9 ms·
Installing an extension to monitor employee use of a company computer is legal and generally accepted behavior. If the Google calendar is for a personal gmail
by robbya 7y ago
Installing an extension to monitor employee use of a company computer is legal and generally accepted behavior.
If the Google calendar is for a personal gmail account, then accessing the calendar details server side is a huge privacy breach.
- usr1106 7y ago> Installing an extension to monitor employee use of a company computer is legal and generally accepted behavior. Legal and generally accepted in US jurisdiction. In Germany that would require approval by employee representatives, unlikely to happen in any bigger company. In Finland a somewhat related and highly controversive law was introduced many years ago that it would be legal if registered with data protection authorities. Something like 3 companies registered in a decade. Maybe some did it without registering, but generally this is not deemed clearly acceptable practice.
- DeckOfSardines 7y agoCan you expand on this point? I wasn't sure if your point was that this might hinder Google expanding in other countries or if you were just taking issue with the phrasing.
- usr1106 7y agoMy point was just to show that legal systems differ and the balance between employer and employee rights can vary. Google has a big data center in Finland. IIRC they stopped their plans for a Berlin lab after visible anti-Google protests in the neighborhood, but I'm sure they have employees somewhere in Germany. International companies just follow local legislation and practices and there is no problem (most of the time at least, there are examples of failure like Walmart trying to expand to Germany with too much of an American management style and eventually giving up).
- jeltz 7y agoGoogle already have expanded to plenty of countries, and presumably in some of them this kind of monitoring would be illegal.
- skissane 7y ago> If the Google calendar is for a personal gmail account, then accessing the calendar details server side is a huge privacy breach. Surely, Googlers have separate work and personal Google accounts, and only the former would be used with the Google corporate calendar? Article says that one of the things which triggers a report is booking more than 10 meeting rooms for a single meeting – surely, a Googler's personal account would lack permission to book meeting rooms in their corporate offices, and only their work account would have permission to do that?
- beerandt 7y agoBut the account associated with reserving the rooms surely mitigates that privacy issue. After all, the rooms belong to Google.
- chongli 7y agoIt’s not legal if employers specifically use it to disrupt employees’ attempts to organize. The NLRA specifically grants employees the right to organize and it prohibits employers from monitoring these organizing employees. The fact that Google employees, in this case, may not be considering forming a union at this time is irrelevant. The meetings they are having may prompt them to form one at a later time. Either way, their freedom of association is protected.
- ChuckMcM 7y agoLike it was a "safety hazard" to have too many people at once in the smoking area behind the textile mill. It is a slippery slope to try to tease apart what is, and what isn't, interference right? Google also has a clause in their employment agreement that says you agree to them putting surveillance software on your devices, company supplied and personal, as a condition of your employment. I asked about that one, got the HR response "Well I suppose you could interpret it that way, but that isn't what we mean." and I said, "Okay, lets change it to say what you mean." and got the "Well we really aren't in a position to change these documents, it would be a mess trying to track a zillion individual agreements." etc etc. That rabbit hole of pushing back and forth leads to "perhaps Google isn't the right place for you." :-)
- defen 7y ago> Google also has a clause in their employment agreement that says you agree to them putting surveillance software on your devices, company supplied and personal, as a condition of your employment. How would Google even know about your personal devices? That seems to only make sense if you intend to use your personal device for work.
- manfredo 7y agoIt's not even an unusual condition. At Dropbox, starting some time in either 2018 or 2019 we had to install a remote administration app on our devices if we wanted to connect to corp vpn or to log into corporate google accounts. Mostly so that the device could be wiped if it was lost, IIRC.
- deleted 7y ago[deleted]
- Iv 7y agoNot in all countries.
- stiray 7y agoJust to add EU view on "legal". This is highly illegal and it is criminal offense in same manner as wiretapping. You (as employer, even if you own employee computer) can get jailtime for this although hefty fine is more plausable. Before employee leaves the company, its manager is responsible to get all the company data stored (by leaving employee) on another computer, then IT takes the computer and wipes all the drives, with at least two persons present.
- meowface 7y agoIt is funny how cultures and legal systems differ. In US corporate culture, it's very ingrained that things done with company property belong solely to the company, and that the company has a right to look at company property and data at any time, for any reason. A big portion of one of my information security jobs involved looking at employees' browsing history and emails daily. Sometimes to investigate potential misconduct (something dumb like a manager wanting to see if someone's slacking off, or something serious like suspicion of stealing information), but usually to investigate potential security issues (like if we believed a computer visited a malware-associated web page, we wanted to see how the computer ended up there). In the US, pretty much no one bats an eye that this is considered necessary and normal. Employees who don't want to be snooped on are free to use their personal devices at work, like their phones, which of course we have no access to. But it's considered very normal that if an employer gives you a computer to use for work, that they can inspect that computer and data to and from it. No one has a feeling of their privacy being violated, because there's no expectation of privacy when using someone else's (the company's) property. For infosec operations people in European countries, how are these things handled? How do you investigate potential breaches which originate from endpoints? Do you have to ask the employee if you can look at their browsing history? What if it's a potential misconduct investigation, where tipping someone off may result in destruction of evidence?
- normalnorm 7y ago> No one has a feeling of their privacy being violated, because there's no expectation of privacy when using someone else's (the company's) property. Excellent. Now you only have to remove the expectation of privacy in any situation from the social norms, and another big problem will be solved. You will be able to live under total surveillance without anyone feeling that their privacy is being violated, because there was no expectation of privacy to begin with. An alternative hypothesis (crazy, I know...), is that the power imbalance in favor of the rich went very far in the US, which means that the poor have no safety net or ability to organize, so they are completely at the mercy of the whims of corporations for survival. And so, they will accept many indignities without bating an eye.