Skip to content

Contents  ·  People

When Individual Data Is Justified

Four cases where attribution is legitimate, the controls each requires, and the drift that turns a justified system into surveillance.

Reference

Individual measurement is sometimes necessary. Naming the cases precisely is what prevents the category expanding until it covers everything.

Safety incident investigation

Justification: establishing what happened requires knowing who was involved and where.

Controls: access triggered by an incident, not standing; a defined authoriser; investigation scope limited to the incident window; findings focused on conditions rather than blame.

The trap: using incident-related access to review unrelated performance. This should be technically prevented by scoping the retrieval, not by asking people not to look.

Equipment competence

Justification: operating handling equipment without certification is unlawful in most jurisdictions, and access control is how it is enforced.

Controls: the record covers licensing and pre-use checks, not productivity; retention matched to the certification cycle.

The trap: the machine now knows who is driving, so utilisation, speed and impact data are all attributable. Keep the purpose limitation explicit here, because this is where drift is easiest.

Training and support

Justification: someone whose work is going badly may need help, and identifying them requires attribution.

Controls: no consequence attached; used by a supervisor to offer support, not by a system to issue warnings; not retained as a performance record.

The trap: the same data, over time, becoming a performance file. If it is used for support it should not also be evidence.

Pay

Justification: premiums, piece rates and hours require individual measurement by definition.

Controls: limited to what pay requires; disputes handled through the normal route with the data available to the worker.

The trap: the pay system's data being used for operational ranking.

The controls that apply to all four

A written purpose, narrow.

Named access, logged.

A retention period, short, enforced by deletion.

A route for the worker to see and challenge their own data.

A review of whether the justification still holds, annually.

Human involvement in any decision that affects the person, with a route to contest, which is a legal requirement in several jurisdictions for automated decisions with significant effects.

The drift to watch

Every one of these systems drifts the same way.

Collected for safety, reported for productivity.

Collected for training, retained as evidence.

Collected for pay, used for ranking.

Access granted for an investigation, retained afterwards.

Detect it by auditing access, periodically, against the stated purposes. Access that does not map to a stated purpose is the finding.

What to refuse

Standing individual dashboards for supervisors, which have no purpose that team-level data does not serve and which guarantee drift.

Automated warnings from rate data.

League tables of workers, in any form.

Retention of individual traces beyond the stated period.

Requests to use safety data for a performance conversation, which should be declined with the reason and escalated if pressed.

Auditing access against purpose

The check that detects drift before it becomes normal.

Log every access to the individual stream: who, when, which records, and the stated reason.

Review quarterly.

Map each access to one of the stated purposes.

Access that maps to none is the finding, and it is usually curiosity or a supervisor looking at their team.

Report the audit result, including a clean one, which is what makes the control visible to the people it protects.

Deleting on schedule

Retention limits are the control most often written and least often enforced.

Automated deletion, because manual deletion does not happen.

Verified, with a report of what was removed.

Including backups and extracts, which is where retained data survives a deletion policy.

With a hold mechanism for incident investigations, applied before the automation runs and released afterwards.

Tested, by confirming that a record past its period is actually gone rather than merely hidden from a report.