Key takeaways
Stop presenting it as a monitoring project and re present it as an equipment project, then put the scope in writing.
Three moves resolve most of these cases. First, split the data model out loud. Availability, performance and quality are attributes of a machine. Show the council the actual dashboard and point at what it contains. Second, run a Data Protection Impact Assessment under Article 35 before you go back to them. It forces you to document necessity and proportionality, which is exactly what a council is entitled to challenge and rarely gets shown. Third, negotiate a works agreement that names the person level reports that will exist, restricts them to named roles, and sets a retention period.
What fails is arguing that no personal data is involved when the system has operator logins. Councils check. Being precise about what is personal, and then constraining it, earns far more trust than claiming there is nothing to discuss.
Last updated: August 2026.
Shop floor resistance to OEE monitoring is rational. Operators have usually seen one of two things: a plant where downtime data was used in an individual performance conversation, or a plant where a number appeared on a screen with no explanation and no way to contest it.
Underneath the surveillance word there are normally three concrete fears.
Fear one: the data will be used against me individually. This is the real one. It is about consequence, not collection.
Fear two: the numbers will be wrong and I will be blamed anyway. A micro stop logged as an operator delay when it was a jam is worse than no data at all, because it is now written down.
Fear three: nobody told us. Transparency obligations exist under Articles 12 to 14 for a reason. A system that appears on the line without notice reads as something being done to people rather than with them.
Address the three fears and the legal conversation gets much easier. Lead with the legal argument alone and you will win the meeting and lose the rollout, because unmotivated operators will simply stop logging stop reasons and your data quality collapses.
This is the order that keeps projects moving. Doing it out of order is what produces the blocked rollout.
The single most effective item in a works agreement is a written statement on disciplinary use. Something close to this:
Data collected by the production monitoring system is processed at equipment level for the purpose of identifying and eliminating technical causes of downtime. It will not be used as the sole or primary basis for individual performance assessment or disciplinary measures.
Councils accept monitoring far more readily once the consequence path is closed. And operationally you lose nothing, because the value of OEE data is in finding the recurring jam on the infeed conveyor, not in ranking operators.
Some of this is configuration rather than negotiation.
Default to shift level rather than individual level aggregation in the dashboards everyone sees. Person level reporting can exist and still not be the default view.
Use role based access control seriously. If every line supervisor can open a per employee productivity report, the council is right to be nervous. If it is restricted to two named roles and every access is logged, the risk profile changes completely.
Let operators annotate stop reasons. This converts the system from something that judges into something that records their side of the story, and it is the fastest fix for fear two. It also materially improves your data.
Be careful with cameras. Computer vision on a line is the highest sensitivity element in the whole stack, and it is also where the strongest technical mitigations exist, including framing the field of view on the machine rather than the workstation. We cover that specific conversation in production line cameras without surveillance.
A German automotive supplier with 210 employees had an OEE rollout stopped by its Betriebsrat after the pilot. The original proposal described "operator performance visibility", which was fatal wording.
The relaunch changed four things. The purpose was rewritten to target the top five recurring stop causes on two lines. A DPIA was produced and shared in full. The dashboard default was moved from operator to shift. A works agreement was signed listing eleven reports, of which two were person level and restricted to the plant manager and the HR lead, with a twelve month retention limit.
The council approved it in the second session. Worth noting what did not change: the software, the sensors and the metrics were identical. The blocker was never technical, and no vendor selection would have solved it.
Six months later the two lines had eliminated a recurring die change delay worth roughly 40 minutes per shift. The operators found it, because they were the ones annotating the stops.
On the last two, Fabrico is hosted on Amazon Web Services in an EU region with a Data Processing Agreement available, is certified to ISO/IEC 27001, ISO 9001 and ISO/IEC 20000-1, and ships its interface in English, Bulgarian, German, French and Polish. The broader data protection checklist is in our GDPR buyer's guide for manufacturing software.
The wider adoption question, meaning how to get operators actively using the system rather than merely permitting it, is covered in our operator adoption strategy guide and in the CMMS change management guide. For the metric itself, start with OEE for manufacturing.
If you want to walk your works council through real screens rather than a slide deck, book a demo and bring them to it. That single move has unblocked more rollouts than any argument on paper.
In several EU member states, including Germany and the Netherlands, systems capable of monitoring employee behaviour or performance are subject to co determination or consent rights, which means the council can withhold agreement. The scope and remedy differ by country, so confirm the position under your own national law before assuming either that they can block it outright or that they cannot.
Machine level availability, performance and quality data describes equipment and is not employee monitoring on its own. It becomes employee monitoring when it is linked to an identifiable person through logins, badge scans or per employee reporting, or when it is used to assess individual performance.
Article 35 requires one where processing is likely to result in a high risk to rights and freedoms, and systematic monitoring of employees in the workplace is commonly treated as meeting that threshold by supervisory authorities. Running one is also simply the fastest way to have a productive conversation with a council.
Often yes, but under conditions: a documented purpose, proportionality, restricted access, a defined retention period and usually an explicit agreement on whether it may inform disciplinary decisions. What rarely survives is untargeted individual tracking enabled by default for every supervisor.
Equipment data can generally be kept as long as it is operationally useful, since it is not personal data. Records that identify individuals need a defined retention period tied to the stated purpose. Twelve months is a common negotiated figure for task execution records, but set it against your own purpose rather than copying a number.