top of page

The Surveillance You Agreed To, and the Kind You Didn't

sebastian25891
Jun 9
14 min read

A few weeks after Privacy Awareness Week, the conversation most Australians never had


Privacy Awareness Week came and went between the 4th and 10th of May. If you didn't notice, you weren't alone. The campaign lived almost entirely on LinkedIn, traded between privacy officers, compliance leads, and a few law firms. Even the heavyweights of the federal cyber community leaned in: the Australian Signals Directorate posted into the feed, the Office of the Australian Information Commissioner ran a packed program, and the National Cyber Security Coordinator, Lieutenant General Michelle McGuinness, used her platform to lift the message. It was a serious effort from serious people. But the audience reading those posts was, almost entirely, the practitioner community talking to itself, as we tend to do during these weeks. The Australians whose privacy the week was nominally about scrolled past, if they saw it at all.

The OAIC's own preliminary numbers from the 2026 Australian Community Attitudes to Privacy Survey tell the story plainly: 93% of Australians say protecting their personal information is important to them, 87% are more concerned about privacy than they were five years ago, and yet most who had a concern in the past year did nothing about it, because they didn't think it would matter, or didn't know how.

That gap, between how much we care and how little we know what to do, is where this field note lives. And there is one part of it that almost nobody talks about plainly: what your employer is allowed to watch you do, what they aren't, and how thin the line is in practice.

I want to walk through it carefully, because the topic is easy to sensationalise and very easy to get wrong. Most of what employers do is legal. Some of it is intrusive but defensible. A narrower slice is unlawful. And a smaller slice still is criminal. Knowing which is which is your job before it's anyone else's.

….

The bargain we've already accepted

For almost 20 years, since Facebook went mainstream around 2007, we've all been quietly absorbing the same lesson: be careful what you post, because your boss is reading. Every couple of months a story makes the rounds about someone fired for a tweet (X), a Facebook rant, a comment under a news article. We mostly read those stories as cautionary tales. The employee should have known better. The employer's reaction was proportionate, or wasn't, and we moved on.

The flip side is the recruitment one. Hiring managers and HR teams routinely scan candidates' public profiles before an offer. They call it cultural fit. It's really a risk decision: is this person going to embarrass us. That is a perfectly legal exercise; the information is public, and you put it there.

At the same time, most of us are encouraged, sometimes pushed, to maintain a ‘professional’ presence. The marketing email lands in your inbox. ‘Please like and share’. The CEO posts on LinkedIn and a Teams message goes around the company. ‘Reshare with a comment’. Living off-grid is no longer a neutral choice; in many fields, it actively costs you the next role.

None of this is wrong. It's intrusive, yes. But it's the norm in a connected economy and there are good reasons for it. I'll come back to that phrase, ‘not wrong’, a few times, because the harder question is what ‘is’ wrong, and where the line sits between an employer doing due diligence and an employer overstepping the law.

….

What the law actually permits

In Australia, workplace surveillance is governed by a patchwork. The most developed regime is in New South Wales, the Workplace Surveillance Act 2005, and it's worth taking seriously because it sets a useful benchmark even if you work elsewhere. As Anna Johnston, Director at Helios Salinger, puts it: "Taking for example a small business operating only in NSW; they might be exempt from the federal Privacy Act, but if they use CCTV on site or monitor their employees they might be regulated by the Workplace Surveillance Act in NSW."

The headline rule is overt surveillance only, with written notice. Section 10 of the NSW Act requires employers to give at least 14 days' written notice before any form of workplace surveillance commences, unless the employee agrees to a shorter period. The notice has to state what kind of surveillance (camera, computer, tracking), how it will be carried out, when it starts, and whether it's continuous or intermittent. Covert surveillance is unlawful unless a magistrate has authorised it.

That is the bar. Most employers meet it on paper through a social media policy or an acceptable use policy, sometimes both, often bundled into onboarding paperwork you ticked through on your first day. A policy is meant to be ‘socialised’ (circulated, explained, and given time to be challenged) before it takes effect. Employees have a window to raise concerns, ask questions, or formally object if a new policy fails what most practitioners I work with quietly call the sniff test: would a reasonable person think this is fair, proportionate, and lawful. If it doesn't, you have grounds to push back, and depending on your workplace, mechanisms to do so through HR, your manager, a union if you have one, or, for the more serious matters, the Fair Work Commission or the OAIC.

Federally, the Privacy Act 1988 governs how organisations handle personal information. The 2024 reforms have begun to tighten it: a new statutory tort for serious invasions of privacy is now in play, the penalty regime has been broadened, and the OAIC has expanded enforcement powers including infringement notices of up to $66,000 for certain breaches. Johnston is direct about what this means for the corporate side: "The risk of privacy enforcement should no longer be seen as simply a 'cost of doing business’. Thanks to reforms passed in 2024, private sector entities regulated by the Australian Privacy Act now face much higher civil penalties – even greater than those seen in Europe for example - and a tooled-up regulator which has been granted greater powers to enforce the law."

The employee records exemption, the carve-out employers have long relied on to argue the Privacy Act doesn't apply to staff information, is being read more narrowly by the OAIC than it used to be. As Johnston points out, the exemption is also less protective than employers often assume: "A larger private sector organisation operating in multiple states and territories might think they can rely on the 'employee records' exemption from the federal Privacy Act, but not all the State and Territory privacy laws have a mirror exemption, and regardless, the workplace surveillance laws would still apply." That trend is one to watch.

And then there is the federal layer that almost nobody outside law enforcement, telcos and a small circle of practitioners thinks about: the Telecommunications (Interception and Access) Act 1979. The TIA Act exists to protect the privacy of people who use the Australian telecommunications system. Its starting position, in section 7(1), is a flat prohibition: you cannot intercept a communication passing over a telecommunications system. Breach that prohibition, and under section 105 you've committed a criminal offence carrying up to two years' imprisonment.

The exceptions are narrow and they are deliberately narrow. Interception warrants. Stored communications warrants. Specific carve-outs for emergency services. A small number of agencies authorised to use them, under judicial or AAT oversight. I used to write TIA warrants, so I will say this plainly: the threshold is high, the documentation is detailed, and the people who do this work for a living are trained to take it seriously. It is not a power that gets handed out lightly, and it is not a power that sits with employers.

….

The question you probably can't answer

So here is the test. When did you last read your employer's social media policy? When did you last read the acceptable use policy attached to your work device, including the BYOD one if you bring your own phone? Do you know, specifically, what your employer is permitted to see when you open a personal app on a corporate device, or a corporate app on a personal device? Do you have to acknowledge any of this every time you log on, or did you tick it once on day one and never see it again?

For most people the honest answer is: I have no idea. And that is the point at which the asymmetry becomes a problem. The employer wrote the policy, runs the tooling, and trains (or doesn't train) the people enforcing it. You signed it. Johnston frames the structural side of this plainly: "One of the downsides of the patchwork system of privacy and surveillance laws we have in Australia is that typically, employees have not been trained in both the relevant privacy laws that apply to their organisation, let alone the overlay effect of surveillance laws, many of which are State-based."

That is the first uncomfortable fact. Here is the second: the technical capability of the people doing the monitoring is not always matched by their understanding of the law. Cyber teams, IT security teams and the small specialist functions that handle workplace investigations are often very good at what they do operationally. Whether they have read the TIA Act in detail, whether they understand the distinction between an employer's infrastructure and the Australian telecommunications network for the purposes of monitoring, whether they know where the line of section 7(1) sits: that varies enormously between organisations.

….

The phone in your pocket is part of the deal

There is a quieter version of this story that almost nobody is briefed on properly. It's the moment you install Outlook, or Teams, or any of the Microsoft 365 apps on your personal phone so you can answer a message after hours or pick up a meeting from the car park. The reasonable, agreeable thing to do. A small favour to your employer, you tell yourself, in exchange for a bit more flexibility.

In most modern enterprises, those apps don't install in isolation. They sit behind a mobile device management layer (Intune, AirWatch, MaaS360, or one of their competitors), and the price of admission for those work apps is enrolment of your device into that management framework. The pitch is usually softened. It's just to protect work data. We can remote-wipe only the work container if you leave. It's for your safety.

Some of that is true. The work container concept genuinely exists, and many MDM deployments are scoped tightly and run by careful teams. But the capability the employer takes on when you enrol the device is materially broader than the scope they tell you they will use. Depending on configuration, and on whether the device is enrolled as personal (BYOD), corporate-owned, or fully managed, the employer can sit on top of your operating system at a level that reaches well past the work container. Location. Installed app inventory. Certificate stores. The ability to push or remove apps. The ability to enforce screen locks, restrict the camera, control which Wi-Fi networks you can join. The ability to trigger a remote wipe of the entire device, not just the work partition. In some deployments, the employer can push a configuration profile that routes traffic through a corporate inspection proxy, meaning every app on the device, including your banking app, your dating app, your private messaging app, is at least theoretically visible to the corporate stack.

That is capability. Whether your particular employer is using all of it is a different question. But capability granted is capability sitting there, waiting on a policy change, a personnel change, or an investigation to be quietly switched on. Once your personal device is corporately controlled, the question of who actually understands the boundaries of that control comes back. The person tuning the MDM policy in your IT team is rarely a lawyer. The vendor's documentation describes what the tool can do, not what your local privacy law permits it to do. Those are not the same thing.

This is the part most employees never get told plainly: you can refuse. Enrolling your personal phone, tablet, or laptop into your employer's mobile device management is not, in most Australian workplaces, a condition of employment. If your employer wants you contactable on work systems out of hours, the cleanly compliant answer (for them, and for you) is for them to issue you a work device. A managed phone, a managed laptop, a managed tablet, supplied by the business, for the business. That is what we want you available on Teams after hours actually costs, and an employer who is serious about the requirement should be willing to wear it.

I will be honest about the trade-off, because the user-experience cost is real. Carrying two phones is annoying. Switching between calendars is annoying. Forgetting which device has the work app installed is annoying. Some people will look at all of that and decide the convenience of a single device is worth the access they're handing over. That is a legitimate choice. It should just be a deliberate one, made with the actual scope of access in front of you, not the marketing version of it. What is the cost to your personal information (your photos, your saved passwords, your banking apps, your LinkedIn, Instagram, or Facebook private messages to people who never consented to any of this) of keeping it on the same device as the corporate stack? Only you can answer that, and you can only answer it honestly if you know what you are being asked.

Ask your IT team, in writing, exactly what their MDM configuration can see on a BYOD device. Ask what would happen to your personal data if a wipe were triggered, accidentally or otherwise. Ask what telemetry is collected continuously, how long it is retained, and who has access to it. If the answer is vague, that is information. If the policy is silent on personal data, that is information. And if the answer is we'd rather not put that in writing, that is the loudest information of all.

….

Infrastructure versus network

This is the distinction that almost every confused conversation about workplace monitoring comes back to. Inside the employer's own systems (the corporate email server, the laptop image, the MDM-managed mobile, the SaaS account licensed to the business), there is a wide field of legitimate monitoring. Logs, web filtering, DLP, email archiving, endpoint telemetry. Provided you've had proper notice and a policy explains it, an employer can capture an enormous amount about what happens on its kit.

The moment a communication leaves that envelope and crosses onto the public telecommunications network, the carrier-grade infrastructure that the TIA Act protects, the rules change. Intercepting a communication in transit across that network, in real time, without a warrant, sits on the wrong side of section 7(1). And it doesn't matter that the device the communication started on belongs to the employer. The protection runs with the communication, not the hardware.

Where this gets genuinely dangerous is in the techniques that blur the boundary. Keyloggers that capture everything typed on a device, including messages typed into a personal WhatsApp web session, a personal Gmail account, a private banking portal. TLS-interception proxies that decrypt encrypted traffic so it can be inspected, even when the traffic is to a personal service. Screen-capture or screen-recording tools that reproduce the contents of a personal conversation visible on the screen. None of these tools are illegal in themselves. Plenty are sold as standard enterprise security products. Their use, however, can reach well beyond the lawful scope of an employer's monitoring regime, particularly where communications captured belong to people outside the organisation: your partner, your friends, your children, your doctor, your lawyer. None of whom ever consented to being monitored, and none of whom are bound by your employer's policy.

If that sounds alarming, it should. The scariest version of this scenario is not deliberate corporate espionage. It is well-intentioned operational monitoring that nobody bothered to scope properly, run past legal, or constrain at the tooling layer. A keylogger doesn't know that what it just captured was a message to your child.

….

Who is lawfully allowed to intercept

The short answer is: a small, defined set of national security and law enforcement agencies, acting under a warrant or statutory authorisation. Interception warrants are typically issued for the investigation of serious offences carrying a maximum penalty of at least seven-year imprisonment. Stored communications warrants cover a wider range of offences but still sit behind a judicial gate. There is process. There is oversight. There is reporting to the Minister and to Parliament.

An employer is not on that list. An employer's IT or security team is not on that list. An external investigator engaged by your employer is not on that list. There are lawful ways for an employer to access certain information on its own systems, and there are lawful ways to cooperate with a law enforcement request. There is no lawful way for an employer to intercept your communications across the Australian telecommunications network on its own initiative.

….

What happens if you think it's happened to you

This is where the field note turns hard, because the gap between what the law says and what it can do for you is uncomfortably wide.

Suppose you have reason to believe you have been unlawfully surveilled by your employer. The legal pathway exists. A breach of section 7(1) of the TIA Act is a criminal offence. There is also a civil remedies path under the Act for unlawful interception. The new statutory tort for serious invasions of privacy may, in time, give plaintiffs a more accessible route. You can complain to the OAIC. You can engage employment lawyers. You can (and probably will, if it has gotten this far) be looking at a Fair Work claim in parallel because employment relationships rarely survive this kind of dispute intact.

Now the reality. Police agencies tasked with prosecuting telecommunications interception offences are not resourced to pursue individual workplace cases. Their priorities are organised crime, national security, and serious cybercrime. A complaint of unlawful interception by an employer is unlikely to be picked up. Civil litigation is expensive, slow, and asymmetric; your former employer has insurance and a legal panel, and you do not. By the time any of this is resolved you will already have lost the job, spent significant money on lawyers, and carried the personal cost of a long dispute.

Here is the part that gets less attention than it should. The structural design of Australia's workplace surveillance regime leaves a gap between what the law prohibits and what an employee can practically do about it. Johnston points to the specific structural cause: "neither the federal nor the NSW privacy commissioner enforces the Workplace Surveillance Act, so guidance on that law is hard to find." Where a regulatory regime contains a gap of that kind, the deterrent value of the law is, in practical terms, weaker than its text would suggest, regardless of any particular employer's intent. That is the structural problem at the heart of this piece. It is the same problem the OAIC's own survey is gesturing at: people don't complain because they don't believe it will change anything. They are not wrong to feel that way, and that is precisely why the asymmetry persists.

….

What to actually do

I am not going to end on a flourish. The practical asks are unglamorous.

Read your employer's social media policy and acceptable use policy in full, including the BYOD one if you have a personal device enrolled in a corporate MDM. If you can't find them, ask. If the policy is silent on what is captured from personal apps, or vague about the line between work and personal use, ask for that to be clarified in writing.

Before you let your personal phone, tablet or laptop be enrolled into corporate management, get the scope of that management in writing. If your employer needs you contactable on work systems, push for a work-issued device. Two devices is friction; the alternative is signing over a level of access to your personal life you almost certainly haven't been shown in plain English.

Treat the corporate device as a corporate device. Do not assume any communication initiated on it is private, even within an app you consider personal.

If you have a genuine concern that monitoring has crossed a legal line, document what you observed and when, get advice from an employment or privacy lawyer before you raise it internally, and consider parallel notification to the OAIC if personal information has been mishandled.

And if you sit on the other side of the desk, if you run a security function, a HR function, a compliance function, or a board with oversight of these tools, the question to put to your own organisation is not whether your monitoring is technically possible or defensible in policy. It is whether your monitoring is lawful, proportionate, understood by the people doing it, and bounded at the tool layer so that capability cannot be quietly stretched into territory the policy never authorised. That is the work that Privacy Awareness Week is asking organisations to actually do, and it doesn't end when the week does.

Privacy is not a campaign. It is the day after the campaign, and the one after that, and the quiet decisions people make about their staff when nobody is watching.

….

Field notes are published as practitioner observations. They are not legal advice. If you believe you have been the subject of unlawful surveillance, get advice from a qualified employment or privacy lawyer.

 
 
 

Recent Posts

See All
Your Memories Are Not Yours

On the fragility of what we store, the silence of those who could act, and the questions we have stopped asking. There was a time when your photos lived in a shoebox. Faded edges. Handwriting on the b

 
 
 
You Are Not a Persona

The thing your bank, your insurer, your government, and your favourite app are doing with your data that they would rather you didn't think about. And what to do about it. Let me tell you what is prob

 
 
 

Comments


bottom of page