That cannot be true or you could never do proper security or investigations. How would you know if an employee machine was compromised if you absolutely cannot read their internet traffic? Sometimes you actually have to dump traffic an analyze it with wireshark to figure out something is wrong.
That's a grey area, and you should not do that here because judges mostly rule in favor of employees.
Honest question: What about in issues of court cases? As in, if an Austrian employee is comitting an international crime of bribery and is under investigation, does that forbid the courts or employer from ever reading the internet traffic? Granted, I'm setting up a 'higher bar' to clear than an internal, company-exclusive issue, but if we're talking scope and priorties of laws, I'm curious how they might be reconciled in the situation you present.
There's a rather important difference between a random employer and the court system warrants.
The employer isn't the police.
Citation needed. Pretty sure onnoffice equipment you are bound by the rules of the company. it's valid for a company to prevent the personal use of office equipment.
You are correct, employers are allowed to block e.g. Facebook (most have given up on that though). But never read or act upon their email/connection data/... in a semantic way.
I have no english source for this, sorry.
If the employer disallows private communication at work and the employee disregards that rule, the employer does not have to special case private data on the company device. This is the same in Austria as the court case here just found.