Skip to content
Novot AI
NLBook a call
← Back to knowledge base

May an AI read along with your staff's conversations?

Yes, but not by default. If the system records conversations traceable to an employee, it is suitable for checking behaviour and performance and therefore an employee monitoring system (article 27(1)(l) of the Dutch Works Councils Act). With a works council in place, consent is required before the decision; without it the decision is null and void once the council invokes that in writing. On top of that the monitoring must be necessary and proportionate, you must announce it to staff in advance, and on the phone to the customer as well.

Published on

An AI assistant in customer contact does not only read what the customer writes. It also reads what your employee writes back. That is almost impossible to avoid: if the assistant has to draft replies, summarise conversations or sense when it should hand over to a person, the whole exchange passes through it — both sides. And the moment that happens, a second set of rules comes into play that many business owners overlook. Not the rules protecting the customer, but the ones protecting your own staff.

This page is about that second set. When does "the AI just reads along" turn into an employee monitoring system? What does that mean for the works council? Under what conditions are you allowed to check up on your people at all? What is the difference between steering on the quality of your customer contact and individually assessing the people who do that customer contact? And does anything change when your team works from home?

Why staff are a category of their own

The instinct around AI and privacy always runs towards the customer. Understandable: a customer has nothing to do with your business except their question, so the law protects them firmly. But the Dutch Data Protection Authority puts it bluntly: the right to privacy applies on the work floor just as much as outside it, so employers may not simply monitor their employees.

"Not simply" is the hinge here. It does not say monitoring is forbidden. It says you have to be able to explain something before it is allowed. And with staff, that explanation is heavier than with customers, for one reason: an employee cannot walk away. A customer who dislikes your methods buys elsewhere. An employee who dislikes the dashboard does not resign. That imbalance is exactly why there is an extra layer on top of the ordinary privacy rules — a layer that comes from employment law and that you will not find in the GDPR.

The practical consequence: everything you have already arranged for the customer side does not automatically cover the staff side. You can have your lawful basis, your processing agreement and your retention period neatly in order and still have introduced a system you were not allowed to introduce. One route says nothing about the other.

When does reading along become an employee monitoring system?

This is where the crucial misunderstanding sits. Business owners test against their own intention: "I do not want to track my people at all, I just want faster replies." That is an honest motive. It is simply not the test the law applies.

The Dutch Works Councils Act, in article 27, first paragraph, under l, refers to arrangements concerning facilities that are aimed at or suitable for observing or checking the attendance, behaviour or performance of the people working in the business. Read that clause again: or suitable for. The whole issue sits in those three words. It is not your intention that determines whether something is an employee monitoring system, but what the system is capable of.

An AI that records every incoming and outgoing message, links it to an employee and attaches a timestamp and a quality judgement is suitable for checking behaviour and performance. Even if nobody ever looks at it. Even if the report is switched off by default. The capability is the trigger, not the use. That makes the question "do we have an employee monitoring system here?" a yes far sooner than business owners expect.

A few signals by which you can recognise it in AI-driven customer contact:

  • The data is traceable to an individual. A team total is something quite different from a list with names behind it.
  • The system records behaviour, not just outcomes. How someone phrases things, how often someone overwrites the AI's draft, how long someone stays on a conversation.
  • It happens continuously, not in response to a concrete incident.
  • The employee cannot avoid it: it sits inside the channel they are required to work in.

If you tick two or more of these, assume you are dealing with an employee monitoring system and not with a handy extra.

Why the works council goes first

If you have a works council, it holds a right of consent where an arrangement for an employee monitoring system is concerned. The Dutch Data Protection Authority names this explicitly as one of the subjects the right of consent covers. Consent is not the same as advice. With advice, the council may hold an opinion and you decide afterwards. With consent, you may not take the decision unless the council says yes — or, if it says no and you consider that unreasonable, unless the subdistrict court grants substitute permission.

What happens if you skip that step is set out in article 27, fifth paragraph of the same act: a decision taken without the consent of the works council or the permission of the subdistrict court is null and void if the council invokes that nullity in writing. Null and void means the decision never existed. Not "you get a slap on the wrist", but the introduction itself stands on nothing legally. That is a real business risk, because the integration is running, the vendor is being paid and the data is being processed — only without a valid decision underneath it.

Two things commonly go wrong here. The first is timing. Consent belongs before the decision, not before go-live. If you have already signed the contract and built the integration, the council is no longer a counterpart but a formality — and it will notice. The second is scope. The right of consent concerns the arrangement, meaning the agreements: which data, who may access it, how long it is kept, what it may and may not be used for. A demo of the tool is not an arrangement. Put those agreements on paper and obtain consent on that, because otherwise you will be back at the table with every expansion.

What if you have no works council?

Most small and medium-sized businesses do not have one. That does not make the question disappear; it means the right of consent under article 27 does not come into play and other forms of consultation remain. In a smaller business an employee representative body or a staff meeting can fill that role. Without either of those, consultation falls back on the ordinary employer-employee relationship.

Important to understand: the absence of a works council removes not a single condition. The privacy conditions below — necessity, less intrusive alternatives, proportionality and announcing it in advance — do not hang on employee participation. They apply just as much with five employees and one shared mailbox. What you lose without a works council is not the obligation, but the pushback that could have helped you meet the obligation properly. In practice a short written agreement with the team is therefore not a needless courtesy but the only evidence that you discussed it at all.

Under what conditions may you monitor?

The supervisory authority sets three hurdles and one duty to inform. They are easy to remember and surprisingly strict once you work them out.

One: necessity. The Dutch Data Protection Authority states that monitoring your staff must be necessary — and immediately fills that in: it means you cannot reach your goal in another way that is less intrusive for your employees. That is a test most AI dashboards fail. If you want to know whether customers are waiting too long, you can measure that at mailbox level. If you want to know whether your answers are correct, you can sample content without a permanent judgement per employee. "We already have the data, because the AI reads it anyway" is not an argument — the fact that it passes through technically does not make using it necessary.

Two: a concrete, predefined purpose. You have to know what you are measuring for before you measure. Purposes that only present themselves once the reporting exists — "we saw that someone was slow, so we raised it in the review" — are exactly the purpose drift the law protects against.

Three: proportionality. The intrusion has to be in proportion to what it gains you. Full transcription of every phone call in order to discover the frequently asked questions is a heavy measure for a light purpose. Ask yourself whether you would defend the measure if it were applied to you.

And: announce it in advance. Covert monitoring is an exception with its own heavy conditions — not the default mode. With AI that reads along, your employees must therefore know that it happens, what is recorded and what it is used for. On the phone this goes a step further: the Dutch Data Protection Authority states that you must also inform the person your employee is calling, such as a customer, in advance that the call is being recorded and what you use the recordings for, for instance training. Two sides of the line, two people who need to know.

Steering on quality or assessing an individual — where is the line?

This is the distinction everything turns on in practice, and it is less vague than it sounds. The line sits at the question: can the outcome be traced to one person, and does it have consequences for that person?

Steering on quality means you learn something about your process. Which questions come in most often, where does it get stuck, which standard answers are no good, at what times of day is the wait too long. You need no names for that. You need conversations, aggregated, and preferably as little on top of that as possible.

Individual assessment means the outcome says something about one employee and weighs in on how things go for them: in a performance review, in an appraisal, in a contract renewal. The moment that is the case, extra brakes apply. A score determined by a model is not automatically valid evidence. You have to be able to explain what it is based on, and the employee must be able to argue against it. And if you let an assessment with consequences be determined entirely by the system without a human genuinely looking at it, you also run into the rules on automated decision-making.

The practical middle road: use AI signals as a reason to look, never as a conclusion. A model that notices a certain type of conversation often escalates is useful. That same model producing a grade per employee that lands unread in a personnel file is a problem — legally, and for the atmosphere in your team.

Does anything change when your team works from home?

No, and that is precisely the point. The Dutch Data Protection Authority is explicit about it: when your employees work from home, the same rules on monitoring apply as if they were present at work. So you may not suddenly monitor them more intensively because they are working remotely.

That runs straight against the instinct many business owners have. In the office you can see whether someone is working; at home you cannot, so you want something to close that gap. That "something" is exactly what is not allowed. The loss of visibility is not a new purpose and therefore not a new justification. Concretely: no extra activity tracking, no screen-time logging, no login patterns, no higher frequency of reading along purely because the employee is at home.

There is another reason for caution here. An AI that calls or chats with customers from a home address often captures more than would happen in the office: background noise in transcripts, timestamps that reveal something about a private rhythm, sometimes video. That touches the private environment of your employee and of the people they live with. What was still defensible in the office can become disproportionate at home — the same measure, a heavier intrusion.

Which form of watching requires what?

The table below sets the forms that occur most often in AI-driven customer contact against what you need to have arranged for them. It does not replace your own assessment, but it shows how quickly the requirements mount once you shift from process to person.

Forms of AI watching in customer contact, alongside what you must have arranged for each
Form of watchingEmployee monitoring system?What you must have arranged
AI summarises closed conversations on the customer record, without the employee's nameAs a rule, noRecord that no tracing back to the employee takes place, and close that off technically as well. Inform the team that the AI reads along.
AI drafts replies that the employee edits and sendsOnly if the editing behaviour is storedAn agreement that drafts and edits are not used for assessment. A retention period for the edit history.
Handling times per mailbox or per teamUsually not, provided the team is large enoughWrite down the purpose in advance. Note: in a team of two, a team figure is still traceable to individuals.
Handling times and volumes per employeeYesConsent from the works council. Substantiate necessity: why is team level not enough? Announce it to employees in advance.
AI assigns a quality or tone score per reply or per employeeYes, in its heaviest formConsent, a proportionality assessment, an explanation of how the score is produced, a way to argue against it, and a human who decides on the substance before any consequences follow.
Recording or transcribing phone callsYes, as soon as recordings are retrievable per employeeAll of the above, plus informing the customer in advance that recording takes place and what for. Keep the retention period short.
AI flags unusual behaviour, for instance on suspicion of fraud or data leaksYesLimit it to flagging against rules you defined in advance. Targeted investigation of one person is a separate decision with its own assessment and its own file.
Extra measurement because employees work from homeYesNothing. This is not allowed: working from home is not an independent reason for more intensive monitoring.

What do you record before you switch it on?

Most of the work sits not in the technology but in the four pages around it. What follows is the minimum set with which you can later show that you made the assessment — and with which you do not have to start from zero if an employee complains or the supervisory authority asks a question.

  1. The purpose, in one sentence, per measurement. Not "improving customer contact", but for instance "establishing which three types of question cause the longest wait". Purposes you cannot get into one sentence are usually not yet purposes.
  2. The necessity test. Which less intrusive options did you consider, and why did they fall away? This is the question you can no longer reconstruct convincingly afterwards, so write it down before you choose.
  3. Exactly what is recorded, and what is not. Field by field. Conversation text yes, keystrokes no. Timestamp yes, location no. What is left out matters as much as what is included.
  4. Who it can be traced to and who can access it. Rights per role, not per person who happens to ask. Your AI vendor falls under this too.
  5. How long it stays. Measurement data about individuals has a shorter shelf life than the customer correspondence itself. Put a separate period on it, not the same one as your bookkeeping.
  6. What the outcome will and will not be used for. This is the agreement that reassures your team most and that you will need most badly if a dispute ever arises.
  7. How you announce it. A line in a staff handbook nobody reads is not an announcement. Tell them, show them, and record when you did so.
  8. Who took the decision, when, and with whom it was discussed. Where there is a works council: the written consent itself, together with the arrangement it relates to.

The three mistakes made most often

Finally, briefly, the patterns that keep recurring in this subject.

Asking the team for permission after the fact. Within an employment relationship, consent from the employee is a shaky basis, because an employee rarely feels free to say no. Do not assume that a signature under an email closes the gap left by missing works council consent and missing necessity.

Taking the functionality along "because it comes with it anyway". A lot of customer contact software ships agent statistics by default. On by default is a choice, even when you did not make it yourself. Switch off what you do not need, and record that you did.

Measuring what is easy instead of what counts. Response time is simple to measure and says little; whether the customer's problem was solved is hard to measure and says everything. Systems that measure the easy thing steer your team towards the easy behaviour. That is not a legal objection, but it is why many of these dashboards end up delivering nothing — and a measure without a yield does not pass the necessity test anyway.

The summary of this page fits on one line: an AI may read along with your staff, but not by default. First determine whether the system is suitable for monitoring, then go past employee participation, then test necessity and proportionality, announce it in advance to both sides of the conversation, and record what you decided. In that order.

See what Novot AI can do for your business.

Book a call