A company computer is not a private vault. Even the internal directive is not permission to read love letters.

Zaměstnavatel smí přiměřeně kontrolovat, zda se firemní technika nezneužívá k soukromým účelům. Reading mail content and surreptitious surveillance is an exception based on good reason, notice and proportionality — not an automatic right because the computer belongs to the business.

A company computer is not a private vault. Even the internal directive is not permission to read love letters.
Editorial illustration created with AI assistance.Zaměstnavatel smí přiměřeně kontrolovat, zda se firemní technika nezneužívá k soukromým účelům. Reading mail content and surreptitious surveillance is an exception based on good reason, notice and proportionality — not an automatic right because the computer belongs to the business.
Evidence record

Evidence passport

Sources and checks
22 sourcesSources checked:
Publication and updates
Published: Updated: Not stated
Correction history
0 corrections
Role of AI
Not stated
Reading time
27 min read
Listen
00:0000:00
Advanced controls
1.00 ×
Ready
Evidence record

Conclusion at a glance

What is established

Zaměstnavatel smí přiměřeně kontrolovat, zda se firemní technika nezneužívá k soukromým účelům. Reading mail content and surreptitious surveillance is an exception based on good reason, notice and proportionality — not an automatic right because the computer belongs to the business.

What remains uncertain

The material used does not by itself establish an individual person’s guilt or motive, or the outcome of a case beyond the facts described.

What would change the conclusion

New verified evidence, a more complete case file, a final ruling or an independent review of the method used would change the conclusion.

Article contents
  1. One hundred and two hours on the web in one September, the body of a work email in January is not open
  2. Workplace control has at least six layers
  3. Control of resource usage is not control of mail content
  4. Consent in an employment contract is not free consent
  5. NSS kidnapped 3 days after the leak. It wouldn't bear a blanket read for sure
  6. A pre-intervention checklist says more than the sentence it's our computer

Section: Justice & law | Technology & AI Author: V Reading time: ~27 min Sources and further reading: 22 items Topics: employer, e-mail, monitoring, § 316, GDPR, Bărbulescu, metadata, privacy SEO / Working Title: Can an employer read your emails and monitor your computer?

Can an employer read your emails and monitor your computer? The question sounds simple until we notice that we are not comparing one thing. Checking the time on the site can be reasonable and reading the body of the message is still an excess. A directive can exist and still lack a scope. A hidden camera at the checkout can stand up in one judgment, but it must not stand up in the dressing room. Consent in an employment contract can be signed without being a free consent under the GDPR.[9] Therefore, the following text does not ask who the computer belongs to. He asks how deep the intervention goes — and whether it will carry reason, information and a gentler way.

1. One hundred and two hours on the web in one September, the body of a work email in January is not open

Let's imagine a post-incident meeting. Employer says: laptop and clipboard name@firma.cz they are ours. The employee complies with Article 13 of the Charter and confidentiality of messages.[3] IT shows a list of visited pages and time. HR is preparing disciplinary proceedings. The Labor Inspectorate reads § 316 of the Labour Code. ÚOOÚ asks about the administrator of personal data and the legal title. Everyone talks about control. But everyone thinks of a different depth of intervention.

In case 21 Cdo 1771/2011, the Supreme Court dealt with a list of internet activities of one employee for the period 1.–30. 9. 2009. In fact, 102.97 hours of non-work related surfing appeared. The court emphasized that it was not about reading the content of e-mails, SMS or MMS, but about checking the use of work resources.[6]

The expert analysis of the same decision on epravo.cz works with the same cut: for the assessment of private use of the Internet, the record of activity was decisive, not the opening of private communication.[17] This is important because the dispute is often told as a blanket consent to monitoring. A more accurate reading says something narrower.

The Supreme Administrative Court dealt with a different situation in judgment 6 Ads 21/2026-27 of 18 March 2026. After a specific leak of personal data at the ČÚZK, the contents of the work mail of one civil servant were checked in a narrow window of 2.-4. 1. 2024. The disciplinary measure was 15% of salary for 3 months; it is a sanction in one official matter, not a tariff for reading emails.[7]

At first glance, this is a "can or can't read emails" dispute. In fact, we are comparing the activity listing to the opening of mail content. Therefore, they can all be partly right and the common sentence still wrong. Company equipment is not a private safe. But even owning a computer does not give the free right to read every message.

A company computer is not a private vault. Nor is the directive permission to read love letters.

— Jiný Kontext

2. Workplace control has at least six layers

The first layer is asset ownership. The laptop, phone, work e-mail and company network may belong to the employer. § 316 odst. 1 of the Labour Code prohibits employees from using the employer's production and work resources, including computer technology and telecommunications equipment, for personal use without consent; the employer may monitor compliance with this prohibition in a reasonable manner.[1]

The second layer is the expectation of privacy in the workplace. In the Halford, Copland and Bărbulescu decisions, the ECtHR works with the understanding that even communications from the work environment can fall under private life and correspondence.[16][12][4] NSS 2026 quotes this line next to Article 13 of the Charter.[7][3]

The third layer is the depth of intervention. Blocking sites is not the same as logging time and URLs. The time log and URL is not the same as the email header. The header is not the body of the message. The message body is not a wiretapping call. A camera on a publicly accessible cash register is not a camera in the employees' background.

The fourth layer is juxtaposed legal regimes. The Labour Code deals with the labour law boundary. Charter protects privacy and messages. GDPR addresses personal data, purpose, minimization, notification and legal title. The Labour Inspection Act provides for offences. For cameras, the ÚOOÚ methodology comes into play as a guide.[1][8][13][14]

The fifth layer is transparency and exemption. The general rule is to inform in advance about the scope and method of control if the employer implements an intervention pursuant to § 316 odst. 2.[1] The exception for covert intervention in European jurisprudence is tied to a strong and concrete reason, not to the convenience of surveillance.[5]

The sixth layer is the application of the result. A log or e-mail that was obtained for the protection of property or data should not end up as entertainment in the collective. In 2026, NSS explicitly assessed that the results of the inspection were not used for another purpose.[7]

3. The best control is the one whose intervention you can explain

Technology can log many things. That's not the answer. The right question is which intervention can be explained to the employee, the court, the labor inspectorate and the ÚOOÚ. If the explanation is based only on the sentence "it's our computer", it is weak even before the first logo.

A kind of failure What does he look like? How to test What will limit the damage
Substitution of odst. 1 and odst. 2 The URL statement is taken as permission to read the body of the email Compare NS 21 Cdo 1771/2011 with the diction of § 316 odst. 2 Metadata before content and narrow reason
Directive without scope The phrase "we may monitor" does not say how Apply the Bărbulescu criteria and § 316 odst. 3 Direct information about the scope and method
Square footage to be sure Reading all mailboxes without a specific incident Compare NSS: one employee, 2.-4. 1. 2024, data breach Time window, subject and subsidiarity
Hidden camera beyond extreme Hidden recording in the background, dressing room or kitchen Compare López Ribalda and KS Ostrava Visibility, public space and good reason
Consent as a stamp Consent in the contract is to replace the GDPR title Read WP29 2/2017 on party inequality Legitimate interest or obligation plus information
Foreign purpose of the result The audit log will be used for slander or other pressure Review purpose, access and retention period Access rights and auditing

Interpretation scheme: The table does not say that every check is prohibited. It shows the places where reasonable control becomes a deeper intervention without support.

Therefore, a good process does not start with what IT can turn on. It starts with what damage the control is intended to prevent. Otherwise, the tool begins to expand according to convenience, not reason. First, more websites are logged, then more headers, then several messages are opened, and in the end, no one knows exactly when the control of the work resource became the surveillance of privacy. It is this transition that must be visible before a dispute arises.

4. Control of resource usage is not control of mail content

§ 316 zákoníku práce is short, but important precisely because of the distinction between layers. Paragraph 1 aims at the use of the employer's funds. An employee may not use work equipment for personal use without consent, and the employer may reasonably control this rule.[1] This is the basis for checking whether the company's technology is not being misused.

Paragraph 2 is another level. It prohibits the employer from violating the employee's privacy at the workplace and in common areas by open or covert monitoring, wiretapping of calls, checking of electronic mail or correspondence without a serious reason based on the special nature of its activity.[1]

Paragraph 3 then says that if the employer is given a serious reason according to odst. 2, he must directly inform the employee about the scope of the inspection and the methods of its implementation.[1] So the directive is not a magic word. They must say what is being checked, how and why.

It does not follow that the employer may never check the electronic trail. It follows that reasonable control of resource usage and control of message content are not the same intervention. The first asks if and for how long. The second asks what exactly was written.

5. Metadata is not content

Metadata is not meaningless. They show who communicated when, through which service, with what length or volume. For a website, they can show the visited domain and time. For an email, they can show the sender, recipient, subject, time or size. All of this can be sensitive.

But the content is something else. The body of an email, an attachment, the text of a private message or a recording of a call go deeper. In judgment 21 Cdo 1771/2011, the Supreme Court relied precisely on the fact that the employer did not check the content of e-mails, SMS or MMS, but a list of activities on the Internet and time spent outside of work.[6]

This is the practical power of the word metadata. It does not excuse general supervision. It helps to find a milder remedy. If an employer is dealing with whether an employee spends work time outside of work, listing the time and categories may be less invasive than opening a personal communication. If they are dealing with a specific data leak, the question can move to content. But that's when the demand for reason, scope and guarantees grows.

Metadata also better indicates when to stop. If the dump is enough to confirm a rule violation, there's no reason to open the body of the message just out of curiosity. If the statement is not enough, the next step must be given its own justification. This sequence is not a bureaucratic embellishment. It's a way to not turn every problem into the deepest possible intervention.

The example is simple. When it comes to suspected excessive private surfing, the body of an email usually doesn't answer any better than a job listing of web activity. If there is a suspicion that a specific file has gone outside the office or company, the mere number of pages visited may not be enough. The precision of the means should follow the precision of the reason. Not the other way around.

Metadata is not content. The page dump is not an open box.

— Jiný Kontext

6. A business address with a name is not a free safe. A private account is a different matter

Email is not one type of space. A personal Gmail or List open on a work computer is a different case than a work address name@firma.cz. Physical address type info@firma.cz is still different. Privacy expectations vary by account purpose, designation, internal rules, and reporting.

Professional literature quoting the historical opinion of the Office of the Inspectorate of Health and Welfare 2/2009 describes the difference between private free-mail, a work address with a name and a mailbox. A private account has the strongest expectation of privacy. For a work address with a name, headers are typically allowed to be checked rather than content. A physical address has a lower personal element.[10][11]

A caveat is needed here. Opinion ÚOOÚ 2/2009 was not found in the file on the ÚOOÚ website as an up-to-date document as of September 2026. Therefore, it cannot be worked with as a binding living rule. It is a historical interpretation cited by literature. The valid framework needs to be built mainly on § 316, the Charter, GDPR, ECtHR and Czech jurisprudence.[1][3][8][4][7]

So it's not a free safe. It's not even a corporate bulletin board without privacy. It is a working tool in which there can be a personal trace. And the depth of intervention must correspond to the reason.

7. The reported monitoring is not a hidden camera

Visible monitoring with a clear notification and hidden recording are not two versions of the same thing. They differ in their interference with expectations of privacy. An employee who knows what is being measured, when and why can adjust their behaviour and can defend themselves. Hidden hit takes away this option.

In López Ribalda and others v. Spain, the ECtHR considered hidden cameras at supermarket checkouts. On 17. 10. 2019, the Grand Chamber found no violation of Article 8 of the Convention by a ratio of 14 : 3. But the essential thing was that it was a space open to the public, there was reasonable suspicion of theft, loss and the recording was limited to 10 days in 2009.[5]

This does not mean that a hidden camera is generally okay at work. It follows that an extreme and narrow factual situation can stand before the ECtHR. Czech § 316, odst. 2, explicitly classifies covert surveillance as one of the interventions that must not occur without a serious reason based on the special nature of the activity, and odst. 3 requires information on the scope and method of control.[1]

The practical distinction is simple. The box office open to the public is not a cloakroom. A visible camera with a pictogram is not a hidden camera. A short check after losses is not a blanket check to be sure.

In employment law, consent easily turns into a rubber stamp. An employee signs a contract, addendum, or directive because they want or want to keep a job. That is why WP29, in opinion 2/2017 on data processing in the workplace, emphasizes the inequality of parties and caution when using consent as a legal title.[9]

GDPR requires legal title, purpose, transparency and minimization for the processing of personal data.[8] For the employer, it is more appropriate to consider a legal obligation or a legitimate interest, if the conditions are met. "I agree to all monitoring" alone is weak because the employee may not have a real choice.

This does not mean that the employee should not receive information. On the contrary. Information is different from consent. The employer must describe what it processes, why, for how long, who has access to it and how the employee can defend himself. For interventions pursuant to § 316, odst. 2, the Labour Code also works with direct information about the scope and method of control.[1]

So the short sentence is: consent is not a cover sheet. If the check wouldn't pass without consent, the employee's signature usually won't save it.

9. Bărbulescu is not a ban on corporate IT auditing. There are six criteria

Bărbulescu v. Romania is often used as a hammer. One side says: ECtHR banned employers from reading reports. The second says: the employee was using a company account, so he lost. Not a single abbreviation corresponds to the judgment of the Grand Chamber of 5. 9. 2017, which by a ratio of 11 : 6 found a violation of Article 8 of the Convention due to the fact that the national courts did not sufficiently verify the protection of the employee against arbitrariness.[4]

The test is essential. The ECtHR formulated questions around prior information, scope of monitoring, legitimate reason, possibility to use less invasive means, consequences for employees and safeguards against misuse. In 2026, the NSS summarized this test in point [27] and applied it to the Czech state of affairs.[7]

What needs to be tested

The test is not done on a sentence in the directive. It is done over a specific intervention. Was the employee informed in advance about the nature and extent of the monitoring? Was the intervention limited materially and temporally? Was there a legitimate reason? Would a milder remedy be enough? What was the result used for? Were the guarantees against arbitrariness?

This does not result in a ban on IT auditing. Hence the obligation to bear its depth. Auditing accesses after a data breach is different from scanning all employees' mailboxes across the board. Dumping the metadata is different than opening the body of the message.

10. López Ribalda did not legalize dressing rooms

The López Ribaldo judgment is well misquoted. Yes, the ECtHR admitted the hidden camera footage in it without prior information. But it involved supermarket checkouts, suspected thefts, losses, an area open to the public and a record lasting 10 days in 2009.[5]

It is the details that hold the result together. When we remove them, the "hidden cameras are allowed" rule won't remain. Only a convenient phrase remains. A dressing room, toilet, rest room or office kitchen has a different intensity of privacy than a cash register, where an employee works in front of customers.

Moreover, the Czech regime is not just a copy of Article 8 of the Convention. The Labour Code in § 316 odst. 2, explicitly talks about open and covert surveillance and binds them to a serious reason in the special nature of the employer's activity.[1] The labor inspectorate can assess the working regime even when someone argues against the European judgment.

It's not a ban on cameras. It is a requirement for place, purpose, visibility, scope, information and retention time.

11. The hardware can be the employer's. Personal data in the logo is subject to GDPR

Owning a computer solves property. GDPR deals with personal data. These modes meet but do not merge. An employer can own a laptop and at the same time be the data manager in a log, email header, camera recording or export from a security tool.[8]

According to the GDPR, the administrator determines the purposes and means of processing. Must have a legal title according to Article 6, comply with the principles according to Article 5 and inform according to Article 13.[8] Act No. 110/2019 Coll. complements the Czech framework for personal data processing.[15] For deeper or systematic interventions, an impact assessment may also be considered, if the conditions of Article 35 of the GDPR are met.[8]

A practical error is the sentence: "It's our computer, so we can do whatever we want with the data." No. It's our computer, so we can protect assets and organise work. If this creates personal data about an employee, purpose, minimization, transparency and access rights come into play.

The EU Charter of Fundamental Rights protects private and family life as well as the protection of personal data in Articles 7 and 8.[21] Article 13 of the Czech Charter protects the confidentiality of messages submitted by telephone, telegraph or other similar device.[3] Corporate ownership does not turn off these layers.

At the same time, GDPR forces employers to describe even seemingly technical details in human language. A log is not just a line in the system. It is information about a specific person, his working day, sometimes about his contacts and habits. Camera footage is not just a security image. It is a record of movement and behaviour. An email header is not just an operational brand. It can show relationship, time and direction of communication. Therefore, it is not enough for the IT department to know the rule. It must be comprehensible to a human,to which it relates.

This has an operational consequence. The employer should be able to show which data is collected automatically, which only in the event of an incident and which may not be opened without special approval. Otherwise, administrator access becomes informal administrator power. At the same time, the law does not only assess the technical possibility, but also the purpose and set guarantees.

12. NSS kidnapped 3 days after the leak. It wouldn't bear a blanket read for sure

The judgment NSS 6 Ads 21/2026-27 is important precisely because it allowed the inspection of the content of company mail within specific limits. It was an employment relationship, a specific leak of personal data, one state employee of ČÚZK, time window 2-4. 1. 2024 and notification by internal regulation and notice when logging in.[7]

Commentaries on the judgment emphasize that the NSS considered a narrow intervention after the incident and that employers should not derive from it a free license to read mail preventively.[19][22] That is the correct reading. The judgment is more of a map of conditions than a permit.

The NSS applied the Bărbulescu test and evaluated, among other things, the reason, scope, reporting and use of the results.[7] If the employer were to read all the mailboxes every month just to be sure, he would miss exactly what the judgment holds: a specific incident, a limited time, a limited circle of people and a connection with data protection.

It does not follow that the content of mail is always inviolable. It follows that content opening is a late and narrow tool. First comes prevention, permissions, training, technical restrictions, headers, access auditing, and other milder paths.

The judgment is also useful for employees. She doesn't tell him that the workbox is a private journal. She tells him that even the office mailbox is not a place without rules. If the employee is informed in advance, works in a company account and there is a specific suspicion of data leakage, his expectation of privacy may be narrower. However, if the employer allows widespread surveillance to run without a clear reason, without scope and without control of use, the similarity with NSS disappears.

13. The camera in the office with the kitchen is not the camera at the cash register

In judgment 22 Ad 11/2023-29, the Regional Court in Ostrava dealt with a fine of CZK 28,000 for cameras in an office with a kitchen without a serious reason.[18] The number is the fine in one court case, not the average cost of a poorly set up camera system. More important than the amount is the resolution of the space.

A supermarket checkout is a place where an employee works in front of a customer and where property losses are dealt with. The office kitchen is a background. The dressing room and toilet are even more sensitive. To transfer the conclusion from one space to another without this layer is a methodological error.

The ÚOOÚ methodology for camera systems works with information and GDPR requirements as a guide for administrators.[14] It is not a substitute for the Labour Code. But it helps to ask practical questions: why the camera exists, what it captures, how long the recording is kept, who can see it, whether there is a pictogram and where the employee can find the second level of information.

So the camera is always also a spatial issue. The same device can have a different legal meaning depending on where it is going.

14. The fine ceiling is not the average of imposed fines

Law works with ceilings. The media often make them the expected fine. That's a mistake. § 24a of the Labour Inspection Act stipulates a maximum fine of up to CZK 1,000,000 for violating an employee's privacy according to defined facts, and a maximum fine of up to CZK 100,000 for not informing about an inspection in accordance with § 316 odst. 3.[13]

The GDPR has its own sanction regime. For selected infringements under čl. 83 odst. 5, the upper limit may be up to EUR 20,000,000 or 4% of the total worldwide annual turnover, whichever is higher.[8] This is the ceiling of the administrative fine in the European regime, not the automatic fine for one work email.

These numbers must be read with the unit, period and mode. They are the upper rates in the legal regulations in force according to the file as of 2026. They do not measure the average of the penalties imposed. It does not measure the probability of control. It does not measure reputational damage or litigation costs.

The meaning of ceilings is different. They show that monitoring is not just an internal IT setting. It can turn into a labour law and data case with responsibility before two types of authorities: labor inspection and ÚOOÚ.

15. The result may only serve the purpose of control

The legality of the acquisition is one question. The use of the result is the second. An employer may have reason to review access to data after an incident. This does not mean that the content of the communication may circulate through the company, end up in an unlimited folder or be used for a purpose unrelated to the original reason.

The GDPR is based on the principle of purposeful limitation and minimization.[8] If the log is collected for a security incident, it should be used to resolve the incident. If the camera protects property, it should not become a tool for permanent evaluation of every movement, if there is no separate reason and information for this.

In judgment 6 Ads 21/2026-27, the NSS also assessed that the results of the inspection were not used for another purpose.[7] This is not a formality. It is the purpose that keeps the intervention within limits. As soon as the result is used outside the original framework, the adequacy assessment also changes.

The rule of thumb is: before collecting, it must be clear where the result will go. Who will see it, how long it will be kept, whether it will end up in the disciplinary file, whether it will be handed over to a lawyer and when it will be deleted. Without it, control is just an open drawer.

16. A pre-intervention checklist says more than the sentence it's our computer

A good check doesn't start with installing the tool. It begins with a description of the intervention. What exactly do we want to find out? What incident or risk are we addressing? What data is sufficient for this? Which legal regime will turn on? Who will read the result?

Three penetration depth tests

The first test is the object. Is company hardware, a company account, a personal account opened on a company computer, or a personal phone checked? Each object carries a different expectation of privacy.

The second test is content. Is the time and URL, mail header, email body, image, sound or GPS location captured? When it comes to the content of the message, wiretapping or covert surveillance, we get into the stricter regime of § 316 odst. 2.[1]

The third test is reason. Is it a specific leak, property loss or security incident, or just prevention without borders? Both Bărbulescu and the NSS require more than a general possibility that something might happen.[4][7]

Before the introduction of monitoring

The employer must have a written and comprehensible warning about the scope and method of control if he is introducing control according to § 316 odst. 2.[1] In addition, according to the GDPR, they must inform about the processing of personal data, the purpose, the legal title, the recipients and the rights of the data subject.[8]

How to test whether a milder agent is sufficient

First of all, the blocking of website categories, restriction of permissions, log headers, training, two-person approval, audit of accesses or control of just a few days are offered. Only when a milder path is insufficient to protect a particular interest does it make sense to consider content. And even then only in a narrow window.

If in doubt, solve two addresses. The regional labor inspectorate assesses the labour law aspect. ÚOOÚ assesses personal data. Compliance with one layer does not automatically excuse violation of the other.[2][8]

The checklist has another advantage. Forces to write the end of the intervention. When will the monitoring end? When is the record deleted? Who will confirm that the purpose has been fulfilled or abandoned? Without an end, even reasonable control easily turns into permanent infrastructure. And permanent infrastructure then looks for new reasons for itself.

The practice of ÚOOÚ shows that these questions are not just training for lawyers. The office's control materials work with attendance, GPS, cameras and § 316 odst. 2 as a common boundary between work management and privacy invasion.[20] The sooner a company draws this line, the less it has to explain later why it crossed it.

17. The hidden cost is privacy, which the directive only listed

Internal directives often create a feeling of a done deal. The employee has confirmed that he can be monitored. The IT tool is running. HR knows where to find the statement. The lawyer has a paragraph about protecting assets. But the real intervention does not take place in the directive sentence. It takes place in what is collected, for how long, with whom, in what space, for what reason and who reads it.

That is why the directive should be more of a map than a shield. It should tell the employee what to expect and put the brakes on the employer. If it just lists all the possible hits, but doesn't separate the normal operation log from the content opening, it doesn't help either side. The employee does not know what privacy actually remains. The employer does not know when he is breaking his own rule.

Therefore, the hidden cost is not only the loss of trust. It is also an inaccuracy. A business that doesn't distinguish metadata from content will use too strong a tool for a weak problem. A company that replaces a cash register with a kitchen will transfer someone else's judgment to another space. A company that relies on consent in a contract overlooks the inequality of the parties. A company that makes NSS 2026 a blanket rule will miss three days, one employee and a specific leak.

This does not mean that the employer is defenseless. It follows that the protection of work, property and data needs precise depth. Sometimes a ban on private use and a reasonable statement are enough. Sometimes an audit is necessary. Sometimes the content of the work mail can also come in handy. But we always ask whether the intervention will carry reason, information, proportionality and a gentler way.

The moment an employer buys a laptop, he is buying a work tool. The moment it watches what a person does on it, it enters privacy and personal data. And then the question is no longer: "Is it our computer?"

It is: how deep does the intervention go — and why so deep?

Evidence record

How this article was made

Method, the role of AI, corrections and source details in one place.

Sources and further reading22 sources
  1. Other sourceColl., Labour Code, § 316. https://www.zakonyprolidi.cz/cs/2006-262#p316 · https://www.e-sbirka.cz/sb/2006/262
    Collection / e-collection: Act No. 262/ · 2006
  2. Institutional sourceState Office of Labour Inspection: Protection of personal rights of employees and protection of property interests of the employer (interpretation of § 316, e-mail vs. cameras). https://suip.gov.cz/documents/20142/43720/ochrana_os_2019.pdf/6e6c9012-7616-40f3-1fef-b443c682e94a
  3. Other sourceColl., Charter of Fundamental Rights and Freedoms, Article 13. https://www.zakonyprolidi.cz/cs/1993-2#cl13 · https://www.e-sbirka.cz/sb/1993/2
    Collection: Resolution of the Presidium of the CNR No. 2/ · 1993
  4. Other sourcehttps://hudoc.echr.coe.int/eng?i=001-176938
    ECtHR, Grand Chamber: Bărbulescu v. Romania , complaint No. 61496/08, 5. 9. · 2017
  5. Other sourcehttps://hudoc.echr.coe.int/eng?i=001-197098
    ECtHR, Grand Chamber: López Ribalda and Others v. Spain , complaints No. 1874/13 and 8567/13, 17. 10. · 2019
  6. Other sourcefile no. 21 Cdo 1771/2011 (list of internet activities, not mail content). https://www.zakonyprolidi.cz/judikat/nscr/21-cdo-1771-2011
    High Court: Judgment of 16. 8. · 2012
  7. Other sourceNo. 6 Ads 21/2026-27 (contents of official mail, Bărbulescu test). https://www.zakonyprolidi.cz/judicat/nsscr/6-ads-21-2026-27
    The Supreme Administrative Court: Judgment of 18/03/ · 2026
  8. Other source/679 (GDPR), in particular Article 4 point 7, Article 5, 6, 13, 83. https://eur-lex.europa.eu/legal-content/CS/TXT/?uri=CELEX:32016R0679
    EUR-Lex: Regulation (EU) · 2016
  9. Other sourceon the processing of personal data at the workplace (Czech version). https://uoou.gov.cz/media/zahranici/dokumenty/ostani-dokumenty-sboru/stanovisko-2-2017-ke-zpracovani-udaju-na-pracovisti.pdf
    ÚOOÚ / WP29: Opinion 2/ · 2017
  10. Other source: epravo.cz, Monitoring of employee activities by the employer . https://www.epravo.cz/top/clanky/monitoring-cinnosti-zamestnancu-ze-strany-zamestnavatele-1-cast-109563.html
    Professional literature citing ÚOOÚ 2/ · 2009
  11. Other source: AK Vych, Monitoring of employees' private communications by the employer . https://www.ak-vych.cz/monitorovani-soukrome-komunikace-zamestnancu-zamestnavatelem/
    Professional literature citing ÚOOÚ 2/ · 2009
  12. Other sourcehttps://hudoc.echr.coe.int/eng?i=001-79996
    ECtHR: Copland v. the United Kingdom , complaint No. 62617/00, 04/03/ · 2007
  13. Other sourceColl., on labor inspection, § 24a. https://www.zakonyprolidi.cz/cs/2005-251#p24a · https://www.e-sbirka.cz/sb/2005/251
    Collection: Act No. 251/ · 2005
  14. Other sourceÚOOÚ: Methodology for camera systems (non-binding guide, two-level information, GDPR). https://uoou.gov.cz
  15. Other sourceColl., on the processing of personal data. https://www.zakonyprolidi.cz/cs/2019-110
    Collection: Act No. 110/ · 2019
  16. Other sourcehttps://hudoc.echr.coe.int/eng?i=001-58039
    ECtHR: Halford v. the United Kingdom , complaint No. 20605/92, 25/06/ · 1997
  17. Other sourcehttps://www.epravo.cz/top/clanky/kontrolla-a-postih-zneuzivani-internetu-zamestnanci-k-soukromym-ucelum-85383.html
    epravo.cz: Control and punishment of misuse of the Internet by employees for private purposes (analysis 21 Cdo 1771/ · 2011
  18. Institutional source-29 (fine of CZK 28,000 for cameras in an office with a kitchen without a serious reason). https://www.zakonyprolidi.cz/judicat/ksos/22-ad-11-2023-29
    Regional court in Ostrava: Judgment 22 Ad 11/ · 2023
  19. BookHAVEL & PARTNERS: The leak of personal data on Facebook and the control of work e-mails: what the NSS told employers and employees . https://www.havelpartners.blog/unik-osobnich-udaju-na-facebook-a-kontrola-pracovnich-e-mailu-co-vzkazal-nss-zamestnavatelum-i-zamestnancum
  20. Institutional source/1472020/uoou-0299319-22.pdf
    ÚOOÚ: Control file for attendance / GPS / cameras (citing § 316 odst. 2 in the practice of the office). https://uoou.gov.cz/media/poskytnute-informace/ · 2020
  21. Other sourceEUR-Lex: EU Charter of Fundamental Rights, Articles 7 and 8. https://eur-lex.europa.eu/legal-content/CS/TXT/?uri=CELEX:12012P/TXT
  22. Other sourcehttps://danovky.cz/cs/nss-a-limity-monitoringu-elektronicke-komunikace-zamestnancu · https://www.grantthornton.cz/clanek/nejvyi-spravni-soud-limity-monitoringu-elektronicke-komunikace/
    KPMG/Grant Thornton: Practical summaries of the Bărbulescu test after NSS · 2026
Discussion

Comments

Have an additional source or a factual correction? Add a comment.

0 comments

Add a comment