Invest1 distinct publisher3 min readUpdated
A test of nine widely used employee monitoring platforms found all of them exporting identifying worker data. The buyer signed the licence and never saw the recipient list.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The diligence question at purchase was whether the tool measured what the vendor said it measured. On the evidence of the Vanderbilt, Northeastern and Berkeley test, it does, and it also does something nobody scoped: across nine platforms the researchers logged 121 separate instances of identifying worker data going to outside firms, an average of about 13 per platform, plus 145 third-party domains receiving activity data, roughly 16 per app [1][3][4][14][15].
Worker data behaves differently from consumer data once it leaves the building. A consumer ad profile is one person of unremarkable provenance. A monitoring platform's user base is one employer's staffing roster, so a name and a work email travelling together carry the employment relationship with them, alongside whatever the same app reported about IP address, device and browsing [3][4]. The investigation's broader finding is that the most common of these programs sent names, emails and other personal worker data to hundreds of data brokers and technology companies without clearly disclosing that they were doing it [7]. The employer signed for that. The worker did not, and had no basis on which to ask.
Two of the permission findings deserve separating from the export numbers. A third of the platforms could fix a worker's precise location with the app running in the background or the worker off the clock [5]. Three of the nine demanded access to a phone's motion sensors before they would register a shift start [6], the same one-in-three proportion [17]. Clocking in is a timestamp. Motion sensor access is a description of how a body moves, and whatever the intended use, the collection outlives the shift it was justified by.
The productivity case for the stack was never audited as hard as the workers were. Lannie Duong, a pharmacist at a medical clinic, told the Associated Press her employer timed her phone calls and appointments and queried the length of them in performance reviews; she says she was terminated after taking medical leave [12]. Wilneida Negron of Coworker argues that advances in AI and data science let employers assemble dossiers used to punish workers or predict their behaviour [9], and that the workers with the least labour market power are where the more intrusive collection gets tested first [10]. The reported examples run that way: administrators reading an adjunct professor's written comments to students [13], conveyor belt scanners holding warehouse staff to an inspection rate of hundreds of items an hour [18].
What a buyer would need to answer a worker's question here is a current data flow list from the vendor, naming recipients. That is a different artefact from a security questionnaire, and on this evidence it is not what anyone received. The per-seat licence was the visible cost. The rest of it sits in the same line item, unpriced, and it was found by academics posing as a customer rather than by any of the customers [1].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Some of the most common workplace monitoring programs have shared names, email addresses and other personal worker data with hundreds of outside data brokers and technology companies without clearly disclosing the practice.
Pharmacist Lannie Duong, who met with patients with chronic conditions at a medical clinic, said her employer tracked the length of her phone calls and appointments and questioned in performance evaluations why she took so long with each patient; she went on medical leave, began organising a union, and says her employment was terminated after the medical leave.
An investigation by Vanderbilt University, Northeastern University and the University of California at Berkeley tested monitoring software by signing up as an employer, deploying nine widely used monitoring platforms, then logging in as a worker to capture what the apps actually sent out.
The nine platforms tested included Hubstaff, Deputy and Time Doctor 2.
Every one of the nine platforms shared identifying worker data, including names and emails, with outside companies, producing 121 documented instances involving Facebook, Google, Microsoft and the ad-tech firm AppLovin.
Separately, the nine apps sent workers' online activity, including IP addresses, device information and browsing data, to 145 third-party domains, among them Yandex, the Russian search company.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One wire report on a named but uncited academic test
The central findings come from a described, plausibly rigorous methodology — sign up as employer, deploy nine apps, log in as worker, capture outbound traffic — attributed to three named universities, and the numbers are specific and internally consistent. But the cluster holds a single publisher carrying wire copy, with no link to or venue for the study, no per-platform breakdown, and no response from the named vendors or data recipients, so the counts cannot be independently checked here.
Broadly deployed category, coarsely quantified
Adoption of the underlying practice is real and named: nine widely used platforms were obtainable and deployable by a self-service employer signup, and reporting places thousands of employers on pandemic-era monitoring tooling across location, task-rate and camera capture. The quantification stops there — no installed base, seat counts, revenue or market-share figures appear — so the level is credible but imprecise.
Headline framing outruns the itemized findings
The measured findings are concrete and the article's body stays close to them. Mild overstatement comes from packaging: the headline collapses two separate result sets — identity data to advertising and platform firms, and activity telemetry to 145 domains including Yandex — into a single implication about one boss's app, and 'hundreds of outside data brokers' sits above the itemized 121 instances and 145 domains without a broker-by-broker accounting. Absent vendor rebuttal or the primary study, the framing is somewhat stronger than what the cluster can verify.
Advocacy and worker sourcing, vendors silent
Interpretation is supplied by parties with stated missions in this fight — Coworker, which helps workers organize, and the Electronic Frontier Foundation — alongside two workers describing adverse employment outcomes they attribute to monitoring. Academic researchers testing surveillance tools also have publication incentives. None of this makes the findings wrong, but the tested vendors and the named recipient companies have no voice in the cluster, so the incentive mix is one-directional.
Moderate: strong findings, thin corroboration
Confidence is limited by single-publisher coverage of an uncited study with no vendor reply, and lifted by the specificity and internal consistency of the reported measurements, the named institutions behind them, and the fact that the tested platforms are commercially available and identifiable. Corroboration from the primary study or a second outlet would move this substantially.
product
The productivity dashboard is now a dossier, and whoever bought it owns the file1 distinct publisher
invest
Nvidia stops eating memory costs: AI server prices up more than 15% on early-2027 shipments1 distinct publisher
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.