How to Measure Return-to-Office Compliance Without Spying on Employees
Return-to-office mandates are back on the agenda in 2026, and this round is more aggressive than the last. California ordered state workers into the office four days a week starting July 1, 2026. Amazon has been running a five-day RTO policy since January 2025. Both moves have been met with real pushback from employees and unions, and a good chunk of that pushback isn’t about the policy itself. It’s about how attendance will be measured and enforced. If your organization is rolling out or tightening an RTO mandate, the tracking approach you choose will shape how much trust you burn along the way.

Quick verdict
Most RTO compliance problems don’t require individual-level tracking to solve. If HR needs to know whether someone hit their required in-office days, a simple badge-in day count answers that question with minimal privacy exposure. If facilities needs to know whether a floor is over- or under-utilized, anonymized aggregate occupancy sensors answer that question better than any individual tracking system, and without the legal exposure. The mistake to avoid is deploying identity-linked tracking (badge trails, WiFi/BLE location, camera recognition) to answer a space-planning question it was never designed to answer cleanly, and that most employees will experience as surveillance.
Two different questions, two different tools
A lot of RTO tracking projects go sideways because they quietly merge two separate business questions into one system.
Question one: did people show up?
This is a policy compliance question. It lives with HR and people managers. The answer they need is binary and low-resolution: did this employee badge in on at least three (or four, or five) days this week? That’s it. No location detail, no dwell time, no desk-level history required. A basic badge or building access day count satisfies this need completely.
Question two: how is our space actually being used?
This is a facilities and real estate question. It doesn’t care who was in the building, it cares how many people were on Floor 3 between 10am and 2pm on a Tuesday, and whether that number justifies the square footage being paid for. Answering this well actually requires less individual detail than question one, not more. Aggregate counts are the right unit of analysis, not identity.
Treating these as the same problem, and reaching for the same individual-level dataset to answer both, is the recurring error behind a lot of the trust damage showing up in 2026’s RTO rollouts. It’s also unnecessary: you get a better answer to the space question by deliberately not tracking identity.
Why over-collecting individual data backfires
It’s tempting to think more granular data is always better data. In RTO tracking, it usually isn’t, for three reasons.
It creates legal exposure you don’t need. Badge, WiFi, and BLE location data that can be tied to a specific person is personal data under GDPR, and processing it for monitoring purposes triggers real obligations: a documented legal basis, proportionality analysis, and in many EU workplaces, consultation with works councils before you even switch it on. [VERIFY: specific GDPR enforcement actions or fines against employers for RTO-related location tracking in 2025 to 2026]
It doesn’t actually improve the space-planning answer. Identity-linked data has to be aggregated back down before it’s useful for capacity planning anyway. You’ve taken on the compliance risk of collecting sensitive personal data just to throw away the identity layer at the analysis stage. Anonymized, aggregate-only sensors give you the same planning output without the exposure.
It erodes trust faster than the policy itself. Employees and unions pushing back on 2026 mandates are frequently reacting less to “come in four days” and more to “and we’ll know exactly when, where, and for how long.” Camera-based systems draw the most concern of all, even when vendors process footage on-device and never store raw video, because the perception of being watched matters as much as the technical safeguards. If your tracking method looks and feels like surveillance, that’s the story employees will tell, regardless of what the privacy policy says.
Comparing tracking methods
Before choosing a method, it helps to see how the common options actually differ once you separate accuracy from privacy exposure and legal risk.
| Method | Accuracy | Privacy risk | Legal / trust exposure |
|---|---|---|---|
| Badge swipe day counts | Good for “did they show up” questions; not useful for desk- or zone-level detail | Moderate: tied to identity, but limited to entry events | Manageable if scoped narrowly to policy compliance and communicated clearly |
| WiFi / BLE location tracking | High spatial resolution, but signal noise and device variance limit precision | High: continuous identity-linked location data | High: strongest GDPR and works council concerns, easily perceived as surveillance |
| Camera + AI | Highest potential accuracy, including occupancy and flow patterns | High: even with on-device processing, employees react to cameras specifically | High: draws the most scrutiny and pushback of any method, hardest to communicate as “not monitoring you” |
| Anonymized occupancy sensors (ToF, PIR) | Good for aggregate counts and utilization trends; no individual identification | Low: presence-only, no images, no identity | Low: straightforward to justify as facilities data, not personnel monitoring |
A practical, defensible approach
Given the tradeoffs above, most IT and facilities teams land on a two-track setup rather than one system trying to do both jobs.
For policy compliance, use badge-in or building access day counts, already collected by most access control systems, and report them at the level HR actually needs: days per week, not minute-by-minute location. Platforms like Envoy’s occupancy dashboard are built around this distinction: they give workplace leaders aggregate attendance trend data, when and how employees are checking in onsite, for space and resource planning, rather than positioning the data as an individual disciplinary tool. That framing matters both legally and culturally.
For space utilization, deploy anonymized, aggregate-only occupancy sensors, ToF or PIR technology rather than camera or location-based systems, and report at the zone or floor level. This is the dataset facilities actually needs to right-size real estate, and it’s the dataset with the least legal and trust baggage attached.
For both tracks, communicate clearly with employees before deployment: what’s being collected, why, who sees it, and what it is not used for. Vague or absent communication is often what turns a reasonable RTO measurement approach into the kind of story that fuels union pushback, even when the underlying system is genuinely low-risk.
Who this is for
This framework is aimed at IT managers, facilities leads, and HR-adjacent stakeholders who are being asked to “figure out how we’ll track RTO compliance” without a clear brief on what problem is actually being solved. If that’s you, start by asking which of the two questions above you’re actually being asked to answer, then pick the tool that matches, before defaulting to whatever tracking system feels the most comprehensive.
If you’re building out the sensor side of this, our occupancy sensor comparison covers the current ToF and PIR options for aggregate space data. For teams navigating density changes alongside RTO, our open plan density and privacy guide goes deeper on balancing utilization data with employee comfort. And if hybrid schedules mean desks aren’t assigned one-to-one, our hot desking policy template is a useful starting point for pairing attendance policy with space allocation.