Gathering evidence by accessing employees’ email accounts

It’s a typical scenario: A former employee starts their own business or goes to work for a competitor. There is some evidence to suggest that the employee used trade secrets they “took with them” to make their new career venture easier. Proof is usually only possible by searching the employee’s work email account. However, this is not always permissible.

The initial case

Our client’s CEO had received a tip from a close acquaintance: A senior employee who had resigned a few weeks earlier had presented this acquaintance with detailed plans for establishing a new business division and a joint venture. As luck would have it, the managing director and his acquaintance had themselves discussed a joint project in this business sector shortly before. A presentation that the former employee had given to the acquaintance contained business details that presumably originated from the client’s company.

The disappointment was great, and the matter was by no means insignificant. The CEO, an old-school type, immediately instructed his IT department to make a copy of the former employee’s entire email inbox – if you look, you’re bound to find something. Before the plan was carried out, colleagues specializing in data protection law intervened and provided legal guidance on the evidence-gathering process. Access to the inbox is not automatically permitted. In the worst-case scenario, not only would the evidence be inadmissible, but analyzing the inbox could also be a criminal offense.

Legal requirements for accessing emails

Since emails constitute personal data, access must comply with the requirements of data protection law. Case law is strict: even the mere fact that an employee sent a message at a specific time constitutes personal data. If the CEO wishes to access this data at a later date, this constitutes processing, for which a legal basis must exist. The conditions for an employer’s access to an employee’s emails are governed by Section 26 of the Federal Data Protection Act (BDSG). This provision also applies to data from former employees. The decisive factor is that the data was generated during the employment relationship.

No permission for private email use

Access to the email inbox based on Section 26 of the BDSG is not permitted if the employer acts as a provider of telecommunications services. This requirement is met if employees are permitted to use their work email address for private purposes as well. Private use need not be expressly permitted; it may also be implied through tacit acceptance.

In this case, the employer (at least according to the currently prevailing view) is bound by the requirements of Section 88 of the Telecommunications Act (TKG) and the principle of telecommunications confidentiality. The employer’s access to these emails is then restricted to protect private communications. In this case, it is also irrelevant that the employer intends to restrict its access to certain emails, as there is a latent risk of – albeit accidental – disclosure of private data and details.

It is up to the employer to avoid this scenario and to establish clear guidelines. The employer may do so either through individual employment contracts with the employees or by means of a works agreement.

Email access for the detection of criminal offenses

If, on the other hand, private use is not permitted, the legality of access is determined by the requirements of Section 26 BDSG. Section 26 (1), sentence 2, BDSG sets forth the requirements that must be met when accessing an employee’s emails on suspicion of criminal offenses. Let us examine the requirements in detail:

  • The data processing must be carried out “for the detection of criminal offenses.” This criterion is generally unproblematic because the “removal” and subsequent use of trade secrets by former employees violates one of the alternative elements of the offense set forth in Section 23 (1) no. 2 or no. 3 of the German Act on the Protection of Trade Secret (GeschGehG). But be careful: The relevant information must, of course, constitute trade secrets. Before reviewing the emails, it must therefore be clarified, in particular, whether the information was subject to appropriate confidentiality measures. If this is not the case, there is no trade secret and thus no criminal offense under the GeschGehG.
  • Furthermore, there must be “documentable factual indications” that justify the suspicion. This, of course, depends on the individual case. However, if specific detailed information emerges that was created within the company itself, this may already be sufficient. The requirements for an initial criminal suspicion are not particularly high.
  • The additional criteria are more challenging: the data processing must be “necessary for detection”, there must be “no overriding legitimate interest” on the part of the employee that would preclude it, and the action must not be disproportionate overall. These criteria call for an even greater degree of caution and careful consideration on a case-by-case basis. Scanning all the emails of an employee who may have taken the contact information of a few suppliers would likely not be justified. The situation is different if it is already highly probable that the former employee has taken at least some top-secret design plans for new facilities. In this case, it would likely be proportionate to conduct comprehensive searches to further investigate the matter. A practical limitation could be to focus the search of emails on a specific time period or on correspondence with specific contacts.

Declaration of consent for email access

In addition to Section 26 (1), sentence 2 of the Federal Data Protection Act (BDSG), there is another way to lawfully access an employee’s emails: Section 26 (2) of the BDSG provides that the employee may submit a corresponding declaration of consent. The validity of a declaration of consent is determined, in particular, by whether the employee gave it voluntarily and under what circumstances. Section 26 (2), sentences 1 and 2 of the BDSG establish an assessment standard that requires interpretation. If valid consent has been given, access may be granted – subject to the respective requirements – on the basis of both Section 26 (1), sentence 2 of the BDSG and Section 26 (2) of the BDSG. In this regard, Section 26 of the BDSG clarifies the provisions of the General Data Protection Regulation (GDPR), which has been in effect since May 25, 2018, and which does not impose any particular obstacles regarding the general requirements for the validity of consent.

Conclusion and practical tip

To investigate the suspicion that a (former) employee has copied trade secrets, the employer needs access to the employee’s email account. After all, sending emails is a relatively simple and, at first glance, inconspicuous way for the alleged violator to secure and reproduce trade secrets for their own benefit.

Access to emails must be structured in a legally compliant manner. It is absolutely essential that the employer establish a company-wide ban on the private use of email. It is also advisable to obtain the employee’s consent upon joining the company. During the active employment relationship, any (more stringent) changes in the law must also be considered in order to adjust the policies as necessary and thereby ensure access for the future as well.