WorkplaceCodex

Privacy & Ethics

Last updated: October 2026

Every workplace evidence stream is people data. Its legitimacy is not granted by legal compliance; it is earned through architecture, restraint and visible respect for the people it describes, and it can be lost in a single episode. This page states the principles this methodology holds, the commitments Workplaced makes where its platform carries the evidence, and how personal data is processed on the platform.

The line between evidence and surveillance

The same instrumentation can serve both. Occupancy sensing can inform capacity decisions or track individuals; booking data can reveal allocation failures or audit attendance; collaboration metadata can show organisational structure or monitor employees. The difference is never the sensor. It is a set of deliberate choices: what is collected, at what resolution, for which stated purpose, visible to whom, governed by what. This methodology draws the line explicitly. Workplace intelligence exists to inform decisions about places, policies and provision: in aggregate, for purposes people have been told about. It does not exist to make judgements about individuals. Any use that infers individual performance, audits individual presence, or evaluates individual behaviour is on the wrong side of the line, whatever it is called in the procurement document.

Aggregate by architecture

Aggregation is an engineering discipline, not a promise. Reported metrics carry minimum cohort thresholds, no figure describes fewer than five people, enforced technically, not procedurally. Suppression controls prevent identification by combination: a team of six on a floor of eight on a quiet Friday can re-identify through intersection, and the architecture must anticipate this, because the research literature is unambiguous that naïve anonymisation fails. Data minimisation is the default posture: collect what the decision requires, not what the sensor offers. Purpose limitation is engineered so that using data for a new purpose requires deliberate governance rather than quiet drift: function creep is the standard failure path of workplace measurement, and it is prevented structurally or not at all.

Consent, choice and the asymmetry problem

Individual-level features exist in this methodology in exactly one form: consent-aware, initiated by the employee, revocable, and consequence-free in both directions. The Workplace Passport is the model: a channel through which people can express the conditions under which they work effectively, on their own terms, for their own benefit. Honesty requires naming the hard problem: consent in an employment relationship is asymmetric. When an employer asks, 'voluntary' carries pressure that consumer consent does not. The mitigations are real but partial, genuine consequence-free non-participation, no manager visibility of individual data, participation rates monitored as a trust signal rather than a compliance target, and the residual asymmetry is a reason for restraint about what is ever asked, not a footnote.

Interpretation, bias and human oversight

Data governance is not only about collection; it is about what conclusions the data is allowed to carry. Workplace analytics can encode bias: occupancy patterns read without context penalise part-time workers and carers; presence metrics read as engagement penalise the location-bound and reward the visible; algorithmic pattern-finding inherits whatever the training context assumed. The disciplines are methodological, triangulation before conclusion, team-level context before interpretation, effect sizes and uncertainty stated honestly, and organisational: a human decision-maker accountable for every consequential interpretation, with AI-supported analysis treated as acceleration of human judgement, never its replacement. Technology does not remove judgement. It removes repeated analytical labour.

Transparency and the response obligation

People have a right to know what is measured, why, at what resolution, and what happened as a result. Transparent workplace intelligence means measurement that is announced, purposes that are stated, and, critically, responses that are visible: evidence programmes that collect without visibly acting train the workforce that measurement is extraction, and response rates decay accordingly. The response loop is therefore both an ethical obligation and the evidence programme's own life-support system. Works councils and employee representation are consulted before deployment, not informed after it; in markets where co-determination applies, this is law, and in markets where it does not, it is still the practice that distinguishes evidence from surveillance.

Legal and cultural variation

The legal floor moves by jurisdiction, GDPR and national employment law in Europe, co-determination regimes in Germany and the Netherlands, different consent and monitoring norms in the Gulf, the UK, the US, and the cultural ceiling moves further still: measurement that is unremarkable in one market is a resignation trigger in another. The methodology's position is to design to the highest applicable standard rather than the local minimum, because evidence architectures travel and trust does not survive discovering that the same employer measures one workforce more invasively than another.

WHERE WORKPLACED CARRIES THE EVIDENCE

The following commitments apply to the Workplaced platform and are stated here as published, verifiable claims:

  • ISO 27001 certified
  • GDPR compliant
  • Data hosted exclusively in Ireland
  • Aggregation threshold: minimum cohort of five employees for any reported metric
  • Individual-level data only with explicit employee consent
  • Suppression controls to prevent identification from aggregate data
  • Encryption in transit and at rest
  • Least-privilege access throughout
  • Microsoft Entra ID integration; OpenID Connect and OAuth2 standards
  • Separated production, pre-production and development environments

These are the commitments. The sections above are why they exist.

The privacy statement

Workplaced Technologies Europe B.V. processes personal data to deliver the Workplaced platform. The sections below explain which data we process, why, and what rights you have.

Who is responsible

Workplaced Technologies Europe B.V. is the controller for account data of platform users. For data an organisation (customer) places in the platform, such as employee data and measurement results, that organisation is the controller and Workplaced acts as processor. The arrangements are set out in the data processing agreement.

What data we process

Account data: name, business email address and sign-in credentials of users who receive an account through an invitation from their organisation.

Usage data: technical logs needed to keep the platform secure and available, such as sign-in events and error reports.

Organisation data: data a customer organisation enters itself, such as project configuration, surveys and aggregated measurement results.

Why we process data

We process account data to provide access to the platform and perform the agreement. Technical logs are used for security and troubleshooting. We do not use personal data for advertising and we do not sell data to third parties.

Retention

Account data is kept while the account is active. After the agreement with an organisation ends, the related data is deleted or anonymised according to the data processing agreement.

Your rights

You have the right to access, rectification, erasure, restriction, portability and objection. For data your organisation placed in the platform, please direct your request to that organisation; we support them in handling it. For account data, contact customer@workplaced.com.

You also have the right to lodge a complaint with your supervisory authority.

Security

Workplaced is ISO 27001 certified (certificate 0202968). Read how we protect data technically and organisationally on the Security and compliance page.

Questions about this document? Email customer@workplaced.com.