\"SecureSafety PPE compliance monitoring — the system workers should understand before it goes live.\"
The manufacturing site had deployed safety AI monitoring on a Thursday. By the following Monday, the site's safety lead had noticed something in the detection data: event rates in the two camera zones covering the main assembly area were running at roughly 40% of the rates in the logistics area. The detection system was working. Workers in the assembly area were simply not walking where the cameras could see them.
A brief site-floor investigation revealed what no data dashboard could have shown. Workers in the assembly area had learned through informal channels that cameras were now monitoring their movements. They had not been told why, or by whom. A rumour had reached the shop floor — origin unknown — that footage was being reviewed by HR. Within a week of deployment, workers had quietly reorganised their movement routes to avoid the monitored zones, walking longer paths to the stores and taking breaks in the car park rather than the covered rest area.
The system was running. The safety it was designed to provide was not.
This is not an unusual outcome for safety AI deployments that skip worker consultation. It is the predictable outcome — and it is almost entirely avoidable.
What the ICO's monitoring guidance requires
In November 2023, the Information Commissioner's Office published updated guidance on monitoring workers (ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/). The guidance applies to any technology-assisted monitoring of workers, explicitly including CCTV-based AI monitoring, and it reflects the ICO's interpretation of how UK GDPR applies in an employment context.
The guidance does not prohibit monitoring. It sets out the conditions under which monitoring can be conducted lawfully. Three requirements are directly relevant to safety AI deployment.
Transparency. Workers must be informed that they are being monitored, what is being monitored, for what purpose, how the data is used, who can access it, and how long it is retained. This obligation arises before monitoring begins. UK GDPR Article 13 requires that individuals receive privacy information at the point their personal data is collected. Images of identifiable individuals captured by CCTV constitute personal data under UK GDPR — confirmed by the ICO and the courts since Durant v FSA [2003] and reinforced by the ICO's CCTV code. The Article 13 transparency obligation therefore applies from the moment AI-enhanced cameras are operational, not from the date the AI pilot report is reviewed.
Necessity and proportionality. The monitoring must be necessary for the stated purpose and proportionate to the risk being addressed. For workplace safety AI, this means being able to articulate specifically: which safety risks justify the monitoring; why less intrusive means are inadequate to manage those risks; and why the scope of monitoring — these cameras, these zones, these detection capabilities — is proportionate to those specific risks. A DPIA (Data Protection Impact Assessment) is required where processing is likely to result in high risk to individuals. The ICO's guidance explicitly indicates that AI-assisted monitoring of workers is likely to meet this threshold.
Lawful basis. UK GDPR Article 6 requires a lawful basis for processing personal data. For workplace safety monitoring, the most appropriate bases are typically legitimate interests (Article 6(1)(f)) — where the organisation's safety interest and legal duties under the Health and Safety at Work Act 1974 constitute the legitimate interest — or compliance with a legal obligation (Article 6(1)(c)), where specific health and safety regulations impose a positive monitoring duty. Consent is almost never the appropriate basis for employee monitoring, because the power imbalance inherent in an employment relationship means consent cannot be given freely, as required by UK GDPR Recital 43.
The ICO's guidance is explicit that covert monitoring — monitoring without workers' knowledge — is only permissible in tightly defined circumstances involving suspected serious criminal activity and requires documented senior sign-off. Deploying AI safety monitoring without informing workers is not, in the legal sense, covert monitoring if the cameras are already visible and their existence is known. But failing to inform workers of the new processing purpose — that AI is now analysing the footage for safety events — means the Article 13 obligation is not met.
Why workforce trust is the hidden success factor
Safety AI monitoring changes the safety environment of a site by providing detection coverage that makes unsafe behaviour more likely to be identified and corrected. The system's effectiveness depends on workers behaving normally within its coverage area. If workers modify their behaviour to avoid the cameras — as the assembly-area workers in the opening scenario did — the system catches easy edge cases and misses the real risk areas, inverting the detection quality map.
This is not irrational behaviour. Workers who do not understand why they are being monitored, or who believe the monitoring is connected to performance management, disciplinary action, or attendance tracking, will take rational steps to minimise their exposure to it. The monitoring then creates an incentive structure that drives exactly the behaviour it is designed to prevent: workers avoid monitored zones, which means higher-risk activities in those zones proceed without any detection coverage.
The trust dynamic runs in both directions. Sites that handle consultation well — explaining clearly that the system monitors hazardous conditions rather than evaluating individual workers, committing in writing that footage is not used for disciplinary purposes unless a serious safety incident requires investigation, and demonstrating transparency about what the system can and cannot see — consistently report better detection outcomes, higher voluntary near-miss reporting rates, and lower zone-avoidance behaviour.
One national oil major that deployed safety AI monitoring across a refinery operation committed to a structured consultation process that included a worker representative on the AI deployment steering group. The outcome was a workforce that actively participated in the system's improvement: identifying camera blind spots the deployment team had missed, flagging false positives that indicated calibration adjustments were needed, and, in one case, recommending a camera extension into a maintenance corridor that the original scope had not covered. Workers who understand the system become participants in it — and a system with engaged participants detects better than one operating in a climate of suspicion.
What good consultation looks like
Consultation is not a presentation delivered to a large gathering. It is a structured process that genuinely informs the deployment design and that continues through the deployment, not only at the point of launch.
Timing. Consultation should begin before the deployment design is finalised. If workers are briefed only after camera positions have been fixed and the system configured, the consultation is cosmetic. Genuine early-stage consultation — explaining the intention, showing the draft camera coverage map, inviting feedback on priorities and concerns — allows worker input to shape the actual deployment. Workers are frequently the best source of intelligence on which areas carry the highest practical risk and which camera angles create gaps.
Format. Department-level briefings in groups of ten to twenty people, conducted by the site EHS lead rather than by an external vendor representative, produce the most substantive engagement. Workers in a small group are more likely to raise genuine concerns than those in a site-wide all-hands session. Follow each session with written materials that workers can keep and review.
What to disclose. Be specific and complete: the detection capabilities being deployed (PPE, vehicle proximity, restricted zones — itemise them); the camera locations and coverage zones (a simple diagram works well); what data is captured and retained, and for how long; who can access footage and under what circumstances; how alerts are processed; the explicit statement that the system does not identify individual workers by name, does not store behavioural profiles of individuals, and does not feed into performance or disciplinary processes.
What not to say. Avoid vague future-scoping statements such as "we may add further capabilities later." If a future expansion is genuinely planned, it should be described specifically in the consultation materials, with a commitment to repeat the consultation process before that expansion occurs. "We might do more with this later" is worse than silence — it activates precisely the anxieties about performance monitoring that undermine trust.
Handling concerns. Record every concern raised in any consultation session, in writing, and provide a written response to each one with a named responsible person and a timeline. UK GDPR gives individuals the right to object to processing based on legitimate interests (Article 21); those objections must be considered in good faith and responded to substantively. A concern that "cameras will be used to check if I'm working hard enough" deserves a written response confirming exactly what the system does and does not do — not a verbal reassurance that evaporates after the meeting.
Safety monitoring versus performance monitoring: the critical distinction
The line between safety monitoring and performance monitoring is the most important conceptual boundary in any worker consultation for AI, and conflating them — even inadvertently — destroys trust in ways that take months or years to repair.
Safety monitoring identifies hazardous conditions: PPE non-compliance, proximity to a moving vehicle, entry into a restricted zone. The subject of the monitoring is the physical hazard, not the individual. The system fires when a person is in a dangerous situation, not when they are working slowly or taking a longer route. Detection outputs are used to intervene in real time and to improve site safety conditions in aggregate.
Performance monitoring evaluates how individual workers perform their jobs: items processed per hour, time at workstation, movement efficiency. This type of monitoring is regulated more strictly under UK GDPR, requires explicit transparency about its employment consequences, and carries significant legal exposure if used in disciplinary decisions without clear advance disclosure.
When workers conflate safety monitoring with performance monitoring — which they will, unless told clearly and repeatedly that these are different things with different purposes and different access controls — they respond to safety monitoring as if it were performance monitoring. The zone-avoidance in the opening scenario is performance-monitoring avoidance behaviour, triggered by a system that was doing safety monitoring.
The Management of Health and Safety at Work Regulations 1999 (Regulation 5) place a positive duty on employers to make and give effect to arrangements for the effective planning, organisation, control, monitoring, and review of preventive and protective measures. Safety AI monitoring is a legitimate mechanism for meeting this duty. The ICO's monitoring guidance confirms that health and safety constitutes a recognised legitimate interest capable of supporting lawful monitoring. The condition is that the system is deployed, configured, and communicated as a health and safety tool — and that this is not merely stated but evidenced in design choices (no individual behavioural profiling, footage access restricted to the safety and emergency response team, no integration with HR systems).
Trade union and works council engagement
Where a site recognises a trade union or operates a works council, those bodies hold specific consultation rights that apply to the introduction of monitoring technology. Under the Trade Union and Labour Relations (Consolidation) Act 1992, recognised trade unions have the right to be consulted on matters affecting their members' working conditions. The introduction of AI monitoring systems is consistently interpreted as such a matter; any EHS manager who proceeds to deployment without engaging the recognised union has created a grievance risk that may halt or unwind the deployment after significant investment.
Practical guidance for engaging trade unions on safety AI deployments:
Initiate contact before any public announcement. Union representatives should receive detailed briefings before wider workforce communication. This is not about giving the union a veto; it is about ensuring that representatives have accurate information before members bring them questions. A union representative who learns about a new monitoring deployment from their members, rather than from management, will approach every subsequent conversation with justified suspicion.
Share the DPIA in summary. Recognised trade unions have a legitimate interest in understanding how their members' personal data is being processed. Sharing a summary of the DPIA — including the necessity and proportionality assessment, the purpose limitation, and the access controls — demonstrates good faith and gives the union the technical basis to engage substantively rather than defensively.
Discuss the access governance framework. Who can pull footage, and under what documented circumstances? Can a union representative request footage on behalf of a member in a disciplinary context? What audit trail exists for footage access? Having clear, written answers to these questions before the union asks for them is considerably better than developing them under pressure after a grievance has been filed.
Agree joint communications where possible. Where the union is willing, a joint communication from site management and union representatives carries substantially more credibility with the workforce than management-only messaging. It signals that the union has engaged, is satisfied with the safeguards, and endorses the safety rationale — which directly addresses the "this is HR monitoring in disguise" concern.
The 7-step worker consultation checklist
- Step 1 — DPIA before design is finalised. Conduct the DPIA before committing to camera locations and detection configurations. Identify risks, document mitigations, and complete the necessity and proportionality assessment. The DPIA is not a post-hoc exercise.
- Step 2 — Prepare consultation materials. Draft materials covering: detection capabilities and what the system can and cannot do; camera locations with a coverage diagram; data retention periods; access controls and who can view footage; the explicit purpose (safety hazard detection only); and the fact that the system does not identify individual workers by name.
- Step 3 — Notify and engage trade union or works council first. Before any wider workforce communication, brief union representatives or works council members with the full technical detail. Provide the DPIA summary. Allow time for questions before the wider announcement.
- Step 4 — Hold department-level briefing sessions. Conduct sessions in groups of ten to twenty people, led by the EHS lead. Use the consultation materials prepared in Step 2. Record all questions and concerns.
- Step 5 — Distribute the UK GDPR Article 13 privacy notice. Issue the formal privacy notice to all workers in scope before cameras go live. The notice must cover processing purpose, lawful basis, data retention period, data subject rights, and contact details for the DPO or responsible person. This is a legal obligation, not an optional courtesy.
- Step 6 — Record concerns and respond in writing. For every concern raised in any consultation session, produce a written response with a named responsible person and a timeline. Do not proceed to deployment until all substantive concerns have received a substantive written response.
- Step 7 — Update induction materials. Add AI monitoring to new worker and contractor induction processes. The Article 13 transparency obligation arises at the point personal data collection begins — it applies to every new worker from their first day on a monitored site, not only to those employed at the time of deployment.
The offshore environments where SecureSafety first deployed safety AI operated under collective agreements with offshore workers' unions and within a regulatory framework — including the Offshore Installations (Prevention of Fire and Explosion, and Emergency Response) Regulations 1995 — that made worker consultation a formal operational requirement rather than a cultural preference. Every deployment was preceded by a structured briefing with the relevant workforce representatives, a written statement of purpose distributed to the crew, and a formal process for questions and concerns before cameras went live. That baseline is now the standard applied to every SecureSafety deployment, onshore and offshore alike: consultation is not the step before deployment — it is part of the deployment. Book a demo to discuss how a deployment at your site would be structured, from the DPIA through to the day-one crew briefing.

