1. Who the monitoring rules apply to
    1. The small business exemption
    2. The employee records exemption is narrow
  2. Give written notice before monitoring starts
    1. New South Wales: 14 days' written notice
    2. ACT: notice plus good-faith consultation
    3. Everywhere else
  3. Stay within surveillance device and interception limits
  4. Apply privacy obligations to the data you collect
  5. Put the framework in writing
  6. What happens if you get it wrong
  7. Compliance checklist
  8. When to get a lawyer involved
  9. The 14-day clock starts before you switch anything on

Nearly every Australian business relies on the internet to get work done, and nearly every employer has wondered what staff are doing online during work hours. Monitoring employee browsing can protect your business from malware, phishing, data theft and misconduct, but it is not something you can simply switch on. When you monitor employee internet use, you take on legal obligations under state and territory surveillance laws, the Privacy Act 1988 (Cth) and, in some cases, federal telecommunications interception laws.

This article sets out who those obligations apply to, the duties you must perform before and while monitoring, the penalties for getting it wrong, and a compliance checklist you can work through with your team. If you are already running monitoring tools, the same rules govern what you do next, including any decision to keep collecting data.

Who the monitoring rules apply to

The rules that govern monitoring depend on where your employees work and whether your business is covered by the Privacy Act. Three questions determine your position:

  • Where employees work: New South Wales has its own dedicated workplace surveillance law, and the ACT has the Workplace Privacy Act 2011 (ACT). Other states and territories regulate surveillance through general surveillance device legislation.
  • Annual turnover: If your business's annual turnover is more than $3 million, the Privacy Act and its Australian Privacy Principles (APPs) apply to how you handle personal information, including browsing logs.
  • What is collected: Browsing logs can amount to personal information even where an exemption looks like it might apply, and the employee records exemption covers only some of what monitoring generates.

The small business exemption

s 6D of the Privacy Act 1988 (Cth) defines a small business as one whose annual turnover for the previous financial year was $3 million or less. A business at or under that threshold is generally exempt from the APPs. Exceptions exist, for example for health service providers, businesses that trade in personal information and credit reporting bodies. Importantly, an exempt business still has to comply with state and territory surveillance laws and federal telecommunications laws.

The employee records exemption is narrow

There is also an "employee records" exemption under s 7B(3) of the Privacy Act. It exempts acts or practices that are directly related to a current or former employment relationship and to an employee record held by the organisation about that individual. The exemption is narrow in practice. It does not extend to job applicants or contractors, because they are not in an employment relationship with you, and not every piece of monitoring data will fall inside the definition of an employee record. If a browsing log does not fit, the ordinary privacy rules apply to it. Treat monitoring data as personal information unless you are confident the exemption covers it.

Give written notice before monitoring starts

The single most important duty is notice. In the two jurisdictions with dedicated workplace surveillance laws, monitoring must not begin until workers have been told, in writing, what is coming.

New South Wales: 14 days' written notice

Under s 10 of the Workplace Surveillance Act 2005 (NSW), surveillance of an employee must not commence without prior written notice given at least 14 days before surveillance starts. An employee may agree to a shorter period. The notice must state the kind of surveillance to be carried out (camera, computer or tracking), how it will be carried out, when it will start, whether it will be continuous or intermittent, and whether it will run for a specified period or be ongoing. Email counts as written notice. If an employee starts work after monitoring is already in place, the notice must be given before they start work.

ACT: notice plus good-faith consultation

Under s 13 of the Workplace Privacy Act 2011 (ACT), an employer may only conduct surveillance of a worker if written notice is given at least 14 days before the surveillance starts, or within a shorter period the worker agrees to. A new worker must receive notice before starting work. The notice must state the kind of surveillance device to be used, how the surveillance will be conducted and who will conduct it. On top of the notice, s 14 of the Act requires the employer to consult with the worker in good faith during the notice period, giving the worker a genuine opportunity to influence how the surveillance is conducted. The ACT Act also requires a "stopped delivery notice" if you block delivery of an electronic communication, such as when filtering or blocking websites.

Everywhere else

There is no national workplace surveillance statute, so outside NSW and the ACT your obligations come mainly from state and territory surveillance device laws and general privacy law. Those laws commonly restrict the use of listening devices, optical devices and tracking devices, and in most states and territories recording a private conversation requires the consent of all parties. The prudent approach is to give written notice covering what is monitored, how, when, why, who can access the data and how long it will be kept, even where no statute expressly demands it.

Stay within surveillance device and interception limits

Notice alone does not make monitoring lawful. The way you monitor must also respect the line between system metadata and the content of communications:

  • Prefer logs over content: Federal telecommunications interception laws restrict accessing the content of communications in transit, and state surveillance device laws restrict recording private communications. Records of domains visited, timestamps and bandwidth use sit on the safer side of that line; reading the content of messages or web pages sits on the riskier side.
  • Get consent for recordings: Live call audio and meeting recordings usually require consent from everyone involved under state surveillance device laws. If call capture is part of your plan, treat it as a separate project from browsing monitoring.
  • Handle BYOD carefully: If staff use their own devices, full-device monitoring is high risk. Limit monitoring to managed corporate applications, corporate email profiles and traffic on your own network, and say clearly in writing what is and is not captured.
  • Set out-of-hours guardrails: Tools that run around the clock can capture private browsing outside work hours. Configure them to pause or filter personal time, or only collect what you have a documented reason to collect.

Apply privacy obligations to the data you collect

If the Privacy Act covers your business, the APPs apply to the monitoring data you hold. That means collecting only what is reasonably necessary for your stated purpose, taking reasonable steps to secure the information, restricting who can access it and deleting it once it is no longer needed. Browsing logs can reveal sensitive information, such as health matters, religious beliefs or union membership, so minimisation and strict access controls matter.

Retention deserves its own planning. Keep high-level logs long enough to detect and investigate incidents, set a documented retention period tied to your purpose, and automate deletion where you can. If monitoring data is involved in a breach that is likely to result in serious harm, the notifiable data breaches scheme under Part IIIC of the Privacy Act requires you to assess the situation within 30 days of becoming aware and to notify the Office of the Australian Information Commissioner and affected individuals.

Even if the small business exemption applies to you, minimisation, security and deletion should still be your standard. Monitoring data is valuable to attackers, and a log of everything your staff do online is a liability if it leaks.

Put the framework in writing

A lawful monitoring program is documented before it is switched on. The documents do the legal work: they give the notice, set expectations and make enforcement fair.

  • Acceptable use and surveillance policy: Set out what is monitored, how, when and why, plus the consequences of breaching the policy. Keep it consistent with what the tools actually do.
  • Acknowledgment: Ask employees to sign an acknowledgment or accept updated terms in your HR system. For new hires, fold it into onboarding alongside the employment contract.
  • Contractor and BYOD coverage: Extend the policy to contractors and temporary staff who access your systems, and address personal devices explicitly so there is no argument later about what was in scope.
  • Governance: Limit access to monitoring data to people with a genuine need, keep audit trails of who viewed it, encrypt data where possible and build monitoring into your incident response plan.

What happens if you get it wrong

The consequences of unlawful monitoring are more serious than most employers assume. Under s 13G of the Privacy Act, a serious interference with an individual's privacy attracts a maximum penalty for an individual of $2.5 million, and for a body corporate the greater of $50 million, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover. Lesser interferences with privacy under s 13H carry a maximum of 2,000 penalty units. The OAIC can investigate, make determinations, accept enforceable undertakings and seek civil penalties in court.

State surveillance laws add their own exposure. In NSW, commencing surveillance without the required notice is an offence under the Workplace Surveillance Act, and the Act expressly allows a person who was the subject of surveillance to bring proceedings. Beyond fines, improperly obtained monitoring evidence can undermine a dismissal or disciplinary action, because it was gathered in breach of the law, and it can damage trust in a way that outlasts any dispute.

Compliance checklist

Work through these items before monitoring starts, and revisit them whenever your tools, workforce or obligations change:

  • Confirm which state or territory rules apply to each workplace you operate.
  • Serve written notice at least 14 days before monitoring starts in NSW and the ACT, and only accept a shorter period with the employee's agreement.
  • State in the notice what is monitored, how, when, whether it is continuous or intermittent, and for how long.
  • Consult with workers in good faith during the notice period in the ACT.
  • Check whether the Privacy Act covers you; if it does, apply the APPs to your monitoring data.
  • Collect the minimum your purpose requires and prefer metadata over content.
  • Secure the data, restrict access on a need-to-know basis and set a retention schedule with automated deletion.
  • Address BYOD, contractors and remote work explicitly in the policy.
  • Train staff on acceptable use and monitoring scope, and keep the policy aligned with what the tools actually do.

When to get a lawyer involved

Most employers can manage the basics of notice and policy, but a practitioner is worth engaging before you switch on monitoring, not after a problem surfaces. A lawyer can audit what your existing tools collect against the surveillance rules for each state where you employ people, draft the notice, the acceptable use policy and the acknowledgment so they match your actual technical setup, and advise on the riskier edges such as BYOD, communications content and out-of-hours collection. If something has already gone wrong, such as an investigation run on improperly obtained logs, a privacy breach notification or a Fair Work dispute, legal input early is far cheaper than defending the consequences later.

The 14-day clock starts before you switch anything on

The duty employers most often miss is the easiest to state: in NSW and the ACT, monitoring must not begin until written notice has been given at least 14 days earlier. If you already have monitoring tools running without that notice, the first action this week is to decide whether your purpose genuinely requires the data, and if it does, serve the notice before the next log line is captured. A monitoring program that began with clear, written, proportionate notice is the one that survives scrutiny from a regulator, a tribunal or a disgruntled employee. Silent monitoring is not a head start; it is the mistake that turns legitimate security work into a legal problem.