Bossware Shared Worker Data 121 Times—Check What Leaves the App

Employee-monitoring software may collect identifiers, device and network details, visited pages, screenshots and location. The privacy question is not only what a manager can see: workers and employers need to map what the installed system collects, when its permissions remain active, who receives the data and when it is deleted.
A report on nine monitoring platforms found that all nine shared identifying worker data and online-activity information with third parties, while three had precise-location features. A Vanderbilt summary of the investigation documents 121 unique sharing instances and transmissions of online-activity information to 145 third-party domains, including Facebook-, Google-, Microsoft- and Yandex-related destinations.
What the 121 instances actually establish
The headline count does not mean every monitored employee had data transmitted exactly 121 times. Researchers registered as employers, configured the services, logged in as workers and captured data sent from the tested websites and mobile apps to third parties. The number represents distinct sharing instances observed in that test setup, not a rate applicable to every worker or product deployment.
That distinction shapes the audit. A privacy policy may name broad recipient categories, while a website or app contacts analytics, advertising, authentication, payment or infrastructure providers through embedded components. A network connection also does not establish how the recipient later used the data, so an audit should record the data element, destination and trigger without inventing an unverified purpose.
A worker audit starts with permissions and boundaries

Inventory the monitoring app, browser extension, device-management profile and companion services required for work. Record whether each component is installed on an employer-owned or personal device, because that is where workplace collection may overlap with private use.
- List enabled access. Check location, camera, microphone, photos, motion sensors, accessibility controls, screen recording, browser access and background operation. Note whether location is approximate or precise and whether access is limited to active use.
- Test the time boundary. Record what happens after clock-out, sign-out and app closure. Use operating-system permission records, battery activity or an authorized test agreed with IT; do not bypass security controls.
- Compare notice with configuration. Read the employee notice and vendor disclosure, then flag any enabled category, recipient or off-hours behavior that is absent or ambiguous.
- Ask about the lifecycle. Request the retention period, deletion procedure, access roles and consequences of withdrawing an optional permission.
These boundaries matter beyond the nine-product study. An FTC discussion of workplace surveillance says collection can occur on personal devices and away from the workplace, while workers may not know what is retained, how it is used or whether it is sold to third parties and data brokers.
The employer audit must follow data past the vendor

An employer needs a data-flow worksheet, not merely a feature list. Create one row for every enabled feature and complete these fields before deployment:
- the data element collected, such as an email address, URL, screenshot or coordinates;
- the collection trigger and whether it operates in the background or outside scheduled hours;
- the documented business purpose and any employment decision the data may influence;
- every recipient, including the employer, vendor, subprocessors and embedded analytics services;
- storage location, access roles, retention period and deletion event;
- employee notice, available controls and relevant jurisdictions.
Support each row with configuration exports, subprocessor lists, data-processing terms, retention schedules and deletion commitments. Where the risk justifies it, conduct an authorized network assessment in a test environment. A blank recipient or trigger is a finding, not an invitation to assume that the vendor’s general privacy language covers it.
Questions IT, HR and procurement should answer
IT should identify the permissions actually deployed, domains contacted, administrative roles, security controls and behavior after sign-out. HR should define why each measurement is necessary, who may use it in an employment decision, how a worker can challenge an inaccurate record and whether less intrusive data would serve the same purpose.
Procurement should ask whether worker data supports advertising, product analytics or model development; which software development kits receive identifiers; how subprocessor changes are communicated; and whether contract termination deletes backups as well as active records. It should also determine whether location can be restricted technically to clocked hours and whether unnecessary telemetry can be disabled rather than merely hidden from managers.
“Industry-standard analytics” is not enough to complete the worksheet. Contracts should identify recipient categories, permitted purposes, retention limits, deletion duties and audit evidence. If essential service delivery cannot be separated from optional analytics, that limitation belongs in both the purchasing decision and the employee notice.
Notice and privacy rights depend on jurisdiction

There is no single rule for every US workplace. The employer’s and worker’s locations, public- or private-sector status, device ownership, data category and monitoring method can change the analysis. The California Privacy Protection Agency’s FAQ says California residents covered as consumers include employees and job applicants, and it classifies precise geolocation as sensitive personal information; the law applies only to covered businesses and includes exceptions and defined limits.
Some states also impose monitoring-specific notice requirements with their own scope. Connecticut’s electronic-monitoring statute generally requires prior written notice describing the types of monitoring, but its definition concerns collection on an employer’s premises and it provides exceptions for specified misconduct and criminal investigations.
Workers can take their inventory, permission records and unresolved questions to HR, IT, a union representative or a qualified adviser in the relevant jurisdiction. Employers should pause a feature when its purpose, recipient, off-hours boundary or deletion rule remains unknown: a generic notice cannot make an unmapped data path accountable.
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.