Short answer: Yes — on a corporate device or corporate network, your employer can technically see a great deal: the sites you visit, work emails, and screen activity. In most jurisdictions this is legal when disclosed in a written policy and employees have been notified. The main takeaway: keep work and personal separate. Use your personal device, personal mobile data, and a personal VPN for anything private — your employer has no technical access to that.
What Your Employer Can Technically See
Your work PC is company property. The IT department has full administrative access to the hardware and corporate network. This doesn't mean someone is watching you live, but the technical capability is there.
Standard corporate monitoring tools include:
- Websites visited and search queries — via a corporate proxy or DPI equipment at the network layer.
- Work email and corporate messaging (Slack, Teams, Google Workspace) — administrators have archive access at the platform level.
- Open files and applications — monitoring agents log which documents are open and what software is running.
- Screenshots and screen recording — DLP software can capture the screen at set intervals or on a trigger.
- Keystrokes (keyloggers) — record everything typed on the keyboard, including passwords to personal accounts.
- Network traffic — via corporate proxy and SSL inspection; encrypted HTTPS traffic can be decrypted at the company's servers.
Monitoring Software and DLP
Employer monitoring tools — ActivTrak, Teramind, Veriato, InterGuard — install as a background agent on the work device, often with no visible system tray icon. The agent operates at the OS level and intercepts data before any application encrypts it, including the browser. This is why running a personal VPN on a managed work PC does nothing to hide your activity from such an agent: screenshots and keylogging happen at the device layer, independently of the VPN tunnel.
Corporate Proxy and VPN
The corporate VPN is not employee protection — it is the opposite. It creates an encrypted tunnel between your device and company servers; traffic is decrypted on the employer's servers. Your entire web browsing through the corporate VPN is visible to IT. This is fundamentally different from a personal no-logs VPN. The difference is explored in our article on VPN for remote work.
Is Employer Monitoring Legal?
In most jurisdictions, monitoring employees on company equipment is legal — provided it is properly disclosed. The legal landscape varies by country, but the principle is consistent: documented policy and employee notice.
In the United States, the Electronic Communications Privacy Act (ECPA) and its "business-use exception" broadly permit employers to monitor work devices and networks when employees are notified. Many states have added their own notice requirements on top of federal law.
In the European Union, monitoring requires a lawful basis under GDPR — typically legitimate interest or contractual necessity — combined with transparency toward employees. The European Data Protection Board (EDPB) has issued guidance requiring that monitoring be proportionate, necessary, and documented. Blanket covert surveillance without notice is illegal.
Across most jurisdictions the core requirements align: monitoring must be disclosed in a written policy (employee handbook, IT policy, or employment contract), employees must have been informed, and data collected must be proportionate to the purpose. Covert monitoring of personal activity on personal devices is generally prohibited regardless of location.
Records gathered through lawful monitoring — properly documented and disclosed — are routinely accepted as evidence in employment disputes and disciplinary proceedings.
Work Device vs Personal Device: Where the Line Is
The key question is not "does your employer monitor" — it is "on which device and network is the activity happening." That determines what your employer can actually see.
| Scenario | Can your employer see it? |
|---|---|
| Personal messaging on a work PC | Yes — screen monitoring, keylogger, traffic |
| Personal sites via corporate Wi-Fi on a work laptop | Yes — proxy and DLP agent |
| Personal phone, personal mobile data, personal VPN | No — device and network are outside company control |
| Personal phone on corporate Wi-Fi without VPN | Partially — DNS queries and TLS-SNI visible to the network |
| Personal phone on corporate Wi-Fi + personal VPN | No — content hidden; only the fact of a VPN connection is visible |
| Work phone with MDM profile | Yes — MDM gives IT access to the full device |
Corporate Wi-Fi and Corporate VPN: Why Personal Traffic Is Still Visible
Corporate Wi-Fi is managed network infrastructure. Even when you connect a personal phone to it, DNS queries go through company servers by default. The domain names of sites you visit are visible at the corporate router level, without decrypting the actual traffic content.
The corporate VPN works very differently from a personal one. When you connect to a corporate VPN, all traffic is encrypted and routed to the employer's servers — where it is decrypted. Your IT department can see exactly which sites you visit through the corporate VPN, just as if there were no VPN at all. That is its design purpose: to give the company visibility into employee traffic during remote work.
An MDM (Mobile Device Management) profile on a work phone is a separate control layer. MDM allows remote management: installing and removing apps, resetting settings, tracking location, and deploying certificates for SSL inspection. A company-issued phone with an MDM profile is company hardware in every meaningful sense.
Personal VPN vs Corporate VPN: What It Actually Protects
A personal VPN with a no-logs policy — like LiMP VPN — encrypts traffic between your device and the VPN server. Your ISP, the office Wi-Fi operator, and the corporate router see only an encrypted stream and the VPN server's IP — not the content of your requests or the sites you are visiting.
This works under one condition: the VPN runs on a device that is not under your employer's control. If you run a personal VPN on a managed work PC with a DLP agent installed, the agent captures screenshots and keystrokes at the OS level before data reaches the VPN tunnel. The VPN encrypts traffic on the network, but it does not hide local activity on the device itself. For a clear picture of what a VPN hides and what it does not, see our article on what incognito mode really hides.
The scenario where a personal VPN genuinely helps is your own phone or laptop on office Wi-Fi. The encrypted tunnel hides traffic content and specific sites visited from the company's network equipment. Your employer may see that a VPN connection is active (from the IP and traffic pattern), but not what is inside it. To understand how Wi-Fi monitoring works at the network level, read our article on MAC address tracking and Wi-Fi surveillance.
Checklist: How to Keep Work and Personal Separate
- Keep personal activity on personal devices. A work PC is a work tool, not a personal computer.
- Do not log into personal accounts on a work PC. If a DLP agent is present, it will record your passwords as you type them.
- Use personal mobile data for personal browsing. Your SIM's data, not corporate Wi-Fi, when handling personal matters.
- Enable a personal VPN on your own device when on office Wi-Fi. This hides traffic content from the corporate router.
- Do not save personal passwords in a work browser. The work browser's password manager is accessible to IT.
- Check installed software. Open the installed programs list (Windows: Programs and Features; Mac: Applications folder) and look for unfamiliar agents — ActivTrak, Teramind Agent, Veriato, InterGuard.
- Read your company's monitoring policy. Ask HR or check the employee handbook — you have a right to know what is being logged.
- Remote access only for official IT. TeamViewer, AnyDesk — only in response to an official IT support request.
Frequently Asked Questions
Can my employer read my personal messages?
In most jurisdictions, your employer cannot legally access private messages on your personal device or personal accounts. However, if you open personal messages on a work PC with a monitoring agent installed, the agent may capture your screen. The legal right and the technical capability diverge — which is why device separation matters.
Can my employer see what I do on my personal phone?
No — if it is your own device without a company MDM profile. Even on corporate Wi-Fi, the employer can only see DNS queries (domain names) and traffic patterns, not content. With a personal VPN running, even the site names are hidden.
Will a personal VPN hide my activity on a work laptop?
Not on a managed work device with a monitoring agent installed. The agent captures screenshots and records keystrokes at the OS level before data reaches the VPN tunnel. On your personal device connected to office Wi-Fi, yes — a personal VPN encrypts traffic and hides it from the corporate router.
How can I tell if monitoring software is installed on my work PC?
Open your installed programs list (Windows: Programs and Features; Mac: Applications). Look for unfamiliar names — ActivTrak, Teramind Agent, Veriato, InterGuard. Also check running processes in Task Manager. If something is unclear, ask your IT department or review your company's IT policy.
Is it legal for employers to use keyloggers?
Generally yes, when disclosed in a written monitoring policy and employees have been notified. Covert keylogging without disclosure is typically illegal — in the EU it would violate GDPR, and in the US it may violate state privacy laws. The key factor is always: was the employee informed in writing?
What is the simplest way to keep work and personal life separate?
Keep personal activity on personal devices and use personal mobile data for personal browsing. For added protection on your own device at the office, run a personal no-logs VPN — that is a boundary that is technically very difficult for an employer to cross.
