Skip to content

Ελληνικά

Employee monitoring and proportionality in Cyprus

The short answer

The one test that decides it

The reasoning is easiest to see in the case the Commissioner actually decided. Faced with biometric clock-in, the DPC did not object to technology as such; it asked whether a less intrusive method would achieve the same purpose, found that ordinary attendance could be captured by a card system, unannounced supervisor checks, a supervisor present, or a camera positioned over the card reader, and concluded that a biometric system was therefore disproportionate. [1] Strip out the biometrics and the shape of the test is general: name the legitimate purpose, ask what the least-intrusive means of achieving it is, and adopt that means rather than a more invasive one. Applied to monitoring at large, the same three steps recur: state the purpose precisely, list the less-intrusive options honestly, and justify any step up in intrusiveness by a purpose the gentler option genuinely could not serve.

The EU authority supplies the missing verbs. The Article 29 Working Party requires the proportionality assessment be carried out before any monitoring tool is deployed: whether the processing is necessary and proportionate is answered first, and a tool that fails is not installed. [3] The same opinion sets a default that quietly rules out a great deal of routine surveillance: that data processing at work should favour prevention over detection, so the benefit an employer gains from catching wrongdoing after the fact rarely justifies monitoring everyone continuously in case it happens. And it puts the consent question beyond doubt at EU level: because of the dependency inherent in the employment relationship, employees are almost never able to give, refuse or revoke consent freely, so consent can serve as a lawful basis only in the exceptional situation where accepting or declining carries no consequence at all. [3] This is the same conclusion the Cyprus Commissioner reached (that employee consent does not rescue a disproportionate measure, because consent in the workplace is not freely given), now backed by the pan-European regulators rather than resting on the national opinion alone. [1] A monitoring practice that fails the necessity test is not cured by a signature. Proportionality is a discipline of restraint, run before deployment, not a box you tick once the decision is made.

Tell people, or lose the argument

Hidden monitoring is hard to defend, and covert surveillance sits at the far, intrusive end of any proportionality analysis. The workable default is openness: tell employees what is monitored, why, and how the resulting data is used, so the monitoring is something they are informed of rather than something done to them behind their backs. Transparency is not just courtesy: it feeds straight into proportionality, because a purpose that could be served by a monitoring practice employees are told about will rarely justify a covert one, and covert monitoring only deepens the intrusion the necessity test is weighing. Practical transparency looks ordinary: a clear notice or policy describing the cameras, location features or access logs in use, their purpose, and their retention; signage where spaces are filmed; and honesty about what is not monitored as much as what is. Because the whole point is to keep monitoring to the least-intrusive means that achieves the purpose, being open about the practice is part of keeping it proportionate, not a separate afterthought. [1]

Transparency and monitoring are not stray concerns; the GDPR names them together as the heart of the employment-data problem. Article 88(2) provides that where Member States lay down specific rules for processing employees' data, those rules must include suitable and specific measures to safeguard the worker's human dignity, legitimate interests and fundamental rights, with particular regard to the transparency of processing, transfers within a group of undertakings, and, expressly, monitoring systems at the workplace. [4] That the drafters named transparency and workplace monitoring in the same short list is a strong signal that openness about monitoring is exactly where the Regulation expects the safeguards to bite. The same transparency duty governs ordinary attendance records, which we cover in detail in our guide to GDPR and attendance data; monitoring simply raises the stakes of getting it right.

What it means for cameras, GPS and the clock-in

The principle gets concrete when you walk it across the common methods. Attendance: recording who worked and when is a low-intrusion purpose a card, fob, QR code or PIN already serves, so a more invasive method is hard to justify. This is not a case the EU authority overlooked: the Article 29 Working Party gives time-and-attendance processing a section of its own, warning that new tracking technologies, including those processing biometric data, can form part of an employer's audit trail yet risk an invasive level of knowledge and control of what employees do in the workplace; its pre-deployment necessity-and-proportionality test therefore reaches the clock-in itself, not only cameras and trackers. [3] And where the attendance mechanism is biometric, the intrusion rises sharply, because a fingerprint or face used to identify a person is a special category of data, prohibited in principle unless an Article 9(2) condition applies, which routine attendance will struggle to meet. The full analysis is in our dedicated guide to biometric attendance in Cyprus. [1] [5] Location and GPS: tracking a vehicle or device can be legitimate for a genuine operational purpose, but proportionality asks you to hold it to what that purpose needs: working hours rather than around the clock, coarse rather than continuous where that will do, and never as a proxy for general surveillance of the person. Cameras: CCTV for premises security is a familiar, often justifiable purpose, yet the same restraint applies to placement, coverage and retention, and a camera trained on a workstation to watch productivity is a different, far harder case than one covering an entrance. Across all three the through-line is identical: the least-intrusive means that achieves a named purpose; and where any of these is high-risk, particularly where new technologies or special-category data are involved, an impact assessment must be completed before it starts. [2] [5]

Quick answers to the questions owners ask

Is employee monitoring allowed in Cyprus at all?

Yes, within limits. Monitoring must be necessary and proportionate to a genuine purpose, using the least-intrusive means that achieves it: the same test the Commissioner applied to biometric attendance, and the one the Article 29 Working Party set for all data processing at work. [1] [3]

When do we run the proportionality test: before or after?

Before. The Working Party is explicit that the necessity-and-proportionality assessment must be carried out before a monitoring tool is deployed, so it is a gate on the decision, not a justification assembled afterwards. [3]

Can we monitor more if employees consent?

Be careful. The Commissioner's view is that workplace consent is not freely given, and the Working Party reached the same conclusion at EU level: employees can almost never consent freely, so a signature does not rescue a monitoring practice that fails the necessity and proportionality test. [1] [3]

Can we watch everyone continuously to catch the occasional problem?

Rarely. The Working Party's default is that prevention should be favoured over detection, so blanket, continuous monitoring aimed at catching infrequent wrongdoing will usually be disproportionate to the risk. [3]

Can we put GPS tracking on company vehicles?

Potentially, for a genuine operational purpose, but proportionality holds it to what that purpose needs, for example working hours rather than continuous, round-the-clock tracking of the person, applying the same least-intrusive-means test the Commissioner set out for biometric attendance. [1]

Do we need a DPIA before installing monitoring?

Where the monitoring is high-risk (particularly involving new technologies or special-category data such as biometrics): yes, an impact assessment must be carried out before processing begins. [2] [5]

Can we use cameras to watch how hard people are working?

That is a hard case. Productivity surveillance is far more intrusive than security-focused CCTV, and a purpose a less-intrusive method could serve will struggle to justify it under the proportionality test the Commissioner set out for biometric attendance. [1]

This article is general guidance on the proportionality principle in Cyprus workplace monitoring, not legal advice for your specific situation. Every legal statement above is footnoted to a primary source you can read in full on our sources and references page.

References

  1. Γνώμη 2/2018 για ΚΚΒΠ και βιομετρικά στο χώρο εργασίας (Opinion 2/2018 on CCTV and biometrics in the workplace) . Office of the Commissioner for Personal Data Protection (Cyprus), 2018-10-19 (CY)
  2. Regulation (EU) 2016/679 (GDPR), Article 35 — Data protection impact assessment . European Union (Official Journal L 119), 2016-04-27 (EU)
  3. Opinion 2/2017 on data processing at work (WP249) . Article 29 Data Protection Working Party, 2017-06-08 (EU)
  4. Regulation (EU) 2016/679 (GDPR), Article 88 — Processing in the context of employment . European Union (Official Journal L 119), 2016-04-27 (EU)
  5. Regulation (EU) 2016/679 (GDPR), Article 9 — Processing of special categories of personal data . European Union (Official Journal L 119), 2016-04-27 (EU)