Can employers read employee emails when investigating misconduct?
Whether an employer may inspect an employee's work email depends on the circumstances of each case, but certain general principles can guide employers before, during and after an inspection.

When an employer suspects misuse of confidential information or IP, breach of non-compete or non-solicitation obligations, conflict of interest, misconduct towards clients or colleagues, or other conduct that may expose the employer to liability, the first instinct may be to inspect the employee’s work email account.
Whether an inspection is permitted at all, and under what conditions, depends on the specific circumstances of each case. Nevertheless, certain general principles can guide employers before, during and after an inspection.
The basic principle is that employees have a legitimate expectation of privacy at work, and continuous or indiscriminate monitoring of their communications will not be justified. Employers should instead prepare in advance for a possible targeted inspection, so that missing safeguards or documentation do not unnecessarily restrict their options. Once potential misconduct is identified, the employer must assess whether an inspection is justified and ensure that, if carried out, it complies with data protection requirements. The need for caution does not end when the inspection is complete: employers must also consider how the findings may be used and handled.
Before any suspicion arises: plan ahead
Employers should prepare in advance. If the necessary rules and safeguards are not already in place when a mailbox inspection becomes relevant, the employer may have fewer lawful options for how to proceed.
- Implement less intrusive preventive measures. Employers should give priority to preventive measures that do not involve reading employee communications, where such measures are available and effective, rather than relying on access to employee emails once a problem arises. For example, an employer concerned about confidential information leaving the organisation may restrict file downloads, limit access to sensitive folders, or maintain access logs.
- Adopt an acceptable-use policy. The policy should clearly set out how employees are expected to use company equipment and accounts, e.g. whether work email may be used for private purposes, when the employer may access an employee's mailbox, and how private emails will be treated. A clear policy limits employees' reasonable expectation of privacy and gives the employer a documented basis for any later inspection.
- Inform employees in advance. Employers must inform employees in advance, through a privacy notice, that their work mailbox may be accessed in cases of suspected misconduct, for what purposes, and under what conditions. Whether employees should also be notified before a particular inspection is carried out depends, among other things, on whether advance notice could compromise the investigation.
When potential misconduct is identified: assess if inspection is justified and define the scope
When potential misconduct is identified, the employer must assess whether inspecting work emails is justified in the circumstances of a particular case and define the scope of the inspection.
- Define what is being looked for and why. The employer should identify the potential misconduct, the facts already known, the information expected to be found in the mailbox, and why they are relevant.
- Assess and document whether access is justified. The employer should consider whether the misconduct is serious enough to justify access, whether there are good reasons to expect to find evidence in the mailbox, and whether the facts could be established in a less intrusive way. This assessment should be documented and, where required, a DPIA carried out.
During the inspection: keep it limited
Throughout the inspection, the employer should keep the review targeted and controlled.
- Narrow the search. Depending on the case, the search may be limited by period, sender or recipient, keywords, attachments, or other criteria linked to the suspected misconduct. Where metadata or system logs can provide the necessary information without reading email content, they should be considered first.
- Do not read irrelevant emails. Once the search has been narrowed, the results of such search should be screened before any email content is reviewed. Only emails that may be relevant to the investigation should be opened, and review of a particular email should stop immediately after it becomes clear that it is irrelevant or private.
- Limit who conducts the inspection. Only persons who need access for their role in the investigation should take part in the review. IT personnel may run the technical search, while HR or legal may need to review potentially relevant emails and determine whether they relate to the misconduct. The number of people involved, and the access given to each of them, should be kept to what is necessary.
When dealing with the information found: limit its use and retention
Once the inspection is complete, the employer must consider how the information found may be used.
- Use the findings for appropriate follow-up action. The inspection findings may generally be used for termination of employment or a less severe sanction, as well as for related court proceedings. Their use should remain within the purpose of the investigation and be limited to the information needed for that action.
- Limit who sees the findings and the emails. The conclusions of the investigation should be shared only with those who need them to decide on or implement further action, such as relevant HR personnel, management, and legal advisers. The employer should avoid sharing the emails themselves unless this is necessary. In many cases, communicating only the findings will be sufficient.
- Limit retention periods. The investigation report and key emails may be kept for the purposes of an internal sanctioning procedure, that may result in a termination of employment, and any related dispute. Irrelevant material should not be retained once it has been excluded from the investigation. If the investigation finds no misconduct, the collected material should generally be deleted once the investigation is closed.
