Employee Privacy Rights at Work

What your employer can legally monitor — emails, messages, devices, location — and where employees retain meaningful privacy expectations in the workplace.

Employee privacy rights in the United States are significantly more limited than most employees assume. The general rule for employer-issued devices, email accounts, and systems is: if the employer owns it and has disclosed that monitoring may occur, you have little or no expectation of privacy. Federal law (the Electronic Communications Privacy Act) allows employers to monitor communications on their own networks and equipment. State laws vary — some states require employers to notify employees of monitoring; others have stricter rules for certain types of surveillance. But in most jurisdictions, an employer with a clearly communicated monitoring policy can legally read your work emails, review your browser history on company devices, log keystrokes, capture screen recordings, and access your company Slack or Teams messages.

The monitoring question gets more nuanced with personal devices, personal accounts, and off-duty conduct. Employers generally cannot access personal email or social media accounts even on a company network, and most states prohibit employers from demanding social media passwords or requiring access to personal accounts as a condition of employment. Off-duty conduct monitoring is more complex: most states have some form of protection for lawful off-duty activities (what you do on your own time is generally your business), but there are exceptions — particularly for roles with heightened trust requirements, licensed professionals, and employees whose off-duty conduct creates a legal liability for the employer. Wage and hour law also limits some monitoring: employees cannot be required to perform work during off-hours without pay.

Physical surveillance in the workplace — cameras, keycard access logs, GPS tracking on company vehicles — is generally permissible with notice, though some states restrict camera placement in areas where employees have a strong expectation of privacy (restrooms, locker rooms, break rooms in some jurisdictions). Drug testing is covered by a separate patchwork of state laws. The emerging category of AI-based monitoring tools — software that tracks productivity metrics, flags 'off-task' time, analyzes sentiment in communications — is rapidly expanding and largely unregulated at the federal level, though a handful of states are beginning to legislate in this area. The practical implication for employees: on company equipment and accounts, assume everything is visible and potentially logged.

What Employers Can and Cannot Do

  • Can monitor: email, chat, and internet activity on company-issued devices and accounts — with or without telling you in most states (though some states require notice).
  • Can monitor: keystrokes, screen activity, application usage on company devices. Productivity monitoring software is widely used and generally legal.
  • Can monitor: physical location via GPS on company vehicles or company-issued phones used for work purposes.
  • Can monitor: security cameras in most workplace areas (with limits on restrooms, locker rooms, and some break room configurations under state law).
  • Cannot access: personal email accounts, personal social media, or accounts on personal devices — even if accessed over the company network.
  • Cannot require: disclosure of personal social media passwords or access to personal accounts as a condition of employment in most states.
  • Cannot monitor (generally): lawful off-duty conduct, personal device usage on personal accounts, and personal calls made on personal phones even during work hours.

The Practical Takeaway for Employees

The safest default is to treat any company device, company email, or company communication platform as having no privacy. That means: don't send personal communications through work email, don't store personal documents on company computers or cloud storage accounts, don't use company devices for sensitive personal research (health, legal, financial), and be aware that work Slack or Teams messages — including direct messages — are accessible to your employer's IT and HR teams in most configurations. This isn't a reason to be paranoid, but it is a reason to be deliberate. If you need to communicate something genuinely private during work hours, use a personal device on a personal data connection. This is the practical norm that informed employees operate by — and it's increasingly important as monitoring tools become more sophisticated and pervasive.

Example

An employee uses her company laptop to draft messages to an employment attorney about a potential discrimination claim against her employer. Her company's IT department, which routinely monitors endpoint activity, flags the communications and alerts HR. Because the messages were sent through her company email and created on a company device with a disclosed monitoring policy, the employer's access is legal under federal law and her state's law. The lesson: for sensitive communications — especially those involving potential legal action against an employer — use a personal device on a personal network.