Skip to main content
Compliance & Law

ICO Guidance

The Information Commissioner's Office (ICO) is the UK's independent data protection authority. It publishes detailed guidance on workplace monitoring, employee data, DPAs and other employer obligations.

About the ICO

The Information Commissioner's Office is the UK's independent regulator for data protection, freedom of information and electronic communications. It enforces UK GDPR and the Data Protection Act 2018 and can impose fines up to £17.5 million or 4 percent of global turnover.

ICO Guidance on Workplace Monitoring

Key principles: be transparent, have a clear lawful basis, ensure proportionality, conduct a Data Protection Impact Assessment (DPIA) for high-risk activities, give workers meaningful choice where possible. teamly's read receipts and analytics are explicitly built around these rules.

Practical Compliance

Publish a clear privacy notice for staff, document the lawful basis for each processing activity, run a DPIA before launch, consult worker representatives where applicable, and review the policy regularly.

FAQ

Frequently asked questions about ICO Guidance

What HR leads, IT managers and compliance officers ask most often.

Do I need a DPIA before launching an employee app?
Almost always, yes. Any system capable of monitoring staff at scale should trigger a DPIA. The ICO publishes a template. teamly supports DPIA workshops as part of onboarding.
What is the ICO's position on read receipts?
Read receipts for safety briefings are generally accepted as proportionate, provided staff are informed and the data is not used for performance management. Document this in your policy and the DPIA.

Considering an employee app?

teamly is the European employee app for mid-market companies. Go-live in 3 to 6 months, your own branded app, UK and EU GDPR compliant.