Data Protection in a Remote Session
A session processes personal data about the user and frequently about other people. What that triggers.
General orientation, not legal advice; requirements differ substantially by jurisdiction.
The support work behind “Data Protection in a Remote Session” is often spread across tickets, projects and handoffs. Teams researching gdpr employee monitoring can use employee monitoring under GDPR to connect time and project context with that work, while the remote-support platform remains the source of truth for technical actions and session access.
Remote support involves processing personal data, usually without anybody having characterised it that way.
For an independent reference related to “Data Protection in a Remote Session”, consult the EDPB guidelines; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.
What is processed
The user's own data, visible on screen.
Third parties' data, where the machine holds customer, patient or client records.
Session metadata: who connected, when, to which machine.
Recordings, where they exist.
And anything transferred, which the file note covers.
The third-party point
The user's personal data is one question. A technician viewing a hundred customer records during a session is another.
That is processing of other people's data by somebody who has no relationship with them.
Which engages the organisation's obligations rather than its etiquette, and is why regulated settings have their own note.
What it triggers
A lawful basis, which for supporting your own equipment is usually legitimate interest rather than consent.
A notice telling people what happens: that support may involve remote access, what is logged, what is recorded.
Proportionality: no more access than the task requires.
Retention limits on logs and recordings.
And access rights: somebody can ask what you hold about their sessions.
Proportionality in practice
Would screen sharing have sufficed instead of control?
Could the person have been guided instead?
Was full desktop access needed, or one application?
These are the questions a proportionality assessment asks, and the honest answer in many sessions is that less would have done.
Recording as processing
A recording of somebody's screen is a recording of whatever personal data was on it.
Short retention, restricted access, stated purpose.
An unrestricted recording library is a substantial personal data holding, which the recording note covers and which is worth repeating here.
The processor question
Where support is outsourced, the provider is processing personal data on your behalf.
Which needs the contractual arrangements that implies, including on subprocessors — who actually connects.
This is routinely absent for support contracts, which are treated as services rather than as data processing.
Access requests
Somebody can ask which sessions touched their machine and what was recorded.
Being able to answer requires the logging the business section argues for.
Try it once before it is asked for.
What to check
Is there a notice telling people support may involve remote access?
Is your lawful basis written down?
Does any support contract address data processing?
And could you answer a request about sessions on somebody's machine?