Law and Regulation

The trigger is what a system can do, not what you intend to do with it.

This page is not legal advice, and it is not a claim of compliance. It sets out what six jurisdictions currently require of systems that could be used to monitor employees, and why an architecture that cannot attribute a response to the person who gave it meets a standard that runs through all of them. For the systems-theory case behind that architecture, see System Science and Operational Empathy.

The pattern across all six

Six jurisdictions, six different legal traditions, one shared test: scrutiny turns on what a system is capable of, not what it was built for.

JurisdictionMechanismThe triggerStatus
NetherlandsWorks council consentSuitability for monitoring, not actual use or intentIn force
GermanyCourt rulingObjective suitability for monitoring, even without recorded or identifiable dataRuled, July 2024
SwitzerlandData protection statuteThe system's default configuration, not later choices about its useIn force since September 2023
SwedenWorkplace-safety regulationOrganisational conditions like workload and hours, not individual diagnosisIn force since March 2016
DenmarkRegulator enforcement prioritiesEmployers using access logging, CCTV, GPS, or AI monitoring toolsAnnounced, January 2026
United KingdomGovernment consultationIntroducing monitoring technology without consulting workers firstConsulting, open until September 2026

01. Netherlands

Consent depends on what a system can do, not what it's used for.

The Works Councils Act requires an employer to obtain works council consent before introducing, changing, or continuing to operate any provision aimed at, or suitable for, observing or monitoring the presence, behaviour, or performance of employees (Article 27(1)(l)).

The trigger is suitability, not intent. A system built for another purpose still needs consent if it happens to be capable of monitoring individuals. Whether it is actually used that way, or whether anyone ever looks, is a separate question from whether consent was required in the first place.

See source →

02. Germany

The Federal Labour Court has already ruled on this exact question.

The Works Constitution Act gives the works council a co-determination right over the introduction and use of technical devices designed to monitor employee behaviour or performance (Section 87(1) No. 6).

In July 2024 the Bundesarbeitsgericht ruled on a warehouse headset system. It confirmed that the test is objective suitability for monitoring, not intent, and that co-determination applies even where a system does not record data and cannot identify individuals. If it is technically capable of monitoring, that possibility is what matters, not whether anyone acts on it.

See source →

03. Switzerland

The default has to already be the strict one.

Switzerland's Federal Act on Data Protection, in force since September 2023, requires data controllers to build in technical and organisational measures that ensure compliance from the outset, not add them once a problem appears (Article 7, privacy by design).

The same article requires privacy by default: a system's default configuration has to apply the strictest privacy settings available, before anyone chooses to configure it more carefully. The obligation sits with the architecture first, not with a later decision to use it responsibly.

See source →

04. Sweden

The unit of assessment moved from the person to the organisation.

The Swedish Work Environment Authority's regulation on organisational and social work environment, in force since March 2016, requires employers to systematically investigate and assess risks connected to workload, working hours, and the conditions available for recovery (Section 5).

That is a structural obligation, not a clinical one. It asks what in the organisation of work is producing strain, rather than asking who among the workforce is struggling with it. A tool that reports on conditions rather than on individuals is answering the question the regulation actually asks.

See source →

05. Denmark

The regulator has already named this as where it's looking next.

In January 2026 the Danish Data Protection Agency announced employee monitoring as a supervisory focus area for the year, with targeted inspections of employers using access logging, CCTV, GPS, and AI-based monitoring technologies.

The announcement follows a mapping exercise the agency ran across Danish workplaces in 2024. It is not a new law. It is a regulator with enforcement power saying, in advance, that this category of system is exactly what it plans to look at.

See source →

06. United Kingdom

A duty to consult before monitoring is now on the table.

In July 2026 the UK government opened a consultation, Make Work Pay: Workplace Monitoring Technologies, running to the end of September 2026. It sets out three options: non-statutory guidance, a statutory code of practice, or a legislative duty on employers to consult and negotiate with workers or their representatives before introducing monitoring technology.

None of these has been enacted. But the direction under consultation, requiring consultation before monitoring rather than disclosure after it, matches what the other five jurisdictions above already require in different forms.

See source →

07. The common direction

None of these six ask what you intended. They ask what the system can do.

The other consistent move is upward. Responsibility for psychosocial risk moves from the individual to the organisation in Sweden. Assessment moves from intent to capability in Germany and the Netherlands. Default configuration becomes a legal obligation rather than a design choice in Switzerland. Regulators are not waiting for evidence of misuse. They are building the requirement into what a system is allowed to be capable of before it is switched on.

08. The architecture argument

A system that cannot identify who said what removes the question these frameworks are built to ask.

Every framework above turns on a version of the same test: is this system capable of connecting a piece of information to an identifiable person? Works council consent in the Netherlands and Germany is triggered by suitability for monitoring individuals. Privacy by design in Switzerland is about minimising what a system can do with personal data by default. Even the softer forms, Sweden's organisational framing and the UK's proposed duty to consult, assume there is a person whose experience could otherwise be exposed.

An architecture that structurally cannot attribute a response to the person who gave it does not need a policy promising not to look. There is nothing to look at. That is also the proportionality test underneath most of this: where a legitimate purpose exists, monitoring has to use the least intrusive method available to achieve it. A method that cannot identify individuals, by design rather than by promise, is by definition less intrusive than one that could and simply chooses not to.

This is a description of what the architecture is, not a claim about any jurisdiction's paperwork. Works council consultation, data protection registration, and organisational risk assessment are separate, jurisdiction-specific obligations that this page does not resolve. What the architecture removes is the trigger these frameworks are built around: the technical capacity to identify an individual from what they said.

A note on how to read this

This page describes requirements as they stand in September 2026. Regulation in this area is moving quickly, most visibly in Denmark and the UK, where enforcement priorities and consultations are active right now. Treat every claim above as a snapshot, not a permanent statement of law, and check current guidance in your own jurisdiction before relying on it. This is not legal advice.

References

Where this comes from.

Where this goes next

The architecture is the same reason this is worth doing well.

The case for asking rather than observing is made on System Science and Operational Empathy. This page is the regulatory backdrop to that argument, not a replacement for it.

See the Delivery Friction Improvement Workshop →