the art of being legal

New Forms of Absenteeism and Their Treatment in Case Law

The use of company computers for purposes unrelated to work duties has posed a significant challenge for both employers and courts, one that has, at times, generated contradictory outcomes.

Article written by

Conesa Legal

At Conesa Legal, a legal advisory firm based in Barcelona, we have a team of lawyers specialized in all areas of law. We also provide comprehensive advisory and management services covering payroll, tax and accounting, and corporate compliance for both companies and self-employed professionals. We stand out for our expertise in labor law and social security, offering a highly specialized and personalized service since 1976. Our services include both preventive and reactive legal advice and representation, tailored to the needs of businesses and workers alike. Our multilingual team provides legal assistance in English, French, and Spanish, and is well prepared to support a broad range of local and international clients, whether they are companies seeking comprehensive legal solutions or individuals in need of personalized legal advice.

View professional profile

The core legal issue is twofold: defining the limits of an employer's right to monitor and supervise employees, and establishing adequate safeguards to ensure that such monitoring does not infringe on employees' fundamental rights, in this case, the right to privacy.

To regulate the use of company computers, employers have the option of introducing an IT acceptable use policy, setting out, as a form of internal rules, which uses are permitted and which are prohibited. Broadly speaking, two main employer positions exist, with many variations in between: a blanket prohibition on any use unrelated to work duties, and a degree of tolerance for personal use within reasonable limits.

The courts, for their part, have progressively defined how monitoring should be carried out by the company and when it crosses the line into a violation of employees' rights. It is worth bearing in mind that this is a relatively new legal challenge, one for which, until fairly recently, no established solutions existed. This has led to rulings that may appear contradictory, but which have collectively helped to shape clear guidelines for practice.

Some of these rulings attracted considerable media attention, for example, the ruling handed down by the High Court of Justice (High Court of Justice (TSJ)) of Madrid on 12 January 2010, which held that an employee's use of a company laptop for purposes unrelated to work, including visiting pornographic websites and thereby exposing the company's network to a virus, did not constitute grounds for disciplinary dismissal. The court concluded that the harm caused was not particularly serious, but rather a potential risk arising from the possibility that the virus might spread across the company's network. It is important to note that Spanish law requires a serious and culpable breach on the part of the employee to justify disciplinary dismissal. In this instance, the court took the view that the harm related to the virus was not sufficiently serious, as it had not actually propagated.

Subsequently, rulings from various High Court of Justices across different autonomous communities have found disciplinary dismissal to be justified in cases where employees were spending part of their working hours browsing the internet:

One example is the ruling handed down by the High Court of Justice (TSJ) of Andalusia on 14 September 2010, which upheld the disciplinary dismissal of a security guard who had been using the company manager's computer for personal purposes, including visiting pornographic websites. The reasoning in that ruling focused on the fact that the misconduct was particularly serious: as the sole guard on the night shift, leaving his post to browse the internet constituted a breach of contractual good faith and a serious failure to fulfil his professional obligations.

A ruling along the same lines was issued by the High Court of Justice (TSJ) of the Valencian Community on 28 September 2010, reaffirming the doctrine already established by the Supreme Court (TS): computers are work tools owned by the company, and the company has the power to monitor their use, provided it respects the employee's dignity. The case concerned an employee who was spending a significant portion of her working day chatting online and using the internet for personal purposes. The company had circulated a notice, signed by all employees, making clear that computers were not to be used for any purpose unrelated to work. After developing reasonable grounds for suspicion that the employee was disregarding this prohibition, the company installed screen-capture spyware on her computer and demonstrated that she was spending extended periods chatting and browsing. The court found that the disciplinary dismissal was justified, as the employee's rights had not been violated given that she had been expressly warned in advance.

In contrast to the various High Court of Justice (TSJ) rulings, the Supreme Court (TS) has issued two judgments addressing the limits of employer monitoring:

The first, dated 26 September 2007, established that computers are work tools owned by the company and may therefore be subject to monitoring by it. However, the ruling clarified that, in order to comply with the requirement of good faith, any company wishing to monitor its IT systems must notify employees accordingly and explain how that monitoring will be carried out.

This ruling is particularly significant because it set out the safeguards that must accompany any employer monitoring: it held that the company cannot access employees' browsing history, as this may contain information relating to religious beliefs, sexual orientation and other matters forming part of the employee's private sphere. The ruling also gave special consideration to emails, which are treated on a par with personal correspondence and enjoy the heightened protection afforded by the constitutional guarantee of communications secrecy. Accordingly, a dismissal based on browsing history or internet activity logs cannot be upheld, as obtaining such information infringes the employee's right to privacy.

A brief note on the monitoring of emails. As mentioned, emails are protected by the right to confidentiality of communications; however, as with a physical letter, it is permissible to record metadata such as the sender, recipient, subject line, and file size, details which can sometimes provide sufficient information to determine whether the communication is work-related, without infringing on the employee's right to privacy, provided that the actual content is not accessed. Think of it like an envelope containing a letter: you can read everything written on the outside of the envelope, but you may not open it to read the letter inside.

The most recent ruling of the Supreme Court, dated 8 March 2011, confirmed the above approach, reiterating that accessing an employee's browsing history or temporary internet files stored on a computer's hard drive constitutes a violation of the employee's right to privacy and cannot serve as the basis for a disciplinary dismissal. The Court established the principle that monitoring internet browsing history is prohibited, though this does not mean it fails to recognise the harm caused to the company when a employee browses the internet during working hours. That harm is real and constitutes a breach of the employee's duty of good faith. However, for a court to find a dismissal justified, the company must comply with all applicable procedural safeguards.

In summary, the consistent position emerging from case law is that companies are entitled to monitor the IT equipment they make available to employees, since such equipment constitutes a work tool.

That said, it is equally important to bear in mind that the power to monitor must be exercised in a manner compatible with respect for the employee's dignity and privacy. Given that a reasonable degree of tolerance towards personal use of company computers is generally accepted (unless an express policy states otherwise), any monitoring must remain within the boundaries established by case law:
Employees must be informed that their use of company computers will be monitored.
Employees must be informed of the manner in which that monitoring will be carried out.
For monitoring to meet all required safeguards, it cannot be based on browsing history or websites visited, as these may contain information falling within the employee's private sphere. In other words, an employer cannot rely on the fact that an employee spent the entire day on Facebook, Twitter, or viewing adult content, as doing so would mean the browsing history had been accessed, and therefore the employee's privacy violated. Monitoring must instead be based on the total amount of time an employee spends on activities unrelated to their work. Software tools exist for this purpose, recording the amount of time an employee spends online without revealing which sites were visited.
This is the legal framework that judges and courts in Spain have developed on this matter to date.

Date published: 6 October 2011

Last updated: 24 August 2026

Published on Updated on