Workplace privacy covers several issues: who can overhear a conversation, what data an employer collects, how monitoring is disclosed and where confidential work can take place. The legal answer depends on the location, employment relationship and technology involved.
This guide provides operational questions and is not legal advice.
Which activities need greater privacy?
Identify which conversations and tasks need greater privacy and use the examples below to map potential exposure. For each activity, record its location, typical number of participants, frequency, duration and whether a suitable space is available when needed. Use activity categories rather than sensitive meeting details.
| Activity | Potential exposure | Practical action |
|---|---|---|
| HR or disciplinary meeting | Conversation audible outside; meeting subject visible on a display | Assess the room’s suitability and restrict booking details |
| Employee health discussion | Discussion takes place at an open desk; sensitive details appear in shared notes | Identify a suitable enclosed space and use restricted record storage |
| Customer or legal call | No suitable room available; screen visible to others | Review room availability, sightlines and call requirements |
| Confidential project meeting | Documents or whiteboard notes remain visible after use | Clear documents and whiteboards, and end shared-screen sessions after use |
Review the findings with Facilities, HR, IT/security and legal teams. Facilities can assess the space and layout, IT/security can check equipment and access settings, and HR and legal teams can clarify confidentiality and recording requirements.
Use the findings to create a brief covering the privacy needs, current gaps and responsible teams.
Can existing spaces meet those needs?
Physical privacy depends on the suitability of rooms, doors, partitions, layout and sound isolation. The U.S. General Services Administration’s Sound Matters guide recommends separating discussion areas from work that requires quiet and providing appropriately designed enclosed rooms for confidential conversations.
Apply these acoustic principles when reviewing existing meeting rooms and smaller enclosed spaces. Consider their position relative to open workstations and whether conversations can be understood from nearby desks or corridors. Separately, check whether screens or documents are visible through glazing.
Before adding capacity, distinguish between availability and suitability:
- A suitable room exists but is difficult to book: review allocation, booking rules and unused reservations.
- Rooms are available but do not provide the required privacy: investigate the layout, enclosure and permitted uses.
- Suitable spaces are regularly unavailable: record the unmet demand before comparing additional options.
Check the room’s current technology settings, including microphone coverage, camera framing, recording and transcription, and information shown on external displays and shared calendars.
For an HR discussion, assess both the space and the visibility of meeting information. Use a neutral booking title such as “Reserved,” restrict access to the invitation and keep case notes in the designated HR system.
What should room systems collect and display?
Limit room-system information to what is needed for the intended purpose. Check public displays and authorised-user views separately, as they may expose different booking details.
Establish whether occupancy and access records can be linked to individuals through names, accounts, access cards or timestamps combined with booking records.
Define when recording is permitted. For sensitive meetings, consider a no-recording default, with exceptions reviewed against applicable legal, accessibility and recordkeeping requirements. Use the inventory below to establish access, storage and sharing arrangements.
Create a data inventory before deployment:
| Record | Questions to resolve |
|---|---|
| Room bookings | Who can see names, titles and attendees? Can public displays show availability only? |
| Occupancy and access logs | Can records identify individuals? Is that detail necessary for the stated purpose? |
| Audio, video and transcripts | Who can activate capture, access recordings, export files or share links? |
| Vendor-held information | Where is it processed? Who provides support access? What happens at contract termination? |
For each data category, assign an owner and define its purpose, access permissions and retention arrangements. Ask IT or the service provider to confirm that the system can apply these settings, including deletion and any required preservation.
Confirm applicable requirements before enabling these functions. Have your legal or privacy team assess the workplace location, recorded-call participants’ locations and data processing arrangements. More than one jurisdiction may apply. The following examples support planning and are not exhaustive or legal advice:
- United Kingdom: Before introducing audio or video monitoring of workers, complete a data protection impact assessment and plan how affected people will be informed, as set out in the ICO’s monitoring guidance. Check the current guidance before deployment, as it is under review.
- European Union: Where the GDPR applies, establish a lawful basis before collecting personal data through booking or monitoring systems, and prepare the required privacy information. Use the EDPB’s guidance on lawful processing alongside applicable national employment rules.
- California: Before enabling recording, assess consent requirements under Penal Code Section 632, which generally prohibits recording confidential communications without all parties’ consent, subject to its scope and exceptions. If the employer is covered by the CCPA, also check the requirements for handling California employees’ personal information using the CPPA’s FAQs.
Explain the agreed arrangements through policies, room notices and software prompts: what is collected, why, who can access it and whom to contact with questions. Include visitors and other participants where relevant. Notices should reflect actual settings; a booking checkbox alone does not resolve recording requirements.
Where a service provider handles personal data, review its contractual responsibilities, security controls and subprocessors before deployment. Keep this review separate from assessing a supplier that provides only the physical room or enclosure.
Verify confidentiality claims
Once the intended activities are clear, ask what evidence supports using the proposed space for them. Claims such as “soundproof” or “fully private” need more detail: request the test method, report reference, tested model and configuration, measured result and units. Check whether the results cover the complete enclosure or only a component.
Match the evidence to the question being asked. For example, ISO 23351-1 provides a laboratory method for comparing how furniture ensembles and enclosures reduce speech levels. For an enclosed meeting room, ASTM E2638 assesses speech privacy using sound isolation and background sound at listening positions outside the room. The appropriate method and acceptance criteria should reflect the intended activity and project requirements.
Compare the documented construction, door arrangement and ventilation configuration with what will be supplied. Ask the supplier to explain differences between the tested configuration and the proposed installation.
Before a trial, agree which activities the space should support and what evidence is needed to approve those uses. Use a scripted, non-sensitive conversation and record the door position, ventilation setting, surrounding activity and listening locations. These observations can identify potential problems, but informal listening does not replace professional assessment where a defined level of speech privacy is required.
If the space does not meet the intended privacy needs, review its location, construction or permitted uses before assigning sensitive activities to it.
Implementation checklist
- Identify applicable employment, privacy and recording laws with local counsel.
- Publish a clear policy in language employees can understand.
- Provide suitable spaces for confidential activities.
- Limit data collection and access to the stated purpose.
- Train managers and review complaints through a documented process.
Assign an owner to each action and review whether the changes address the privacy and space-availability issues identified at the start.
Share your floor plan, intended activities and typical number of users with the Soundbox team to discuss configurations and request acoustic information for the selected model. Have your legal or privacy team assess the requirements applicable to the proposed use.



