An organizational network map may reveal that every approval passes through one specialist. Give the same map to that person's manager without context, and it may become an employee scorecard. Ethical organizational network analysis (ONA) begins before the graph: with a purpose, limits on the data, and a decision about who may act on the findings.
Where ONA becomes surveillance
ONA examines relationships defined for a question: who asks whom for help, how groups connect, where knowledge passes through one broker. Surveillance begins when collection exceeds the purpose, employees cannot tell what is measured, or a network result quietly becomes a ranking of people.
A weak tie between two teams, for instance, might reveal a broken handoff. It might equally mean their responsibilities are sensibly separated. A graph does not supply the cause. Our introduction to ONA explains what a network measure can and cannot show.
Our practical rule is to redesign the question and access controls if the only proposed outcome is an individual performance ranking. A separate, openly described assessment process may have its own legal and methodological requirements; it should not be hidden inside an ONA project.
Choose the least intrusive data
Methods capture different ties. A network survey can ask whom employees consult for expertise, but its answer depends on participation and wording. Work-system metadata covers many contacts, yet message frequency does not prove trust, helpfulness, or outcomes. Explicit actions inside a platform preserve the context of a particular event but omit work elsewhere. Our Viva Insights alternatives comparison examines those differences in actual products.
Collect only the fields needed for the approved question. To study handoffs between departments, the direction of a tie, the groups involved, and the observation period may be enough. Message content, personal topics, every message timestamp, or continuous location data do not help answer that question. A smaller dataset can also support a more honest interpretation: it is harder to present every digital interaction as valuable collaboration.
Names may be unnecessary in a management report. Replacing them with codes, though, does not guarantee anonymity: the only bridge in a small team is often obvious. Aggregated views can also expose a person when small groups overlap or periods are compared. A minimum group size is a useful safeguard, not a universal promise. Test reidentification risk against the actual access people will have.
Set rules before collecting data
Explain the purpose in ordinary language
Tell employees which actions or systems feed the analysis, who can see the map, how long records remain, and what decisions may follow. “We want to improve collaboration” is too vague. “We are checking whether support-to-product handoffs depend on one person” gives people something specific to question or correct.
Establish a lawful basis and assess risk
Where GDPR or UK GDPR applies, the organization must identify a lawful basis for its particular processing, respect minimization and transparency, and conduct a data protection impact assessment (DPIA) when processing is likely to be high risk. The UK's ICO advises employers to consider less intrusive methods, document the decision, and involve workers in risk assessment; its published guidance is currently under review. Other jurisdictions may impose different rules; check local law and employee-representative arrangements separately.
Do not replace that assessment with a box labelled “employee consent.” The European Data Protection Board explains that consent is rarely freely given in employment because of the imbalance of power. That does not mean ONA is always prohibited or that one lawful basis fits every study. Purpose, necessity, and proportionality must be assessed for the actual processing proposed.
Limit access and retention
Assign a study owner and access roles before launch. An analyst may need person-level ties to check errors; a manager will often need only group findings with caveats. Set deletion dates for raw events and derived results, and control exports. Ask vendors exactly what reaches their system and who on their side can access it.
Read results without harming employees
High centrality may reflect expertise, overload, or simply a job that requires many contacts. Low visibility may reflect shift work, customer work outside the measured channel, or survey nonresponse. A network metric should therefore not be turned directly into a performance grade, promotion decision, or disciplinary trigger.
Imagine finding that one support specialist is the only link to the product team. A useful response is to ask why there is no second route for complex requests. A harmful response is to label the specialist a bottleneck and demand more messages. Ask the people involved how the work actually moves, then change the process. Our article on key person dependency examines that risk.
Publish the limits alongside the pattern: coverage by team, period, source of each tie, survey response where relevant, and plausible alternative explanations. Give employees a way to correct factual mistakes and challenge an interpretation before leaders act.
A privacy checklist for an ONA pilot
- Write down one organizational question and the action the evidence could support.
- Compare collection methods; choose the least intrusive one that answers the question.
- Document coverage, personal fields, access roles, retention, and deletion.
- Review lawful basis and the need for a DPIA with qualified people in the relevant jurisdiction.
- Explain the purpose and boundaries before collection; offer a route for questions and objections.
- Check whether individuals can be recognized in small groups or by combining data.
- Validate the network explanation with the people doing the work before making a decision.
A limited process and a short observation period are easier to govern. Our 30-day ONA pilot plan shows where to check coverage and keep early signals separate from conclusions.
Frequently asked questions
Is organizational network analysis of employees legal?
It depends on jurisdiction, purpose, sources, and use of results. Under GDPR or UK GDPR, assess the applicable lawful basis, transparency, data minimization, and risk; high-risk processing may require a DPIA. Review the specific project with qualified advisers.
Can ONA be done without reading employee messages?
Yes. Network surveys, interaction metadata, and explicit work actions can map defined ties without reading email or chat content. Each has blind spots and still needs personal-data safeguards.
Is removing names from an ONA graph enough?
No. Team structure, job role, and overlapping groups can identify someone in a small network. Assess reidentification risk and restrict detailed views.
Do employees have to consent to ONA?
Consent should not be assumed to be an appropriate basis in an employment relationship, where it may not be freely given. Determine the basis under applicable law and clearly inform employees in any case.
Examine one work relationship
Discuss a HiveHR pilot with a defined purpose, access rules, and retention period.
Sources
- UK Information Commissioner's Office: data protection and monitoring workers and method-specific considerations.
- European Data Protection Board: Guidelines 05/2020 on consent, including the employment context.
- Microsoft Learn: minimum group-size settings in Viva Insights, an example of a technical safeguard that still requires contextual review.