Standard practice is monitoring emails, chat, web traffic and so on.
It seems blatantly obvious for security and audit reasons a company should log internet usage on their secure network
Overall in practice, there is nothing stopping creepy sysadmin, boundary overstepping lawyer or creepy manager from secretly stalking specific employees by pushing IT departments to install extra monitoring software or just plain spying on specific employees.
That's assuming that the spyware isn't some sort of rootkit that tries to hide its presence. If you're on windows, it's also very easy to hide behind some generic looking executables like svchost.exe
Being at work, on company's hardware, isn't enough to completely void your expectation of privacy.
I've been working in software for almost 20 years and have never had spyware like this installed on my PCs. I've worked for companies with over 70k employees, down to start ups with fewer than 100. Both in office and remote.
I'm not saying it doesn't happen, but it's definitely not normal, and I would personally never work under those conditions.
Also, security tools are getting more sophisticated. As legacy AV gets replaced by next-gen stuff, there will be more creepy shit. If you have a tool like Crowdstrike, most developers will do stuff will get them flagged as high-risk.
It's questionable how much such tools actually improves security, most of it appears to be a power grab by someone in charge of security, usually there's no transparency, and even C*Os aren't aware of how much they are snooped on. For example (as atp does), recording of all commands including arguments, stored in a searchable database. Who does this benefit the most?
I would agree it's often a power play for would be corporate cyber-warriors.
But the tools are very effective for certain threat categories. The downside is that they require skilled operational security people to be used effectively, and may security organizations are mostly compliance focused and don't have the talent or framework to pivot the organization. It's similar to how underperforming IT organizations were/are aligned with the CFO -- many security orgs are aligned with counsel/risk.
They often don't disclose explicitly that this stuff is running, because it rightfully creeps people out and the 'security' types don't want people to know.
There's a lot you can get away with by making a process complex, arduous, and potentially expensive. Faced with that option vs letting some employer take photos of you in your pajamas without shaving while watching your every move, people tend to forego privacy.
When the working population at large starts to follow suit, you've artificially introduced a new trend with artificial social acceptance. Now, it makes a single employee battle concerned about privacy even more daunting and introduces perception of increased risk of failure if legally pursued for the employee thinking of litigating.
The end result is: privacy is eroded. Rinse repeat, for just about anything you want to change. Just make change gradual and give it time. It then takes someone with the financial and time resources to take a hit and pursue as well as eagerness to bother.
https://en.wikipedia.org/wiki/AT%26T_Mobility_LLC_v._Concepc...
Just because I own a microphone and camera doesn't mean I can use it unknowingly in your home. Even if you were to borrow it and willfully bring that camera and microphone into your home, there are reasonable expectations of privacy that can't be violated.
If I explicitly said I'll be using that microphone and camera to record you, made that very clear, and had you sign off on it without duress, then there may be grounds. The problem is, as a condition of employment, at least for me, would be a form of duress. If it becomes widespread and everyone caves into signing off on that sort of recording, then itll start to lose strength as being a form of pressure.
https://docs.microsoft.com/en-us/windows/security/threat-pro...
Like this:
Murder is an example here, but there are similar laws regarding spying on people, using private information in business and reading someone else's mail. Consent does not override the law.
But to get more specific to your point and the grey area: there is a case where the law permits video surveillance (i.e. in an office) and as a side-effect some footage of a display might be captured. If the display happens to show private content, that is not actionable/admissible anymore. Some countries and laws go as far as to make dashcam recordings inadmissible and even illegal. While impractical in some cases (i.e. if your car gets bumped in to by another car while parked) it's also to prevent a government to "get all recordings of all cars in a street to find a person that might have walked by".
Some laws have exemptions like high security areas where the law explicitly states that if you are not allowed to be there expect for specific purposes, and not allowed to conduct anything there except specific tasks, and you are allowed to record the area to be able to verify it (i.e. nuclear energy plant), then that specific area is off-limits to your private activities/data. But it's not broad enough to allow any company to spy on anyone doing work for them. I suppose that might be different in the US or some US-states.
However, many firms provide WiFi APs for visitors and consultants, and employees can use them for their personal devices. So there's no need for anything personal to touch a business device.
Ex: California Social Media Law (2013)
https://readwrite.com/2013/01/15/californias-new-privacy-law...
Also when network connections are recorded it does not stop at a list of ips, surveillance software commonly also provide easy-to-consume search facilities and cross reference capabilities, dashboards including comprehensive history and supplied annotation, i.e can tell when and how often you visited facebook.com, what you looked at, how much time you have spent at non-essential sites, and of course it also does this when you're at home using your employer's laptop for WFH or anything else.
The same is true when using a company phone when travelling, it can not only tell your employer where you're staying currently, but also where you usually stay at your holidays.
One such software is ms atp, if you have "Advanced Threat Protection" installed, it does occur. I would be surprised if it holds up in any EU court, because when I worked with development of similar software, long before gdpr, it did not.
They would install all kinds of stuff to monitor our computers, and continuously require explanation on why we installed this or that tool. It wasn't fun.
Actually, thinking about this now, I don't even remember they existed this type of software in 90s but I might be mistaken.
I am actually still friends with the guy (we were both quite young back then, and you learn from your mistakes), and I tease him about this incident at least every few years.
You also cannot monitor employees using cameras.
In any case, you have to make that absolutely clear to your employees. Any unanounced surveillance is a criminal offence here.
Over workers, pointing at workstations no.
However, MTIM proxies by bluecoat ... Apparently is okay.
Can my boss monitor my work computer?
Permanent and comprehensive PC monitoring at the workplace based on a general suspicion is not permitted. The employer may only monitor the employee on the PC if there is sufficient concrete suspicion of improper use of the work computer.
What applies to private use of the work computer?
If private use of the work computer is expressly permitted to the employee, PC monitoring at the workplace is fundamentally excluded.
What if the boss monitors my PC even though he is not entitled to it?
If the employer does not adhere to the requirements for PC surveillance, he is punishable and in the worst case must be prepared for imprisonment.
Cool. In most places that are not fancy IT companies where everyone is given a brand new MacBook Pro to use as a mixed work/personal machine, there is no such thing as "private use of the work computer". So given what you posted, there is no legal issue then.
> if there is sufficient concrete suspicion of improper use of the work computer
That is when there is no legal issue.
https://www.tyosuojelu.fi/web/en/employment-relationship/rig...
https://www.tyosuojelu.fi/web/en/employment-relationship/rig...
Take a screenshot while the employee is reading his/her personal email and the union takes you to court faster than you can say a cat :)
See the link I have posted in a sibling comment: https://gdpr.report/news/2017/11/17/5383/
>The ECtHR held that the employer had breached B’s right to privacy because they didn’t inform him of the monitoring in advance and nor did they tell him that they may access the content of his communications. The previous courts had also failed to determine the reasons justifying the monitoring and whether these were proportionate to the purpose or whether the employer could have used less intrusive measures to achieve the same result.
If I read this correctly even if the person had been informed of the monitoring the evidence wouldn't have been receivable because the monitoring wasn't deemed "proportionate".
Edit: Apparently there are now at least two examples of this.
In Sweden, relating to facial recognition:
https://www.gamingtechlaw.com/2019/09/fine-gdpr-sweden.html
In Poland, relating to fingerprints:
https://venturebeat.com/2020/03/06/polish-school-hit-with-gd...
I've edited my earlier comments to add some sources, including a reference to the official guidance from the UK's national data protection authority that directly states that just because someone is at work it does not mean they have no expectation of privacy. You can also find lots of public commentary from employment lawyers on the Web where they have interpreted the GDPR similarly, similar statements from other national regulators, etc. Some of these highlight tricky situations like the need to respect personal email as well.
Like, it's pretty explicit. I don't know how different that is from just sending an email saying "hey your screen is being monitored every 30 seconds".
The E-mails were eventually read - but in the presence of the employees in question and their (chosen by them, paid by the company) legal counsel.
I can not imagine an employer going to such lengths to accommodate the employees unless required by law to do so. This was in Norway.
See for instance https://gdpr.report/news/2017/11/17/5383/
> * Employers can monitor employees’ emails at work but need to approach this with caution and careful consideration.
> * Follow the ICO Code and 29 WP opinion, including conducting a DPIA prior to undertaking any monitoring, considering whether it is possible to achieve the objective through less instructive means and ensuring policies clearly notify employees that monitoring takes place, why and that the content of emails may be viewed.
> * If emails are identified as or are clearly “personal” do not open unless there is a real risk of serious harm to the business and, where possible, inform the employee in advance that the content may be viewed.
I find that perfectly reasonable IMO. You're not your company's property. Your boss can't put a camera in the corporate bathroom's stall just because he owns it.
However, I must say that's just weird to me, because you're not required to use company resources for private matters.
The bathroom analogy doesn't really hold in my mind, since it's reasonable to expect privacy in any bathroom, but I see where you're going with that.
I mean sure, if it's the PC controlling some industrial machine you're probably not expected to browse Facebook on it. But if you're some temp working the reception you might have some time to kill even if you do your work properly...
There's also the situation where you're traveling and don't want to carry two laptops from instance.
As a rule of thumb, an employer can take reasonable steps to protect themselves as far as monitoring is concerned, often with the requirement that the subjects of the surveillance have been told in advance that it might happen. But there is always an implied requirement of necessity and proportionality in the background. Monitoring a specific employee where there is evidence to suggest they are leaking trade secrets is one thing. Routine monitoring of everyone's computers where you end up, say, recording the login details they used to access online banking and check whether their expenses have been paid yet is something very different.
Edit: Some easy-to-read sources:
https://www.peoplemanagement.co.uk/experts/legal/gdpr-implic...
https://gdpr.report/news/2017/11/17/5383/
You can also check the guidance from the various national data protection agencies, such as the ICO's publication "The employment practices code", which address this issue in quite a lot of detail.
It's not black and white, and many people will have some expectation of privacy when using company-provided equipment.
US law is irrelevant outside the US
If you can convince the judge that taking the screenshot has other purpose then GDPR doesn't apply.
From (2): The WP29 outlines that a DPIA is likely to be required if «a company systematically monitor(s) its employees’ activities, including the monitoring of the employees’ work station, internet activity» since it implies a «systematic monitoring and data concerning vulnerable data subjects» (23), form GDPR and Personal Data Protection in the Employment Context CLAUDIA OGRISEG
In (1) at point 8: the employeer has to inform the employee about: (i) whether and when monitoring is applied. (ii) the purpose of data processing, (iii) the means used for data processing.
https://legalict.com/factsheets/privacy-monitoring-work-gdpr...
Point 2) What king of personal data does an employer process, includes: Remote management of all mobile devices, such as phones and laptops;