Has anyone come across a situation where department managers want access to their employee’s emails to monitor their conversations with clients or other partners.
To come up with a compromise they will give the employees a second company email address for private or HR purposes to help protect the employee’s personal data.
I feel there are better ways to provide visibility without this intrusion
Thoughts ?
Dominga Leone
Sounds like a strange culture to me. Could they not just be copied into the relevant conversations if it is that important?
As a DPO I would make sure the organisation is very clear about the purpose and lawful basis for doing this and articulates it clearly in the Employee Privacy Notice. Without knowing the detail, it seems highly unlikely to be necessary or proportional, but a I think this processing would certainly benefit from a DPIA.