Not a vulnerabilityNothing is exploited. The software was bought to do this, it is installed by the employer, and the objection is to what it records rather than to a defect in it.
What it is
Software on the work device or in the work account records what the person does at intervals: which application is in the foreground, whether keyboard or mouse moved, how long a window was idle, how many messages or tickets were handled in an hour. The rows are attributable to a named worker and are stored per interval rather than per day. A figure follows from them, a score, a percentage or a ranking, which a manager sees and which is used in conversations about the person.
Why it is a separate entry
Employment is a relationship in which refusing costs something, so consent is not available as a basis and necessity has to carry it. Being measured minute by minute changes what people do: it rewards visible presence over work, and it turns a break, a disability or care at home into a dip that has to be explained. The worker usually cannot see their own rows while the manager can.
How it arises
a feature enabled by default in remote-work or endpoint software
aggregate reporting bought, per-person reporting delivered in the same product
an interval left at the product default instead of set to the coarsest that serves the purpose
a pilot for one team that stayed on for everyone
Not to be confused with
A measurement series from a device in the home that reveals occupancy is Reporting interval that reveals occupancy, where the subject is a household and the party a supplier. Images of what is on the worker's screen are Screen capture of a worker's device: this entry counts activity, that one records content. A figure about a team that cannot be resolved to a person is not this entry.
How to establish it
The product's own output contains rows attributable to one named worker at an interval shorter than a working day: a timestamp, an identifier of the person, an activity value. Establish it from the administrator's view or from the worker's own access request, not from the product description or the dashboard.
method document-comparisonQoD 85
Requirements on the measurement
ask for the records of one person over one day, in the form the product exports them
record the interval, and whether the worker can see the same rows
record whether the figure is used in any assessment, and where that use is written down
note the difference between what the dashboard shows as an aggregate and what is stored per person; the storage is the finding
What would refute it
by handThe stored records cannot be resolved to a person, and the export shows totals per team only.finding falls
by handThe activity value is produced by the worker's own action, such as time they book themselves.finding falls
by handThe worker sees the same rows at the same interval and can correct them.weakens
by handThe measurement runs for a bounded investigation with a stated ground and an end date.A targeted investigation is a different processing from permanent measurement of everyone, and it is written down somewhere.weakens
Where this plugs into existing processes
The one question that surfaces itShow me one day of one employee, in the form the system stores it.
In a DPIA, verify this
Verify what the product stores per person per interval, rather than what the dashboard shows the manager.
As a procurement clause
The product stores no per-person activity row at an interval shorter than the reporting the purpose requires, and the worker can see their own rows.
With a complaint, hand over
The export of one worker's rows for one day, the interval, and the works council decision if there is one.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
eu-gdpr-5-1-c
eu-gdpr-88
nl-wor-27
eu-gdpr-22
Objections, and the answer
“The employees agreed to it.”
In a relationship of authority consent is rarely free, because refusing costs something. That is why the discussion runs over necessity and over the works council rather than over a signature.
“We only look at team totals.”
Then the storage should be team totals. A per-person row that exists can be looked at, and will be as soon as there is a reason to look.
“It is our equipment.”
Owning the device settles who may install software on it, not what may be recorded about the person using it.
“The system does not decide anything, a manager does.”
Where the manager sees the score and not the work, the system did the selecting. What has to be shown is what the manager had in front of them.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0036: Per-person productivity scoring at work. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0036
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0036, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.