Your employer can read your work email in the Netherlands, but only within narrow limits and never simply because the company owns the mailbox. Business email is a company system, so the employer sets the rules for its use; actually reading what an employee has written is a separate step that needs its own justification. An inspection is lawful only if the employer has a legitimate interest under the GDPR, if reading the mailbox is necessary and proportionate to that interest, if staff were informed beforehand through a written policy, and if the works council has agreed to the monitoring arrangement.
Can my employer read my emails?
Yes, for a concrete business reason and only as far as that reason reaches. Two sets of rules apply at the same time. Under article 7:660 of the Dutch Civil Code (Burgerlijk Wetboek) an employer may give instructions about the use of company equipment and may check whether those instructions are followed. Under the General Data Protection Regulation the content of a mailbox, and the traffic data around it, are personal data of the employee, so every inspection is a processing operation that needs a legal basis and must stay within the limits of data minimisation. The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, supervises that second layer.
The distinction that decides most disputes is the one between technical access and lawful use of that access. A system administrator can nearly always open a mailbox, restore a deleted message from backup or export a year of correspondence. That is a fact about the IT department, not a permission. The legal question is whether the employer may look, at what, and for how long, and that question is answered by the GDPR and by the duty of good employership in article 7:611 of the Civil Code, not by who pays for the licence.
In short, the answer to can my employer read my emails is: yes, but not whenever it likes and not everything. It also matters what is being read. Automated filtering of spam and malware, or a mail gateway that blocks attachments above a certain size, processes email without anyone reading it; that kind of security measure is usually straightforward to justify. A manager who opens a colleague’s inbox and reads through months of correspondence is doing something entirely different, even though both are technically monitoring. The heavier the intrusion, the stronger the reason has to be.
One point is often misunderstood by both sides. The absence of a private-use ban does not make a mailbox private, and the presence of one does not make it fully open. Dutch employers commonly tolerate incidental private use of work email and telephones, and that tolerance carries weight when a court later assesses how much privacy an employee could reasonably expect.
The legal basis is legitimate interest, not your consent
Monitoring of employees in the Netherlands almost always rests on the legitimate interest ground in article 6(1)(f) of the GDPR. That ground demands three things, in this order. The employer must identify a real and present interest rather than a hypothetical one. The processing must be necessary to serve that interest. And the balance between the interest and the rights and freedoms of the employee must come out in the employer’s favour. The assessment has to be made before the mailbox is opened and it has to be recorded, because an employer that cannot show its reasoning cannot show that the processing was lawful.
Interests that hold up in practice are concrete and usually urgent: a security incident, a suspected leak of trade secrets or client data, a suspected fraud or kickback, an obligation to investigate imposed by a regulator, or a criminal complaint that the company itself has to substantiate. What does not hold up is a general wish to see how hard people are working, curiosity about a colleague, or a vague feeling that something is off since the team started working from home. Measuring performance by reading correspondence is treated as disproportionate, because performance can be assessed from output, agreed targets and ordinary conversation.
Because monitoring is a processing operation like any other, the general principles of article 5 of the GDPR apply in full. Data must be collected for a specified purpose and not reused for another one, which means that material found while investigating a data leak cannot casually be turned into a performance file. Data must be adequate and limited to what is necessary, which is the legal root of the requirement to search on keywords and date ranges rather than to read everything. And data must not be kept longer than needed, so the export of a mailbox made for an investigation has to be deleted once the investigation is closed and any resulting procedure has ended. Where monitoring is systematic and extensive, the employer also has to carry out a data protection impact assessment before it starts; the AP publishes a list of processing operations for which it always requires one.
Why consent rarely works at work
Consent under article 6(1)(a) of the GDPR is not a realistic basis in an employment relationship. Consent has to be freely given, and an employee asked for permission by the person who decides on their contract, their pay and their promotion is rarely in a position to say no without consequence. A clause in an employment contract in which the employee agrees to email monitoring therefore does not, on its own, make the monitoring lawful.
Such a clause is still worth having, because it is evidence that the employee was informed, and transparency is a requirement in its own right. But it does not replace the balancing test, and it does not replace the consent of the works council. These are separate hurdles and an employer has to clear all of them. Our overview of email and data protection under the GDPR sets out how those obligations fit together for an organisation that is designing its own policy.
The necessity and proportionality test
Necessity asks whether the goal can be reached without reading the mailbox at all. Proportionality asks whether the intrusion is in scale with the problem. These are the two questions on which employers most often lose, not because their reason was bad but because they went further than their reason justified.
Subsidiarity: the least intrusive route first
Subsidiarity is the practical side of necessity: if a lighter method reaches the same result, the lighter method has to be used. In an investigation into a suspected data leak, that usually means starting with metadata rather than content. Sender, recipient, timestamp, message size and the presence of an attachment are already personal data, but they are far less intrusive than the body of a message, and they are frequently enough to confirm or dispel a suspicion. Only if the metadata points somewhere does opening the messages themselves become defensible.
The same logic applies to more ordinary situations. If a manager needs a client file from the mailbox of a colleague on long-term sick leave, the answer is not to log in and browse. The employee can be asked to forward the document, or an administrator can run a narrow search for that one file. Sick leave is precisely the situation in which a mailbox is likely to contain medical information, which is a special category of personal data with its own strict regime, and an employer has no business seeing it.
What a proportionate search looks like
A proportionate inspection is limited in three dimensions at once: who is searched, what is searched for, and over which period. An investigation into a leak from a single development team covers that team, uses search terms tied to the leaked material, and looks at a window of weeks around the incident. It does not cover the whole company, it does not read everything those developers wrote, and it does not go back three years.
Two further safeguards make the difference between a defensible investigation and an indefensible one. The first is that the search should be carried out by someone with no personal stake in the outcome, in practice a security officer, the privacy officer or an external specialist rather than the manager who raised the suspicion. The second is that everything is logged: what was searched, on whose instruction, on what grounds and what was found. An employer that cannot reconstruct its own investigation is in a weak position when the employee asks the AP or a court to review it.
Key conditions for lawful email monitoring
| Condition | What it means in practice |
|---|---|
| Legitimate interest | A specific, present business interest such as a suspected leak, fraud or security incident, recorded before the inspection starts. |
| Necessity and subsidiarity | No lighter route reaches the same result. Metadata before content, a conversation before an investigation. |
| Proportionality | Limited in scope, in search terms and in time, carried out by someone independent and fully logged. |
| Transparency | A written policy that employees knew about before any monitoring took place, explaining purposes, methods and retention. |
| Works council consent | Prior consent for the monitoring arrangement under article 27 of the Works Councils Act, where a works council exists. |
Private messages in a business mailbox
A message that is clearly private keeps a measure of protection even inside a company mailbox. Article 8 of the European Convention on Human Rights protects private life and correspondence and applies at the workplace as well, and Dutch courts apply it directly. In 2017 the Grand Chamber of the European Court of Human Rights set out the factors a national court should weigh when an employer monitors an employee’s communications: whether the employee was told in advance and how clearly, how far the monitoring went and whether content was read or only traffic data, whether the employer had legitimate reasons, whether a less intrusive method was available, what consequences the monitoring had for the employee, and whether the employee was given adequate safeguards.
Applied to a Dutch mailbox, that produces a workable rule. An employer conducting a lawful search that stumbles on a message which is obviously private, because of the sender, the subject line or the folder it sits in, has to stop reading it and leave it out of the file. The same applies to messages that reveal health, religion, trade union membership or political views: these are special categories of personal data and the grounds for processing them are far narrower than for ordinary data.
Employees can strengthen that protection themselves. Keeping personal correspondence out of the work account is the most effective step, and moving anything personal that does arrive into a clearly named folder is the second. It is not a magic shield, but it marks the boundary, and a boundary that was visible before the investigation started carries much more weight than one asserted afterwards.
Messaging apps follow the same logic but shift the balance, because the account and often the device belong to the employee rather than to the company. We deal with that separately in our article on whether your employer can read your WhatsApp messages.
Why the works council has to agree first
An employer that wants to introduce, change or withdraw an email or internet monitoring arrangement needs the prior consent of the works council. Article 27(1)(k) of the Works Councils Act (Wet op de ondernemingsraden) covers arrangements for the processing and the protection of the personal data of people working in the company. Article 27(1)(l) covers arrangements for facilities that are intended or suitable for observing or checking the attendance, conduct or performance of those people. Email logging, internet filtering, camera surveillance, access passes and productivity software all land under one or both of these headings.
A works council is compulsory in a company where at least fifty people work. In smaller organisations the obligation does not arise, but the transparency and balancing requirements of the GDPR do not disappear with it; the employer simply has one fewer internal check and one more reason to document its own reasoning carefully.
The sanction for skipping the works council is real. If the employer takes the decision without consent, the works council can invoke the nullity of that decision in writing within one month of learning of it, and the decision is then void. An employer that has built a monitoring system on a void decision has a compliance problem and an evidence problem at the same time, and the works council can ask the subdistrict court (kantonrechter) to order the employer to comply with the Act and to refrain from acting on the decision.
One nuance is regularly missed in both directions. What needs consent is the arrangement, not each individual investigation. An employer does not have to ask the works council for permission every time it looks into one concrete suspicion, provided the investigation stays inside a framework the council has already approved. Conversely, consent by the council does not turn an excessive investigation into a lawful one: the GDPR test still has to be passed on the facts of the case.
What a lawful monitoring policy must contain
Transparency is not a courtesy but a condition. Articles 12 to 14 of the GDPR require that employees are told, in clear language and before the fact, what is processed about them and why. In practice this takes the form of an email and internet policy, handed out with the employment contract or included in the staff handbook, and referred to often enough that nobody can credibly say they never saw it. A reservation of rights along the lines of “the employer may monitor communications” is not enough, because it tells the employee nothing about purposes, scope or safeguards.
A policy that survives scrutiny states at least the following, in plain terms:
- the purposes of monitoring, described concretely rather than as a list of everything imaginable;
- what is actually processed and by which technical means, including whether content can be read or only traffic data;
- who may authorise an inspection, who carries it out, and how the four-eyes principle is applied;
- how long monitoring data and the results of an investigation are kept, and when they are destroyed;
- whether private use of company systems is permitted and, if so, within what limits;
- the rights of employees, including access to their own data and the right to complain to the AP.
The policy also has to be lived up to. An employer that has promised keyword searches and then exports a full mailbox is in a worse position than one that never wrote anything down, because it has now breached its own published rules. Our note on understanding employer and employee obligations and our wider insights on the legal obligations of Dutch employers go further into how these documents interact with the rest of the employment relationship. Organisations that want an external benchmark for their processes often work through a general GDPR compliance checklist, but a checklist is a starting point for a conversation, not a substitute for the balancing test.
Monitoring when the employer suspects misconduct
Most disputes about email monitoring arise from an investigation into a specific suspicion rather than from routine surveillance. The suspicion is usually one of a small number of things: confidential information leaving the company, a conflict of interest with a supplier or a competitor, expenses that do not match reality, harassment of a colleague, or an employee setting up a competing business on company time. In all of these the employer has a genuine interest. The question is never whether it may investigate, but how far it may go.
The limits of a targeted investigation
A defensible investigation starts with a written decision that records the suspicion, the facts on which it rests, the purpose of the investigation and the reason why lighter means are insufficient. It then follows the scope set out in that decision. Widening the search because the first round produced nothing is exactly the fishing expedition the necessity test is designed to prevent, and it is the point at which many investigations become unlawful.
Covert investigation is possible in the Netherlands, but it is the heaviest variant and it is only defensible where informing the employee in advance would frustrate the investigation, for example because evidence would be destroyed. Even then it must be temporary, narrowly framed, and followed by informing the employee afterwards. An employer that monitors covertly as standard practice, without a specific and documented reason, is on the wrong side of the line.
The employee is not without rights during the process either. Good employership means an employee confronted with findings is told what was investigated and on what basis, and gets a genuine opportunity to explain before conclusions are drawn. A confrontation in which an employee is presented with printouts and asked to sign a settlement on the spot rarely holds up well afterwards.
What happens to the evidence in a dismissal case
Employers regularly assume that unlawfully obtained email evidence is automatically worthless, and employees regularly assume the same in their own favour. Neither is right. Dutch civil procedure works with free evidentiary rules, and the courts have held that the interest of establishing the truth generally outweighs exclusion, so evidence obtained in breach of privacy rules is only set aside in exceptional circumstances.
That does not make the breach costless. The employer that monitored unlawfully still faces a claim for damages, a complaint to the AP, and a court that weighs its conduct when it assesses the dismissal. In a summary dismissal (ontslag op staande voet) the employer must show an urgent cause within the meaning of article 7:678 of the Civil Code, that it acted without delay, and that it communicated the reason immediately. An investigation that dragged on for months undermines the immediacy requirement, and a heavy-handed investigation feeds an argument for a fair compensation on top of the ordinary entitlements. Our guide on how to handle employee dismissal legally sets out that sequence in detail.
What to do if you think the monitoring went too far
Start by establishing what actually happened rather than what you suspect. As the person whose data is processed you have a right of access under article 15 of the GDPR: you can ask your employer in writing which personal data it processes about you, for which purposes, on which legal basis, who received the data and how long it will be kept, and you can ask for a copy. The employer must answer within a month, extendable in complex cases, and it may only withhold material where the rights of others genuinely require it. A well-drafted access request is the single most effective first step, because it forces the employer to put its own account on paper.
In parallel, raise the matter internally. If the company has a data protection officer (functionaris gegevensbescherming) that is the natural addressee; otherwise HR or the works council. The works council has a specific interest here, because if monitoring is happening outside an approved arrangement, that is its problem as much as yours. Keep the exchange factual and in writing, and record dates, systems and the messages you believe were read.
If that leads nowhere, there are two external routes and they serve different purposes. A complaint to the AP is a supervisory route: the authority can investigate the employer’s practices and impose corrective measures or a fine, but it does not award you compensation. A civil claim is the route for your own position: you can ask the court to order the monitoring to stop, to have data deleted, and to award damages for the breach, and if the monitoring is entangled with a dismissal the two are usually dealt with in the same proceedings before the subdistrict court.
Timing matters in employment matters, because the deadlines around dismissal are short and unforgiving, and evidence in IT systems is overwritten as logs rotate. If a warning, a suspension or a dismissal is already on the table, take advice before you respond to it rather than afterwards; an employment lawyer can assess in one conversation whether the investigation that produced the accusation was lawful and what that means for your position.
Monitoring beyond the inbox: logging, filtering and remote work
Email is only one strand of the digital trail an employee leaves. Internet and proxy logs, VPN and login records, access passes, mobile device management on a company phone, mail gateways and productivity dashboards all process personal data, and the framework is the same for each of them: a specified purpose, necessity, proportionality, transparency in advance and, where a works council exists, its consent. Employers that treat each tool as a separate procurement decision tend to end up with a level of surveillance that none of them ever intended and that no single business case supports.
At the far end of the scale sit tools that watch the employee continuously rather than the system: keystroke logging, screenshots taken at fixed intervals, software that scores active and idle time, and a requirement to keep a webcam switched on during the working day. These are extremely difficult to justify. They are permanent rather than incident-driven, they capture the private surroundings of the employee as well as the work, and there is nearly always a lighter alternative in the form of agreed output and normal supervision. A Dutch court has already held that requiring an employee to keep a camera on all day was an unacceptable intrusion into private life.
Working from home does not lower the threshold; it raises it. The home is the core of the private sphere protected by article 8 of the European Convention on Human Rights, and monitoring that reaches into it needs a correspondingly stronger justification. Bring-your-own-device arrangements need the same care in reverse: management software on a personal phone should be limited to the work container, and the employer should be able to explain exactly which data it can and cannot see on that device.
Your mailbox after you leave
Employees often assume the question of whether an employer can read my emails ends on the last working day. It does not, because the mailbox stays behind and the personal data in it does not become free for the taking. A former employer remains the controller of that data and remains bound by purpose limitation and storage limitation.
The defensible approach is a short, announced wind-down. The account is deactivated promptly rather than left running for months. An automatic reply points correspondents to a named colleague, without forwarding the content of incoming messages. Where forwarding to a successor is genuinely necessary for continuity, it runs for a limited and communicated period, and it stops. Personal correspondence that the departing employee flags is handed over or deleted rather than read. Keeping a former employee’s mailbox live and monitored indefinitely, in the hope that something useful will turn up, has no legal basis at all.
A former employee keeps the right of access to their own personal data, and can ask for data that is no longer necessary to be erased. Those rights are worth exercising early, because after a departure the practical answer often depends on what backup and retention schedules have already done.
Frequently asked questions about email privacy
A few situations come up so often that they deserve a direct answer.
Can my employer read deleted emails?
Yes, it's very likely they can. When you hit 'delete' on an email, it usually just lands in a "Deleted Items" folder. It's not gone for good just yet.
More importantly, most businesses run sophisticated backup systems. These systems archive all email data, often for legal compliance or disaster recovery. This means that even if you permanently purge an email from your own mailbox, a copy probably still exists on a company server. If your employer has a legitimate, legally sound reason to investigate, they can often retrieve these archived messages.
Deleting an email doesn't make it disappear forever.
What about my personal device?
Using your own laptop or phone for work might feel more private, but the same general rules apply. The moment you connect your personal device to the company’s network or use it to access your work email, your professional communications fall under the employer's policies.
The real question isn't who owns the device, but who owns the email account and the data flowing through it. Work-related emails are considered company property, no matter if you're checking them on a company PC or your personal smartphone.
This is exactly why keeping a clear line between your personal and professional accounts is so vital for protecting your own privacy.
Are chat messages also monitored?
Absolutely. Messages you send on workplace platforms like Slack, Microsoft Teams, or other internal chat systems are treated just like emails under Dutch privacy law. They are business communications, plain and simple.
This means an employer can monitor them if they meet the strict legal tests of having a legitimate interest, and ensuring the monitoring is necessary and proportional.
Just as with email, your employer must have a transparent policy that tells you about any potential monitoring on these platforms. Never assume a "private" chat with a colleague on a company system is truly confidential. These conversations become part of the company's digital records and can be pulled up in a lawful investigation.
Law & More advises employers on drafting and implementing monitoring policies that survive scrutiny by the works council and the AP, and advises employees who are confronted with material taken from their mailbox. If you are dealing with an investigation, a policy that needs review or a dismissal built on email evidence, please get in touch so we can assess your position.


