Thursday, 23 July 2026 · Europe
EUR/USD 1.139 EUR/GBP 0.8532 EUR/CHF 0.9295 EUR/PLN 4.327 All rates →
Sign in · Join
EUROPES The European Report
European Edition Thursday, 23 July 2026
LATEST
Tech & Startups

TD Bank staff tracking plan highlights EU privacy shield

TD Bank staff tracking plan highlights EU privacy shield

Toronto-Dominion Bank's abandoned plan to harvest employee keystrokes for AI training has exposed a legal vacuum in Canada that European workers are already protected against.

Toronto-Dominion Bank recently told employees in its financial-crimes and risk-management units that it would deploy software called WorkiQ to monitor their activity across web browsers, messaging apps, and meeting platforms. The bank described the deployment as “standard practice across the industry,” stating it uses automated tools to improve insights and allocate resources.

Internal memos reveal a more ambitious, and ultimately shelved, plan. TD had initially intended to capture employees’ mouse movements and keystrokes to serve as training data for artificial intelligence models. The bank scaled back this element only after weeks of internal pushback from staff.

This shift mirrors a recent move by Meta, which deployed a programme to capture keystrokes and mouse clicks on employee machines for AI training. Meta paused that tool in June following a data-security scare. The emerging corporate strategy treats everyday digital work as free raw material to feed algorithmic development.

In Canada, workers have almost no legal leverage to refuse such surveillance. The country's federal privacy law, PIPEDA, does not apply to provincially regulated employers in Ontario, where much of the financial sector operates. Since October 2022, Ontario employers with 25 or more staff must have a written policy on electronic monitoring. However, the law compels disclosure, not restraint. It does not give workers a right to object, limit the monitoring, or keep the data out of performance files.

Without a single statute to define the limits of surveillance, employee protection in Canada relies on a weak patchwork of employment-standards rules, common-law privacy torts, contracts, and collective agreements. For the TD employees on that call, how much of their workday belongs to their employer remains mostly up to the employer.

The contrast with Europe is sharp, and the divergence carries real weight for multinational businesses and investors. Under the EU’s data-protection regime, the kind of monitoring TD proposed runs directly into the principle of purpose limitation. This rule explicitly prevents data gathered for one reason from being quietly repurposed for another.

Harvesting an employee's digital footprint to train AI models is precisely the type of repurposing that European rules are built to block. For European firms, particularly in the banking sector, this creates a higher compliance hurdle. However, it also insulates them from the internal backlash, operational disruptions, and data-security vulnerabilities currently plaguing their North American counterparts.

More from Tech & Startups