Skip to main content
Privacy Law 9 min read By Adv. Or Elyashiv

When Does Employee Monitoring Cross the Legal Line in Israel

Balancing a company's need to protect its assets and secure its information against an employee's right to privacy — a legal guide for employers deploying workplace monitoring tools.

קראו בעברית

When Watching Employees Becomes Standard Practice

A technology company discovers that sensitive source code has been transferred outside the organization and wants to inspect employee computers. Another company installs monitoring software on the laptops of remote employees to verify availability and productivity. Both scenarios illustrate a dilemma that grows more common as hybrid work becomes the norm: where exactly is the line between a legitimate business interest and an intrusion on employee privacy.

The right to privacy is enshrined as a constitutional right under Basic Law: Human Dignity and Liberty, and given concrete form in the Privacy Protection Law, 5741-1981 (as amended by Amendment 13, in force since August 14, 2025). This right does not disappear when an employee walks through the office door, but it is not absolute either — the National Labor Court has repeatedly recognized an employer's need to protect its assets, trade secrets, and information security.

This article surveys the legal framework governing employee monitoring in Israel, as of the date of writing, and offers practical guidelines for building a lawful and balanced monitoring policy.


Two principal statutes govern employee monitoring in Israel. The first is the Privacy Protection Law, 5741-1981, as amended by Amendment 13, which prohibits infringement of privacy absent a legal defense and imposes on any entity processing personal data — including employee data — duties of proportionality, purpose limitation, and information security. Amendment 13 also significantly expanded the enforcement powers of the Privacy Protection Authority, including the imposition of substantial administrative fines on violators.

The second statute is the Wiretapping Law, 5739-1979, which prohibits intercepting the content of communications — phone calls, messages, email — without the consent of one of the parties, and imposes criminal liability for doing so. Monitoring that goes beyond reviewing metadata (when, to whom, how much) and reaches the actual content of communications may constitute unlawful wiretapping, even when carried out by an employer on a company-owned computer.

National Labor Court Case Law

In leading rulings on employee email monitoring, the National Labor Court has established a multi-factor test for assessing the legality of such monitoring: the existence of a legitimate purpose for the monitoring, the proportionality of the means relative to that purpose, clear advance notice to the employee, and a distinction between a dedicated work mailbox and a mailbox the employee also used for personal purposes. These principles remain the foundation for evaluating any form of workplace monitoring today, not just email.


Monitoring Email and Internal Communications

Email monitoring is one of the most sensitive areas, as it directly implicates the Wiretapping Law and the principles established in case law. An employer seeking to review the content of an employee's email messages must demonstrate a clear purpose — for example, suspected leakage of a trade secret, investigation of a harassment complaint, or compliance with industry regulation — rather than a generalized wish to oversee employee performance.

Employers should expressly distinguish between a work mailbox allocated solely for business purposes and use of that mailbox for personal matters. To the extent an employer permits limited personal use, it should expect a correspondingly higher expectation of privacy on the employee's part, and exercise heightened caution before reviewing message content.


Surveillance Cameras, GPS, and Employee Location Tracking

Security cameras in the workplace are common and sometimes necessary, but they too are subject to principles of proportionality and transparency. The Privacy Protection Authority has published guidance on the use of workplace cameras, advising that cameras be avoided in areas carrying a heightened expectation of privacy — changing rooms, restrooms, break rooms — and that camera use be directed toward security and safety purposes rather than employee performance evaluation.

GPS tracking in company vehicles raises a similar issue. An employer may, generally, track a company vehicle for fleet management, safety, and operational purposes, but should avoid using the resulting data to track an employee's movements outside working hours or for purposes unrelated to routine operations. The same applies to mobile device management (MDM) applications installed on personal phones under a BYOD policy — work data must be clearly segregated from personal data, and the personal device must not be exposed to blanket monitoring.


Monitoring Computer Use, DLP Software, and Information Security

Many technology companies deploy data loss prevention (DLP) tools, network activity logging, and device monitoring as part of their preparation for cybersecurity obligations under the Privacy Protection Law and applicable cyber-security regulation. As a general matter, these tools are legitimate and often necessary to protect sensitive information and meet security obligations — but their implementation must remain proportionate.

Tools that examine network traffic anomalies, unusual file transfer attempts, or unauthorized access to data repositories infringe on privacy to a relatively limited degree given the security benefit they provide. By contrast, tools that log every keystroke (keylogging) or capture continuous screenshots throughout the workday represent a deeper intrusion into privacy, and require careful examination of the need for them against less invasive alternatives. Employers should incorporate these considerations into a risk assessment before procuring monitoring tools, and, where appropriate, conduct a privacy impact assessment before implementation.


Building a Lawful and Balanced Monitoring Policy

Employers seeking to implement monitoring tools of any kind should consider the following guiding principles:


What Happens When an Employer Crosses the Line

An employer that deploys disproportionate monitoring, or fails to provide adequate notice, faces exposure on several fronts. On the civil side, an employee may bring a claim for invasion of privacy and seek compensation. On the criminal side, monitoring that extends into the content of communications may give rise to liability under the Wiretapping Law. On the regulatory side, following Amendment 13 to the Privacy Protection Law, the Privacy Protection Authority holds expanded enforcement powers, including the imposition of administrative fines on employers that process employee personal data in a manner inconsistent with the law. Beyond this, intrusive monitoring may also surface as an issue in labor disputes, including claims of wrongful termination.

The balance between an employer's legitimate business interests — protecting intellectual property, securing information, meeting regulatory obligations — and an employee's right to privacy is not governed by a fixed formula; it depends on the circumstances. The clearer the purpose, the more proportionate the means, and the more transparent the notice given to employees, the greater the likelihood that the monitoring will be deemed lawful.

Technology companies, which typically hold sensitive information and valuable intellectual property, have particular reason to prioritize building a structured monitoring policy in advance — not as a reaction to an incident, but as an integral part of ongoing legal and operational planning.


The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.

Adv. Or Elyashiv
Written by

Adv. Or Elyashiv

Founder of Or Elyashiv Law Firm, specializing in technology law, privacy protection, intellectual property, and commercial law. Advising tech companies, startups, and international investors. Data Protection Officer (DPO), a graduate of the Tel Aviv University training program for data protection officers, held in cooperation with the Israeli Privacy Protection Authority.

View All Articles

Need Legal Guidance on Employee Monitoring Policy?

Our firm advises technology companies on developing employee monitoring policies, evaluating planned monitoring tools, and aligning them with the requirements of the Privacy Protection Law and the Wiretapping Law. We are glad to help design a balanced framework tailored to your organization's needs.