Laws regarding internal company policy are super loose.
Basically, anything on official computers, phones, or paper docs belongs to the company. That includes desks, drawers, filing cabinets—everything.
So, sure, you can lock your papers in a drawer and take the key home, but the company still has the right to peek inside whenever they want without you knowing.
Even those landline calls at the office? They can be recorded at will without even telling the person on the other end. The call is company property, period.
Work cell phones are a bit more sensitive since the data usually goes through an outside carrier, but it’s the same deal. The phone or the number belongs to the firm, they pay the bill, so they own the recording. There are telecom services that can redirect every single call from an employee's mobile or work number straight to a server chosen by the owner of Company X. You might think you have a phone, but if the number belongs to Company X, every call or text gets sent straight to them automatically.
It's the same if you're using a company phone but have a private number plugged in. Ever heard of "locked" phones?
Whose money, whose rules.
A company can't touch your private email, Skype, or WhatsApp accounts—not legally—even if you open them on a work device.
But! If you use them on company gear, they have plenty of rights to install spyware that logs everything from your passwords to every chat, encryption be damned. It happens all the time. There are stealth programs that run in the background and beam everything to specific servers. There are even third-party cloud services that handle this. Just a quick Google search will show you.
https://www.spyagent.net/ They can even capture full screenshots without ever touching your webcam. And don't even get me started on how some bosses feel entitled to use the camera—whether it's on your PC or your phone—to spy on employees, even after hours, just because the device is "official."
So, if you start a private video or voice session like Skype on a work device, the company basically has the right to record everything you do.
Don't confuse this with talking to outside parties; for those people, companies actually have to give explicit notice at the start of the call if it's being recorded.
American laws are pretty weak on this stuff. (Like everything else, honestly.)
Back in the day under socialism, this was explicitly banned, but hey, technological progress... democracy and the rule of law, right?
And no, encryption won't save you. Your only bet is using completely private devices that are totally disconnected from the company.
As far as I'm concerned, if you find a company pulling this kind of surveillance, you should bail the second you get a few solid references under your belt. That’s a toxic, rotten environment run by incompetent bosses. If someone is really riding you, gather evidence of the spying. It’s always useful when you can shove proof in the face of the people "supervising" you that they never disclosed they were watching. Nothing shuts a monitor up faster than proving you were actually monitoring *them*. And since you did it on your own private gear, they can't claim any rights to your logs or content. Watch how fast their tone changes then. 😉
=================
Keep in mind, all they need to surveil you is to know you're posting on Facebook, Twitter, Instagram, or Reddit.
Some sites aren't even properly secured with HTTPS, making them extra vulnerable. Bosses like that can literally read what employees are writing online in real-time. These managers think they're so clever, assuming their staff doesn't realize they're reading their messages. The only question is who those messages are for—the random people on a forum or their own bosses.
It’s the exact same deal with Facebook, Twitter, or whatever else—even if they’re technically "safe" because of HTTPS. Look, if you check the logs on a local firewall, it’s dead easy to see when Employee X hits up Facebook to drop a message (you can tell just by looking at the traffic spikes). Give me an hour or two of shallow digging, and I can bridge that 1:1 gap to prove that "John Doe" on Facebook is actually Mike Miller from Company X. It’s honestly as simple as signing a contract with your full legal name and SSN.
Sure, there are ways to put some guardrails up (like using a VPN, Secure DNS, DNS over TLS, or DNS over HTTPS), for example:
https://www.cloudflare.com/learning/dns/dns-over-tls/But at the end of the day, it always comes back to this: any halfway decent firewall admin can spot user activity in their sleep.
There’s a fix for that too, but that’s a whole different conversation.
Bottom line? Use your own phone, your own number, your own laptop. Keep everything encrypted and stay off the company Wi-Fi or the office cellular network entirely.