Monitoring Employee Emails: An Updated Position Under Czech Law
General Framework
The Czech Labour Code (Section 316) lays down a straightforward principle that employees may not use their employer’s equipment for personal purposes without employer’s consent. This covers, among other things, work computers, company phones, and corporate email accounts. Employers are correspondingly entitled to monitor compliance with this rule — but only within limits.
The limits on the monitoring are substantial. Monitoring may quickly run up against the employees’ right to privacy, protection of correspondence, and the confidentiality of their communications. The fact that a device or email account belongs to the employer is not, on its own, a sufficient justification. Even communications conducted using company equipment will attract a degree of legal protection. Employers therefore need to think not only about whether they have grounds to monitor, but also how they carry out such monitoring.
Recent case law
The practical boundaries of employer monitoring were addressed by the Supreme Administrative Court in its judgment of 18 March 2026 (Case no. 6 Ads 21/2026).
The case involved a civil servant at a cadastral office who was suspected of posting a property registration document — containing unredacted personal data of a party to the proceedings — on Facebook. He was then alleged to have forwarded similar documents from his work email to various recipients, both at work and also to external addresses. The employer responded by reviewing the employee’s work email correspondence. The employee argued this constituted an unlawful interference with his privacy and the secrecy of his communications.
What the court decided
The court confirmed that work email is not a privacy-free zone. It referenced the European Court of Human Rights judgment in Halford v. United Kingdom (1997), which established that the protection of private life and correspondence can extend to communications made using workplace equipment. At the same time, the court emphasised that in an employment context this protection is limited by the employer’s legitimate interests — such as protecting property, trade secrets, confidential information, or personal data.
The court rejected blanket or pre-emptive email monitoring based on nothing more than a general interest in ensuring employees doing their jobs properly or efficiently. What made the monitoring lawful in this specific case was a combination of several factors:
- The employer handled sensitive data about real estate transactions and individuals’ personal circumstances.
- There was a specific, concrete suspicion of a data leak — not a vague concern.
- The monitoring was limited in time and scope, focused on establishing the extent of the leak rather than conducting a general sweep of the employee’s personal communications.
- There were no less intrusive means of establishing what had been disclosed and to whom.
The information requirement
Section 316(3) of the Labour Code requires that where an employer introduces monitoring mechanisms — particularly where the nature of its operations warrants them — it must inform employees in advance of the scope of monitoring and how it will be carried out.
The court clarified that no single prescribed form is required. The obligation can be met through an internal policy, an email notice, a verbal briefing, or other appropriate means. In the case at hand, it was significant that the employer’s internal rules expressly flagged the possibility of email monitoring, that the work email system was designated for work purposes only, and that employees confirmed awareness of the personal-use ban and of monitoring activity each time they logged into their work computer.
Practical takeaways for employers
Employers should set out the rules before they need them. The safest approach is to start thinking about monitoring policy before incidents occur. Internal IT policies, cybersecurity rules, employee briefings, and log-in notices represent appropriate means which may in practice determine whether a monitoring exercise is lawful or whether the employers would themselves face liability for privacy violations or collect evidence that would be inadmissible.
Employers’ inspection must be limited and specific, not sweeping. A general clause in internal documentation that “the employer may monitor everything” will typically not be sufficient. Rules must be concrete, intelligible, and proportionate to the nature of the business.
Employer should always start with the least intrusive monitoring options. Before reviewing the actual content of messages, employers should consider whether metadata — send times, recipients, message volumes — are able to answer the question. Looking at content should generally be the last resort, reserved for cases involving a specific suspicion of serious misconduct: a data breach, a confidentiality violation, a threat to trade secrets, or a comparable incident.
Employers should document the entire process. Monitoring should be limited in time, scope, and the individuals concerned. Employers should be able to show, after the fact, who carried out the monitoring, why it was necessary, what was the purpose, what it covered, and how the information obtained was subsequently handled.
The bottom line
While this recent judgment is broadly employer-friendly in confirming that companies can effectively protect their data, assets, and legitimate interests through email monitoring, it does not, however, provide a blank cheque for casual or routine reading of employees’ correspondence. Any employer wishing to use the results of monitoring in disciplinary proceedings, an employment dispute, or a damages claim should expect the court to scrutinise the legitimate purpose, prior notice to the employee, proportionality of the interference, the availability of less invasive alternatives, and the use to which the information was eventually put. The most effective compliance strategy is therefore not reactive but structural: clear rules, properly communicated and consistently applied, remain the employer’s best guide to lawful email monitoring – and the most reliable protection both before and after an incident occurs.

