This is not legal advice. This template is a starting point written by an IT security company. Requirements differ by state, and some states require specific wording, posting, acknowledgment or timing. Have your attorney review your final policy before you use it. See our monitoring laws guide for an overview.
How to use this template
- Replace every item in [brackets] with your own details.
- Delete sections that don't apply. For example, remove the screenshots section if you don't use the screenshots add-on.
- Keep the language plain. Employees should be able to understand it in one read.
- Make sure the policy matches what you actually do. A policy that says less than your tools collect is worse than no policy.
Employee computer monitoring policy
1. Purpose
[Company name] provides computers, accounts and network access so that employees can do their jobs. To manage workload fairly, plan staffing, support employees working remotely and protect company and client information, [Company name] monitors certain activity on company-provided computers. This policy explains what we monitor, why, who can see it and how it is used.
2. Who this policy covers
This policy applies to all employees[, contractors and temporary staff] who use a [Company name] computer, whether in the office, at home or elsewhere.
3. What we monitor
On company-provided Windows computers, our monitoring software records:
- Whether the computer is in active use or idle, based on whether keyboard or mouse input occurs. The software does not record which keys are pressed.
- The application in use and the title of the active window.
- The names of websites visited, such as "example.com." Full web addresses and page content are not recorded.
- System events such as sign-in, lock, unlock and sleep.
- Copying files to removable USB storage devices.
- [If using the screenshots add-on: Periodic screenshots of the screen while the computer is in active use. See section 5.]
[Company name] may also block access to certain websites on company computers.
4. What we do not monitor
- We do not record keystrokes or anything you type, including passwords.
- We do not read the content of email, documents, chat or messages through this software.
- We do not record full web addresses or page content.
- We do not install this software on personal devices.
- We do not use this software to record audio or video from your camera or microphone.
5. Screenshots [delete this section if not used]
Screenshots are taken only while the computer is in active use and are never taken while the screen is locked. Screenshots are deleted automatically after [7 / 14 / 30] days. Access to screenshots is limited to [roles].
6. When monitoring happens
Monitoring occurs whenever a company computer is on and signed in, including outside scheduled work hours. Please do not use company computers for personal activity you would not want recorded as described above.
7. Why we monitor
We use this information to:
- Understand workload and plan staffing.
- Support fair, consistent expectations for employees in the office and working remotely.
- Track schedule adherence for roles with set hours.
- Detect and respond to security risks, such as large file copies to USB drives.
- Investigate specific concerns about policy violations or misuse of company systems.
8. Who can see the information
Access is limited to [list roles, for example: the owner, your direct manager and the office manager]. Our monitoring and IT security provider, [Provider name], operates the system and can access data to support and secure it. All access requires multi-factor authentication. We do not sell or share this information with anyone else except as required by law.
9. How the information is used
Activity data is one input among many. Managers will look at patterns over time and consider the nature of each role, including work that happens away from the computer, such as phone calls and meetings. Activity data alone will not be the sole basis for discipline. If a concern arises, your manager will discuss it with you first.
10. Alerts
The software can send alerts to [roles] for certain events, such as [large USB file copies, use of file-sharing sites, extended idle time during scheduled hours, or significant after-hours activity]. Alerts are reviewed by a person before any action is taken.
11. Monitoring notice
A monitoring notice [is displayed on your computer / is posted at (location)] so that you know monitoring is in place.
12. Your rights
Nothing in this policy limits your right to discuss wages, hours or working conditions with coworkers, or any other right protected by law. [If applicable: Depending on where you live, you may have rights to access, correct or delete personal information. Contact (name/role) to make a request.]
13. Questions
If you have questions about this policy, contact [name, title, email].
14. Changes
[Company name] may update this policy. We will notify employees in writing before material changes take effect.
Effective date: [date]
Acknowledgment form
Several states require a written or electronic acknowledgment. Even where it isn't required, it's good practice. Keep a signed copy in each employee's file.
Acknowledgment of employee computer monitoring policy
I acknowledge that I have received and read the [Company name] Employee Computer Monitoring Policy dated [date]. I understand that [Company name] monitors activity on company-provided computers as described in the policy, including active and idle time, applications and window titles, website names, system events and USB file copies[, and screenshots]. I understand that the monitoring software does not record keystrokes or the content of my email, documents or messages.
I understand that I may ask questions about this policy at any time by contacting [name, title].
Employee name: ______________________________
Employee signature: __________________________
Date: ______________
State-specific additions to discuss with your attorney
- New York: give notice upon hiring, collect acknowledgment, and post the notice in a conspicuous place.
- Connecticut: post the notice conspicuously, describe the types of monitoring and the locations where it may occur, and give employees hired after October 1, 2026 a plain-language statement of prohibited activities that may be monitored without notice.
- Delaware: collect a one-time acknowledgment, or display an electronic notice each day the employee uses company email or internet.
- Maine: give written notice before monitoring begins, an annual written notice, and disclosure to applicants during interviews.
- California: if the CCPA applies to your business, align the policy with your employee notice at collection and privacy policy.
Rolling out the policy
- Finalize the policy with your attorney and make sure it matches your actual settings.
- Brief managers first. Make sure anyone with access understands the ground rules in section 9.
- Announce it live. Use a team meeting or video call. Explain the reason, what's collected, what isn't, who sees it and when it starts.
- Distribute the policy and acknowledgment the same day. Give people time to read it and ask questions.
- Start monitoring after notice is given. Give at least a few days between the announcement and the start date.
- Turn on the employee notice in the monitoring software and post notices where required.
- Add it to onboarding so new hires receive the policy and sign the acknowledgment before their first day of monitoring.
- Review it every year, or when you change what you monitor.
For help with the announcement itself, read how to introduce employee monitoring without killing trust.
