Summary
A VPN encrypts the traffic between your device and the VPN provider, so anyone watching the network in between sees scrambled data going to one address. That is all it does. On a work laptop, your employer is not watching the network in between; they are on the laptop itself, through monitoring software, device management and a managed browser, all of which read your activity before the VPN encrypts anything. On a personal device on the company Wi-Fi the answer is different, and on a personal device on your own connection the employer sees nothing at all. This guide walks through each case, explains why the corporate VPN your employer gives you is the opposite of private, and sets out what employers can and cannot lawfully do with what they see.
E-Monitor tells employees exactly what is recorded on work devices, during work hours only, with a dashboard they can open themselves. Book a demo →
What a VPN Actually Hides
A virtual private network creates an encrypted tunnel from your device to a server run by the VPN provider. Your traffic enters the tunnel, travels encrypted across whatever network you are on, exits at the provider's server and continues to its destination from there. Two things are hidden from anyone sitting on the network between you and the provider: the content of your traffic and the addresses you are talking to. The network sees one encrypted connection to the VPN server and nothing else.
That is a genuine protection against the right threat: a coffee shop network, an internet provider, or a corporate router logging which sites you visit. It is no protection against anything that runs on the device itself, because the device sees your activity in plain form before it enters the tunnel. Keystrokes, screenshots, the application in the foreground, the page title in the browser: none of that passes through the VPN at all.
Case 1: Work Laptop, Any Network
This is the case most people are asking about, and the answer is that a personal VPN hides almost nothing.
Three layers on a company-managed laptop see your activity regardless of any VPN. Monitoring software such as E-Monitor or its competitors records active applications, websites by title and address, time in each, and optionally screenshots. It reads this from the operating system, not from the network. Device management tools such as Microsoft Intune or Jamf control what can be installed, can block VPN clients outright, and log device state. A managed browser with company extensions or policies records history and can block sites on its own, inside the browser, before any packet leaves the machine.
There is a fourth layer on many corporate laptops: a security agent that inspects traffic on the device itself, including traffic that would otherwise be encrypted. Combined with DNS logging and TLS inspection at the corporate proxy, it means even the network view is not as blind as the VPN marketing suggests.
The practical result: on a work laptop, the VPN changes what the network sees and nothing about what the employer sees. Installing one may also breach the acceptable-use policy, and on a managed device the installation itself is logged. The guide to what employers can see on a computer covers the full list.
Case 2: Personal Device on the Office Network
Here the VPN does what it says. Your personal phone or laptop has no company software on it, so the only place the employer can observe is the network. The office Wi-Fi normally logs DNS requests and destination addresses, and a VPN replaces all of that with a single encrypted connection to the provider.
What the employer still sees: that a device connected, that it is using a VPN (the destination is a known VPN server and the traffic pattern is distinctive), and how much data it moved. Many corporate networks block known VPN endpoints, so the practical effect may be that the VPN does not connect at all. What they cannot see is which sites you visited or what you did there.
Whether the employer may monitor a personal device on its network depends on the policy you accepted when you joined the Wi-Fi. The home computer guide explains the bring-your-own-device rules.
Case 3: Personal Device on Your Own Connection
No company software, no company network. The employer has no technical visibility at all, with or without a VPN, except through accounts you log into. If you sign in to the company email or a company SaaS tool from a personal device, the service logs that access: time, IP address and sometimes device type. The VPN changes the IP address the service sees and nothing else.
This is also the case that trips up people using a VPN to appear to be in one place while working from another. The account logs show a VPN exit address, which is often more conspicuous than the real location would have been, and the laptop location guide explains what employers can infer from it.
The Corporate VPN Is the Opposite of Private
Many remote workers are required to connect through the company's own VPN. This is easily confused with the privacy product of the same name, and it does the reverse job. A corporate VPN routes your traffic through the company network so that company systems can be reached, and so that company security tools can see it. Everything you do while connected is, by design, visible to the organisation at the network level, in addition to anything the laptop records.
Split tunnelling, where only company traffic goes through the corporate VPN and the rest goes direct, reduces what the network sees but changes nothing about the device layers. Running a personal VPN inside a corporate VPN mostly produces a broken connection and a log entry.
What Employers Can Lawfully Do With What They See
Visibility and permission are different questions. In the United States, monitoring of employer-owned devices is broadly lawful, and several states require written notice: New York, Connecticut and Delaware among them. In the EU and UK, monitoring must be disclosed, proportionate and limited to a stated purpose, and the ICO and national data protection authorities have fined employers for covert or excessive collection. Everywhere, the employer's position is strongest when the policy says what is recorded and the employee was told before it started.
Three limits apply broadly. Monitoring should stop at the edge of work: outside scheduled hours, and on personal devices without an explicit agreement, employers should not be collecting. Monitoring should not read private communications, even on work devices, in jurisdictions with strong privacy law. And whatever is collected should be visible to the person it describes. The legal guide sets out the rules by country, and the policy guide shows what the disclosure should say.
Quick Reference: Who Sees What
The three cases reduce to a single table. "Device layer" means monitoring software, device management and a managed browser; "network layer" means Wi-Fi logs, DNS logging and proxy inspection; "account layer" means the login records of company email and SaaS tools.
| Situation | Device layer | Network layer | Account layer | What a personal VPN changes |
|---|---|---|---|---|
| Work laptop, any network | Sees everything | Sees VPN connection only | Sees logins | Nothing that matters; installation is logged |
| Work laptop on corporate VPN | Sees everything | Sees everything | Sees logins | Usually will not connect |
| Personal device on office Wi-Fi | Nothing | Sees VPN connection and data volume | Sees logins | Hides sites visited |
| Personal device on own connection | Nothing | Nothing | Sees logins and IP | Changes the IP the account sees |
How to Find Out What Your Work Laptop Records
You do not need to guess. Five checks, in order of effort, tell you what is actually in place.
- Read the monitoring policy. In the EU, UK and several US states the employer must tell you what is collected; the policy is usually in the handbook or the intranet
- Check installed programs and running processes. Monitoring agents and device management clients appear by name; E-Monitor, for example, is visible as an installed application and does not hide
- Check the browser's management page. Chrome and Edge show whether the browser is managed by your organisation and which policies and extensions are forced
- Look for a device management profile. On Windows, Accounts, Access work or school; on macOS, System Settings, Profiles
- Ask for your data. Under GDPR and the UK and California privacy laws you can request what has been collected about you, and a transparent program will show you a dashboard without the request
If the answers do not match the policy, that is a compliance problem for the employer, not a reason to install a VPN. Raise it with HR or the works council. The stealth versus transparent monitoring guide explains why undisclosed monitoring is the employer's legal exposure, not yours.
What This Means for Employees
If you want privacy at work, a VPN is the wrong tool and a personal device is the right one. Keep personal browsing on a personal phone on mobile data, and the employer has nothing to see. On a work laptop, assume everything during work hours is visible, read the monitoring policy to find out what is actually recorded, and ask for your own data if the policy says you can see it.
If you are using a VPN on a work laptop to hide something specific, two things are true: it is not hidden, and the installation itself is probably the policy breach that gets noticed first.
What This Means for Employers
Employees reach for VPNs when they do not know what is being recorded and assume the worst. The cheapest fix is disclosure: a short policy that lists what the monitoring software collects, confirms it runs only during work hours on work devices, and shows employees their own dashboard. Organisations that do this report fewer workarounds, not more, because there is nothing left to guess about.
Technically, block personal VPN clients on managed devices through device management if the policy prohibits them, and say so in the policy rather than discovering it in a log. The trust guide explains why the saying-so matters more than the blocking.
Frequently Asked Questions
1. Does a VPN hide my browsing from my employer on a work laptop?
No. Monitoring software, device management and a managed browser read your activity on the laptop itself, before the VPN encrypts anything. A VPN only hides traffic from the network in between, which is not where your employer is looking.
2. Can my employer see that I am using a VPN?
Usually yes. On a managed laptop the VPN client is visible as an installed program and a running process. On the office network, the connection to a known VPN server and its traffic pattern are distinctive, and many corporate networks block VPN endpoints outright.
3. Does a VPN hide my activity on a personal device on company Wi-Fi?
Largely yes. With no company software on the device, the employer can only observe the network, and the VPN replaces your browsing with a single encrypted connection. They can still see that a device connected, that it used a VPN, and how much data it moved.
4. Is the company VPN the same as a privacy VPN?
No, it is the opposite. A corporate VPN routes your traffic through the company network so that company systems and security tools can see it. Everything done while connected is visible to the organisation by design.
5. Can I get in trouble for using a VPN on a work computer?
If the acceptable-use policy prohibits unauthorised software, installing a VPN client is itself a breach, and on a managed device the installation is logged. Check the policy before installing anything.
6. Can my employer see what I do on my phone?
Only if the phone is company-owned or enrolled in company device management, or when you log into company accounts, which record access time and IP address. A personal phone on mobile data with no company software gives the employer no visibility.
Nothing to hide, nothing to guess E-Monitor records work-hours activity on work devices and shows employees exactly what is collected, which is why nobody needs a VPN to feel safe. Sign up →
