Commonwealth Bank’s 2026 enterprise-agreement negotiations have turned into a fight over the data generated by ordinary work tools: a staff app used around offices, presence signals from remote devices, and activity captured through Microsoft Teams. The Australian Financial Review reported on August 6 that the Finance Sector Union is seeking limits on systems it says can reveal where employees are in an office, when they step away from a home workstation, and how they engage in Teams meetings. For Windows users and IT administrators, the dispute is a warning against treating device telemetry, presence and collaboration analytics as interchangeable with performance management. CBA’s systems may be intended to support building access, desk booking, security, remote-work administration and collaboration. But once the same data can identify a particular employee’s movements, idle periods or meeting activity, its purpose has shifted from workplace infrastructure to individual surveillance.
The immediate issue is bargaining, not a new regulatory finding that CBA broke the law. Yet the union’s proposed agreement terms expose a wider gap in Australian white-collar workplaces: employers have accumulated granular data from phones, laptops, access systems and Microsoft 365, while the rules governing when managers can use that data to judge workers remain thin.

A businessman analyzes futuristic dashboards showing maps, video calls, profiles, and performance charts.The CBA dispute is about data use, not a single app​

The Financial Review’s report names location tracking, away-from-keyboard time while working remotely, and Teams meeting participation as the union’s concerns. The FSU’s own CBA bargaining material confirms surveillance and employee data rights are formal claims in the negotiations covering the bank’s workforce. Its agenda calls for monitoring to be limited to circumstances necessary for worker and public safety, for employee data collection and retention to be transparent and limited, and for restrictions on selling employee data.
That matters because the union is not simply asking CBA to disclose a privacy policy. It is attempting to put enforceable limits into an enterprise agreement: the document that governs pay and conditions for covered staff and can be enforced through Australia’s Fair Work system.
The FSU began negotiations for a new CBA agreement in January 2026. Its campaign describes the bank as a standard-setter for the finance sector, and the Financial Review reports the agreement under discussion covers roughly 35,000 employees. If surveillance language lands in the final agreement, the result could become a template for bargaining at other banks, insurers, super funds and large employers that run hybrid workplaces on Microsoft 365 and managed mobile devices.
CBA’s current agreement, approved by the Fair Work Commission in 2023, predates this bargaining round. The 2026 negotiations are therefore the practical opportunity to decide whether data controls remain internal policy choices or become negotiated workplace rights.

The record supports concerns about location collection, but not every claimed capability​

The union has publicly described CBA’s Navigate application as a central part of the concern. In a June article, the FSU quoted a CBA employee who said the app could connect with Bluetooth devices at home and that location-related prompts appeared through work applications. The union’s statements are allegations from a bargaining party, not independent technical verification of every feature or of how CBA uses each data point.
Still, there is evidence that the underlying issue did not materialise overnight. A recent academic paper on employee surveillance at work states that CBA employees use Navigate for office entry, workstation booking, fault reporting and visitor registration, and says app reviews indicated requests for precise, continuous location access. A Victorian parliamentary inquiry document also cited the FSU’s earlier evidence that the app collected precise location information and that some workers believed data was being used in leave or productivity discussions.
Those records establish the important point: a system built around physical office services can generate data capable of reconstructing employee presence. They do not establish that CBA routinely uses all of that data to discipline staff, nor do they establish the frequency, retention period, managerial access rules or algorithmic decisions connected to it. Those are precisely the operational details CBA has not publicly set out in the material available for this dispute.
That omission is more consequential than the app’s branding. A location permission required to open a door or allocate a desk may be proportionate to a narrow facility-management purpose. Retaining the same record, combining it with laptop activity, then presenting it to a manager as evidence of attendance or productivity is a separate use with a different risk profile. Employees need to know the difference before an isolated data point is used in a performance conversation.

Microsoft Teams can measure activity, but activity is not output​

The reference to Teams should also be read carefully. Teams includes extensive reporting capabilities that many organisations enable without deploying specialist bossware. Microsoft’s current documentation says meeting attendance and engagement reports can record who attended, join and leave times, meeting duration, and event interactions such as unmuting, camera use, raised hands, reactions and Q&A activity. Administrators can configure who receives those reports and, in some cases, whether people can opt out of appearing in them.
Microsoft 365’s broader Teams activity reporting can show usage patterns such as messages, calls, meetings, audio, video and screen-share sessions. Some reports can expose user-level data when an organisation elects to show identifiable details rather than anonymised names. Teams also changes a user’s presence status automatically when a computer is locked, idle or asleep, and its web client can request permission to detect activity outside the Teams tab to avoid an inaccurate “Away” state.
The technical point is straightforward: Teams offers participation signals, not a productivity verdict. A meeting report can show that an employee joined for 47 minutes, unmuted or raised a hand. It cannot reliably establish whether that employee completed analysis, resolved a customer issue, reviewed a security incident, wrote code, made a sound judgement or did other work outside a Teams window.
Microsoft’s own reporting descriptions reinforce that limitation. Video-duration figures can count the full meeting duration when video was enabled, rather than active camera time; screen-sharing metrics can count the whole session if sharing happened at any stage; and audio or video participation time is not a measurement of active speaking or active camera use. Turning a set of collaboration metrics into a score for effort would be an inference made by the employer, not a fact supplied by Teams.
For Windows administrators, that distinction should shape policy design. The fact that the Teams admin centre permits an attendance or engagement report does not decide whether a manager should be allowed to use it, whether workers should be told, or whether it should form part of a disciplinary record. Product capability is not a governance model.

Australia’s privacy rules leave a hole that bargaining can fill​

Australian private-sector employees have a weaker privacy position than many workers assume. The Office of the Australian Information Commissioner says the Privacy Act does not specifically regulate workplace surveillance. More importantly, personal information held in an employee record and directly related to an existing or former employment relationship can fall within the employee records exemption.
That exemption does not give employers limitless permission to collect anything they want, and it does not necessarily cover every dataset generated by software, particularly where a third-party service provider handles it. But it can substantially narrow Privacy Act protections where data becomes part of employment administration, performance or conduct records. The OAIC has argued that the exemption should be removed, citing the unequal bargaining power between employers and workers and the difficulty of treating consent as freely given in an employment relationship.
State laws create another uneven layer. New South Wales, for example, has a Workplace Surveillance Act with notice requirements for computer, camera and tracking surveillance, while other jurisdictions do not operate under an identical regime. A national bank with staff spread across Australia therefore faces a patchwork of rules, corporate policies and platform settings rather than a single, clear employee-data code.
That is why the CBA negotiation matters beyond CBA. A collective agreement can require transparency and restrict use even where privacy law does not supply a simple individual right to object. It can require consultation before a tool is introduced, define a permitted purpose, prevent covert secondary use, set retention limits, establish human review, and give employees a way to challenge inaccurate conclusions.

The missing controls are the story​

Neither the Financial Review report nor the public CBA materials examined here provides a complete technical account of the bank’s data flows. CBA has not publicly identified which tools feed location, device-presence or Teams-related data into management systems; whether records are joined by employee identifier; who can query them; how long each category is retained; whether a third party processes it; or whether any automated system flags staff for investigation.
Those are not minor implementation questions. They determine whether an organisation has a building-services application and collaboration reporting, or whether it has assembled a continuous employee-monitoring system from otherwise familiar tools.
The FSU’s bargaining agenda points toward a more useful test than asking whether surveillance is “on.” CBA should have to state the specific safety, security or service purpose for each dataset; identify whether participation is optional or required; disclose which managers and systems can access identifiable records; prohibit using weak proxies such as presence indicators as standalone performance evidence; and set a retention schedule that does not leave routine activity data available indefinitely for future disputes.
The bank may have legitimate reasons to know who can access a secure office, whether a workstation is occupied, whether a meeting took place, or whether an employee is working from an approved jurisdiction. But the more data sources are combined, the more the system can reveal about behaviour beyond those original purposes. That combination risk—not one green Teams status or one desk-booking record—is where CBA’s agreement negotiations could set a meaningful boundary.
The first concrete test will be whether CBA accepts enforceable restrictions on surveillance and employee-data use in the agreement now being negotiated. If the final deal contains only general promises of privacy while leaving telemetry, retention and performance use to internal policy, 35,000 employees will have gained little protection from the growing ability of ordinary workplace software to watch them.

References​

  1. Primary source: AFR
    Published: August 6, 2026 at 6:08 AM UTC
  2. Related coverage: learn.microsoft.com
  3. Related coverage: learn.microsoft.com
  4. Related coverage: support.microsoft.com
  5. Related coverage: support.microsoft.com