PRIVACY BY GOVERNANCE

GDPR Compliance

Support Accountable Employee Monitoring Under GDPR

DeskGate provides self-hosted technical capabilities that can support privacy-conscious deployment. Each customer remains responsible for determining its lawful basis, purpose, notices, proportionality, retention, and data-subject procedures.

DeskGateSelf-Hosted ControlClear scope · accountable access · documented review
Compliance overview · Last updated August 18, 2026Questions? Contact DeskGate

Roles and Responsibilities

GDPR compliance is an organizational program, not a software setting.

The customer normally determines why and how employee or endpoint information is processed in its DeskGate environment and therefore acts as controller. DeskGate may act as processor when providing contracted support that involves customer data. For website inquiries, account administration, commercial communications, and our own business records, DeskGate may act as an independent controller.

Customers must identify an appropriate lawful basis before monitoring begins. Employee consent may not be freely given because of the imbalance in an employment relationship; it should not be treated as the automatic or only legal basis. Organizations should obtain advice appropriate to their jurisdiction, workforce, collective arrangements, and intended processing.

A Practical GDPR Deployment Framework

01

Define purpose

Document the specific business need and reject collection that does not contribute to it.

02

Assess necessity

Compare less intrusive alternatives and complete a DPIA where high risk is likely.

03

Inform people

Provide clear notices covering categories, purposes, basis, access, retention, and rights.

04

Limit access

Assign roles by responsibility and review administrator privileges and activity regularly.

05

Review results

Use human context, investigate inaccuracies, and avoid solely automated employment decisions.

Data minimization and retention

Configure only the modules and evidence required for the documented purpose. Apply narrower scope, schedules, groups, classifications, or policies where possible. Set defined retention periods for database records, screenshots, exports, backups, USB events, support logs, and other evidence. Delete or anonymize information when the approved purpose expires, subject to legal preservation requirements.

Security and self-hosting

Customers control deployment infrastructure, database access, network boundaries, backups, recovery, administrator accounts, and physical security. Use strong authentication, least privilege, supported encryption, secure configuration, patching, logging, incident response, and periodic access review. Self-hosting provides control but does not remove the customer’s security obligations.

Data-subject rights

Controllers need procedures for access, correction, deletion, restriction, objection, portability where applicable, and complaints. DeskGate capabilities and database administration may assist retrieval, but the controller evaluates identity, scope, exemptions, third-party rights, legal holds, and response deadlines. Requests should be documented from receipt through completion.

Transfers, vendors, and incidents

Review every vendor or support arrangement that may involve personal data. Use contracts and transfer safeguards where required. Maintain an incident process covering containment, evidence, risk assessment, processor-to-controller notification, authority or individual notification where applicable, corrective action, and lessons learned.

Configure DeskGate Around Your Compliance Program

Customers should consult qualified privacy and employment-law advisers. Product information does not constitute legal advice.

Request a Demo

Operational Checklist for Controllers

Maintain a living record of processing that identifies DeskGate modules, affected locations and teams, personal-data categories, recipients, retention, security measures, and international transfers. Revisit this record after organizational changes, product updates, new reports, or expanded endpoint coverage. Involve the data protection officer, employee representatives, human resources, information security, and legal advisers where their participation is required or useful.

Train managers not to interpret productivity labels as objective measures of performance. Application and website categories can be incomplete, time records can reflect technical or operational conditions, and a device user may not be the person assumed. Establish a documented path from a report or alert to verification, contextual review, an opportunity to respond, and a proportionate outcome. Avoid special-category data and private communications unless a narrowly defined legal need has been reviewed.

When a customer asks DeskGate for support, provide the minimum diagnostic information necessary, remove credentials and unrelated personal data, use approved secure channels, and authorize access for a limited period. Record who requested the assistance and close access after resolution. Periodically test restoration, deletion, account revocation, incident escalation, and data-subject request searches so written procedures work under real deadlines.

Compliance also requires evidence. Keep approvals, notices, training, access reviews, configuration decisions, deletion records, incidents, requests, and corrective actions in a form that can be explained to leadership, auditors, supervisory authorities, and affected people. Assign review dates and owners so documentation reflects actual operation rather than an outdated launch plan.