.
Monitoring deployed to prevent data loss should be used to prevent data loss. Repurposing the telemetry for performance management is where organisations get into difficulty.
Collect what the purpose requires and no more. This is the condition most directly affected by which product you choose.
Company-owned devices, company accounts, business use — published, so employees know where the boundary is.
Architecture is a legal question
A DLP product that transmits the raw prompt to a server for inspection is collecting the full content of employee communications, including whatever personal content they typed. A product that detects locally and transmits a redacted event record collects a data type, a count, a confidence score, a masked snippet and a destination.
Both achieve the stated purpose. Only one is the less intrusive means — and “could you have achieved this with less?” is precisely the question a DPIA asks.
When an administrator cannot read an employee’s messages because the system never received them, the proportionality analysis becomes materially easier.
Jurisdictions
European Union. GDPR applies to employee monitoring as processing of personal data. Expect a lawful basis (usually legitimate interest with a documented balancing test rather than consent), a DPIA for systematic monitoring, transparency obligations, and national employment law on top. Works council consultation is required in several member states and should start before the technical work.
United States. Primarily state by state. A number of states have specific electronic monitoring notice requirements, and the list changes. Sectoral rules may also bear on how the monitoring data itself is handled.
United Kingdom. UK GDPR plus the ICO’s employment practices guidance; similar shape to the EU, without the works council mechanism.
Elsewhere. Canada, Australia and Brazil all have distinct regimes. Do not generalise from the US or EU position.
Sequence
The legal work is the long pole, not the deployment. Run them in parallel and start the slowest first.
And write it down, because everything downstream is measured against it.
That decision is now part of your DPIA rather than an implementation detail.
Not after an incident.
In parallel with the DPIA. It will be the longest pole.
This reduces legal risk and materially improves adoption.
Then warn, then block.
And re-run the assessment whenever scope changes.
Straight answers
In most employment contexts consent is a weak legal basis, because it cannot be freely given where there is a power imbalance. Legitimate interest with documented balancing, plus transparent notice, is the more common footing.
In several EU countries, works council consultation is required before deploying endpoint monitoring. It commonly takes longer than the technical rollout, so start it first.
It should. A tool that transmits raw prompt content collects far more personal data than one that transmits a redacted event record, and the minimisation principle asks whether the less intrusive option would have achieved the same purpose.
Treat that as out of scope. Monitoring personal hardware raises materially different legal questions and is rarely defensible. Itzal targets company-owned devices and company accounts by design.
The architecture section is usually the shortest part of the assessment, and we can help you write it.