Work Devices, Personal Data and Employee Privacy
Somewhere in Accra this morning, an employee is logging into a personal email account on a company issued laptop. Another employee probably is saving family photographs to the office desktop, or running a side business from a work computer between tasks. None of them is thinking about the law. Most would be surprised how much of it applies to them.
A recent decision from Nairobi should give both employers and employees pause.
What the Court Decided
In Lucy Wacheke Gatere v Royal Tulip Canaan Nairobi, Kenya's Employment and Labour Relations Court considered whether an employer violated an employee's privacy by inspecting a workplace computer containing her personal email and data.
The Court held that it had not. The computer belonged to the employer. The inspection followed a workplace incident, served a legitimate business purpose, and was proportionate to it. An employee who uses an employer's computer for personal communications or private business, the Court reasoned, has only a limited expectation of privacy when the employer legitimately inspects that device. The Court also rejected the claim that she had a proprietary right to return to the computer after leaving the company to retrieve personal files.
That is not the whole judgment. The same Court found the employee had been unfairly dismissed, and had suffered harassment and violations of her rights to dignity, fair labour practices and fair administrative action. The employer won on privacy and lost on everything else.
The decision does not bind Ghanaian courts. It is nonetheless instructive, because the facts are ordinary and could arise in any Ghanaian workplace tomorrow.
Two Dangerous Misreadings
The first is the employee's. Many employees treat the company issued laptop as a private space because it sits on their desk and holds their password. It is not. The device is the employer's property, the network is the employer's network, and personal material placed there does not become invisible because it is personal. Employees who run private business, store family documents or keep personal correspondence on employer equipment accept a risk most have never consciously weighed.
The second misreading is the employer's, and the more dangerous. It is tempting to read such a case as authority for unrestricted monitoring — that because the organisation owns the machine, it may look at whatever it likes, whenever it likes. That is not what the Court said, and under Ghanaian law it would be wrong.
Ownership of a device is not authority over the data on it. The Data Protection Act, 2012 (Act 843) regulates the processing of personal data, not the ownership of hardware. The moment an employer accesses, reads, copies or analyses personal data on a work computer, every obligation in the Act attaches — regardless of who bought the laptop.
What Act 843 Requires of Employers
Section 17 sets out the principles governing all processing: accountability, lawfulness, specification of purpose, data quality, openness, security safeguards and data subject participation. Several bear directly on workplace monitoring.
A lawful basis is required. Employers commonly assume a clause in the employment contract solves this. It rarely does. Consent from an employee is fragile, because the imbalance of power makes it hard to argue it was freely given. A refusal that risks one's job is not a real choice. Employers stand on firmer ground identifying a genuine, documented business justification — protecting company property, investigating a specific incident, securing systems — and being able to explain it.
Purpose must be specified in advance, and processing limited to it. An inspection authorised to investigate a suspected data leak does not license a general trawl through private correspondence. Look at what the purpose requires, and no more.
Transparency is not optional. Sections 23 and 35 require data subjects to be made aware of the purpose of collection and the details of processing. In practice, employees must be told before any monitoring occurs what may be monitored, in what circumstances, by whom, and for how long records are kept. Monitoring a workforce learns of only when the evidence appears at a disciplinary hearing is difficult to defend.
This is where European jurisprudence diverges from the Nairobi outcome. In Bărbulescu v Romania, the European Court of Human Rights considered an employer that monitored an employee's messaging account on a work computer. The Grand Chamber found a violation of the right to private life — not because monitoring is forbidden, but because the employee had no adequate prior notice of its nature and extent. The GDPR expresses the same principle through the transparency obligations in Articles 12 to 14, and Article 88, which treats employment as a context requiring specific safeguards.
The lesson is consistent across all three systems. Monitoring is lawful when justified, proportionate and announced in advance. It becomes unlawful when covert, indiscriminate or disproportionate.
Security and retention still apply. Section 28 requires safeguards over whatever monitoring collects — logs and inspection records are themselves personal data, and are frequently left unprotected. Section 24 requires they be kept no longer than necessary.
What Organisations Should Do
Five documents, in plain language, would place most Ghanaian employers on defensible ground.
- An acceptable use policy, stating whether and to what extent personal use of work devices is permitted.
- An employee monitoring policy, setting out what may be monitored, on what basis, in what circumstances, and who authorises it.
- An access control policy, ensuring inspections are authorised, logged and limited to those with a legitimate need.
- A retention schedule covering monitoring records, investigation files and departed employees' data.
- An exit management procedure — the most neglected of the five, and the one the Nairobi case turned on.
That last point deserves emphasis. Many disputes arise not from monitoring but from separation. An organisation that gives departing staff a defined, supervised opportunity to remove genuinely personal material before access is revoked eliminates an entire category of claim, cheaply and at no risk to itself.
And For Employees
The advice is simple. Keep personal life on personal devices. Do not run private business from employer equipment. Do not assume a folder marked "Personal" carries legal weight. And before you leave a job, retrieve what is genuinely yours — because once the account is closed, the argument that you may go back for it is a difficult one to win.
Privacy at work is not the absence of oversight. It is oversight exercised lawfully, proportionately, and in the open.
Author has 71 publications here on modernghana.com
Disclaimer: "The views expressed in this article are the author’s own and do not necessarily reflect ModernGhana official position. ModernGhana will not be responsible or liable for any inaccurate or incorrect statements in the contributions or columns here."