Not a vulnerabilityNothing is exploited. The agent takes the images because it was configured to, and the objection is to the configuration rather than to a defect.
What it is
The device produces images of the screen, or a stream of it, on a timer or on a trigger such as a keyword, an application coming to the foreground, or a score crossing a threshold. The image holds everything that was visible: the work, but also a private message in another window, a colleague's data, a document belonging to a client, a password manager at the moment it was open. The images are stored centrally and can be opened by someone other than the person captured.
Why it is a separate entry
A screenshot is not a measurement about the worker alone. It captures whatever was on the screen, including data about clients, patients and colleagues who have no relationship with the monitoring at all, and it captures the private moments that occur on any device used all day. The worker cannot see when a capture is taken, and cannot know afterwards which ones exist.
How it arises
a screenshot feature bundled with time tracking and enabled as delivered
a trigger list that fires far more often than the incident it was bought for
recordings kept for months although the review they serve happens the same week
an agent rolled out for one team and left running on the standard image
Not to be confused with
Counting activity per person is Per-person productivity scoring at work: that records how much, this records what. Recording a visitor's session on a website is Session recording, which is bounded by the page; a screen capture is bounded by nothing that was open.
How to establish it
Image or video records of the worker's screen exist in the product's store, produced at a moment when the worker performed no action to produce them. Establish it from the administrator's view, from the worker's own access request, or from the files the agent writes locally, and count them per hour.
method document-comparisonQoD 85
Requirements on the measurement
ask for the images of one hour of one person and record how many there are
record what triggers a capture, and whether the worker is told at the moment it happens
record what is visible in the images besides the work: other applications, other people's data
record the retention of the image store separately from the retention of the activity records
What would refute it
by handEvery capture is started by the worker, for instance to attach evidence to a ticket.finding falls
by handThe stored image is reduced before storage to a form in which no content is readable.Check a stored image rather than the setting that claims to do it.finding falls
by handCapture runs only during a bounded investigation with a stated ground, and the worker was told.weakens
by handThe device serves one task and nothing else can appear on the screen.weakens
Where this plugs into existing processes
The one question that surfaces itHow many pictures of my screen were taken this hour, and who can open them?
In a DPIA, verify this
Verify how many images of one person exist for one hour and what else is visible in them, rather than the sentence that screenshots are possible.
As a procurement clause
The product produces no screen image unless the worker starts it, or capture is bounded to a stated investigation with an end date.
With a complaint, hand over
The number of images per hour for one worker, a sample in which third-party data is visible, and the retention of the image store.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
eu-gdpr-5-1-c
eu-gdpr-5-1-e
eu-gdpr-88
nl-wor-27
Objections, and the answer
“It is only for security incidents.”
Then it runs during an incident. A capture that runs continuously is not an investigation but a standing recording, and the difference is visible in the number of images per hour.
“Nobody looks at the images.”
They exist, they are readable, and the retention says how long that stays true. What is looked at is not the measure.
“Employees know it happens.”
Knowing is not the same as necessary, and it does nothing for the clients and colleagues whose data is in the frame and who were told nothing.
“The worker can pause it during breaks.”
Test that, and check the store for the period it was paused. A pause that stops the display and not the capture is the finding rather than the answer to it.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0037: Screen capture of a worker's device. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0037
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0037, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.