1. The short answer, and why the rules exist
  2. Who the Workplace Surveillance Act puts in the picture
  3. The default rule: blocking is prohibited unless a policy has been notified
  4. Building a policy that makes blocking lawful
  5. The lines you cannot cross
    1. Surveillance stops at the boundary of work
    2. Camera surveillance has its own rules
    3. Listening devices are outside the Act entirely
    4. Covert surveillance requires a court-issued authority
  6. Where blocking rules bite in practice
  7. When a lawyer earns their fee
  8. The notice you send before the filter matters more than the filter itself

The short answer, and why the rules exist

Most businesses that block websites for their staff do it for one of three reasons: to protect productivity, to reduce security risk, or to stop employees landing the business in legal trouble by accessing gambling, adult content, piracy sites or other material that carries liability. All three are legitimate aims, and no Australian law says an employer cannot block websites outright. What the law regulates is how you go about it.

In New South Wales the rules are set out in the Workplace Surveillance Act 2005 (NSW), which treats blocking and monitoring as forms of workplace surveillance. The short version of the scheme is this: blocking a website is technically prohibited unless you are acting under an email and internet access policy that was notified to the employee in advance, and monitoring an employee's computer use is only lawful if you have given notice and operated under a policy the employee knows about. Get those pieces in place and blocking is legal. Skip them and you are exposed to fines of up to 50 penalty units per breach, which is $5,500 (AUD) at the current NSW rate of $110 per unit set by s 17 of the Crimes (Sentencing Procedure) Act 1999 (NSW), as well as the employment-law fallout that usually follows.

This article walks through how the scheme actually operates: who it applies to, what turns a block into a lawful one, the limits you cannot cross, and where it goes wrong in practice. It is written for business owners and operators who want a defensible approach, not a checklist borrowed from a lawyer's file.

Who the Workplace Surveillance Act puts in the picture

The Workplace Surveillance Act 2005 (NSW) applies to employers and employees in New South Wales, and its definitions deliberately sweep in contractors and voluntary workers as well. There are three main actors under the scheme:

  • The employer: sets the policies, gives the notices, and is the party liable for fines if a block or surveillance is done without the required policy and notification.
  • The employee: must be notified of the policy in advance, in a way that makes it reasonable to assume they are aware of and understand it.
  • A Judge of the Local Court: issues authorities for covert surveillance, the only situation where an employer can monitor without the employee knowing.

The key concept is computer surveillance, which the Act defines as surveillance by software or other equipment that monitors or records the information input or output, or other use, of a computer, including the sending and receipt of emails and the accessing of internet websites. Blocking a website is not itself surveillance, so the Act deals with it in its own dedicated provision, which we come to next. But the policy machinery that makes blocking lawful is the same machinery that governs computer monitoring, so the two rules have to be read together.

One point worth flagging early: NSW is one of only two jurisdictions with a law dedicated to workplace surveillance, the other being the ACT, which has its own Workplace Privacy Act 2011 (ACT). Everywhere else, employers rely on the general surveillance device legislation in their state or territory, the terms of the employment contract, and the ordinary law of unfair dismissal. That means an employer running sites in several states cannot simply copy one NSW policy and assume it works everywhere. The mechanics in this article are the NSW mechanics, and a lawyer should check the position in each state you operate in.

The default rule: blocking is prohibited unless a policy has been notified

The provision that directly answers the blocking question is s 17 of the Workplace Surveillance Act 2005 (NSW). It starts from a prohibition: an employer must not prevent, or cause to be prevented, access to an internet website by an employee. Blocking a site through your firewall is exactly the conduct the section targets.

The prohibition lifts only if you are acting in accordance with a policy on email and internet access that was notified to the employee in advance, in such a way that it is reasonable to assume the employee is aware of and understands the policy. Two things stand out about that condition.

First, the policy must be notified in advance. A policy that exists on an intranet, or was emailed once to the whole company, will generally satisfy this if it is written in plain language and employees are told to read it. A policy drafted after the fact, to justify a block that has already happened, does not.

Second, the test is about reasonable assumption of awareness, not proof of actual awareness. This is why the common practice of including the policy in the employment contract and having the employee sign it is the gold standard: a signed contract makes the reasonable-assumption test very hard to argue against. For existing staff, an email that attaches the policy and asks them to confirm they have read it achieves much the same result.

Email is treated differently from websites. If you block an email addressed to or from an employee, you must not only be acting under the notified policy but also give the employee a prevented delivery notice as soon as practicable, telling them delivery was blocked. There are exceptions, mainly for emails that appear to be commercial electronic messages within the meaning of the Spam Act 2003 (Cth), and for emails blocked by automated programs designed to catch spam or malware, both of which s 17 itself carves out. The practical takeaway: if your filter silently drops an employee's personal email, you are in breach, even with a perfect policy.

The maximum penalty for a breach of s 17 is 50 penalty units, or $5,500 (AUD). That is per offence, so a filter configured without a notified policy that blocks hundreds of sites is not one breach, it is potentially many.

Building a policy that makes blocking lawful

The policy is the engine of the whole scheme, so it is worth understanding exactly what the Act requires of it. Section 12 imposes the conditions for computer surveillance: it must be carried out in accordance with a policy of the employer on computer surveillance of employees at work, and the employee must have been notified of that policy in advance in a way that makes it reasonable to assume they are aware of and understand it. Section 10 adds the notice requirements that apply to surveillance generally.

The practical effect is that a lawful web-filtering arrangement needs two documents working together:

  • The internet and email policy: the substantive rules, covering what sites are blocked or restricted, why, and the consequences of trying to bypass the filter.
  • The notice: a written notice to each employee, given before the arrangement starts, setting out the mechanics of any monitoring that will accompany it.

On timing, s 10 requires at least 14 days' written notice before surveillance commences, though an employee can agree to a shorter period. A new employee who starts after monitoring is already in place must be given the notice before they start work. Email counts as notice in writing, so the whole process can be run electronically.

The notice must say five things: the kind of surveillance to be carried out (camera, computer or tracking), how it will be carried out, when it will start, whether it will be continuous or intermittent, and whether it will run for a specified limited period or on an ongoing basis. A notice that says "we may monitor your computer" without any of that detail does not comply.

When you draft the policy itself, the content is up to you, but the categories of site you block should be matched to a reason you can defend. Blocking gambling, adult content and piracy sites is easy to justify on legal and security grounds. Blocking social media and streaming services is a productivity call, and one employees may resent, so the policy should say clearly which categories are blocked and which are merely discouraged. Whatever you decide, the policy should be reviewed whenever you change the filter, because a policy that says one thing while the firewall does another is the fastest way to lose the reasonable-assumption argument.

The lines you cannot cross

A compliant policy gives you a lot of room, but not unlimited room. Part 3 of the Act sets out what remains prohibited even with a policy in place, and Part 4 imposes a strict regime for covert surveillance.

Surveillance stops at the boundary of work

Section 16 prohibits an employer from carrying out surveillance of an employee using a work surveillance device when the employee is not at work. The important carve-out: this does not stop computer surveillance of the employee's use of equipment provided by, or at the expense of, the employer. So monitoring how an employee uses the company laptop after hours can still be lawful, but pointing a camera or using a tracking device on an employee outside work is prohibited. The Act only regulates surveillance of employees while they are at work, a term it defines in s 5.

Camera surveillance has its own rules

Under s 11, cameras must be clearly visible where the surveillance is taking place, and signs notifying people they may be under surveillance must be clearly visible at each entrance to the area. There is no way to make covert camera surveillance lawful.

Listening devices are outside the Act entirely

The Act notes that it does not apply to surveillance by means of a listening device, which is regulated instead under the Surveillance Devices Act 2007 (NSW). If your monitoring captures audio, you have moved into a different legal scheme with different requirements.

Covert surveillance requires a court-issued authority

The Act defines covert surveillance as surveillance that is not carried out in compliance with the Part 2 requirements, meaning surveillance the employee was not properly notified about. Section 19 prohibits it unless authorised by a covert surveillance authority, again with a maximum penalty of 50 penalty units.

Authorities are not rubber-stamped. The employer must apply to a Judge of the Local Court, and the application must state the grounds for suspecting a particular employee is involved in unlawful activity, what other managerial or investigative procedures have already been tried and their outcome, and the names of the employees or a description of the group to be watched. The Judge must be satisfied that reasonable grounds exist, having regard to the seriousness of the unlawful activity, and for areas like recreation rooms and meal rooms the Judge must consider the heightened expectation of privacy employees have there. An employer who is refused can apply to a judicial member of the Industrial Relations Commission within 30 days. In short, covert surveillance is available in principle, but it is a narrow, court-supervised path reserved for suspected unlawful activity, not a shortcut around the notice requirements.

Where blocking rules bite in practice

The fines attach to the employer, but the disputes that actually reach courts and tribunals are usually about dismissal, not the surveillance itself. This is where the policy earns its keep.

When an employee is dismissed for breaching an internet policy, the fairness of that dismissal depends heavily on whether the policy was clear and known. The NSW Industrial Relations Commission has upheld dismissals where employees stored or accessed pornographic material on work computers, treating it as a serious breach of trust, for example in Budlong v NCR Australia Pty Limited [2006] NSWIRComm 288 and Lane v Northern Sydney Central Coast Area Health Service [2006] NSWIRComm 380. In Bellenger v Mid North Coast Local Health District [2017] NSWIRComm 1019, the Commission found serious misconduct proven where an employee used the workplace email system inappropriately in breach of a communications policy, and while it found the dismissal harsh and awarded compensation, it did not find it unreasonable or unjust. The pattern across these cases is consistent: a clear, communicated policy is the anchor of a defensible decision, and a vague or unknown policy is what turns a fair dismissal into an unfair one.

Two further realities are worth keeping in mind. The first is that technical blocks are porous. Employees who want around a filter will use a VPN or their personal phone on the office Wi-Fi, so a blocking policy that is not paired with some monitoring, and some enforcement, tends to become theatre. The second is culture. A filter that quietly blocks everything can read as distrust, and employers who impose blocks without explaining the reasons often find the productivity gains cancelled out by resentment. The businesses that make this work treat the policy as a communication exercise, not just a firewall configuration.

When a lawyer earns their fee

The scheme is workable without a lawyer in the straightforward case: a plain-language policy, a 14-day notice, and a filter that matches the policy. But there are three situations where professional help is usually worth the cost.

First, drafting the policy and notices. The requirements are precise, and a template pulled from the internet will not tell you whether it satisfies the reasonable-assumption test for your particular workforce, including contractors and new starters. Second, any move toward covert surveillance. Preparing an application to a Judge that meets the statutory grounds, and handling a refusal or appeal, is specialist work, and getting the application wrong wastes the only lawful route to covert monitoring. Third, when a dismissal follows a policy breach. A lawyer can assess whether the breach is serious misconduct under the policy and the relevant employment legislation, and can defend the decision if an unfair dismissal claim follows, which is where the policy's clarity is tested in front of a tribunal.

The notice you send before the filter matters more than the filter itself

If you take one thing from this article, take the sequencing. The Act does not stop you blocking websites; it stops you blocking them quietly. The entire legal foundation of a web filter is the policy that was notified before the filter went on, in terms an employee could reasonably be expected to understand. A business that sends the 14-day notice, attaches the policy, and asks staff to confirm they have read it has already won the argument before the first site is blocked. A business that configures the filter first and writes the policy later has turned a routine IT decision into a $5,500-per-breach liability and, often, a tribunal case. If you are running this in NSW and have not yet notified a policy that matches your filter, that is the gap to close first, and it is a quick, inexpensive fix to get right with a lawyer's review.