Employee monitoring and workplace privacy issues discovered during due diligence in North Macedonia

Thursday 30 July 2026

Ljupka Noveska Andonova
Qoku & Partners Law Firm in cooperation with Karanovic & Partners, Skopje
ljupka.noveska@karanovicpartners.com

Anisija Stojkovska
Qoku & Partners Law Firm in cooperation with Karanovic & Partners, Skopje

Sanja Lambershek
Qoku & Partners Law Firm in cooperation with Karanovic & Partners, Skopje

Introduction

Digital transformation has significantly changed the way employers manage and supervise their workforce. The use of CCTV systems, electronic communications monitoring, biometric attendance systems, and remote work productivity tools has become increasingly common across industries. While such technologies may serve legitimate business purposes, including security, operational efficiency and regulatory compliance, they also raise important privacy concerns. Workplace monitoring practices represent an increasingly relevant compliance area for buyers and investors conducting due diligence in North Macedonia. Improper monitoring measures may expose companies to regulatory sanctions, employee claims, reputational harm and significant remediation costs. Consequently, reviewing workplace surveillance practices has become an essential component of due diligence.

The legal framework in North Macedonia

Employment relationships in North Macedonia are primarily governed by labour legislation, which recognises the employer’s right to organise work processes and protect business interests while simultaneously safeguarding employees’ dignity, privacy and fundamental rights. Employers may implement monitoring measures where there is a legitimate business justification. However, such measures must remain proportionate, transparent and necessary for achieving a specific purpose. Excessive surveillance may be challenged as an infringement of employee rights and may create disputes with employees, trade unions or labour authorities.

Furthermore, the processing of employee data through monitoring systems is also subject to the Law on Personal Data Protection, which is largely aligned with the principles of the EU General Data Protection Regulation (GDPR). Employers must establish a lawful basis for processing personal data and ensure compliance with core principles such as: (1) lawfulness, fairness and transparency; (2) purpose limitation; (3) data minimisation; (4) accuracy; (5) storage limitation; and (6) integrity and confidentiality. Particular attention is required where monitoring activities involve sensitive categories of personal data, including biometric information used for employee identification or access control purposes.

Key areas of review during due diligence

One of the most common areas reviewed during due diligence involves workplace video surveillance systems. Buyers and investors should assess whether CCTV systems have a clearly documented and legitimate purpose, whether employees have been adequately informed about surveillance activities, and whether the scope of monitoring complies with applicable privacy requirements. Particular attention should be given to the locations covered by surveillance cameras, the retention periods applicable to recorded footage, and the internal procedures governing access to recordings. Concerns may arise where cameras are installed in areas where employees have a heightened expectation of privacy or where monitoring appears disproportionate to the employer’s stated objectives.

Electronic communications monitoring is another important consideration. The monitoring of company email systems, internet usage and other forms of electronic communications is a crucial area of review. During due diligence, investors should examine whether the employer has implemented clear internal policies regulating electronic communications and whether employees have been properly informed about monitoring practices. The scope and frequency of monitoring activities, the methods used to collect and retain information, and the security measures protecting monitored data should also be assessed. Monitoring employee communications without sufficient transparency or appropriate safeguards may create significant compliance risks and increase the likelihood of employee complaints or regulatory scrutiny.

Biometric attendance and access control systems also require careful assessment. The use of biometric technologies, including fingerprint scanners and facial recognition systems, is becoming increasingly common for attendance tracking and access control purposes. Since biometric information constitutes a particularly sensitive category of personal data, due diligence reviews should carefully assess the legal basis relied upon for such processing and whether the use of biometric systems is necessary and proportionate to the employer’s objectives. Investors should also evaluate the security measures protecting biometric databases, the procedures governing data retention and deletion, and the availability of alternative identification methods for employees. Deficiencies in these areas may expose employers to potential enforcement actions.

The growth of remote and hybrid working arrangements has led many employers to adopt software tools designed to monitor employee activity and productivity. These technologies may collect information relating to computer usage, login and logout times, application activity, productivity metrics, screen activity and, in some cases, location data. During due diligence, buyers should determine whether such monitoring measures are necessary for legitimate business purposes, proportionate to the intended objectives, and properly disclosed to employees. Excessive monitoring of remote workers may create significant privacy concerns, negatively affect employee trust, and increase legal and regulatory risks for the employer.

Potential due diligence risks

A common issue identified during due diligence involves the collection and processing of employee information beyond what is necessary to achieve legitimate business objectives. Excessive monitoring may take various forms, including continuous surveillance of employees without sufficient justification, the collection of extensive productivity-related data, the indefinite retention of monitoring records, or monitoring activities that extend beyond working hours. Such practices may conflict with the principles of data minimisation and proportionality, which are fundamental requirements under personal data protection legislation. Where monitoring exceeds what is reasonably necessary, employers may face increased regulatory scrutiny and potential legal challenges from employees.

Another frequent issue involves insufficient transparency. Many workplace privacy compliance issues arise from inadequate communication with employees regarding monitoring activities and the processing of their personal data. During due diligence, investors should assess whether employees have been properly informed about the existence, purpose, scope and legal basis of workplace monitoring measures. Compliance concerns may arise where privacy notices are missing or incomplete, employee handbooks have not been updated to reflect current monitoring practices, monitoring policies have not been formally adopted, or data protection documentation is insufficient. A lack of transparency may increase regulatory exposure, undermine employee trust and contribute to workplace disputes or complaints.

Buyers should also assess whether personal data is being processed lawfully. Employers may face significant compliance risks where workplace monitoring systems process personal data without a valid legal basis or where processing activities exceed the scope originally communicated to employees. This risk is particularly relevant in connection with biometric attendance systems, facial recognition technologies and other advanced monitoring tools that collect substantial amounts of personal information. Failure to establish an appropriate legal basis for processing or to comply with applicable data protection requirements may result in corrective measures and financial penalties.

In addition, privacy-related deficiencies that remain undiscovered until after the completion of a transaction may generate substantial costs and liabilities for buyers and investors. Regulatory authorities may initiate investigations, requiring employers to implement corrective measures or address identified compliance failures. Employee complaints and litigation may also arise where monitoring practices are perceived as intrusive or unlawful. Buyers may incur significant expenses associated with redesigning monitoring systems, updating internal policies, implementing new compliance programmes, and enhancing data protection safeguards. Beyond direct financial costs, non-compliance may have a negative effect on workforce relations and create reputational risks which harm business operations. Consequently, workplace privacy issues should be carefully assessed during transaction planning, due diligence reviews, and risk allocation discussions.

Broader impact

As digital monitoring technologies and remote work arrangements continue to expand, workplace privacy compliance is becoming an increasingly important component of due diligence. Employee monitoring practices are no longer viewed solely as operational matters but as compliance issues that intersect employment law, data protection and corporate governance. Early identification of privacy-related risks can help buyers and investors mitigate potential liabilities, improve transaction planning and ensure compliance with North Macedonia’s employment and personal data protection framework.

Conclusion

Employee monitoring and workplace privacy issues are becoming increasingly important components of due diligence in North Macedonia. Early identification of privacy-related risks can reduce regulatory exposure, minimise post-closing liabilities and support compliance with North Macedonia’s employment and personal data protection framework. By integrating privacy considerations into due diligence processes, investors can better protect the transaction while promoting responsible and legally compliant workplace practices.