A missing six-minute entry looks harmless until it happens across 30 people, five client accounts and every working day of the month. Professional services firms need dependable time data, but they also need to respect the people producing it. So, does employee monitoring require consent? In the UK, usually not in the simple sense employers expect. But that does not give a business permission to watch everything, collect anything or introduce monitoring quietly.
The real test is whether monitoring is lawful, necessary, proportionate and clearly explained. Get that wrong and a tool intended to protect margin can create an employee-relations problem, a data protection risk and a trust deficit that costs more than the lost time ever did.
Does employee monitoring require consent under UK law?
Employee consent is rarely the strongest legal basis for workplace monitoring. The power imbalance in employment means staff may feel unable to refuse, even when a form says consent is voluntary. Under UK data protection law, consent must be freely given, specific, informed and easy to withdraw. That is difficult to demonstrate when refusing could appear to put someone’s job at risk.
For most organisations, monitoring is more likely to rely on legitimate interests, or occasionally on the performance of a contract or a legal obligation. A firm may have a legitimate interest in recording billable work accurately, protecting confidential client information, managing security risks or understanding project profitability. But an interest is not a blank cheque.
You must balance the business need against the impact on employees’ privacy. Monitoring should go no further than needed to achieve a defined purpose. If client-time allocation can be established from work patterns without recording private messages, keystrokes or screen content, the less intrusive route is usually the smarter one.
That distinction matters. Consent may still be relevant in narrow, genuinely optional situations, such as a voluntary wellbeing feature that is separate from employment decisions. It is not the default answer for ordinary workplace monitoring.
Transparency is not optional
The practical requirement is not a signature buried in an onboarding pack. It is transparency. Staff should know what data is collected, why it is collected, how it is used, who can access it, how long it is retained and whether it informs performance, disciplinary or pay decisions.
For a client-service firm, that explanation should be concrete. Saying “we monitor computer use” is vague and alarming. Saying that the organisation uses work activity signals to help allocate time to client matters, improve billing accuracy and reduce retrospective timesheet admin is clearer. It also forces leaders to define what the system is actually for.
Your privacy notice and monitoring policy should address the reality of the tool, not a watered-down version of it. If activity records are reviewed by managers, say so. If data is aggregated for utilisation reporting, say so. If the system does not capture the content of emails, passwords or personal browsing, say that too.
Clear communication is not merely a compliance exercise. People are more likely to accept automated time capture when it removes tedious timesheets rather than acting as a digital stopwatch over every minute of their day.
Start with the business problem, not the surveillance feature
Legacy time tracking asks people to remember what they did after a day of calls, documents, meetings and client interruptions. The predictable result is reconstructed timesheets, generic entries and revenue that is never billed. That failure is operational, not moral.
The wrong response is to install the most invasive monitoring software available. Screenshots every few minutes, webcam checks and keystroke counts may create a volume of data, but they do not necessarily create accurate client allocation. They can also punish legitimate work that happens away from a keyboard: thinking, reading, speaking with a client, sketching a solution or attending site.
A better approach starts with a precise question: what information do we need to allocate work accurately and run the business well? For many firms, the answer is high-level application and project context, combined with staff review and sensible controls. It is not a permanent recording of every digital movement.
This is where eppiq Timer takes a different route from timer-led tracking. Client Time Intelligence is designed to recognise work patterns and suggest client allocation, reducing reliance on memory without turning productive professionals into suspects.
Carry out a DPIA before introducing intrusive monitoring
A Data Protection Impact Assessment, or DPIA, is often required where processing is likely to create a high risk to individuals’ rights and freedoms. Systematic monitoring of staff, especially at scale or where detailed behavioural data is involved, can meet that threshold.
Even where you conclude a DPIA is not legally mandatory, completing one is sound operational discipline. It makes the decision-makers confront the questions that matter before the software is live and the data has started accumulating.
A useful DPIA should document the purpose of the monitoring, the data categories involved, the people affected, the expected benefits and the possible harm. It should test alternatives. Could less data achieve the same billing outcome? Could records be pseudonymised for reporting? Could managers see summaries rather than granular activity by default?
It should also set safeguards: role-based access, short retention periods, encryption, manager training, audit trails and a process for employees to query inaccurate records. Machine-led suggestions are not automatically correct. Staff need a meaningful way to review and correct time attribution, particularly where it may influence performance conversations or client invoices.
Covert monitoring is the exception, not a shortcut
Covert monitoring is highly sensitive. It may be justifiable in exceptional circumstances, usually where there is a reasonable suspicion of serious criminal activity or gross misconduct and telling staff would undermine an investigation. It should be targeted, time-limited and authorised at the appropriate senior level.
It is not a remedy for late timesheets, low utilisation or a manager’s general anxiety about remote work. Using covert monitoring to solve ordinary management problems is likely to be disproportionate and corrosive to trust.
If you are considering it, seek specialist employment and data protection advice before acting. The commercial desire for certainty does not remove the legal and human consequences.
Build a monitoring policy people can understand
A usable policy beats a dense legal document that nobody reads. It should explain that the organisation collects only what it needs, applies the same rules consistently and does not use time data as an automatic verdict on effort or value.
Before rollout, consult employees or their representatives where appropriate. Consultation can expose practical issues leadership has missed: shared devices, work on personal phones, accessibility needs, client confidentiality constraints, hybrid schedules and roles where computer activity tells only part of the story. For larger firms, involve HR, IT, information security, finance and the operational leaders who understand how client work is actually delivered.
Managers need training as well. A dashboard can identify unusual patterns; it cannot explain them. A solicitor may spend an hour reading a complex bundle. An architect may be in a workshop. An accountant may be discussing a client’s records by phone. Treating a low-activity metric as proof of poor performance is bad management dressed up as data.
A proportionate rollout checklist
Before enabling any employee monitoring capability, make sure you can answer five questions clearly:
- What specific business outcome are we trying to achieve?
- What is the least intrusive data needed to achieve it?
- What lawful basis and balancing assessment support the processing?
- How will employees be told, consulted and able to challenge errors?
- When will we delete the data, and who is permitted to see it?
If the answers are vague, the monitoring design is not ready. Do not hide uncertainty behind a broad consent form. Fix the purpose, controls and communication first.
The firms that gain the most from time intelligence do not treat privacy as an obstacle to accurate billing. They treat it as a design constraint that produces a better system: less manual admin, fewer invented timesheets, tighter client visibility and a working relationship built on clarity rather than suspicion. That is the standard worth setting before the first minute is captured.
