"You have no reasonable expectation of privacy ..."
"You have no reasonable expectation of privacy ..."
Author
Discussion

Kiltie

Original Poster:

7,505 posts

275 months

Wednesday 15th July 2015
quotequote all
I work for a US company.

I work in the UK and I am British.

When I log in to the network, I have to acknowledge agreement to the following.

  1. Communications and data transmitted or stored on this Network are monitored and may be intercepted or searched at any time and for any lawful purpose by ***.
  2. You have no reasonable expectation of privacy regarding any information passing through or stored on the Network.
  3. All communications and data may be disclosed or used for any lawful purposes.
Isn't that all meaningless under EU law? ... and, actually, I do have a reasonable expectation of privacy?


BJG1

5,966 posts

241 months

Wednesday 15th July 2015
quotequote all
I wouldn't have thought so. They're saying they have the right to look at any data that passes through their network, the phrasing makes it sound worse but the same thing has been in every employment contract I've ever signed.

AndrewEH1

4,922 posts

182 months

Wednesday 15th July 2015
quotequote all
You're on their network so their rules. It's not like they are snooping your private network at your house?

I have similar terms of use where I work.

justanother5tar

1,314 posts

154 months

Wednesday 15th July 2015
quotequote all
Similar at my work, too.


davepoth

29,395 posts

228 months

Wednesday 15th July 2015
quotequote all
All your data routes through a US server presumably, so US rules apply there.

Some Gump

13,018 posts

215 months

Wednesday 15th July 2015
quotequote all
It's a work computer, on a work network.
Do work stuff, no frankie vaughen and deffo no borderline banter with colleagues via email.

Kiltie

Original Poster:

7,505 posts

275 months

Wednesday 15th July 2015
quotequote all
I'm not concerned about anything like that.

As far as I'm concerned, my boss or the HR lady can come and browse my inbox and sent items any time they like. They only have to ask and I'll let them sit at my desk.

I do use my work email to communicate with my wife and family. There's some delicate family stuff happening and it's the most reliable way of getting in touch with me.

Nothing sinister and I'd happily discuss it with the boss or the HR lady if they're really interested.

I just don't like the idea that I'm agreeing to someone being able to snoop. That's all.

In reality, I know that it's unlikely that anyone will ever look at my emails. I just don't like that I'm agreeing to them being able to.

To me, it feels similar to someone looking through my desk drawers or listening to my phone calls (incidentally, I reckon the voice system is part of the "Network" so I guess they could).

I know ... I know ... I should man up and just accept it.

It just feels wrong to me; that's all.

I think it's not unreasonable that I expect a degree of privacy.

Anyway, nearly half eight and I'm still in the office so enough's enough.

98elise

32,495 posts

190 months

Wednesday 15th July 2015
quotequote all
You can't expect any privacy on a companies IT equipment. Its there for you to do your job, not for personal stuff.

Most companies will accept that you may need to do personal stuff every now and again, but you can't expect them to respect your privacy if you do it on their network.

The reality is they are very unlikely to look at it, but should they need to then you have accepted that they can.

ChasW

2,162 posts

231 months

Thursday 16th July 2015
quotequote all
This is not uncommon. I have seen people taking liberties with company IT, ie visiting gambling sites, having facebook open all the time etc. I would not be disturbed by such notices.

edc

9,620 posts

280 months

Thursday 16th July 2015
quotequote all
I appreciate you may have some difficult family issues to deal with but at the end of the day, work tools are provided for work. You have a choice whether you use them or not to communicate with your family and I suspect you choose to do so because it is convenient for you. You're at a desk with email always on or have a handheld which picks up email straightaway. A company will always monitor to some extent the use of its equipment to watch out for unauthorised data transfer amongst other things. They won't for your convenience pick and choose which email addresses to review and which not to. If you want more privacy you want more control so unfortunately use your own tools.

PurpleTurtle

8,855 posts

173 months

Thursday 16th July 2015
quotequote all
Kiltie said:
I'm not concerned about anything like that.

As far as I'm concerned, my boss or the HR lady can come and browse my inbox and sent items any time they like. They only have to ask and I'll let them sit at my desk.

I do use my work email to communicate with my wife and family. There's some delicate family stuff happening and it's the most reliable way of getting in touch with me.

Nothing sinister and I'd happily discuss it with the boss or the HR lady if they're really interested.

I just don't like the idea that I'm agreeing to someone being able to snoop. That's all.

In reality, I know that it's unlikely that anyone will ever look at my emails. I just don't like that I'm agreeing to them being able to.

To me, it feels similar to someone looking through my desk drawers or listening to my phone calls (incidentally, I reckon the voice system is part of the "Network" so I guess they could).

I know ... I know ... I should man up and just accept it.

It just feels wrong to me; that's all.

I think it's not unreasonable that I expect a degree of privacy.

Anyway, nearly half eight and I'm still in the office so enough's enough.
15yrs ago I'd have agreed with you as there was no other way of getting in touch with me by email during the working day, so I dealt with a lot of my personal stuff (before/after work or during lunch) via my work email account. Boss was happy with that. He did the same.

Nowadays any decent smartphone gives you full connectivity. No real need to use work equipment so, draconian as it sounds, I'd just jib out ans use email on my phone if I was bothered about it.



Robbidoo

263 posts

196 months

Thursday 16th July 2015
quotequote all
edc said:
I appreciate you may have some difficult family issues to deal with but at the end of the day, work tools are provided for work. You have a choice whether you use them or not to communicate with your family and I suspect you choose to do so because it is convenient for you. You're at a desk with email always on or have a handheld which picks up email straightaway. A company will always monitor to some extent the use of its equipment to watch out for unauthorised data transfer amongst other things. They won't for your convenience pick and choose which email addresses to review and which not to. If you want more privacy you want more control so unfortunately use your own tools.
+1

I have a very similar disclaimer that appears when I turn on my work laptop - for that reason my personal email stays in a browser window where it runs over https. Of course google and the NSA can still read it but that's the price of doing business!

AndrewEH1

4,922 posts

182 months

Thursday 16th July 2015
quotequote all
Robbidoo said:
+1

I have a very similar disclaimer that appears when I turn on my work laptop - for that reason my personal email stays in a browser window where it runs over https. Of course google and the NSA can still read it but that's the price of doing business!
I suspect your company can still see this? I thought https only worked between your network and the network you are connecting to?

andy-xr

13,204 posts

233 months

Thursday 16th July 2015
quotequote all
A lot of security applications can do https inspection fairly easily, it's by no means 100% secure

As to the main question, I think that's fair, there's many reasons to sniff what's going on across the network for quite a few departments in the average company.

Robbidoo

263 posts

196 months

Thursday 16th July 2015
quotequote all
AndrewEH1 said:
I suspect your company can still see this? I thought https only worked between your network and the network you are connecting to?
No, https creates a connection between the requestor and the answering server, so it is a secure connection between two points where anything inbetween can only view the traffic opaquely.

As Andy-XR says appliances can indeed do sneaky things to inspect this traffic but it's far from trivial to implement - and on a large corporate network would be prohibitively expensive to deep-inspect everything.

As with anything when it comes to network security and privacy, you can only reach a level of confidence, never an absolute.

AndrewEH1

4,922 posts

182 months

Thursday 16th July 2015
quotequote all
Robbidoo said:
No, https creates a connection between the requestor and the answering server, so it is a secure connection between two points where anything inbetween can only view the traffic opaquely.

As Andy-XR says appliances can indeed do sneaky things to inspect this traffic but it's far from trivial to implement - and on a large corporate network would be prohibitively expensive to deep-inspect everything.

As with anything when it comes to network security and privacy, you can only reach a level of confidence, never an absolute.
Sorry, I don't know much about security, but won't the company be able to view the request before it leaves their network? Therefore see what you're up to?

Muzzer79

13,032 posts

216 months

Thursday 16th July 2015
quotequote all
I had a very similar query from an employee of mine, when we stated that her e-mail had to be set that management had access to it in the event of sickness, etc.

She saw this as an invasion of privacy, citing potentially confidential e-mails to HR as an example.

We had it clarified that it was a company-owned and run IT system that employees use. It was made very clear that if an employee wishes to make confidential communications that they do not want members of other departments to have access to, they should use their own e-mail account or another non-company form of communication.

So, in short, it's their system so they can read what they like.

Dromedary66

1,924 posts

167 months

Thursday 16th July 2015
quotequote all
AndrewEH1 said:
Sorry, I don't know much about security, but won't the company be able to view the request before it leaves their network? Therefore see what you're up to?
They will absolutely be able to see that Mr Bloggs has been on GMAIL for 3 hours for example. They won't be able to see the contents of e-mails or anything like that, just the URLs

andy-xr

13,204 posts

233 months

Thursday 16th July 2015
quotequote all
Dromedary66 said:
They will absolutely be able to see that Mr Bloggs has been on GMAIL for 3 hours for example. They won't be able to see the contents of e-mails or anything like that, just the URLs
That's what the web filter will say, but DLP Software can tell you what's going on where fairly easily. If you try and send out the company personnel file or customer database for example, you email it to yourself over Gmail there's many products out there that can stop that happening. Their use or intention can also be to make sure that what you're sending is sent and received to/by the people they're supposed to be between, rather than someone else.

Crusoe

4,123 posts

260 months

Thursday 16th July 2015
quotequote all
When your computer is on the network anyone with the root admin can look at anything on your c: drive. Anything you send or save on network drives is also available to someone or logged and backed up. Rare that we would look at a specific machine unless there was an issue but it's the same back door they use to make sure things like your antivirus is up to date and you have the correct versions of software.