Can an employer monitor employees’ email? The law in the UK

Do employers have a right to monitor workers’ email? Yes, within limits, and the limits are tighter than the headlines of January 2016 suggested. That month the European Court of Human Rights decided the case of a Romanian engineer, Mr Bărbulescu, who had been dismissed after his employer read the Yahoo Messenger account it had asked him to set up for work and found personal messages on it. The court’s first ruling went the employer’s way, and this article, when it was first written, said so. In September 2017 the Grand Chamber reversed that decision and held, by a majority, that Romania had failed to protect Mr Bărbulescu’s private life (Bărbulescu v Romania, Grand Chamber, 5 September 2017). The practical advice below was sound in 2016 and is sounder now.

What Bărbulescu decided

An employer may monitor its staff’s communications, but only within a framework that protects them. The Grand Chamber listed what a court will look for: whether the employee was told in advance, and clearly, that monitoring might take place and what kind; how far it went, and in particular whether the employer looked at the flow of messages or read their content; whether the employer had a legitimate reason for monitoring at all, and a weightier one for reading content; whether a less intrusive method would have done; what the consequences for the employee were; and whether there were safeguards, so that content could not be read unless the employee had been warned. Mr Bărbulescu lost his job on the strength of 45 pages of transcripts of private conversations that he had never been told could be read. That is the line an employer in this country should assume it cannot cross.

The position in the UK

Employers here have the right to monitor employees’ use of company resources, including computers, telephones and email accounts, provided they have a legitimate reason, tell staff what is monitored and why, and keep the monitoring proportionate. The rules come from three places: the UK GDPR and the Data Protection Act 2018, which treat monitoring as processing of personal data and require a lawful basis, transparency and a data protection impact assessment for anything intrusive; the Investigatory Powers (Interception by Businesses etc.) Regulations 2018, which allow a business to intercept communications on its own systems for defined purposes such as detecting crime, checking compliance and protecting the system, but only if it has made reasonable efforts to tell users that interception may happen; and the Human Rights Act, which carries Bărbulescu into every tribunal. The Information Commissioner’s guidance on monitoring workers, published in October 2023, sets out what that means in practice, and covert monitoring is reserved for exceptional cases where telling the worker would prejudice the prevention or detection of crime.

Employers cannot monitor employees’ personal devices without their agreement, and they cannot reach into personal accounts. A work computer is the employer’s; the employee’s Gmail account, even when opened on that computer, is not, and an employer who reads it is on the wrong side of both data protection law and the Computer Misuse Act 1990. Activity outside work, on personal social media and personal email, is off limits unless it bears directly on the job or there is a specific legal reason to look. My advice to employees has not changed: do not check your personal email on the work computer at all, because there may be circumstances in which the employer is justified in looking at what passes over its system, and nothing good comes of testing the boundary.

Why employers monitor, and what good practice looks like

Employers monitor to protect intellectual property, to preserve the reputation of the business and to protect other staff and third parties. An employee who defames or harasses someone through the work computer can make the employer vicariously liable, so there are circumstances in which an employer is duty bound to keep an eye on what leaves its systems. Good practice is straightforward: a written policy that says what is monitored, how and why; a rule that staff do not use personal email or messaging accounts to communicate on behalf of the business; a clear statement that the employer reserves the right to monitor its systems; and a habit of looking at the least that will answer the question, traffic before content, a sample before the lot. The case people still cite against the technology companies, Microsoft’s reading of a blogger’s Hotmail account in 2014 to trace a leak of its own software (NBC News, March 2014), was a provider reading a customer’s account, not an employer reading an employee’s, and it illustrates the point: the outcry forced Microsoft to promise never to do it again without going to court. The same restraint is now expected of employers.

First published 10 February 2016. Reviewed and updated 28 September 2026.

Scroll to Top