While I understand the employer's desire to ensure employees are working, does this open up personal cell phone conversations to monitoring as well?
While I understand the employer's desire to ensure employees are working, does this open up personal cell phone conversations to monitoring as well?
I think this is relevant, at my workplace which is in EU, sysadmins are allowed to access anything that is not explicitly marked as personal.
I've always assumed that this is some kind of EU regulation, but I don't know. Does anybody here knows?
For instance, reading news articles on your work computer browser, browsing your personal facebook account, either during a break or for a few minutes a day, will be seen as reasonable. On the other hand, if you spend 6hrs out of 8 doing personal stuffs, the employer can use this against you.
I also assumed this kind of usage would be protected by a court like the European Court of Human Rights, but I was wrong.
I would actually add a bit more as the judges were trying to differentiate between work accounts and personal accounts:
"He argued that his right to a private life had been breached when his employer had read a log of messages on a Yahoo Messenger account he had set up for work, as well as that from a second personal one."
"Despite claims about the second, personal account, the judges only discussed the work account in their ruling."
"The device used to send the messages was owned by the employer, and the judges did not elaborate on whether it would have made any difference if he had used a personal device."
The missing piece of this article is what does the company policy say? In addition, it's clear the judges are saying that if you are using the work (corporate) network, you should not have any expectation of privacy, regardless of who owns the device.
What is unclear thing is who defined/authorized the personal account he created while using the work network? If the company authorized it, then they cannot log it and there is indeed an expectation to privacy. If they didn't, and he is simply personal making accounts using the corporate network, then he would not have an expectation of privacy in my opinion.
I'm also surprised only 1 judge said "One of the eight judges disagreed with the decision, saying that a blanket ban on personal internet use was unacceptable."
There should always be some room for personal use e.g. calling your doctor, kids at school, etc. A blanket ban is not practical at all and can never be fully enforced.
Not quite right - this is one of the grey areas where the law defines something in between "has an expectation of privacy" and "doesn't have an expectation of privacy". Basically, the employer generally can't access personal information on work computers, even connected to work networks, unless they have a reasonable belief that e.g. there's evidence of the employee breaking policy in that personal information.
Even then, they must access as little as possible - for example, if you believe that the employee has personal information on their computer and having personal information is against policy in itself, and that's the only thing you believe, all you can do is ascertain that it actually exists - you can't go digging through people's family photos or private communications unless you reasonably believe that there's further policy violation in there.
The policy the employee accepts, and to be honest not enough employers explain these policies, should be the starting point of determining what is allowed and what isn't to a certain extent.
This is definitely a difficult problem.
While true, we also have a "right to a private life" under Article 8 of the ECHR (where many rights protect you from employers as well as the State, including this one). When your spouse, or your doctor, calls you with an emergency on your company phone because they can't reach you on your mobile for whatever reason, should your employer have the right to know intimate details of your private life or health?
The answer we came to is "no", whereas the US might come to "yes" as its constitution only covers a very narrow definition of privacy which doesn't take into account many modernities.
So widespread, aimless listening on work communications, in the majority of cases, is probably against the law across the EU due to the above argument. Proportionate and limited listening is allowed - for example, if you wanted an alert every time someone accessed Facebook as using it for personal use is against policy, you could do that, but you couldn't go and read all their private chat messages and posts whatever your policy says (unless you have a reasonable belief the account was supposed to be work-specific - for example, you specifically authorized this specific account - and you accidentally stumble across something personal, or that the employee is e.g. sharing trade secrets through Facebook).