Note that in this case he lost because his employer had the policy clearly in place. He might have won if they didn't have that.
All my employees are regularly reminded that work equipment is work equipment and that we have access to it and will in certain cases use that access. I'll try not to go through their private stuff, but if there's something I urgently need from their device (or account) and they're not able to provide it (1) I'll have to. If you send private conversation via a company account you know what you sign up for.
(1) for any reason, ranging from extended holidays away from the internet to "this person is no longer among us".
In the restroom case, an owner often can safely assume that the user's activities will be restricted to a quite limited range of behaviors. However, if I had reason to believe that the user might be performing some illicit activity in the restroom (e.g. arson), I might feel surveillance is warranted.
The difference comes down to the disparate levels of suspicion.
I haven't put NEARLY enough effort into securing the accessible services on my LAN against unauthorized access. There's a practical upper limit on how much undetected damage someone could do in my bathroom (without a crowbar or a wrench) that is significantly exceeded by how much undetected damage they could do on my network.
Of course, I'm Canadian and our privacy law is fairly strict. Violations are also a tort, even without proof of damage, so my case may be unique.
But regardless, firm, written guidelines applied equally across the organization are always a good defense.
I don't know UK law but in several eu countries a employer can't monitor their own computers unless they have in writing informed the employees about it.