5 ms·
If you are 'god'-level admin on any enterprise mail server I've ever used you can read users email or even manipulate it in transit. This is intentional, all bu
by def8cefe 7y ago
If you are 'god'-level admin on any enterprise mail server I've ever used you can read users email or even manipulate it in transit. This is intentional, all business correspondence is property of the organisation.
- Kwantuum 7y agoAlso likely illegal in most of the world.
- GhostVII 7y agoUnder what laws would it be illegal? I think it is completely reasonable for a company to have access to all data on company-provided accounts, so long as the employees aren't mislead into thinking it is private.
- distances 7y agoThis is a big difference between Europe and US. I think different European countries require different levels of strictness -- it may be employer isn't allowed to even track who are the correspondents, let alone reading the email contents.
- kube-system 7y agoIt is regulated in Europe, not banned. In general, employers can read your email, they just have to do it a certain way. Here's a guide for UK employers: https://uk.practicallaw.thomsonreuters.com/2-107-4386?transitionType=Default&contextData=(sc.Default)&firstPage=true&bhcp=1 https://uk.practicallaw.thomsonreuters.com/2-107-4386?transi...
- revax 7y agoI don't know for the rest of the world, but in France you can indicate your mail being private by adding a prefix to the subject of your mail with "Privé". Then the "secrecy of correspondence"[1] apply. Some company restrict the usage of private messages using the company-provided mail, but it is not the default case. The company cannot access those messages without your consent or without a suspicion of a crime (like a leak of data). [1] https://en.wikipedia.org/wiki/Secrecy_of_correspondence https://en.wikipedia.org/wiki/Secrecy_of_correspondence Source in French with some court's judgement : https://www.arobase.org/entreprise/email-personnel.htm https://www.arobase.org/entreprise/email-personnel.htm
- SanchoPanda 7y agoIn my industry it would be explicitly illegal not to log and monitor all employee emails when they are using a corporate email or a personal email if that personal email was used for business purposes. This is by design and not contradicted by any privacy laws.
- d4mi3n 7y agoSecurity guy working in fintech: this is true of many industries that need to adhere to regulation or compliance, including: 1. Finance 2. Medicine 3. Aeronautics There are likely more I'm personally unaware of. In finance, which I'm most familiar with, lenders (sometimes banks, but can be things like credit unions, marketplace lenders, or investors) have a laundry list of regulations they need to meet in order to business in the US. Many of these regulations explicitly require that the lender produce any and all communications between the lender and borrower on-demand--and for good reason. There's a long history of bad actors in finance lying or misrepresenting things in official communications (fraud, embezzlement, money laundering, etc). If you work for any finance company, you had better expect that everything you do on your corp accounts/devices will be logged, audited, and periodically reviewed. That said, the only time I've heard of an employees' email being pulled out of an archive and read were due to concerns around IP theft or questionable behavior between said employee and business clients.
- goatinaboat 7y agoMany of these regulations explicitly require that the lender produce any and all communications between the lender and borrower on-demand--and for good reason. This is why traders WFH during coronavirus lockdowns is so problematic; not only a lack of externally accessible recorded phone lines but the impossibility of policing OOB communications when the local compliance guy can’t physically see you talking on your mobile phone.
- d4mi3n 7y agoThen it should not surprise you to know that phishing attempts have spiked in recent months. The pandemic has sewn much chaos, and bad actors are taking advantage. :( What really concerns me is that these phishing attempts are just the attacks we're observing. Many more will go unnoticed given how ad-hoc current work environments have become with so many organizations going full-time remote overnight without the IT/security systems and processes in place to safely support it.
- reaperducer 7y agoAlso likely illegal in most of the world. Where "likely" means "I'm not a lawyer so I'm just guessing here" and "most" means "I read on HN that Europe likes privacy."
- Carpetsmoker 7y agoIn the Netherlands there was a court case which ruled that an employer cannot just read an employees work email, as even work-related emails are considered private information. There are some exceptions of course: if you notify the employee and have a justified reason you can check some emails. So it's not outright forbidden. It matters a lot on the case and what you did, exactly. I'm not aware of the situation in other countries. (In Dutch: https://www.cnvvakmensen.nl/nextnow/blog/2016/march/mag-de-baas-jouw-e-mail-lezen https://www.cnvvakmensen.nl/nextnow/blog/2016/march/mag-de-b... and https://www.sprengersadvocaten.nl/publicaties/wanneer-mag-een-werkgever-zich-toegang-verschaffen-tot-de-mailbox-van-een-medewerker/ https://www.sprengersadvocaten.nl/publicaties/wanneer-mag-ee...)
- Skunkleton 7y agoI like this personally. I can have a private conversation with a coworker in the break room, why not by email? If I wanted to include my boss I would have CC'd her. This is not the current state of the law in the US however.
- saagarjha 7y agoCan an employer set up a microphone in the break area without letting you know?
- mentat 7y agoDepends on the state. I believe there are several in which the answer is "yes". https://www.justia.com/50-state-surveys/recording-phone-calls-and-conversations/ https://www.justia.com/50-state-surveys/recording-phone-call... Also, depends on to what extent that room can be considered public. (IANAL TINLA)
- manigandham 7y agoAccess for auditing and security is not only legal but actually required in many regions. Even editing is allowed (automatic disclaimers, file scanning, data loss prevention, etc).
- duxup 7y agoI know that in some parts of the world using a work phone or work email for personal use is protected (I think it is a little silly, but not a big deal), but that's not quite what you sound like you're describing. I'm not at all sure that I've heard of many places where your employer explicitly ISN'T allowed to access employer provided resources. If that were the case generally I'm not sure how anyone would even provide security or etc.
- kube-system 7y agoSome countries have limits on which emails can be monitored or how often it can happen. I haven't heard of any where it is forbidden. I can't imagine how hard it would be to run a business in a jurisdiction where that would be the case. How would you handle audits, employee turnover, records retention, civil suits, etc?
- bradly 7y agoFor public companies in the US it is illegal not to.
- sbilstein 7y agothe reason for this power isn't just for abuse of power, it's literally to prevent fraud and reduce liability. You need to know if your dev is exfiltrating PII to his buddy who is a scammer, if your employees are participating in bullying or discriminatory behavior, etc. Work is work, it's not your personal life.
- abruzzi 7y agoWhere I work, anyone in the world can read my emails. You just have to make a request, and we have 15 days to provide the email. There are some cut-outs like attorney/client communication or health related, but pretty much any email I’ve ever sent or received is subject to inspection by any member of the public. (Most government entities have a similar law and it generally more open than the Fed’s FOIA.
- koheripbal 7y agoI can confirm as a GSUITE Enterprise admin and that this is correct and is done at multiple companies I've worked for, for a variety of business use-cases (things like detection of data-exfiltration, compliance, regulatory monitoring, lawsuit investigations, etc...) Courts (at least in the US) have repeatedly ruled that employees have no reasonable expectation of privacy when using company email systems.
- BrandoElFollito 7y ago> all business correspondence is property of the organization This depends on the country. Absolutely not in France (and probably most of EU), if by business you mean "within a company" (which would be aligned with the idea of looking at correspondance")