Yes, with conditions that differ by state. What notice you must give, where the Privacy Act fits, and why the employee records exemption is narrow.
12 September 2026 · 10 min read
Yes, generally — with conditions, and the conditions depend on where your staff are.
There is no single Australian law called the Employee Monitoring Act. What you are actually navigating is a state surveillance statute, possibly the Privacy Act, and the general body of employment law that governs how you treat people. They overlap unevenly, which is why the answer to "is this legal" is usually "it depends what you mean by monitoring, and which state they work in".
This is a practical orientation, not legal advice. If you are about to switch monitoring on across a workforce, this is the point to spend an hour with an employment lawyer rather than an afternoon with a blog.
Across the states that regulate this, the consistent theme is notice. Covert surveillance is the thing that is generally prohibited or requires a court order. Disclosed surveillance, conducted for a legitimate business purpose, generally is not.
New South Wales is the most prescriptive and is worth knowing even if you are elsewhere, because it is the shape the others broadly follow. Under the Workplace Surveillance Act 2005 (NSW), computer surveillance of an employee requires written notice in advance — at least 14 days before it starts, or before a new employee begins — and it must be conducted in accordance with a policy that the employee has been notified of. Camera surveillance has its own requirements, including visible signage.
The ACT has closely comparable legislation. Victoria, Queensland, Western Australia, South Australia, Tasmania and the Northern Territory regulate surveillance devices through their own Acts, with different scopes — several are focused on optical and listening devices rather than computer activity specifically, which is a gap people sometimes read as permission. It is safer to read it as an area where the law has not caught up than as a licence.
If your team is spread across states, your obligations are set by where each person works, not by where your office is.
The Privacy Act and the Australian Privacy Principles apply to most businesses with an annual turnover over three million dollars, plus some smaller ones such as health service providers.
There is an employee records exemption, and it is invoked far more confidently than it deserves. It applies to records directly related to a current or former employment relationship — and that is narrower than "anything we collected about an employee". It has been the subject of ongoing review and criticism, and it does not extend to prospective employees or contractors at all.
If a meaningful part of your workforce is engaged as contractors, the exemption is doing nothing for you in respect of them.
Two practical consequences regardless of whether the exemption applies to you:
Statutes aside, the questions that determine whether a monitoring arrangement survives scrutiny are fairly consistent:
Did the employee know? Not "was it in a policy they signed three years ago" — did they actually know, in terms they could understand, what is captured and when. This is the one that fails most often.
Is it proportionate to a real purpose? "We want to see what people are doing" is not a purpose. "We bill clients by the hour and need defensible time records" is. The narrower and more concrete the purpose, the easier everything else becomes.
Is it limited to work? Monitoring someone's personal laptop outside their shift is a different act from monitoring a company device during it. If people use their own devices, capture that stops at clock-out is not a courtesy — it is the thing that makes the arrangement defensible.
Can you explain it to the person it concerns? This is not a legal test, but it is the most reliable predictor. Any monitoring arrangement you would not be comfortable describing, in full, to the employee it applies to is one you should expect to have to defend.
The businesses that get into trouble are rarely the ones doing sophisticated surveillance. They are the ones who switched something on quickly, told people vaguely or not at all, and kept everything forever because nobody chose otherwise.
A defensible arrangement usually looks like this:
None of that is expensive. It is mostly decisions.
Monitoring is off by default and enabled per person rather than per workforce, because the reason for monitoring a warehouse picker and a salaried manager are not the same and usually only one of them holds.
Every monitored person acknowledges a disclosure naming what is captured before anything is captured. It cannot be switched on silently — not as a policy commitment, but because the product will not do it.
On a personal device, capture happens only between clock-in and clock-out. Owners, managers and contractors are never monitored whatever the setting says; that ceiling is enforced in the product rather than left to an administrator to remember.
Retention is set by the business and enforced nightly, and when a screenshot expires the image is destroyed while the record that a capture happened survives — so the sensitive part goes on your schedule and the audit trail stays.
Data is held in Sydney. If you are ever asked where your staff's screens are stored, that should be a short answer.
It is legal if you tell people, keep it proportionate to a real purpose, confine it to work, and do not keep it forever. It is not legal, in most of the country, if it is covert.
The single best question to ask before switching anything on: *could I describe exactly what this captures to the person it captures, without softening it?* If not, the problem is the arrangement, not the wording.