The question arises in nearly every office whose network starts getting organised: how far may an employer see what staff do on the office internet?
The short answer: further than some employees assume, and much less far than some employers assume.
What separates the two isn't the tooling but something simple, whether the people being monitored knew about it in advance.
The legitimate interest, and its limits
Companies have real reasons to monitor their networks, and those reasons aren't manufactured:
- Protecting the network from malware and intrusion.
- Ensuring the bandwidth being paid for is used for work.
- Meeting record-keeping obligations that genuinely exist, see the guide to log retention obligations.
- Protecting company data and the customer data it holds.
What does not become lawful merely because the network belongs to the company:
- Reading the contents of private conversations.
- Collecting data about employees' private lives beyond the employment relationship.
- Singling out an individual for monitoring without basis, for personal reasons.
- Using monitoring results for purposes other than those disclosed.
Owning the network confers authority to manage it. It does not confer authority over the people using it.
The three conditions that decide
1. Told in advance
This is the most commonly skipped condition, and the most decisive. Disclosed monitoring is network administration; covert monitoring is data collection without a basis, and the difference lies not in what is collected but in whether people knew.
The notice needn't be elaborate: one written policy, given before access is granted, with a record that employees received it. The structure resembles the guide to guest Wi-Fi terms, with one important difference, an employment relationship isn't between equals, so clarity is required more, not less.
2. Confined to what's necessary
For nearly every legitimate purpose above, what's actually needed is far less data than most equipment collects by default.
The comparison is clearer side by side:
| Purpose | What is actually needed |
|---|---|
| Protection from malware | Destination addresses, not contents |
| Bandwidth management | Data volume per device |
| Record-keeping duties | Which device, at what time |
| Investigating an incident | Records for that period only |
None of them requires the contents of conversations. Equipment that breaks encryption to inspect traffic contents exceeds every purpose above, and places the company in a far harder position to defend.
3. Used only for the stated purpose
Data gathered for network security is used for network security. Using it to assess performance, or for anything never mentioned in the policy, undoes the basis for collecting it in the first place.
This also settles who may open it. Network records aren't general reading for all of management; access needs confining to those who actually run the network.
Restricting beats monitoring
There's a simpler route that is nearly always overlooked: rather than monitoring and then reprimanding, simply restrict from the start.
Blocking particular services on an office network isn't monitoring. It collects nobody's data, touches nobody's private life, and requires none of the three conditions above, because no personal data is processed. How blocking works is covered in the guide to how site blocking works.
Other equally light approaches:
- Throttle entertainment traffic rather than banning it. Video that stutters solves the bandwidth problem without a single conversation, see the guide to limiting Wi-Fi speed.
- Provide a separate network for personal phones. This resolves several things at once: personal traffic no longer mixes with work traffic, so it is neither monitored nor a burden. The method is in the guide to separating guest networks.
- Segment by department in larger offices, see the guide to VLANs.
A separate network for personal devices is the single step that resolves the most at once. Most employee objections to monitoring stem from personal activity being mixed into the work network; separating them removes the problem rather than managing it.
Writing the policy
A policy that can be followed beats a policy that is exhaustive. What it needs:
- What is recorded: stated concretely. "Websites visited and data volume per device", not "network activity".
- What is not recorded: equally important, and the part that reassures.
- How long it is kept, and what happens afterwards.
- Who may access it, and under what circumstances.
- What it is used for, with a statement that it isn't used beyond that.
- What isn't permitted on the office network, including things that can draw in the company itself, as in the guide to copyright and illegal downloads.
Because those records contain personal data, the duties attaching to them are the same as for any other personal data the company holds, see the guide to personal data protection law and the guide to customer data collection rules, whose framework applies equally here.
Cameras are a separate question
Network monitoring and camera surveillance are often bundled into one policy, though they answer to different considerations and require different notice. Those rules are covered separately in the guide to CCTV and privacy rules.
In short
A company may monitor its network. What it may not do is monitor its people without their knowledge.
Three conditions make it lawful: told in advance, confined to what's necessary, used only for the stated purpose. All three are easier to meet than they sound.
And in most offices the better route isn't monitoring more tidily but monitoring less, by restricting what can be reached, and moving personal devices onto a network of their own.
Frequently asked questions
May a company monitor its employees' internet use?
Within limits, and subject to conditions. The network belongs to the company, and protecting it is a legitimate interest. What determines lawfulness is three things: employees are told in advance, monitoring is confined to what's necessary, and the results are used only for the stated purpose.
May an employer read employees' private messages?
No. Monitoring network traffic is very different from opening the contents of private conversations. The first protects the network; the second touches confidentiality of communications, and doesn't become lawful merely because it happens on an office network.
Do employees have to be informed?
Yes, and this is the most commonly skipped condition. Covert monitoring changes the matter from network administration into data collection without a basis. The notice needn't be elaborate, one written policy, known before access is granted, is enough.
Can social media be blocked on the office network?
Yes. Deciding which services are reachable through the company's network is resource management rather than monitoring, and touches nobody's personal data. It's a lighter approach than monitoring and then reprimanding.