Private messages at work can be read by EU employers
bbc.com
bbc.com
why are these laws never symmetric?
Why can't employees also access things possessed and used by the employer, like, say, HR personnel files, or executive emails, so that employees can verify the company is not committing fraud, engaging in discriminatory practices, etc.?
There's such an emphasis on what the company has a right to do to protect itself that we almost don't even think about how company actions, which could be damaging to and unapproved by the employee, go on unchecked all the time.
I assume the answer is just "might makes right" and the employer is the one with capital available for legal and political manipulation. But what's so surprising to me is that we rarely even talk about it even in an era with so much overt and publicly hated corporate corruption.
Just one example - giving employees open access to company materials affects the privacy rights of other people, not just the company. So in order to protect the privacy rights you do have vs the company, they will have to restrict other people's access to your information.
The title of this article is misleading in the sense that the decision was that companies may inspect employees' PMs that originate from company computers. They did not make a blanket decision that the company may monitor personal phones or personal computers.
That highlights how the situation is not symmetric in the sense that you haven't loaned your computers to the company in order to produce their personnel files.
But, I see a lot of emphasis being placed on the fact that it was a company-owned machine and that it was ostensibly being used for company purposes. These two facts seem to underpin a lot of what everyone says.
But ownership and mode of use are not the only kinds of resources or properties to think of. For example, at least in the US we have the concept of "company time" which covers the time periods during which you are performing an action sanctioned by a company. Could this be used to demand the ability to monitor employees during time periods when they are on company time?
Likewise, there are a lot of gray areas going in the reverse direction -- from employee to employer. For example, it is true that HR records (say, for example, performance reviews written by my boss about solely me) are electronic files that are the property of the company, just like a computer workstation is property of the company.
But, just as a computer workstation could be misused for personal use, and thus needs to be inspectable for compliance, so also the HR files could be misused for personal use (making jokes, talking about non-professional aspects of me, conspiring to deny a promotion simply due to personal preference, etc.) -- so why aren't such files open for inspection?
Yet another interesting aspect of all of this is why we believe that not only must the workstation be made available for inspection, but further that it is the employer who gets to perform the inspection.
Why isn't such inspection required to be handled by a third-party arbiter, much the way that tax and official records are required to be kept by a certified firm specializing in it. We don't trust companies to say, "Yep, these are my taxes and records, I swear I didn't lie or hide any money." We at least require some third-party to attest to that and stake a reputation on it (subverted though it may be).
Yet with issues of inspection, we just sort of capitulate to this idea that the employer not only gets to raise the issue of suspicion about misuse, but also gets to be the authority on the investigation of whether or not misuse occurred, and to what extent employee privacy must be invaded to get all the relevant info.
Your primary agreement with the company is a trade of your time and skills in return for money, and the symmetric right you have is that you definitely do have the right to monitor and verify that you've been given the proper amount of money.
> HR files could be misused [...] so why aren't such files open for inspection?
In some places, they are open for inspection. There are laws in at least some US states that the company must show you your own personnel file, if you request it.
Not really. The tradeoff is not just for money but for a spectrum of compensation, which could be equity (which could confer voting or board rights to you to monitor certain things about the company financial health), vacation time, conference attendance, foosball table access, etc.
Often these things are negotiable, at least if the employer values talent. So why couldn't we negotiate that part of compensation is some sort of verifiable transparency and mutual respect in terms of monitoring the appropriateness of company activities (whether on behalf of the employer or employee)?
I don't see any fundamental reason why these couldn't be negotiated as part of an employment agreement. Instead, what I see is that most employees either don't know or don't care about these items, and, more importantly, that employers actively collude and engage in e.g. regulatory capture specifically to deny workers the opportunity to be able to negotiate these things.
If you have that, then you have significantly elevated access to the information you were talking about, and you're already landing on the side of protecting the company. The issues you raised don't really apply here.
> [...] vacation time, conference attendance, foosball table access, etc.
If you value those on par with your salary, then I have a job for you! ;)
> I don't see any fundamental reason why these couldn't be negotiated as part of an employment agreement.
You're right, there is no reason. You can and should negotiate these things. Negotiate away!
Just recognize that you may have multiple conflicting interests within yourself. If you want access to confidential company information about others, you're implicitly requesting that they have access to confidential information about you. Most of us wouldn't mind knowing everyone else's salary, and most of us don't want others to know ours. Most of us would love access to the personnel reviews of our co-workers, and most of us would be mortified to let them read ours.
Those things are worth some fraction of salary, at least.
The issue of symmetries of power brings into call the granting and enforcing of rights at a very basic level. If rights are not endowed in a symmetric fashion, shouldn't we step the conversation back and talk about that instead of throwing our collective hands up and agreeing to participate in perpetuating institutionaled inequality?
While I don't agree with these policies on a personal level, I've seen enough to understand it's usefulness in certain environments.
To avoid these kinds of things, always use your own device on your own internet for all things outside of work. Then you only have to worry about the upstream snooping your data.
The only thing I am saying is that this is a two-way street. If employers are allowed to investigate networks because of some socially constructed and arbitrary property (e.g. it is "work-related") then why aren't employees allowed to do the same thing, or to ensure that a certified third-party arbiter can do so on their behalf.
My issue is not that employers can see what employees do on employer-owned property. My issue is that employees should also be able to see what employers do, to verify that they are acting in the best interest of the employee in situations where an employee has a right to expect that. If it is "the company" that owns these things, machines, HR files, etc., then why does only one 'class' of corporate citizen get to have the access (the executive class, generally administered through a layer of HR/legal/compliance officers) while huge other classes of corporate citizens, regular workers, who are just as much "the company" as anyone else is, are never allowed symmetric access to make sure of the issues that could affect them.
Saying that "the company" owns things is not helpful, because if we're all equally "the company" then we all have our professional lives riding on adherence to company policy, verifiably not committing fraud, and so forth. Yet courts consistently side with the ruling classes within a company and clearly support the idea that employees do not get to have such access.
The other point I raised is that, even granting the company has the right to investigate what transpired on its owned equipment, why does that mean that the company itself gets to be the entity that performs the inspection? If we wanted to (a) determine whether or not a worker inappropriately used company property and also (b) protect that workers privacy, at least as far as it is related to the employer, then we should be willing to let a neutral third-party arbiter perform the investigation and agree in advance to be bound by its decision.
I guess what I'm saying is that it's much more complicated than "Company owns the machine. Company can do what they want." No. They can do what we determine it is right for them to do. Maybe that is doing X but not Y if we value protecting Y. We can make these laws or make them part of negotiated employment agreements, but rather than doing so, we allow ourselves to be asymmetrically treated as a lower class within the organization, and we rationalize reasons post facto for why this should be so.
I'm not sure this is a good example. Bear in mind that 'the company' is just other employees. I am not aware of any particular set of 'rights' limiting which employees have access to your information - just policy which is entirely decided by the power hierarchy.
People are commoditized and anything but a race to the bottom with employee wages and rights is an inefficiency.
I hear examples like this a lot but it simply hasn't been my experience, and I haven't always worked in developer-run (or even developer-friendly) industries or companies.
I 100% accept that I might just have been lucky in my previous and current employment, but any time I've had a doctor's appointment or had to run to the vet or anything like that, I've either made the time up that evening or the next day (one time for a long Wednesday AM appointment, over the next two days).
I say this not to discredit the very real fact that employers like this exist, but only to suggest that this is on the same level as poverty wages and forcing someone to buy their own office supplies. If you work in an environment like this, moving on (either simply by employment or geographically) should be among your top priorities.
Because unless you work for some sort of co-op or a very specific subset of unionized labor, employees by definition do not have the right to approve anything
If the company owns the infrastructure, the subscription, the accounts, whatever, they can decide what to do with it.
In contrast, an employer can't, say, search your car without your consent.
But if you deliver for Papa John's, and they think you swiped some stuff, they can't search your cat.
Of course, law enforcement may acquire a search warrant, but that applies to everything, employer and employee.
I think that this discussion is old enough now that it is safe for me to say how much I enjoyed the mental image conjured up by this typo.
(There's some more rules, since this is a case where property rights conflict, so generally they have to notify about the situation upfront.)
There's only so much that can be learned from publicly available statements. So, when somebody might want to point out "Hey look our company has been profitable and growing at 3% for the past XX quarters so why are you not even giving small-fry employees a COLA raise?" it could be a reasonable discussion. I don't see that happening, as you say, based on the "might makes right" platform of ranking.
It's a pretty bad situation for employees in my opinion, and yet I don't think there's any established 'format' or 'platform' where such information is more widely shared or discussed in US workplaces.
That's the very definition of union meetings that happen in preparation to collective bargaining. Commonplace where the workplace is unionized.
They are, in a cooperative company, that is, in a company owned by their workers, it is symmetric and transparent.
In a company that is owned by someone else, obviously this someone else decide what is done in the company.
"Why can't employees also access things possessed and used by the employer, like, say, HR personnel files, or executive emails, so that employees can verify the company is not committing fraud, engaging in discriminatory practices, etc.?"
Some employees have access to such information on any company, but those employees are trusted by the owner.
Employees are not saints. If a design of a prototype is valued in millions of euros and they have access to it, they could have the temptation to sell it to the competition and become rich, or just compete with the original company with the info without having done the investments.
This is valid to anything that could be considered "trade secret" that if competition knows, could simply destroy your company. Information like geomineral prospective studies that took millions of dollars to make in the end is so simple like "here there are so many tons of gold or platinum". With this info in a phrase a competitor could save millions.
You can extract all the info you want about a company if you have access to their private communications.
In general, your workplace can (assuming that you have agreed to this in policy) ensure that you're using your computer for approved uses, and it can access all work-related information on the computer. You do have (limited) privacy over anything personal on the computer, but they're welcome to discipline or fire you just for its existence, and in some cases they may access it if they have reasonable belief that they have to.
This ruling clarifies that if your personal information is mixed in with professional information, the company may access it, as little as necessary (the word you'll come across lots is "proportionate"), as part of an internal investigation or similar. This has been spelled out by at least the British Government for a while now, nothing has changed.
EDIT: On a side note, anyone else notice how the article names the ex-employee and not the employer?
Don't work for a company that monitors it's own IT equipment?
Monitoring the equipment is to ensure it's working properly, as well as to guard against employees misusing company equipment by installing toolbars and apps that have no business purpose (which ultimately leads to mis-performing equipment, and lost productivity).
I don't think I'd want to work for a company like that - the IT equipment would be in shambles, borderline unusable.
It's not your property, don't abuse it. It's really, really simple.
No, it is not. Where is the line between use and abuse?
If I install Notepad++ because it allows me to work faster, am I using or abusing the computer?
What if I install Firefox because some suppliers' site doesn't work in the company-provided IE8 anymore?
What if I install Dell's ActiveX control to download their drivers?
What if I disable the company-installed Flash Player because I feel safer without it?
What if I install NoScript or Flashblock using a company-provided Firefox install?
What if I look up my GP's phone number using a work computer because I need a consult for my back issues? Should I take sick leave just so I can call my GP?
I've worked in IT support, and the general rule among those companies was this: if employees have local administrator rights, they are expected to manage their system themselves. So all of the above would fall under "use" where I've worked. If your employees cannot be trusted to manage their machine, why do they have administrator rights in the first place?
This, and all of your examples, would be considered abuse if your corporate policy stated you were not allowed to install any software without IT's permission. It is that simple, really.
> if employees have local administrator rights, they are expected to manage their system themselves
This sort of thing really only occurs at small businesses with little-to-no internal IT support, or with very special cases (such as a developer, which would have special approvals by the company to do so).
> If your employees cannot be trusted to manage their machine, why do they have administrator rights in the first place
Well, they shouldn't, and they don't at most companies.
In the end, you signed a usage agreement. If you deliberately break that agreement, don't be surprised by the consequences.
Except that two of my examples did not involve installing anything.
Well in that case any sane person would try to avoid working for a company with such draconian and controlling policies.
I should not need to explain that you can monitor installed applications without reading the contents of someone's gmail tab.
You should not be using gmail while being paid to do work on someone's equipment.
A parallel would be if your company used GMail for business purposes. You log into your personal Gmail account instead, and stay logged in. The company needs to gain access to an email from a customer, so they open Gmail on your computer - but discover you are logged into your personal account and can clearly see you have spent your afternoon sending personal emails... not working.
Another parallel would be if you were hired to drive a bus route, but decided to use the company owned bus to go shopping instead. You are misusing company equipment, and if they discover that via a typical investigation (such as checking your bus' GPS location), then they have done nothing wrong.
I don't see how any reasonable person could argue that this man's case was a clear violation of his privacy. This is a typical case of a person misusing equipment/breaking the rules, then getting upset that he was caught.
... in a completely benign way that you might expect of a real human being, not a slave or serf.
No reasonable person can advocate in good faith that employees should actively ignore workplace policies and rules, because they're "real human beings"... and further, that there should be no consequences for these deliberate actions.
Also less effective. Example: Shadow IT exists for a reason, and that reason is not some variation of sticking it to the man.
Don't abuse company owned equipment, and don't use company owned equipment for personal reasons (especially during work hours) is certainly not an "arbitrary, illogical and backwards" policy.
> Also less effective
If you truly believe an IT department ensuring their systems are maintained properly and function as they should is "less effective" than just allowing chaos... I'm not sure what to say really.
> Shadow IT exists for a reason
Have you worked at a company which had different departments all using whatever they wanted? It's a nightmare, and not just from an IT perspective. Nothing is compatible with each other... transferring from one department to another results in a slew of new applications and practices to learn (and which are not necessarily better)... and when IT does need to step in and fix this new system a bunch of non-IT department staff cobbled together... it gets even worse. Soon these departments complain to the IT department when their "shadow IT" system breaks down and demand it be fixed promptly. It's not a net good for any company.
> Nobody follows all the rules all the time, and those that do are generally seen by the rest of society as stodgy and inflexible
Don't be ridiculous. It's not your property - you don't get to do whatever you want with it. It's really, really simple.
It's a bloody computer, not a backhoe. I know precisely nobody who has a computer at work that doesn't at least check their mail on it.
Why companies feel they have to treat their employees as serfs in this matter is beyond my comprehension. Nor do I understand the mindset that treats a mail check as "abuse".
Have you worked at a company which had different departments all using whatever they wanted?
Have you ever worked at a company which had an IT department that was so bureaucratic and slow moving that it prevented people getting actual work done? Your diatribe ignores the reason shadow IT springs up - because the "official" IT isn't doing their job and providing decent services.
I've been on both sides of this. The old quote "the harder you squeeze, the more slip through your fingers" applies. Shadow IT means that things are being provisioned without official approval, not that there's a policy allowing random things to be provisioned without approval.
OTOH there are problems with salespeople communicating with customers on their private emails, like, ugh, the director of the CIA who was recently caught by a teenager.
My point is that they don't have to intend to make monitoring possible for it to be possible; it's practically the default.
Also: pay close attention to what 'Spook23 is saying downthread about discovery. Your employer doesn't even have to want to monitor your stuff; all that needs to happen is they get sued, and if you've been mixing business and personal comms, it can all end up in scope.
Also at a previous employer (multinational, 30+ countries) the CIO took an explicit decision not to employee any kind of technology that could "spy" within SSL traffic to avoid potential liabilities around company IT staff having visibility of personal banking details etc.
Also, just because something is in an employment contract or handbook doesn't mean it's enforceable.
1. Private use is forbidden.
2. Employer can't be held responsible for storing or processing private data if employee didn't follow 1.
Not exactly but quite similar to the ruling described in the original post.
> EDIT: On a side note, anyone else notice how the article names the ex-employee and not the employer?
That's weird. This particular court case is him vs Romania, not him vs his employer. The earlier cases, in Romania, would have been him vs the employer.
There are many reports of this case, and most of them do the same thing:
http://www.bloomberg.com/news/articles/2016-01-12/companies-...
https://www.rt.com/news/328755-echr-employee-messages-snoopi...
http://sputniknews.com/europe/20160113/1033075519/eu-court-p...
> The case dates back to 2007 when Bărbulescu was informed by his employer that his Yahoo Messenger communications had been monitored from 5 to 13 July 2007 and that the records showed he had used the Internet for personal purposes.
> Barbulescu replied in writing that he had only used the service for professional purposes. He was presented with a transcript of his communication including transcripts of messages he had exchanged with his brother and his fiancee relating to personal matters such as his health and sex life.
http://www.express.co.uk/life-style/science-technology/63426...
The suit is in the European Court of Human Rights. He was claiming that Romania violated his right to confidential correspondence by having civil law that allowed his company to read private messages. He lost, therefore Romania's laws are fine, and thus the employer is still in the right.
Eh, yeah, that is weird, now that you mention it. It's like they were interested in protecting the reputation of the company, but they wanted to throw the ex-employee to the wolves.
I don't know UK law but in several eu countries a employer can't monitor their own computers unless they have in writing informed the employees about it.
Of course, I'm Canadian and our privacy law is fairly strict. Violations are also a tort, even without proof of damage, so my case may be unique.
But regardless, firm, written guidelines applied equally across the organization are always a good defense.
Note that in this case he lost because his employer had the policy clearly in place. He might have won if they didn't have that.
All my employees are regularly reminded that work equipment is work equipment and that we have access to it and will in certain cases use that access. I'll try not to go through their private stuff, but if there's something I urgently need from their device (or account) and they're not able to provide it (1) I'll have to. If you send private conversation via a company account you know what you sign up for.
(1) for any reason, ranging from extended holidays away from the internet to "this person is no longer among us".
In the restroom case, an owner often can safely assume that the user's activities will be restricted to a quite limited range of behaviors. However, if I had reason to believe that the user might be performing some illicit activity in the restroom (e.g. arson), I might feel surveillance is warranted.
The difference comes down to the disparate levels of suspicion.
I haven't put NEARLY enough effort into securing the accessible services on my LAN against unauthorized access. There's a practical upper limit on how much undetected damage someone could do in my bathroom (without a crowbar or a wrench) that is significantly exceeded by how much undetected damage they could do on my network.
...and there's the part where I'm not surprised this fellow lost his lawsuit.
Honestly, if I come to a railroad crossing and the gate/arm is down and red lights are blinking, and I go onto the tracks anyway, I think I kind of sort of lose the ability to win a lawsuit against the railroad company for hitting my car.
On the other hand, an employer physically assaulting an employee (with or without warning) wouldn't need to be heard by the ECHR because there is so much law and precedent to say that employers can't do that.
This is a straw man argument, and it's really not worth debating.
But I think his argument would have been stronger if he had raised the issue after his initial warning. Why did they have to invade his privacy twice for it to become an issue for him? The answer: because he was sacked. This seems to change it from a privacy issue to a retaliation.
Not that I'm okay at all with employers being able to violate his privacy, regardless of his motives for claiming his civil rights.
Assault is probably against Romania's laws. As such, any policy or contract specifying assault is illegal.
Invasion of privacy in the workplace is allowed under law; this law was challenged in the ECHR - and the challenged failed, so the law stays. So it is legal to put this in any contracts in EU, since the judgement sets precedence across EU.
Nitpicky, but I believe it says that any European country can have laws which allow this but they are not required to allow it. E.g. the Belgium Gov't might still pass a law which says companies are not allowed to do this.
As an example you could give employees 2 accounts on the company's email servers: John@company.com and John-private@company.com. If now John-private@company.com sent to you-private@company.com "lets grab a beer after work. Also check this link below. I guess it fixes the problem we had all week with our servers", as an employer you would have to warn and ultimately fire him over such transgressions of the rule to split private from work. The problem is that you are not allowed to read his private correspondence (grepping the backup for business problems like "where was that link again?") but you are allowed to do all this with his business mail. Not enforcing a split leads to the company legally loosing all access to all the correspondence.
I've worked with several highly regulated industries, and while data preservation is a big deal, very frequently compliance officers have said "Just don't store personal-type or non-material information like calendar meeting requests for off-site dinners" because they're simply outside the purview of what's needed to satsify the rules.
On the other hand, it was quite clearly stated that if doing filing/archiving one comes across correspondence that reflects an error of judgment (intentional or not), say relating to giving a "personal" gift to somebody above/beyond the accepted corporate policy or legal mandates (ex: local government officials), then by all means, that's in the company's interest to review and address.
There's a perfectly fine reason some sensitive conversations should take place over the phone instead of in writing (most notably "OUR IT SAYS WE'VE HAD A BREACH OMG OMG OMG"), just like there's ample reason talking about something sketchy is frequently performed over the phone. Funny creatures, us humans.
Just curious, are you in the US? My employer's policy is essentially "Your work-provided laptop is for work. However, we recognize that you'll access personal websites and content from time to time. Don't miss deadlines because you're on Facebook or the NY Times all day." However, they explicitly retain their right (but not responsibility!) to monitor, log, and retain all traffic and activity on not only the work machines, but the work wifi (including guest wifi).
I asked about the US because I know privacy protections are much strong in the EU and I had never heard that allowing private messages bars an employer from reading them.
The employer isn't the police.
That's why this is a concerning decision. It indicates this european court believes there is no right to privacy at work.
When you're on the employer's dime, using the employer's equipment, and using the employer's internet connection, you don't get to send personal messages. This guy did, and then found out the consequences. It's pretty simple.
The company used MSN Messenger for business purposes. This guy took it upon himself to setup a separate account from which he privately messaged people during business hours.
This guy would not have been able to send those private messages had the employer not fully paid for all the equipment and necessary components to facilitate messaging for business purposes.
Imagine the parallel. I hire you to telemarket for me (make sales phone calls). I tell you all calls are recorded. Sometime later, I'm digging through the recordings to find a customer's call, and discover you have been making many personal non-business-related phone calls. Instead of using my equipment to conduct business, you have decided to make personal calls to your friends. Of course you would be terminated, and of course I listened to the calls, because I own them.
And of course in several EU countries you'd be staring down a possible severe consequences for breach of privacy. Some countries do not consider employment a right to total ownership of an employee.
Several EU countries recognise that employee has a right to privacy even when working (which includes phone calls and other communication with their families while working and sometimes - like France - even on computer equipment).
This isn't about "owning" an employee, this is about owning the equipment which an employee uses against it's explicit purpose (to conduct business).
I don't think many would have an issue with an employee stepping out for a few minutes to handle a personal call. But many would have an issue with an employee phoning friends and chatting during regular business hours instead of doing their work.
The guy in the original story was chatting with friends while at work over MSN Messenger... instead of working.
> And of course in several EU countries you'd be staring down a possible severe consequences for breach of privacy
That's not true in this case. If you have a policy that prohibits personal use of company equipment, and another policy which states clearly all communications are recorded for business purposes, and it's signed by the employee, then it's really cut and dry.
The court has been clear (in this case, and cases in the past) that employees do have a right to privacy at work, and that an employer cannot just trawl everything all the time, even if there are policies in place.
They didn't make any judgement about his personal account (which also got read) because as I understand it they've already ruled that you can't read personal accounts without very good reason.
That's not true and I guess you haven't really read what the ruling is about. It's about this one exact case where the court ruled that the employer reasonably expected that the account they were looking at wasn't personal.
If the employer would knowingly look into employees personal correspondence the ruling would be different.
Because it believed it was accessing a work account, the judges said, the firm had not erred.
The man, named Bogdan Barbulescu, ...argued that his right to a private life had been breached when his employer had read a log of messages on a Yahoo Messenger account he had set up for work, as well as that from a second personal one.
Mr Barbulescu's employer had banned its staff from sending personal messages at work.
To check his account, the judges said, it had been necessary for his employer to access his records."
It sounds like a stupid policy, but all the company did was access a Yahoo account that he had set up as a work account and saw that he had also been using it for personal communications.
Not that I'm paranoid about my current employer (extremely relaxed culture) but it is something I do out of habit.
I have no idea if my employer knows about this, but I haven't had any remarks about it and I do this for years now. Reading articles on this website and elsewhere (like Slashdot) is a distraction I need on a regular basis. And we don't have a policy like this, so I guess this doesn't apply to me.
The downside being that it's possible someone sees you three times in one day and you happen to be on your phone two or three of those times.
Most likely from his personal YM! account.
The real problem was using YM! for work conversations. But if the company involved did not have its own internal messaging setup... it's an easy mistake to make.
It should be taught in school: Don't use your work accounts for personal stuff, and don't use your personal accounts for work stuff (I'd go even further and say don't have just one personal account for everything).
Likewise they may have certain legal rights if an employee violates their computer-usage policy -- but that shouldn't give them the right to violate the CFAA.
Checking whether an employee "completing their professional tasks" and reading their private correspondence are very different things. How is this any different (aside from prefixing the word computer) then if you had personal letters on your desk and a manager confiscated them from you (and read them) - in order to "confirm" that you were using "completing their professional tasks".
> His employer had discovered that he was using Yahoo Messenger for personal contacts, as well as professional ones.
> Because it believed it was accessing a work account, the judges said, the firm had not erred.
EDIT: Removed unnecessary remark.
Best not to do that stuff at work. You also have to wonder about the internal wifi people put their phones on.
The key issue here is the definition of authorized access. If you create a contract with your employer whereby they give you money and you authorize them to access your digital communications (via an explicit policy) then their access is not unauthorized.
Yes, for example the corporate gmail terms of use explicitly states that your employer has rights to any communications contained therein.
But I would be extremely surprised if someone logging into their personal Gmail account at work would constitutes a 'right' for an employer to access that account (and potentially look through years of personal correspondence) to verify that they were "completing their professional task" - essentially access without authorization (at least in the pre-internet days where these would have been physical letters) would have equated to theft of personal property.
But it wouldn't be. It's their computer. If I use your computer, you have every right to examine every file I created while using it; you have every right to install a keylogger; it's your computer (whether it would be decent to do those things is a different subject).
It's not private correspondence if you conduct it in public; it's not private computing if you do it on someone else's computer. If you want privacy, use your own device.
No doubt they will have an internal CA installed, but if you keep an eye on who authored the certificates on your favorite websites, you can reasonably be assured of some privacy. Additionally install HTTPS everywhere.
Then all you need to be paranoid about is remote monitoring software.
But IN PRACTICE, what is normal?
Your statement seems to indicate that IT staff can just browse personal communications, desktop displays, keypresses. I am sure that they can if necessary, but what kinds of scale and automation are we talking about? Doing such surveillance ad-hoc or without a very small number of targets seems like it would easily become intractable for any org with thousands of people.
I am not in an IT department, so I have no idea what goes on.
It seems the standard advice is always to take the most extreme precautions and to follow the corporate rules to the letter... but here I am typing this into a work computer on a chrome browser without a care in the world.
http://www.huffingtonpost.com/2010/02/26/dan-ackerman-school...
So here is an example of a school administrator spying on students via their provided laptops. It's not the only one. This was 'normal' for the school system until they got called on it.
Blanket collection and searching of data by a company is very possible, in just the same way as you search through mass of logs from applications. They aren't going to have someone watching these logs all the time though, so you don't have to have a huge staff to handle it. They may spot check, they may only go thought the data when something suspicious occurs. They may automatically troll through the data looking for keywords which escalate to a real person for further analysis.
When I go into a company I make sure we put a policy in place that to review an employees emails / web traffic / devices we need to have Legal and HR sign off on it unless the person being investigated is part of one of those groups then it is one group and an executive.
This covers me from legal/HR fallout and it covers the employees because they know we aren't just sneaking around looking at their stuff, it creates trust.
But, in general, never do X advice can be actively harmful because it advises people against doing things that very many do without repercussions and causes people to ignore advice that it's important to follow.
They can read your emails, and chat logs and whatever else is sitting on your work machine. The only way of dealing with that is never have personal information on them in the first place.
Even if your employer is fine with personal use, courts will rule that it's all in scope during a discovery phase. I've been involved in litigation scenarios where people's personal email ended up being sifted through by the other litigant because opposing counsel convinced the judge that business was being conducted there, and there was evidence of frequent access on a corporate device.
All of your protections from a legal point of view are really defined by custody and scope of control. Data stored on your device in your home is the most protected. Data stored on your employer's PC or file server on your employer premises is the least protected.
Is it safe to assume that the only way that that (or any https content) can be captured is by keylogging or some kind of desktop capture?
Any forensic analysis of a PC/Laptop or look at proxy logs will show your connectivity to an personal email account. In a discovery scenario, all that needs to be done is to present a pattern where personal mail was used for business in the company. (I guarantee that is happening somewhere)
It's one of these scenarios where it isn't a problem, until it is
No, plenty of corporate firewalls provide HTTPS MITM by installing their own root certificate and making client machines trust it. HTTPS certificate pinning as it's implemented in most browsers specifically allows this behavior by not checking pinned certificates if the root certificate is in the computer's private keystore (vs. system keystore) because it's assumed the private keystore is full of only certificates the user or machine owner wants to always trust.
I'm a lot more confused about 'Bring Your Own Device' (BYOD) companies. BYOD has proliferated because employees are generally happier to pick their own devices and not have to carry two devices. Employers are happy because it's cheaper, even if there is some stipend involved. It makes IT a bit more complicated but thats about it.
But can they look at my messages then? What if they pay my service bill but I own the device?
Client gets upset about some deal, they sue your employer. They claim you leaked some information to a competitor. Client and employer both want access to your device, to look for evidence of the information leak. You conducted work, on behalf of the employer, on your own personal device. They have to have the legal right to search that device for evidence..
Now.. if you had two devices. One for work, one for personal. You never used your personal device for work.. then to me, personal device is off limits, unless they found compelling evidence ELSEWHERE that you had disclosed information via your personal device. However, that would need to come out and be backed by evidence. They can't just look at your device without being compelled. I am no lawyer though, and my knowledge of civil/criminal evidence handling is shallow..
What if you had just memorized the information – does the company have to have the right to waterboard its employees just because they would like to search for evidence?
And the law, especially in the US, agrees.
What the ruling DOESN'T mean is employers cannot say, demand access to your personal gmail account. However they can reprimand you for visiting gmail.com or whatever for periods of time more than what they deem acceptable.
If you send private messages over your company's Twitter account, you can expect to be fired, too.
Protip: Never, ever, use company resources (laptops and workstations, potentially even cell phones) for your personal communications. They likely are MITM with their own root CA and can see what you're doing.
Reason: It's their device on their network, and it has access to company data. Get a cell phone with a good data plan.
While I understand the employer's desire to ensure employees are working, does this open up personal cell phone conversations to monitoring as well?
I would actually add a bit more as the judges were trying to differentiate between work accounts and personal accounts:
"He argued that his right to a private life had been breached when his employer had read a log of messages on a Yahoo Messenger account he had set up for work, as well as that from a second personal one."
"Despite claims about the second, personal account, the judges only discussed the work account in their ruling."
"The device used to send the messages was owned by the employer, and the judges did not elaborate on whether it would have made any difference if he had used a personal device."
The missing piece of this article is what does the company policy say? In addition, it's clear the judges are saying that if you are using the work (corporate) network, you should not have any expectation of privacy, regardless of who owns the device.
What is unclear thing is who defined/authorized the personal account he created while using the work network? If the company authorized it, then they cannot log it and there is indeed an expectation to privacy. If they didn't, and he is simply personal making accounts using the corporate network, then he would not have an expectation of privacy in my opinion.
I'm also surprised only 1 judge said "One of the eight judges disagreed with the decision, saying that a blanket ban on personal internet use was unacceptable."
There should always be some room for personal use e.g. calling your doctor, kids at school, etc. A blanket ban is not practical at all and can never be fully enforced.
Not quite right - this is one of the grey areas where the law defines something in between "has an expectation of privacy" and "doesn't have an expectation of privacy". Basically, the employer generally can't access personal information on work computers, even connected to work networks, unless they have a reasonable belief that e.g. there's evidence of the employee breaking policy in that personal information.
Even then, they must access as little as possible - for example, if you believe that the employee has personal information on their computer and having personal information is against policy in itself, and that's the only thing you believe, all you can do is ascertain that it actually exists - you can't go digging through people's family photos or private communications unless you reasonably believe that there's further policy violation in there.
The policy the employee accepts, and to be honest not enough employers explain these policies, should be the starting point of determining what is allowed and what isn't to a certain extent.
This is definitely a difficult problem.
While true, we also have a "right to a private life" under Article 8 of the ECHR (where many rights protect you from employers as well as the State, including this one). When your spouse, or your doctor, calls you with an emergency on your company phone because they can't reach you on your mobile for whatever reason, should your employer have the right to know intimate details of your private life or health?
The answer we came to is "no", whereas the US might come to "yes" as its constitution only covers a very narrow definition of privacy which doesn't take into account many modernities.
So widespread, aimless listening on work communications, in the majority of cases, is probably against the law across the EU due to the above argument. Proportionate and limited listening is allowed - for example, if you wanted an alert every time someone accessed Facebook as using it for personal use is against policy, you could do that, but you couldn't go and read all their private chat messages and posts whatever your policy says (unless you have a reasonable belief the account was supposed to be work-specific - for example, you specifically authorized this specific account - and you accidentally stumble across something personal, or that the employee is e.g. sharing trade secrets through Facebook).
I think this is relevant, at my workplace which is in EU, sysadmins are allowed to access anything that is not explicitly marked as personal.
I've always assumed that this is some kind of EU regulation, but I don't know. Does anybody here knows?
For instance, reading news articles on your work computer browser, browsing your personal facebook account, either during a break or for a few minutes a day, will be seen as reasonable. On the other hand, if you spend 6hrs out of 8 doing personal stuffs, the employer can use this against you.
I also assumed this kind of usage would be protected by a court like the European Court of Human Rights, but I was wrong.
Understandably, if you make a send a message/make a personal phone call on company time to your doctor or spouse regarding some issue then that shouldn't be grounds for the company to investigate just because you were on their time and my reasoning for this is that even when you're off the clock, you can still be disciplined for activities that may portray the company in a bad light (getting into a bar fight after work, for example) so its assumed that you're never really off work.
Either way, if I were him I wouldn't have assumed I could have used company hardware to send personal messages yet still have an expectation of privacy.
The headline does make it sound a bit oft when you read the article and not the best choice when you read it is not as clear cut as the headline portrays.
Still never mix business with pleasure being the moral on this one and not a mass panic my private emails can be demanded by HR.
Keep that simple rule in mind and you'll save yourself a lot of heartache.