Skip to content
VPNmine
PRIVACY AND LAW

What your employer can see on a work laptop

On a managed laptop, monitoring runs on the device itself, above any tunnel. Management software can see applications, files, browser activity and often screen contents, and a personal VPN encrypts traffic after all of that has already been observed locally.

4 min read

Illustration of a laptop, a briefcase and an eye, joined by a dashed tunnel line on a dark grid.

The instinct is reasonable: install a personal VPN on the work laptop and the company can no longer see what you are doing. The instinct is also wrong, and understanding why is more useful than any configuration.

Where monitoring actually happens

A VPN encrypts traffic as it leaves the device. Management software runs on the device, above that point. It observes activity before anything is encrypted and after anything is decrypted.

That inverts the usual mental model. The tunnel is not a wrapper around your activity; it is a wrapper around the network leg of it, and the company's visibility is not on the network leg.

What a managed device can typically see

Depending on what is deployed, and most organisations deploy some of it:

  • Every application installed and running, with timestamps.
  • Browser history, through a managed browser policy or an extension.
  • Files created, modified and copied, particularly to removable media.
  • Screen contents, in organisations that use session recording.
  • Keystrokes, in a small number of high-security environments.
  • Location, on laptops with management agents that report it.
  • The fact that you installed a personal VPN. Software inventory is one of the most basic management features there is.

A personal VPN affects none of these.

What it does affect

One thing: it hides the destinations of your traffic from the network you are sitting on. If you are working from a café, a personal VPN stops the café network from seeing your destinations.

If the company's monitoring runs on the laptop, that is a small win against a party you were not worried about, at the cost of a conspicuous entry in the software inventory.

Corporate VPNs run in the other direction

A company VPN is not a privacy tool for you. It routes your traffic into the corporate network so you can reach internal systems and so security controls can inspect what leaves.

Many run full-tunnel, meaning all your traffic goes through the corporate gateway, including personal browsing. Where that is the case, the company's inspection point sees the destinations of everything you do on the device.

Split tunnelling, where configured, sends only corporate destinations through the tunnel. That is a network configuration decision made by the organisation, not a privacy control offered to you.

The realistic advice

Do not use a work device for personal things. This is not about trust; it is about the fact that the device is instrumented and the instrumentation is working as designed. A cheap personal phone is a better solution than any software configuration.

Do not install a personal VPN on a managed laptop without checking policy. It usually breaches an acceptable use policy, it is visible in inventory, and it achieves very little.

Assume the device reports. Not out of paranoia — out of accuracy. Endpoint detection and response tools are standard, and their job is exactly this.

What employers can and cannot do about personal devices

If you use a personal phone or laptop for work through a mobile device management enrolment, the organisation's visibility depends on the enrolment type. A work profile on Android confines management to the work container: the organisation sees apps and data inside it, and not your personal side.

Fully managed enrolment on a personal device gives far broader visibility. It is worth knowing which one you agreed to, and the enrolment screen states it at the time.

In the European Union, workplace monitoring is subject to GDPR and to national employment law: it must be proportionate, and workers generally must be informed. Employers usually satisfy that with a policy document signed at onboarding.

In other jurisdictions the employer's latitude is broader. Either way, the practical position is the same: the monitoring exists, it was disclosed somewhere, and a personal tunnel does not touch it.

Where a personal VPN does belong

On your own devices, on networks you do not control. That is the case it was built for, and it works well there — the privacy policy describes what is and is not recorded on the provider's side, and the Windows client is the same software whether the laptop is yours or not. The difference is entirely in who else is already watching the machine.

Sources

  1. Apple — Device management payloads
  2. Microsoft — Windows Defender for Endpoint
  3. Android Enterprise — device policy controller

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine