tracking-computer-activities

Computer activity tracking does not have one fixed data boundary. What is logged depends on the product, enabled features, work schedule, device, permissions, and administrator configuration. Basic activity metadata may show an application or website and its duration; optional capture features can collect visible screen or webcam images.

That distinction matters. A company should never promise employees that a system records “only metadata” without checking its actual settings, and an employee should not assume that the term activity tracking means every message or password is collected.

Activity metadata commonly recorded by Yaware

Depending on configuration, Yaware can record:

  • work-session start and end times;
  • active and idle intervals;
  • application names and duration;
  • website domains or resources and duration;
  • productive, neutral, or unproductive categories;
  • project, task, and offline-activity records;
  • reporting dimensions such as employee, team, date, or project.

This metadata can support workload and process analysis, but it does not prove intent, quality, or business value. A browser domain does not reveal why it was opened. Idle time may represent a call, meeting, paper work, or break rather than inactivity.

Review app and website monitoring, offline activity tracking, and reports and dashboards.

Optional features may collect content or images

Yaware also offers configurable screen and webcam captures. When enabled, those images may contain text, messages, documents, notifications, credentials, people, or private surroundings visible at the moment of capture.

Calling the overall product “activity tracking” does not turn those images into metadata. Organizations must assess the capture feature separately, limit it to a defined purpose and work period, restrict access, use available privacy controls, and set retention.

What standard activity metadata does not imply

A record that an employee used a messaging application does not, by itself, mean the message content was read. A website-domain record does not necessarily include form entries or passwords. Application duration does not equal keystroke recording.

However, content can still appear through optional screenshots, webcam images, notifications, integrations, browser extensions, DLP tools, or other software on the same device. The correct statement is therefore configuration-specific: verify the complete monitoring stack instead of relying on a generic product category.

How employees and managers can verify the boundary

  1. Request the monitoring notice or internal policy.
  2. Ask for the exact enabled feature list, not only the product name.
  3. Confirm covered devices, schedules, time zones, and off-hours behavior.
  4. Check whether screenshots or webcam captures are enabled and at what interval.
  5. Ask whether message content, URLs beyond domains, keystrokes, or form entries are collected by any tool.
  6. Identify who can access individual data and exports.
  7. Confirm retention and deletion periods.
  8. Test a pilot account and let the employee view the resulting record.
  9. Document how inaccurate categories or records can be corrected.

Privacy questions for remote work and BYOD

Homeworking and personal devices increase the chance of collecting private or household information. Define whether the monitoring agent runs only inside a work profile, whether it stops outside agreed hours, and what happens when the device changes time zone or remains logged in.

A company-owned device does not remove every privacy obligation, and a personal device does not make broad monitoring appropriate. Use the least intrusive configuration that meets the documented purpose and obtain jurisdiction-specific advice.

Ukrainian legal context

Ukrainian law does not create a simple rule that “metadata is legal and content is illegal.” The assessment depends on what is collected, the purpose, transparency, proportionality, legal grounds, and the rights affected.

Articles 31 and 32 of the Constitution of Ukraine protect correspondence and private life. The Law On Personal Data Protection requires a lawful, defined purpose, transparent and non-excessive processing, limited retention, protection, and respect for data-subject rights. Article 163 of the Criminal Code addresses violations of correspondence transmitted through communications or computers; it does not make every tool with a particular marketing label automatically criminal.

Written consent may be relevant in some cases, but the Personal Data Protection Law lists multiple possible grounds for processing in Article 11. Consent is not a blanket cure for excessive or otherwise unlawful collection. Qualified counsel should assess the actual configuration and employment context.

A transparent monitoring notice should answer

  • Which metadata and optional captures are enabled?
  • Why is each field needed?
  • When does collection start and stop?
  • Who sees individual and aggregated records?
  • How long is each data type retained?
  • How can an employee access, explain, or challenge a record?
  • Will any automated score affect evaluation or discipline?

For a complete governance process, use the Ethical and Legal Employee Monitoring Checklist. For technical categories, read Computer Monitoring: Types, Data Collected, and How to Choose Responsibly.

Last reviewed: July 31, 2026. General information only; not legal advice.

Effective timetracking on the computer

Comments are closed.