Risk
4/5/2010
03:46 PM
50%
50%

N.J. Supreme Court Rules Employers Can't Always Read Personal Email

Employees who use password-protected, third-party services can have a reasonable expectation of privacy, court says

In a ruling that could affect enterprises' privacy and security practices, the New Jersey Supreme Court last week ruled that an employer can not read email messages sent via a third-party email service provider -- even if the emails are accessed during work hours from a company PC.

According to news reports, the ruling upheld the sanctity of attorney-client privilege in electronic communications between a lawyer and a nursing manager at the Loving Care Agency.

After the manager quit and filed a discrimination and harassment lawsuit against the Bergen County home health care company in 2008, Loving Care retrieved the messages from the computer's hard drive and used them in preparing its defense.

The court found the company's policy regarding email use to be vague, noting it allows "occasional personal use."

"The policy does not address personal accounts at all," the decision said. "The policy does not warn employees that the contents of such emails are stored on a hard drive and can be forensically retrieved.

"Under all of the circumstances, we find that Stengart [Marina Stengart, the nursing manager] could reasonably expect that emails she exchanged with her attorney on her personal, password-protected, Web-based email account, accessed on a company laptop, would remain private," wrote Chief Justice Stuart Rabner in the decision, which upholds an appeals court ruling last year.

"Stengart plainly took steps to protect the privacy of those emails and shield them from her employer," Rabner continued. "She used a personal, password protected email account instead of her company email address and did not save the account's password on her computer."

Peter Frazza, Stengart's attorney, says the ruling sets a new boundary for employers who believe they have a right to all e-mails simply because they own the computer.

"Big Brother is always there, but employees have got to be comforted by the ruling, knowing they are protected," he says.

A legal analysis of the case suggests the court would have ruled against the company even if its policy had been more clearly stated.

"The Court stated that even a more clearly written and unambiguous policy regarding employer monitoring of emails would not be enforceable," the analysis states. "That is, a clear policy stating that the employer could retrieve and read an employee's attorney-client communication, accessed through a personal, password-protected e-mail account using the company's computer system, will not overcome an employee's expectation of privacy and the privilege would remain."

The Court's opinion also seems to suggest that employers cannot discipline employees for simply spending some time at work receiving personal, confidential legal advice from a private lawyer, although the Court noted that an employee who "spends long stretches of the workday" doing so can be disciplined, the analysis says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6090
Published: 2015-04-27
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix...

CVE-2014-6092
Published: 2015-04-27
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause...

CVE-2015-0113
Published: 2015-04-27
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation...

CVE-2015-0174
Published: 2015-04-27
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2015-0175
Published: 2015-04-27
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.