European court rules companies must tell employees of email checks
reuters.com
reuters.com
In my experience, employee contracts are negotiable in practice. I negotiated limiting or removing 'non-compete' clauses several times in different companies. If email checks were important for me (they're not) I would negotiate this term as well.
The article doesn't give details as to which thresholds the ruling sets, though.
I guess they might be an improvement over Romanian law for example, but below French law (and probably other EU countries as well) where what is sent or received on nominative work email addresses is private communication and can not be monitored.
In order for a company to be allowed to monitor, they would need to pass some kind of audit, they would need to prove that they don’t store, for example, sensitive personal data, etc.
Are you suggesting a framework where I could be prosecuted for running "cat /var/log/mail" on my own computer?
Because your employees are human beings and not machines. They have a life, they have needs, etc.
> Are you suggesting a framework where I could be prosecuted for running "cat /var/log/mail" on my own computer?
Yes. That's exactly it. The court ruled that employees have an expectation of privacy, even that can be limited by the company when there are reasons to do so. When you give an employee a computer, it is the company property but it's the employee's computer.
People have rights, even while working for an employer. They are employees, they are not slaves.
...they also have access to gmail and a thousand other services, no?
> People have rights, even while working for an employer. They are employees, they are not slaves.
being asked to use gmail (etc) instead of company systems for your personal stuff doesn't 'make you a slave'.
It's pretty far fetched to suggest that an employer has a legitimate business purpose in collecting cookies for their employees' personal accounts that they happen to access on their work computer.
However, I think it's pretty easy to make the case that there's a legit business purpose in monitoring employee email (that is, email sent or received through an employer-issued email address), or at least in having access to it.
The reason being that all official bank communications need to be stored and there are strict regulatory requirements that mandate that.
That does not mean that they have the right to read your email (at least in most European countries). Exceptions apply if dodgy dealings are suspected, but that's quite restricted and limited.
In any case and even with a relatively lenient internet policy any service, which can be used to exchange messages will be blocked by a bank.
> Because your employees are human beings and not machines. They have a life, they have needs, etc.
They are free to satisfy those needs when not at work. We already have things like lunch breaks and rest break; surely we could have communications breaks were it that important.
> When you give an employee a computer, it is the company property but it's the employee's computer.
Which is nonsense. I cannot comprehend the sort of mindset which believes that an employee must (not may: must) be permitted to use his employer's equipment for personal ends. Must a machinist be permitted to make gears for his car at the factory? Must a soldier be permitted to take his mortar home? Must a racecar driver be permitted to borrow his car for groceries?
I think it's eminently fine from a business perspective to permit incidental use of equipment (although even incidental use of IT resources does expose the firm to malware vectors it would otherwise not encounter). I can even understand others who choose to take advantage of their employers' personal-use permissions. But I personally would never be comfortable doing anything personal on a system I myself don't control.
Among other things, that's why I don't want a laptop running Windows 10 or macOS.
The corporation has no inherent right to protection. It has no inherent right to exist as a legal entity.
For most of human history they have not been a thing. They were created by society by law as a means to an end, and in doing so we gave corporations a bunch of rights that restrict our rights, by allowing corporations to e.g. continue to hold on to legal rights pasts the death of the person running it for example, and giving them special tax treatment.
As such, these corporations exists at our leisure. It's up to us to set the terms, as If you don't like those terms you're free to not set up a corporation, and instead rely on e.g. doing business as a sole trader and see how much fun that is.
The entitlement when people think that a corporation should be free to treat people however they like is astounding - society made them possible and created them, and we can shut them down if we deem they don't benefit society sufficiently.
So when society says there is an expectation of privacy of communication at work: Tough. It's our right to determine the rules for what a corporation must accept in order to be allowed to exist.
(and yes, we can go to far an mess up our economies in the process, so that we can do it does not mean that we always should do it, but in this case I fully agree with the court)
are corporations the only entities which employ people in europe, besides the governments? can pierre not just rent a building and start employing some people himself? do these rules not effect pierre, in his capacity as an employer?
That is already now illegal in some (most?) European countries. For example, in Finland employer can never read the contents of employee emails, and even reading email metadata such as recipient requires prior notifications both to users and the data protection ombudsman.
Some societies did not let the digitalization to erode the basic rights.
If an employee drove the company car to a hooker, would that be allowed under “privacy?”
A company ought to be able to control the use of their resources. It isn’t like a company email is the only email available to people.
That seems.... insane. (thought about changing that, but really, the above seems so disconnected from reality that perhaps it is an appropriate term)
(at 9AM) "Hey Bob, my email's not going through. Can you check the logs for errors?"
"Sure George, just let me send a notification to all employees and the data protection ombudsman that I'll be accessing the mail logs at 2PM so there's enough time for any objections first."
"....Never mind, I'll just print it out and fax it."
edit: Thinking about it, these days it's just as likely to end up with "I'll share it via cloud storage and just text a link."
more edit: Also, do those restrictions apply to entities subject to audit and investigation? I'm thinking financial industry, etc. where records and audit logs may have to be kept for years but I'm sure there are all sorts of regulated industries I'm not factoring in.
So no, this is not legal from 2018.
I claim that it's a new situation that collecting values submitted through HTML forms is illegal by default.
If that's the case, EU firms are going to get spear phished so much in the coming years! Operating an effective corporate SOC will be... challenging.
I'm not sure if these still exist but Iran (reportedly) had "halal" brothels at one point. They would marry the "couple," do the deed, then divorce. The cookie law was like that.
Legislators started with a real world goal, protecting users privacy from certain violations. They looked through their legal lens to determine the specific rights bein violated.
But, the fix never left the legal realm. The lawyers got to work making sure that users rights are not violated, but without actually giving them any more privacy. Somehow, this absurd interpretation of "informed consent" held water.
Six or seven years ago, South Park made fun of Apple's 47 page terms, updated meticulously. Today, we probably "sign" a thousand pages of pseudo-contracts per week. The cookie law normalized it. Regulators of regulated industries demand more of it.
This is so absurd! The legal profession (including legislators & regulators) just go on with their method of keeping society free of prostitution by making sure everyone gets married and divorced at the correct time.
"as necessary" is the important part. In fact, it is bad for a company to have a clause that says "we own all your email". Such a clause is invalid and it will be invalidated in court. A more reasonable and justified clause in the contract will hold in court.
* https://www.theguardian.com/law/2017/sep/05/romanian-chat-me...
Except in the most comically draconian workplaces does anyone _really_ care if an employee sends an email to his wife using a work email address (eg, "Forgot phone, do you want me to pick up pizza on the way home, honey?").
Aren't these rules just conveniences for HR departments so they can get rid of someone using the nearest available broken-rule that can be documented?
I don't use my work email for personal use, but what kind of company would fire me for "Alright love, you want a pizza when I am on my way back?".
What is next? "Excuse me Sir, Excuse me Sir, Can I go to the toilet please?" Fuck working for a place like that. Leave your dignity at the door.
> what kind of company would fire me for "Alright love, you want a pizza..."
Virtually no company would do it just for that.Many companies use those kind of rules, however, to fire people that are already in their cross-hairs. If a server logs the message, and employee handbooks says, "personal email blah, blah, blah"... it is pretty cut-and-dried from an HR-drone point of view and much easier than firing someone for the things they _really_ did.
Things they allegedly did. Easiest way to avoid paying severance is to have something clearly black and white, otherwise court fees can add up.
But generally, employment in most european countries is not as tenuous as you suggest. You need valid reasons to get rid of someone, and usually you need to give the employee fair warning and a reasonable opportunity to improve or correct the issue that led to the warning. Nobody gets fired for sending a single email even if it's in violation of a clear company policy.
https://arstechnica.com/gadgets/2013/07/no-bathroom-breaks-i...
I'm quite convinced that you cannot sign away your legal rights on an employment contract and even if you were coerced to do so, the contract becomes illegal by definition. I'm not a lawyer though.
Did it? I'm highly skeptical about that. Do you have any source showing that the general population is better informed about cookies after that law?
While it is fair to expect that one "follows the rules", breach should not imply that your private life is something that the employer can do with what they wish, Especially, as the court decision notes, when the risks (e.g. damage and liability) are theoretical.
Occasionally my wife will send me an email to my work address, because she thinks I may see it quicker. Does this use of company resources mean that the contents of the email can be used by the company, or is there an expectation that it is still private?
It seems that the judgement is less about the monitoring and notification thereof, but whether or not you have an expectation for private things to remain private at work.
Or to frame that question another way, if you have an expectation of privacy when you have taken no steps to ensure it and other privacy-protecting options abound. To extend your example, your wife could simply email your work address to say "you've got mail".
I think that any expectation of privacy when using work resources to communicate is unreasonable — IOW, I believe it's illogical to expect that the company will not be aware of the fact that one has communicated.
The question of whether the company may use the contents of such messages for its own purposes is a bit trickier, and I can see arguments in either direction. The best course of action is don't use an employer's resources for private purposes; then one cannot go astray.
And this is STILL the case in many industries - you're not allowed to carry your phone with you on a factory floor, so when something important happens, your personal communication MUST go through company owned equipment. In those cases, ensuring that employers don't needlessly invade employee privacy is rather reasonable.
Remember, most of the world's workers aren't rockstar developers sitting in an office with their phones in the pocket.
I assume this must be depend on the society, as I have a very strong expectation in the contrary. I already mentioned this in another thread; here the employer may never read e-mail contents, and reading metadata requires very specific legal steps to be taken.
I guess the guy just never thought of it as an issue even if he was being monitored until it became an issue. I don't know.
I assume the same applies to at least some of the others.
(This is different from, say, browsing the Internet from a work computer, in which case I don't think the company has any non-security reasons to monitor which pages you visit.)
One exception is can see is answering private emails - if my wife or a friend writes to my work address, I can't see any problem with replying from that same address, and it would feel a little silly to require employees to copy-paste the email to a different account.
I don't know if that was the reason this Romanian employee was fired. And now that I think about it, firing an employee over this offence seems comically draconian to me, which makes me wonder if:
a) the employer wanted to fire the guy for unrelated but hard-to-prove reasons, and the personal emails were a convenient and easily documented excuse
and/or
b) the Court aren't actually worried about the right to personal privacy in your work email account, but they are very worried about potentially handing employers a convenient way to fire an employee at any time for the IT equivalent of jaywalking, even years after the fact
If it's (b) I would consider the Court's decision very wise.
edit: just read the PDF linked below. This part stood out to me:
> On 13 July 2007 Mr Bărbulescu was summoned by his employer to give an explanation. He was informed that his Yahoo Messenger communications had been monitored and that there was evidence that he had used the internet for personal purposes. Mr Bărbulescu replied in writing that he had only used the service for professional purposes. He was then presented with a transcript of 45 pages of his communications from 5 to 12 July 2007 [..] On 1 August 2007 the employer terminated Mr Bărbulescu’s employment contract for breach of the company’s internal regulations that prohibited the use of company resources for personal purposes.
All potential of abuse aside - If I were an employer, and an employee brazenly lied to my face like that, I would consider it a strong reason for firing him even if the matter at hand were wholly trivial.
From the excerpts of the verdict I've read, this is pretty much what they're saying. That is, employers should exercise some discretion when they start reading employee's emails and shouldn't do so on a whim. Seems pretty reasonable to me.
It's a subtle difference, but IMO a relevant one. I think it's closer to writing a letter on the company's stationery, letterhead and all. Particulary since, in my experience, company email accounts normally add a signature with company's contact information and the sender's position in it.
The article suggests more employees are using their work email for personal purposes, and that is really the problem, I think. Particularly because it places your personal data inside your employer's control, and your employer can terminate that account at any time. It would be much more preferred if you connect your personal account to your work devices as well, so that you still have a clearly denoted personal/corporate firewall in your communications, but can still access both from work.
I don't think employers which heavily monitor their employee's corporate email are... good employers, persay, but I'd question any suggestion they shouldn't have the right to.
Then again, I get the impression that I was brought up in a very different way from most people since I regularly have to explain seemingly minor details to coworkers. To explain how these seemingly petty policies are there to avoid problems that may rarely pop-up on small scales, yet are tangible costs/risks when a business has hundreds or thousands of employees.
Yes. I honestly don't see any downside to this. Informing people of things allows them to make better decisions on, say, where to work.
Yes. Legally, in Europe, the expectation is that communication is private, and if you want to listen in, you need to get permission. Owning and operating telecommunication equipment does not give you the right to listen to its users.
On the other hand - just the other day I was looking at "Blind" (because it got advertized on my Instagram feed) that claims to be a "private"-ish social network for employees of a company to share information. Many of the reviews claim there are ulterior motives, etc. but the chief complaint seems to be that it requires verification through work email, and obviously that's begging for your employer to find out about your involvement in these back channels. Online employer verification that doesn't give yourself away, and isn't as easy to spoof as LinkedIn? That seems like a hard problem to solve...
I mean, you're also doing something catastrophically wrong personally if your privacy is dependent on a company wanting to read company-related data on their own infrastructure but thinking, "Oh, no... a European court might frown on this..."
I don't think this reasoning holds up in this case, given that it was a Yahoo! messenger account with private messages to the employee's brother and fiancee that were in question.
That aside, there are different standards in Europe, IIRC, for things like using work email and network resources for personal use. Most employers I'm aware of don't mind occasional personal use, even while at work, within reasonable parameters (e.g. browsing porn at work probably would not fly at most places, possibly even if it's only on the work network after hours). Many of us posting here now are probably posting from work. Another commenter mentioned that his wife occasionally sends him mail at his work email because she thinks it would be faster or something. All of these would probably be broadly acceptable outside of places like finance or defense contracting that heavily monitor and regulate their networks. I don't think such things are generally considered acceptable in Europe. (I am happy to be proven wrong, if anyone has firsthand knowledge, however.)
I expect my work email to be monitored, because that's how US corporations work. I would never use my work email address to sign up for anything personal and important. I've got a device in my pocket that's linked to my personal email if I want to access something like that at work, anyway.
In spite of my expectation that I'll be monitored using work accounts and on the work network, I still believe people should be told so explicitly. Not only should they be told that monitoring will occur, but they should be fully notified of what is and is not acceptable. This just seems basic to me.
Oh, and BTW, and FYI, it's per se.
[1] https://hudoc.echr.coe.int/eng#{%22languageisocode%22:[%22EN...}
[2] Any person shall be enabled: (a) to establish the existence of an automated personal data file, its main purposes, as well as the identity and habitual residence or principal place of business of the controller of the file; (b) to obtain at reasonable intervals and without excessive delay or expense confirmation of whether personal data relating to him are stored in the automated data file as well as communication to him of such data in an intelligible form; ... (d) to have a remedy if a request for confirmation or, as the case may be, communication, rectification or erasure as referred to in paragraphs b and c of this article is not complied with.”
In fact, I keep strictly segregated work and personal email, and I run my own company!
I really don't see how any reasonable person could disagree with that.
> The company had presented him with printouts of his private messages to his brother and fiancée on Yahoo Messenger as evidence of his breach of a company ban on such personal use.
I know the distinction is a fine one, but it is still a difference.
They didn't need to produce a message, just having a non-business contact would have sufficed.
https://hudoc.echr.coe.int/eng-press?i=003-5825428-7419362
And judgement: https://hudoc.echr.coe.int/eng#{"itemid":["001-177082"]}
For me my company email is a company provided resource that they own and it belongs to them entirely. That includes their ability to monitor, read, or do most anything.
No matter what the legal protections it seems like mixing personal life with work resources / tools carries an infinite number of possible issues and complications.
I would have to believe the likes of FB, Aapl, GOOG, MSFT, etc. likely have some process in place to detect exfiltration.
"I can't look in that Inbox, there might be an email from his brother"
Puhleeze
Yes, if Adam had notice he was going to be out there'd be a controlled handoff, but that didn't happen, so you have to just open up his email and move onwards.
1. Get a written consent from your employee; and
2. Get a second pair of eyes to oversee you reading the said employee's email; and
3. Locate the communication that is needed, and leave others be.
I'm not kidding in the slightest. This may be more than people in the US are used to, but I absolutely do expect my employer to follow this or similar procedure if they are to read any of my private communication.
> I absolutely do expect my employer to follow this or similar procedure
The procedure is "don't use my company's computers for personal correspondence"
> The procedure is "don't use my company's computers for personal correspondence"
So just assume they're not, and quit wasting time and energy over nothing.
You yourself just said that everyone should know. Rather than creating needless paperwork for everybody they'd be better served with a public relations campaign by the government to teach people that your work email is owned by your company which means they can read and monitor it.
Snark aside, there's no real downside to mandating something in an employment contract that is probably already in most employment contracts anyways. This catches the stragglers.
Employer could ignore the standard or modify it and the employee could still amend it but it would help small companies get this sort of thing right and help with protecting both parties (which is the point of an employment contract).
I don't think this is a problem that needs solving by the Government, since these contracts are essentially a commodity and have wound up being priced as such.