Your Employer Can Monitor You More Than You Think. Here's What's Legal and What Isn't.

Your Employer Can Monitor You More Than You Think. Here’s What’s Legal and What Isn’t.

There’s a version of workplace privacy a lot of people still carry around, dating from before a laptop had a webcam and before “work” meant a device that travels home in a backpack every night. That version assumed a reasonable zone of privacy at your own desk, on your own screen, during a coffee break. The legal reality has drifted a long way from that assumption, and it’s drifted almost entirely in one direction: toward employers having considerably more latitude than most employees think, with real but narrower limits than people assume actually exist.

What’s Actually Legal on a Company-Owned Device

Start with the baseline, because it surprises most people. On a device your employer owns, connected to a network your employer controls, the default legal position in the U.S. favors the employer almost completely. Reading work email, logging keystrokes, taking periodic screenshots, tracking which applications and websites get used during work hours, and recording time spent active versus idle are all generally lawful practices, and courts have consistently found that an employee’s expectation of privacy on employer-owned equipment is minimal, particularly where a company has any kind of monitoring policy in writing, even a vague one buried in an employee handbook.

This extends further than most people expect. Video surveillance in common work areas is broadly permitted. GPS tracking on company vehicles or company-issued phones is generally lawful. Even monitoring during breaks taken at a company-owned workstation typically falls within an employer’s legal latitude, since the device and network remain company property regardless of what the employee happens to be doing on them in a given moment.

What Changes on Your Personal Device or Personal Time

The legal picture shifts, though less dramatically than people hope, once a personal device or personal time enters the picture. An employer generally cannot access a personal phone or personal computer without consent, and several states have specific laws protecting off-duty conduct on personal time and personal accounts, including provisions in some states barring employers from requiring access to personal social media passwords. But this protection has real limits worth understanding precisely: if a personal device connects to a company network, uses company VPN software, or has a company-mandated security or device-management application installed on it, that connection point itself can become a legitimate basis for employer visibility into at least some of what happens on that device while connected, even though the device itself is personally owned.

This is precisely the gray zone where a growing share of monitoring disputes actually originate — not “can my employer read my personal texts” (generally no, absent a specific and narrow set of circumstances), but “does installing this company security app on my personal phone give my employer more visibility than I realized” (frequently yes, to a degree many employees don’t anticipate when they agree to the installation).

The Federal Government’s Own Concerns About Where This Was Heading

Regulators have been paying closer attention to this shift than most employees realize. The National Labor Relations Board’s General Counsel issued a formal memo in October 2022 expressing concern that increasingly intrusive electronic monitoring and algorithmic management tools — including wearable devices, GPS tracking, keyloggers, and software capturing screenshots, webcam photos, or audio recordings throughout the day — could interfere with employees’ rights to discuss workplace conditions and organize under the National Labor Relations Act, proposing a framework that would require employers to justify such monitoring against a genuine business need. It’s worth being precise and current about this memo’s actual legal weight: it represented enforcement guidance and a proposed legal theory rather than an adopted regulation, and it was subsequently rescinded by a new acting general counsel in February 2025 along with a broader set of prior guidance memos. The underlying concern hasn’t disappeared from the regulatory conversation, but the specific enforcement framework it proposed is no longer active federal guidance, which is a meaningful and often overlooked detail in a topic that moves this quickly.

This matters for how to actually read the current landscape: the technologies the memo flagged as concerning remain widely deployed and, in most cases, legally permitted absent a state law specifically restricting them, even though the particular federal labor-law theory challenging their use is not currently in force.

The Gap Between What’s Legal and What People Actually Expect

There’s a meaningful public opinion gap worth understanding here, because it shapes how monitoring policies actually land with employees even where they’re fully lawful. Pew Research Center’s national survey found that 68% of full-time workers oppose employers using AI to track workers’ movements while they work, with majorities also opposing AI systems that keep track of when office workers are at their desks or record exactly what people are doing on their computers. That’s a substantial gap between legal permissibility and actual worker comfort — the practices described are, in most U.S. jurisdictions, lawful on company equipment, yet a clear majority of the workforce affected by them opposes their use. That gap doesn’t change the legal analysis, but it’s worth an employer’s attention for reasons well beyond compliance, since Pew’s research also found majorities expect this kind of monitoring to make employees feel inappropriately watched, regardless of its legal status.

Where Actual Legal Limits Do Exist

Despite how permissive the general framework is, real limits genuinely apply in specific areas. A handful of states, including New York, Connecticut, and Delaware, require employers to provide advance written notice before conducting certain kinds of electronic monitoring, meaning the monitoring itself may be legal but doing it covertly, without disclosure, is not, in those specific jurisdictions. Recording audio conversations without appropriate consent runs into wiretapping laws that vary meaningfully by state — some require only one party to consent, others require every party to the conversation to agree, and an employer recording a call without meeting the applicable standard can face real legal exposure regardless of whose device the call happened on. Biometric data specifically, such as fingerprints or facial recognition scans used for time-clock systems, faces some of the strictest rules in the country in states like Illinois, where courts have allowed substantial legal claims against employers that collected biometric data without the specific consent and disclosure procedures state law requires.

This connects to a broader discipline worth building generally around digital exposure. Our guide to protecting your privacy when using AI covers a related instinct — checking the actual settings and policies governing a tool rather than assuming defaults are protective — and the same instinct applies directly here: reading an employer’s actual written monitoring policy, rather than assuming a comfortable but unverified level of privacy, is the single most useful thing most employees never actually do.

A Practical Way to Think About Your Own Exposure

Given how permissive the baseline legal framework actually is, the practical response isn’t outrage at any specific monitoring practice — most of what employers do is legal, and complaining about legality where none is actually violated wastes energy better spent elsewhere. The more useful posture is treating any company-owned device, company network connection, or company-installed application as fully visible to your employer by default, regardless of what you’re personally doing on it, and reserving genuinely private activity and communication for a personal device on a personal network with no company software installed. Our guide to what data you should never give AI covers a related principle worth extending here directly — treating any digital environment you don’t fully control as a place where privacy can’t be assumed, which is exactly the right default for a company-managed device or network.

A Concrete Walkthrough of a Common Gray Area

It helps to see how this actually plays out in a specific, realistic scenario. An employee uses a personal laptop for work because their company operates on a bring-your-own-device policy, and IT requires installing a mobile device management application to access company email and shared drives. That application, once installed, often has the technical capability to see far more than just work email — depending on its configuration, it may be able to see installed applications, general device activity, and sometimes location data, on a device the employee still considers, understandably, to be personally owned.

The legal reality sits in an uncomfortable middle ground here. The employer generally isn’t violating the law by requiring this software as a condition of accessing company systems, and the employee generally did technically consent by agreeing to the company’s device policy, even if they didn’t read every detail of what that policy actually enabled. But the employee’s practical expectation of privacy on their own personal device was, without much deliberate thought on anyone’s part, meaningfully narrowed the moment that software was installed. This is precisely the kind of gap between technical legality and lived reality that catches people off guard — not a dramatic violation, but a quiet expansion of visibility that both sides technically agreed to without either fully registering what that agreement actually meant in practice.

A Quick Audit of Your Own Monitoring Exposure

A useful, honest exercise: list every device and account connected in any way to your employer — your work laptop, a personal phone with company email or a security app installed, a company VPN client, any wearable or vehicle tracker tied to your job. For each one, ask specifically whether you’ve ever actually read the monitoring policy governing it, or whether you’re simply assuming a level of privacy nobody at your company has ever actually confirmed. Most people, being honest, will find at least one device in that list where the honest answer is the latter, which is exactly where a genuine gap between assumption and actual legal reality is most likely sitting unexamined.

Frequently Asked Question

Can my employer read my email or track my computer activity?

Yes, generally, on a company-owned device or company network. Reading work email, logging keystrokes, taking periodic screenshots, and tracking application and website use during work hours are broadly legal in the U.S., particularly when a company has any written monitoring policy in place, even one included in an employee handbook.

Can my employer monitor my personal phone or personal computer?

Generally not directly, but connecting a personal device to a company network, VPN, or installing a company-required security application can give an employer visibility into at least some activity on that device while connected, even though the device itself remains personally owned.

Does my employer have to tell me if I’m being monitored?

In some states, yes. New York, Connecticut, and Delaware require employers to provide advance written notice before conducting certain kinds of electronic monitoring. In many other states, no specific notice requirement exists, meaning the monitoring itself may still be legal even without direct disclosure.

Is it legal for my employer to record my phone calls or conversations?

It depends on the state. Some states require only one party to a conversation to consent to recording, while others require every party to agree. An employer recording a call without meeting the applicable state’s consent standard can face legal exposure regardless of whose device the call took place on.

Did the government ever try to limit employer monitoring specifically?

The NLRB’s General Counsel issued a memo in October 2022 proposing that certain intrusive electronic monitoring practices could violate workers’ rights to organize under federal labor law. That memo was rescinded in February 2025 by a new acting general counsel, meaning the specific enforcement framework it proposed is not currently active federal guidance.

How do most workers feel about being monitored, even where it’s legal?

Pew Research Center found that 68% of full-time workers oppose employers using AI to track their movements at work, with majorities also opposing tracking of desk time and computer activity, even though these practices are generally lawful on company-owned equipment in most U.S. states.

Conclusion

The legal reality of workplace monitoring in the U.S. leans heavily toward employer discretion on company-owned equipment and company networks, with real but narrower protections kicking in specifically around personal devices, audio recording consent, biometric data, and a handful of state-specific notice requirements. Federal labor-law guidance has pushed back on the most intrusive uses, though the specific framework proposing that pushback is not currently active guidance, which is worth tracking rather than assuming settled.

The practical takeaway isn’t paranoia — it’s calibration. Treat anything on a company-owned device or company-connected network as visible by default, read the actual monitoring policy rather than assuming one, and reserve genuinely private activity for equipment and networks with no company presence on them at all. That single habit closes most of the gap between what people assume about workplace privacy and what the law actually allows.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *