Can I check my employee's browsing history?

Can I check my employee's browsing history?

Employers in England and Wales can monitor staff internet use, but only if they do it lawfully and proportionately. Checking an employee's browsing history is "monitoring", and monitoring involves processing personal data, so data protection law and privacy rights apply. Done carelessly, it can lead to complaints, tribunal claims and ICO enforcement. Here is how to do it properly.

Monitoring is allowed, within limits

There is no outright ban on monitoring employees' internet use. Employers have legitimate reasons to do it: protecting their network and data, preventing misuse, and meeting legal or regulatory duties. But employees retain a reasonable expectation of privacy, recognised under Article 8 of the European Convention on Human Rights, so monitoring must be justified and proportionate.

The data protection rules you must follow

Because browsing data is personal data, the UK GDPR and Data Protection Act 2018 apply. In practice that means:

  • Lawful basis. You usually rely on legitimate interests, and must do a balancing exercise weighing your interest against the employee's privacy.
  • Transparency. Tell staff what you monitor, why and how, normally through a clear written policy. Secret (covert) monitoring is hard to justify and only acceptable in rare, serious cases.
  • Proportionality and data minimisation. Collect the least information needed for the purpose. Continuous, blanket surveillance of everything an employee does is rarely justified.
  • A Data Protection Impact Assessment (DPIA). For monitoring that is likely to be intrusive or high-risk, you should carry out a DPIA before you start.

The ICO publishes specific guidance on monitoring workers, it is well worth following.

A simple framework: be clear, communicate, control

A practical way to stay on the right side of the law:

  • Clarity, decide and document exactly what you will monitor and why.
  • Communication, tell staff in advance through an acceptable-use and monitoring policy, so there are no surprises.
  • Control, limit access to the monitoring data, keep it secure, retain it only as long as needed, and use it only for the stated purpose.

What to avoid

  • Covert monitoring without a compelling, documented justification.
  • Using monitoring data for purposes you never told staff about.
  • Monitoring special category data (such as health or trade union activity) without the extra protections the law requires.
  • Treating "we can see everything" as the same as "we may lawfully act on everything."

Key takeaways

  • You can monitor internet use, but it must be lawful, transparent and proportionate.
  • Identify a lawful basis (usually legitimate interests) and do the balancing exercise.
  • Tell staff through a clear policy; carry out a DPIA for intrusive monitoring.
  • Follow the ICO's guidance; covert monitoring is only for rare, serious cases.

Sources

  • UK GDPR and Data Protection Act 2018 (lawful basis, transparency, DPIAs)
  • Human Rights Act 1998 / Article 8 (right to respect for private life)
  • ICO guidance on monitoring workers

--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.

Back to the blog