Yes, your employer can read your work email in the Netherlands, but only within narrow limits and never simply because the company owns the mailbox. The main exception to “the employer decides” is that reading content always needs its own justification: a legitimate interest under the GDPR, a search that is necessary and proportionate, a written policy you knew about in advance and, where there is a works council, its prior consent to the monitoring arrangement.
Business email is a company system, so your employer sets the rules for its use. Reading what you have written is a separate step. In this article we explain when that step is lawful, where the limits lie and what you can do if you think your employer went too far.
Can my employer read my emails?
Yes, for a concrete business reason and only as far as that reason reaches. Two sets of rules apply at the same time: Dutch employment law and the GDPR.
Under article 7:660 of the Dutch Civil Code (Burgerlijk Wetboek) your employer may give instructions about the use of company equipment. It may also check whether you follow those instructions. Under the General Data Protection Regulation (GDPR, in Dutch AVG), the content of your mailbox and the traffic data around it are your personal data. Every inspection is therefore a processing operation. It needs a legal basis and must stay within the limits of data minimisation. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) supervises that second layer.
Does technical access mean your employer may look?
No. Most disputes turn on the difference between technical access and lawful use of that access. A system administrator can nearly always open a mailbox, restore a deleted message from backup or export a year of correspondence. That is a fact about the IT department, not a permission.
The legal question is whether your employer may look, at what, and for how long. The GDPR answers that question, together with the duty to act as a good employer (goed werkgeverschap) in article 7:611 of the Civil Code. Who pays for the software licence does not decide it.
Does it matter how the email is monitored?
Yes. The heavier the intrusion, the stronger the reason has to be. Automated filtering of spam and malware processes email without anyone reading it. The same applies to a mail gateway that blocks attachments above a certain size. Such security measures are usually easy to justify. A manager who opens a colleague’s inbox and reads through months of correspondence does something entirely different, even though both are technically forms of monitoring.
One point is often misunderstood by both sides. The absence of a ban on private use does not make a mailbox private. The presence of such a ban does not make it fully open either. Dutch employers commonly tolerate incidental private use of work email and telephones. That tolerance carries weight when a court later assesses how much privacy you could reasonably expect.
On what legal basis may your employer monitor you?
Almost always on legitimate interest, not on your consent. Monitoring of employees in the Netherlands rests on the legitimate interest ground in article 6(1)(f) of the GDPR.
That ground demands three things, in this order:
- your employer must identify a real and present interest, not a hypothetical one;
- the processing must be necessary to serve that interest;
- the balance between that interest and your rights and freedoms must come out in the employer’s favour.
Your employer has to make this assessment before it opens the mailbox, and it has to record it. An employer that cannot show its reasoning cannot show that the processing was lawful.
Which interests hold up?
Interests that hold up are concrete and usually urgent. Think of a security incident, a suspected leak of trade secrets or client data, suspected fraud or bribery, a duty to investigate imposed by a regulator, or a criminal complaint the company has to substantiate.
What does not hold up is a general wish to see how hard people are working. The same goes for curiosity about a colleague, or a vague feeling that something is off since the team started working from home. Measuring performance by reading correspondence is treated as disproportionate. Performance can be assessed from output, agreed targets and ordinary conversation.
Which general GDPR principles apply?
All of them. Monitoring is a processing operation like any other, so the principles of article 5 of the GDPR apply in full.
Data must be collected for a specified purpose and not reused for another one. Material found while investigating a data leak therefore cannot casually be turned into a performance file. Data must also be adequate and limited to what is necessary. That is the legal root of the requirement to search on keywords and date ranges instead of reading everything. And data must not be kept longer than needed. An export of a mailbox made for an investigation has to be deleted once the investigation is closed and any resulting procedure has ended.
Where monitoring is systematic and extensive, your employer must also carry out a data protection impact assessment (DPIA) before it starts. The AP publishes a list of processing operations for which it always requires one.
Why does consent rarely work at work?
Because consent has to be freely given, and in an employment relationship it rarely is. Consent under article 6(1)(a) of the GDPR is not a realistic basis here. You are asked for permission by the person who decides on your contract, your pay and your promotion. You are rarely in a position to say no without consequences.
A clause in your employment contract in which you agree to email monitoring therefore does not, on its own, make the monitoring lawful. Such a clause is still useful to an employer. It shows that you were informed, and transparency is a requirement in its own right. But it is no substitute for the balancing test, nor for the consent of the works council. These are separate hurdles, and your employer has to clear all of them. Our overview of email and data protection under the GDPR explains how those obligations fit together for an organisation that is designing its own policy.
How do necessity and proportionality limit a search?
Necessity asks whether the goal can be reached without reading the mailbox at all. Proportionality asks whether the intrusion is in scale with the problem.
Employers most often lose on these two questions. Usually not because their reason was bad, but because they went further than their reason justified.
Must the least intrusive route come first?
Yes. This is subsidiarity, the practical side of necessity: if a lighter method reaches the same result, your employer has to use the lighter method.
In an investigation into a suspected data leak, that usually means starting with metadata instead of content. Sender, recipient, timestamp, message size and the presence of an attachment are already personal data. But they are far less intrusive than the body of a message, and they are often enough to confirm or dispel a suspicion. Only if the metadata points somewhere does opening the messages themselves become defensible.
The same logic applies in ordinary situations. An illustrative example: a manager needs a client file from the mailbox of a colleague on long-term sick leave. The answer is not to log in and browse. The employee can be asked to forward the document, or an administrator can run a narrow search for that one file. During sick leave a mailbox is likely to contain medical information. That is a special category of personal data with its own strict regime, and your employer has no business seeing it.
What does a proportionate search look like?
A proportionate search is limited in three ways at once: who is searched, what is searched for, and over which period.
Take a leak from a single development team. The investigation covers that team, uses search terms tied to the leaked material and looks at a window of weeks around the incident. It does not cover the whole company. It does not read everything those developers wrote. And it does not go back three years.
Two further safeguards separate a defensible investigation from an indefensible one. First, the search should be carried out by someone with no personal stake in the outcome. In practice that is a security officer, the privacy officer or an external specialist, not the manager who raised the suspicion. Second, everything is logged: what was searched, on whose instruction, on what grounds and what was found. An employer that cannot reconstruct its own investigation is in a weak position when you ask the AP or a court to review it.
Which conditions must lawful email monitoring meet?
| Condition | What it means in practice |
|---|---|
| Legitimate interest | A specific, present business interest such as a suspected leak, fraud or security incident, recorded before the inspection starts. |
| Necessity and subsidiarity | No lighter route reaches the same result. Metadata before content, a conversation before an investigation. |
| Proportionality | Limited in scope, in search terms and in time, carried out by someone independent and fully logged. |
| Transparency | A written policy that employees knew about before any monitoring took place, explaining purposes, methods and retention. |
| Works council consent | Prior consent for the monitoring arrangement under article 27 of the Works Councils Act, where a works council exists. |
Are private messages in a business mailbox protected?
Yes, a message that is clearly private keeps a measure of protection, even inside a company mailbox. Your employer may not simply read it along with the rest.
Article 8 of the European Convention on Human Rights protects private life and correspondence. It applies at the workplace as well, and Dutch courts apply it directly. In 2017 the Grand Chamber of the European Court of Human Rights set out the factors a national court should weigh when an employer monitors an employee’s communications:
- whether the employee was told in advance, and how clearly;
- how far the monitoring went, and whether content was read or only traffic data;
- whether the employer had legitimate reasons;
- whether a less intrusive method was available;
- what consequences the monitoring had for the employee;
- whether the employee was given adequate safeguards.
What must your employer do when it finds a private message?
Stop reading it and leave it out of the file. Applied to a Dutch mailbox, the factors above produce a workable rule. During a lawful search, your employer may come across a message that is obviously private because of the sender, the subject line or the folder it sits in. It then has to stop reading.
The same applies to messages that reveal health, religion, trade union membership or political views. These are special categories of personal data. The grounds for processing them are far narrower than for ordinary data.
How can you protect your own privacy?
Keep personal correspondence out of your work account. That is the most effective step. The second step is to move anything personal that does arrive into a clearly named folder. It is not a magic shield, but it marks the boundary. A boundary that was visible before the investigation started carries much more weight than one claimed afterwards.
Messaging apps follow the same logic but shift the balance, because the account and often the device belong to you and not to the company. We deal with that separately in our article on whether your employer can read your WhatsApp messages.
Why does the works council have to agree first?
Because Dutch law gives the works council (ondernemingsraad) a right of consent over monitoring arrangements. An employer that wants to introduce, change or withdraw an email or internet monitoring arrangement needs the council’s prior consent.
Article 27(1)(k) of the Works Councils Act (Wet op de ondernemingsraden) covers arrangements for the processing and protection of the personal data of people working in the company. Article 27(1)(l) covers arrangements for facilities that are intended or suitable for observing or checking the attendance, conduct or performance of those people. Email logging, internet filtering, camera surveillance, access passes and productivity software all fall under one or both of these headings.
What if there is no works council?
Then the consent requirement does not apply, but the GDPR still does. A works council is compulsory in a company where at least fifty people work. In smaller organisations the transparency and balancing requirements of the GDPR remain in full. The employer simply has one fewer internal check, and one more reason to document its reasoning carefully.
What happens if the employer skips the works council?
The decision can be declared void. If the employer takes the decision without consent, the works council can invoke the nullity of that decision in writing within one month of learning of it. The decision is then void.
An employer that has built a monitoring system on a void decision has a compliance problem and an evidence problem at the same time. The works council can also ask the subdistrict court (kantonrechter) to order the employer to comply with the Act and to refrain from acting on the decision.
Does every investigation need works council consent?
No. What needs consent is the arrangement, not each individual investigation. Your employer does not have to ask the works council for permission every time it looks into one concrete suspicion, as long as the investigation stays inside a framework the council has already approved.
The reverse also holds. Consent by the council does not turn an excessive investigation into a lawful one. The GDPR test still has to be passed on the facts of the case.
What must a lawful monitoring policy contain?
A clear, written explanation of what is monitored, why and how, given to you before any monitoring starts. Transparency is not a courtesy but a condition.
Articles 12 to 14 of the GDPR require that employees are told, in clear language and in advance, what is processed about them and why. In practice this takes the form of an email and internet policy. It is handed out with the employment contract or included in the staff handbook, and referred to often enough that nobody can credibly say they never saw it. A general clause such as “the employer may monitor communications” is not enough. It tells you nothing about purposes, scope or safeguards.
A policy that survives scrutiny states at least the following, in plain terms:
- the purposes of monitoring, described concretely and not as a list of everything imaginable;
- what is actually processed and by which technical means, including whether content can be read or only traffic data;
- who may authorise an inspection, who carries it out, and how the four-eyes principle is applied;
- how long monitoring data and the results of an investigation are kept, and when they are destroyed;
- whether private use of company systems is permitted and, if so, within what limits;
- the rights of employees, including access to their own data and the right to complain to the AP.
The employer also has to live up to its policy. An employer that has promised keyword searches and then exports a full mailbox is worse off than one that never wrote anything down, because it has now breached its own published rules. Our note on understanding employer and employee obligations and our wider insights on the legal obligations of Dutch employers explain how these documents interact with the rest of the employment relationship. Many organisations use a general GDPR compliance checklist as an external benchmark. That is a good starting point for a conversation, but it is not a substitute for the balancing test.
How far may your employer go when it suspects misconduct?
Only as far as the documented suspicion reaches. In these cases your employer usually has a genuine interest in investigating; the question is how far it may go.
Most disputes about email monitoring arise from an investigation into a specific suspicion, not from routine surveillance. Typical suspicions are confidential information leaving the company, a conflict of interest with a supplier or competitor, expense claims that do not match reality, harassment of a colleague, or an employee setting up a competing business on company time.
What are the limits of a targeted investigation?
The limits are set by a written decision taken at the start. That decision records the suspicion, the facts on which it rests, the purpose of the investigation and the reason why lighter means are not enough. The investigation then follows the scope set out in that decision.
Widening the search because the first round produced nothing is exactly the fishing expedition the necessity test is meant to prevent. It is also the point at which many investigations become unlawful.
Is covert monitoring allowed?
Only in exceptional cases. Covert investigation is possible in the Netherlands, but it is the heaviest variant. It is only defensible where informing you in advance would frustrate the investigation, for example because evidence would be destroyed. Even then it must be temporary and narrowly framed, and you must be informed afterwards. An employer that monitors covertly as standard practice, without a specific and documented reason, is on the wrong side of the line.
What rights do you have during the investigation?
You have the right to be heard. Good employership means that an employee confronted with findings is told what was investigated and on what basis. You must get a genuine opportunity to explain before conclusions are drawn. A confrontation in which you are shown printouts and asked to sign a settlement on the spot rarely holds up well afterwards.
What happens to the evidence in a dismissal case?
Unlawfully obtained email evidence is usually still admitted, but the unlawful monitoring can cost the employer elsewhere. Employers often assume that such evidence is automatically worthless, and employees often assume the same in their own favour. Neither is right.
Dutch civil procedure works with free rules of evidence. The courts have held that the interest of establishing the truth generally outweighs exclusion. Evidence obtained in breach of privacy rules is therefore only set aside in exceptional circumstances.
That does not make the breach costless. An employer that monitored unlawfully still faces a claim for damages, a complaint to the AP, and a court that weighs its conduct when it assesses the dismissal. In a summary dismissal (ontslag op staande voet) the employer must show an urgent cause within the meaning of article 7:678 of the Civil Code. It must also show that it acted without delay and that it told you the reason immediately. An investigation that dragged on for months undermines that immediacy requirement. A heavy-handed investigation supports a claim for fair compensation (billijke vergoeding) on top of the ordinary entitlements. Our guide on how to handle employee dismissal legally sets out that sequence in detail.
What can you do if you think the monitoring went too far?
Start with a written access request, then raise the matter internally. Only if that leads nowhere do you turn to the AP or the court.
How do you find out what your employer has done?
Use your right of access under article 15 of the GDPR. You can ask your employer in writing which personal data it processes about you, for which purposes and on which legal basis. You can also ask who received the data and how long it will be kept, and you can ask for a copy.
Your employer must answer within one month. In complex cases that period can be extended. It may only withhold material where the rights of others genuinely require it. A well-drafted access request is often the most effective first step, because it forces your employer to put its own account on paper.
Who do you raise it with internally?
If the company has a data protection officer (functionaris gegevensbescherming), that is the natural addressee. Otherwise, go to HR or the works council. The works council has its own interest here: if monitoring happens outside an approved arrangement, that is its problem as much as yours. Keep the exchange factual and in writing. Record dates, systems and the messages you believe were read.
Which external routes are open to you?
There are two, and they serve different purposes. A complaint to the AP is a supervisory route. The authority can investigate your employer’s practices and impose corrective measures or a fine, but it does not award you compensation.
A civil claim is the route for your own position. You can ask the court to order the monitoring to stop, to have data deleted and to award damages for the breach. If the monitoring is linked to a dismissal, both are usually dealt with in the same proceedings before the subdistrict court.
Why is timing important?
Because the deadlines around dismissal are short and strict, and evidence in IT systems is overwritten as logs rotate. If a warning, a suspension or a dismissal is already on the table, take advice before you respond to it, not afterwards. An employment lawyer can assess in one conversation whether the investigation behind the accusation was lawful and what that means for your position.
Does the same apply to logging, filtering and remote work?
Yes. Email is only one part of the digital trail an employee leaves, and the same framework applies to every other monitoring tool.
Internet and proxy logs, VPN and login records, access passes, mobile device management on a company phone, mail gateways and productivity dashboards all process personal data. For each of them your employer needs a specified purpose, necessity, proportionality, transparency in advance and, where a works council exists, its consent. Employers that treat each tool as a separate purchasing decision tend to end up with a level of surveillance that nobody intended and that no single business case supports.
What about continuous monitoring tools?
These are extremely difficult to justify. At the far end of the scale are tools that watch the employee continuously instead of the system. Examples are keystroke logging, screenshots at fixed intervals, software that scores active and idle time, and a requirement to keep a webcam on during the working day.
Such tools are permanent, not incident-driven. They capture your private surroundings as well as your work. And there is nearly always a lighter alternative in the form of agreed output and normal supervision. A Dutch court has already held that requiring an employee to keep a camera on all day was an unacceptable intrusion into private life.
Does working from home change the rules?
Working from home does not lower the threshold; it raises it. Your home is the core of the private sphere protected by article 8 of the European Convention on Human Rights. Monitoring that reaches into it needs a correspondingly stronger justification.
Bring-your-own-device arrangements need the same care. Management software on a personal phone should be limited to the work environment on that phone. Your employer should be able to explain exactly which data it can and cannot see on that device.
What happens to your mailbox after you leave?
Your employer may not keep reading it. Many employees assume the question “can my employer read my emails” ends on the last working day. It does not. The mailbox stays behind, and the personal data in it does not become free for the taking. The former employer remains the controller of that data and is still bound by purpose limitation and storage limitation.
The defensible approach is a short, announced wind-down:
- the account is deactivated promptly and not left running for months;
- an automatic reply points correspondents to a named colleague, without forwarding the content of incoming messages;
- where forwarding to a successor is genuinely necessary for continuity, it runs for a limited and announced period, and then stops;
- personal correspondence that the departing employee flags is handed over or deleted, not read.
Keeping a former employee’s mailbox live and monitored indefinitely, in the hope that something useful will turn up, has no legal basis at all.
As a former employee you keep your right of access to your own personal data. You can also ask for data that is no longer necessary to be erased. Exercise those rights early. After a departure, the practical answer often depends on what backup and retention schedules have already done.
In summary
- Your employer may read your work email only for a concrete, recorded business interest, and only as far as that interest reaches (article 6(1)(f) GDPR).
- The search must be necessary and proportionate: metadata before content, limited in people, search terms and time, carried out independently and logged.
- You must know the monitoring policy in advance, and where there is a works council, it must have consented to the arrangement (article 27 Works Councils Act).
- Clearly private messages and special categories of data stay out of the file, also during a lawful search.
- If you suspect the monitoring went too far, start with an access request under article 15 GDPR and take advice quickly if a dismissal is involved.
Frequently asked questions about email privacy
Below we answer three questions about specific situations directly.
Can my employer read deleted emails?
Often it can technically retrieve them, but the same legal limits apply as to any other email. When you delete an email, it usually just moves to a “Deleted Items” folder. It is not gone for good yet.
In addition, most businesses run backup and archiving systems, for example for legal retention duties or disaster recovery. Even if you permanently remove an email from your own mailbox, a copy may still exist on a company server. If your employer has a legitimate and well-founded reason to investigate, it can often retrieve such archived messages. The search must still be necessary and proportionate.
Deleting an email does not make it disappear for good.
What about my personal device?
Using your own laptop or phone for work may feel more private, but the same general rules apply to your work email. As soon as you use your personal device to access your work email or the company network, that work communication falls under your employer’s policy.
What matters is not who owns the device, but whose email account and systems the data runs through. Work email in a company account falls within your employer’s monitoring framework, whether you read it on a company PC or on your own smartphone. Your employer still has no right to look at the private content of your own device.
This is why keeping a clear line between your personal and work accounts is the best way to protect your own privacy.
Are chat messages also monitored?
They can be. Messages on workplace platforms such as Slack, Microsoft Teams or other internal chat systems are treated in the same way as email under the GDPR. They are business communications on a company system.
Your employer may only monitor them if it meets the same legal tests: a legitimate interest, and monitoring that is necessary and proportionate.
Just as with email, your employer must have a transparent policy that tells you about any monitoring on these platforms. Do not assume that a “private” chat with a colleague on a company system is truly confidential. These conversations become part of the company’s records and can be retrieved in a lawful investigation.
Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.


