On this page
“Can my boss see what I’m doing on my work computer?”
It’s one of the most common — and most misunderstood — questions employees ask. The honest, short answer is: yes, considerably more than most people assume, and it’s usually legal, provided the employer has been upfront about it.
This post is a plain-language guide, written for Northern Ontario employees and small-business owners who want a realistic understanding of workplace digital privacy in 2026. It’s not legal advice, but it is an accurate picture of what actually happens on a modern managed work device — and what the law in Canada says about it.
The Short Version
On a company-issued device connected to a company network, your employer can typically see:
- The domain of nearly every website you visit — even in incognito mode, even over HTTPS
- Every email and calendar event on your corporate account, including metadata (who, when, how large, from what device)
- Every file you create, open, download, upload, email, or sync via company systems
- Every application you install or run, and how long you use each
- Your login activity — location, time, device, method, success/failure
- The device’s physical location (for mobile devices and many laptops)
- A full inventory of the device — serial number, operating system version, patch status, installed software, available storage
On a personal device that’s enrolled in your company’s Mobile Device Management (MDM) or accessing company data, visibility is more limited — typically just the work apps and work data container — but enrollment itself gives the employer specific rights over that data.
What the employer usually cannot see, in a typical Canadian SMB setup, is the actual content of most individual websites you browse (just the domain), the personal apps on a BYOD phone, or anything you do on a truly personal device that’s never been used with company accounts.
Let’s unpack that.
Can my employer see if I used a Google account on my work laptop?
Yes, in a typical Canadian SMB setup they can see that it happened. They usually cannot read the emails.
Signing into Gmail, Drive, or a personal Google account on a company laptop leaves a trail:
- DNS and web filtering log accounts.google.com and mail.google.com, plus the time
- A managed browser can show which Google profile is signed in
- The message content is encrypted in transit, so IT is not sitting there reading personal mail
- On a fully managed device they could still pull a screenshot or local cache if there is an investigation
If the laptop is personal, never enrolled, and never used with a work account, they typically cannot see that Google activity.
This is not legal advice. It is what the logs actually show on a modern managed device.
What’s Actually Being Logged on a Company Computer
Modern workplace technology generates a lot of logs. On most managed business environments, the following are recorded by default:
Browser Activity
It’s worth naming the single biggest misconception first: incognito / private browsing does not hide your activity from your employer. Incognito mode only prevents the browser itself from saving your history and cookies locally. It does nothing at the network level.
When you visit a website on a company network:
- Your company’s DNS resolver (often a filtering service like Cisco Umbrella, DNSFilter, or Cloudflare Gateway) records the domain of every site your device tries to reach. This happens whether the site is HTTPS, whether you’re in incognito, whether you’re using a VPN unless that VPN is specifically trusted to bypass the corporate filter.
- Your company’s firewall logs the destination, time, and volume of traffic.
- Web filtering policies may block or categorize the site (social media, gambling, adult content, news, etc.) and record the category.
For HTTPS traffic, the specific pages and content within a website are usually encrypted and not visible — but the domain is. “I visited example.com at 2:14 PM” is recorded. “I read this specific article” usually isn’t (though in some enterprise environments with SSL inspection, even that can be visible — rare for Canadian SMBs).
Email and Messaging
- Microsoft 365 and Google Workspace keep detailed audit logs of every email sent and received on a corporate account
- Metadata — sender, recipient, subject, time, size, attachments — is retained for compliance, typically 90 days to 7 years depending on the retention policy
- Teams / Slack messages on corporate accounts are retained and can be searched by eDiscovery tools
- “Deleting” a message removes it from your view, not from the compliance archive
Files and Documents
- Every action in OneDrive, SharePoint, and Google Drive is audit-logged — created, modified, shared, downloaded, previewed, deleted
- Attaching a file to an email generates a record
- Copying a file from a company system to a USB drive or personal cloud can be detected by Data Loss Prevention (DLP) systems
Application Use
- Management tools like Microsoft Intune, NinjaOne, or similar RMM platforms inventory every installed application
- Some environments log application usage time per day
- Web apps used through the browser are logged at the DNS/firewall level
Location and Device State
- Company-issued phones almost always have location services available to the MDM platform (often only used when the device is lost or stolen, but technically visible)
- Laptops can report their approximate geographic location via IP address on every login
- Device posture — encryption status, patch level, antivirus state — is reported continuously
Logins and Identity
- Every login attempt to Microsoft 365 / Google Workspace records: time, device, IP address, approximate location, MFA method used, success or failure
- Failed logins, logins from new locations, and logins from unusual devices trigger alerts in most modern environments
What the Law in Canada Says
Three key points for Ontario and Canadian employees:
1. Employers have a broad right to monitor company systems — if they tell you. Under Canadian jurisprudence, employees have a reduced (not zero) expectation of privacy on work devices. The leading case is R. v. Cole (Supreme Court of Canada, 2012), which held that an employee using a work laptop had a reasonable expectation of privacy in personal information stored on it — but that expectation is diminished when the employer has a clear policy stating the device is monitored and is not for personal use.
Translation: if the employer has a written, communicated policy saying “we monitor this,” your privacy expectation is limited. If there’s no policy, it’s stronger.
2. Ontario’s Working for Workers Act, 2022 requires written disclosure. Ontario employers with 25 or more employees are legally required, as of October 11, 2022, to have a written policy on electronic monitoring and to share it with every employee (new hires within 30 days). The policy must describe whether, how, and in what circumstances the employer monitors, and the purposes of monitoring. If you work for a 25+ employee Ontario business, you should have received this policy in writing.
Under 25 employees, the written-policy requirement doesn’t strictly apply — but the employer may still monitor, and your expectation of privacy on work systems remains limited.
3. PIPEDA applies to how employee personal information is handled. Under PIPEDA (federally-regulated employers) and equivalent provincial laws, an employer that collects personal information about employees through monitoring must have a legitimate purpose, must limit collection to what’s necessary, and must safeguard the information. It’s not a blanket prohibition on monitoring — it’s a framework for doing it responsibly.
What “intrusion upon seclusion” doesn’t cover here. The Ontario tort of intrusion upon seclusion (Jones v. Tsige, 2012) protects against highly offensive, intentional intrusion into private affairs. Routine, disclosed workplace monitoring of company systems generally doesn’t meet that bar.
Common Misconceptions
“Incognito mode hides my browsing from IT.” No. Incognito only hides history from the local browser. DNS logs, firewall logs, and web filtering still record the domains your device reaches.
“I’m using my personal Gmail on my work laptop, so it’s private.” The URL (gmail.com) and the time spent are visible to network filtering. The content of the emails is encrypted in transit, but if the device is company-managed, IT could — in theory — access local browser data, cached credentials, or take a screenshot of what’s on the screen. Most SMBs don’t do this routinely, but the capability exists on a fully-managed device.
“I deleted it, so it’s gone.” Usually not. Corporate M365 and Google Workspace environments keep deleted email, files, and chat messages recoverable for a period by default, and for years where a retention policy or legal hold is configured. A user-initiated delete is recoverable by an admin for long after the user thinks it’s gone.
“My personal VPN hides me from IT.” On a personal device on a personal network, probably. On a company device, IT can often see that you connected to a VPN (and which one), even if they can’t see what you did inside it — and depending on policy, using a personal VPN on a company device may itself be a policy violation.
“They’d never look at my stuff.” In most day-to-day situations, correct — nobody’s reading your emails. But the capability is there, and when an incident, investigation, audit, or termination happens, that’s exactly when the logs get pulled.
What Typical Canadian SMBs Actually Do With This
To be fair to employers: most small businesses are not surveilling their staff. The logs exist for security and compliance reasons — detecting phishing, investigating incidents, responding to a PIPEDA breach, supporting cyber insurance claims, or establishing a factual basis during a workplace investigation. In normal operations, nobody is watching your screen.
The practical reality is that the capability is broad, but active use is usually narrow and event-driven:
- A security alert fires → IT pulls the relevant logs
- An employee is under a workplace investigation → HR requests specific records through a defined process
- A device is lost or stolen → MDM tracks and wipes it
- A regulatory or legal request arrives → records are produced
Knowing this is actually a good thing for most employees: the default isn’t active surveillance, it’s passive logging. But the passive logging is comprehensive, and it’s there if needed.
What This Means for You as an Employee
Three practical habits:
1. Keep personal business on personal devices and networks. If you wouldn’t be comfortable with your employer seeing it in a disclosed audit, don’t do it on a work device or a work network. Personal tax filing, job hunting, medical appointments, personal finances — do those from a personal device, off the company Wi-Fi.
2. Read your employer’s monitoring policy. If you’re in Ontario at a 25+ employee business, they’re legally required to have one. Ask HR for it. It will tell you exactly what’s monitored and why. You have a right to know.
3. Assume everything on a work device is seen. Not because it usually is, but because it can be. That single assumption keeps you clear of most workplace privacy problems.
What This Means for Small-Business Owners
Three things from the other direction:
1. Write the policy. If you’re an Ontario employer with 25+ staff, it’s legally required. If you’re under 25, it’s still best practice and makes your cybersecurity posture defensible to insurers, auditors, and lawyers.
2. Tell your staff what you actually do. A clear, specific monitoring policy — not “we may monitor everything” — builds trust. Overly vague policies breed either paranoia or contempt, neither of which serves you.
3. Actually use monitoring for its stated purpose. Using security logs to respond to security incidents is fine. Using them to micromanage an employee’s break times is a different conversation — and one that carries legal and cultural risk. Keep monitoring tied to security and compliance, not productivity surveillance, unless productivity monitoring is explicitly disclosed.
How DVG Systems Helps
We configure, document, and operate workplace monitoring in a way that’s defensible on both sides — employer compliance and employee clarity:
- Electronic monitoring policy drafting that meets Ontario Working for Workers Act requirements
- DNS filtering, firewall logging, and endpoint telemetry configured with proportionate retention and named purposes
- Microsoft 365 audit logging and eDiscovery set up to support incident investigation and PIPEDA breach response without over-collection
- MDM (Intune) deployment with clear work-vs-personal data separation for BYOD scenarios
- Staff communications — plain-language summaries of what’s monitored and why, so expectations are aligned on day one
The goal is a workplace where employees know the rules, employers have what they need when something goes wrong, and nobody is surprised by the logs in a disciplinary conversation.
The Bottom Line
Your employer can see more than you think, but usually doesn’t look unless there’s a reason to. The law in Canada permits broad monitoring of company systems provided it’s disclosed — which, in Ontario at 25+ employees, is now a written requirement.
The honest frame for both sides is this: work devices and work accounts are for work. Personal life belongs on personal devices and personal networks. That single rule clears up almost every privacy misunderstanding before it starts.
And if your employer hasn’t put a monitoring policy in writing, that’s the conversation to have — not the one where you find out what was logged, after the fact.
Related Reading
- The IT Acceptable Use Policy Every Small Business Should Have — the employer-facing companion to this post
- Password Sharing at Work: Why “One Login for the Team” Is a Six-Figure Risk — why shared logins destroy the very audit trail monitoring depends on
- When Employees Leave: The IT Offboarding Checklist — how monitoring and offboarding intersect
DVG Systems provides managed IT services, electronic monitoring policy drafting, Microsoft Intune deployment, and HR/IT alignment for small and mid-sized businesses across Northern Ontario, including Thunder Bay, Timmins, and the surrounding region. If you’d like help drafting or implementing a clear, defensible monitoring policy, book a free assessment or reach us at (807) 700-0061 or solutions@dvgsystems.com.