Skip to content
Six Frames an Hour

All notes / Client

The Data You Now Hold

Screenshots of somebody else's machine are a holding with obligations, and most clients acquire them without noticing.

Client · Analysis

General orientation, not legal advice; obligations differ by jurisdiction.

The boundary described in “The Data You Now Hold” should be set before any tracking configuration is chosen. A team evaluating workforce analytics software for project visibility for workforce analytics software should disclose the purpose, limit access and retention, and give each person a practical way to review or correct the record.

Requiring proof of work means accumulating images of another person's screen. That is a data holding, and the client is responsible for it.

For an independent reference relevant to “The Data You Now Hold”, consult the ICO employment-practices guidance; compare its principles with the proposed contract, collection, access model and real review process.

What is in it

The contractor's working screen, including whatever else was open.

Their personal material, incidentally.

Other clients' confidential information, incidentally.

Third parties' personal data: names, addresses, records visible in the applications they were using.

And over months, a great deal of all four.

Why it is your problem

You required it, you receive it, and in most regimes you are processing personal data.

Which brings a basis requirement, a transparency requirement, retention limits and access obligations.

Most clients hiring a contractor have none of the infrastructure that usually surrounds this, and the obligations do not scale down with the organisation.

The third-party dimension

If a contractor works on systems containing other people's data, your screenshots contain it too.

Those people did not agree to that and have no relationship with you.

This is the obligation that most often stops the arrangement when somebody raises it, and it is rarely considered in advance.

The practical minimum

Decide how long you keep it, and delete on schedule.

Decide who can view it, and keep that to one or two people.

Say so to the contractor in writing.

And delete at the end of the engagement, which should be a term, and almost never is.

Where it is stored

On a platform, the platform holds it and you have access — which is simpler for you and means the record outlives your relationship.

Direct, it is on your systems, with your security and your retention.

The second is more exposure than most clients realise they took on.

The breach question

If your systems are compromised, this material goes with them.

Images of somebody's working life, their other clients' material, and third parties' data.

Which is a disclosure you would have to make and an incident you would rather not have caused, for a record nobody was reading.

The proportionate position

Keep as little as possible for as short as possible.

Intervals rather than continuous capture.

Deletion at engagement end, automatically.

None of this reduces the assurance you were buying, because that assurance came from the arrangement existing rather than from the archive.

What to check

How long do you keep proof-of-work material?

Who can view it?

Does your contract say anything about deletion?

And does any of it contain third parties' data?