← Back to blog

Do You Need a Workplace Surveillance Policy in Australia?

August 25, 2026
Do You Need a Workplace Surveillance Policy in Australia?

Yes. If you monitor employees through cameras, computers, GPS tracking, or audio recording, you need a tailored workplace surveillance policy that satisfies the Privacy Act 1988 and, if you operate in New South Wales or the ACT, meets statutory notice requirements. This isn't optional paperwork. In NSW and the ACT, running surveillance without proper written notice can expose you to legal action and render footage inadmissible in a dispute.

The single most urgent thing to check right now: does your current notice give staff written warning before surveillance starts, and does it match the Workplace Surveillance Act 2005 requirement of prior notice, commonly delivered with written notice ahead of time in NSW? If you can't answer that with certainty, your policy has a gap.

Before drafting or revising anything, pull these four sources:

Quick fact: NSW's Workplace Surveillance Act requires employers to give employees written notice before camera, computer, or tracking surveillance begins, and that notice has to specify the kind of surveillance, how it will be carried out, and when it starts.

Key Takeaways

A defensible workplace surveillance policy in Australia combines Privacy Act compliance, jurisdiction-specific notice rules in NSW and the ACT, and proportionate, purpose-limited monitoring backed by documented technical deployment.

PointDetails
No single national lawCombine the Privacy Act 1988 and APPs with state or territory surveillance legislation for full coverage.
NSW/ACT notice is non-negotiableGive written notice, commonly 14 days ahead in NSW, before starting camera, computer, or tracking surveillance.
Employee records exemption has limitsIt covers direct employee records only, not contractors or third-party vendors handling surveillance data.
Proportionality beats blanket monitoringDocument a specific reason for each surveillance type rather than justifying monitoring generally.
Professional installation supports complianceDjcengineering's site surveys and accredited CCTV installs document field of view, signage, and retention to back up policy claims.

Table of Contents

There's no single federal law that governs workplace surveillance in Australia. Employers have to piece together obligations from the Privacy Act 1988 and its Australian Privacy Principles, plus whichever state or territory surveillance law applies to where the work happens. That patchwork catches out a lot of employers who assume a privacy policy written for Sydney head office automatically covers a Perth warehouse or a Darwin depot.

NSW and the ACT are the outliers with dedicated workplace surveillance statutes: the Workplace Surveillance Act 2005 (NSW) and the Workplace Privacy Act 2011 (ACT). Both impose specific notice and conduct rules that other states don't have in the same form. Queensland, Victoria, South Australia, and the rest generally rely on broader surveillance devices legislation and general privacy law, which is less prescriptive but still enforceable.

One wrinkle catches almost every employer off guard: the Privacy Act's employee records exemption. It limits how the APPs apply to records an employer holds directly about its own current or former employees, provided the record relates to the employment relationship. It does not extend to job applicants, contractors, or data handled by third-party service providers. Send your CCTV footage to a cloud storage vendor and that data can fall straight back under full APP obligations.

Legal advisors are blunt about this: "monitoring just in case" isn't a defensible position. Employers need a documented, proportionate reason for each specific type of surveillance, not a blanket justification for watching everything.

Three bodies matter if things go wrong:

  • The Office of the Australian Information Commissioner (OAIC), which handles Privacy Act complaints and can investigate serious or repeated breaches.
  • State and territory regulators, including NSW courts that hear Workplace Surveillance Act matters and can order penalties for covert or unnotified monitoring.
  • The Fair Work Ombudsman, which addresses surveillance issues that intersect with unfair dismissal, adverse action, or workplace rights.

Get the notice wrong in NSW and you're not just risking a complaint. You risk having the surveillance evidence itself thrown out if you ever need it to support a disciplinary decision.

What Counts as Workplace Surveillance?

Most employers picture a CCTV camera in the loading bay and stop there. The legal definition is much broader, and your policy needs to name every category you actually use.

  1. Camera and CCTV surveillance — fixed cameras, body-worn cameras, dash cams in company vehicles.
  2. Computer and IT monitoring — email content, browser history, keystroke logging, software usage tracking, screen recording.
  3. Tracking and GPS surveillance — vehicle telematics, asset tracking, location data from company phones or tablets.
  4. Audio surveillance and recording — call recording, voice-activated devices, ambient microphones on CCTV units.
  5. Biometric and access-control data — swipe cards, fingerprint scanners, facial recognition entry systems.

Map these against your actual sites. An office might only need IT monitoring and door access logs. A warehouse likely runs CCTV plus vehicle GPS. A remote worker's laptop monitoring raises different privacy questions than a shared office terminal, because you're now reaching into someone's home.

Some activities sit in a higher-risk category almost automatically: audio recording in break rooms, covert cameras anywhere, and any monitoring of areas where employees have a reasonable expectation of privacy, like bathrooms or change rooms. Those need either an outright prohibition in your policy or documented, narrowly justified exceptions.

Covert camera lens hidden in wall vent

Pro Tip: Run a surveillance audit before you write a single clause. List every camera, tracking device, and monitoring tool currently in use across every site, then check each one against your draft policy. Gaps show up fast.

Key Elements Every Workplace Surveillance Policy Should Include

A defensible policy isn't a paragraph bolted onto your employee handbook. It needs structure that stands up if a regulator, court, or Fair Work Commission ever reads it line by line.

Build the document around these headings:

  • Purpose and lawful basis — why you're monitoring, tied to a specific business or safety reason, not a general catch-all.
  • Scope — which sites, roles, devices, and surveillance types are covered.
  • Notice and transparency — how, when, and where employees are told, including signage locations and written notice timing.
  • Prohibited areas and uses — bathrooms, change rooms, prayer rooms, and any use of surveillance for reasons unrelated to the stated purpose.
  • Data access and retention — who can view footage or logs, how long it's kept, and the criteria for deletion.
  • Disclosure rules — when and to whom data might be shared, including law enforcement requests.
  • Roles and responsibilities — who administers the system, approves access requests, and handles complaints.
  • Review schedule — a fixed date or trigger event for reassessing the policy.

Then connect the dots to your other workplace documents. Your surveillance policy should cross-reference your acceptable use policy, your information security policy, and your disciplinary procedure, so an employee reading one document understands how it fits with the rest. A surveillance policy that contradicts your IT acceptable use policy on email monitoring creates exactly the kind of inconsistency a lawyer will exploit in a dispute.

Two principles should run underneath every clause you write:

  1. Proportionality — the level of monitoring has to match the actual risk. Full-time keystroke logging for a receptionist role is hard to justify next to occasional access-log reviews.
  2. Purpose limitation — data collected for security shouldn't quietly get repurposed for performance management unless your policy explicitly allows it and staff were told.

The Fair Work Ombudsman's best-practice guidance backs this structure precisely because vague, catch-all policies tend to fail both compliance checks and internal disputes.

NSW and ACT Notice Rules: What Trips Employers Up

If you employ staff in New South Wales, the Workplace Surveillance Act 2005 sets out exactly what your notice needs to say: the kind of surveillance, how it's carried out, when it starts, and whether it's continuous or intermittent. Written notice generally needs to reach employees before surveillance begins, with 14 days commonly cited as the practical benchmark employers use to stay safely compliant.

Camera surveillance under the NSW Act also requires visible signs at entrances alerting people that cameras operate on the premises, positioned so anyone entering actually sees them, not tucked behind a fire door.

The ACT's Workplace Privacy Act 2011 runs on a similar logic: employers must notify employees before covert surveillance is even approved, and overt surveillance requires clear advance notice covering the same categories NSW does. The ACT Act also sets a formal process for employers seeking covert surveillance authority through a magistrate, which is a heavier bar than most employers expect.

The traps that catch employers most often:

  • Rolling out one national policy written for head office and applying it unchanged to NSW or ACT sites without the extra notice content those states require.
  • Installing vehicle GPS trackers without giving drivers the specific written notice the tracking surveillance provisions demand.
  • Treating "we told them at induction two years ago" as sufficient notice for a system installed last month.
  • Using covert monitoring based on suspicion without the documented process and, in the ACT, without magistrate authorization.

Practical guidance from employment law specialists consistently flags the single-policy problem as the most common failure point, precisely because it's the easiest mistake to make and the hardest one to notice until an employee raises a complaint. A practical fix is a short jurisdictional addendum attached to your core policy, stating the extra notice period and content NSW or ACT law demands, without rewriting the entire document.

A Drafting Checklist and Sample Clauses You Can Adapt

Work through this order when building or revising your policy:

  1. Audit every surveillance type and location currently in use.
  2. Draft the core national policy covering purpose, scope, and general notice.
  3. Attach jurisdiction-specific addenda for NSW and ACT sites.
  4. Route the draft through legal or HR sign-off before circulation.
  5. Set signage and written notices before, not after, go-live.

Sample clauses worth adapting:

  • Purpose clause: "Surveillance is conducted for the purposes of workplace safety, asset protection, and operational efficiency, and will not be used to monitor union activity or protected industrial action."
  • Notice clause (NSW): "Employees will receive written notice at least 14 days before new camera, computer, or tracking surveillance commences, specifying the type, method, and timing of surveillance."
  • Signage clause: "Cameras are indicated by signage at all public entrances to premises where camera surveillance operates."
  • Vehicle tracking clause: "Company vehicles fitted with GPS tracking will display a notice inside the vehicle, and drivers will be notified in writing before tracking begins."

Contractors and visitors need separate treatment. Employees fall under your surveillance policy through their contract; contractors need the notice built into the service agreement itself, and visitors typically only need signage since you're not collecting ongoing behavioral data on them the way you would an employee.

A policy sitting in a shared drive protects nobody. Getting it into daily practice takes a deliberate sequence.

  1. Notify before you switch anything on. Letters of offer for new hires, induction sessions for existing staff, and a standing notice on the staff portal all need to say the same thing, in the same words.
  2. Bake it into contracts. New employment agreements should reference the surveillance policy directly, and existing contracts may need a variation notice if surveillance is being introduced for the first time.
  3. Extend it to vendors. Any third party handling footage or monitoring data, cloud storage providers, IT support contractors, needs a data handling clause in the procurement agreement, not a verbal assurance.
  4. Train the people who run it. Managers need to know what they're allowed to review and why; IT and security staff need clear escalation paths for access requests; everyone needs to know who owns compliance auditing.

Set a recurring audit, even a simple quarterly check that signage is still up and notices still match what's actually installed, catches drift before it becomes a complaint.

Contractors, Cloud Vendors, and the Employee Records Exemption

The employee records exemption only covers records an employer holds directly about its own current or former employees, and only where the record relates to the employment relationship. It doesn't cover contractors, job applicants, or data sitting with an outside vendor.

That gap matters the moment you use cloud-based CCTV storage or a third-party monitoring platform. The vendor is generally bound by full APP obligations, which means your contract needs specific clauses covering data handling, breach notification, and deletion timelines. Run due diligence on any payroll, IT, or security vendor before signing: ask how they store footage, who can access it, and what happens to the data when the contract ends. A partner resource on security and data handling practices is a useful benchmark for the kind of due diligence questions to ask.

The safer play, and one increasingly treated as best practice, is applying APP-level protections to employee records voluntarily, even where the exemption technically lets you skip them.

Technical Best Practices for Compliant CCTV Deployment

Legal compliance and camera placement are the same conversation, not two separate ones. A camera angled into a break room window or catching a neighboring property creates a privacy problem no policy wording fixes after the fact.

  • Position cameras to capture entry points, asset zones, and work areas, never bathrooms, change rooms, or spaces with a reasonable expectation of privacy.
  • Store footage on encrypted systems with logged access, so every view or export is traceable.
  • Set retention periods that match your stated purpose, then auto-delete, rather than keeping years of footage "just in case."
  • Configure AI analytics with human review built in. European monitoring research shows algorithmic flagging without human oversight raises risk, not just for accuracy but for how defensible the decision looks later.
  • Respect after-hours boundaries in system settings, particularly for remote or hybrid staff, given the direction employment law is heading on out-of-hours monitoring.

Pro Tip: A documented site survey, recording field of view, signage placement, storage architecture, and retention schedule, is exactly the kind of evidence you want on hand if a surveillance decision ever gets challenged. Djcengineering builds that documentation into every accredited CCTV installation, pairing a 4K AI-capable camera system with a first-visit fix rate that avoids the placement redos which quietly create compliance gaps.

Handling Complaints and Data Breaches Involving Surveillance Records

When an employee raises a concern about surveillance, or footage becomes evidence in a disciplinary matter, the process matters as much as the outcome.

  • Preserve the original footage or log file immediately, don't edit, clip, or overwrite before the investigation concludes.
  • Restrict access to a named investigator and document every person who views the material.
  • Assess whether unauthorized access or a system failure has exposed the data to anyone outside your policy's stated access list.

Quick fact: A breach involving surveillance data can qualify as an eligible data breach under the Privacy Act if it is likely to cause serious harm, which triggers a notification obligation to the OAIC and affected individuals.

Discipline decisions based on surveillance evidence should always reference the specific policy clause that authorized the monitoring in the first place. If the notice wasn't given properly, the evidence itself becomes vulnerable to challenge, regardless of what it shows.

Primary Legislation and Regulator Guidance to Bookmark

Keep these close when drafting or auditing your policy:

Balancing Security and Privacy Without Guesswork

The employers who get this right treat the policy as a living document, not a launch-day checkbox. A properly documented site survey does double duty: it satisfies proportionality questions before anyone asks them, and it gives you a paper trail if a decision ever gets challenged. Revisit the policy annually, or the moment you add a camera, a tracker, or a new vendor.

— Dylan

Get a Compliance-Ready CCTV Setup From Djcengineering

Writing the policy is half the job. The other half is a system that actually backs up what the policy promises, correct camera placement, working signage, encrypted storage, and access logs that hold up if anyone ever asks. That's where a generic installer falls short and a properly scoped one earns its fee.

Djcengineering

Djcengineering handles both sides of that equation across South East Queensland: a site survey that documents field of view and signage placement before a single camera goes up, accredited installation with a 98% first-visit fix rate, and secure, encrypted storage configured to match your retention policy rather than a generic factory default. Our 4K AI-capable CCTV systems are built for exactly the compliance documentation this article covers, and we handle the networking side too, from secure structured cabling to reliable connectivity, so your surveillance data never sits on a shaky connection. If your current setup was installed without a compliance conversation, request a site survey and quote through Djcengineering and get a system that matches your policy on paper.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources