Someone with twenty years at the same company asks to work from Lisbon for eight weeks. The answer comes back no, with no reason attached, and it lands as a judgment about whether they can be trusted.
It usually isn’t one, though. The refusal is almost always about tax and legal exposure the company doesn’t want to explain, and here is the part nobody tells the person asking: eight weeks is about 15% of a year. The thresholds that create real problems for an employer sit at roughly half a year. A two-month stay is nowhere near any of them.
What can happen at eight weeks is smaller and more mundane. A login from an unfamiliar country trips a security alert. A policy surfaces that nobody had read. A manager says yes and no one checks whether the company agrees. These are the ordinary outcomes, and they’re worth understanding because they are the ones most people will actually run into.
The longer stays are a different conversation, and the second half of this covers them.
Jump to:
What Actually Happens First: The Login
Your employer doesn’t need to buy anything to know what country you signed in from. If your company runs Microsoft 365, as many do, the tools are already there and switched on.
The most basic one is free with every Microsoft account. It flags any login that arrives through a privacy VPN or the Tor browser, and it does so in real time. Nothing has to be purchased or configured. It simply works, on every account, everywhere.
Companies paying for the higher tiers get more. One tool watches for logins from countries you have not used before, keeping a record of where everyone in the organization normally signs in from. Another learns your usual pattern over the first couple of weeks and then flags anything that breaks it, including the network, the location, the device and the browser. A third compares two logins and works out whether you could physically have travelled between them in the time available.
None of this was built to catch employees. It was built to catch stolen passwords, because a login from Lagos twenty minutes after one from Toronto usually means someone’s credentials have been sold. The system cannot tell the difference between that and you, on holiday, checking your email.
So the alert fires. What happens next depends entirely on who reads it and what your company’s policy says, which is the next thing to find out.
What a VPN Does and Doesn’t Do
There are sound reasons to run a VPN that have nothing to do with hiding. Airport and café wifi is genuinely unsafe, plenty of companies require one to reach internal systems, and not wanting your internet provider logging your browsing is a reasonable preference. None of that is in question here.
What a VPN changes is the address your traffic appears to come from. That’s one signal out of several, and it isn’t the one that matters most.
Start with the odd part. Your employer’s own VPN usually makes you look more trustworthy, not less, because company networks are typically added to a list of known-safe locations that reduce security alerts. A commercial privacy VPN does the opposite. As covered earlier, the free tier flags those in real time, so the attempt to obscure an address is itself something the system records.
Then there’s the setting that makes the whole question moot. Companies can restrict logins to specific countries, and they can choose to confirm your country using GPS from the authenticator app on your phone rather than your network address. Where that’s switched on, what your VPN reports is not what’s being checked.
And where an employer has installed monitoring software on the laptop, which is mostly finance, health care and defence work rather than the general case, a VPN is beside the point. The software reads location from Windows or macOS directly. Switching location services off doesn’t help, because it checks periodically and turns them back on, and it hides the icon that would normally tell you location is in use.
None of this touches the tax questions further down. Those turn on where your body is, not where your traffic exits.
The Policy You Probably Haven’t Read
Somewhere in your onboarding paperwork there may be a document that answers most of this. Whether it exists and what’s in it depends on where you work.
In Ontario, Canada, for example, if your employer has 25 or more Ontario employees, it is legally required to have one and to have given you a copy. Under the Employment Standards Act, that policy has to say whether the company monitors employees electronically, and if it does, how, in what circumstances, and what the information gets used for.
It covers people working from home. Employers who don’t monitor still have to have a policy saying that. If you can’t find yours, ask. They’re required to have it and required to give it to you.
In the UK, there’s no equivalent document by name, but the substance is there. Monitoring falls under data protection law rather than employment law, and guidance from the Information Commissioner’s Office requires employers to have a proper reason for monitoring, to tell workers about it in terms they can actually understand, and to assess the risks first where the monitoring is extensive.
It usually lives in an employee privacy notice. You can also request the monitoring data held about you, which is a stronger right than anything an American has.
In most of the United States, nobody has to tell you anything. Federal law requires no disclosure of electronic monitoring at all. Three states are exceptions: Connecticut, Delaware and New York, all of which require written notice, and all of which were written around telephone, email and internet use.
None of them mentions location. California came closest to changing that with a bill covering geolocation directly, but it died in committee in February 2026, and some monitoring companies’ websites still describe it as current law.
The thing to notice is what none of these do. Every one of them requires disclosure, but not one restricts what an employer may monitor or how it uses what it finds. Ontario’s own guidance says so outright.
If You’re Going for Longer Than a Few Months
Past roughly half a year in one country, the math changes and the employer’s caution starts being warranted rather than reflexive.
Three separate things can shift, and they shift at different points.
The first is whether your company becomes taxable where you’re sitting.
The OECD rewrote its guidance on this in November 2025, and the rough shape is that working from a foreign home for less than half your total working time over any twelve months generally doesn’t create a taxable presence for your employer.
Crossing that line doesn’t automatically create one, either. There has to be a business reason for you being in that country, not just your own preference. This is the threshold the whole conversation turns on, and it’s why eight weeks is unremarkable and eight months is not.
The second is social security.
For Americans, your employer keeps paying into US Social Security and Medicare unless the country you’re in has an agreement with the US, and there are about thirty of those.
They cover most of Europe plus Canada, Japan, South Korea, Australia and a handful of others. They do not cover Thailand, Malaysia, Vietnam, Mexico, Colombia, Costa Rica or the Gulf.
Within Europe there’s a parallel arrangement, but it’s built for people who live in one EU country and work for an employer in another, not for someone spending a season somewhere they don’t live.
The third is your own tax residency, which runs on its own clock and is not your employer’s problem.
Many countries treat you as resident after 183 days. Americans owe US tax on worldwide income wherever they are, and some states keep taxing people who left without properly severing ties.
Related:
None of this is something to work out alone. The point of knowing it is to ask a better question, and to recognize that a company saying no to six months may be saying something reasonable.
Freelancers and the Self-Employed
Almost everything above assumes an employer. Working for yourself changes the shape of the problem rather than removing it.
The monitoring question mostly disappears. Your accounts, your laptop, your logins. Nobody is watching where you sign in from because nobody has the access to do so. The exception worth knowing: if a client issues you an account on their system, your logins show up in their records the same way an employee’s would, and if they hand you a company laptop, whatever is installed on it is installed.
Related:
The tax question gets heavier, not lighter. An employee’s foreign presence is a risk their employer manages. A self-employed person is the business, so the exposure is their own. The European social security arrangement that helps employed cross-border workers excludes the self-employed outright.
The real difference is structural. Nobody hands a freelancer a policy, an approved-country list or a refusal. There’s no one to ask and no one to check. The count is theirs to keep.
What to Find Out First
There are five things you can check before any conversation:
Whether your destination has a Social Security agreement with the US. The Social Security Administration publishes the list. If your country is on it, your coverage carries over with a form your employer files. If it isn't, that's worth raising before you go.
If you're in Europe working for an employer in another European country, whether both countries have signed the cross-border telework agreement. Belgium keeps the official list and the dates each country joined. The arrangement is narrower than it sounds, so it's worth checking whether your situation actually fits before assuming it applies.
What the employment contract says about work location. Many say nothing, which is itself the answer to a different question.
Whether a monitoring notice was ever received. In Connecticut, Delaware and New York one should have been, and it will describe what is collected.
Then, from the employer: how many days, in which countries, and who keeps the count. Requested in writing, because a verbal yes from a manager is not a position the company has taken.
The answer that comes back may be a policy, or it may be that nobody has worked it out yet. Both are worth knowing before the flights are booked.
This is reporting, not tax or legal advice. Anything involving a stay of several months or more is worth putting in front of an accountant or employment lawyer who knows both countries.
Sources
OECD, press release on the 2025 Model Tax Convention update, Nov. 19, 2025
OECD, “The 2025 Update to the OECD Model Tax Convention”, Nov. 19, 2025
OECD, summary of key changes (PDF), Nov. 2025
DLA Piper, “OECD’s 2025 Model Tax Convention update”, Nov. 2025
BLG, “Permanent establishment and remote work”, March 2026
KPMG, “Navigating permanent establishment risk in a remote work era”, 2026
IRS, LB&I international practice unit on permanent establishment (PDF)
Treasury technical explanation to the US Model Income Tax Convention (PDF)
Social Security Administration, US international Social Security agreements
PwC Legal Belgium, conditions and signatory states of the framework agreement
Microsoft, “What are risk detections?”, Entra ID Protection documentation, revised April 22, 2026
Morrison Foerster, “New York Enacts Employee Monitoring Notification Law”, Nov. 15, 2021
Baker McKenzie, on New York’s electronic monitoring disclosure law
Information Commissioner’s Office, “Employment practices and data protection: monitoring workers,” Oct. 3, 2023 — ico.org.uk
You might also like:










Great info! Thank you so much.