GDPR Compliance

Last Updated: May 15, 2026

EU General Data Protection Regulation (GDPR) — 2016/679

Operated by N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121)

TheDeskMonitor's GDPR Position

TheDeskMonitor operates as a Data Processor on behalf of your organisation (the Data Controller). We process employee monitoring data only on your documented instructions, for the purposes you have communicated to your employees, and subject to appropriate technical and organisational safeguards.

1. Lawful Basis for Processing

TheDeskMonitor's monitoring features require a lawful basis under GDPR Article 6. The most commonly applicable bases for employee monitoring in a professional context are:

  • Legitimate Interests (Art. 6(1)(f)): Employers have a legitimate interest in monitoring productivity, ensuring security, and verifying work performance. A Legitimate Interests Assessment (LIA) should be conducted and documented by the Data Controller.
  • Contract Performance (Art. 6(1)(b)): Monitoring may be necessary for performance of an employment contract where the contract includes monitoring obligations.
  • Legal Obligation (Art. 6(1)(c)): In regulated industries (finance, healthcare), monitoring may be required to meet legal or regulatory obligations.

TheDeskMonitor does not rely on employee consent as the lawful basis for monitoring — consent is not freely given in an employment context and is therefore an inappropriate basis under GDPR.

2. Data Minimisation & Privacy by Design

TheDeskMonitor implements the GDPR principle of data minimisation through built-in features:

  • Smart Blur: All background (non-active) windows in captured screenshots are automatically blurred. The active window — the one the employee is currently working in — remains clear so productivity context is preserved. Smart Blur does not perform content-aware PII detection within the active window.
  • Keystroke aggregation only: Activity levels are measured as counts per minute, not as keystroke logging. No text content is captured.
  • Privacy Mode: Employees can pause monitoring at any time. The pause is logged for transparency.
  • Zone Compliance: EU-based users are automatically placed in a GDPR-compliant monitoring profile with reduced data collection.

3. Data Subject Rights

Employees have the following rights under GDPR, which TheDeskMonitor supports:

RightHow TheDeskMonitor Supports It
Right of Access (Art. 15)Employees can view their own activity, timesheets, and screenshots in their personal dashboard
Right to Portability (Art. 20)Employees can download their timesheet and activity data at any time
Right to Erasure (Art. 17)Data Controllers can initiate deletion workflows; automatic purge at retention window end
Right to Rectification (Art. 16)Timesheet corrections can be submitted and approved through the correction workflow
Right to Restrict Processing (Art. 18)Privacy Mode allows employees to pause monitoring at any time

4. Data Processing Agreement

GDPR requires a Data Processing Agreement (DPA) between the Data Controller (your organisation) and the Data Processor (TheDeskMonitor). Our standard DPA is available for all plans and covers:

  • Subject matter, nature, and purpose of processing
  • Categories of data and data subjects
  • Sub-processor list and approval mechanism
  • Technical and organisational security measures
  • Data breach notification obligations
  • Return and deletion of data on termination

Request our countersigned DPA →

5. International Data Transfers

TheDeskMonitor uses cloud infrastructure providers located in Australia and internationally. For tenants with team members outside Australia, data transfers are governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission where GDPR applies. Our DPA includes SCCs where applicable. We will notify Controllers of material changes to data storage geography with 30 days' notice.

6. Data Breach Notification

In the event of a personal data breach affecting your tenant's data, TheDeskMonitor will notify you as the Data Controller within 72 hours of becoming aware of the breach — consistent with Article 33 GDPR. The notification will include the nature of the breach, likely consequences, and measures taken or proposed.

7. Contact the TheDeskMonitor DPO

For GDPR queries, Data Subject Access Requests on behalf of your employees, or DPA requests, contact our privacy team at:

N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121) |

Need a DPA or GDPR consultation?

Our privacy team can provide a DPA and answer compliance questions for your organisation.