Google allows G Suite administrators to monitor and audit user emails
goldyarora.com
goldyarora.com
Here's a guide for UK employers:
https://uk.practicallaw.thomsonreuters.com/2-107-4386?transi...
The company cannot access those messages without your consent or without a suspicion of a crime (like a leak of data).
[1] https://en.wikipedia.org/wiki/Secrecy_of_correspondence
Source in French with some court's judgement : https://www.arobase.org/entreprise/email-personnel.htm
1. Finance
2. Medicine
3. Aeronautics
There are likely more I'm personally unaware of. In finance, which I'm most familiar with, lenders (sometimes banks, but can be things like credit unions, marketplace lenders, or investors) have a laundry list of regulations they need to meet in order to business in the US. Many of these regulations explicitly require that the lender produce any and all communications between the lender and borrower on-demand--and for good reason.
There's a long history of bad actors in finance lying or misrepresenting things in official communications (fraud, embezzlement, money laundering, etc). If you work for any finance company, you had better expect that everything you do on your corp accounts/devices will be logged, audited, and periodically reviewed.
That said, the only time I've heard of an employees' email being pulled out of an archive and read were due to concerns around IP theft or questionable behavior between said employee and business clients.
This is why traders WFH during coronavirus lockdowns is so problematic; not only a lack of externally accessible recorded phone lines but the impossibility of policing OOB communications when the local compliance guy can’t physically see you talking on your mobile phone.
What really concerns me is that these phishing attempts are just the attacks we're observing. Many more will go unnoticed given how ad-hoc current work environments have become with so many organizations going full-time remote overnight without the IT/security systems and processes in place to safely support it.
Not if phones are checked in at the security desk when you arrive, there is a phone jammer operating in the building, and compliance staff are patrolling to make sure no one has smuggled a phone in. These measures are normal on most trading floors.
Because I work in aeronautics, and we've never had such requirement. Unless my company retains all deleted emails without telling us.
Where "likely" means "I'm not a lawyer so I'm just guessing here" and "most" means "I read on HN that Europe likes privacy."
There are some exceptions of course: if you notify the employee and have a justified reason you can check some emails. So it's not outright forbidden. It matters a lot on the case and what you did, exactly.
I'm not aware of the situation in other countries.
(In Dutch: https://www.cnvvakmensen.nl/nextnow/blog/2016/march/mag-de-b... and https://www.sprengersadvocaten.nl/publicaties/wanneer-mag-ee...)
This is not the current state of the law in the US however.
https://www.justia.com/50-state-surveys/recording-phone-call...
Also, depends on to what extent that room can be considered public. (IANAL TINLA)
It's not always an option, even if they can't read your email casually, your company may still have perfectly legitimate reasons to keep it under their control for reasons of auditing etc.
Even if you do have a good reason, perhaps they're ill, you're not allowed to open them if it's obviously not from a business contact or it's obviously a private email. So reading an email from an employee's spouse or girlfriend would be illegal.
Please don't be a jerk in HN comments, no matter how ignorant someone else is or you feel they are.
If that happens enough, the best users—who don't want to read snark, aggression, petty spats, etc.—will leave, ceding the field to the commenters who do, eventually driving everyone else away and leaving a scorched-earth wasteland [2]. The classic death spiral of an internet forum.
HN started [3] with the idea of trying to avoid that outcome [4], or at least stave it off [5]. Think of it like a complex but fragile ecosystem that needs protecting. Since we all benefit from the ecosystem, we're all responsible for protecting it, much as you wouldn't leave a campfire burning in a dry forest, drive a 4x4 across a mountain meadow, litter in a city park, and so on.
The bonds that hold HN together are weak, because we only have access to tiny blobs of text that are open to misunderstanding. Users don't have relationships that can sustain disruption and still be repaired; the group is too large. Since the organism can't easily repair itself, it needs not to take too many hits in the first place.
Most of the damage is thoughtless rather than malicious. The solution is to become more conscious about the goal of the site and how to further it. This isn't really an ethical question. We're not telling people that they should be good (maybe they should, but who is an internet moderator to tell anyone that?) Rather, it's an optimization problem. We're trying to optimize the site for curiosity [6]. That requires overcoming the default tendencies of the internet, and for that we need to sustain a certain culture.
[0] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
[0.5] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
[1] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
[3] https://news.ycombinator.com/hackernews.html
[4] https://news.ycombinator.com/newswelcome.html
[5] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
[6] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Even editing is allowed (automatic disclaimers, file scanning, data loss prevention, etc).
I'm not at all sure that I've heard of many places where your employer explicitly ISN'T allowed to access employer provided resources.
If that were the case generally I'm not sure how anyone would even provide security or etc.
I can't imagine how hard it would be to run a business in a jurisdiction where that would be the case. How would you handle audits, employee turnover, records retention, civil suits, etc?
Courts (at least in the US) have repeatedly ruled that employees have no reasonable expectation of privacy when using company email systems.
This depends on the country.
Absolutely not in France (and probably most of EU), if by business you mean "within a company" (which would be aligned with the idea of looking at correspondance")
Even if I couldn't read the email (which I can, but fortunately have never actually had the need to or done so), I can always reset a password and gain full and instant access.
You should always assume your employer can see your enterprise correspondence. G Suite or not.
AFAIK, resetting an individual GSuite account's password is the only way GSuite Admin can access individual account's emails. Is there any other way to get access?
For GSuite basic subscriptions, there is a 30GB quota per inbox, having BCCs for every account's emails will like exceed the plan allowance. I doubt it would work if you exceed the account quota allowed for the subscription plan.
Also consider that the first amendment isn't absolute and there is certain material that is highly unsavory, eg child pornography, that party B doesn't even want the potential of possessing.
There are certainly nefarious usages for that level of access as well, but I can imagine legitimate usage exists as well.
Some companies build it into their systems to automatically catch and mask that data, sometimes someone has to rollup their sleeves and do it manually.
I'd wager that 95%+ of orgs have tons of sensitive customer data scattered into chat messages in Slack, Teams, Hangouts, etc that would horrify most of us here.
Check out this: - https://cloud.google.com/dlp - https://www.youtube.com/watch?v=MY3PjFpI3rE
My least enjoyable job would be going into the admin to recover emails "deleted" by disgruntled employees who got wind that they were about to be let go. Why they tried to delete their emails - I'll never know. They should've realised that Google hates deleting anything from their clouds.
One of my happiest days at that job was the day I got told I didn't have to be a GSuite admin anymore and could go do some proper coding work instead.
Once our service account has been granted access, we can assume the role of any user and access anything we have permission for. So, you should assume your IT administrator can also access all your emails, since they're likely to be the person that grants permission to the service account.
[0]https://developers.google.com/gmail/api/v1/reference/users/m...
Edit: an administrator can also create an API token with org-wide credentials, allowing her to read, write, and delete messages from any user's inbox.
I had an employer who insisted that after I leave, every email I receive to my corporate address be forwarded to him. I remember asking a lawyer how legal this is and not receiving a conclusive answer. (Still interested in an answer for CA+NY if someone knows)
Yes, it is totally legal for them to do that, there is no question, and it wouldn't make sense for it to be any other way.
I'm sure jurisdictions vary, but in Norway, excepting any written concent, your employer may not read mail addressed to you by name.
Personally addressed work email likely (but not certainly) fall in a similar category.
Like, who would use their work mailing address with a medical clinic? The only physical mail I've ever had sent to my workplace is maybe the occasional December parcel that I need to conceal from its ultimate recipient. We're long past the days where anyone's work email address is their only (or even primary) email address.
- A politician with a state-provided residence in the capital city.
- A soldier living in a barracks
- A teacher living at a boarding school during the term, or someone very senior at a university with an on-campus house/apartment. Or a PhD student.
- A vicar or priest living at the vicarage
- A diplomat or embassy staff posted abroad
Certainly for myself many years ago as a university student, I acknowledged that my lodgings were temporary and had anything of any importance at all sent to my parents' address.
You'd be surprised. For those of us here on HN, your statement has been true for decades (for some of us).
But for the average 'worker', there are still way too many who's only computer is the 'work laptop' and who's only email address is 'the work email address'. This tends to be the tech-unsavy and/or tech-fearful crowd that falls into this bucket (who also don't browse HN, so we never interact with them here), but they are still present, and there are far more in this bucket than most tech-savy folks realize.
As recently as 10 years ago I would have agreed but now smartphones and tablets are so common I think more people have an email-capable personal device, and probably a “free” email address.
Just about a month or so ago the union at $job emailed around to again warn members that, yes, management does monitor your work machines, and indicated that just recently several employees were targeted for using their work laptop at home, after hours, for personal purposes, and one of the personal purposes was one of the specific 'uses' (porn) that management keeps a close watch out for and goes after users for accessing on their work machines.
Someone hiding their visit from a spouse?
Expectations of privacy - even for corporate e-mail - is a thing some places. To what extent it applies tends to depend on a whole range of things.
The productive part of the population is treated like children in the US. Daddy gives you health insurance and reads you diary. If daddy no longer likes you, daddy cancels you health insurance but still reads your mail.
I've also experienced where I've emailed people who left and received immediate automated replies informing me of the change and providing me with a new contact person.
I've never, ever experienced a time where I've emailed person@company[dot]com and received a casual reply like "Hey man, I quit that place. Hit me up and we can grab beers!"
And I think anybody would be shocked if that were the case. Especially if you kept getting those emails as a former employee and no other current employees were getting them also. Nevermind mailboxes cost money or physical resources most of the time. To expend those resources to all former employees indefinitely is not practical. And I don't want to keep my mailboxes at former employers anyway. I have enough notifications on my phone to be batting away vendors and suppliers from previous employers.
Additionally, if you work for a company or industry where such correspondence must be preserved and tendered on request due to applicable laws or regulations, such organizations are legally required to have access to all employee emails.
I would assume even just to do business fluidly they might need access.
1. My ISP provides me internet access, but they are not entitled to collect my bank information when I access my bank account.
2. Depending on the nature of the corporation, it may not be legal for an individual to forward emails in the manner described. Consider: what if the email account belonged to a lawyer or doctor? Client confidentiality probably trumps many other legal concerns here.
3. Is said manager part of the IT/InfoSec department within this organization? If not, they may be circumventing organizational controls, which in itself may not be legal.
Context is important.
Under European data protection laws, for example, many countries have considered the privacy restrictions to extend to employee e-mail addresses.
This includes Norway, for example, where employees have extensive rights to prevent employers from accessing their corporate e-mail accounts without substantial safeguards to prevent them from accessing personal information, and including rights to be notified where possible, be present, be able to respond and challenge the access etc.
You can find a lengthy (in Norwegian, though Google translate ought to do a decent job) walkthrough of the rules here [1].
Not everywhere treats people as serfs at work.
[1] https://www.datatilsynet.no/personvern-pa-ulike-omrader/pers...
The corporation owns the email server, so their choice when you leave for whatever reason, is either to disable the account entirely (or give a bounce message) or keep it active.
Is your question really on the legality of the latter case, i.e. once you've left a company can they keep your email address live and perhaps even respond from it?
So in that case it is really jurisdictional. The US falls down pretty heavily on the corporate-owns-everything, but not everywhere does.
In my experience It's pretty common for companies to retain emails of people who have had outside contacts at least for a while, so nothing gets dropped on the floor, usually redirected to a supervisor or whomever took over the projects.
Just to expand here. You should assume that your employer has access to _everything_ that you do with their assets. If you are trying to maintain privacy from your employer for whatever reason, do not use your work phone/laptop/email/etc.
For example, one day your laptop forcibly restarts and afterwards you're locked out. Then a day later, you get the call that you were canned.
So always keep private communication separate and get private phone numbers / email addresses from coworkers that you get along well with. The company can delete your extension and email address, but with a bit of preparation that doesn't have to be the end of your personal relationships.
I hear this a lot and it seems like sound advice, but always leaves me with questions.
Sure, my employer can see what URL's I am hitting, what applications are installed, their usage, and if they want they could even decrypt https traffic, take screenshots without my knowledge, key-log, turn on microphone and camera too.
I mean, I won't hesitate to open my personal gmail, read news, make comments on social media sometimes (like this), perform online "errands". At the back of mind, however, I wonder if someone is seeing what I am doing.
It makes me wonder, what is typical? Under what kinds circumstances would the most draconian measures (like screenshots) be taken? How much latitude are IT folks given? Are there ways to detect when really ugly things like keyloggers/cameras/mics being controlled by whatever "enterprise IT" software suite?
It seems IT folks don't talk about this much. The dominant advice is always don't use work computer for _anything_ but work. The reality is that almost everyone in every profession takes that advice with a grain of salt.
You should redirect this question to each HR department: how much does HR want to protect a company from its (possibly) rogue employees?
It seems like a lot of effort to monitor screens, it makes me think there has to be a compelling reason, and not just browsing around looking for "problems".
depends. it can often be chalked up to management having too much time on their hands, or busy work delegated to use up part of the day.
I worked for an ecommerce site that keylogged everyone's computer and was tasked with going through the recorded input for someone that quit on bad terms to find out "if she'd done anything". it was a colossal waste of time, and we only learned that she was into furry websites
We never looked at anyone's activity without a clear reason, but that reason wasn't always very justifiable by my personal standards. However, I'd say most of it was necessary (like when tracing root cause of an alert or infection). My naive guess is this is probably pretty close to how it is in most big US companies.
For the times that were unnecessary (assessing "productivity"), our team, including our managers, always tried to provide as much evidence and guidance as possible that would work in the employee's favor, because we all knew it was complete bullshit and a big overreach. It's also very difficult to tell exactly what someone was or wasn't doing at specific times just by their browsing history. (We didn't have screen recording spyware or anything like that.) I'd say 98% of investigations were necessary and 2% were bullshit like those.
Reading emails or IMs was extremely rare and reserved for people replying to scammers/phishers, or accusations of serious misconduct or crimes.
1 - some program is scanning ingoing/outgoing data looking for compliance violations (typically finance, some classified work; should be for medical privacy/PII but I don't see much of that happening). Also scans for liability issues such as porn at work etc. Easier to screen that stuff out up front rather than later, frankly.
2 - you have a highly restrictive job (e..g call center) and are being spot monitored from time to time; statistics are likely kept continuously. Distopian but yes, happens.
3 - Sysadmin ends up looking at some of your mail while debugging a problem or doing some investigation not necessarily related to you e.g. some employee is terminated for fraud: let's look at their correspondence, some of which -- innocently -- is from you. Or there was a disk crash and some data is being reconstructed, which includes your call logs or email or whatever.
The third case is the most common and is why there is often a blanket "we can read and get all your data" statement in the employee handbook. There are others, and you can guess them.
Most email servers/services have a setting to keep deleted emails for a period of time. Most corporations also have a separate email server for execs that have different settings. This is above and beyond compliance settings that also email retention for different periods of time. Then there are also backups and archiving...you get the idea.
Your employer may be able to wipe your phone, track it, etc. Instead, I installed a different browser dedicated to logging into work email.
Sadly virtual machines on phones are prevented pretty thoroughly by the android/iOS system design, at least in any kind of efficient way.
"Work profiles" don't really cut it...
I recently had to wipe my phone and changed from full-access to work profiles and it's nice to have that clean division between my work account and personal.
Individual apps can wipe their own data, but apps don't have the arbitrary ability to wipe the entire phone. Even Google's apps.
To quote the docs:
> [0] Before you can wipe a user’s mobile device, you need to turn on mobile management. For details, see Set up mobile device management[1].
PS - I'm responding because this myth that simply retrieving GSuie/Office 365 email allows device wipes just won't die. That isn't how any of this works. Enterprise device management requires special device enrollment, simply signing into a random email app isn't it.
[0] https://support.google.com/a/answer/7542661?hl=en
[1] https://support.google.com/a/answer/7396025?visit_id=6372178...
[0] https://developer.android.com/guide/topics/admin/device-admi...
Nowadays most setups allow employers to wipe the work profile but not the whole phone (and again, this is explicitly stated to the user upon adding the profile).
Disclaimer: Now a Googler, opinions are my own.
Additionally, when robocopying their profile data you would see their internet history(each visited/cached site, cookies, etc). I couldnt believe the number of VP/C level employees that would have vast quantities of porn and shady history on their work machine. no judgement here, but if worker bees had the same content they would be fired without question.
Do what you want on your own time or computer, but dont expect a work PC to be private or not monitored.
I am very surprised by the number of people claiming it is illegal or not possible.
You should always assume your email (and the contents of your hard\network drive, your browser based activity, and everything you do, down to the key strokes) is being recorded and may well be being actively monitored by your employer (or anyone else with privileges on the systems you use). Similarly, anything you delete is unlikely to be actually deleted.
Your friendly local IT guy might be stealing your bank details or checking for people trying to unionize or just spying for a competing department. It's not "Nice", but no one owes you nice.
Please act and plan accordingly.
Now I would be interested in whether Google Vault retains those. Because it's a conundrum either way.
If google vault does retain it, you have sensitive content that people think are private but is not.
If google vault does not retain it, then accountability, auditing, liability, etc... goes out the window and google vault isn't a vault anymore.
Anyone on G Suite Business can check and confirm?
https://support.google.com/a/answer/7664184?visit_id=6372178...
If history is off, messages are deleted after 24 hours. Vault can't hold, retain, or search direct messages that are sent with history turned off. Check with a Vault admin to confirm that these history settings comply with your organization's data retention obligations.
March 7, 2019
If your organization enables Gmail confidential mode, Vault can hold, retain, search, and export all confidential mode messages sent by users in your organization.
Confidential messages sent after November 30, 2018 are visible to Vault in the mailboxes of all internal senders and recipients. Messages are always available to Vault, even when the sender sets an expiration date or revokes recipients' access to confidential mode messages.
https://support.google.com/a/answer/7684332?hl=en
Confidential mode messages and Vault Vault can hold, retain, search, and export all confidential mode messages sent by users in your domain. Vault has no visibility into the content of confidential mode messages sent to your organization from external parties. If your domain uses Vault, carefully review how Vault handles confidential mode messages
To support Vault's requirement to access confidential mode messages, Gmail attaches a copy of the confidential mode content to the recipient's message.
Here's what you should know about this copy:
It's attached only when the message sender and recipient are in the same organization. It's only available to Vault. Senders and recipients cannot access the copy from Gmail. Third-party mail archiving tools cannot access the copy. To delete all copies of a confidential mode message, you must delete it from the sender account and all recipients' accounts.
So it would fall under your company’s policies for retention of sent messages.
I knew that capability existed, and it sounds like a great avenue for phishing. People who routinely receive highly sensitive messages like that are going to be more apt to open a link than my mom, who is aware of phishing and whose spidey senses would be tingling.
Slack Plus/Corporate: "This type of export includes content from public and private channels and direct messages."
https://slack.com/help/articles/201658943-Export-your-worksp...
If you want to store something important for the long term, Slack is not the place to do that.
Funny how "I don't want the GMail app" is the only piece of my existence that Google seems unable to keep track of.
In many organisations the guy who operates the mail server does not have the same seniority as the CEO, and neither would they be read into every commercially sensitive project, every HR, disciplinary, or employee medical discussion.
So it seems odd to me that IT administrators, who are often such sticklers for security and opponents of the idea of trustingly granting overly-broad permissions, would even want the ability to do an end-run around information isolation.
Searching LastPass I (an engineering manager who knew from day 1 this very problem set) signed up to HBO Now and Task Rabbit with my work email - entirely by accident.
It's worse in email-obsessive non-technical roles like sales. They can spend 3+ hours per day in Gmail alone and anecdotally sign up for all manner of personal deliveries and dating profiles through that same work email!
Ultimately email providers like Gmail should do a better job separating professional and personal accounts and informing their users how little privacy they actually have. I heavily blame GMail's multi-account selection interface and how non-technical users can struggle to change the default account they are logged in under. I think the odds of Google warning users to worry more about their own privacy is slim to none. /rant
on a more serious note, this is only the case for small businesses. in anything larger, security practices like separation of duties and minimum required permissions strongly mitigate this problem. you cannot eliminate it by definiton; there is always a ring 0.
You're not wrong but:
* It's necessary for someone (or some group) to have these powers in order for anything to work.
* Usually everything you do as an Admin is logged just like for the users and you cannot purge those logs or not without drawing a lot of attention or making it obvious you did so. So you too will eventually be caught and punished if you abuse these powers. You have more power but not infinite power as there will be other admins watching you and if a log file suddenly disappears at the same time you make some strange stock purchases you may be asked difficult questions...
It's also worth noting that humans are surprisingly honest. Millions of workers have access to your medical records, your bank accounts, information useful for insider trading or state\company secrets. And it's pretty rare that anyone steals any of it. If anything, humans are too willing to keep company\state secrets and we'd be better off if people leaked MORE (e.g. Sherron Watkins or Edward Snowden)...
I decided that I didn't want to deal with maintaining a gmail oauth token, so I went down the rabbit hole of getting my service auth set up as a gsuite admin. It turned out to work fine, no more oauth token necessary. But then I thought for a second, and changed the email address from the the junk one I setup specifically for this task to mine, and it worked. So I tried my colleagues (with their knowledge) and it worked as well. Turns out giving your service account admin rights means giving them full access to the entire company's accounts.
So with a sigh and a dammit, I went back to using the oauth token. I couldn't find any way to be a "limited" gsuite admin over just some set of email addresses; it was all-or-nothing. This seems like a strange oversight on Google's part, but I also could have missed some documentation.
While this means that yes, "the company" can read your e-mails, it also means that they can't deny doing it if it actually happened. Neither can a rogue employee do it without there being a record, assuming you have accounts properly setup and don't share account passwords.
There has to be some degree of corporate espionage occurring when every startup and many mature corps are using everything from Gmail to teams to slack to discord. It would be really difficult to sniff out if the offending admin kept quiet. All you need is one person with access...and if you're a less than ethical executive it isn't hard to find a dev to do your bidding quietly.
If you look in Chrome's privacy settings, you may notice: "Your administrator can change your browser setup remotely. Activity on this device may also be managed outside of Chrome". Considering I've granted Google Hangouts screen/webcam/microphone access, I'm assuming they can access my screen/webcam/microphone whenever.
The same thing happens to Slack where they can access to archive of all messages, including private channel.
NEVER gossip anything with WORK account. Always assume they will see you. Create a PRIVATE Facebook, PRIVATE Gmail, etc and discuss there.
It's like if you write all your correspondence on postcards (no envelopes) and then wonder if the mailman can read your mail.
Is it insider trading if Google uses that to decide in what stocks to park their excess cash?
Article still needs proofreading lol
... with all necessary and legal steps taken regarding your continued employment at that organization should you refuse to voluntarily divulge the contents of the message or a way to decrypt it.
This of course depends on the structure of the communication, but for many industries, it is required by law to be able to produce communication upon request, and not doing so would be a crime.
More broadly, end-to-end encryption may put the employer at risk in some situations. In harassment claims, employers can become liable for harassment using company-provided channels because they're argued to 'enable' it. Providing a communication channel that doesn't allow them to verify claims during an investigation or stop ongoing harassment can expose them to greater risk.
To my knowledge, in Europe (or some European countries) it's illegal to monitor employee communications except in the context of a specific claim. In the US broad-based communication monitoring is generally legal unless someone can somehow prove that it's specifically used to prevent employees from organizing a union.
IANAL, take these as broad-stroke general impressions and not precise or accurate statements of fact.
That's a lot of words to say "Use your smartphone email client and don't connect to the wifi", but there you go ;) ).