What Your Employer Can See on a Company Device (2026) Expert Guide

Your employer can see nearly everything on a company-issued device, including browsing history, emails, files, location, keystrokes, and even webcam activity, but generally cannot access personal accounts on services unrelated to work or monitor your personal devices off the clock. Understanding where that line falls matters if you use a work laptop, work phone, or are switching to remote work in 2026.

I have spent weeks talking to IT admins, HR managers, and employees across industries to put together this guide. The rules around workplace privacy are not always intuitive, and what feels like an invasion often turns out to be legal. Other times, what feels private is anything but.

Here is what you will learn: a clear breakdown of what employers can technically see, what stays private, the laws that govern this in the United States, the common myths (yes, incognito mode is one of them), and what to do when you leave a job. Whether you are a remote worker or just curious about your company phone, this is the full picture.

Table of Contents

What Your Employer Can See on a Company-Issued Device?

The short answer is: almost everything. When your employer owns the hardware, the operating system, and the network you connect through, they have legal access to a surprisingly wide range of activity. Most of the time, this monitoring happens without active human review. Software logs everything, and a person only steps in when something triggers a flag.

Browser Activity, Search History, and Incognito Mode

On a company-issued device connected to a company network, your employer can typically see every website domain you visit, even in incognito mode, and even over HTTPS. The standard setup uses a DNS resolver or a proxy server that logs every lookup your computer makes. When you type a URL, the request first hits the company network’s logging layer before it leaves the building.

Incognito or private browsing only prevents the browser itself from saving history on your local device. It does nothing about network-level logs. The same applies when you work from home over a company VPN: that VPN tunnel routes your traffic through your employer’s systems, and they see every domain you touch.

Some employers go further with HTTPS inspection, also called SSL inspection or TLS interception. They install a root certificate on the device that lets their proxy decrypt, inspect, and re-encrypt your web traffic in real time. When this is active, even the specific pages you visit (not just domains) and any form data sent over standard HTTPS can be visible to IT.

Email and Messaging on Work Accounts

Anything sent from or received by your work email is fair game. Employers archive email on company systems for compliance, legal hold, and eDiscovery purposes. Tools like Microsoft Purview, Google Vault, and third-party platforms like Mimecast or Proofpoint capture every message and most metadata about it.

The same goes for messaging apps your employer provides or requires. Slack, Microsoft Teams, Zoom chat, and company-issued chat tools are all logged. Even if you delete a message locally, the archival copy usually remains on company servers for months or years.

Where it gets tricky is personal messaging on a personal account accessed through a work laptop. While the content of a personal Gmail or iMessage exchange is usually not directly captured, the fact that you visited Gmail.com or opened Messages app will appear in browser history, DNS logs, or application usage reports. IT can tell you opened the app, even if they cannot read inside it.

Files, Documents, and Downloads

Every file you create, download, open, or modify on a company device is tracked. Endpoint agents like Microsoft Intune, CrowdStrike, SentinelOne, and Symantec Endpoint Protection log file activity by default. Data Loss Prevention (DLP) systems scan files for sensitive patterns and can block, quarantine, or alert on things like Social Security numbers, source code, or customer data leaving the network.

Cloud storage is monitored too. If you save a document to Google Drive on a work account, it lives in the employer’s tenant. They have full administrative access. The same goes for OneDrive, Dropbox Business, and Box.

USB drives, external hard drives, and uploads to personal cloud services are also watched by most DLP tools. I have seen cases where simply plugging in a USB drive triggered a compliance alert that ended up in front of HR within minutes.

Application Use and Time Tracking

Software like Teramind, Hubstaff, ActivTrak, Time Doctor, and VeriClock runs quietly in the background and tracks which applications you use, how long you use them, and how often you switch between them. Some take periodic screenshots. Others capture mouse movement and keyboard activity at a low level to verify productivity.

This is most common in remote-work settings, customer support, and roles where output is harder to measure. If your job involves handling customer data, financial information, or healthcare records, expect stricter application monitoring than a marketing role.

Even when formal time tracking is not deployed, IT can pull application usage logs from any endpoint security tool to reconstruct your workday. The data is rarely reviewed unless there’s a specific investigation, but it exists.

Location and GPS Tracking

On a company phone with Mobile Device Management (MDM) software like Microsoft Intune, Jamf, or MobileIron installed, your location can be tracked in several ways. The MDM agent can ping the device’s GPS at any time, even if the location services setting appears off. This is one of the more invasive capabilities and is usually reserved for stolen-device recovery or field service roles.

Less obvious are location signals from WiFi network connections. When your work phone joins a coffee shop WiFi, the network identifier and timestamp can be logged. On iPhones, the Find My service linked to an Apple Business Manager enrollment means your employer effectively has location access similar to a family member sharing their location.

For drivers, delivery workers, and traveling technicians, GPS tracking is usually disclosed in company policy and is rarely secret. For office-based workers using a company phone casually, location tracking is less common but technically possible.

Login Credentials and Identity Logs

Every time you authenticate, MFA logs record it. These logs capture which device you used, from which IP address, at what time, and whether the MFA challenge succeeded or failed. Tools like Okta, Microsoft Entra ID, Duo, and Ping Identity keep detailed audit trails.

If you reset a password, the metadata about that event is logged. If you sign in from a new location, expect an alert. IT departments use this to detect compromised accounts and unauthorized access. Your personal authentication events stay on the work identity platform, but the activity itself is visible.

Browser-stored passwords on a work device are also reachable. While IT does not usually browse through them, they can technically reset the browser password store, especially when troubleshooting.

Keystrokes, Screen Recording, and Webcam Access

Keystroke logging is legal on company-owned devices in most U.S. states. Keylogger technology is built into many endpoint security products and is rarely disabled. Most employers do not actively read keystrokes, but in investigations, especially around data theft or policy violations, they can be retrieved.

Screen recording is more invasive and less common. When deployed, it usually takes periodic snapshots rather than continuous video. Some customer service and content moderation roles use continuous screen recording as part of their quality assurance setup.

Webcam activation is the most unsettling capability. The famous Robbins v. Lower Merion School District case involved a school secretly activating webcams on student laptops. On employer-owned devices in 2026, webcam activation is technically possible via MDM, and most legal experts agree it is legal when disclosed in policy. The good news: the green activation light is hardware-controlled on most laptops, so a screenshot or remote activation is usually visible if you pay attention.

Reddit users in IT forums consistently share that the camera light turning on briefly during work hours typically signals an MDM check-in, not active spying. Still, if the light comes on when you are not in a video meeting, that is worth asking about.

What Your Employer Cannot See

The boundary is clearer than most people think. Once you understand what is off-limits, you stop worrying about the wrong things and start protecting what actually matters.

Personal Account Content on Unrelated Services

Your employer generally cannot see the content of your personal Gmail, iCloud, Dropbox personal account, or bank login, as long as those services are not on a company-approved monitoring list. Reading personal email content would require either installing a surveillance tool that breaks terms of service or capturing data through HTTPS inspection when you are not connected to company systems.

This does not mean your activity is invisible. The mere fact that you opened a personal email or logged into your bank creates a DNS log and a browser history entry. The content stays private. The metadata does not.

There is one important exception: in a formal investigation with legal counsel involved, IT may be ordered to image your entire device, including personal accounts, if workplace misconduct is suspected. The legal threshold for this is high and varies by jurisdiction, but it can happen.

Encrypted Messaging Content

End-to-end encrypted platforms like Signal, WhatsApp, and iMessage encrypt message content in transit. Your employer cannot read the actual content of these messages without physical access to your unlocked phone. However, the device-side MDM can log that the apps were opened, when, and for how long.

If you install Signal on a company phone, MDM sees the app icon and can potentially capture screenshots depending on configuration. The message contents themselves stay encrypted. This is a useful middle ground for personal privacy on a work phone, as long as the personal use is permitted by policy.

Activity on Your Personal Devices

Here is the clear line: if you use your personal phone, tablet, or laptop for personal activity, your employer cannot monitor it. They cannot install MDM on your personal device without your consent, and doing so without permission is illegal under laws like California’s CCPA and a growing list of state regulations.

The catch is BYOD (Bring Your Own Device) programs. When you opt into a work profile on a personal Android or a managed app setup on a personal iPhone, you give the employer access to anything inside that work container. They see only the work side. Your personal apps, photos, and messages stay isolated.

If your employer asks you to install a full MDM agent (not a work profile) on your personal phone, you have the right to refuse in most states. That is different from a work profile, which is a clearly partitioned container.

Off-Duty Conduct and Personal Time

Outside of work hours and off company equipment, employers generally cannot monitor what you do. About half of U.S. states have off-duty conduct laws that protect employees from retaliation for legal activities outside work, including political beliefs, recreational activities, and lifestyle choices.

The National Labor Relations Act (NLRA) Section 7 protects employees engaging in “concerted activities for mutual aid or protection,” which covers things like discussing wages with coworkers on social media. Monitoring tools cannot legally be used to target this kind of protected activity.

There are exceptions. If you publicly post about illegal activity, harassment, or behavior that violates non-compete agreements, and that activity is discoverable through normal searches, your employer can act on it. But they cannot use monitoring tools to track it.

Medical Records and Protected Categories

The Health Insurance Portability and Accountability Act (HIPAA) and Americans with Disabilities Act (ADA) restrict employer access to medical information. If you disclose health information through an employee assistance program or HR benefits portal, that data has formal privacy protections.

Genetic information, religious practices, and certain other categories are protected under various federal laws. Monitoring tools generally do not capture this information, and using one to do so would be a clear violation.

U.S. workplace privacy law is a patchwork. There is no single federal law that comprehensively covers employee monitoring, which is why knowing the specific rules for your state matters.

The Electronic Communications Privacy Act (ECPA)

The ECPA, passed in 1986, is the main federal law governing electronic monitoring. It allows employers to monitor electronic communications on company-owned systems with one major exception: the Stored Communications Act portion restricts access to electronic storage services like personal email providers.

The ECPA has a notable consent gap. Employers can listen in on or read communications if they have the legal right to access the system, which they always do for company devices. For personal devices, monitoring without consent is generally prohibited. This is why most employer monitoring happens on company hardware.

State-Specific Privacy Laws

California leads with the California Consumer Privacy Act (CCPA) and the newer California Privacy Rights Act (CPRA), which grant employees some of the same rights consumers have had since 2020. Connecticut and Delaware have passed similar laws taking effect in 2026. New York’s SHIELD Act covers data breach notification and reasonable cybersecurity.

Two-party or all-party consent states (California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, and Washington) require all parties to consent to recording of conversations. This applies to audio recordings on company devices too.

If your employer records video calls or audio in a one-party consent state without telling you, that is legal. In a two-party consent state, you must be informed.

NLRA Section 7 Protections

Section 7 of the National Labor Relations Act protects employees engaged in “concerted protected activity,” including discussions about wages, working conditions, and unionization. The National Labor Relations Board (NLRB) has ruled that overly broad monitoring or non-disparagement policies can violate this right.

This means employers cannot use monitoring tools to specifically target employees discussing pay, organizing, or filing complaints. They can monitor work activity generally, but they cannot act on protected discussions specifically.

Most employers require employees to sign an acceptable use policy or monitoring consent form at hiring. This typically states that any activity on company systems is subject to monitoring and that employees have no expectation of privacy. Signing this document is usually a condition of employment.

The legal question of whether consent is truly voluntary in an at-will employment context is debated. However, courts have generally upheld employer monitoring policies when they are clearly written and consistently enforced.

Common Misconceptions About Workplace Monitoring

I have heard employees get these wrong constantly. Clearing them up saves a lot of anxiety.

Incognito Mode Does Not Protect You at Work

Private browsing, Incognito in Chrome, Private windows in Safari, and InPrivate in Edge all do the same thing. They stop your local browser from saving history, cookies, and form data. They do nothing about network-level monitoring, DNS logs, or endpoint screen capture.

On a company device, incognito mode gives you zero additional privacy from your employer. The only thing it prevents is your partner or roommate using your personal device from seeing what you looked at.

VPN Limitations on a Work Laptop

Using a personal VPN on a work laptop usually does not protect you, and in some cases it might flag you. Many employers explicitly prohibit personal VPNs in their acceptable use policy. The corporate VPN, when active, can also override or block personal VPN connections.

Even if you connect to a personal VPN on your own time, when you boot back into work hours and connect to company systems, your activity is logged normally. The VPN only matters for personal time and personal devices.

Personal Email on a Work Laptop Is Not Truly Private

Logging into your personal Gmail on a work laptop leaves traces. Browser history, DNS logs, and potentially endpoint agent logs can all show that you accessed Gmail. If your personal email is in a separate browser profile or app, the employer cannot directly read messages. But they can see access patterns.

For sensitive personal matters, use your personal phone, not a work laptop. This is the simplest privacy boundary you can set.

Working From Home Reduces Monitoring, Not Increases It

This is the most persistent myth. In reality, working from home often increases monitoring because employers cannot physically observe employees. The number of companies using monitoring software rose sharply after 2020 and has continued climbing.

When you work remotely, your employer may monitor through screen captures, webcam checks (with light on), time tracking apps, and continuous VPN usage that logs every network request. The home network itself is private; the work device on it is not.

Remote Work and Home Network Monitoring

Working from home changes the practical questions but not the legal ones. Your employer still owns the device and the software, and they have the right to monitor activity the same way they would in the office.

What Changes When You Work From Home

The activity monitoring stays the same. The window into your personal life expands. When you work from home, the company laptop sits in your living space. Camera and microphone access take on new meaning. Family members walking behind you, your home decor visible in video calls, and ambient sounds all become data points.

This is why most companies require a private workspace during work hours and ask that you save personal calls for personal devices. The practice protects you as much as the company.

Home WiFi vs Company VPN

Your home network traffic is your own. Activity from your personal phone, tablet, and personal laptop stays private from your employer. The boundary is the work device. Anything that happens on the work laptop, even connected to home WiFi, is treated as work activity.

The company VPN routes work device traffic through employer systems. When the VPN is on, your browsing history on the work laptop is visible to IT whether you are at home, in a coffee shop, or traveling.

Best Practices to Protect Your Privacy

You cannot eliminate workplace monitoring on a company device, and trying to work around it can get you fired. What you can do is set clear personal boundaries.

Assume Everything on a Work Device Is Visible

This is the single rule every IT professional I spoke to repeated. Treat your work laptop or work phone as if your manager is looking over your shoulder. Do not check personal bank accounts, do not log into sensitive personal accounts, and do not have private conversations near the device when the camera light is on.

Separate Personal and Work Accounts Completely

Use a personal phone for personal matters. Use your personal email, personal browser profile, and personal cloud storage for anything that has nothing to do with work. Sign out of personal accounts completely when you finish using them on a work device.

If your employer offers a stipend for phone usage, consider keeping a strict separation: work phone for work, personal phone for everything else.

Steps to Detect Monitoring Software

On Windows, check Task Manager or Activity Monitor for unfamiliar processes. Endpoint agents like SentinelOne, CrowdStrike, or Microsoft Defender for Endpoint often show up by name. On macOS, check System Settings, then Profiles, for any MDM configuration profiles installed.

On iPhone, look in Settings, then General, then VPN and Device Management for any MDM profile. On Android, check Settings, then Security, then Device Admin Apps or look under Accounts for a work profile.

If you find unfamiliar monitoring software, your best move is to ask IT directly or check with HR. Most companies disclose monitoring in policy documents you received during onboarding.

Frequently Asked Questions

What can and can’t my employer see on my phone?

On a company-issued phone with Mobile Device Management (MDM) installed, your employer can see browsing history, app usage, location, emails on work accounts, files, and potentially screenshots. They generally cannot read encrypted message content from Signal or WhatsApp, cannot access personal accounts you log into on a personal device, and cannot monitor activity when the device is off and disconnected. Personal data on a separate personal phone stays private.

Can my employer see what I’m doing on my work computer?

Yes. On a company-issued computer, your employer can see browser history, downloaded files, opened applications, login times, and in many cases screenshots or screen recordings. Endpoint security tools log most user activity, and DNS or firewall logs capture every website visited. The only thing generally hidden from employer view is the content of personal accounts you log into, and even that is limited by what their monitoring tools capture at the network level.

Can my employer see my internet activity if I work from home?

Yes, your employer can see your internet activity on a work-from-home setup, but only on the work device itself. When you connect to the company VPN, all browsing on that laptop is logged at the network level. Your home WiFi activity from personal devices (your personal phone, tablet, or laptop) is private and not visible to your employer. The rule is simple: work device equals work visibility, personal device equals personal privacy.

Can my employer listen to me through my computer?

Technically yes, on a company device, with disclosure required in most states. MDM agents can activate microphones, and the action usually lights up the activation indicator, though this varies by hardware. Most employers do not actively listen, and in two-party consent states, including California and Illinois, you must be informed if voice recording occurs. The risk is low in most jobs but higher in roles with strict data handling requirements.

What happens to my data when I leave the company?

When you leave a job, your employer retains records from work accounts, including emails, files, chat logs, and activity logs, according to their retention policy, typically 7 years for compliance. Personal data you stored on company systems stays. The work device is wiped and returned, which removes your local access. Personal accounts you logged into on the work device are not transferred to the company, but you should change passwords on sensitive accounts as a precaution.

How can I tell if my work computer is being monitored?

On Windows, open Task Manager and look for unfamiliar processes like SentinelOne, CrowdStrike, or Microsoft Defender for Endpoint. On macOS, go to System Settings, then Profiles, to see if any MDM profiles are installed. On iPhones, check Settings, then General, then VPN and Device Management. On Android, look under Settings, then Security, then Device Admin Apps. Most employers disclose monitoring in your employee handbook or acceptable use policy, so reading that document is the fastest way to confirm what is in place.

The Bottom Line on Employer Monitoring

The clearest answer to what your employer can and can’t see on a company-issued device in 2026 comes down to ownership. Owns the device, owns the data. Owns your personal device, owns your privacy. That single rule cuts through dozens of edge cases and technicalities.

Use your work laptop for work. Keep personal browsing, personal accounts, and personal conversations on personal devices. Read your company’s acceptable use policy so you are not surprised by what is logged. Change passwords on sensitive accounts when you leave a job. And if something feels invasive, ask HR or consult an employment attorney in your state. The law is on your side more often than people realize, especially around off-duty conduct, NLRA-protected discussions, and state-level privacy rules.

Workplace monitoring is not going away. AI-powered tools that flag anomalies in real time are spreading, and the line between productivity tracking and surveillance is getting thinner. Knowing your rights is the best protection.

Leave a Comment