A research team from Northeastern, Columbia, Vanderbilt and UC Berkeley ran the cleanest possible test of employee-monitoring software: they signed up as an employer, deployed nine widely used platforms — a sample that included Hubstaff, Deputy and Time Doctor — then logged in as workers and recorded every byte the apps transmitted. All nine shared identifying worker data — first name, last name, email, employer — with outside companies. The study landed in May with less noise than it deserved. A Fortune feature published today changed that.
The scale is the story. The nine platforms sent workers’ online activity — IP addresses, device details, pages visited, unique identifiers — to 145 distinct third-party domains: Facebook, Google, Microsoft, LinkedIn, Stripe, mobile-ad platform AppLovin and yandex.com, the Russian search company. Each platform contacted between 14 and 54 outside domains. Researchers logged 121 separate instances of identifying data being shared, with worker emails going to as many as six third parties at once, including ZoomInfo and Segment. Only two of the nine vendors named any third-party recipients in their public privacy documents — and even those lists missed companies the researchers caught in testing.
Two details sharpen the picture. Three of the nine apps can track a worker’s precise location at any time — app in the background, worker potentially off the clock — and three require motion-sensor access just to clock in. And surveillance ran uphill: of the 121 data-sharing instances, 76 involved the managers’ own accounts. The boss who installs the watching software gets watched more than anyone in the building.
Our take: if you pay for monitoring software, this is your problem twice. Workers’ data is leaking to ad networks nobody consented to — and the researchers explicitly map that conduct onto UDAAP, FCRA and state privacy law, where the employer who deployed the tool carries exposure alongside the vendor. You cannot outsource compliance to a company that won’t name its own subprocessors. The same logic that applies to over-permissioned AI agents applies here: audit what your stack actually transmits, not what the brochure claims — and if the answer is ugly, run the vendor exit.
What to watch
- Regulatory follow-through. The researchers recommend bright-line bans on selling or sharing worker data and flag unlimited retention. State attorneys general and the FTC already have the statutory hooks if they choose to use them.
- Vendor response. Whether the named platforms trim their tracker lists or expand disclosures. Only Hubstaff and Time Doctor published subprocessor lists at all — and testing showed even those were incomplete.
- The web-versus-app gap. Browser dashboards leaked roughly three times more than mobile apps — 104 sharing cases against 39. Expect “use our app” to become a vendor compliance talking point.
The monitoring industry sold employers certainty about what their people do all day. What it built, per this study, is a second business selling everyone’s behavior out the back door — a pattern of unaudited tool risk the software world keeps relearning, from 143,000 vulnerabilities in MCP servers on down. The cheapest fix is knowing what you installed.
