WhatIs.com

employee privacy policy

By Wesley Chai

An employee privacy policy is documentation specifying an organization's rules and procedures for gathering, using and disclosing the personal information of former, current or prospective employees. Some elements of privacy policies may be mandated by labor laws, while others are specific to a given organization.

An employee privacy policy should define what constitutes personal information and the means by which it might be collected. As a rule, most companies define personal information to include all employee data (such as home address and work history), and all communications that are not work-related.

A policy should clearly stipulate situations in which an employee should not assume their data and communications are private. Phone calls, texts, emails and social media communications that are transmitted on corporate-owned equipment, for example, are not legally protected. Software and websites that are not required for business purposes may be restricted according to policy or blocked to prevent problems.

It's also important to specify under what conditions employee data will be disclosed. Those conditions could include situations where the employee had consented, emergency situations and legal situations, such as a warrant or a court order.

Privacy policies should also disclose any employee monitoring systems, such as video recording. Employees should be provided with copies of the privacy policy and should be required to confirm that they have read and understood it.

Personal data is becoming more valuable as networked devices are frequently used for work and personal purposes. With sensitive data exchanged on these devices, concerns about personal data tend to exist -- with employees concerned that their data may be poorly handled and leaked to malicious entities. A good employee privacy policy aims to prevent these concerns with upfront disclosures.

Frequent employee privacy concerns

Privacy-related issues employees are likely to be concerned include the following:

What is protected employee information?

Typically, only personal information (aka personal data or Personally Identifiable Information, or PII) is afforded special protection by employee data privacy regulations. This usually includes one or more types of personal information that identifies or is linked to an identifiable living individual (such as name, address, phone number, birth date, Social Security number, medical records, etc.) In some cases, it includes a combination of such information that could potentially identify an individual (e.g., birth date, gender and postal code taken together).

Certain types of sensitive data is often given enhanced protection under privacy regulations such as GDPR (General Data Privacy Regulation). Sensitive data under GDPR, for example, includes race, ethnicity or national origin, political opinions or associations, union membership, sexual orientation, marital status, health-related information, and criminal history.

In the United States, a few U.S. federal statutes protect specific types of personal information. One key law is the Health Insurance Portability and Accountability Act (HIPAA), which protects PII when it is used in a medical context (for covered entities). Combined together (PII + medical information), this type of personal data is known as PHI (Personal Health Information). In addition, most U.S. states have laws concerning data security and security data breach notification. Many of these laws are focused on identity theft and/or financial protection measures that generally aim to protect Social Security numbers and similar financial personal information against unauthorized use or disclosure.

Some states in the United States, such as California, have enacted stricter, more comprehensive privacy laws, and this trend is expected to continue in the United States. Those laws offer the consumers covered by them more comprehensive data privacy protection.

Building an employee privacy policy

In general, a great way to prepare for creating an employee privacy notice is to create a personal data processing register, data inventory and/or data map, which identifies the following:

The above information can then be used to determine what privacy regulations apply to the personal information/data, and can be used to create compliant processes and a privacy notice, which addresses the requirements of those regulations.

An employee privacy policy should include:

Please note, the elements that should be included vary by state as well as whether a regulation is in scope for specific employees.

Laws and federal regulations

A few examples of laws and federal regulations include:

HIPAA (Health Insurance Portability and Accountability Act)

GINA (Genetic Information Nondiscrimination Act)

FACTA (Fair and Accurate Credit Transactions Act)

CCPA (California Consumer Privacy Act). Allows employees to:

State Data Breach Laws. Each U.S. state (plus Washington D.C., Guam, Puerto Rico, and the Virgin Islands) has laws requiring organizations to notify individuals in the event of a security breach with personal information. It is important to check specific state laws for up-to-date details on regulations.

Workplace privacy. While video surveillance is legal in workplace areas if disclosed, it is not legal in other common areas, such as washrooms and break rooms. Within the United States, video surveillance cannot include audio recording, which is illegal under wiretap law.

24 Mar 2020

All Rights Reserved, Copyright 1999 - 2024, TechTarget | Read our Privacy Statement