In short: an employer may not simply read your WhatsApp messages. Access is only lawful where there is a legitimate interest, where reading the messages is genuinely necessary and no less intrusive route exists, and where staff were told in advance what may be monitored and why. A structural monitoring arrangement also requires the consent of the works council under Article 27 of the Works Councils Act. Reading private messages outside those conditions breaches the GDPR and the employee’s right to private life.
Your employer cannot read your WhatsApp messages at will, on a private phone or on a company phone. Messages are personal data, so any access needs a lawful basis under the General Data Protection Regulation, and in the employment relationship that basis is almost always the employer’s legitimate interest. That basis only holds up where the employer has a concrete reason, reads no more than that reason requires, has no less intrusive alternative, and has told staff in advance that this can happen.
The question comes up in two very different situations, and they are worth separating from the start. The first is private messaging on a personal phone, where the employer’s position is weak and the employee’s protection is close to absolute. The second is business messaging, whether in a company WhatsApp group, on a company account or in a workplace chat tool, where the employer has far more room but still cannot help itself to everything. This article deals with both, with the works council’s role, and with what an employee can do if the line has already been crossed. The position on company email is set out separately in our article on whether your employer may read your emails, and the rules there follow the same structure.
Why messages are protected in the first place
Three layers of law apply at the same time. The right to respect for private life and correspondence under Article 8 of the European Convention on Human Rights applies in the workplace: the European Court of Human Rights has held that an employee retains a reasonable expectation of privacy at work, that an employer must inform staff in advance of the nature and extent of any monitoring, and that a court must weigh the employer’s reasons, the scope of the intrusion and the availability of less intrusive means. Article 10 of the Dutch Constitution protects private life in the same way.
The second layer is data protection. The content of a message, the identity of the sender and recipient, the time it was sent and the fact that a conversation took place are all personal data, and reading them is processing. The General Data Protection Regulation therefore applies in full, with its principles of lawfulness, purpose limitation, data minimisation and storage limitation. Our overview of general data protection sets out those principles, and the Dutch Data Protection Authority supervises them.
The third layer is employment law. The employer’s right of instruction covers the way work is done, not the employee’s private life, and an employer that oversteps risks not only a data protection claim but also a finding of seriously culpable conduct in a dismissal case. Where the employer goes further still and breaks into an account or a device it has no access to, criminal law comes into view: unauthorised access to a computerised system is an offence under Article 138ab of the Dutch Criminal Code.
The lawful basis: why consent does not work
Every processing operation needs one of the lawful bases in Article 6 of the General Data Protection Regulation. Employers regularly assume they can rely on the employee’s consent, whether given in the contract or in an IT policy signed on the first day. In an employment relationship that assumption is wrong. Consent must be freely given, and the dependence between employer and employee means a refusal is rarely without consequence. Both the European data protection supervisors and the Dutch Data Protection Authority treat consent in the workplace as invalid in almost all monitoring situations, and a clause in a contract does not repair that.
What remains is the employer’s legitimate interest. Protecting company property and confidential information, investigating a concrete suspicion of fraud or theft, complying with a statutory duty, and guaranteeing the security of the network are all capable of being legitimate interests. Curiosity, general suspicion of the workforce, checking productivity and wanting to know what people say about management are not.
Relying on legitimate interest is not a formality. The employer must be able to show that it identified the interest, that the processing is necessary for it, and that the balance between that interest and the employee’s rights and freedoms comes out in its favour. That assessment should be recorded before the monitoring starts, not reconstructed afterwards when an employee complains. In its guidance on monitoring employees, the Dutch Data Protection Authority sets out the conditions it applies, and it is worth reading before drafting a policy.
Necessity, proportionality and subsidiarity
Necessity means the employer cannot achieve its aim in any other way. Before reading messages, the obvious alternatives have to be exhausted: interviewing the people involved, checking system logs, examining the transactions themselves, asking the employee for an explanation. If one of those would have answered the question, reading the messages was not necessary and the processing is unlawful, however incriminating the outcome.
Proportionality means the intrusion has to be in a sensible relation to what is at stake. A credible suspicion that an employee is selling the customer database to a competitor justifies far more than an unexplained absence or a suspicion about expense claims. A search of one conversation over a defined period is proportionate in a way that a full export of a phone is not.
Subsidiarity means choosing the least intrusive form of the measure that will still work. In practice that translates into narrowing the search before it starts: a limited date range, named participants, defined search terms, and a rule that anything obviously private is not read. It also means limiting who sees the results. A search carried out by a small, identified group under a written instruction is defensible; one where a manager scrolls through a phone at their desk is not.
Two supporting duties belong here. Where monitoring is systematic and on a significant scale, a data protection impact assessment is required under Article 35 of the General Data Protection Regulation before it begins. And whatever is collected must be kept no longer than the purpose requires; an investigation file that stays on a shared drive for years is a separate breach.
Transparency: the policy comes first
Monitoring that has never been announced is almost always unlawful, because the employee could not know it might happen. The employer therefore needs a written policy on the use of devices, networks and communication tools, and it has to be genuinely accessible rather than buried in an appendix nobody has read.
A workable policy answers concrete questions. Is private use of the company phone permitted, and to what extent? Which systems are logged, and for how long are the logs kept? In what circumstances can content be looked at, who decides, and who carries out the check? Is the employee informed, and when? What happens to the material afterwards? A policy that merely reserves the right to monitor everything at any time is worse than useless: it is unlikely to be enforceable, and it signals to a court that the employer never thought about proportionality.
Employees should read the policy before there is a problem, and should treat vague wording as a warning sign. Phrases such as monitoring may take place from time to time, or the company may access any and all data on company equipment, are not a lawful basis. They are a statement of intent that Dutch and European law does not automatically honour.
The works council has to agree
In the Netherlands monitoring is not a decision management can take on its own. An undertaking that normally employs at least fifty people must have a works council (ondernemingsraad), and Article 27 paragraph 1 of the Works Councils Act gives that council a right of consent, not merely a right to be heard, on two arrangements that are directly relevant here.
- Under subsection k, any arrangement concerning the processing and the protection of the personal data of the people working in the undertaking.
- Under subsection l, any arrangement concerning facilities that are intended for, or suitable for, observing or monitoring the presence, conduct or performance of employees.
The consent requirement bites on the arrangement, not on the individual investigation. An employer that wants to introduce monitoring software, a logging regime, a camera system or a policy allowing communications to be inspected needs the works council’s written consent first. If consent is refused, the employer can ask the subdistrict court for substitute approval, which is granted only where the refusal is unreasonable or the decision is justified by compelling business reasons.
The consequence of skipping the step is severe and often overlooked. A decision taken without the required consent is void if the works council invokes that nullity in writing within one month of learning that the decision was taken, and the employer can then be restrained from applying it. An employer that dismissed someone on the strength of a monitoring regime the works council never approved has a problem that is quite separate from the merits of the dismissal.
Private phone, company phone, and bring your own device
Ownership of the device matters far less than employers think. What matters is the nature of the communication and what the employee could reasonably expect.
On a private phone, the employer has no access at all. It cannot require the phone to be handed over or unlocked, it cannot install software on it without agreement, and an employee who refuses is exercising a right rather than obstructing an investigation. An employer that takes disciplinary action purely because an employee declined to unlock a private phone is on very thin ice. The only realistic routes to material on a private device run through the criminal process, with the powers that belong to the investigating authorities, or through a court order in civil proceedings.
On a company phone the position is more nuanced but not reversed. If private use is permitted, expressly or in practice, the employee retains a reasonable expectation of privacy in private conversations on that device, and WhatsApp is understood by everyone as a channel for private communication. The employer may look at what it needs for a defined and legitimate purpose. It may not treat ownership of the handset as a licence to read everything on it.
Bring your own device arrangements sit in between and deserve more attention than they usually get. Where an employee uses a personal phone for work, the employer’s access should be confined to a separate, managed work environment on the device: the work container, the company mail account, the managed applications. Mobile device management software that allows the employer to see location, installed applications or personal content goes beyond what the arrangement requires. Before agreeing to install such software, an employee should ask in writing what it can see, what happens on termination of employment, and whether remote wiping affects private data. Those questions belong in the policy, and the works council has a say in it.
Business chat is a different case
Not every message is private. A message in a company WhatsApp group about a client, a conversation in a workplace chat tool provided by the employer, or an exchange on a company account used for customer contact is business communication. It is recorded on systems the employer controls, it is part of the administration, and in some sectors it has to be retained for regulatory reasons.
Even there the employer’s freedom is not unlimited. The same principles apply: a defined purpose, no more data than that purpose requires, transparency about what is logged and retained, and a rule for what happens when private matters surface in a work channel, as they inevitably do. Colleagues discussing a birthday present in a work group have not surrendered their private life. The realistic guidance for employees is the practical kind: keep private conversations off work channels and off work devices, because the clearer the separation, the stronger the legal position on both sides.
When targeted access is lawful
There are situations in which an employer may look, and it helps both sides to know what they look like. The pattern is always the same: a concrete, articulable suspicion of serious misconduct, an investigation that starts with the least intrusive step, and a narrow search that is documented as it happens.
Take a suspicion that an employee is passing client files to a competitor. A lawful investigation begins with the objective material: which files were downloaded, when, from which account, and whether the pattern matches the suspicion. If that establishes the facts, the messages are never touched. If it does not, and the remaining question can only be answered from communications, the employer defines the scope in advance, limits it to the relevant period and the relevant channel on the equipment it provides, has the search carried out by a defined group, and records the reasoning. Confronting the employee with the findings and hearing their explanation is part of the process, not an optional courtesy.
The unlawful version of the same investigation is familiar. Monitoring software is installed on the phones of a whole department, months of conversations are read in the hope that something turns up, and the private messages of people who were never suspected of anything are examined along the way. That fails necessity, proportionality and subsidiarity at once, and the fact that it produced evidence does not repair it.
Covert monitoring, where the employee is not told in advance, is exceptional. It can only be considered where informing the employee would defeat the purpose, where the suspicion is serious and specific, where the measure is limited in time and scope, and where the employee is informed afterwards. Anything that becomes a permanent secret regime has stopped being an exception.
What happens to unlawfully obtained evidence
Employees often assume that a breach of privacy makes the evidence unusable. In Dutch civil proceedings, including employment cases, that is not the rule. The interest in establishing the truth generally prevails, and evidence obtained in breach of privacy rules is set aside only in exceptional circumstances. The breach is not without consequence: it can support a separate claim, it colours the court’s view of the employer, and it can turn a finely balanced dismissal case against the employer. But an employee who is counting on the material simply being excluded is usually counting on the wrong thing. The interaction between privacy and dismissal is dealt with in our article on summary dismissal based on WhatsApp messages.
When a colleague hands over the messages
In practice the employer usually does not go looking at all. A participant in the chat forwards a screenshot, or a colleague who was shown something on a phone reports it. That changes the analysis, because the employer has not accessed anything; it has received information.
Receiving is not the end of the matter. From the moment the employer holds the material it is processing personal data, and the same questions apply: is there a legitimate interest in using it, is using it necessary, and is the scope limited to what that interest requires? An employer that receives one screenshot and responds by asking for the whole conversation, or by asking the reporting colleague to keep collecting, has moved from receiving to monitoring and needs to meet the full test.
The employee’s position is weaker here than many expect. A message sent to a colleague has left the sender’s control, and a recipient is generally free to pass it on. The argument that the employer obtained it unlawfully rarely succeeds where a participant handed it over voluntarily. What can still be argued is context and completeness: a screenshot of four messages out of a long exchange is a partial picture, the employer knows that, and an employer that acts on it without asking for the rest or without hearing the employee has not investigated properly. Where an employer is confronted with such material, the safe course is to secure the full conversation from the person who reported it, to record how it was obtained, and to hear the employee before drawing any conclusion.
Three situations that regularly go wrong
The first is sickness absence. An employer that reads messages, or checks social media, to test whether an employee is really ill is processing health data, which enjoys the strongest protection. An employer may ask when the employee expects to return and whether work-related causes played a part; it may not ask about the nature of the illness and may not record it. Those questions belong with the company doctor.
The second is a suspicion of undisclosed side activities. Whether an ancillary job is even prohibited depends on the contract and on the statutory rules on ancillary employment, and reading messages is almost never the least intrusive way of establishing what someone does in their own time.
The third is a reorganisation or a conflict that has already escalated. Once a dispute is running, an employer that starts searching communications for material to use in it is doing something a court will read as building a file rather than investigating an incident, and the intrusion will be weighed accordingly.
What to do if your employer has read your messages
Act in a considered order, and do not delete anything. Deleting messages after a dispute has arisen looks like concealment even when it is not, and it can be held against you in later proceedings.
Start by establishing what happened. Ask the employer, in writing, on what basis the messages were accessed, what exactly was accessed, by whom, when and for what purpose, and what has happened to the material since. You are entitled to that information as a data subject, and a request for access under the General Data Protection Regulation obliges the employer to answer within one month, extendable by two months for complex requests. That answer is also the foundation of anything you do afterwards.
Then choose the route. An internal complaint to the employer or to the data protection officer, if there is one, is the quickest and is often enough where the breach was a misjudgement rather than a policy. The works council is the right body where the problem lies in the monitoring arrangement itself rather than in your individual case. A complaint to the Dutch Data Protection Authority is free and can be filed by any data subject; the authority decides for itself whether to investigate, and it is a supervisory route rather than a way of obtaining compensation.
Where you want compensation or an order to stop, the civil court is the forum. The General Data Protection Regulation gives a right to compensation for material and non-material damage caused by an infringement, and Dutch courts award restrained amounts for non-material damage: distress alone is not enough, and the loss has to be substantiated. In an employment context the more effective claim is often not the privacy claim at all. If the monitoring is used as the basis for dismissal, the argument that the employer acted in a seriously culpable manner can be worth considerably more than the data protection claim standing on its own. Our overview of employee rights in the Netherlands sets out the wider position.
Practical guidance for employees
The habits that protect you are unremarkable and effective. Keep private conversations on your own phone and off company hardware and company networks, because that is what makes the expectation of privacy obvious rather than arguable. Treat anything written in a work group as part of the professional record, since it is. Check whether backups of work-related chats are being saved to your personal cloud account, and whether work applications on your own phone are syncing more than you intended.
If you are asked to hand over or unlock a phone, ask on what basis, what exactly will be looked at and who will look. Put the answer in writing. Declining to unlock a private device is a right; on a company device, ask for the scope to be defined and for the check to be carried out in your presence. If you are asked to install management software on your own phone, ask what it can see and what happens when you leave.
Practical guidance for employers
Doing this properly is not expensive; doing it badly is. The order of work is fixed. Write the policy first, describing what is monitored, why, by whom and for how long the data are kept. Obtain the works council’s consent for the arrangement before it is introduced, and record that consent. Carry out a data protection impact assessment where the monitoring is systematic or extensive.
When an incident arises, resist the instinct to look immediately. Define the question, exhaust the objective sources, and if messages are genuinely needed, fix the scope in writing before opening anything: the period, the channel, the participants, the search terms, the people authorised to see the results. Hear the employee. Keep the material secure, use it only for the purpose that justified collecting it, and delete it when that purpose has been served.
Two errors recur. The first is treating ownership of a device as a licence, which it is not. The second is retrofitting the justification, writing down the legitimate interest only once an employee complains, which reads exactly as it is. An employer that can produce a policy, a works council consent, a written scoping decision and a record of what was examined is in a strong position even if the investigation itself finds nothing. Our guide to Dutch data privacy law covers the surrounding obligations.
Frequently asked questions
Can my employer read messages I have already deleted?
Generally, no. Once you’ve properly deleted a message from your device, your employer can’t access it through any normal means. From their perspective, that digital trail is gone.
However, there's a crucial exception for formal legal investigations. In the rare event of a court order, forensic specialists might be able to recover deleted data. But this is an extreme scenario and has nothing to do with standard workplace monitoring. Also, remember that unless you used the "delete for everyone" feature right away, the other person in your chat still has a copy.
What if I use WhatsApp web on my work computer?
Using WhatsApp Web on a company computer is a significant privacy risk. It's highly likely that your employer has software installed that can monitor screen activity, log keystrokes, or track network traffic.
While your messages are still end-to-end encrypted as they travel across the internet, monitoring software can capture them directly from your screen as they are displayed. It's the digital equivalent of someone reading over your shoulder.
The safest bet is to keep all private communications strictly on your personal phone, completely off company-owned hardware and networks. This creates the clearest possible boundary and gives you the strongest legal protection.
Does this apply to other apps like signal or telegram?
Yes, absolutely. The robust privacy protections under Dutch and EU law, especially the GDPR, are tied to the act of communication, not the specific app you use. Your fundamental right to privacy and your "reasonable expectation of privacy" extend to personal conversations on any messaging service, whether it’s Signal, Telegram, or another platform.
An employer would have to meet the exact same strict legal tests—necessity, proportionality, and transparency—before they could even think about monitoring messages on these apps. The legal principles are universal.
my boss asked to see my phone. what are my rights?
You are under no obligation to hand over your personal phone or unlock it for your employer. Simple as that.
For a work-provided phone, your company’s IT policy is the first place to look. But even with a company device, an employer cannot force you to open a private app like WhatsApp without a valid and serious reason—one that satisfies the demanding legal standards we've discussed.
If you feel pressured, it's best to calmly state that you aren't comfortable sharing your private data and suggest they speak with HR. If the pressure continues, your next best step is to seek advice from a legal representative.
Law & More advises employees and employers on workplace monitoring, from assessing whether an inspection of messages was lawful to drafting a policy that will survive scrutiny by the works council and the Dutch Data Protection Authority. Where monitoring has led to a dismissal, we assess both tracks together. Contact our employment lawyers to discuss your situation.


