That's quite extreme. What is your threat model?
That's quite extreme. What is your threat model?
Company surveillance (of their employees) is very real and unlike 'google reads all my emails' they actually can and do and it is a person they actually know whos private information they are viewing. I dont even need to get into the chance of every piece of information being in a lawsuit or get into the lack of any controls around data retention etc to be worried.
First step IT would take when I dropped my phone in 'because they had to run the update' - they would open my photos and take a look through. Second step - they would go to the deleted photos and have a look through. It was done as part of any company-mandated review of the device but out of personal 'curiosity'.
Every private message on teams etc was logged and routinely reviewed by a compliance team and often escalated to line managers - the team doing so knew everything professional and personal going on in the place. Who was getting hired, fired, promoted, working hard, slacking. Who was sleeping with someone, depressed, happy, gay, straight, having kids, getting divorced, getting a nose job, getting a vasectomy etc.
So whats the threat? I have nothing to hide, I am popular, a hard worker, not having an affair with the intern, so they are not going to trawl through looking for any dirt to diminish or fire me. There is little value in this information beyond gossip, but a permanent record remains all the same. For me there is little extra effort required to phone home from my phone rather than the recorded office line and that way the call wont be listened to by the guy in compliance.
Here in Germany I think gathering many of these facts would simply be illegal.
That said, when I have worked outside the region or in less regulated positions - the intrusion into particularly email and written communications is the exact same. When you leave an organisation in particular, you do reflect on how big a trail of information you have left behind in their hands.
This is also exactly why I always check all the paperwork for "personal usage" of the devices and services provided by the company (email and stuff). If there is nothing about it, I send my mom a random cat picture from my work email (always outside of office hours, in other cases it could be a contract violation). Why? Because if it's not forbidden, you are implicitly allowed to and after at least one private message was sent by the account, it's legally like a private account.
If your employer snoops in the account, it's a massive privacy violation (Datenschutzgesetz and DSGVO/GDPR) and a strong case in employment law. Never needed it, but it's better to be safe than sorry.
I dont think I have ever worked under an IT policy that was anything but 'for work use only' - although that didnt stop me from taking great pleasure at seeing how many work emails were used to sign up for sugardaddie etc whenever they leaked. I was never too fussed - having two phones, two emails, two laptops etc doesn't bother me in the slightest. You lose access to the work phone number / email / storage when you leave anyway so it's really of no use.
I have even come to like the physical separation of work and personal, there are times each needs more than 50% of my attention.
Extreme surveillance from your employer would unnerve you.
Your remediation is:
Firewall between work and personal.
Is that a reasonable restating?
Threat model is straightforward: I have no expectation of privacy on my work devices. I do not want my employer entangled digitally with my personal life.
A threat model would be (albeit an absurd one):
I will be fired and blacklisted if an employer determines how many personal emails I send a day