# EMPLOYEE MONITORING POLICY
Date: 1 April 2029
Parties: Cedar & Finch Retail Ltd and its workers
## 1. Purpose of this policy
This policy applies from 1 April 2029 to workers of Cedar & Finch Retail Ltd, 22 Market Square, Leicester LE1 5AB. It explains limited monitoring of company systems, warehouse CCTV and vehicle telematics; it is not a licence to monitor private activity.
## 2. Scope and definitions
Purposes are network security, fraud prevention, stock safety, driver safety, service quality and investigating specific suspected misconduct. Monitoring must be necessary, proportionate and based on a documented lawful basis; it must not be used for general curiosity or covert productivity scoring.
## 3. Operating rules
Company email, access logs and managed-device security events may be logged. CCTV covers entrances, tills and stock areas, not toilets or changing rooms. GPS is active during paid delivery work and normally disabled outside it. Audio recording, keystroke capture and biometric monitoring are not used under this policy.
## 4. Consent and controls
Workers receive this notice before monitoring starts. Cedar & Finch will consult affected staff where required, complete a data-protection impact assessment for higher-risk processing, and tell workers about any material change. Managers may access records only for a stated purpose and must not secretly copy them.
## 5. Retention and security
Security logs are kept for 90 days, CCTV normally 31 days, and investigation material until the case and any appeal are complete, then deleted under the retention schedule. Access is role-based, exports are recorded, and suppliers must follow written confidentiality and UK GDPR obligations.
## 6. Rights and enquiries
Workers may ask HR or the Data Protection Lead about processing and may exercise applicable UK GDPR rights, subject to lawful exemptions. Monitoring evidence will not by itself determine misconduct; a fair process, opportunity to respond and ACAS-consistent procedure remain required.
## 7. Review and publication
Complaints go to HR, then the Data Protection Lead, without removing the right to complain to the ICO or pursue an Employment Tribunal or court route where available. The board reviews this policy annually and publishes the current version on the intranet.