What about employers intercepting SSL connections to spy on social networking/external email usage on the corporate network? Is that against the law too? Genuine question.
This is quite prevalent, and they make it very clear in the Acceptable Use policies that all usage is monitored.
IANAL, and I don't live in the US either, but I can tell you that at least here in Brazil the network traffic is the property of the employer, and you have no expectation of privacy while working, so they can do whatever they want with the traffic that is going to their routers.
Why? Anything you do at work is open to your place of employment. I work in network/information security, and while we don't decrypt encrypted connections, we do log employee Internet access and use the data for investigative purposes. Why would an employee have an expectation of privacy from their employer while they are using corporate assets?
Yes, many companies have DLP (data loss prevention) systems what sniff all outbound data watching for information leaks. If you're posting on Facebook at work, it is very likely that your employer can see exactly what you're sending. We just don't care unless it's sensitive data (get back to work).
This is quite prevalent, and they make it very clear in the Acceptable Use policies that all usage is monitored.