So no, this is not legal from 2018.
I claim that it's a new situation that collecting values submitted through HTML forms is illegal by default.
If that's the case, EU firms are going to get spear phished so much in the coming years! Operating an effective corporate SOC will be... challenging.
"as necessary" is the important part. In fact, it is bad for a company to have a clause that says "we own all your email". Such a clause is invalid and it will be invalidated in court. A more reasonable and justified clause in the contract will hold in court.
* https://www.theguardian.com/law/2017/sep/05/romanian-chat-me...
Except in the most comically draconian workplaces does anyone _really_ care if an employee sends an email to his wife using a work email address (eg, "Forgot phone, do you want me to pick up pizza on the way home, honey?").
Aren't these rules just conveniences for HR departments so they can get rid of someone using the nearest available broken-rule that can be documented?
I don't use my work email for personal use, but what kind of company would fire me for "Alright love, you want a pizza when I am on my way back?".
What is next? "Excuse me Sir, Excuse me Sir, Can I go to the toilet please?" Fuck working for a place like that. Leave your dignity at the door.
> what kind of company would fire me for "Alright love, you want a pizza..."
Virtually no company would do it just for that.Many companies use those kind of rules, however, to fire people that are already in their cross-hairs. If a server logs the message, and employee handbooks says, "personal email blah, blah, blah"... it is pretty cut-and-dried from an HR-drone point of view and much easier than firing someone for the things they _really_ did.
But generally, employment in most european countries is not as tenuous as you suggest. You need valid reasons to get rid of someone, and usually you need to give the employee fair warning and a reasonable opportunity to improve or correct the issue that led to the warning. Nobody gets fired for sending a single email even if it's in violation of a clear company policy.
Things they allegedly did. Easiest way to avoid paying severance is to have something clearly black and white, otherwise court fees can add up.
https://arstechnica.com/gadgets/2013/07/no-bathroom-breaks-i...
I'm not sure if these still exist but Iran (reportedly) had "halal" brothels at one point. They would marry the "couple," do the deed, then divorce. The cookie law was like that.
Legislators started with a real world goal, protecting users privacy from certain violations. They looked through their legal lens to determine the specific rights bein violated.
But, the fix never left the legal realm. The lawyers got to work making sure that users rights are not violated, but without actually giving them any more privacy. Somehow, this absurd interpretation of "informed consent" held water.
Six or seven years ago, South Park made fun of Apple's 47 page terms, updated meticulously. Today, we probably "sign" a thousand pages of pseudo-contracts per week. The cookie law normalized it. Regulators of regulated industries demand more of it.
This is so absurd! The legal profession (including legislators & regulators) just go on with their method of keeping society free of prostitution by making sure everyone gets married and divorced at the correct time.
In my experience, employee contracts are negotiable in practice. I negotiated limiting or removing 'non-compete' clauses several times in different companies. If email checks were important for me (they're not) I would negotiate this term as well.
Did it? I'm highly skeptical about that. Do you have any source showing that the general population is better informed about cookies after that law?
I'm quite convinced that you cannot sign away your legal rights on an employment contract and even if you were coerced to do so, the contract becomes illegal by definition. I'm not a lawyer though.
The article doesn't give details as to which thresholds the ruling sets, though.
I guess they might be an improvement over Romanian law for example, but below French law (and probably other EU countries as well) where what is sent or received on nominative work email addresses is private communication and can not be monitored.
In order for a company to be allowed to monitor, they would need to pass some kind of audit, they would need to prove that they don’t store, for example, sensitive personal data, etc.
Are you suggesting a framework where I could be prosecuted for running "cat /var/log/mail" on my own computer?
Because your employees are human beings and not machines. They have a life, they have needs, etc.
> Are you suggesting a framework where I could be prosecuted for running "cat /var/log/mail" on my own computer?
Yes. That's exactly it. The court ruled that employees have an expectation of privacy, even that can be limited by the company when there are reasons to do so. When you give an employee a computer, it is the company property but it's the employee's computer.
People have rights, even while working for an employer. They are employees, they are not slaves.
> Because your employees are human beings and not machines. They have a life, they have needs, etc.
They are free to satisfy those needs when not at work. We already have things like lunch breaks and rest break; surely we could have communications breaks were it that important.
> When you give an employee a computer, it is the company property but it's the employee's computer.
Which is nonsense. I cannot comprehend the sort of mindset which believes that an employee must (not may: must) be permitted to use his employer's equipment for personal ends. Must a machinist be permitted to make gears for his car at the factory? Must a soldier be permitted to take his mortar home? Must a racecar driver be permitted to borrow his car for groceries?
I think it's eminently fine from a business perspective to permit incidental use of equipment (although even incidental use of IT resources does expose the firm to malware vectors it would otherwise not encounter). I can even understand others who choose to take advantage of their employers' personal-use permissions. But I personally would never be comfortable doing anything personal on a system I myself don't control.
Among other things, that's why I don't want a laptop running Windows 10 or macOS.
The corporation has no inherent right to protection. It has no inherent right to exist as a legal entity.
For most of human history they have not been a thing. They were created by society by law as a means to an end, and in doing so we gave corporations a bunch of rights that restrict our rights, by allowing corporations to e.g. continue to hold on to legal rights pasts the death of the person running it for example, and giving them special tax treatment.
As such, these corporations exists at our leisure. It's up to us to set the terms, as If you don't like those terms you're free to not set up a corporation, and instead rely on e.g. doing business as a sole trader and see how much fun that is.
The entitlement when people think that a corporation should be free to treat people however they like is astounding - society made them possible and created them, and we can shut them down if we deem they don't benefit society sufficiently.
So when society says there is an expectation of privacy of communication at work: Tough. It's our right to determine the rules for what a corporation must accept in order to be allowed to exist.
(and yes, we can go to far an mess up our economies in the process, so that we can do it does not mean that we always should do it, but in this case I fully agree with the court)
are corporations the only entities which employ people in europe, besides the governments? can pierre not just rent a building and start employing some people himself? do these rules not effect pierre, in his capacity as an employer?
...they also have access to gmail and a thousand other services, no?
> People have rights, even while working for an employer. They are employees, they are not slaves.
being asked to use gmail (etc) instead of company systems for your personal stuff doesn't 'make you a slave'.
It's pretty far fetched to suggest that an employer has a legitimate business purpose in collecting cookies for their employees' personal accounts that they happen to access on their work computer.
However, I think it's pretty easy to make the case that there's a legit business purpose in monitoring employee email (that is, email sent or received through an employer-issued email address), or at least in having access to it.
The reason being that all official bank communications need to be stored and there are strict regulatory requirements that mandate that.
That does not mean that they have the right to read your email (at least in most European countries). Exceptions apply if dodgy dealings are suspected, but that's quite restricted and limited.
In any case and even with a relatively lenient internet policy any service, which can be used to exchange messages will be blocked by a bank.
That is already now illegal in some (most?) European countries. For example, in Finland employer can never read the contents of employee emails, and even reading email metadata such as recipient requires prior notifications both to users and the data protection ombudsman.
Some societies did not let the digitalization to erode the basic rights.
That seems.... insane. (thought about changing that, but really, the above seems so disconnected from reality that perhaps it is an appropriate term)
(at 9AM) "Hey Bob, my email's not going through. Can you check the logs for errors?"
"Sure George, just let me send a notification to all employees and the data protection ombudsman that I'll be accessing the mail logs at 2PM so there's enough time for any objections first."
"....Never mind, I'll just print it out and fax it."
edit: Thinking about it, these days it's just as likely to end up with "I'll share it via cloud storage and just text a link."
more edit: Also, do those restrictions apply to entities subject to audit and investigation? I'm thinking financial industry, etc. where records and audit logs may have to be kept for years but I'm sure there are all sorts of regulated industries I'm not factoring in.
If an employee drove the company car to a hooker, would that be allowed under “privacy?”
A company ought to be able to control the use of their resources. It isn’t like a company email is the only email available to people.