The information your boss collects about you may reach Facebook and Russian companies
Researchers from four leading US universities tested nine employee monitoring programs and discovered that all of them shared identifying information with third parties. In some cases, browsing data and real-time location were also collected.

If your employer has installed software that tracks your working hours, location, or activity level, it is possible that they are not the only ones exposed to the information collected about you. An investigation by researchers from four academic institutions in the US tested nine common employee monitoring systems and discovered that all nine systems transferred identifying information about employees to external companies.
Among the companies that received information are Facebook, Google, Microsoft, and the advertising company AppLovin. Information about online activity was also sent to domains of Yandex, the Russian technology giant. The findings, published in a study in May, received renewed exposure in reports by the Associated Press and Fortune.
Researchers posed as employers and then as employees to check what happens behind the scenes. They registered on nine monitoring platforms — Apploye, Deputy, Desklog, Hubstaff, Monitask, Buddy Punch, Time Doctor 2, VeriClock, and When I Work — and tracked the information that applications and websites actually send to external services. The results were unequivocal: all nine platforms transferred identifying information, including first name, last name, email address, and the name of the employer.
In total, researchers documented 121 unique cases of sharing information with external companies. Additionally, information about online activity — such as IP addresses, device details, visited pages, and digital identifiers — was sent to 145 different external domains, including Google, LinkedIn, Bing, Stripe, and Yandex.
It is important to qualify: the mere fact of sending information to an external domain does not necessarily mean the company "sold" the information or used it for advertising. The study checked the flow of data, not what those parties did with it after receiving it.
Location tracking risks
The information collected does not end with names and email addresses. Researchers found that three of the nine systems tested include options that allow tracking an employee's exact location, even when the application is running in the background or when the employee is not connected to work. In three systems, it is also possible to require access to the phone's motion sensors, such as an accelerometer and gyroscope, to log into a shift.
The researchers argue that some of this data sharing is not clearly explained to employees and may contradict the platforms' own privacy policies. They call on regulators to limit the types of information allowed to be collected, the retention period, and the parties to whom it can be transferred.
The issue has become especially significant since the pandemic, when the use of "Bossware" systems—which track keystrokes, computer activity, screenshots, and location—skyrocketed. Today, with advanced AI and data analysis, this information can be used to rank employees and analyze their behavior patterns.
Privacy experts recommend that employees first find out what monitoring tools are active in their organization and separate personal life from workplace equipment as much as possible. Do not use the computer or phone provided by your employer for medical, family, or sensitive personal matters.





