Workplace Email Privacy: What Your Employer Can and Can’t Read
Updated September 2026
A woman in New Jersey used her work laptop to email her attorney about a discrimination claim. She used her own Yahoo account, password-protected, and never saved the login. Months later, after she’d handed the laptop back, her employer’s forensic examiners pulled the messages out of the browser cache, and the company’s lawyers read them.
The New Jersey Supreme Court held they had no right to. The emails were hers, the privilege survived, and the company’s attorneys were sanctioned for reading them.
That case is the clearest illustration of what workplace email privacy actually protects and what it doesn’t. Your work account isn’t private and never was. Your personal account usually is, even when you open it on their equipment. The device is the thing everyone fixates on, and it turns out to be the least important part.
The Short Answer
| Your work email account | Your personal account | |
|---|---|---|
| Can they read it? | Yes, essentially without limit | Generally no |
| Does it matter whose device? | No | No |
| Does the policy control? | Largely | No — a policy can’t authorize accessing an account you own |
| What protects you | Almost nothing | The Stored Communications Act, and in some cases privilege |
The device is the thing people fixate on and it’s the least important variable. What matters is who owns the mailbox.
For the work-account side of this in more depth, see can your boss read your emails. What follows is mostly about the side people don’t understand.
Table of Contents
Your Work Email Account
Short version: assume everything is readable, retained, and searchable.
Employers own the system. Courts have consistently found employees have little to no reasonable expectation of privacy in email sent through a company account, particularly where a policy says so. Messages sit on the company’s servers, are typically retained for years, and become discoverable in litigation.
Deleting doesn’t help. Deleted mail persists in backups and journaling archives long after it leaves your view, and IT can usually produce it in minutes.
The practical rule hasn’t changed in twenty years: don’t write anything in work email you wouldn’t want read aloud in a deposition. Which is also the subject of can you be fired for something you say in an email.
Personal Email Checked on a Work Computer
Here’s where it gets interesting, and where most people assume they have no rights when they actually do.
In 2010 the New Jersey Supreme Court decided Stengart v. Loving Care Agency. Marina Stengart used her company laptop to email her attorney about a discrimination claim, through her own password-protected Yahoo account. She never saved the password. After she returned the laptop, the company hired forensic examiners who recovered seven or eight of those emails from the browser’s cached temporary files, and the company’s lawyers read them.
The court held unanimously that she kept a reasonable expectation of privacy. Her account was personal and password-protected, the company’s policy was ambiguous about personal webmail, and nothing warned employees that cached copies could be forensically recovered. The emails stayed privileged. The company’s own lawyers were sanctioned for reading them.
The principle that survives: using a company device to access a personal account doesn’t hand your employer the contents of that account. A cached fragment on a hard drive isn’t the same as a message in the company’s mail system, and a broad monitoring policy doesn’t automatically cover it.
That’s a New Jersey decision and it binds only New Jersey courts. But it’s been widely cited, and the reasoning has traveled.
When an Employer Logs Into Your Account
This is the clearer violation, and it happens more than you’d think — usually because a browser saved the password on a company computer and someone decided to look.
In Pure Power Boot Camp v. Warrior Fitness Boot Camp, an employer used credentials automatically saved on company computers to log into former employees’ Hotmail and Gmail accounts, reading 546 messages over nine days. A federal court in New York held this violated the Stored Communications Act.
Two parts of that ruling are worth knowing.
First, statutory damages were available even though the employees proved no actual harm. You don’t have to show the reading cost you anything.
Second, the court counted violations by account accessed, not by message read — four accounts, four violations, at the statute’s $1,000 minimum each, rather than 546 violations. That cuts both ways: it caps the arithmetic, but it also means a single unauthorized login is worth $1,000 before you prove anything else.
Saved credentials are not consent. That the password was sitting there didn’t make the access authorized.
What the Stored Communications Act Gives You
The SCA, at 18 U.S.C. §2701, makes it unlawful to intentionally access stored electronic communications without authorization, or to exceed authorized access.
It’s the most useful statute in this area because it’s specific, it carries a damages floor of $1,000 per violation, and it provides attorney’s fees — which means a lawyer can take the case.
Where it applies: your personal webmail, your personal messaging accounts, communications held by a service provider.
Where it doesn’t: email in your employer’s own system. They’re the provider. Reading their own stored mail isn’t unauthorized access.
There’s a companion statute, the Wiretap Act, covering interception of a message in transit rather than in storage. In practice most workplace cases are SCA cases, because employers read stored messages rather than intercept live ones.
Attorney-Client Privilege
If you’re talking to a lawyer about your employer, use a personal account on a personal device, over a network that isn’t theirs.
Stengart held that privilege survived even on company equipment, which is reassuring. But litigating whether privilege survived is a fight you’d rather not have, and a different court in a different state could come out the other way — particularly if the employer’s policy is explicit about personal webmail rather than ambiguous.
The cost of using your own phone on your own data is zero. The cost of getting this wrong is your case.
Never use work email for this. Not once.
States That Require Notice
Several states require employers to tell you they’re monitoring electronic communications. Notice doesn’t make the monitoring unlawful — it makes the silence unlawful.
These laws are expanding and the details change. Check your state’s current requirements rather than relying on a summary.
| State | Requirement |
|---|---|
| New York | Written notice at hire of any monitoring of email, internet or telephone, with employee acknowledgment, plus a posted notice |
| Connecticut | Prior written notice of electronic monitoring. Public Act 26-73, effective 1 October 2026, adds requirements around location-specific monitoring |
| Delaware | Daily notice or a one-time written acknowledgment before monitoring email or internet use |
Twenty-eight states also restrict employers from requiring passwords or account access for personal online accounts — a separate protection that reaches personal email in many of them.
If your employer never told you and you’re in a notice state, that’s a violation independent of anything they found.
Forwarding Work Email to Yourself
The most common serious mistake people make, and they make it at exactly the wrong moment.
Someone decides to make a claim, realizes the evidence is in work email, and forwards a few hundred messages to a personal account before resigning. It feels like preserving evidence. What it often looks like afterward is misappropriation of confidential information, and employers have used it to counterclaim, to justify termination for cause, and to shift a case from being about the employer’s conduct to being about the employee’s.
There’s a better route and it costs nothing. Tell your attorney what exists and where. An employer under a litigation hold has an obligation to preserve it, and a formal preservation letter is far stronger than a folder in your Gmail — because it can’t be characterized as theft.
If you’ve already done it, tell your lawyer immediately. It’s a manageable problem handled early and a serious one handled late.
What to Do
Keep the accounts separate. Personal mail on a personal device, over personal data. Not because your employer is watching, but because entanglement is what creates the hard questions.
Clear saved passwords from company machines. Browser-saved credentials are how most unauthorized access actually happens.
Look up your state’s notice law. If you’re in New York, Connecticut or Delaware and were never told, that’s worth knowing.
Write down what happened, with dates. If you believe your personal account was accessed, note when you discovered it, what evidence you have — login alerts, IP records, device history — and who had access to the machine.
Check your account’s security log. Gmail and Outlook both show recent sign-in activity with times and locations. That record is often the whole case, and it doesn’t keep forever.
Frequently Asked Questions
Can my employer read my personal Gmail if I check it on my work laptop?
Not the account itself. What they may be able to recover are cached fragments left on the device — which is what happened in Stengart, where the court held the employee still kept her privacy expectation and her privilege. Logging into the account is a different matter and can violate the Stored Communications Act.
Does it matter if I signed a monitoring policy?
For your work account, yes — it strengthens the employer’s position considerably. For your personal account, much less. A policy about company systems doesn’t authorize access to an account the company doesn’t own.
Can they read emails I already deleted?
From your work account, almost certainly. Deleted mail persists in backups and archives well beyond what you can see.
I’m on my own laptop but the company Wi-Fi. What can they see?
Network traffic is a different question from email content, and modern encryption limits what’s visible in transit — generally which sites you connected to rather than what you wrote. See can your employer see your browsing history.
They read my personal email. What’s it worth?
The SCA provides statutory damages of at least $1,000 per account accessed, plus attorney’s fees, and Pure Power held you don’t need to prove actual harm. Whether it’s worth pursuing alone depends on the facts, but it’s often a strong add-on claim to a larger case.
Does any of this apply to Slack or Teams?
Same principle, different platform: the company’s workspace is the company’s. See can employers monitor Slack or Microsoft Teams messages.
The Bottom Line
Stop thinking about the device and start thinking about the account. Your employer’s mailbox is theirs to read; your mailbox is yours, and it stays yours even when you open it on their laptop.
Two practical consequences. If you’re going to talk to a lawyer, do it from a personal account on a personal device — the protection probably survives either way, but you don’t want to spend your case proving it. And if you’re gathering evidence, don’t forward work email to yourself. Tell your attorney what exists and let a preservation letter do the work.
Related Articles
- Can Your Boss Read Your Emails?
- Can You Be Fired for Something You Say in an Email?
- Can Employers Monitor Slack or Microsoft Teams Messages?
- Internet Privacy at Work: Do You Have Rights?
- Can Your Employer See Your Browsing History?
- Can Your Employer Search Your Phone at Work?
Disclaimer
This article is general information about employment law, not legal advice, and reading it does not create an attorney-client relationship. Privacy and monitoring laws vary by state and change frequently, and the cases described are decisions of particular courts that may not control in your state. For advice about your own situation, consult an employment attorney licensed in your state. Please also read our Disclaimer and Terms and Conditions.
Discover more from Worker Wisdom℠
Subscribe to get the latest posts sent to your email.