Where the Rules Come From
Data protection, employment law and sector rules all apply, and task mining engages all three. A general orientation.
Reference
Process mining reads records that already exist. Task mining creates new records about people. The regulatory position differs accordingly.
General orientation. Requirements differ substantially by jurisdiction and change; take advice for yours.
Process mining
Frequently low exposure, because the events are business records and the analysis can be aggregated.
The resource field is the exception. Once who performed an activity is included, the analysis processes personal data about identified employees.
Which engages lawful basis, notice, purpose limitation, retention and access rights.
Aggregating to role or team removes most of it, and it is the reason to do so by default rather than as a concession.
Customer data in case attributes carries its own obligations, particularly where special categories are involved.
Task mining
Systematic monitoring of identified individuals, which is the highest-exposure activity in this field.
Notice, before deployment, specific rather than general.
Proportionality, with less intrusive alternatives considered and the consideration recorded.
Impact assessment, required in several jurisdictions.
Consultation with employees or representatives, a legal requirement in a number of places.
Retention limits, where excess retention is itself a failure.
Access rights, so the person can see what was captured.
Employment and collective rules
Works councils and similar bodies have codetermination or consultation rights over monitoring in several jurisdictions, and deployment without their agreement can be unlawful regardless of data protection compliance.
Collective agreements may restrict monitoring independently of statute.
Consultation on changes to working conditions, which desktop capture is.
Automated decisions
Where a prediction or a conformance flag triggers a consequence for a person, restrictions commonly apply.
Human involvement and a route to contest are frequently required.
Which is an argument for using outputs to prioritise work rather than to judge people, and that is also where they are most useful.
Sector rules
Financial services, healthcare and public administration frequently have specific requirements on access to transaction data and on audit evidence.
Some of these support the programme: conformance checking produces exactly the evidence they ask for.
Check what applies rather than adopting a general framework and assuming coverage.
The practical position
Include the resource field only when needed, and aggregate it by default.
Treat task mining as a separate decision with its own assessment, consultation and end date.
Document the proportionality reasoning at the time, because it cannot be reconstructed credibly two years later.
Map the applicable rules once and identify where one control satisfies several requirements, which most do.
The proportionality record
What a regulator asks for and what cannot be reconstructed credibly later.
The question the monitoring answers.
Why the event log could not answer it.
Which less intrusive alternatives were considered, named individually.
Why each was insufficient, specifically.
What safeguards were added: allow lists, exclusions, retention, deletion dates, access control.
Who decided and when.
Written at the time. A justification assembled two years into a dispute persuades nobody, including the person who wrote it.
Mapping the regimes once
Three bodies of rules overlap, and mapping them individually wastes years.
List what applies: data protection, employment and collective rules, sector requirements.
Extract the provisions touching monitoring, access to transaction data, and automated decisions.
Map each to a control you operate, noting the evidence it produces.
Identify the controls satisfying several provisions, which most do.
Note where conformance checking already produces the audit evidence a sector rule requires, which is frequently the strongest argument for funding continuous operation.
The two directions of pressure
Compliance requirements and data protection requirements pull opposite ways, and both apply.
Audit and control frameworks push toward more evidence: who did what, when, in what order.
Data protection pushes toward less: minimise, aggregate, limit purpose, limit retention.
Excess retention of monitoring data is itself a failure in several jurisdictions, not a safe default.
The reconciliation is usually aggregation: almost every process question is answerable at role level, and almost every data protection concern falls away once individual attribution is removed.
Document the reasoning at the time, because it cannot be reconstructed during a dispute.
Also in this section