Abstract
One of the key conflicts in today’s workplace has been quietly coming to a head. Each day, millions of workers arrive at work with their personal phones, personal bags, and personal lives — and many employees don’t know just how much their employer is legally entitled to look at, search, and record.
This article explores two key issues facing all working individuals in 2026: Can your employer search your bag at work? Can they read your personal chats like WhatsApp, iMessage or private emails when you are at work? The answers to both these questions are short and simple: It depends. This will vary depending on your country, your device, your contract and whether your employer has notified you of this. A simple yes or no question is actually a legal minefield impacted by privacy legislation, employment contracts, court rulings, and evolving standards of what is reasonable for the workplace. This topic is more important than ever in 2026. Monitoring tools are now adopted into the mainstream due to hybrid and remote working. Surveillance software, also known as ‘bossware’, is now monitoring keystrokes, taking screenshots, tracking app usage and more, even eye movements. Meanwhile, courts and regulators around the world – in the United States, UK, the EU and India – are tightening their grip on what constitutes an illegal intrusion. The relationship of employer supervision and employee privacy is still being negotiated and will have an impact on the workplace over the next ten years.
What the Law actually says, the Baseline Rules.
In private sector workplaces, employers have a lot more control than employees think about them when it comes to surveillance. That power is not unlimited though.
In the United States, the Fourth Amendment that guarantees citizens against unreasonable government searches only covers the government. However, if you’re employed with a private business, that constitutional protection doesn’t protect you at work. While it may be possible for employees to use their own devices, it is generally not possible to monitor the same without a company disclosure in an employment policy or without taking the case to court. ECA prohibits intercepting communications without consent, but most employers avoid this by having a blanket monitoring consent clause in their onboarding contracts which most employees sign without reading carefully.
In the United States federal law mandates no notification to workers that they are being monitored. That duty lies at the state level and currently only a few states have done so. For instance, prior written notice is required in Connecticut and Delaware before the use of electronic monitoring begins. But most other states do not.
It’s a different way of doing things in the UK. Compliance with GDPR and the Data Protection Act 2018 means employers are required to have a lawful basis for processing employee information, to inform their employees that they are being monitored, and ensure that any monitoring is proportionate to the legitimate purpose of the processing. There is a clear expectation, as stated in the UK’s Employment Practices Code published by the Information Commissioner’s Office (ICO): covert monitoring should only take place in rare circumstances where an employee is engaging in serious misconduct, and even then it should be narrowed, rather than broadened. The rules are even more stringent throughout the EU.
In Europe, Germany has the best employee privacy protections, and workplace privacy is recognized as a constitutional right. Any monitoring software used by employers in those countries must be approved by the works council. Secret monitoring may only be used where there is documented, concrete suspicion of a specific violation – not where there is general suspicion – and not as a routine management tool. In France, prior notification must be made by the internal data protection policies and consultation with the works council. Under GDPR, blanket monitoring is de facto prohibited in the EU.
India is undergoing change. The Digital Personal Data Protection Act 2023 has entered into force and is changing the landscape of organizations’ handling of employee data, including an increasing demand to provide information on what is collected and why.
When and how is a Physical Search allowed?
The standard expectation of any employee is that their employer will not open their bag when it is taken to work. In most Western jurisdictions that intuition is technically correct, but not absolutely so. A balancing test is used in the United States where the more intrusive the search, the more compelling the justification the employer must present. Little excuse is needed for an open desk search. But a search of a backpack or personal handbag calls for more. The only valid reason for body searches is a compelling one, and rarely, if ever, are they legally justifiable for private employers. This is a framework which has been created in several judicial decisions and applies to most US states, although that of Washington State has been legislated in certain terms, such as the ban on searching vehicles parked on employer property. In the UK, employers are not legally entitled to search their employees or their possessions. Employers should have a clearly drafted contractual clause allowing for the search of bags, a written policy on what may be searched, who can search and the right to a witness, and the policy should be applied consistently and in a non-discriminatory way.
Employers in the UK should exercise caution with ad hoc searches as there is no policy in place. Commonly, the industries in which bag searches occur, such as retail, financial services, pharmaceuticals, and high-security manufacturing, have clauses in their employment contracts that require the employee to consent to a bag search. These clauses have been generally upheld by courts when the searches are carried out in a dignified manner and are not directed towards groups. No employer can do what no employer can do – in any jurisdiction – search humiliatingly and/or discriminatingly. Randomly stopping workers of a certain ethnic group is the invitation to an employment discrimination claim and a huge blow to their reputation.
A Legally Complex Territory: Personal Chats at Work
The legal jungle really gets interesting now — and where many employees are likely to get their biggest exposure. Who is using that – what network are you on?
Your employer will not have any legal authority to access the contents of the messages if you are using a personal phone, with your own mobile data, to message a friend or friends on WhatsApp. The content is private, the device belongs to you and an employment contract cannot change that. The end-to-end encryption of apps such as WhatsApp makes sure that the messages cannot be read by anyone other than the sender and receiver, not even WhatsApp itself — let alone your employer. But the situation changes if you are using a company-provided phone or a company computer. Employers, employment lawyers always tell their employees: “If it’s on the device, then it’s visible to the employer.” In the United States, UK and throughout the EU, courts have held that employers can gain access to data, such as personal messages from personal accounts, on devices belonging to their employees while the devices are being used on company equipment, as long as the account is used for the company. This is the same for the company WiFi network. Normal network traffic can be seen by anybody who can control the network. While employees may be legally safer in using a personal phone on a company Wi-Fi network to send personal messages, they should be aware that the metadata (who they messaged, when, and for how long) may still be seen by network administrators.
The Barbulescu case that was heard before the European Court of Human Rights in 2017 was a landmark decision in which it was held that the Romanian authorities violated the right to privacy of an employee under Article 8 of the European Convention on Human Rights, by observing his personal Yahoo Messenger account on a work computer. The court determined that notifying employees in advance that their communications can be monitored is a requirement as well as having a legitimate aim and a proportionate means. This is the basis for employee privacy in Europe.
Vendors like WhatsApp and Slack and their growth in workplace messaging.
Growth of vendors such as WhatsApp and Slack in workplace messaging. In the realm of legal risks, messaging apps have generated a new category of risk that impacts not only employers, but also employees. This is the number of cases filed before the Employment Tribunals in the UK that have been referenced to WhatsApp messages, which increased from 48 in 2019 to 562 in 2024, which is almost 12 times the amount in 5 years. Comments made in personal group chat, off-hours chats and even private chats with co-workers are being presented as evidence in disciplinary proceedings, termination proceedings, and even discrimination complaints. The case of Donaldson v Aberdeen City Council was heard in a UK tribunal in 2025 where the employer terminated a staff member who sent obscene photos and text to a group he had set up on WhatsApp during his working hours. The staff member responded that it was “harmless teasing”. The content was deemed to be below the minimum behavioural standards for the work and the dismissal fair. Metrolinx v Amalgamated Transit Union was a case in Canada that involved a WhatsApp group where male employees made derogatory and sexist remarks about a female employee. The employer was tipped off to the conversation due to a screen shot being shared with the affected employee who brought the issue to their attention. Ontario court affirmed that the employer had the right to investigate and discipline on that basis.
These cases show a reality of work: a message sent from a personal cell phone may, if it ends up in a company, is forwarded to a colleague, or is made public via a data subject access request, become evidence in work. End-to-end encryption is technically secure, but doesn’t prevent you from taking a screenshot of a word that you’ve sent to someone.
The regulators are taking things one step further in financial services. As early as late 2024, the US Securities and Exchange Commission (SEC) issued charges to over 100 companies and levied over $2 billion in fines for staff members conducting regulated business activities over WhatsApp, Signal and personal texts. The SEC, for instance, fined 26 firms a total of $393 million in August 2024 for recordkeeping issues related to off-channel messaging. In regulated industries, the message from the regulators is neither ‘informal’, nor ‘business’.
AI Monitoring in 2025 and 2026: The Rise of Bossware.
Monitoring of the old school method (reading e-mail or checking browsing information) has been replaced with something much more advanced. 74% of US employers now routinely use online tracking tools. Another 61% rely on AI-powered analytics to gauge employee productivity or behaviour. 85% of Employers in the UK watch their employees’ online presence. Worldwide 71% of the employees are monitored by a digital instrument in some way.
Contemporary “bossware” logs every keystroke (including delete and pauses), captures random photos every couple minutes, logs active apps and their durations, logs metadata of incoming email, and in some instances records eye movement or facial expressions on webcams. Microsoft Teams has added features that are able to sense a user’s current room within an office. Amazon has been under intense criticism for its social media monitoring to detect and act against union organising.
Many of the types of AI-based workplace monitoring covered by the EU’s AI Act, which is fully in effect in 2024 and 2025, are deemed ‘high risk’. In this classification, employers using these tools are required to carry out conformity assessments, keep technical documentation, establish human monitoring systems and communicate with those affected by the use of the tools. Penalties for non-compliance range up to 30 million euros or 6% of the company’s global turnover each year.
Evidence for the effectiveness of monitoring in improving outcomes is mixed at best, and so are the tools that are adopted aggressively. The Harvard Business Review study from 2024 revealed a productivity improvement between 15-20% for companies that openly communicated the intent behind implementing the monitoring software, shared the results with their employees, and utilized the data to guide as opposed to punish. Those companies that used the same tools covertly or punitively experienced a 25% increase in stress among the employees they were monitoring, while those who were monitored experienced a 2.3 times higher risk of intending to quit.
Employers’ rights and responsibilities: A summary of what employers can and cannot do, and why.
In most jurisdictions, some consistent themes have emerged from the case law, guidance, and legislation: Employers can generally: monitor activity on any of their devices and/or networks; search bags if this is expressly stated in employment contracts and consistently applied; access emails and messages sent using company platforms such as Outlook or Slack; install monitoring software on company equipment, if employees are informed; rely on data from personal communications in disciplinary proceedings, if that data has been voluntarily disclosed or accessed through company systems.
Employers cannot: Monitor personal phones on personal mobile data connections without prior contractual authorization; use AI-based monitoring tools in the EU without complying with the AI Act requirements for high-risk systems; monitor in a discriminatory manner; target monitoring at specific workers (under the US National Labor Relations Act); Conduct bag searches or body searches without prior contractual authority; Access personal accounts on personal devices without consent.
The grey zone falls in the middle: personal communications that occur while using company equipment, messaging applications that are operated via company Wi-Fi, and which messages contain both personal and professional content. Where this occurs, the courts will balance the employer’s legitimate business interest with the employee’s reasonable expectation of privacy and decisions are case-specific and vary according to jurisdiction.
Case Studies
Case – 1 : In 2022, Morgan Stanley was forced to pay $200 Million in failure damages for the company’s failures at WhatsApp.
The US Securities and Exchange Commission and the Commodity Futures Trading Commission slapped Morgan Stanley with a $200 million fine over its inability to capture and retain business communications from employees using their own cellphones, via WhatsApp. Senior staff regularly communicated with clients outside of the scope of the regulations. The case helped to define that, in regulated industries, the phrase ‘I used my personal phone’ is not a defence in court.
Case – 2 : The second case is Amazon Warehouse Monitoring and Union Activity (2024-2025).
In 2024 and 2025, there was a lot of criticism regarding Amazon’s surveillance of employees’ social media use. In February 2025, workers at a facility in Garner, North Carolina voted to not unionise, after Amazon unionized them through a campaign that distributed anti-union messages on devices within the work environment, and surveiled Facebook groups and Reddit forums for any signs of union activity. The Electronic Frontier Foundation and Center for Democracy and Technology called for mandatory disclosure requirements. Monitoring communications to determine if there are union supporters can be an unfair labour practice, the NLRB pointed out.
Case – 3 : Barbulescu v. Romania, European Benchmark (2017)
This decision of the European Court of Human Rights, in the Grand Chamber, is the most important decision in European employee privacy law. A Romanian worker has lost his job after the company used a computer to spy on his personal Yahoo Messenger profile. The court determined that Romania had infringed his right to the private life guaranteed by the Convention, thus ruling that the necessity of giving prior notice to monitoring is a convention obligation, and that the necessity of giving prior notice to monitoring is a convention obligation, even if there is a monitoring in the working environment.
Conclusion
This booklet concludes with a section on where this is heading by 2030. The path ahead to 2030 suggests that employer monitoring will be under greater scrutiny, there will be greater disclosure of employer monitoring systems and tools, and that organisations will be increasingly subject to legal liability if they use a monitoring system or tool without a clear policy framework. There is currently no federal privacy law in the United States that covers the monitoring of employees, although it is possible that there will be legislation in the future. There are more states, such as New York and California, extending monitoring disclosure rules, and federal proposals aimed at AI-based employment decisions are now supported by members of Congress.
Monitoring cases are being actively litigated by civil rights organisations and labour unions, and the pool of case law is expanding rapidly. Once fully implemented, the AI Act will impose significant compliance obligations on employers in the EU who use high-risk AI monitoring tools. In Germany, the works council is becoming more stringent, in France, the CNIL is consulting, and the UK’s new Data (Use and Access) Act 2025 has come into operation in June 2025.The works council in Germany is getting even tighter, the CNIL consultation obligations in France are in effect, and the UK’s new Data (Use and Access) Act 2025 came into force in June 2025. The sentiment is clear: there is an increasing push towards transparency, more worker rights, and increasing demands for accountability on employers globally, including in India’s Digital Personal Data Protection Act, the disclosure requirements in the federal legislation in Canada, and emerging regulatory pressures in Asia Pacific.
This is the reality for workers in 2026: When using a company device, presume everything is visible. When using a company network, do the same. Personal conversations are to be conducted on a personal device with personal data. Even then, keep in mind that anything you send to a colleague can reappear as evidence – messages don’t disappear once they get to another person. Employers have also learned from all these regulatory events, tribunal cases and employee surveys — that covert, punitive or disproportionate monitoring is legally risky, undermines trust and is not an effective way of improving productivity. The organisations that run this well in 2026 are the ones that communicated to their employees what they are monitoring, why, and how the collected information is going to be utilised – and they also utilised the information to inform about their employees’ performance rather than to police their behaviour. The right to monitor is a genuine right. The right to privacy is a true right. In 2026, it is the principle of transparency that is emerging as the key characteristic of both. Employers and workers who know that will be well-equipped for whatever work the coming ten years will bring.
References / Sources
- Flowace (December 2025). Employee Monitoring Laws: Legal Guide 2026. Retrieved from flowace.ai
- WorkTime (March 2026). 41 Most Asked Questions on U.S. Employee Monitoring Laws. Retrieved from worktime.com
- MWH Law Group (April 2025). Employee Monitoring Laws: What Every Employer Should Know. Retrieved from com
- Sprintlaw UK (August 2025). Employee Rights and Legal Considerations for Random Searches at Work in the UK. Retrieved from sprintlaw.co.uk
- Nolo Legal Encyclopedia (November 2024). Employer Searches and Seizures: What Are Your Rights? Retrieved from nolo.com
- AMG Law (January 2026). Employee Privacy Rights in the Era of Virtual Monitoring. Retrieved from amglaw.com
- iGDPR (April 2026). Employee Monitoring GDPR: What Employers Can Do. Retrieved from igdpr.eu
- eMonitor (March 2026). Employee Monitoring Laws by State 2026. Retrieved from employee-monitoring.net
- LeapXpert (May 2025). SEC WhatsApp Fines: Top Cases from 2023-2025. Retrieved from leapxpert.com
- Stephens Scown (January 2026). WhatsApp and Work: A Legal Minefield Employers Cannot Ignore. Retrieved from stephens-scown.co.uk
- Field Law (January 2026). WhatsApp Got To Do With It: Metrolinx v Amalgamated Transit Union, Local 1587, 2024 ONSC 1900. Retrieved from fieldlaw.com
- High5Test (January 2026). Employee Monitoring Statistics in the U.S. (2024-2025): Surveillance and AI Tracking. Retrieved from high5test.com