Employer viewing e-mail
Author
Discussion

busa_rush

Original Poster:

6,930 posts

281 months

Monday 21st March 2005
quotequote all
Does an employer need to do anything, like inform an employee, before they view the employees mailbox ?

I know the company owns the e-mail address etc but I was just wondering if the company has any obligations to the employee ?

Thanks

liszt

4,337 posts

300 months

Monday 21st March 2005
quotequote all
If they are switched on there should be a statement in the T&Cs / company policy saying that email isn't private and they are watching you in a way which would have Big Brother green with envy

supraman2954

3,241 posts

269 months

Monday 21st March 2005
quotequote all
I’m more worried about the company monitoring the time I spend on PH

Plotloss

67,280 posts

300 months

Monday 21st March 2005
quotequote all
Nope, its implied because its there equipment...

streaky

19,311 posts

279 months

Monday 21st March 2005
quotequote all
My first advice is to check the Employment Contract and any Information (Security) Policy.

A UK employer has no right of access to private e-mail, but does have right of access to e-mails sent and received in the course of business ... except with the consent of the employee - which my be embodied in an employment contract or applicable policy.

If the employer is situated outside of UK, different rules might apply. In the employer is in the USA, different rules on 'interception of communciations' apply in different states. That is, you need to know where your e-mails are being processed or where they are going to determine whether the employer has a right in law to intercept them.

Back to the UK; on 3 October 2000 (consequent upon RIPA), the Minister for e-Commerce and Small Business published draft regulations setting out the conditions in which businesses can record and monitor e-mails and phone-calls. The regulations allow business and public authorities to record or monitor communications without the caller's consent in such cases as:

* Recording evidence of transactions;
* Ensuring compliance with regulatory or self regulatory rules orguidance;
* Gaining routine access to business communications;
* Maintaining the effective operation of their systems;
* Monitoring standards of service and training; and
* Combating crime and the unauthorised use of their systems.

RIPA (the Regulation of Investigatory Powers Act 2000) establishes a new legal framework to govern the interception of communications in the course of their transmission on public or private telecoms systems. It also establishes a basic principle that communications may not be recorded or monitored without the consent of the senders and recipients. The purpose of the Lawful Business Practice Regulations is to make sure that legitimate business practices are not prevented by the new regime.

The Act ensures that the UK's interception regime is compliant with the Telecoms Data Protection Directive which requires Member States to protect the confidentiality of communications. The Lawful Business Practice Regulations take advantage of the scope allowed by the Telecoms Data Protection Directive for Member States to limit the general prohibition on interception without consent in order to ensure that businesses may record or monitor communications to obtain evidence of transactions or other business communications.

Hope this helps.

Streaky

PS - note the "and" in the emboldened text above. It is no good (in the UK) just having the consent of one party - S

>> Edited by streaky on Monday 21st March 15:59

birdbrain

1,564 posts

269 months

Monday 21st March 2005
quotequote all
Moral of the story, never send/receive anything you really don't want others to see from your work email.

Don

28,378 posts

314 months

Monday 21st March 2005
quotequote all
birdbrain said:
Moral of the story, never send/receive anything you really don't want others to see from your work email.


Absolutely. We couldn't guarantee the privacy of e-mail if we wanted to! So all employees have to accept - the business e-mail address is NOT private.

We do allow private use...we just warn everyone NOT to keep or send e-mails they're unhappy about anyone else reading!

skittle

312 posts

291 months

Monday 21st March 2005
quotequote all
Don said:

birdbrain said:
Moral of the story, never send/receive anything you really don't want others to see from your work email.



Absolutely. We couldn't guarantee the privacy of e-mail if we wanted to! So all employees have to accept - the business e-mail address is NOT private.

We do allow private use...we just warn everyone NOT to keep or send e-mails they're unhappy about anyone else reading!


This is particulary relevant for govt. bodies under the new FOI act

BliarOut

72,863 posts

269 months

Monday 21st March 2005
quotequote all
Just use your hotmail

D4V KC

644 posts

269 months

Monday 21st March 2005
quotequote all
BliarOut said:
Just use your hotmail

Yep, simple as that really!

busa_rush

Original Poster:

6,930 posts

281 months

Monday 21st March 2005
quotequote all
Thanks, they've taken a copy of various people's mailboxes to check. Somebody left the company last year and is taking the company to an Industrial Tribunal and the mailboxes copied are of people who may or may not have helped this person. (about 6 of us)

My work mailbox contains nothing but work e-mail, I'me very careful not to use it for anything else and there's nothing in there that I wouldn't want anybody in the company to see.

I know the mailboxes were copied as I have the event logs from the Exchange server and a screen shot showing processes running under that user's ID including one process that's only used for this task. Any Exchange admin will know what I'm talking about.

I guess that it's possible that as the mailboxes were taken without the users being made aware, their use in court could be very limited, similar to theft of a letter etc ?

Imadreamer

353 posts

276 months

Monday 21st March 2005
quotequote all
I'm an IT manager and look after the email servers at my work. Also look after data protection issues.

See the below guidance taken from our (very good/well respectedin the City) company lawyer: (includes Internet monitoring as well)

Monitoring E-mail and Internet Use

In the UK, it is unlawful to intercept electronic communications unless the interception has been authorised, whether by a warrant, by consent, or by regulations. Regulations that came into force in October 2000 provide circumstances in which a business can lawfully intercept e-mails (and telephone calls) made on its own systems, such as:-


Gaining routine access to business communications;

Monitoring standards of service and training;

Preventing or investigating crime; and

The unauthorised use of systems.
There are other conditions on monitoring found in these Regulations, the Human Rights Act and guidance from the Data Protection Commissioner, including:-


The employer must have taken all reasonable steps to inform the recipient and caller that the e-mail and/or phone call will be intercepted.

The employer must be open about monitoring. Therefore, the limits of personal use should be set out and any restrictions specified. Ensure that employees know that their e-mail and internet use will be monitored before they begin using it or before monitoring begins.

The employer should not intrude on the privacy of the employee and provide a mechanism for employees to delete e-mail from the system.

Where possible, monitoring should be limited to an automated process. Do not monitor the content of e-mails unless the traffic record alone is not sufficient and do not open e-mails which are clearly personal.

Any personal information that is found that concerns employees must be used fairly.

The employer must establish a business purpose for monitoring (for example, to ensure that working time is used productively),and ensure that the impact on staff is not out of proportion to the benefits to the employer.

Do not monitor web sites visited/content viewed unless the business purpose cannot be achieved by recording the time spent on the internet.

In using the results of monitoring, take into account the ease with which sites can be visited by accident, and always give the employee an opportunity to explain or challenge the results.

If you permit employees to access the internet for personal reasons, ensure that no record is kept of the sites visited. If this is not technically possible, you must ensure that employees are made aware of what is retained and for how long.

Conclusion

As for monitoring e-mail and internet use, as an employer you can do so if your purpose falls within the circumstances set out above and you have made your employees and all recipients aware that the communication may be intercepted, provided you do so in an appropriate and proportionate manner.

If implementing a new policy, notify all employees by memo or circular that there will be a change of their contract terms, identify the date of implementation and give employees an opportunity to review the policy. Any policy can only be effective if it has been brought to the attention of employees and they follow it. The best approach is not to rely only on a policy but also to educate your employees on the correct use of e-mail and the internet.

Finally, bear in mind that a policy will not be effective unless it is enforced. An employer cannot turn a blind eye to abuse of an existing policy then expect to suddenly enforce it against one or a number of employees. Such an unfair approach could easily backfire on the employer



>> Edited by Imadreamer on Monday 21st March 23:03

streaky

19,311 posts

279 months

Tuesday 22nd March 2005
quotequote all
As Imadreamer's policy points out (and I highlighted above), the employer must have taken all reasonable steps to inform the recipient and caller that the e-mail ... will be intercepted.

If you communicate with me from your employer's e-mail address and your employer monitors (intercepts) that e-mail and I don't know this will happen ... your employer is breaking the law.

busa_rush - in the case you mention above, the following applies (assuming your employer and mail server are in the UK):

1) For internal e-mails only, if employees were not previously aware that their e-mails could be intercepted (copied, monitored, whatever) - your employer has (very probably) broken the law. Criminal santions against individuals may apply.

2) If employees were previous aware, but any of those e-mails were to persons outside the organisation - who were not themselves previous aware that the e-mails could be intercepted - your employer has (very probably) broken the law. Criminal santions against individuals may apply.

The main piece of legislation in question is the Regulation of Investigatory Powers Act 2000 (RIPA). The title of this does not immediately indicate its application, but it updated the Interception of Communications Act 1985 - which had a more pertinent name.

Although generally aimed at providing a legislative framework for the interception of communications by various investigative services and for the handing over of encryption keys to the authorities upon request, the Act has wider consequences.

In particular and of relevance here, the Act provides an environment whereby:
* interception of communications on an organisation's own telecommunications networks, including computer communications such as e-mail, are unlawful unless in accordance with RIPA or the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000:
* unlawful interception on an organisation's own telecommunications networks may lead to criminal sanctions against an individual operating without the organisation's authority;
* unlawful interception on an organisation's own telecommunications networks may lead to civil action against the institution where the organisation authorised the interception.

The Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 can be found here: www.hmso.gov.uk/si/si2000/20002699.htm

There are, as usual, several 'get-out' clauses for the organisation. One or more of these may apply in the case you mention.

If you busa_rush are the "system controller" (i.e. a person with a right to control the operation or use of the e-mail system) who was involved in the copying of e-mails, make sure you have an instruction in writing from your line manager so to do (or whisper in the relevant person's ear to this effect). Ideally, somewhere up the chain there should be an instruction signed by the Company Secretary - strengthening the overall legitimacy of the request.

Streaky


>> Edited by streaky on Tuesday 22 March 11:11

busa_rush

Original Poster:

6,930 posts

281 months

Tuesday 22nd March 2005
quotequote all
Thanks, that's interesting.

Deva Link

26,934 posts

275 months

Tuesday 22nd March 2005
quotequote all
We have an issue when people leave - both our HR and IT departments (probably working in concert) say we can't monitor emails sent to the person who has left. So their account gets deleted and any email sent to them just bounces.
In our business people usually move to competitors so they get marched out straight away but it becomes very difficult for us to pick up all their current customer activity.

wiggy001

7,367 posts

301 months

Tuesday 22nd March 2005
quotequote all
BliarOut said:
Just use your hotmail


Is it still the case that Hotmail (or was it Yahoo?) emails get cached as internet pages on the user's hard-drive?

I know after the break-up, I was able to read all emails received by my ex just by scanning the c: drive for the relevant HTML files (she used webmail online, rather than downloading).

Made for very interesting reading...

MilnerR

8,273 posts

288 months

Tuesday 22nd March 2005
quotequote all
If i'm sending anything personal I always use PGP. That way, even if they do read yuor emails it'll be nothing but encrypted junk. I know its not infallible but its good enough for day to day use.

jacko lah

3,297 posts

279 months

Tuesday 22nd March 2005
quotequote all
Don said:

birdbrain said:
Moral of the story, never send/receive anything you really don't want others to see from your work email.



Absolutely. We couldn't guarantee the privacy of e-mail if we wanted to! So all employees have to accept - the business e-mail address is NOT private.

We do allow private use...we just warn everyone NOT to keep or send e-mails they're unhappy about anyone else reading!


Use a web based email address like me ?????@mk2cav.com