Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
The Article 29 Working Party's opinion on employee monitoring under EU data protection law: consent almost never works at work, legitimate interest needs a necessary, least intrusive and time, place and data-limited method, workers must be told what is monitored and why, and nine scenarios from social media screening and TLS inspection to keystroke logging, BYOD, wearables, CCTV analytics and vehicle tracking with a private-use switch. Guidance, not law; the EDPB has said it remains valid. Built from the complete English text.
Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) is a compliance framework from European Union and EEA with 5 domains and 41 controls that map to 1 other frameworks. The largest domains are Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
| Code | Title |
|---|---|
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(a) | 3.1(a) Specified, legitimate purposes and data that are adequate, relevant and not excessive |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(b) | 3.1(b) Proportionality and subsidiarity, whatever the legal ground, tested before monitoring starts |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(c) | 3.1(c) Let workers exercise access, rectification, erasure and blocking |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(d) | 3.1(d) Accurate data kept no longer than needed, with a set retention period |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1(e) | 3.1(e) Security of monitoring data and staff awareness of data protection duties |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(a) | 3.1.1(a) Consent is not the legal ground for most processing at work; default settings are not consent |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(b) | 3.1.1(b) Contract and legal obligation as grounds, with workers fully informed of legally required processing |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(c) | 3.1.1(c) Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.1(d) | 3.1.1(d) Limits on monitoring: places, data and time |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.2 | 3.1.2 Tell workers that monitoring exists, why, and what else fairness requires |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.1.3 | 3.1.3 No decision based solely on automated evaluation of work performance without a permitted ground |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.2.1 | 3.2.1 Data protection by design and default in monitoring devices and tools |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::3.2.2 | 3.2.2 Data protection impact assessment for high-risk monitoring and prior consultation if residual risk stays high |
Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
| Code | Title |
|---|---|
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::4 | 4 No incompatible further use of monitoring data |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.1(a) | 5.1(a) Recruitment: social media and public data only with a legal ground, when relevant to the job, and with prior notice |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.1(b) | 5.1(b) Recruitment data deleted once no offer is made or it is declined |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.2(a) | 5.2(a) No generalised screening of employees' social media during employment |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.2(b) | 5.2(b) No demand for access to what employees or applicants share on social networks |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.2(c) | 5.2(c) Employees keep a private profile; no compulsory employer-provided profile |
Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
| Code | Title |
|---|---|
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(a) | 5.3(a) Network and TLS inspection tuned to prevent permanent logging of employee activity |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(b) | 5.3(b) Exclude sensitive traffic from inspection and tell employees what is monitored |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(c) | 5.3(c) Policy on who may access suspicious log data and when, reviewed at least annually |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(d) | 5.3(d) Acceptable use and privacy policies implemented and communicated before monitoring |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(e) | 5.3(e) Involve a representative sample of employees, and the works council where the law requires it |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(f) | 5.3(f) Data loss prevention: transparent rules and a warning before an email is blocked |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(g) | 5.3(g) Private spaces in employer-provided online applications |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.3(h) | 5.3(h) Prefer prevention to detection: block rather than monitor |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.1 | 5.4.1 Home and remote working: no keystroke, mouse, screen or webcam capture |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.2(a) | 5.4.2(a) Bring your own device: separate private from business use and keep out of private areas |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.2(b) | 5.4.2(b) Bring your own device: secure the employer's data, weigh monitoring during personal use, or bar private use |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.3 | 5.4.3 Mobile device management: DPIA first, a specified purpose, tracking held back until a device is lost |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.4.4 | 5.4.4 Wearables: health and activity data stay with the employee |
Sections 5.5 to 5.7: Time and attendance, video and vehicles – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
| Code | Title |
|---|---|
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.5 | 5.5 Time and attendance and access control: informed, necessary, and not reused for performance evaluation |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.6 | 5.6 Video monitoring: no video analytics of expressions or movements, no facial recognition |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7(a) | 5.7(a) Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7(b) | 5.7(b) Tell drivers a tracker is fitted and that movements, and possibly driving behaviour, are recorded; notice in the vehicle |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7(c) | 5.7(c) No location monitoring outside agreed working hours, save a proportionate theft safeguard |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.7.1 | 5.7.1 Event data recorders and in-cab cameras: only where necessary and proportionate; no continuous recording of drivers |
Sections 5.8, 5.9 and 6: Disclosure, transfers and fundamental rights – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
| Code | Title |
|---|---|
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.8 | 5.8 Disclosure of employee data to customers only where proportionate |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::5.9 | 5.9 International transfers of HR and monitoring data: adequacy preferred, minimum data, limited group access |
| article-29-working-party-opinion-2-2017-on-data-processing-at-work-wp249::6.1 | 6.1 Owning the equipment does not remove employees' secrecy of communications; location tracking only where strictly necessary |
Maps to 1 other framework
Coverage is not the same as your position
This page shows what Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) and who does it apply to?
Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) is a compliance framework from European Union and EEA with 5 domains and 41 controls. The Article 29 Working Party's opinion on employee monitoring under EU data protection law: consent almost never works at work, legitimate interest needs a necessary, least intrusive and time, place and data-limited method, workers must be told what is monitored and why, and nine scenarios from social media screening and TLS inspection to keystroke logging, BYOD, wearables, CCTV analytics and vehicle tracking with a private-use switch. Guidance, not law; the EDPB has said it remains valid. Built from the complete English text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) actually require?
Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) has 41 controls organised across 5 domains. The largest domains are Section 3: Principles, legal grounds and GDPR duties for employers – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (13 controls), Sections 4, 5.1 and 5.2: Further processing, recruitment and in-employment screening – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) do I already cover?
Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) maps to 1 other compliance frameworks. The top mapping partners are GDPR (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)?
Start your Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 844 frameworks.
Get Started Free →Free forever — no credit card required