legal247

When can an employer access an employee's email in Norway?

In brief

Under Norwegian law, employers may only access an employee's email when access is necessary for day-to-day operations or other legitimate interests, or where there is a well-founded suspicion of serious misconduct. As a rule the employee must be notified in advance and be able to attend. Automatic forwarding counts as unlawful monitoring and has led to administrative fines.

An employee goes on sick leave, and an important customer is waiting for a reply. Another employee leaves abruptly, and management suspects that customer lists have been sent out. In both cases it is tempting to open the mailbox. That may be lawful, but only when the conditions in a dedicated set of regulations are met and the procedure is followed. Getting any one of these points wrong has led to administrative fines in several cases.

Which rules govern employee email access?

Employee email access in Norway is governed by the Regulations on employers’ access to email accounts and other electronically stored material, often referred to as the Email Regulations (e-postforskriften). They are issued under Working Environment Act § 9-5 of the Working Environment Act (arbeidsmiljøloven), and the Norwegian Data Protection Authority (Datatilsynet) supervises them under Email Regulations § 6. The GDPR also applies, so the employer must have a legal basis for processing as well, normally legitimate interests under GDPR Art. 6(1)(f).

Under Email Regulations § 1 the Regulations apply to access to an email account the employer has made available to the employee, and to the employee’s personal areas on the business’s network or other electronic equipment. They also cover deleted material on backups, and they apply to both current and former employees.

The Regulations are mandatory. Under Email Regulations § 5 they cannot be departed from to the employee’s detriment, whether by instruction or by agreement. A clause in the employment contract stating that the employer always has access therefore has no effect.

When may the employer access an employee’s email?

Under Email Regulations § 2(1) the employer may access email in only two situations.

The first is where access is necessary to safeguard the business’s day-to-day operations or other legitimate interests. Typical examples are an employee who is ill or has left, where the business needs a specific customer exchange, contract or quotation in order to deliver. The test is necessity. It is not enough that access is convenient. If the information can be obtained in another way, for example by asking the employee, the customer or colleagues, access will usually not be necessary.

The second is where there is a well-founded suspicion that the employee’s use of email or electronic equipment involves a serious breach of the duties arising from the employment, or may give grounds for dismissal with or without notice. The suspicion must rest on concrete evidence, not on general unease or a wish to “see what is there”.

Even where one of the conditions is met, access must be proportionate. The search must be limited to what the purpose requires, for example specific senders, periods or search terms.

Is automatic forwarding of email lawful?

No. Under Email Regulations § 2(2) the employer has no right to monitor the employee’s use of electronic equipment. The exceptions cover only administration of the computer network and the detection or investigation of security breaches. Datatilsynet regards automatic forwarding of an employee’s email as continuous monitoring, and it is therefore not permitted.

Automatic forwarding is not a shortcut to access. It is monitoring, and it has led to administrative fines.

The alternative is an automatic out-of-office reply referring the sender to another address. That meets the operational need without anyone reading the employee’s email.

How must access be carried out?

Email Regulations § 3 sets requirements for the procedure. These requirements are as important as the conditions, and breaching them alone can lead to sanctions.

Requirement Content
Prior notice As far as possible the employee must be notified and allowed to comment before access. The notice must explain why the conditions are met and inform the employee of their rights
Right to object The employee may object under GDPR Art. 21, and the objection must be considered
Right to be present As far as possible the employee must be able to attend, assisted by a union representative or another representative
Subsequent notification If access takes place without notice or without the employee present, written notification must be given as soon as access is complete, stating the method, which emails were opened and the outcome
Verifiability Access must be carried out so that the information is not altered and the outcome can be verified
Closing Emails that turn out to be irrelevant or private must be closed immediately, and any copies deleted

An exception from notice requires a specific justification, for example that notice would cause evidence to be deleted. The exceptions from the duty to inform in Personal Data Act § 16 of the Personal Data Act (personopplysningsloven) apply correspondingly to the subsequent notification.

In practice the employer should keep a record of the decision, the reasons, who took part, which searches were run and what was opened. That record is the business’s most important evidence if the employee complains to Datatilsynet or the matter ends up in court.

What happens to the email when the employee leaves?

Under Email Regulations § 4 the mailbox must be closed when employment ends, unless there is a particular need to keep it open for a short period. Information that is not needed for day-to-day operations must be deleted within a reasonable time.

The business should therefore make sure that work-related material is moved to shared systems while the employee is still in post. That reduces the need for access after the person has left, and it is the simplest way of avoiding conflict.

What has the Privacy Appeals Board reacted to?

Decisions of the Norwegian Privacy Appeals Board (Personvernnemnda) show that both automatic forwarding and failures of procedure lead to sanctions.

Decision What the employer did Sanction
PVN-2021-03 Set up forwarding of a sick-listed employee’s email for five weeks without notice, and continued after an objection Fine of NOK 250,000, reduced from NOK 400,000 because of lengthy case handling
PVN-2022-14 Set up forwarding of a departed employee’s email to the chief executive without informing them Fine of NOK 100,000, around 2.2 per cent of turnover
PVN-2024-01 Had grounds for access on suspicion of embezzlement, but gave no notice, gave inadequate subsequent notification, shared information with an external party without a legal basis and searched too widely Reprimand and order to put procedures in place

The last case is particularly instructive. The employer had a legitimate basis for access, but was still sanctioned because the procedure failed. A valid basis does not rescue a deficient process.

Administrative fines are imposed under GDPR Art. 83, and the upper limit for breaches of the basic principles and legal basis is EUR 20 million or 4 per cent of global annual turnover. For most businesses, however, the real risk lies just as much in the employment dispute. Information obtained in breach of the rules is a weak foundation for a dismissal, and the employee may claim damages.

What about other digital traces, such as AI assistants?

The Regulations also apply to the employee’s personal areas on the business’s equipment. There is much to suggest that chat history in AI assistants linked to the employee’s account should be treated in the same way, although the question has not been settled in practice. See the article on AI policies for employees for how monitoring of AI use should be handled.

The employee may also request access to the information the employer has extracted. That is a common response after email access, and the deadlines and exceptions are covered in the article on subject access requests under the GDPR.

What should the business do?

  1. Prepare a written access procedure describing the conditions, who decides, notice, execution, record-keeping and notification.
  2. Prohibit automatic forwarding in IT procedures, and use out-of-office replies instead.
  3. Ensure shared storage of customer correspondence and contracts, so that operational needs rarely require access to personal mailboxes.
  4. Limit each access to specific senders, periods or search terms, and close private emails immediately.
  5. Clarify any external assistance before access begins. Sharing with auditors, investigators or the IT provider requires its own legal basis and agreement.
  6. Close the account when the employee leaves and delete what is not needed for operations within a reasonable time.
  7. Involve HR and the data protection officer before access on suspicion of misconduct, because the matter often ends up as an employment dispute.

More articles on the subject are available on the topic page on data protection.

Questions and answers

Can we set up an automatic reply when an employee leaves or is on sick leave?

Yes. An automatic out-of-office reply that refers the sender to another address is not access, and is the recommended alternative to forwarding. Once employment has ended the account must be closed, unless there is a particular need to keep it open for a short period.

Can we agree with employees that the employer always has access to their email?

No. The Regulations cannot be departed from to the employee's detriment, whether by instruction or by agreement. A clause in the employment contract granting unrestricted access therefore has no effect, and the conditions and procedure must be followed every time.

Do the rules also apply to former employees?

Yes. The Regulations apply to both current and former employees, and they also cover access to deleted email held on backups. The former employee must therefore be notified and given an opportunity to comment in the same way.

Next legal review: 1 April 2027