I know that legally, employee data has no expectation of privacy. But I'd like to gently push back here.
The word "private" means "having privacy" in the normal, everyday sense. Using that word to describe something that isn't private is lying. You and I both know there do exist many people who suffered consequences for not understanding the definition of that word.
In my opinion, the ethical thing to do is to use a different word when no expectation of privacy applies. And the upside is powerful: transparency gains trust.
Slack did this well: they call them "direct messages".