Screen recording in the contact center done right: GDPR, employee data protection & works agreement
Screen recording in the contact center done right: after the CJEU ruling on § 26 BDSG – legal basis, works agreement, purpose limitation, retention periods and technical safeguards for GDPR-compliant screen capture.
Screen recording shows what advisors do on screen during a conversation: which forms they open, what they enter, how they navigate systems. Combined with call recording, it creates a complete picture of an interaction – valuable for quality management, training, compliance evidence and process improvement. But because it processes both customer data and employees' personal data, doing it lawfully is demanding. This guide summarises what matters in 2026.
Note: This article is general orientation and does not replace individual legal advice.
Why screen recording in the contact center?
Screen recording closes the gap that audio-only recording leaves. Only the screen reveals whether a case was documented correctly in the CRM, whether mandatory fields were captured, or where a process breaks down. Typical purposes are quality management (objective assessment instead of gut feeling), onboarding new staff with real examples, evidencing regulatory obligations (for example in financial services or healthcare), and optimising workflows and systems. The value is high – which is exactly why the data-protection basis must be right.
Two data-protection layers: customer and employee data
Screen recording always involves two groups of data subjects. On one side, customers whose data becomes visible on screen (name, contract data, potentially payment or health data). On the other, employees whose working behaviour and performance are captured by the recording. Both layers need their own clean legal basis – and the employee layer in particular has been in flux since 2023.
Legal basis after the CJEU ruling (C-34/21): what now applies
For a long time, § 26 (1) BDSG was treated as the obvious basis for processing employee data. However, in its ruling of 30 March 2023 (Case C-34/21), the CJEU held that such a national provision is incompatible with EU law where it essentially only repeats the GDPR's general lawfulness conditions. The opening clause in Art. 88 GDPR only allows "more specific" rules – not a mere duplication. In practice, this makes § 26 (1) sentence 1 BDSG an uncertain legal basis.
For contact centers this means: processing of employee data through screen recording should rest on more robust grounds. Options include the general GDPR grounds (Art. 6(1) GDPR, in particular necessity for the employment relationship or legitimate interest after careful balancing) and – especially relevant in practice – the works agreement as a collective agreement within the meaning of Art. 88 GDPR. An important clarification from 2025 CJEU case law: a works agreement cannot legitimise processing arbitrarily. It must fully comply with the GDPR's principles and minimum standards; what would be unlawful under the statutory grounds cannot be justified by a works agreement either.
Outlook: a ministerial draft of an Employee Data Protection Act dated 8 October 2024 is intended to bring more clarity; it is under inter-ministerial coordination. Until then: choose the basis carefully, document it and review it regularly.
Works council co-determination (§ 87 (1) no. 6 BetrVG)
Screen recording is a technical device suitable for monitoring employees' behaviour and performance. This triggers the works council's mandatory co-determination right under § 87 (1) no. 6 BetrVG. Without involving the works council, injunction claims may arise and unlawfully obtained findings can be challenged in proceedings. The introduction and design of screen recording – purposes, scope, retention, access rights, evaluation rules – therefore belongs in a works agreement, which can simultaneously serve as the GDPR legal basis. Relying solely on individual employee consent is risky, because its voluntary nature is regularly doubted in the dependent employment relationship.
Purpose limitation, data minimisation and retention
The principle of purpose limitation requires naming the recording purposes specifically in advance – for example quality management, training, compliance evidence. If you record only "for training purposes", you may not simply reuse the data later for a different evaluation. Data minimisation means recording no more than necessary: selective or event-based recording, hiding areas that are not needed and masking sensitive content significantly reduce the intrusion.
For retention, the GDPR sets no fixed period; it must be defined, documented and aligned with the purpose. As guidance: screen recordings are often kept for a short, defined period (only as long as needed for the specific evaluation, frequently a matter of weeks), unless a specific reason – such as an ongoing investigation – justifies longer retention. Regulatory retention obligations may differ. Automated deletion tied to purpose and retention period is the best evidence of lived compliance.
Technical and organisational measures
Recordings must be protected by appropriate technical and organisational measures, scaled to sensitivity and risk. Proven measures include encryption (in transit and at rest), strict access limitation on a need-to-know basis, an audit-proof access log, selective or event-based recording, and automatic masking of sensitive data (e.g. payment or health data) before storage. This keeps recordings useful for quality and training while building data protection in "by design".
Transparency towards employees and customers
Employees must know that, why and to what extent recording takes place – ideally set out clearly in the works agreement and complemented by understandable employee information under Art. 13 GDPR. Customers must be informed about the processing of their visible data; the privacy policy should state purpose, legal basis, retention, recipients and data-subject rights. Transparency is not optional but a legal duty – and it builds acceptance in the team.
Compliant implementation with onsoft
onsoft combines screen and call recording in a platform built for compliance: selective and event-based recording, masking of sensitive data, fine-grained access rights with logging, configurable retention and deletion policies, and analytics for objective quality management. This lets you implement the requirements of the GDPR, employee data protection and the works agreement technically – without losing the value for quality and training. Talk to us about an implementation that fits your governance.
Frequently asked questions (FAQ)
Is screen recording of contact center employees allowed at all?
Yes, under conditions. It needs a robust legal basis (after the CJEU ruling on § 26 BDSG, typically Art. 6 GDPR combined with a works agreement), works council involvement (§ 87 (1) no. 6 BetrVG), clear purpose limitation, data minimisation, defined retention periods and transparency.
Is employee consent sufficient as a legal basis?
Usually not on its own. In the employment relationship, the voluntary nature of consent is often doubted because of the dependency. A works agreement and the statutory grounds are more robust.
What changed with the CJEU ruling C-34/21?
The CJEU classified § 26 (1) sentence 1 BDSG as incompatible with EU law because it essentially only repeats the GDPR. Processing of employee data must therefore rest on more robust grounds, and a works agreement must fully comply with the GDPR.
How long may screen recordings be stored?
The GDPR sets no fixed period; it must be defined, documented and aligned with the purpose. Screen recordings are often kept for a short defined period unless a specific reason justifies longer retention. Automated deletion evidences compliance.
Which technical measures make sense?
Encryption, need-to-know access limitation, audit-proof access logs, selective or event-based recording, and automatic masking of sensitive data before storage.


