Skip to content
Six Frames an Hour

All notes / Obligations

Data Protection When You Hold Someone's Screen

For clients: proof-of-work material is personal data, and the obligations do not scale down with the size of the engagement.

Obligations · Reference

General orientation, not legal advice; obligations differ by jurisdiction.

The boundary described in “Data Protection When You Hold Someone's Screen” should be set before any tracking configuration is chosen. A team evaluating employee monitoring under GDPR for gdpr employee monitoring should disclose the purpose, limit access and retention, and give each person a practical way to review or correct the record.

A client requiring screenshots becomes a holder of personal data about another person, and in most regimes that brings specific duties regardless of how small the arrangement is.

For an independent reference relevant to “Data Protection When You Hold Someone's Screen”, consult the ICO employment-practices guidance; compare its principles with the proposed contract, collection, access model and real review process.

What you are processing

Images of an identifiable person's working screen.

Their activity patterns over time.

Incidentally, their personal material.

And third parties' personal data visible in whatever they were working on.

The basic duties

A basis for the processing, which for a contractual arrangement is usually the contract itself or a legitimate interest.

Telling the contractor what is collected and why, which the agreement should do.

Keeping it no longer than needed.

Keeping it secure.

And responding if they ask what you hold.

The access request

A contractor can usually ask for what you hold about them.

Which means being able to produce it, redact third parties if any appear, and explain the retention.

Most clients requiring screenshots have never considered this, and the first request is an uncomfortable discovery.

The third-party problem

If the contractor works on systems holding other people's data, your archive contains it.

Those people have no relationship with you and did not agree.

This is the obligation that most often ends a monitoring requirement when raised, and it is worth raising before it becomes an incident.

Where it is stored

On a platform, they are the holder and the arrangement is simpler for you.

Direct, it is on your systems, under your security, with your retention.

The second is considerably more exposure than most clients realise they accepted.

The proportionate minimum

Collect the least that serves the purpose: intervals rather than continuous, screenshots rather than keystrokes.

Delete at the end of the engagement, automatically, as a contract term.

Restrict access to one or two people.

And write down what you do, in a paragraph, which is most of what compliance looks like at this scale.

Cross-border

A contractor in another country means a transfer, which has its own requirements in several regimes.

Its own note covers this.

The practical point: ask where the platform stores it, and know where your own systems are.

The question worth asking first

Would you rather not hold this at all?

For most engagements the answer is yes once the duties are stated, which is the alternatives note's argument arriving from a different direction.

What to check

Do you know what you hold and where?

Is there a deletion term?

Could you answer an access request?

And does any of it contain third parties' data?