Nine out of nine. That is how many workplace monitoring platforms researchers tested this year were found sharing identifying worker data with outside companies, often without telling the workers or, in most cases, without disclosing it clearly to the employers who bought the software. If your organization runs any kind of activity-tracking or productivity software, that number should worry you more than any single vendor’s privacy policy does.
I want to be direct about the argument I’m making here: the workplace monitoring category, as it exists today, is not primarily a privacy problem you can solve by picking a better vendor. It is a compliance liability that most HR and legal teams have not priced correctly, and the data now backing that claim is hard to argue with.
What the research actually found
Researchers affiliated with Columbia Law School’s Center for Law and the Economy and Northeastern University’s Khoury College examined nine widely used workplace monitoring platforms, including tools used by large employers such as Ace Hardware, Ben and Jerry’s, CVS Pharmacy and Dunkin’. All nine shared workers’ identifying data, including names, email addresses and employer information, with outside companies. All nine also shared workers’ online-activity data, routed to a combined 145 unique third-party domains, including Facebook, Google and Microsoft. Three of the nine included features capable of tracking a worker’s precise location even while the app ran in the background.
Only two of the nine platform providers named specific third parties anywhere in their own privacy policies, and even those disclosures covered only a fraction of what the researchers actually observed moving across the wire. This was not limited to line workers being watched by management: 76 of the 121 documented data-sharing instances involved managerial accounts, meaning the managers running these tools were funneling their own activity data to the same third parties as the employees they supervised.
The counter-argument, and where it fails
The obvious pushback is that monitoring software serves legitimate purposes: security, productivity measurement, compliance with client contracts that require activity logging. That’s true, and I’m not arguing employers should stop measuring what remote and hybrid teams are doing. The counter-argument has real weight. Roughly three-quarters of employers already use some form of online monitoring, according to industry survey data cited alongside this research, and most of that use is unremarkable: web-browsing logs, login timestamps, basic screen activity.
Where that argument breaks down is the leap from “we need to monitor productivity” to “our vendor can silently hand worker data to Meta and an ad-tech supply chain we’ve never audited.” Nothing about legitimate workplace monitoring requires that data reach a mobile advertising network. David Choffnes, a professor at Northeastern University’s Khoury College of Computer Sciences and a co-author of the study, put the risk plainly: “This is another specific harm because essentially you now have the monitoring program able to follow you as you move around the world.” That is not a theoretical harm. It is what the researchers actually measured, running boss and employee accounts on each platform and intercepting the traffic directly.
Why this is a compliance problem, not just a privacy one
State law is already catching up in ways that should worry any HR team that has not audited its monitoring stack. Maine’s L.D. 61, enacted this year, defines workplace surveillance broadly enough to capture AI-driven keystroke monitoring, productivity scoring and biometric tracking, and it requires employers to notify job applicants during the interview process and give employees annual written notice. Employers who assumed their monitoring vendor’s own privacy policy covered them are going to find that assumption tested the first time a regulator or plaintiff’s attorney asks for the actual data flows, not the marketing language.
This is precisely the pattern HR teams have already seen play out with AI notetakers now facing their own direct legal liability and with the wave of suits over silent recording tools that vendors marketed as compliant. The lesson from both is the same one this research points to: a vendor’s privacy policy is not a legal shield, and “the software vendor handles that” is not a defense that survives contact with a regulator or a plaintiff’s discovery request.
What HR leaders should actually do
Before renewing or expanding any monitoring platform contract, ask the vendor directly which third parties receive worker data, in what form, and why, and get the answer in writing rather than accepting a generic privacy policy as sufficient. If the vendor cannot answer specifically, that is itself the answer. Cross-reference any state where you employ monitored workers against emerging surveillance-notice laws like Maine’s, because the compliance floor is rising state by state, not falling. And treat “we bought this from a reputable vendor” as the beginning of due diligence, not the end of it.
The uncomfortable truth in this research is that reputable vendors, serving well-known employers, still failed this test unanimously. Waiting for the market to sort this out on its own is a bet most legal departments would not take if they understood the odds. HR should not be taking it on their behalf either.