Showing posts with label employee privacy. Show all posts
Showing posts with label employee privacy. Show all posts

Monday, July 12, 2010

No Harm, No Foul; Ninth Circuit Affirms Dismissal of Data Breach Case Against The Gap

Written by Kevin McGinty

It’s a distressingly common scenario. A corporate laptop containing job applicant data, including social security numbers, is stolen from an employee who has taken the laptop off of corporate premises. Access to the social security numbers makes it possible for wrongdoers to engage in identity theft. Is an applicant’s fear that data will be misused enough to support claims for negligence and breach of contract against the company? The federal Ninth Circuit Court of Appeals has joined a growing number of courts in answering that question in the negative. In Ruiz v. Gap, Inc., the court held that California law requires actual damages to support claims for negligence and breach of contract, and that time and effort that the applicant allegedly expended to monitor for identity theft were insufficient to constitute actual damages. The court reached similar conclusions as to the claim under California’s consumer protection statute and, significantly, the claim for invasion of privacy. As to the latter, the court ruled that increased threat of a breach of privacy does not constitute an actual invasion of privacy.

None of this is to say that a company is immune from state law liability and can simply elect to do nothing when a data breach occurs. Although not detailed in the Ninth Circuit’s decision, The Gap took affirmative steps to protect applicants from potential harm arising from theft of their data. Not only did The Gap notify the applicants about the theft of the computer containing their personal information, but it also offered to provide twelve months of credit monitoring and fraud assistance without charge, plus $50,000 worth of identity theft insurance. The lesson of the Ruiz decision is that companies that do take reasonable steps to mitigate against potential misuse of stolen data will have a strong defense against further liability. It also reinforces the commonsense proposition that has bedeviled many attempts to parlay data breaches into class actions – the mere threat of bad consequences is not the same as actually suffering bad consequences. Thieves generally steal computers because they want the hardware, not the data. The loss of a computer containing personal data does not inevitably mean that such data will be misused. As such, claims arising from data breaches are unlikely to succeed unless there has also been identity theft and resulting adverse consequences for individuals whose identities have been stolen.

Tuesday, June 22, 2010

More on Supreme Court Ruling in Quon

And as promised in our last post, here is the latest Client Advisory on the Supreme Court's ruling in the Quon case.

Thursday, June 17, 2010

Breaking News: Supreme Court Issues Decision in Employee Privacy Case

Written by Martha Zackin

As we’ve blogged in this space,, back in December, the Supreme Court agreed to hear City of Onatario v. Quon, a case on the privacy of text messages sent by a government employee on employer-provided devices. Specifically, the Court agreed to consider whether a police sergeant assigned to a Ontario, California SWAT team had a reasonable expectation of privacy under the Fourth Amendment in sexually-explicit, non-work related text messages transmitted on a department-issued pager and stored by an outside service provider even in the face of the City’s "general practice" of non-monitoring of such communications.

Today, the Court issued its opinion, finding that the City’s search of Sergeant Quon’s text messages to his colleagues and the woman with whom he was having an affair was reasonable. Although the Court did not reach agreement on whether and to what extent government workers have any reasonable expectation of privacy in communications such as those at issue here, the Court did agree that the search was reasonable.

The impact of this decision may be limited to Sergeant Quon and his co-workers; the Court explicitly cautioned against using the facts of the case to establish “far-reaching premises that define the existence, and extent, of privacy expectations enjoyed by employees when using employer-provided communication devices.”

More to come.

Thursday, April 29, 2010

Connecticut Woman Files First Suit Under Federal Law Prohibiting Genetic Discrimination

Written by Jennifer Rubin

A Connecticut woman has filed a charge of discrimination under the Federal Genetic Information Nondiscrimination Act ("GINA"), which prohibits discrimination against employees based upon their status as carriers of genetic information. The woman claims her status as a carrier of the BRCA2 gene, a gene sometimes associated with the elevated risk of breast cancer, led to her termination after she had preventive surgery relating to her breast cancer risk.

GINA was passed to address concerns of individuals who might be reluctant to undergo genetic testing because the results, if disclosed to an employer, might be used in a discriminatory manner by employers. While it is premature to predict the probability of outcomes of this employment dispute, it reminds employers of their obligations to comply with GINA and other numerous other Federal and state laws concerning the management and use of health information in the workplace.

Related Links:

Hartford Courant
Woman claims genetic test led to firing at Stamford firm - StamfordAdvocate
Home WGGB abc40 News, Weather and Sports in Springfield Massachusetts

Tuesday, April 6, 2010

More on last week's NJ Supreme Court decision -

The decision we blogged about in this space last week is creating quite a bit of buzz in both privacy and employment law circles. My employment law colleagues in our New York office have authored an analysis of the decision here: Employment Alert: New Jersey Supreme Court Finds Privacy Rights in Employee E-Mails

And, the International Association of Privacy Professionals' Daily Dashboard quoted my partner, Jen Rubin:

PRIVACY LAW -- U.S.
Employee E-mail Decision Spurs More Questions
Last week's New Jersey Supreme Court decision that employees should have an expectation of privacy when they use personal e-mail accounts on corporate computers is raising new questions, NetworkWorld reports. The court's decision specified that when it comes to monitoring employees' actions online, "employers have no need or basis to read the specific contents of personal, privileged, attorney-client communications in order to enforce corporate policy." Jen Rubin, attorney at Mintz Levin in New York, says the decision brings up new questions about employer ownership of e-mail created on company-issued computers and is likely to have businesses taking much closer looks at their e-mail policies. Full Story

This is an important decision with wide-reaching implications. If you are an employer and you have not looked at your "Acceptible Use Policy" or other such electronic systems policy in a while (or worse, if you don't have one at all.....), this case should motivate you to pull it out and look again.

Wednesday, March 31, 2010

BREAKING NEWS: NJ Court Upholds Employee E-mail Privacy

In a precedent-setting decision, the New Jersey Supreme Court today ruled that a company should not have read e-mails a former employee sent to her lawyer from a private Web account through her employer's computer (See November 5, 2009 Privacy and Security Information blog post). According to the Star-Ledger, the court, which determined the company's policy regarding e-mail use was vague, upheld the sanctity of attorney-client privilege in electronic communications.

Given the importance of this decision to both privacy issues and employer/employee workplace issues, we will provide a complete analysis.

Monday, February 22, 2010

T Minus 10,080 Minutes and Counting.....

We have just one week to go before all entities that own, store, license -- or basically do anything with -- personal information of Massachusetts residents must comply with the Commonwealth's new data security regulations. Things to consider:
  • Have you done your risk assessment? Looked at what you collect and how you collect and how it is transmitted through and outside your organization?
  • Have you reached out to service providers that may have access to PI of your employees/customers?
  • Is your written information security plan in place, or at least have you started pulling together the various policies and processes ("P&P") that would make up a "written information security plan"? Is the plan tailored to your actual P&P and, thus an accurate representation of what your business really does (and not a template with [insert company name here])?
  • Have you thought about employee security awareness training?

Thursday, January 28, 2010

Data Privacy Day -- Tip #4 -- Transactional Best Practices for Lawyers

Written by Michael Arnold and Jennifer Rubin

Even though lawyers working on both sides of an M&A transaction during the due diligence phase might immerse themselves in a “confidentiality bubble”, they still must be careful not to disclose or access confidential employee information in the course of that transaction. Attorneys evaluating potential transactions might be tempted to access information regarding target employees, such as personnel files, compensation information, and information concerning performance evaluation and other historical employment information. Transactional attorneys are often surprised to learn that dissemination of some of this information, even among those subject to a confidentiality agreement, may violate an employee’s privacy rights and even violate the law.

Some states preclude employers from disclosing employee personnel information or from revealing information regarding employee compensation altogether while other states require a waiver from the employee as a condition to dissemination to any third parties. Federal and many states laws make it illegal for companies to disclose employee medical records without authorization, and this is particularly a concern where those records include personal health information and may implicate newly-expanded HIPAA regulations. Personnel files of employees that are Massachusetts residents will contain "personal information" that can only be transmitted in compliance with the Massachusetts regulations. In the cross-border M&A context, "personal data" of employees can only be transferred to the U.S. (or to U.S. persons) in compliance with applicable data protection laws in their country of residence/employment -- and in most cases can only be with the employee's consent. Even documents in a digital "data room" that can be accessed from the U.S. may fall afoul of data protection laws in other countries.

Companies must ensure that they have the proper mechanisms in place to minimize the exposure of personnel information during a contemplated transaction, including having a good understanding as to what legally may and may not be provided to potential acquirers, and securing any necessary waivers from employees prior to turning that information over in the due diligence process.

And finally, storage and disposal of due diligence files containing personal information or protected health information must be handled in accordance with applicable state and federal laws. If you don't keep it, you can't lose it!

Data Privacy Day - Tip #3 - The weakest link??

My lunchtime speaking engagement was at the International Association of Privacy Professional's Boston KnowledgeNet. I had the pleasure to share the panel with Mike Spinney from SixWeight (www.sixweight.com) and identity theft guru Robert Siciliano. We had a spirited discussion about privacy training and awareness. You can access their blogs in the panel to the right.

Our conclusion -- People are one of the weakest links in information security: employee negligence or wrongdoing is among the most common causes of security breaches.

Implement and train employees to follow formal information security policies that protect the private information of employees and customers.

Limit the number of people who have access to and/or handle confidential documents. Be careful when hiring new employees and perform full reference checks and, where warranted, ask new hires to sign confidentiality agreements.

Privacy awareness is as important as training and it should be continuing education.

Monday, November 9, 2009

When employee handbooks don't tell the whole story.....

Written by Cynthia and Jennifer

The discussion of employer access to employee emails in our September 21 blog entry continues with another appellate court decision about workplace privacy rights.


In Stengart v. Loving Care Agency, Inc., the court completely rejected an employer's attempt to rely upon an email policy to gain access to an employee's confidential communications with her attorney conducted through the employer's email system. The court found that the employer could have no legitimate interest in reviewing an employee's private communications with her attorney, noting that "[p]roperty rights are no less offended when an employer examines documents stored on a computer as when an employer rifles through a folder containing an employee's private papers or reaches in and examines the contents of an employee's pockets; indeed, even when a legitimate business purpose could support such a search, we can envision no valid precept of property law that would convert the employer's interest in determining what is in those locations with a right to own the contents of the employee's folder of private papers or the contents of his pocket." The court went on to reject the notion that emails relating to an anticipated lawsuit against her employer would seem to be an illegitimate business use of the computer system: "the company had no greater interest in those communications than it would if it had engaged in the highly impermissible conduct of electronically eavesdropping on a conversation between plaintiff and her attorney while she was on a lunch break." Additionally, the court sanctioned the employer's law firm for not returning the emails to the employee as soon as the law firm became aware they were privileged communications.

This is a very interesting pro-employee decision but its lesson is clear: even email policies that notify employees that they are waiving certain privacy rights in the workplace do not give employers carte blanche to access or take ownership of all of those communications. Employers who access (intentionally or not) such information should promptly seek counsel before proceeding further.

Thursday, October 29, 2009

$1.8 Million Verdict in Pretexting Case

Written by Cynthia and Michael

A Cook County, Illinois jury recently awarded $1.8 million dollars to Kathy Lawlor, who claimed that her former employer, North American Corp. of Illinois, violated her privacy rights by hiring a private investigator who fraudulently obtained her telephone records through the use of “pretexting” – or by pretending to be Lawlor herself. Some of you might be familiar with the concept of pretexting from the Hewlett Packard scandal in 2006 where HP’s Chairwoman directed independent security experts to investigate the source of an information leak. The security experts obtained the personal phone records of journalists and HP board members by pretexting – or by pretending to be them - and it ultimately allowed HP to determine the source of leak. HP’s efforts caused an uproar, including leading to criminal charges, a congressional investigation and the passage state and federal laws prohibiting pretexting.


In the summer of 2005, prior to the HP scandal, North American terminated Ms. Lawlor’s employment because she would not agree to modify her salesperson commission agreement prior to landing the biggest account of her career. As a result, Ms. Lawlor sued North American seeking to recover certain commissions and for a judgment to lift her non-compete agreement. Ms. Lawlor did not know that at the time she sued North American, it had decided to hire a private investigator to investigate whether Ms. Lawlor’s was stealing its confidential information and clients, and that it had provided certain personal information about Ms. Lawlor to the private investigator, including her Social Security number and phone numbers. During its investigation, in addition to stationing individuals outside Ms. Lawlor’s home, the private investigator arranged for a third party vendor to obtain Ms. Lawlor’s personal phone records by pretexting. When Ms. Lawlor later discovered that North American was investigating her activities she added a claim for invasion of privacy to her lawsuit.


At trial, North American denied that it knew that its private investigator had engaged in pretexting, but the jury was unsympathetic and awarded Ms. Lawlor $1.8 million, most of it coming in the form of punitive damages. North American is contesting the jury’s decision, and the parties continue to litigate North American’s claim that Ms. Lawlor misappropriated its trade secrets, but this case should serve as a warning to employers considering whether and how to conduct investigations of their employees. The North American case confirms that any time an employer conducts an investigation into an employee’s activities it runs the risk of violating that employee’s rights and a resulting lawsuit. Employers must takes steps to ensure that any investigation, whether it be conducted internally or through the use of third party investigators, do not utilize unlawful or other inappropriate methods, including the use of pretexting, which is now prohibited by state and federal law.

Friday, September 25, 2009

Privacy and Security Bits and Bytes

After a bit of a hiatus, our Friday afternoon feature is back:

  • Do you know what your information is worth on the black market? It may just surprise you. Good piece on a new Symantec tool to let you do the calculations. See Information Security Resources - What Are You Worth On The Black Market?
  • Despite all of the public flurry surrounding security breaches, and customer expectations that the information entrusted to vendors will be secure, a new survey finds that an astounding 71 percent of those companies surveyed said they still weren't making data security a top initiative in their IT budgets, even though 79 percent of them admitted that they had been hit by one or more data breaches since the PCI DSS standard was enacted in 2005. Companies Still Not Securing Customer Data - InternetNews.com.
  • Companies around the world are preparing for the swine flu pandemic and putting policies and procedures in place for workers and business continuity. What, if anything, are people doing about the privacy issues that need to be addressed in that planning?
    Good article, with links to resources here - Protecting Your Privacy During a Pandemic
  • Remember our blog posts on the demise of the Clear program? Next week, the Committee on Homeland Security is holding a hearing on "The Future of the Registered Traveler Program"
    Wednesday, September 30, 2009 @ 2pm
    311 Cannon House Office Building
    The hearing will evaluate the recent cessation of operations by Registered Traveler (RT) providers, actions undertaken by the Transportation Security Administration (TSA), and the impact on airports. There will be a webcast of this hearing.

Should be fascinating viewing. I wonder if we'll hear anymore about whatever happened to all that data???

Monday, September 21, 2009

What is "reasonable expectation of privacy" in an employment context?

Written by Cynthia and Jennifer

A recent decision by the Maine Supreme Court highlights the tension between an employee's reasonable expectation of privacy in conducting personal business through a company's computer system and the individual's right to prevent the company's publishing of such material. In Fiber Materials, Inc. v. Subilia, the Maine Supreme Court dismissed an interlocutory appeal by a former executive who charged the company with improperly accessing and publishing the executive's attorney-client privileged communications with his attorney which had been stored on the company's computer system. While the court dismissed the appeal for procedural reasons, the court criticized the company's counsel for taking the preemptive position that the material retrieved was appropriately disclosed publicly without first seeking advice from state bar counsel before publishing it in a complaint.

The issues in this case are similar to those raised in the Scott v. Beth Israel case, where a New York trial court concluded that an employee's use of the employer's email system to communicate with his attorney waived the privilege because the employer's policy expressly prohibited personal use of the email system.

While these cases appear to produce two different results, they dictate the care employees and employers alike must take with respect to accessing information on a company-owned computer system and the use of that system in the first instance to conduct any type of personal business, especially sensitive personal business.