If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game.
Laptops are cheap. There’s no reason to mix personal and corporate usage.
If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game.
Laptops are cheap. There’s no reason to mix personal and corporate usage.
From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it.
You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office to decide to fire you based on that information (though I don't know if US laws actually protect workers in this case -- in Australia and basically all of Eastern Europe this would be insanely illegal on several levels).
> Laptops are cheap.
Not for everyone.
How often did that stop an employer?
>Commenting on the ruling, Pam Cowburn, the communications director at in London, said: “The European court’s ruling is welcome. In some workplaces, it may be necessary for emails to be monitored, but if employers are going to do so, they should make staff explicitly aware of it.”
>Despite finding that Bărbulescu’s rights under article 8 of the convention had been violated, the court declined to award him any compensation, saying the ruling was “sufficient just satisfaction”.
The largest example probably is the 2020 GDPR fine of 35 million euro for clothing retailer H&M for violating the privacy of their employees, despite the employees being informed of that.
In most EU countries, tracking company-owned hardware is explicitly okay, and where it's not mentioned in law there are judicates that make it OK.
As I said, even the government and its wholly/partially owned enterprises are doing it, and working as a contractor for the government here requires you to track usage of your employees' workplace computers too, so I can't see how it could be in any way illegal. Same thing with working for banks and insurance, and I bet there are more cases.
Don't know about other EU countries, but at least NL deviates significantly from the sketched scenario.
[1] https://blog.iusmentis.com/2017/11/22/wanneer-mogen-mailbox-...
Still cheaper then searching for a new job... without a current one.
(This probably doesn't work so well in the US.)
Wow
Don't use work computers to look at porn, your employers already know about it.
But they were quite frank about allowing us to do what ever we want on the laptops providing we delivered positive outcomes for the business.
If this meant the laptops were used to browse porn at home or even during business hours (clearly not on the shop floor if you were in the office) or playing video games, it was fair game.
This employer also had _incredibly_ poor standards and culture for removing misogyny and bigotry, in fact it was one of the worst I've ever seen. Not saying causation = correlation or similar but an interesting data point nonetheless.
I think that the periodic checks were set up because a subordinate of the manager's had seen the porn on the machine, and had gone to HR.
In the USA and other countries with subpar privacy laws.
https://www.grcworldforums.com/business/can-employers-legall...
It is very hard to see the Workplace Relations Commission (WRC - the body which handles workplace disputes) accepting that identifying a user on Glassdoor would meet the test of being necessary, legitimate, or proportional. This is particularly true as the WRC has previously found that monitoring internet usage for example for pornography is not proportionate where the employer has the option instead to block such sites and make a policy against their access.
Of course, an unscrupulous employer could also use surreptitious surveillance and find another reason to let the employee go, although firing an employee in Ireland is notoriously difficult short of gross negligence.
The US is more "employer-friendly" if you like, and much less complicated to fire employees (boo!) compared to Europe - yes. But generally not categorically different when it comes to the right of employers to snoop on their employees, which people here might want to be aware of.
Understatement of the year.
For the employer to open/read such communication would be highly illegal, akin to opening others private snail mail.
I do believe that this also extends to corporate issued phones and computers. Especially since you’re automatically taxed for “private use” of such equipment when assigned.
so you get charged a tax when an employer gives you equipment required for work? What happens if you can't afford that tax then?
This feels very wrong - taxing someone for a potential benefit when it is not proven that such benefit exists.
The vast majority of people prefer to also use the car privately, and pay the tax (which is reasonable, if taxation is reasonable).
Cars that keep rotating between drivers are not subject to that (but exact record keeping of driver and trip required to avoid tax)
Similarly, employer provided phone subscription is assumed to be partly private use (50% of monthly subscription cost considered a a taxable benefit iirc), not sure what hoops you need to jump through to prove it is not private use at all. (But phone plans are cheap - excellent domestic plans are $10 or so)
Obviously this only happens when the equipment you get can plausibly be used for personal purposes. Such as a company car.
> What happens if you can't afford that tax then?
That's extremely unlikely.
I think you need to specify "here" to get an answer to that question.
That has nothing to do with putting private email in a private folder on the company mail server, near as I can tell, and nothing in that statement would address the statement about companies monitoring use of company equipment and network etc.
Since they’d need to know even in the private email case what they folder names were, for instance, to know there even WAS private email.
People have legitimate expectations of privacy in the office and/or during working time.
Employment means selling your skills and effort, not becoming a servant or a slave in a feudal society.
Additionally, having delicate information in the hands of the company in general or sysadm/security engineers create a ton of liabilities.
There has to be a balance between security needs, corporate surveillance, privacy and worker rights.
That requires them to use tools which can easily let them know, for instance, what websites someone is visiting, and what executables are executing on the machine, what devices are being accessed and when, etc.
It’s pretty fundamental. An individual looking to secure their machine would need to do the same thing.
If a company abuses that to spy on every waking moment of an employee, that is obviously abusive (barring cases of investigating legitimate suspected abuse by the employee I guess?). But you’d need to somehow codify in law the line, and I haven’t see anyone having any success here so far.
I have seen employees steal massive amounts of trade secrets, secretly steal customers from employers, run porn sites from company equipment, etc.
I’ve also seen employees so creepy stuff like stalking customers, stalking other employees, harassing other employees using this tech too.
Personally, I’ve always kept employer laptops and stuff closed and off when not used, and try to segregate personal and work equipment, but that’s been more to avoid something embarrassing coming up during a presentation or the like.
People could be making backhanded deals on their phones or they could be having an urgent confidential conversation with their doctor or spouse. Should the company record and review phone calls?
People could be stalking customers/coworkers or making deals in the bathroom. Or they could be using it for more personal purposes. Should the bathrooms have CCTV with audio?
People could be selling company data in the company parking lot, in the mall or at home near/using the company laptop/phone that is permitted to be used for personal reasons, or just mandated to be near them, or they could do the same thing without presence or use of any company equipment. Where do you draw the line, and at what point is it even sufficient to prevent losing information etc.?
Do you trust your employees? All trust can be abused, yet how can the company function if they don't trust their employees at all?
Imagine I were to die in the office in some embarrasing way, on company time, in full view of company CCTV, do they have the right to upload the video to YouTube to make money from it?
What if they record audio of me at home, can they publish it? Can they show it to anyone at the company?
What if audio is recorded outside of compaby time by a company laptop thats had its lid closed? What if it's recording 24/7?
Are they allowed to snoop on traffic of my home network? If I have a home camera thats not password protected, can they help themselves to that Video?
If my network drive has no password, is it okay if they help themselves to those files?
I can't think of which law stops a company sharing a video of your death - presymably they own the copyright
Even more restrictive countries like Germany are fine with this.
Your advice is still sound.
Exactly! I'm always amazed at people who do ANYTHING personal on corporate resources, especially in this day and age. Even when personal computers were rare and cost thousands of dollars I still didn't do jack shit on work computers, no matter how tempting or "acceptable use" it was.
It’s a nightmare from a privacy point, but its also a problem for the InfoSec tools… How do they distinguish between an unmanaged private device on a private network or a unmanaged device on a corporate network?
Trivially, from the simplistic (check IPs and router MACs / SSID in use) to the marginally more advanced (deploy an agent that is only reachable from the corporate network) to determine if the tool should even be running in the first place.
E.g. tag the port on the switch, run a cable to the device so that it doesn't know there's a vlan involved, block routing between vlans. As far as I can tell that's probably good but might not be.