Skip to content
What They Can and Cannot Do

Home / Above it

Lawful Is Not the Same as Defensible

Two tests with different examiners, different timescales and different consequences. Passing the first says nothing about the second.

Above it · Analysis

Legal and defensible are separate standards, examined by different people, at different times, with different consequences for getting them wrong.

The legal boundary discussed in “Lawful Is Not the Same as Defensible” should also shape the configuration of workforce technology. When a team evaluates how to monitor employees without being intrusive for how to monitor employees without being intrusive, it should record the purpose, lawful basis, notice, access and retention settings before collection begins, then keep a correction route open for misleading records.

For an independent benchmark relevant to “Lawful Is Not the Same as Defensible”, consult the NCSC insider-data guidance. Use it to test necessity, scope, safeguards and review rather than to replace a documented assessment of the particular workforce and jurisdiction.

The two examiners

Lawful is assessed by a regulator or a tribunal, after something has gone wrong, against rules written in advance. The consequence is a penalty or an order.

Defensible is assessed continuously by the people subject to it, by colleagues, by candidates, and occasionally by a journalist. The consequence is slower and harder to reverse: people leave, stop reporting things, or stop applying.

The first is episodic and survivable. The second is continuous and compounds.

NoteDefensible here means: explicable to the people affected, to colleagues, and in public, without the explanation making things worse.

Where they come apart

Lawful and not defensible: an arrangement with a proper basis, a documented assessment and a published notice, which nonetheless records far more than the purpose needs because the product offered it and nobody said no.

Defensible and not lawful: rarer, and it happens — an employer doing something sensible and humane that a specific rule prohibits.

The first is the common case and it is the one this collection is about.

The counterIt is objected that this is just reputation management dressed as ethics. Partly fair — but a standard you would be ashamed to state publicly is usually a standard worth revisiting for reasons beyond reputation.

The test that separates them

Not "would a regulator accept this" but "could I explain this to the person it applies to, in plain words, without the explanation making it worse".

That test is harder, faster to apply, and catches most of what compliance misses.

An arrangement that requires euphemism to describe — productivity insights, workplace analytics, engagement signals — has usually failed it already, and the euphemism is the evidence.

Where this failsSome defensible things are unpopular. Public acceptability is a useful test and a poor master, and safety measures that people dislike are the clearest example.

Why the gap persists

Because nobody owns it. Legal owns lawful. Nobody owns defensible, so it is assessed by whoever happens to care, with no standing and no process.

Naming an owner is most of the fix: somebody whose job is to ask the second question before the first one is answered.

In practiceOrganisations that try this report the main obstacle is not disagreement but that nobody owns the question, so it is nobody's to raise.

What this does not mean

That every unpopular measure is indefensible. Safety requirements, regulated recording, investigations with a proper basis are frequently disliked and entirely defensible.

The distinction is whether the measure can be explained in terms of what it protects, to the people it constrains. Where it can, unpopularity is tolerable. Where the only available explanation is that the law permits it, something has gone wrong upstream.

The counterA reasonable objection is that this asks employers to do unfunded work. The reply is that the work is a page and the alternative is doing it later under challenge.

The euphemism test

An arrangement that requires a special vocabulary to describe has usually failed the defensibility question before anybody applies it. The vocabulary exists because the plain description was unsatisfactory to somebody, and that dissatisfaction is the finding.

JurisdictionLocal rules differ on every point in this note. The shapes described recur; the specifics always require checking.

Who owns defensibility

Nobody, in most organisations. Legal owns lawful; defensible is assessed by whoever happens to care, with no standing and no process. Naming an owner is most of the fix, and it costs a line in somebody's objectives.

The test that separates the two

Not would a regulator accept this, but could I explain it to the person it applies to, in plain words, without the explanation making it worse. Harder, faster, and it catches most of what compliance misses.

Unpopular against indefensible

Safety requirements and regulated recording are frequently disliked and entirely defensible. The distinction is whether the measure can be explained in terms of what it protects. Where the only available explanation is that the law permits it, something has gone wrong upstream.

Naming an owner

Legal owns lawful. Unless somebody is named, defensible is assessed by whoever happens to care, with no standing and no process — which is why it loses every time.