Computer monitoring is an umbrella term for technologies that collect very different types of work-device data. Recording work hours is not the same as listing applications, capturing a screen, recording keystrokes, or preventing files from leaving a network. Each method has a different purpose, privacy impact, and governance requirement.
No feature is universally “legal” or “illegal” based only on its product name. The assessment depends on jurisdiction, purpose, necessity, proportionality, notice, device ownership, working location, data content, access, retention, and how the information affects people. This article explains the technology; obtain qualified local advice for a legal decision.
Computer monitoring types at a glance
| Type | Typical data | Primary purpose | Relative privacy impact |
|---|---|---|---|
| Work-time tracking | Start, stop, active, idle, schedule, project time | Attendance, workload, billing, project effort | Lower when limited to work periods |
| App and website monitoring | Resource name, category, duration, timestamp | Workflow and activity-pattern analysis | Medium; context and role classification matter |
| Screenshots | Periodic or event-triggered screen images | Evidence or visual work verification in defined cases | High; may capture unrelated or sensitive content |
| Webcam captures | Images from the device camera | Specialized identity or presence scenarios | Very high, especially in homes or shared spaces |
| Keystroke recording | Keys typed, potentially including message content and credentials | Specialized security/testing uses; sometimes surveillance | Very high; content and credential exposure risk |
| DLP | File movement, classifications, destinations, policy events | Preventing unauthorized disclosure of sensitive data | Varies with content inspection and policy design |
1. Work-time tracking
Work-time tracking records when a work session starts and stops and may associate time with a person, project, or task. It can support payroll inputs, billable-time records, workload review, and project estimation. The least intrusive setup normally limits collection to agreed work periods and excludes personal devices and off-hours.
See Yaware’s time and productivity tracking and automated timesheets.
2. Application and website monitoring
This method records metadata such as the name of an application or domain and the duration of use. It does not automatically explain what the employee was doing, why the resource was needed, or whether the result was valuable. A resource may be productive for one role and irrelevant for another.
Use app and website monitoring to identify patterns worth discussing, not to turn a category or percentage into an automatic performance decision.
3. Screenshots
Screenshots capture visible screen content. That can include client data, private notifications, health information, union communications, credentials, or confidential material unrelated to the intended purpose. A configurable interval does not remove those risks.
Before enabling screen captures, document why metadata is insufficient, restrict schedules and recipients, use privacy controls, define retention, and assess professional-secrecy or sector rules.
4. Webcam captures
A camera may capture a person, household members, living space, documents, or other private context. Remote work makes this especially sensitive. Webcam collection requires a separate necessity assessment; it should never be treated as a routine extension of time tracking.
5. Keystroke-recording tools
Keystroke tools can capture everything typed, including passwords, messages, document content, and special-category or confidential information. This creates severe privacy, communications-secrecy, credential, and security risks.
It is inaccurate to state that every technology called a keylogger is automatically a crime in every context. It is equally unsafe to assume that company-device ownership authorizes it. In Ukraine, the secrecy of correspondence is protected by Articles 31 and 32 of the Constitution, while Article 163 of the Criminal Code addresses violations of correspondence transmitted through communications or computers. Whether particular conduct meets those rules is a legal determination based on facts, not a product label.
6. Data loss prevention
DLP systems apply policies to files, destinations, devices, or data classifications. Their purpose is security, not general productivity measurement. DLP can still process personal or confidential information, so scope, access, false positives, retention, and employee notice require review.
Ukrainian legal context: what the cited laws actually say
The Labour Code of Ukraine contains working-time and employment rules, but Article 30 does not mandate electronic monitoring or time-tracking software; it states that an employee performs assigned work personally. Working-time duties must be identified from the provisions applicable to the actual work arrangement.
The Law of Ukraine On Personal Data Protection requires a defined lawful purpose, transparent processing, data that is adequate and not excessive, limited retention, and appropriate protection. Article 11 lists grounds for processing; consent is one possible ground, not a universal formula that automatically legalizes every monitoring practice. Article 8 describes data-subject rights, while Article 24 concerns protection of personal data.
These provisions must be considered together with constitutional privacy and correspondence rights, employment rules, sector obligations, contracts, collective arrangements, and the exact data flow. Consult qualified Ukrainian counsel before deployment.
How to choose the appropriate method
- Define the specific business problem.
- Choose the least intrusive data that can answer it.
- Map devices, people, working periods, fields, recipients, and retention.
- Verify the legal basis and required employee process in every jurisdiction.
- Test settings with a limited pilot.
- Give employees clear notice and a way to explain or correct context.
- Review permissions and security.
- Do not use one automated metric as the sole basis for an adverse decision.
For governance, use the Ethical and Legal Employee Monitoring Checklist. For implementation, read How to Monitor Employee Internet Usage Responsibly.
Last reviewed: July 31, 2026. General information only; not legal advice.