
Employee Monitoring and Surveillance in Belarus: What’s Legal for Foreign Employers
You’ve hired five developers in Minsk. Your global IT policy runs an activity tracker on every corporate laptop, screenshots land…
You’ve hired five developers in Minsk. Your global IT policy runs an activity tracker on every corporate laptop, screenshots land in a US dashboard every ten minutes, and Slack messages are archived indefinitely. In most jurisdictions, you’re fine.
In Belarus, you may already be exposed to administrative fines — and, in a worst case, criminal liability.
Belarus has a dedicated personal data protection regime that borrows heavily from GDPR but is stricter in the ways foreign employers don’t expect. If you employ Belarusian staff — directly or through a partner — the local rules apply, no matter where your HQ sits.
Here’s what you can legally monitor, what will get you in trouble, and how to structure your setup so you don’t have to guess.
The short version
- Consent is the default legal basis for processing employee data in Belarus. “Legitimate interest” is not a standalone alternative the way it is under GDPR.
- Your consent forms need very specific content. Copy-pasted GDPR templates usually fail the local requirements.
- Monitoring is allowed — email, corporate devices, productivity tools, video, GPS — but only with proper written policy, disclosure, and consent.
- Cross-border data transfer to the US, UK, and most non-EU countries requires additional legal grounding.
- Penalties run from administrative fines to criminal liability of up to five years imprisonment in severe cases.
The three laws you actually need to know
Belarus regulates workplace monitoring through several overlapping instruments. Three matter to you.
The Labour Code of the Republic of Belarus (No. 296-Z, 1999) governs the employment relationship itself, including what employers must disclose about how they handle employee data and any third parties involved.
Law No. 99-Z “On Personal Data Protection” took effect on 15 November 2021 and is the main framework. It’s inspired by GDPR but adds detailed consent content requirements and narrower lawful bases. Enforcement sits with the National Personal Data Protection Center (NPDPC).
Law No. 455-Z “On Information, Informatisation and Data Protection” (2008) sits alongside 99-Z and covers information security duties more broadly. The full texts of these laws are published on the national legal portal of Belarus.
Article 28 of the Constitution provides the baseline right — protection against unlawful interference with private life. Everything else builds on top of it.
One more thing worth flagging: draft amendments to Law 99-Z are expected to move through the Council of Ministers during 2026 and will explicitly cover video surveillance, audio recording, and AI-based monitoring. Any policy you build today should be reviewed once those come into force.

Consent isn’t the consent you’re used to
If you take one thing away from this article, take this: Belarusian consent is not GDPR consent.
Under Article 4(3) of Law 99-Z, consent is the default lawful basis for processing personal data. Article 6 lists narrow exceptions — administration of justice, protection of life and health, certain public interest cases — but employment monitoring rarely qualifies for any of them.
Article 5 then requires that consent, before it’s given, includes a specific list of disclosures:
- The operator’s identity and location
- The exact purposes of processing
- The full list of personal data being collected
- The validity period of the consent
- Any authorized processors (i.e., your monitoring vendors)
- The complete list of processing actions and methods
- A clear, plain-language explanation of the employee’s rights and the consequences of refusing
Consent itself can be captured in writing, as an electronic document, or through a checkbox flow — as long as receipt is provable. Detailed practical guidance on what belongs in an HR consent has been published by Belarusian counsel.
Here’s the trap: most foreign employers land in Belarus with GDPR-style consent forms. Those forms almost never include everything Article 5 requires. A missing element makes the consent formally defective, which makes the processing unlawful.
If your monitoring stack is built on a consent form drafted in Berlin or San Francisco, you probably need to redo it. Our team runs compliance reviews for foreign employers looking at exactly this problem.
What you can monitor (and under what conditions)
Monitoring isn’t banned. It’s regulated. Here’s how the main categories break down.
Corporate email and messaging. Allowed with proper policy, disclosure, and consent. Blanket real-time reading of messages sits at the risky end — you need a defined business purpose and proportionate scope.
Company-owned laptops and phones. Allowed. The device must actually be company-owned, the employee must be informed in writing, and the collection scope must be defined and proportionate to the stated purpose.
Productivity and activity trackers (Hubstaff, Time Doctor, Teramind, and similar). Allowed, but everything hinges on disclosure. The tool must be named in the consent, its data collection listed in detail, and its scope limited to work hours.
Screenshots and keystroke logging. High-risk. Permissible only with a narrow, justified purpose, explicit consent, and safeguards that prevent capture of personal accounts, banking sessions, and other private material. If your default is a screenshot every ten minutes with no filters, you’re going to have a problem — the practical requirements are covered in more depth in the DataGuidance country note on employee monitoring in Belarus.
Video surveillance in physical offices. Allowed with signage, a written policy, and defined purposes. Continuous webcam surveillance of employees working from home is a different story and sits in a red zone.
GPS tracking of vehicles or field staff. Allowed with notice, tied to a legitimate work purpose, and proportionate. Tracking outside work hours will not survive scrutiny.
Bring-your-own-device (BYOD). Significantly more restricted. Mixing personal and work data on a single employee-owned device without a clean separation policy invites liability. Most foreign employers underestimate this one.
The mistakes foreign employers make most often
After hundreds of onboardings, the same five gaps show up over and over.
- Reusing a US or EU consent form without localizing to Article 5. It’s the single most common defect.
- Sending monitoring data to servers outside Belarus without confirming adequacy or obtaining a specific transfer consent. We’ll come back to this in the next section.
- Assuming remote employees fall outside Belarusian jurisdiction because the employer is offshore. They don’t. The location of the employee determines the applicable law.
- No named person responsible for personal data protection inside the organization. Law 99-Z operators are expected to have one.
- No signed monitoring policy on file. Verbal acknowledgment at onboarding doesn’t cut it.
Any of these on its own is enough to trigger an NPDPC finding. If you’re planning your first Belarusian hire, our guide to hiring employees in Belarus walks through what needs to be in place before the offer letter goes out.
Cross-border data transfer is the hidden trap
Your monitoring stack almost certainly sends data outside Belarus. That’s a regulated act under Law 99-Z.
Belarus applies an “adequate level of protection” test to cross-border transfers. Countries qualify automatically if they’re:
- Parties to the Council of Europe’s Convention 108 on data protection
- Members of the Eurasian Economic Union (EAEU)
The United States, the United Kingdom, and most other non-EU destinations do not qualify automatically. If your monitoring dashboard is hosted in AWS US-East, or your HR system runs on a UK-based SaaS, you need a separate legal basis for the transfer — usually explicit, specifically scoped consent that names the destination and the purpose. DLA Piper’s Belarus country note is a good high-level reference for how the transfer test works in practice.
This is where a lot of foreign employers accidentally cross the line. The monitoring itself might be locally sound; the transfer of that data abroad is the violation.
Penalties: administrative and criminal
Belarus has real teeth in this area.
Administrative liability applies to unlawful processing of employee data. The NPDPC can investigate on its own initiative or in response to complaints, and findings are public.
Criminal liability kicks in under Articles 203-1 and 203-2 of the Criminal Code. Penalties include fines, arrest, restriction of freedom, or imprisonment of up to five years. The threshold offences include deliberate illegal collection of personal data without consent that causes significant harm, and failure to implement data protection measures that leads to unauthorized dissemination with serious consequences.
Foreign HQs sometimes assume they can absorb an administrative fine and move on. That’s a bad bet — the reputational cost of a public NPDPC investigation, and the operational disruption of a criminal case involving local management, is far higher than the fine itself.
The clean way to run monitoring in Belarus
If you’re hiring in Belarus, you have three broad options.
Set up a local entity. You take on the full compliance burden yourself — Article 5 consent forms, a named data protection responsible person, NPDPC-facing obligations, and localized monitoring policies. This makes sense at scale.
Contract independent contractors. Cheaper and lighter, but the monitoring conversation gets more complicated. Contractors have stronger claims to independence, and misclassification risk in Belarus is real.
Use an Employer of Record. The EOR becomes the legal employer in Belarus. Consent forms, monitoring policies, data processing agreements, and NPDPC-facing responsibilities are executed under Belarusian law from day one. You keep operational control — task assignment, performance management, your own tooling — while the compliance layer sits with a local specialist.
For most foreign teams under 30 people in Belarus, the EOR route is the fastest path to a compliant setup without building local legal muscle you don’t need.
FAQ
- Can I use Hubstaff, Time Doctor, or Teramind with my Belarusian employees?
Yes, but only if the specific tool is named in a Belarusian consent form that meets Article 5, if the collection is scoped to work hours, and if any cross-border transfer to the vendor’s servers is separately grounded. The tool itself isn’t the problem — the paperwork around it is.
- Does my company need to comply if we’re based outside Belarus?
Yes. The law applies to processing of personal data of individuals located in Belarus, regardless of where the employer is incorporated. Employing a Belarusian resident brings you into scope.
- Does Belarus accept GDPR-style consent?
Not by default. GDPR consent forms typically miss required elements under Article 5 of Law 99-Z — validity period, list of processing actions, authorized processors, the specific rights language. Localizing the form is a small job compared to the risk of leaving it as-is.
- Can I monitor an employee’s personal laptop if they use it for work?
Very cautiously and with narrow scope. BYOD monitoring is one of the most exposed setups under Belarusian law. Most employers who take this seriously either issue a company device or restrict monitoring to a clearly separated work container.
- Who enforces personal data protection in Belarus?
The National Personal Data Protection Center (NPDPC), established under Presidential Edict No. 422 of October 2021. It has advisory, corrective, and investigative powers, and can escalate serious cases to law enforcement. Its official English-language site is a useful starting point for the regulator’s own guidance.
- What if I already have Belarusian employees and my monitoring setup isn’t compliant?
Fix it, don’t hide it. Update the consent forms, put a written monitoring policy in place, review cross-border transfers, and consider engaging a local partner to run a compliance check. Retroactive fixes are far cheaper than an NPDPC investigation — reach out to our team for a review.
If you already have Belarusian staff on the books and you’re not sure how your monitoring stack lines up with Law 99-Z, that’s the audit to run before an incident forces you to. Book a call with our team and we’ll walk through your current setup.
Our Blog
The latest news in our blog
Employee Monitoring and Surveillance in Belarus: What’s Legal for Foreign Employers
You’ve hired five developers in Minsk. Your global IT policy runs an activity tracker on every corporate laptop, screenshots land…
EOR Insurance and Liability Coverage Explained: What You’re Actually Protected Against
A CFO forwarded us a Slack thread last quarter. His head of legal had asked what sounded like a simple…
Performance Improvement Plans in Belarus: What’s Actually Enforceable Under Local Labor Law
A US COO wrote to us a couple of months back with a two-line brief. Put Alexei on a 30-day…
Contact
We’re available for the new projects

