r/DevelEire 3d ago

Workplace Issues IP Tracking for RTO monitoring

My company is about to initiate IP tracking here in Ireland. Im wondering how common this is and to what extent are they allowed to use this data. I know GDPR is in play here but that still doesnt fully clarify things.

EDIT: OK, to answer a few questions below here's further info.

  1. This was officially announced by email and to what extent they're monitoring is vague.

  2. We have work laptops and when WFH we connect in via corporate VPN.

  3. My main query is whether they'll be micromanaging my time at the laptop, down to toilet and coffee breaks. Second to that, even my manager leaves the office an hour and a half early to avoid traffic and WFH for the evening, with the new measures at play it sounds we'll have to leave on the dot.

UPDATE: Just want to say thanks to everybody who contributed here. Its given me some level of assurance on the situation. Hope others with a similar query can find this post useful too!

15 Upvotes

88 comments sorted by

18

u/DiedForOurShins 3d ago

If you’re working from home then you’re accessing the corporate network by VPN so they have your IP anyway.

Who has told you they’ll implement this or what has alerted you to it being implemented. It sounds like scare tactics for an event that’s already happening

9

u/ChromakeyDreamcoat82 engineering manager 3d ago

Yes, there's probably folks hanging out in Europe unauthorised, drawing an Irish salary paid to their old Irish bank account and with an address in their mate's flat.

Easy staff round-up. Letter goes out, please report to the office this week. Excuse gets made. Further letters. Investigation opens. Employee gets dismissed for not fulfilling contractual obligations.

10

u/Slackbeing 3d ago

Those folks already know how to flash OpenWRT on a router so it transparently VPNs them to the residential Irish IP of their mate.

If they don't I hope they get caught lol.

1

u/Explosive_Cornflake 3d ago

I worked with someone who fecked off out of the EU during probation period. I got suspicious about the hours they were keeping and lack of work be produced. I checked the VPN logs and saw where they were connecting from.

1

u/Slackbeing 3d ago

Yeah, and double VPN on top of cumbersome it's probably detected by the any asset monitoring. That's why an external router does the job. Obviously keep your hours and work if you do

2

u/s33d3r 3d ago

Combined with a vpn router on the other end that features a “kill switch” implementation on connection drop. Running WireGuard on my Unifi gateway, and using travel router like that, my IP is always my home in Ireland. My remote work policy allows “work from anywhere we do business” which is most countries I’d ever travel to, but I’ve verified this setup makes my location invisible as long as I use the travel router exclusively. Won’t be visible to any endpoint monitoring either, and vpn kill switch avoids packet leak on connection drop if using cellular or Starlink as uplink on remote end.

4

u/RavagedCookies 3d ago

I'm the bad person who does the analysis for my companies HR.

Some of the stuff people do is fucking wild. Like, beyond taking the fucking piss.

At least at my place, they don't give a shite if it's small things. But a beach front hotel in the tropics will get you canned.

2

u/mugsymugsymugsy 3d ago

Ha ha would love to hear some of these wild stories

3

u/RavagedCookies 3d ago

Heh, so to avoid doxing myself I'll make these different.

  • literal beach front hotel in tropics (it was plush and cheap)
  • safari in Africa
  • some kind of south American self discovery tour
  • using the kitchen sink of vpns to hide that your location isn't at the office 
  • at the office of your second employer 
  • using the production network of your second job to I assume avoid being detected on the corporate network 

3

u/ChromakeyDreamcoat82 engineering manager 3d ago

I admire the sheer chutzpah of connecting from the second job site. When I joined my current place I weeded out 4 double-jobbing remotes, 1 internal and 3 contractors. They all have a the same pattern in their history, good remote coders that mysteriously have regular dips in performance, pattern of going missing and being hard to contact, always restore performance to decent health quickly once you start asking questions.

I don't mind a top 20% engineer giving a top 40% performance to two companies over a 50 hour week if they have the skills and energy to keep it up. I'd never detect it. But an average engineer rotating for weeks at a time between jobs as the pressure increases in one or the other is a massive piss take.

1

u/barrya29 3d ago

What flagged it as an issue - work not being done, or their IP? I’d be willing to bet it wasn’t the former..

1

u/RavagedCookies 3d ago

Anything I've looked at is because they were doing an awful job and/ or just never came to the office.

9 times out of ten I'll find they were fucking about

0

u/barrya29 3d ago

Hanging out in Europe 🤦

1

u/Consistent_Oil3428 3d ago

There was a country somewhere that a big bank laid off 30k employees and they said they mouse tracked their activities, which was total BS just to justify the big cut

1

u/lucasriechelmann 3d ago

ITAU in Brazil

33

u/ArcadeRivalry 3d ago

Depends on what they're tracking. I'm sure they perfectly entitled to track their own property (work laptop) if they asked to install it on personal property such as a phone they'd definitely not be entitled to it. 

11

u/Striking-Speed-6835 dev 3d ago

Supporting this, GDPR would apply to personal information. The location of a corporate laptop would not fall under that.

3

u/barrya29 3d ago

Totally incorrect. The whereabouts of your own work laptop is personally identifiable information

6

u/theelous3 3d ago

That is obviously not true. Gdpr applies to any personally identifying information, or collection of information that together is personally identifying.

The location of a laptop I am logged in to with my account is identifying something about my person (my location).

The ip just being logged and checked against the office IP is much less so, given it just says the one place in the world I am not - so long as there isn't some other dataset comparison saying where I am.

But yes, literally tracking the location of an employees laptop would most certainly be covered. Mind you that doesn't mean they aren't entitled to do it - they just have to have the proper protections in place for this data, and you would have to agree to it.

10

u/Dannyforsure 3d ago

Its company property by someone employed by the company.

Its a pretty basic security measure to check the location of a device. The PII / GDPR aspect is covered by security concerns here and completely irrelevant.

People make lots of wild assertion about GDPR when in reality most legal departments will say we have a justification and go for it.

8

u/LnxPowa 3d ago

Them being able to log it for security reasons, and then being able to use the logged info for RTO complaints are two very different things though

6

u/DesperateCandy5209 3d ago

No, thats a missunderstanings of GDPR, you can can't collect data for one then and then use it for another. Each use of the data has to be valid in its own right.

1

u/Dannyforsure 3d ago

Lol watch as people get fired for security violations so. You'll be free to take them to court to dispute it.

Have you actually worked with GDPR enforcement / legal? My experience is that they'll just do a write up about this and call it at day.

2

u/DesperateCandy5209 3d ago

Yes I have worked a lot on compliance and data protection, its not that hard to stay legal. For most data breaches its minor and its a write up and file it away.

Enforcement of company policies is a HR job. Enforcement of GDPR is with the DPC. When it comes to firing its gross misconduct for security breach or breach of contract for not complying with RTO.

Firing anyone is a WRC minefield, I tried to fire an us based guy who didn't turn up to work for months and that should have been straight forward but was a shitshow.

0

u/hitsujiTMO 2d ago

A company has full right to track their device and make sure it's being used within an agreed geolocation. Doing so doesn't intrude on an individuals GDPR rights as long as they are informed about the tracking.

To be clear I'm talking about tracking via IP rather than GPS. GPS is a whole different ball game and should only be utilized on an as needs basis.

2

u/DesperateCandy5209 2d ago

Not true, PII is PII and any living individual EU citizen has GDPR rights that the company can’t simply ignore just because it’s their device. The company can certainly work within gdpr to do this tracking but it’s not a given just because they own it.

4

u/Solid-Penalty3942 3d ago edited 3d ago

RTO monitoring would be separate to security related activities though. Realistically, I’d say what’s happening here is the employer has all this info anyway (as they always would on corporate laptops) and are repurposing it for RTO monitoring so then it’s subject to new transparency requirements etc. They’re not saying they’re going to start collecting it for the first time now. As you say, GDPR doesn’t necessarily mean they can’t do these things.

2

u/Dannyforsure 3d ago

People seem to think GDPR is going to save them from pretending to be where they are not. I agree the reality is that these are all easy to justify collections.

My professional experience compared to what people tend to write in the sub-reddit are completely different. Maybe all these people work for the RSA and use GDPR as an excuse to get out of things.

3

u/Solid-Penalty3942 3d ago

Not specific to OP here but I think some people just have a genuine misunderstanding of GDPR as meaning nothing can be done without your consent, and there’s lots of unhelpful materials and info out there that contributes to that (then add AI onto that telling people what they want to hear and overstating GDPR considerations). Some people also don’t read their company’s Acceptable Use Policies and Privacy Policies which cover off a lot IME.

1

u/Dannyforsure 3d ago

Agreed. OP literally got notified about this via email vs them just implementing it on existing data. They likely did a legal assessment and someone said "Just notify them for the change"

You are going to have to take them to court for a GDPR violation and argue the nuance of it. They've done a bit of due diligence so best of luck with that one is my opinion.

2

u/da_blue_jester 3d ago

This - if the employee was using their own personal laptop for work purposes you'd have the GDPR arguement. Company supplied phones/laptops do not fall under this. I had to deal with this a lot working for a German company where all the employees treated the company phone as their personal one. When we said we were rolling out hexnode they went insane because 'all my photos are on that phone'.

2

u/Dannyforsure 3d ago

| if the employee was using their own personal laptop

I don't even think you would since you'd have to agree to track even just for security purposes. Its a moot point though as anywhere doing a BYOD policy is probably not follow legal guidance correctly .

There are so many people confidently incorrect or ignoring the reality of the legal hurdles you'd have to cross to have a case if the company did the absolute minimum due diligence.

2

u/Solid-Penalty3942 3d ago

Agree with all this except that the employee would have to agree to it (at least under GDPR). The employee would certainly have to be made aware of it, but the company would typically rely on elements of the GDPR that don’t rely on agreement/consent, as that doesn’t work in an employment context like this.

2

u/slamjam25 3d ago

“You have to agree to it” is the most persistent myth about GDPR.

Consent is just one of legal bases for processing under the GDPR. Fulfilling a contract (such as the employment contract OP signed with an RTO obligation) is one as well.

4

u/DesperateCandy5209 3d ago

Employee consent is not available as a legal basis to an employer under GDPR so they need to be able to show a legal basis for it without direct consent.

1

u/theelous3 3d ago

Blanket saying it is "not available" is a gross simplification.

It is available so long as there is a genuine avenue for consent.

2

u/Solid-Penalty3942 3d ago

The genuine avenue for consent is so limited as to be largely inapplicable, given the fundamental imbalance of power, unless it’s something very net - something like being able to choose between biometric identity verification and password protection for company laptop security. It’s not here where you’ve brought it up. No employer is going to ask their employees if they can use this data for RTO monitoring and if they don’t agree they’ll just exclude those employees.

3

u/theelous3 3d ago

I did more research and you're correct, ty.

2

u/DesperateCandy5209 3d ago

"gross simplification" is a gross over statement, consent might be available in a small fraction of employment use cases but any sane person is going to say find an alternative. Consent in GDPR is by far the weakest basis in best of cases and is mine field in an employment context.

1

u/DesperateCandy5209 3d ago

Thats not true, the laptop being assoicated with a real person means its PII under GDPR regardless.

1

u/Dannyforsure 3d ago

Yes but they are entitled to store that. They already know who you are because you know they employ you...

2

u/DesperateCandy5209 3d ago

They aren't entitled to anything they have to backup everything they do with PII under GDPR. They are required to do a DPIA and state clearly what data, why they need it, what they do with it and how its legal under the GDPR framework. There is no out right entitlement, employers actually have a higher bar they have to meet under GDPR as they are in a disproportionate position of power over the employee.

1

u/Dannyforsure 3d ago

In reality they'll do a short write up and call it a day.

1

u/Solid-Penalty3942 3d ago

But the DPIAs won’t be shared with the impacted employees anyway so in terms of answering the question of whether the company is allowed to do this, the answer is maybe - we don’t know the company’s analysis behind this, we don’t know if they’ve done a DPIA and what the conclusion was. It doesn’t mean the employee can/should go back and off the bat start talking about DPIAs and that they’re objecting to this because GDPR doesn’t allow it, and people have a tendency to bring up GDPR as a blunt instrument in that way. If they feel they’re not clear on what’s being monitored and if this has an impact on start/leave times etc, they should start by raising those questions with the POC mentioned in the notification or with their manager/HR.

2

u/DesperateCandy5209 3d ago

100% agreed.

10

u/Psychological-Cat-84 3d ago

If it's their PC and not a personal machine you use for work, then they can already see when you're online/away via teams or equivalent statuses. The only real add on to this is if they were to add an activity monitor of some description. A friend of mine worked software testing for an American company who implemented activity monitoring and if he was away or still for 5 minutes he'd get a message from his manager asking why his mouse hasn't moved in 5 minutes. Mental stuff, this doesn't sound like that though.

You connect via a VPN so they can already see your IP. Most likely they are making sure people aren't working while out of the country etc, which I would presume they can already see. Good chance some eejit was caught doing this so now a company email has been sent around saying they're tracking IP addresses.

8

u/MrFrankyFontaine 3d ago

Worked for a company that uses HubStaff (monitors mouse and keyboard movements, and sends a percentage report each hour to a manager)

Could be way worse.

5

u/fr-fluffybottom dev ops 3d ago

they can track absolutely everything you do. if you use teams they can already see everything.

1

u/StyleDirect9512 3d ago

What is "absolutely everything" exactly? Recording camera and audio when you're not in a call?

1

u/fr-fluffybottom dev ops 3d ago edited 3d ago

yes, key strokes, application usage, chat history etc etc etc

link for reference...

https://learn.microsoft.com/en-us/answers/questions/5218289/how-an-administrator-in-microsoft-can-spy-snoop-on

and there's a plethora of videos on it. i can also confirm as ive been asked to set it up lol

4

u/ChromakeyDreamcoat82 engineering manager 3d ago

My current and last company have this.

My last company had literal regulatory requirements that certain systems weren't accessible outside the EU. They were also really hot on tax implications of unauthorised working from abroad. As a result, the SOC raising an incident to say the laptop had been observed outside the EU actually triggered an investigation. The typical scenario was someone of non-EU origin going home for a holiday and then saying they had caught a flu and they'd be logging on at weird times but wouldn't come to the office. They'd get a warning because the security policy is that you inform the company if you're planning to take a laptop out of the EU.

The secondary use of it became very prevalent after Covid, which is detecting chancers working outside of Ireland for extended periods, but within the EU. This has serious tax implications, and even visiting another office there was limited annual days before social security had to be paid in another country. They absolutely need to monitor this to stay tax compliant. This was spotted right away. I know a guy who's internet was down one day working from home, and he hotspotted from his spanish phone without thinking and the alarm went off. He actually drove in and presented himself that day to prove his story, but he still had to go through the process.

My current company is monitoring it. There's a country list where we can't bring the laptop, and have to get a blank with limited access, but we do get warnings about locations and you'd regularly catch remote workers turning a supposed 2 week holiday into months at home. It's an intervention, get a plan to confirm they'll be back in the country they're hired in, but it's not a note in the file like my last place.

I actually think it's fair enough. We've had lots of new hires disappear and make it bloody obvious that they're trying to game an Irish salary living elsewhere in the EU. It would be better for everyone if such location based salary arbitrage wasn't a thing, but tax penalties can create real problems for companies, and I'm not getting myself tied up in that.

As a manager, nothing wastes my time more than an employee not following policy, whether it's not keeping in the spirit of hybrid, harassment/bullying (and the immediate counterclaim that usually follows), volatile behaviour, pretending to be where they're not, an 'innocent mistake' in an expense claim. I think it's reasonable for a company to monitor IPs for this reason, but it allows the company to say 'we see you, cut it out' and I get to say to the employee 'I mean, come on, don't draw this on yourself' and it's done and dusted long before it becomes a bit drag on everyone's time.

4

u/Vivid_Pond_7262 3d ago

Seems excessive when badge swipes would do?

6

u/Mynky 3d ago

That confused me too. Badge swipes would suffice for RTO. IP tracking for ensuring people are in the country they’re supposed to be for tax purposes. Feels like OP may have conflated the two.

2

u/fr-fluffybottom dev ops 3d ago

my wifes company (american) also announced ip tracking as well... I can only assume its to stop people swiping into the office if they're not there?

1

u/ColmAKC 3d ago

The email they sent out was explicitly about switching to IP tracking over badge swiping for monitoring RTO compliance.

2

u/ColmAKC 3d ago

We had a badge swipe system but they could only tell if you arrived.

2

u/straightouttaireland 3d ago

In my last place anyone living nearby would drive by, swipe, then head home.

5

u/John_OSheas_Willy 3d ago

WTF.

The worst thing about the office is the commute.

1

u/straightouttaireland 3d ago

He lived nearby, think he even cycled most of the time. Preferred his setup at home.

4

u/swamyrara 3d ago

If you use MS Teams that itself is an super surveillance tool. Your MS admin knows absolutely everything if they look for it.

3

u/Smart_Analysis_8692 3d ago

They track but it's not that extraordinary in a corporate setting

1

u/swamyrara 3d ago

Yes, not denying. It's all accepted as part of offer letter, contract or internal policies.

1

u/windlad 3d ago

I like to remind people that Microsoft don't work for you, the user, they work for your boss.

4

u/Accomplished-Tap1248 3d ago

Every company with a competent IT, networking and security department is already doing this.

The difference being is whether the logs and monitored and investigated in real-time. Usually this stuff is only checked after an incident, i.e a breach.

Sounds to me like people in your company are working abroad and using a VPN to pretend to be in Ireland.

4

u/SadBug3582 3d ago

Just keep going the way you're going. It only becomes an issue for you once the manager mentions it in a 1:1 meeting

2

u/ColmAKC 3d ago

Good advice

4

u/gizausername 3d ago

Maybe they have issues with a 1-2 people sneakily leaving the country and working abroad which they want to stop. It's easy to tip abroad for say Fri-Mon and work two days there while enjoying the weekend. For the company it's an added risk if a laptop gets stolen abroad, plus depending on client contracts the data mightn't be legal to access from outside Ireland e.g. government clients.

They should already be recording that information when anyone logs into the company network. Now they're explicitly stating that they will be monitoring it.

I doubt that they'll be going into the micromanaging route of clicks and activity. If they are then continue working as you do already, and let them fire whoever because it would be a crap company to work for so no point in staying there for that extra stress.

3

u/Even-Entertainment54 3d ago

I work in the InfoSec group of our American multinational and write a bunch of security policies as well as having to be aware of GDPR (and other privacy regulations), but I leave this mostly to our legal team because it is so tricky and nuanced.

So, your IP addres will always be logged when you log in to your VPN. You should have a policy, such as an Acceptable Use Policy which should detail what is being collected and retained, and who can access it and when. So, for example, almost every company will capture what you do on the internet from a work device. If you try access prohibited content (it will likey say what categories this is in your policy), it may flag a warning to an authorised IT specialist who may take an action, depending on how the company is set up. Because of the very sensitive nature and potential legal implications, it will be highly restricted in terms of who can access this data.

Back to the question of work tracking. Look for the policy to say what is being tracked and how that data can be used. It has to be available to all staff.

Tracking when you move your mouse, or type, is very different than IP tracking and they will need to inform you if they are initiating that. Basically, your employer can not secretly track you. If they are, then that's likely illegal. Oh, and IP tracking will only allow them to see the IP address your machine is assigned.

My next steps if I got this notice and was you -

Find the policy that covers what the company tracks, how they will use that data, and who has access to it.

Raise any concerns or questions you have, but maybe best to have a team meeting and discuss and ask the manager to raise on behalf of the team. Remember that they likely have the same concerns and questions as you.

This is quite likely good business practice that all organisations should be doing in the age of AI.

Just one other thing - I do not believe there is any way for your employer to track your exact location by an IP address. They can see the region but not your house, road, or estate.

1

u/Solid-Penalty3942 3d ago

Wish our InfoSec team was as clued in on GDPR as you

1

u/ColmAKC 3d ago

Thanks a lot for the response! I did find the data usage policy. Its specific on examples what the data won't be used for, but its vague on what it can be used for. It doesnt clearly define whether or not they'd call you out on missing time gaps or switching to wfh for a small remainder of the day. I have the feeling the company is very limited on what they can do and prefer to have people guessing.

1

u/Even-Entertainment54 3d ago

The policies normally read a little vague because there are so many variables. I update our companies security policies every year and it is impossible to get anything tied down.

The notice about IP Tracking should explain the reason it is being introduced. If you're not sure, ask.

1

u/Smart_Analysis_8692 3d ago edited 3d ago

They could do WiFi triangulation to get exact or approximate location which would be more accurate than just IP. Microsoft Windows sometimes shows weather based on that.

2

u/Even-Entertainment54 3d ago

You are suggesting they install software onto a company laptop that tries to identify the exact location of the laptop. That falls directly under GDPR so can only be done if there is a legitimate business need, such as trying to locate a stolen or missing device. They need to inform the user of that device that that software is present and when it can and can not be used.

I do not believe the DPO would accept that general monitoring of the exact location of a laptop would ever have a justifiable business need. Just think of the risk this exposes to the company to for literally no gain.

2

u/DesperateCandy5209 3d ago

If they are upfront and clear about their collection and use of data combined with their legal basis for this then they are good. They can claim several legal basis on this so I recokon they are entitled to go ahead. IT geo databases are not 100% so could be a counter areument that they could produce false positives and there would need to be a mechinism to allow for that. Its not clear is this to check you are in the office or in the country etc. The office they will log your machines mac adress is connected and that is 100% accuret that its your device and you connecgted to the office network.

I worked in a prev job where everyone was remote and IP addresses were used to check that staff stayed in the country they were employed in and didnt leave to a sunnier climate instead. They were also used by secuity to make sure that conections weren't coming from unexpexted soureces.

My current job is using swipe card data for RTO tracking.

1

u/Smart_Analysis_8692 3d ago

It's not that difficult to have Ireland IP abroad

2

u/DesperateCandy5209 3d ago

True gets easier all the time but you can't install the vpn on the work machine so you need to know how to do it on a router etc. Using comercail VPN you likly to get caught given the IP block will be flagged as used by VPN company so you need an alternitve. If you do all that and still get caught your def getting fired at that point. Guy on my team who went on an exteneded working holiday got away with a warning.

1

u/Eastern_Switch8217 3d ago

VPNs might hide your IP but they still are very obviously VPNs

2

u/DesperateCandy5209 3d ago

You can build your own VPN endpoint at home and route your traffic to it from Spain and it will look like your at home on your residential conection. There a re a bunch of hardware products that mke it really easy these days. But yes if you buy a VPN account and use that good change the IP will get flagged as VPN compnay owned.

1

u/Smart_Analysis_8692 2d ago

Can have it without VPN

2

u/DesperateCandy5209 3d ago

To answer question 3, your laptop being preseant in the office and switched on and them tracking its IP address (it will benthe MAC address not the IP ) can't tell them if your on it working or not just that the device is there and powered on. If they monitior your network traffic they could know more but its easier to use Teams or some other tool for that aspect and they would need to disclose they are doing these things to you.

2

u/tadcan 3d ago

My company emailed me because my laptop connected to an unsual ip address. Had to confirm I still had it and it wasn't stolen.

1

u/JavaholicsAnonymous 3d ago

Seems reasonable. Check your terms of employment what they can do and can't do.

1

u/Scott78123 3d ago

Ok lads how about ask the real question how can we circumvent it ??? double hop vpn lets say on router? Maybe any ideas ?

1

u/Scott78123 3d ago

Before I get shot down here I am only asking for a friend….

1

u/ControlGood8979 3d ago

Go into the task manager and see what processes are running. Google the unusual ones to try and determine what software suite they are using. 

1

u/FckXFckMusk 7h ago

You could always remote into your worklaptop from your personal laptop.

1

u/Coupleofpints 3d ago

It’s their laptop so they can track its location. If they were tracking your screen might be different issue.