Policy templates
No-surveillance monitoring policy template
Most monitoring policies list what the employer may do. This one lists what it will not do, which is the half employees actually want in writing.
Opens in Excel, Google Sheets, Numbers and LibreOffice — no conversion needed.
Document structure — headings and sections
Preview
The opening of the document. Every bracketed value is meant to be replaced.
# No-Surveillance Monitoring Policy — Template > Replace every **[bracketed]** value before use. This template states what an > employer will and will not collect about how people work. It is drafted to sit > alongside an attendance policy, not to replace one. Not legal advice — review > with counsel before issuing. ## 1. Why this policy exists **[Company name]** records working time because it is required by law, because pay depends on it, and because client work is billed against it. It does not record working time in order to observe how individuals spend their day. This policy states the boundary explicitly so that employees do not have to guess, and so that any future proposal to widen collection has to be measured against a published commitment. ## 2. What we collect - The start and end time of each work session. - The project, client or activity a session relates to. - Breaks taken, according to the configured policy. - Approval status and the identity of the approving manager. - Leave applied for, approved and taken. ## 3. What we do not collect **[Company name]** does not, as part of workforce monitoring: - Capture screenshots or record screen contents. - Log keystrokes or clipboard contents. - Record application or website usage. - Score "activity levels", idle time, or mouse and keyboard frequency. - Track continuous location, or any location outside working hours. - Capture biometric identifiers such as fingerprints or face templates. - Access personal devices, personal accounts or personal communications. - Operate any monitoring software that is hidden from the person using the device. ## 4. Why the boundary sits here Under the Digital Personal Data Protection Act, 2023, personal data must be processed for a specified lawful purpose and limited to what that purpose requires. Attendance, payroll and billing are achievable from session records. Screen contents and activity telemetry collect substantially more personal data — including data belonging to third parties — without improving the accuracy of what we actually need.
How to use it
- →Publish it alongside the attendance policy rather than burying it in an IT acceptable-use document.
- →The 'what we do not collect' list is the substance — do not soften it into vague language, or it commits to nothing.
- →If you later need to expand collection, section 7 sets the process: document the purpose, the alternatives considered, and the retention period.
Before you rely on it
Drafting starting point, not legal advice. Under the DPDP Act, 2023, processing must be limited to what a specified lawful purpose requires — a published boundary helps demonstrate that, but does not replace a proper assessment.
When the spreadsheet stops scaling
A template is the right answer until the reconciliation between sheets costs more than the sheets save. Workclave records the same data as work happens, applies your policy automatically, and produces the register, the payroll input and the client hours statement from one source. Free for up to 3 users.
Ihr Team arbeitet. Fangen Sie an zu verstehen, wie.
Schließen Sie sich Teams an, die Sitzungen erfassen statt bloßer Zeit. Kostenlos bis 3 Nutzer — ohne Kreditkarte, ohne Mindestabnahme, ohne Bindung.