Policy templates

No-surveillance monitoring policy template

Most monitoring policies list what the employer may do. This one lists what it will not do, which is the half employees actually want in writing.

Get the MD

Leave an email if you would like us to tell you when this template is updated. Optional — the download works either way.

Skip and download

One email about this template. No drip sequence, no sharing with anyone else. See our privacy policy.

Opens in Excel, Google Sheets, Numbers and LibreOffice — no conversion needed.

Document structure — headings and sections

Preview

The opening of the document. Every bracketed value is meant to be replaced.

# No-Surveillance Monitoring Policy — Template

> Replace every **[bracketed]** value before use. This template states what an
> employer will and will not collect about how people work. It is drafted to sit
> alongside an attendance policy, not to replace one. Not legal advice — review
> with counsel before issuing.

## 1. Why this policy exists

**[Company name]** records working time because it is required by law, because
pay depends on it, and because client work is billed against it. It does not
record working time in order to observe how individuals spend their day.

This policy states the boundary explicitly so that employees do not have to
guess, and so that any future proposal to widen collection has to be measured
against a published commitment.

## 2. What we collect

- The start and end time of each work session.
- The project, client or activity a session relates to.
- Breaks taken, according to the configured policy.
- Approval status and the identity of the approving manager.
- Leave applied for, approved and taken.

## 3. What we do not collect

**[Company name]** does not, as part of workforce monitoring:

- Capture screenshots or record screen contents.
- Log keystrokes or clipboard contents.
- Record application or website usage.
- Score "activity levels", idle time, or mouse and keyboard frequency.
- Track continuous location, or any location outside working hours.
- Capture biometric identifiers such as fingerprints or face templates.
- Access personal devices, personal accounts or personal communications.
- Operate any monitoring software that is hidden from the person using the device.

## 4. Why the boundary sits here

Under the Digital Personal Data Protection Act, 2023, personal data must be
processed for a specified lawful purpose and limited to what that purpose
requires. Attendance, payroll and billing are achievable from session records.
Screen contents and activity telemetry collect substantially more personal data —
including data belonging to third parties — without improving the accuracy of
what we actually need.

How to use it

  • Publish it alongside the attendance policy rather than burying it in an IT acceptable-use document.
  • The 'what we do not collect' list is the substance — do not soften it into vague language, or it commits to nothing.
  • If you later need to expand collection, section 7 sets the process: document the purpose, the alternatives considered, and the retention period.

Before you rely on it

Drafting starting point, not legal advice. Under the DPDP Act, 2023, processing must be limited to what a specified lawful purpose requires — a published boundary helps demonstrate that, but does not replace a proper assessment.

When the spreadsheet stops scaling

A template is the right answer until the reconciliation between sheets costs more than the sheets save. Workclave records the same data as work happens, applies your policy automatically, and produces the register, the payroll input and the client hours statement from one source. Free for up to 3 users.

● Más de 740.000 pymes tecnológicas siguen sin dar el paso

Tu equipo ya está trabajando. Empieza a entender cómo.

Únete a los equipos que ya registran sesiones, no solo tiempo. Gratis hasta 3 usuarios: sin tarjeta, sin mínimos y sin permanencia.

Gratis hasta 3 usuariosPreparado para el RGPDCancela cuando quieras