Monitoring that survives a works-council review
Few markets test a workforce-analytics product like Germany. A works council can veto a tool outright, and many do. The rollouts that survive share a pattern that has nothing to do with clever legal drafting and everything to do with what the software refuses to collect.
“The strongest privacy argument is not a policy document. It is a field that was never collected.”
Why the default answer is no
A Betriebsrat exists to protect employees from exactly the kind of tool we build. Under German co-determination law, any system capable of monitoring performance or behaviour requires works-council agreement before deployment. Councils have seen keyloggers marketed as wellness tools. Their scepticism is earned.
The first meeting is therefore adversarial by design, and that is fine. We have sat in perhaps thirty of these sessions alongside customers. The councils that eventually said yes did not soften because of charm. They said yes because every uncomfortable question had a concrete, verifiable answer.
If your vendor cannot show a council exactly what leaves the laptop, byte by byte, the review will fail and deserve to.
Minimisation is architecture, not policy
GDPR’s data-minimisation principle is usually treated as a paragraph in a privacy notice. Works councils treat it as an engineering audit. Their question is never whether you promise not to look at something. It is whether the data exists at all.
This is why Momentum’s agent classifies locally and transmits categories, not content. No screenshots, no keystrokes, no URLs beyond the domain needed for app classification, no webcam anything. When a council asked one customer’s IT lead to run a packet capture during the demo, the payload was a list of app-category durations. That capture did more persuading than forty slides.
Aggregate-first reporting completes the argument. Managers see team patterns by default; individual-level views require explicit permission, exist only where the works agreement allows them, and leave an access log the council itself can inspect. A safeguard the other side can audit is worth ten safeguards they have to take on faith.
The DPIA as a design tool
Most organisations write their Data Protection Impact Assessment after choosing the tool, which is backwards. The DPIA is the best requirements document you will ever get for free. Done early, it forces the questions that otherwise surface in month six: who accesses what, why, for how long, and what happens when someone objects.
A 900-person insurer in Cologne drafted their DPIA before shortlisting vendors. Two products fell out immediately because they could not disable screenshot capture at the architecture level, only hide it in settings. A toggle is not a safeguard. A council will ask who controls the toggle.
We now hand customers a pre-filled DPIA template covering our processing activities, retention defaults, sub-processors and the residual risks we think an honest assessment should admit to. It saves their privacy team perhaps two weeks. More usefully, councils notice when the vendor arrives with the homework already attempted, weaknesses included.
Retention: delete on a schedule you publish
Data you keep forever is a liability you renew daily. Our default retention is 12 months for aggregated analytics and 90 days for the underlying event-level data, and customers can shorten both. The number matters less than its visibility: put it in the works agreement, and let the council verify deletion actually happens.
One customer’s council requested a quarterly deletion certificate, an automated report confirming what had been purged and when. It took us an afternoon to build. The goodwill it bought lasted the entire negotiation and well beyond, because it converted a promise into a routine that produced evidence on a schedule nobody had to chase.
Short retention also improves the analytics, oddly enough. Managers stop litigating what someone did last spring and start looking at the current quarter, which is the only period anyone can still influence. The compliance constraint and the good management practice point the same direction here, which is rarer than it should be.
What consent does and does not cover
Employers love consent because it feels clean. European regulators mostly reject it in employment contexts, because consent given under a power imbalance is not freely given. If declining the agent could plausibly hurt someone’s standing, the consent is decorative.
The sturdier basis is legitimate interest, documented through the DPIA and balanced against employee rights, or the works agreement itself, which in Germany can function as a legal basis under §26 BDSG. This is not legal advice; it is a pattern we have watched succeed. Your counsel should own the final wording.
What consent-style mechanics are still good for is transparency. The Momentum agent shows every employee their own data, in full, before any manager sees an aggregate. People consent with their trust, renewed daily, whatever the legal basis says.
The question that decided one review
In a review last spring, a council member at a Munich engineering firm asked a question we now quote in training: if a manager wanted to use this to build a dismissal case against one person, what would stop them?
The honest answer had three parts. Accessing individual data requires a justification recorded in the audit log. The works agreement restricted individual-level access to the employee themselves and HR under defined procedures. And the tool surfaces four-week aggregates, not minute-by-minute timelines, so the raw material for a surveillance case simply is not there.
The council approved a six-month pilot with a review clause and a named council member as data-protection liaison. Eighteen months later the agreement was renewed without amendment, in a meeting that lasted under an hour. Nobody had triggered the individual-access audit log even once, which was itself the finding that settled the renewal.
Make the employee view the best view
The most persuasive thing in any review is the employee dashboard. When each person can see their own focus patterns, their own classification of apps, and exactly what their manager’s aggregate view contains, the tool stops being something done to them.
In deployments where employees actively use their personal view, works-council complaints in the first year round to zero across our customer base. Where the agent runs silently, even lawfully, grievances follow within months. Transparency is not the compliance garnish. It is the mechanism.
A monitoring tool that survives a works-council review is, almost by definition, one that did not need to hide anything. Build for that reviewer from day one and every other market gets easier.
days of event-level data retention by default, with 12 months for aggregates
If you only remember four things
- Works councils audit architecture, not promises; data that is never collected is the only safeguard they fully trust.
- Draft the DPIA before shortlisting vendors so it works as a requirements document rather than retrospective paperwork.
- Consent is a weak legal basis in employment contexts; legitimate interest or the works agreement itself is sturdier.
- Publish retention periods in the works agreement and automate deletion evidence, such as a quarterly certificate.
Writes for The Signal about compliance and the future of measurable, humane work — drawing on anonymised patterns from the teams and focus hours analysed on Momentum.
Want this picture for your teams?
See timelines, productivity scores, and department comparisons on your own data.
Book a demo