AI in the Workplace: Can an Algorithm Assess Employees’ Stress?

AI in the Workplace: Can an Algorithm Assess Employees’ Stress?

August 10, 2026

Modern technologies, and in particular artificial intelligence systems, are increasingly present in the workplace and are being used for various purposes. At the same time, their use raises important questions concerning the protection of personal data, privacy and the dignity of employees.

In this regard, this article analyses the decision of the Italian data protection authority (“Garante”) of May 2026, concerning the use of an AI tool to analyse messages exchanged by employees for the purpose of assessing their level of stress at work.

The decision is significant as it highlights the limits of the use of AI tools and, in this regard, the need to ensure the protection of personal data and employees’ privacy already at the design stage of such AI solutions.

Background of the Case

Myndoor S.r.l. developed an AI tool intended for companies that wish to enable their employees to monitor certain indicators of stress and psychological well-being at work. The tool operates as a plug-in within Slack and Microsoft Teams applications and uses artificial intelligence to analyse the content of messages sent by employees who choose to use it.

The data subject to processing are determined at the employer’s discretion and may include the employee’s first and last name, telephone number, residential address and email address. The processing may also involve special categories of personal data within the meaning of the General Data Protection Regulation (“GDPR”), which are processed, as stated, for the purposes of preventive medicine and occupational healthcare, and are deleted after processing.

As explained by Myndoor, employers do not have access to the data of individual users – employees ,as the data are processed directly by Myndoor. However, under certain conditions, an employer may request an aggregated report from Myndoor on the stress level of employees using the system, through the Myndoor platform and within the employer’s protected account. Accordingly, Myndoor acted as the controller in relation to users’ data, while the employer was technically prevented from accessing the data processed by Myndoor for the purpose of preparing the aggregated report.

Such a report could only be generated if at least ten employees had used the plug-in, and it related to all employees of the company, with the aim of reducing the risk of identifying individual employees.

In the case at hand, an aggregated report was provided to only one company, and the Garante initiated an investigation ex officio following media reports concerning the company.

The Garante’s Decision

Following its investigation, the Garante did not establish a specific violation of data protection legislation, as it was not demonstrated that the personal data of individual employees had been disclosed to their employer.

The Garante established that the employer in question did not possess additional information that would have enabled it to identify individual employees on the basis of the report, or to link an employee’s name to the data contained in its database.

However, the Garante considered that it could not be completely ruled out that, in the future and depending on the information available to an employer, aggregated results could enable the identification of individual employees.

For this reason, the Garante issued a warning to Myndoor and ordered it to implement appropriate technical and organisational measures to prevent any disclosure, including indirect disclosure, of employees’ data to their employers.

Protection of Employees’ Privacy and Restrictions on Data Processing in the Workplace

The Garante primarily addressed the protection of employees’ personal data under the GDPR and, in this regard, under Italian national legislation.

Data processing in the workplace must take into account the dignity, privacy and fundamental rights of employees. Therefore, an employer cannot have unlimited access to information relating to its employees.

In this context, the Garante specifically emphasised that data which are not relevant to an employee’s work activities, and in particular data concerning employees’ psychological well-being and stress levels, are data to which an employer should not have access, meaning that there is no appropriate legal basis under the GDPR for processing such data for the stated purposes.

In other words, the fact that an employer enables employees to use a tool for monitoring their well-being does not automatically mean that the employer is entitled to know which employees are experiencing stress or what their psychological state at work may be.

Data Protection as Part of the Design of AI Systems

The Garante also paid particular attention to the GDPR principle of data protection by design and by default, i.e. the obligation to take data protection into account already at the stage of designing, developing and implementing AI solutions.

This is particularly important for AI solutions of this type, as protection cannot depend solely on whether an employer currently has direct access to the data.

It is necessary to ensure that the system is designed in such a way as to prevent an employer from subsequently determining, by combining aggregated results with other information, to whom a particular result relates.

Use of AI Solutions for Assessing Employees’ Emotions

In addition to the GDPR, the Garante referred to the AI Act, particularly the prohibition of certain uses of AI systems for inferring the emotions of natural persons in the workplace.

In this context, taking into account data protection principles and specific national legislation providing enhanced protection of employees’ dignity in their working and professional environment, the use of such systems must not result in employers gaining access to information about their employees obtained through AI solutions.

This is because AI systems do not merely process data directly provided by users. They may also draw additional inferences about an individual on the basis of such data.

Such inferences may not always be reliable or easily verifiable. Therefore, the reliability of AI models, data quality, transparency and explainability of results, as well as appropriate human oversight, are of particular importance.

Limits of AI-Based Employee Analysis

The Garante’s decision demonstrates that the use of AI systems in the workplace requires particular caution where such systems are capable of drawing conclusions about the psychological or emotional state of employees.

Data protection must therefore be taken into account already during the development of such systems, particularly where there is a risk that an employee could be identified, even indirectly.

An additional concern is that AI may draw conclusions from analysed data that are not always accurate or easily verifiable. This may result in inaccurate assessments and may, in certain sensitive situations involving vulnerable individuals, lead to harmful consequences and discrimination, with potentially serious and difficult-to-remedy effects on an individual’s identity and dignity.

For this reason, the use of AI systems in the workplace must be carefully aligned with the rules governing data protection and employees’ privacy.

This article is for informational purposes only and does not constitute legal advice. Should you require any further information, please feel free to contact us.