​​You have the right to monitor Internet access and examine any content on a computer used by an employee if you supply the computer.​​

The case of TBG Insurance Services Corp. v. The Superior Court of Los Angeles County offers some guidance on creating policies governing use of business computers, email and Internet access.

TBG Insurance Services Corporation terminated an employee for accessing pornographic websites on his computer at work. TBG requested a court order requiring the former employee to turn over a computer provided by the company for home use. The employee agreed to return the computer, but wanted first to delete personal information he and family members placed on the hard drive, which he claimed was covered by the California Constitution’s right to privacy.

The court rejected the employee’s claim. The employee signed an agreement to be bound by the company’s computer use policy that said computers were provided for business purposes and not for personal use unless explicitly approved. Company policy also prohibited computer use for obscene purposes and included a consent to company monitoring as needed. The court said the employee could not have had any reasonable expectation of privacy.1

It is unlawful for any elected state or local officer, including any state or local appointee, employee or consultant, to knowingly use a state-owned or state-leased computer to access, view, download or otherwise obtain obscene matter, as defined in the Penal Code.2 The law does not apply to accessing, viewing, downloading or otherwise obtaining obscene matter for use consistent with legitimate law enforcement purposes; to permit a state agency to conduct an administrative disciplinary investigation; for legitimate medical, scientific, academic or legislative purposes; or for other legitimate state purposes.

Policy Sets Forth Privacy Expectation

In Holmes v. Petrovich Development Company, Gina Holmes used her employer-provided email account and employer-provided computer to consult with her attorney about a potential lawsuit against the employer.

Holmes claimed that the emails fell under confidential attorney-client communications. The court disagreed, ruling that Holmes did not have a reasonable expectation of privacy in her emails with her attorney because of the company’s strictly worded technology resources policy.

This policy plainly stated that employees had no right of privacy with respect to personal information or messages created using company technology.

The policy further stated that email was not a private communication and that the company had the right to monitor email usage. The policy warned employees that email should be regarded as a “postcard rather than as a sealed letter.”3

Why You Need a Computer Use Policy

The case LVRC Holdings, LLC v. Brekka demonstrates the need for clear computer use policies. In this case, the employer authorized an employee performing Internet marketing for the company to use the company’s computer network. The employee lived out of state, but was often in the employer’s office and he would email information from the company computer to his personal computer to work on later. The company assigned a user name and password to the employee to use when accessing the company’s website.

When the employment relationship ended, an employee discovered that someone had logged into the company’s network using the ex-employee’s user name and password. The company brought suit claiming that the ex-employee violated the federal Computer Fraud and Abuse Act (CFAA), when he emailed company documents to himself, prior to leaving the employer.

The court held that a person uses a computer “without authorization” under CFAA when someone has not received permission to use the computer for any purpose or when permission to access the computer is rescinded and the person continues to use the computer anyway.

There was no proof that after the employment relationship ended, it was the former employee who used the user name and password to access the company website. However, if the company could have proved that it was the former employee using the login information, the access would be unauthorized under the CFAA because permission to access had been rescinded.

  • Develop clear policies and guidelines about computer access and communicate them to all employees. A strongly worded and properly distributed policy on Internet security and email usage can help you assert control over electronic communications. In addition, advise and train all employees about handling electronic information, managing and reporting security breaches and using available encryption technology to transmit critical information.4 Inform your IT department of terminations so that they can prohibit future access by ex-employees.5

Electronic Media Use Policy

Electronic media includes computers, software applications, handheld devices, etc. Creating a policy about the use of electronic media prevents employee misuse. This, in turn, helps avoid claims that you committed an invasion of privacy by searching the media.

Your policy should:

  • List the electronic media that your company uses.
  • State that the media belongs to the organization.
  • State that the media communications and files are subject to inspection by the company at any time.
  • Inform employees that electronic media must only be used for company business.
  • State that employees cannot use these media in any manner that conflicts with your discrimination and harassment policies.

Internet Access Policy

Implement a policy for appropriate use of the company’s resources to access the Internet. Set guidelines for Internet access during working hours and for employees who are allowed Internet access for personal use during breaks, meal periods and other non-work time. The policy should also clarify disciplinary procedures for personal use of the Internet during work times and detail proper and improper use of Web browsers.

Include language telling employees that they should have no expectation of privacy regarding communications sent and received through the company’s email and/or intranet, nor should they expect privacy when accessing the Internet. This includes employee’s personal electronic devices that use organization servers to access the Internet or send and receive email or text messages.

Many employers also include a policy about the safe use of company cell phones and limitations on their use for personal business.

  • An employer electronic media and internet access policy is available as part of CalChamber’s Employee Handbook Creator®. Visit our online store to find out more about how to easily create your employee handbook.

Keep in mind that electronic media and Internet access policies should not be enforced in a manner that would limit an employee’s right to discuss the terms and conditions of employment, such as wages and working conditions. These discussions are generally protected under California law and section 7 of the National Labor Relations Act. For more information, see Protected Concerted Activity in Union and Non-Union Workplaces.

Privacy and Text Messaging

The U.S. Supreme Court ruled in favor of an employer in City of Ontario v. Quon. The case involved the employer’s review of text messages stored on a third party’s server. The employer’s policy about Internet use included the right to monitor all network activity, including email, with or without notice. The policy did not specifically mention text messages. However, the employer made it clear that text messages would be treated the same as email.6

An employee who consistently exceeded his monthly text message allowance. The supervisor obtained transcripts of the text messages. It was apparent that some of the messages were not work-related and contained sexually explicit material.

After an investigation, the employee was disciplined and the employer was sued. The case was eventually heard by the U.S. Supreme Court, which held that the employer’s search was reasonable and did not violate the employee’s rights.

Though the case deals with a public employer’s search, it is pertinent for private employers as well. The Court found that in the private sector, such a search would have been reasonable. The facts in this case are specific; it is unknown how a California court would rule on the “reasonable expectation of privacy” standard that applies to private sector employers.

This case emphasizes the necessity of having a well-communicated policy about email, Internet, voice mail and other communication devices and sources that record or store information.

Protecting Company Property

In Intel Corporation v. Hamidi, a company’s effort to prevent a former employee from using the company’s email addresses to distribute email messages critical of the organization’s policies to other employees was rejected by the California Supreme Court.

Over a period of approximately two years, an ex-employee sent a total of approximately 200,000 email messages to large numbers of former co-workers criticizing the organization’s personnel practices. There was no breach of any security barriers or damage to or network disruption. The sender complied with employee requests to be removed from his mailing list, but he rejected company requests that he stop his disruptive email messages. The company sued, alleging trespass to the corporate computer network.

The California Supreme Court rejected the trespass theory, saying that the organization failed to show that the email messages damaged its network or interfered with the property’s use or possession. According to the Court, the loss of employee productivity resulting from the controversial content did not injure the organization’s interest in its network.

The California Supreme Court observed that its decision is not intended to grant senders any special immunity from liability for the message content, such as defamatory statements.7

The decision underlines the importance of taking all necessary steps to secure your electronic communication systems, data and address books. Publish policies that limit employee use of organization computers and networks to matters reasonably related to organization business and forbid transmission of inappropriate messages that offend or harass others.

Advise employees that they should have no expectation of privacy with regard to messages sent using the organization’s network and that you have the right to monitor messages to ensure compliance with organization policies.


1. TBG Insurance Services Corp. v. The Superior Court of Los Angeles County, 96 Cal. App. 4th 443 (2002)

2. Penal Code secs. 311-312

3. Holmes v. Petrovich Development Company, LLC, 191 Cal. App. 4th 1047 (2011)

4. TBG Insurance Services Corp. v. The Superior Court of Los Angeles County, 96 Cal. App. 4th 443 (2002)

5. LVRC Holdings, LLC v. Brekka, 581 F.3d 1127 (9th Cir. 2009)

6. City of Ontario v. Quon, 130 S. Ct. 2619 (2010)

7. Intel Corporation v. Hamidi, 30 Cal. 4th 1342 (2003)