Dialogue Magazine

I wrote a privacy column for the Canadian Payroll Association's (CPA) Dialogue Magazine from 2010–2019. There were 46 columns in total. I was able to recover the bilingual PDF layout as originally published for the first 13 (2010–2012). I have found and am posting the full column text for all but one (a "Union Dues" column from 2013 whose source text could not be recovered). Click a title below to read the column.

Employee Data and Consent

July/August 2010

Read column

This is my first column for CPA Dialogue, and I’d like to start with a large thank you to Murray Long, whose writings have graced this page for more than a few years. My first encounter with privacy and payroll occurred when I was working for a payroll outsourcing firm, and was tasked with a project to make sure that we were ready for new federal legislation about privacy in the private sector. I did some reading and attended a few conferences to try and get up to speed. Murray’s wisdom and insight back then helped to minimize the wrong steps that I took, and I’m sure that his columns and work with the CPA have had a similar salutary effect on many others. His will be large shoes to fill.

As this is my first article, I thought I’d start with a discussion about the way that I approach the practice of privacy, which is to say as a former operations manager and business process improvement project manager. That approach is characterized by a couple well-known sayings:

1) The perfect is the enemy of the good - This might seem counter-intuitive to a payroll person, since you know that every pay statement HAS to be perfect or you will most certainly hear about it - usually loudly and often profanely. However, privacy is not something that can be easily converted into an algorithm, and any hope of getting your privacy program right for all people in all circumstances is a recipe for failure. The best that you can hope for is that you will implement privacy protections that most of the people whose data you are protecting, most of the time, will accept as reasonable.

2) You can’t manage what you can’t measure - This one will seem intuitive to payroll people, much of whose world consists of things that are easy to measure - hours worked, rates of pay, statutory remittances, etc. On the other hand, privacy metrics will be counter-intuitive to some privacy practitioners, especially the ones that focus on legal compliance and policy development. But at the end of the day, a privacy program must be reflected in activities done, or not done, by an organization and the outcomes of these activities can provide feedback on a privacy program.

So what does this mean in the real world? How do you, as a payroll professional, translate these glib sayings into meaningful guidance about the way that you do your job on a day to day basis? As it happens, shortly before the deadline for this article the federal government introduced Bill C-29, “An Act to amend the Personal Information Protection and Electronic Documents Act” which includes a number of provisions that are directly impact privacy in the payroll world. Regular readers of this column will remember that some of the possible proposed changes were mentioned last issue. I’d like to take the rest of this column to look at one aspect of the proposed changes to PIPEDA - consent - and talk about its operational consequences for payroll professionals.

To be clear, if and when the new amendments to PIPEDA go into affect, however amended, they will directly affect you ONLY if you are a federal work, undertaking or business (FWUB). If you are covered this way you probably already know it, but the quick rule of thumb is that if you are covered by the Federal Labour code, instead of a provincial code, you are probably a FWUB. That being said, PIPEDA is often used by privacy professionals as a guideline for best practices where there is not a specific provincial regulation or collective agreement in place. So you should pay attention to PIPEDA changes affecting payroll because they may change your departments goals or deliverables.

What’s changed: The definition of consent and the necessity for consent in the employment context

The new legislation states that, “… the consent of an individual is only valid if it is reasonable to expect that the individual understands the nature, purpose and consequences of the collection, use or disclosure of personal information to which they are consenting.” This, I believe, significantly reduces the circumstances in which ‘opt-out’ or ‘assumed’ consent could be regarded as valid.

For payroll practitioners the impact on this may be somewhat mitigated by another change, apparently modelled on the Alberta and BC models for employee privacy. If the bill passes as it reads now, consent of employees will NOT be required to collect, use or disclose their personal information, IF that collection use or disclosure is necessary to establish, manage, or terminate the employment relationship. However, the employer must notify employees so that they are aware of what data is being used for these purposes. You should also know that the definition of employee personal information will be expanded to include applicants for employment.

Operational impact:

Data: You will need to do an inventory of the employee information you have and the uses to which you put it to categorize whether those uses are necessary for the employment relationship (SIN # for statutory remittances, e.g.) and those that are not (home contact information for a social club, e.g.). If you already have this meta-data about your data you are ahead of the game, but if you haven’t now is a good time to start, since you probably have a number of months before the legislation is passed and possibly more before it goes into affect.

Policy & Procedure: You will need to schedule a review and update of your employee privacy policy and related procedures and forms. Where these policies and procedures impact other departments, you may need to initiate a new project or projects to deal with implementing the changes. At a minimum you will need to change the wording on most or all of the consent forms that you currently use, changing them from a signature for consent to a signature acknowledging notification. You may have to split some of your forms between notification and consent signatures.

Communications: You will need to prepare a communications plan, with various messages for a number of different audiences. For senior management you will need to prepare an estimate of the resources that will be required to maintain compliance. This can be based on your initial assessment of data changes and policy changes above. For line managers you will need to prepare messaging and training on how to respond to likely employee concerns about ‘losing’ consent. For IT you may need to work together to prepare functional requirements documentation to change your HRIS. Alternatively you may need to proactively engage your payroll service or software vendor in a conversation about how they are planning to address the changes in PIPEDA. Finally, and most importantly, you need to prepare communications for all staff. You need to tread a fine line between making a big deal about these changes - which will have the affect of generating push-back, questions and concerns simply because you have presented it as a big deal - and making sure that employees are notified in a timely manner about changes that affect them without doing so in a way that minimizes their legitimate concerns. This should be done as routine and regular communication, preferably including a timeline and a FAQ that applies to your particular employee population.

The change to consent is just one of a significant number of changes to PIPEDA. I would be remiss in my duties in this column if I didn’t point out that the proposed changes include mandatory breach notification requirements, including to the Commissioner and to the person whose data was breached. A more fulsome discussion of this will be forthcoming in a future column but in the meantime, I will point CPA members to last year’s July/August issue and check out the ABC’s of Breach Notification contained therein.

At the end of the day, protecting employee privacy is one of the best ways that an employer can demonstrate respect for employees, which in turn will have positive impacts on employee engagement. Good privacy is good business.

Suggested Call Out or Box:

More information on the proposed PIPEDA changes

As I write this in early June, one of the best sources for information on the proposed changes to PIPEDA is David Fraser, a Halifax lawyer, whose Canadian Privacy Law Blog is a must read for privacy professionals. He has posted a ‘red-line’ version of the proposed changes on his blog at http://blog.privacylawyer.ca/2010/05/markup-of-bill-c-28-and-bill-c-29.html. In addition, you can find his overview of all the changes here: http://www.slaw.ca/2010/05/26/overview-of-proposed-pipeda-amendments/. For the Industry Canada press release you can check out http://www.ic.gc.ca/eic/site/ic1.nsf/eng/05596.html("http://www.ic.gc.ca/eic/site/ic1.nsf/eng/05596.html").

Accessing Employee eMails

September/October 2010

Read column

Email Privacy

How much of the day to day operations of your payroll depends on email? If you’re like most of us the answer varies from most to almost all. What happens when a questions arises, the answer to which depends on an email sitting in the email box of a person no longer with the company? What are the privacy rights of the employee whose email you need access to, and how do balance those rights against your legitimate business needs? How many of you are thinking, “No problem. We have a policy that says the company email system is company property, and employees have no expectation of privacy.”? If you do, I’d like to direct your attention to PIPEDA Case Summary #2009-019 (http://www.priv.gc.ca/cf-dc/2009/2009_019_0529_e.cfm("http://www.priv.gc.ca/cf-dc/2009/2009_019_0529_e.cfm")), particularly the following (emphasis added): emails are also the employees’ personal information protected by the Act.

In this particular case, the complaint by the employee was not to be ‘not well-founded’. In making the deliberation, factors that the the Assistant Commissioner considered included the company’s email policy and that the complainant’s email was investigated in the course of an investigation. Specifically, the company only accessed the employee’s email after an external investigation regarding a ‘leak’ of confidential corporate information provided reasonable grounds for the investigator to suspect a particular employee. Despite ruling against the employee in this particular case, the case summary states that accessing and using employee emails would normally require the knowledge and consent of the individual employee. In other words, if your company’s policy does not set out reasonable thresholds that must be met before an employee’s email is monitored, the policy may not provide a defence in the event of a complaint. This is the case even if you are in a jurisdiction where the requirement for employee consent is limited. In 2006, the BC Information and Privacy Commissioner (Order P06-05) found similarly to the Federal Commissioner. In that case emails were accessed in the course of an investigation and those emails contained ‘collateral’ personal information intertwined with other information, including work product. Once again, the fact of an investigation provided reasonable cause to retrieve and examine emails - which suggests that such a retrieval and examination outside the context of an investigation might be problematic.

So where does this leave us with the case of the departed employee’s email? We are left with the 6 P’s - Prior Planning Prevents Poor Privacy Protection. If we assume that employee emails are work product, but that it is entangled with personal information, then we must minimize the risk of a privacy breach and/or complaint when dealing with employee email. The elements that will mitigate agains risk of a successful complaint AND pushback from privacy sensitive employees are the same:

1. Decide what you want to do. You have a number of options. You could give the ex-employee’s managers a copy of the employees email file. This has the advantage of convenience, allowing the manager to access the file as circumstances warrant. The offsetting risk is that it essentially removes any privacy that the employee may have had. Not the preferred option. At the other end of the scale, you can delete the employees email on termination, and make sure managers are aware of this policy so that they can build practices to compensate. Probably not very reasonable. The middle ground would be to keep a secure copy of the employees email for a reasonable time (depending on your business needs and other regulatory requirements), and allow the manager access on request when a need for particular correspondence comes up - and document those instances.

2. Revisit (or write) your policy that refers to employee email. It should state that while the organization reserves the right to examine email, it will only do so when there is a legitimate business reason to do so. The exact wording and intent of this may well vary depending on the type of organization to which you belong, and the technology that you have. Certain kinds of data loss prevention or security monitoring tools will regularly inspect the contents of emails - often for spam detection and/or virus protection. Your policy should be written with some knowledge of what your technology is currently doing.

3. Update your onboarding process to let new employees know what your retention and post departure access policy is for employee emails. Ideally, they would sign a form consenting to use of their email files after departure as part of onboarding.

4. Update your employee refresher training - and your manager training - so that everyone knows what happens to their email on departure.

5. Update your termination process. In the case where employees are aware of termination (resignations with notice, retirements, etc) sending our reminders to clean personal information out of their emails would be helpful. In addition, prepare a consent form for employee signature to enable use of their email after departure. As a contingency, also prepare a notice form in the even that the departing employee is not willing to give consent. The notice will reiterate your policy providing the business justifications for limited access.

At the end of the day, most former employees will recognize that their email files are business records. However, in the case of disputes or conflict, making sure you have your policies and procedures aligned is the appropriate due diligence.

Privacy & Year-end

November/December 2010

Read column

Privacy and Year End

As I write this, the leaves have barely begun to turn colour, but already thoughts of year end are dancing in my head. In my case, as a consultant, that mainly has to do with the end of the tax year and all of the attendant work that goes with that. For payroll professionals however, year end and the holiday season is one of, if not the, busiest time of the year. Since this column is for the November/December issue of Dialogue it’s the appropriate place to talk about privacy in the context of year-end. Why is year-end such a nightmare for payroll? In my experience it boils down to two issues. The first is updating your software or systems for any changes that come into affect on January 1st. The second is the requirement to send out tax forms - T4s and Releve 1’s primarily. Your experience may be different, but I’m certain it’s not fun. Let’s look at each of these issues separately.

Whether you are running software in-house, or whether you are using a hosted or outsourced solution, that software will be updated sometime in December so that your first payrolls of the new year will have the correct formulae for calculating statutory remittances. You might not normally consider this update to have any privacy issues. But if you look at from a change management, or system change perspective you might reconsider. Organizations operating at a high level of capability maturity for privacy can be expected to have a Privacy Impact Assessment (PIA)policy that sets out the parameters that trigger a PIA. Such policies normally state that any new system or process that deals with personal information OR any significant change to a process or system that deals with personal information should be a candidate for a PIA. Altering the basic algorithms for calculating statutory remittances - especially in years where the changes are more than just changing the basic calculation percentages - could certainly be regarded as an important change. While this should not rise to the level requiring a PIA in most cases, just because it happens on a yearly basis doesn’t mean that some form of review shouldn’t happen. The questions you need to ask are whether the testing of the software upgrades by the developers included a review of privacy and security considerations. This means running regression tests to ensure that privacy and security provisions are still intact. This, in turn, means that the security and privacy provisions that are in the code should be documented in a way to ensure that they continue to be tested and validated every time the code is updated. Otherwise you are taking privacy and security protection on faith - and that doesn’t qualify as due diligence. Making sure that someone owns the responsibility for privacy and security quality assurance (QA) falls under Principle 1 - Accountability, and any failure to deliver robust privacy and security protection in a software update would be a failure of technical safeguards under Principle 7 - Safeguards.

Let’s all agree that tax forms are a nightmare. Whether it is determining how many to order, or tracking them, or even storing them while you wait for them to processed - none of it is particularly rewarding. But it has to be done. There are two privacy risks that come to mind here. All of a sudden you have volume of printed forms that you have at no other time. Where do you store them and do you need extra help in dealing with the volume? Remembering that the contents of the forms are deeply sensitive information you need to be mindful that wherever you store the printed forms has to be a secure area with access limited to people that are authorized to see the contents of the forms. If you end up in a position where you have spread out to other spaces to store, or address, the completed forms you run the risk of violating Principle 7 in terms of the physical safeguards you provide. If you need extra space, make sure to ensure that you are the only one that has access to that space for that time period. In addition, if you need to use extra staff - or temporary staff, you need to ensure that the training they receive includes privacy and that they sign appropriate confidentiality agreements. If not, you may be in violation or Principle 7 in relation to organizational safeguards.

The more likely privacy problem with tax forms is that you are required to send out forms to people that you are no longer in regular contact with - either through termination or retirement. What assurances do you have that you have the correct addresses for these people? Because if you send the forms to the wrong address that would qualify as a privacy breach. Obviously you can’t eliminate the possibility and if fact your want to record this so that you have good metrics. After all, people that are terminated for cause are not likely to be motivated to keep you up to date on their addresses. With retirees, and depending on how your organization handles retirement, you may still be in contact with them regularly.

What is your due diligence requirement? If you have a high turnover rate, or if you have had a major layoff or other workforce correction that involved significant numbers of terminations, it may be that you should take some extra steps to validate addresses for former employees. That could be as simple a matter of sending an email to their last known personal email address asking for change of address. Perhaps you should consider putting some text on the outside of the envelope you are using to send out the T4 or releve. How many T4s and releve’s did you have to re-issue or resend last year? If that number seems excessive to you, you should consider looking at your year-end processes to head off these potential privacy issues before they occur.

The Cost of Privacy

January/February 2011

Read column

The Cost of Privacy

Whether you are directly responsible for the protection of employee privacy, or whether you are responsible for payroll and are therefore tasked with ensuring payroll privacy requirements are met, you will find yourself from time to time in discussions with other parts of the business that may want to have access to data that you are the custodian of.

What kind of conversations are they? They may be risk based, especially if your organization has a coherent risk management policy. The conversation may be focussed on compliance, especially if your organization is in a regulated environment. Both of these conversations (and they are not mutually exclusive) focus on avoiding negative impacts on the organization. This approach necessarily means that the minimum necessary resource investment to avoid pain is the investment that will be made. There is a third approach to payroll privacy - an employee relations and organizational effectiveness approach. Using this approach, the organization will seek to understand the positive impact that protection of privacy will have on its employees and what that will mean for organizational commitment. This approach is the least used but, I would argue, is the most effective approach.

Integral to the evaluation of privacy risk, or the cost of compliance, is an evaluation of the impact to the organization of a failure to meet objectives. As a matter of rational business practice, the amount of resources devoted to ensuring that privacy is protected will not exceed the cost of failing to do so. This is the cost of privacy for risk management or compliance purposes. A number of decisions in 2010 made by Commissioners and Courts last year have qualified this potential cost significantly.

If an employee, whose privacy complaint to the federal Privacy Commissioner has been determined to have been ‘well-founded’, wants monetary damages they must seek redress in the Federal Court. Decisions in two such cases were made last year. In one case (Randall v. Nubodys Fitness Centres) the employer paid half of a monthly fee at a fitness club for an employee. The employee complained that their privacy had been breached with the fitness club shared attendance records with the employer and the employer talked about this information in a meeting. Both the Privacy Commissioner and the Court agreed that this was a privacy violation (no consent had been obtained for the sharing of the information. In the other case (Stevens v. SNF Maritime Metal Inc.) the owner of a scrap metal operation terminated an employee upon learning from one of their customers that the employee had opened an account with their customer in his own capacity to sell scrap as well. The employee complained that by divulging his account information to his employer his privacy had been violated. Again, both the Commissioner’s Office and the Court agreed that there was a breach.

In both of the above cases, no award was given to the former employee. In the first case the court determined that violation of privacy was not serious enough to warrant an damages. The judgement stated that, pursuant to PIPEDA, an award of damages should only be made in the most egregious circumstances - which was not the case. In the second case, the Court argued that the source of the complaint was the loss of employment after being terminated for cause. Here the court stated that, “The PIPEDA right of action is not an end run on existing rights to damages.” The net affect of these decisions, in the words of Michael Geist, a law professor and blogger on these kinds of issues, is to set a ‘high bar’ for the awarding of damages for privacy.

Lest those responsible for payroll privacy in a risk based environment relax too much, there were a couple of decisions from the Alberta Commissioner last year, one directly related to payroll information, that pointed out risks of real and significant harm that the employer was required to take responsibility for. In these cases, the issue at hand was whether the organization were required to notify individuals that their privacy had been breached. The breach notification requirement in the Alberta privacy law is a result of changes last year, and these decisions are the first opportunity to see how this requirement is going to be applied in practice. The requirement to notify individuals is triggered if there is a ‘significant harm arising from the breach’.

In one case (OIPC P2010-ND-001) an organization in the United States found a small number of underwriting files and other documents containing personal information outdoors near their headquarters. Since some of the individuals whose information was in the files were Albertans, the Commissioner had jurisdiction. In the other case (OIPC P2010-ND-002), an employer’s storage facility was disposed of without knowledge of the employer resulting in payroll records being found in a dumpster. In both cases, the Commissioner found the missing information to be information that, “…could be used to cause significant harm to individuals…” and, “… and provides comprehensive individual profiles that could be used for identity theft and/or fraud.” As a result both organizations were required to notify individuals of the breach.

What do the above decisions mean for the cost of privacy in payroll? The Alberta decisions confirms both that payroll information is financially significant and that the best practice is that individuals should be notified when their payroll privacy is breached, particularly when the breach is an unauthorized disclosure. The Federal Court decisions leaves the question of whether the breaches in Alberta, which were serious enough because of the risk of significant harm, rise to the level of ‘egregious’ and would therefore qualify for monetary damages. To hedge this risk, payroll professionals should ensure that they have mature security practices and a robust privacy program.

How seriously do you take privacy?

March/April 2011

Read column

How seriously do you take privacy?

On Wednesday, January 12th 2011, just a few days after the tragic shootings in Tucson Arizona, a number of news outlets reported the firing of three employees and one contracted nurse from the University Medical Centre (UMC) where the surviving victims were being treated. "The hospital has terminated three clinical support staff members this week for inappropriately accessing confidential electronic medical records, in accordance with UMC's zero-tolerance policy on patient privacy violations," was quoted as the statement issued by UMC officials. Since most surveys of Canadians indicate that there are two types of data about themselves that are critical and must be protected. These are medical data and financial data. Are there similar types of privacy violations in the payroll world? Should your organization terminate for cause for deliberate privacy violations like these? Can your organization terminate for cause for deliberate privacy violations? Would your organization take the same immediate actions if there was a similar breach in payroll privacy? Let’s go these questions one at a time.

1. Are there similar types of privacy violations in the payroll world?

It seems to me that this is readily answered in the affirmative. We don’t even have go to criminal activities, such as taking payroll data to sell to identity thieves. It could be as simple a matter as a payroll administrator looking up a manager’s or coworker’s pay or benefits as a favour for a friend or associate to help them out. This is a deliberate accessing of personal information for a purpose other than the one for which that information was collected.

Bonus points to readers who can identify which privacy principles have been violated!

2. Should your organization terminate for cause for deliberate privacy violations like these?

Most privacy policies will include a phrase which looks something like this, “Violations of this policy may lead to discipline, up to and including termination.” That’s all well and good, but if you are responsible for a policy that says that, you need to be clear in your mind what kind of violation would lead to termination. Will a single egregious violation be enough or does it require a pattern of behaviour? Does the violation have to be deliberate? Do the number of records involved matter? Does it matter if the person whose information is the subject of the violation knows about the violation? At the end of the day my view is that a single egregious and deliberate violation of one person’s privacy should be sufficient to trigger an immediate termination for cause. Despite training and awareness, despite most peoples’ desire to the right thing, despite all the ‘carrots’ we may choose to use to create a culture of privacy, it seems unlikely that your organization’s commitment to the protection of personal information will be taken seriously by a regulator or auditor unless you have the ‘stick’ of termination available to you.

You should consider asking the questions above to yourself and senior management to see where your organization stands.

3. Can your organization terminate for cause for deliberate privacy violations?

Even if you think you should terminate for cause, can you do so? Do you have a policy in place that makes clear that this is the case? Are you in a unionized environment and what does the collective agreement have to say about this, if anything? A useful parallel might be to think of a privacy policy violation in the same way that you think of a violation of workplace health and safety rules. The union has an obligation to defend their membership, but if someone is ignoring those rules, they may be a danger to everyone, including the union members. Examining these questions will tell you if you have the capability to terminate for cause for privacy violations.

You should validate the prescriptions in your privacy and HR policies to make sure that they match your policy wishes, expressed in your responses to the questions above. If you identify any significant gaps then you have a project in front of you.

4. Would your organization take the same immediate actions if there was a similar breach in payroll privacy? Can you walk your talk?

So you have determined that your organization’s policy is to take privacy violations seriously. You’ve also determined that your policies and procedures are written to give you the discretion to terminate. At this point in reading this column, if you are a sensible person, you are fervently hoping that this is a policy that you’ll never have to try and implement. But it’s better to be clear going in. If you’re not willing to enforce your policies, you should seriously consider modifying the policy. Play this scenario out. Your organization has an IT person, maybe a database administrator, who understands ALL your systems, even the ones where the company that created the software went out of business 10 years ago. You find that this person has been casually using live data for testing new systems, and that most of the company could access the data if they wanted to. This person has demonstrated a casual disregard for your security and privacy policies. But she or he would be very difficult to replace. If it was anyone else, you would initiate termination. Would you for this person? Unless and until you have a clear answer to that question, you won’t be sure that you’re ready to face a serious privacy incident.

Expectations of Privacy

May/June 2011

Read column

Expectations of Privacy

Context is king in determining whether an employee has an expectation of privacy on a laptop supplied by his employer.

Employers are normally advised to write and implement policies to ensure that employees are aware that their computers, their files, and their emails are subject to inspection by the employer. This is a well understood matter of due diligence to protect the sensitive or valuable information that those employees may have access to, including non-employee personal information that may be collected, used, or disclosed by the employer. Protecting this personally identifiable information is normally the purpose of organizational privacy programs.

Employers may also spend a lot of time and resources to ensure that safeguards are implemented to protect the privacy of their own employees. For some employers this is a regulatory issue because employee data is protected in their jurisdiction, or a collective agreement issue because of clauses invoking privacy or individual respect in existing contracts. For many employers, and hopefully to readers of this column, protecting employee privacy is a best practice that is representative of an organizational commitment to value employees. It can be difficult to determine how to balance the requirement to monitor employees’ electronic activities for security and respecting employee privacy.

A recent decision by the Ontario Court of Appeal has shed some light and raised some questions about what the expectation of privacy might mean. You might find the answer surprising. The facts of the case are these. In the normal course of his duties, a computer technician at an Ontario school board found sexually explicit pictures of a young woman on a teacher’s laptop. Suspecting the pictures to be of a student, the technician copied the pictures to a disc and showed the face of the young woman to the principal. The principal confirmed that she was a student, and confiscated the laptop from the teacher the next day. The police where called in, and given the laptop, which belonged to the school board, along with school board appropriate use and other policies. The school board policies allowed teachers to take laptops home, and for them to make ‘reasonable’ personal use of these computers. In addition school board policies warned employees that they had no expectation of privacy in their emails. A police officer took possession of the laptop without obtaining a warrant, assuming that was OK because it was the board’s computer.

At trial the defense argued that the defendant had an expectation of privacy in respect of his laptop. The Court of Appeal of Ontario ( R. v. Cole, 2011 ONCA 218), looked at the case to determine whether the teacher had, in fact, a reasonable expectation of privacy. The court determined that he did. That being said, the technician was acting in the execution of his duties when he found the pictures on the laptop. Thus the teacher had no basis for an expectation of privacy in respect of technicians working on the school board laptop. Similarly the principal acted appropriately in the best interests of the students, and in accordance with his duties under the Education Act, in ordering the laptop confiscated. Because of this, the disc of pictures that the technician discovered is allowable as evidence. The police however, should not have seized the laptop without a warrant - which could easily have been obtained. As a result the other files that they obtained from the laptop are excluded from evidence. The matter has been referred back to the court for trial as of the writing of this column - with the disc of pictures in evidence, but without the laptop’s other files.

The Cole case is a Charter of Rights case, particularly around search and seizure, but is nonetheless interesting for HR and Payroll departments. What can employers do to avoid a similar collision of expectations and rights?

  • If an employer expects an employee to take their laptop home with them, and allows them ‘reasonable’ personal use of that laptop, then it could be inferred that the employee has privacy rights over that laptop and their information stored therein - even if there are contrary policies in place.
  • An employer’s policy with respect to ‘acceptable use’ and to their right of audit and inspection of employee laptops needs to be very carefully crafted to establish the rights that the employer wants established - and to recognize and establish the boundaries within which employees may expect some reasonable privacy protection.
  • Employers should look at their operations to minimize the number of employees that have laptops and are expected to take them home. If 80% of an organization’s laptops stay at the office most of the time, there is a good argument to be made to convert the employees in question to desktop computers. This will also have cost and security advantages because such computers are less expensive and are easier to ‘lock down’ from a security perspective. Creating a small pool of utility laptops that employees can ‘check out’ for off-site or at-home work may be a way to avoid a sense of personal ‘ownership’ in a laptop.
  • It seems likely that the same logic applied above to a laptop would also apply to company supplied portable phones or other mobile devices. Once an employee has exclusive use of the machine, and it leaves the office with them, some privacy protections are likely to accrue to the device. Organizations need to look to the devices that go in and out of the office with this decision in mind.

At the end of the day, the employer has to make a reasonable attempt at balancing possibly opposing rights. When employees have exclusive use of a laptop, it’s entirely likely that they will use them for online banking, personal and possibly intimate email, and other normal activities that should be protected from as many eyes as possible - including those of the employer. While most, this author included, will argue that employees have a responsibility not to do use their laptops for anything that would leave embarrassing or compromising information on their machines, some will do so anyway and a prudent payroll privacy person will have thought about this in advance. If employers expect employees to take work home with them, it seems that its not unreasonable for the employee to bring some home to work with them, and when they do that they bring with it some of the normal privacy expectations we all share in our quotidian existence.

What's the harm?

July/August 2011

Read column

What’s the harm

Determining whether or not to notify customers or employees that there has been an incident that breached their privacy is becoming simpler.

The battle lines have long since been drawn with respect to notification:

  • Privacy advocates would have every data processor notify affected individuals, and relevant regulatory bodies, every time every single item of personally identifiable information is unaccounted for.
  • Data processors would eliminate all data breach notification requirements and only compensate those who complain and can prove that real financial harm occurred and is the processor’s fault.

While these statements pretty clearly represent the extreme views on breach notification, and most organizations fall somewhere in the middle, there are bases for both sides of the arguments. Privacy advocacy, it seems to me, is based on the view that privacy is a right (c.f. Article 8 of the European Convention on Human Rights) and that this imposes an obligation on the part of the data processor (a payroll processor, for our purposes today) to divulge completely to the data subject any time that privacy rights are infringed. The contrary view is that privacy breaches are harmless in and of themselves, and that it individuals must demonstrate monetary harm to receive monetary compensation. To do otherwise would be an unreasonable restriction on the conduct of business, and businesses have a right to conduct their affairs without undue state interference. So the question for a payroll practitioner becomes, what is the reasonable middle between these two extremes that is consistent with Canadian regulation, HR/payroll best practices, and the expectations of management and staff. It would be nice if there was some competent authority to provide guidance.

Luckily enough, there is. In Alberta, a 2010 amendment to that province’s Personal Information Protection Act (PIPA) added a new requirement for organizations to notify the Information and Privacy Commissioner of incidents “involving the loss of or unauthorized access to or disclosure of personal information where a reasonable person would consider that there exists a real risk of significant harm to an individual.” PIPA was also amended to give the Commissioner the power to require organizations to notify individuals to whom there is a real risk of significant harm as a result of such an incident.

Since that amendment has come into force, there have been a small stream of breach notification decisions from Commissioner Work’s office that are providing guidance on what qualifies as a disclosure with a real risk of significant harm to an individual. In May of 2010, one of these decisions was specifically about payroll.

The events as described in the decision are these. The company in questions uses an external payroll provider to process its payroll. The company’s accounting staff noticed that an unauthorized special pay period had been added to their system (as well as 3 new employees). There had also been an unsuccessful attempt to move money into the accounts of the 3 new employees. The external payroll provider confirmed that the company’s system had been accessed using authentication information from the company’s accounting administrator. The payroll data included the normal payroll, financial, and demographic information that one would expect in such a system. Finally, and this is key to understanding the decision, neither the company nor its payroll provider, “…could provide an audit trail of exactly what information was viewed or perhaps copied during the time period of the unauthorized access to the payroll system.”

Did the systems’ safeguards work? Well, the accounting person who was reviewing the accounts and noticed the discrepancy would qualify as an administrative safeguard. It enabled discovery of the incident. Similarly, the technical measures at payroll provider were able to prevent an unauthorized transfer of funds. With respect to the financial security of the system, there was no harm. However, because the system was unable to identify what personally identifiable information may have been viewed or copied, there was a fundamental failure of privacy controls.

Simply viewing personally identifiable information on a screen, especially when that viewing is a result of unauthorized system access is privacy breach. When the data being viewed, even if the information can only be written down, can be used for the purposes of identity theft then, the Commissioner has decided, there is a real risk of significant harm. It’s worth quoting the decision on this point:

“I have decided that there is a real risk of significant harm to individuals as a result of this incident. I have based my decision on the fact that the type of information involved could be used to commit identity theft which is a significant harm. There is no audit trail to confirm what information was accessed and given the sensitivity of the information, there remains the possibility information in the payroll system was viewed or copied.”

It may be of some importance to readers of this column to know that the report named the company whose payroll was breached, but not the name of the payroll provider. This points the arrow of accountability in one direction, and reinforces the rubrique that, “Accountability can’t be outsourced.” Having myself worked for a payroll processing company I feel comfortable in saying that most such providers provide high quality privacy and security controls - and in many cases controls that are unaffordable for smaller enterprises. Nonetheless it is important to remember who is accountable at the end of the day.

The lesson here that must be made clear to all technical people supporting payroll systems, and to some payroll professionals, is that the simple viewing of payroll data is a potentially serious privacy violation. In other words, assertions that data was not altered or copied are insufficient to provide privacy assurances.Access to these systems, and their data, whether on screen or on paper, MUST be limited to the minimum number of people actually required for payroll to function, and no more than that.

Are you ready to meet your regulator?

September/October 2011

Read column

Are you ready to meet your regulator?

Does you privacy management plan meet expectations?

You’ve just been notified by your IT department that an external hacker has had access to your HR database for the last 10 days. She or he had not been able to change any data, but has been able to read everything. In other words you have a security incident that includes a probable privacy breach. Does your organization have an incident management plan? Does it include provisions for privacy breaches? If not, it should. The time to create a breach management plan is NOT while in the middle of dealing with a breach. Let’s start with a couple of assumptions:

1. There will be breaches - It’s not a question of “IF”, but rather a question of “How Frequently” and “How much information”.

Corollary - If you think you aren’t having privacy breaches, then you don’t have a good program, you have a flawed reporting system.

2. The urge to deny what we don’t want to hear is incredibly strong - This is especially true when it comes to issues where your organization has failed to live up to its commitments - like privacy breaches.

Corollary - Without appropriate planning and preparation, your first significant privacy breach will be mishandled.

What is a privacy breach?

For the purposes of this article, I’ll borrow the definition from Industry Canada, which has defined a breach, in its proposed Breach Notification Model, as ”…an incident involving loss, unauthorized access to, or disclosure of, personal information as a result of a breach of an organization's security safeguards…” In this definition ‘unauthorized’ means that the loss, access or disclosure was contrary to the safeguarding requirement, and thereby captures all types of incidents including accidental events, such as inadvertent actions of employees, as well as fraudulent or malicious activities, such as criminal activity, and covers breaches of personal information stored electronically as well as written or oral records. Most commissioners’ sites have good information on how to respond to breaches. But what happens when you have to face the privacy commissioner or some other regulator yourself? Does your breach management plan include how to deal with the regulator?

What is a privacy complaint?

A privacy complaint occurs when someone contacts a privacy commissioner and makes a claim that they believe that their privacy rights have been violated. What happens then? What can an organization do? It is best to start with the understanding the following 4 points:

  • Assume that there WILL be complaints
  • Regulators must listen to all complaints
  • You must be prepared to respond to all complaints
  • The time to prepare for complaints is BEFORE you get the first one

Your organization may be entirely in the right, and the complainant could be completely mistaken, but this will only be revealed in the investigative process. In other words, you can not dismiss any complaint without demonstrating the merit of your organization’s position. This requires submitting to an investigation by the regulator. For an example, the following diagram captures the process for the Information and Privacy Commissioner of Ontario("scrivcmt://002DA183-5E03-44C3-902F-748D825345A9"):

Let’s walk through this step by step. A complaint is formally initiated when it is sent to the “Registrar” at the Commissioner’s Office. This triggers the Intake Stage and the Screening process. At intake an analyst attempts to resolve the complaint informally, dismiss the complaint, or prepare the complaint file for the Investigation Stage. Based on the work of the analyst, at Screening the Registrar reviews the complaint and decides whether to stream it to resolution, investigation or dismissal.

More often than not the Office of the Commissioner is able to dismiss, close, or settle a complaint without a formal investigation. A complaint is dismissed when it it it determined that the complaint is not within the jurisdiction of the Office or when, in the Registrar’s view, it does not merit further action. A privacy complaint will be closed at the conclusion of the Intake Resolution stream if the Registrar or the Intake Analyst is satisfied with the outcome. A privacy complaint is settled where the issues have been resolved to the satisfaction of the parties involved.

If a more formal investigation is required, it proceeds to the Investigation Stage, where an Investigator investigates the circumstances of the privacy complaint and attempts to effect a settlement of some or all of the issues. Again, at this stage the complaint may be settled or resolved. If that is the case, the file is closed by a letter to the parties involved and no report will be prepared. Finally, if not settled or resolved, a public report is issued. The report may include: a summary of the complaint; a discussion of the investigation; conclusions; findings; and recommendations. Depending on which particular act and regulation are involved, the report may take the form of an order. Commissioners’ orders, have the force of administrative law and must be complied with.

The point of this quick tour through the complaint procedure is to point out that it does not have to a painful exercise. In most cases the Office of the Commissioner will be working with both parties to find a way to close or settle the case without requiring a formal report. You will have multiple opportunities to avoid the consequences of a public report or order by working with the Commissioner’s office. That is not to say that egregious violations won’t lead to orders, but even then risks can be mitigated by cooperation.

Protecting Yourself First

November/December 2011

Read column

Protect Yourself First

I’ve been writing these columns for a while, talking about issues affecting how you, as a payroll professional, can protect the privacy of the employees whose personal information that you have access to. That’s all well and good, and I’ll return to that kind of thing in the new year. But as the year winds down, and many of you start spending more time on line looking for gifts and paying for gifts, I thought it might be a good idea to talk about how you can protect your own information privacy.

We have all heard the horror stories about identity theft, or breaches of medical information. We’ve been trained to be scared. But think about it. People regularly go to restaurants and hand their credit cards over to under paid serving staff who may be students with enormous debts hanging over their heads. And yet our credit cards are mostly protected. So while this column is about protecting your privacy on-line, as the Hitchhiker’s Guide to the Galaxy says, “Don’t panic”. You have options and choices. Let’s take an example. When you find a web site or receive an email suggesting that you can get something for free, you may want to exercise some caution. That’s because, with the exception of some open source software, free likely means one of three things:

1. You are not the customer, you are the product. Normal broadcast television is the classic example of this, and websites like Facebook and Google follow the same model. In these cases the customers are the advertisers that pay the television station or the web site. The difference is that with television the product was the opportunity to broadcast to that audience. With companies like Facebook and Google, the advertisers get to know exactly what you’re interested in, and perhaps what you have done.

There is no such thing as free, and your personal information has commercial value

{\Scrv_ps=Privacy Rule 1: Don’t post anything or search for anything that you wouldn’t be comfortable sharing with your friends and colleagues. Think of this as your public persona, not your private one.

\end_Scrv_ps}

2. The service offering is legitimate, and trying to offer you a ‘taste’ of the product. This is done in the hope that you will buy the non-free offering. In some cases, the ‘free’ offering is accompanied by ads, in which case it is like the situation above. In other cases, the premium version of the ‘freemium’ services pays for the free version, and you may feel comfortable using the services. For example, Dropbox offers 2 GB of cloud storage for free, but there are subscription models that offer 50 or 100 GBs, so you are the customer, not some advertiser.

If it looks too good to be true, it probably is.

{\Scrv_ps=Privacy Rule 2: The terms of the free portion of a “Freemium” service need to make clear how the service pays for itself. If it doesn’t, free won’t be.

\end_Scrv_ps}

3. You are the potential victim of an Internet fraud, or are being enticed to a web site that will infect your computer with malware. Depending on how your computer is set up, you run the risk of becoming infected with malware just be visiting a site. Sometimes you need to actively click on an email attachment or a portion of a web site to become infected.

Trust people, not technology. And even then, only people you already know and are expecting email from.

{\Scrv_ps=Privacy Rule 3: Don’t click on links or attachments unless you were expecting them.

\end_Scrv_ps}

You will have noticed that I haven’t talked about technology. That’s because the right attitude precedes any technology choices. There are anti-virus products. There are ‘Internet Security’ products. You can sign up for a service to use encrypted email, and you can sign up to a number of services so that you can web surf anonymously. I suspect that if you are technically inclined you are already doing so. However, if you don’t have the right attitude to protecting your own privacy, then all the technology available won’t prevent you from making a mistake. Your privacy starts with you. That being said I’ll end with these technology recommendations:

1) Select and buy an Internet security package for your computer, based on reviews from reputable web sites. Most of these packages require annual subscriptions. Pay them.

2) Make sure that both your computer’s operating system and your browser software are kept up to date. If you don’t know how to do this, ask your family tech support person. Many families have a person with some tech skills who supports others in the family.

3) DO NOT use the same password on every site. There are password managers that can help you to come up with, track, and use secure passwords. KeePass is an open source option in this area.

4) If you use USB keys, encrypt them. Better yet, encrypt your computer’s hard drive. TrueCrypt is the leading open source option here.

At the end of the day there is no such thing as perfect privacy or security. Only you can determine the balance between sharing information, open web surfing, and protecting your privacy is appropriate for you. It would be a pity, however, to find out after the fact that the opportunity to protect your privacy is already past.

An information life cycle approach

January/February 2012

Read column

An information life-cycle approach

It’s not always about you

Sometimes its worthwhile to step back and take a look at what you are doing. When there are risks involved, as is the case with the collection, use, disclosure, retention, and disposal of personally identifiable information, then it is especially true that you want to examine what you are doing and why. Just because you were minimizing risks with your approach last year doesn’t mean that events haven’t overtaken you. The new year is a good time to start thinking about this. After year-end and the yearly tax deadlines are past might be a good time to map out where you are going with your information policies and procedures.

Information life cycle management (ILM) is a comprehensive approach to managing the flow of an information system’s data and associated metadata from start to finish. This approach is not just about hardware, or storage procedures, but tries to capture, and sometimes automate, the process of moving information through an organizations information systems. Information, or data, management is becoming increasingly important as compliance related issues proliferate. Privacy is just one such issue. If your organization doesn’t have an ILM project, it may well start one in the near future. What does that mean for payroll/hr professionals?

In the balance of the columns for this year I’ll try and take a look at various parts of the life cycle of payroll/hr data from an privacy perspective. For these purposes I’ll be using a simplified life cycle that involves the information coming into the organization (collection), what is done with the information while is at the organization (use), how that information is shared outside the organization (disclosure), and finally how that information is disposed of.

In order to get ready for managing the information through it’s life cycle you will need to ensure that you have the policies and procedures in place to implement what you need. The following provides a list of some of the more essential tools that you will need.

Policies

Employee Privacy Policy - This policy should state clearly what data is collected from employees and for what purposes. This ensures that ‘collection’ and ‘use’ are documented properly. From an ILM perspective, the policy should also provide guidance on when data may be disclosed and to whom as well as setting out the general rules for retention.

Data Security Policy - The security policy is the complement to the privacy policy. It will, or should, set out the requirements for ensuring that data disposal is documented, and how retention limits may be implemented.

Data Retention Schedules - Each organization will have to establish what requirements for data retention apply to it. At a minimum this should define what data is required to be kept to meet CRA requirements. There may be additional industry or professional standards. From a privacy point of view, the actual length of retention is the minimum time necessary to exhaust all reasonable business uses and applicable regulatory requirements for retention.

Third party requirements Policy - There should be a policy, or at least boilerplate language that sets out the limits that organizations to whom data is disclosed must adhere to. This does not apply to government agencies that obtain data under statutory authority.

Data Disposal Policy - At the end of the retention period for personally identifiable information it must be disposed of. This policy will provide guidance to ensure that all copies of data are identified and disposed of in a timely manner.

Case Studies or Questions sought

In the course of the upcoming year I will devote one column to each of the following topics:

Collection - what information can you gather, and why?

Use - what can you do with the information you have, and why?

Disclosure - with whom can you share information, and why?

Disposal - how can you safely dispose of information?

Metrics - what kind of information do you want to use to measure your successes?

I want to include practical advise that relates to how you do your business. To that end I’d like to ask you ask me questions about privacy and information life cycle, or to send me examples of when you did one aspect of the life cycle particularly well. I’m also interested in hearing about the challenges that you have faced. With your input I think we can make some interesting and relevant case studies to help all of us improve the way we meet our privacy requirements.

Collection

March/April 2012

Read column

Collection initiates the life-cycle

Do you really need to know that?

Sometimes consultants get paid to tell an organization what they should already know. This is sometimes the case in the privacy world as well. For instance, the Personal Information Protection and Electronic Documents Act (PIPEDA) says that an organization may collect, use or disclose personal information only for purposes that a reasonable person would consider are appropriate in the circumstances. Of course this mythical reasonable person does not exist, and we are left with trying to figure this out as we go, guided by findings, investigations, and educational output from Commissioners’ offices. What your organization should already know is that collecting unnecessary personal information increases risks and should be avoided. By collecting the minimum necessary information you are minimizing the risk associated with that information through it’s life-cycle in your organization.

Readers who will have read the last issue of this column will know that this year’s columns are dedicated to following personal information through it’s life cycle at an organization and to determining what each stage of that life cycle means for payroll professionals. Library and Archives Canada defines 7 steps("http://www.collectionscanada.gc.ca/007/002/007002-2012-e.html") in the Records and Information Life Cycle. PIPEDA, on the other hand, mentions the collection, use, and disclosure of personal information. In our discussions later in this series we will also include retention and disposal of information as types of use. For our purposes in this column, the privacy information life cycle starts with collection.

By collection we mean any means by which personally identifiable information comes under your organization’s custody and control. When you ask an employee to complete their on-boarding forms, you are collecting that information. When you do a search on a social network about an employee (not a recommended practice outside of an investigation already under way for justified purposes, by the way), you are collecting personal information. When a payroll person records that a person was sick for a day, or had a doctor’s appointment, adding that information to the employee’s file is a collection of information.

Once you’ve got the information you are responsible for it. If you’ve received it under contract from the entity that actually collected it from the individual, you may not be accountable (you can’t outsource accountability) but you are responsible. Having custody and control of personal information increases risk. Risks from a privacy breach, whether or not it is a violation of privacy legislation include loss of reputation, loss of customers, and remediation costs. Managing this risk means determining, for each data point that you collect, whether you:

◆ Eliminate the risk by not collecting that information

⁃ Not an option for information required for statutory remittances

⁃ Not an option for the information required to initiate, maintain or terminate the employment relationship.

◆ Remediate the risk by collecting the information but implementing controls to reduce the possibility of a privacy breach. Examples might by

⁃ Move the payroll printer to a closed area

⁃ Hand out pay statements in sealed envelopes instead of stacks of printout

⁃ Train your payroll staff in privacy

⁃ Outsource the payroll if you want to reduce exposure from internal staff

⁃ Bring your payroll in house if you want more direct control

◆ Accept the risk, collect the information and make no changes. If you have an experienced payroll department this might be tempting. Nonetheless, you should consider getting a third party validation of your payroll departments privacy capabilities (Think about getting a Privacy Impact Assessment). At the very least this will enable you to provide assurances to your stakeholders.

◆ Transfer the risk. This is usually done by insurance, and has only limited applicability to privacy and payroll.

By far the best risk strategy you can adopt is to minimize the amount of information that you collect about your employees. Sensitive information you don’t have is, by definition, not a risk you incur. For the remainder of the information there is a simple risk management formulation to determine risk. At its most basic it is the realization that the amount of risk is the product of the likelihood of the breach occurring in a given time period multiplied by the impact of the breach occurring.

Example: Assume that the impact of losing an employee’s pay statement is $100 in rework and lost time. Further assume that an organization loses one pay statement in a thousand. If that organization runs a monthly payroll for 250 people, then we can expect to lose 3 pay statements in an average year. This means that the annual loss expectancy is $300. This is very likely a risk that an organization could accept. Unfortunately, in the real world it is hard to assign impact so precisely. One way to make an assessment is to assign low, medium, or high risks on a number of scales. In the table below, I’ve identified five data elements and have assigned arbitrary numbers for low(1), medium(5), and high(9) risk to assign arbitrary impact risk numbers to each element and rank them accordingly. Changeability indicates how often/easily a data element can be changed. Identifiability indicates the utility of a data element for identity theft or data linkage. Finally, sensitivity reflects what people reveal through surveys and the like.

Data|Changeability|Identifiability|Sensitivity|Impact|

Date of Birth|9|9|5|405|

SIN|9|5|9|405|

Address|5|9|5|225|

Bank Account|5|1|9|45|

Hours Worked|1|1|1|1|

High Impact Numbers indicate data elements that should not be collected or, if they must be collected, must be protected at the highest level reasonably possible. By doing this exercise with the payroll data you collect, and by applying your judgement to determine what values make sense in your context, you will have the basis for determining if you are applying the right types of controls to the information you collect. Who knows, it might even persuade you that you might be able to reduce the amount of personal information that you collect.

Use

May/June 2012

Read column

Using employee information without abusing employee trust

Protecting employee privacy is good management.

An information life-cycle approach to privacy protection marks the collection, use, disclosure, and disposal of personally identifiable information as the key separate stages in the life-cycle. Payroll practitioners spend the greatest amount of time, by far, in the middle stage - data use. You are used to the extraordinary detailed scrutiny that you get from <some> employees in relation to payroll calculations, gross-to-net, remittances, and so on. The question of today’s column is whether you could sustain the same level of scrutiny in relation to ensuring the privacy and confidentiality of that information. That information doesn’t show up on the pay statement, but if you get it wrong it, some employees will be as offended as if you missed entering their overtime!

If you read the last column - on data collection and risk management - I hope that you have plans to reduce the data in your payroll/HR database to the minimum necessary to accomplish the purposes for which you have collected the information. Now the question becomes what uses are appropriate, and what uses are inappropriate, in the context of managing privacy risk.

There is no problem with someone in payroll and HR having access to standard payroll information like time and attendance, benefits amounts, accruals and the like. After all someone has to make sure the the payroll is produced and delivered on time! If you are part of a large HR/payroll team it may be that you only have access to some of these categories of information, or you may be limited to having access to only some departments. Either way it indicates that your group has thought about ensuring that only the minimum number of people needed to produce payroll have been given access to the data they need for that purpose. Unfortunately, not all organizations apply this kind of business rule.

Think about an organization that uses an ERP system (Baan, Momentum, MS Dynamics, and SAP are some examples that leap to mind) and for convenience allows everyone on the system to have access to employee information. The thinking here would be that this information is tantamount to an employee directory and/or we trust everyone who has access to the ERP software, so why take the time and trouble to restrict access. This thinking would be wrong. Let’s talk about two specific ways in which this approach is problematic - legislative and personal risk. The legislative is self-evident - in jurisdictions where privacy law applies to employee data, general access like this will almost certainly be a violation of the privacy laws. As a side note, this kind of treatment of employee data might also be a violation of a collective agreement in a unionized environment. That leaves the question of personal risk.

What is the harm in making an employee’s home address available to a manager who wants to send them a get well gift when they are sick? This is one of the most frequently asked questions I get when I present or teach payroll privacy. In most cases sharing this information would be harmless. It is certainly allowable in all cases where you have employee consent for publishing or sharing their home address. That being said, it is an HR/payroll person’s responsibility to understand the minority of situations where a person wants their home address to be kept confidential. Unlisted phone numbers are a good parallel. People request them for a variety of reasons - including protecting themselves from physical threats from ex-spouses. Your policies need to account for the possibility of these kinds of situations, and you need processes in place to give affect to these policies.

A note about retention. So long as you are retaining your HR/payroll data you are using it. To minimize the risk of inappropriate use, and to minimize system costs, as well as to comply with legislation and best practices you need to dispose of employee information as soon as all reasonably foreseeable business needs for that information have been fulfilled. For example, you need to keep certain information for CRA purposes (6 years after year end). Once that time period has elapsed do you still have a business requirement for some or all of that information? Similarly can you articulate a business requirement for keeping a twelve year old record of a disciplinary hearing for an employee that has been a model employee for the last ten years? Remember that keeping information for the minimum time is not necessarily the same as a short time. If you have a business need that you can articulate you can keep some information about employees - such as their home contact information - for the duration of their lifetime, assuming you are paying them a pension. But eventually you will need to dispose of all of this information. Building and implementing a retention schedule will put you on the right path.

Making sure that your ‘uses’ of employee data are limited and specific will go a long way to minimizing the risks of a privacy breach and to maintaining employee trust. In the next edition of this column I will address the ‘disclosure’ portion of the payroll information life-cycle.

Disclosure

July/August 2012

Read column

What did you say you were doing with that data?

Can you match use to purpose?

In the life cycle of personal information, an organization spends by far the most time and effort on ‘use’ (see last month’s column), and corresponding efforts implementing security measures and protecting privacy. And if you have taken due care in minimizing your ‘collection’ of personally identifiable information you might be thinking to yourself that you are in a pretty good position. But you also have to consider “disclosure” of information to close the loop on the three main elements of personal information’s privacy life cycle.

For our purposes, disclosure occurs when personally identifiable information that was in your custody and control moves out of your custody and control. This does not include ‘third party processing’ of your own data. For example, the use of a payroll service bureau does not qualify as a ‘disclosure’ but transferring information about employees to the CRA does. The rule of thumb that I use to distinguish between use and disclosure is whether the third party is doing something that the organization could easily do in-house and/or is in fulfilment of the purposes for which the organization collected the information.

Employee data will be disclosed. Disclosure increases your risk. How do you manage that risk? There are a number of steps that you can take to minimize the risk that you disclose to a party with information practices below your standard and ensure a minimal impact on employee morale and organizational commitment should a breach occur.

Third parties collecting information are often dedicated purpose organizations, and it may be the case (especially if you are part of a small organization) that one of the reasons that they can be trusted is that they have dedicated information security and privacy teams. You minimize your risks of privacy breaches generally when you take advantage of another organization’s strength’s to compensate for your organizations weaknesses. It should go without saying that you should disclose the minimum amount of information that you have to. To close the loop on minimizing the risk related to third party disclosures, you should have a clear contract or agreement specifying their privacy and security obligations.

To minimize the impact on employees your organization should be open about disclosures. Your employees should never be surprised to find that their information is in the custody and control of another organization. Long time readers, or those well trained in privacy, will remember that one of the privacy principles is “Openness”. By taking reasonable steps to ensure that your employees. A person who is surprised to find out that their information has been shared may choose to blame and/or complain about the organization that shared it. So before you disclose their information, disclose to your employees that this will be happening.

The diagram below represents what research tells about how people feel about their privacy. The great majority of people are ‘privacy pragmatists’. They accept that privacy may be reduced in return for certain services and/or benefits, and they expect that organizations will exercise reasonable due diligence. Then there are are people who are not sensitive to the privacy of their information, whom I call the privacy free. Finally there are the ‘privacy fundamentalists’. They will not share their information unless required to do so, and have very high expectations of what is required for ‘due diligence’. It is important to remember that these broad categories describe personality types. In other words, you cannot persuade people to change their views on what is reasonable to share and what is not reasonable to share. This reinforces the need for openness in most circumstances, because it is much easier to deal with objections before the information is disclosed than afterwards.

PrivacyTypes-eps("scrivlnk://4F9D7E5F-AC33-473D-9B0A-76CAADAD5ABB")

With respect to disclosures to government, you do have to do your due diligence. When a representative from a government agency has asked for a disclosure of information if is reasonable for you to ask for the authority being used for the request. For example, if you receive a phone call asking for information about an employee, you might require that the request come in writing, and that the specific authority for the request should be included. It may be the case that the government agency has the authority to ask, but not require, a disclosure. In that case it becomes a discretionary issue for your organization. This is why privacy policies will often have the phrase, “unless authorized or required by law”. When you are presented with a court order or a subpoena, you have no choice, but other requests do not have the same force. What is your commitment to your employees and their privacy? Is the request a normal or routine one? Should it be normal or routine? And finally, if you accede to the request will it either lead to more requests? If your organization’s privacy policy doesn’t give you guidance on these issues, perhaps it’s time to update your privacy policy.

At the end of the day we live in an information economy and you will be disclosing information about your employees. You will have done your privacy due diligence if you are able to identify every disclosure and identify how it conforms to the rules that you have set up on your privacy policy. That way, when the breach comes (as you have to assume it will) no one will be surprised to find their information in the hands of the third party and your employees’ trust in your respect for their privacy will be undiminished.

Disposal

September/October 2012

Read column

Know when to hold ‘em, know when to fold ‘em

When and how to dispose of information.

The information life-cycle ends when you dispose of the data that you no longer have a business use for, and for which there is no legal requirement for retention. This is easily said, and like most things that are easy to say it can prove difficult to execute in practice. Proper disposal means creating retention schedules, processes and procedures for data deletion and data destruction, and ways to set specified data aside so that it does NOT get deleted when everything else does.

At its most simple a data retention schedule identifies types or categories of data and how long that data should be kept, typically after a particular time in the business calendar. This can be set out in table like the following:

Data|Trigger|Retention|Comment|

Payroll details|Calendar year|2 years|Keep weekly payroll details (hours worked, eg.) for two years after the calendar year end in case of grievance.|

Garnishee details|Calendar year|1 year|Delete garnishment details 1 year after garnishment is complete.|

Your mileage may vary, or course, and I discussed retention in the May/June column this year, so I won’t go into more detail here. What is important is that reaching the end of the retention period should trigger disposal procedures, and there are a number of questions you need to answer at that point:

  • Is the information stored electronically, physically or both?
  • Do you know where all the copies of the information are?
  • Is the information stored with other information that can’t be disposed of, or at least not yet?
  • Are there exceptions to your general disposal rule that need to be accounted for.

With the answers to those questions you can formulate your disposal procedures, bearing in mind that you need to retain a record of destruction, especially for discovery (more on that below).

Disposing of electronically stored information will require a conversation with your IT folks. If you are using an HRIS, or a payroll system, then it may be that when you delete information in the application it is still retained in the database for the application. You will need to confirm with your technical people that the data has actually been overwritten or deleted in a way that actually removes the possibility of recovery. You also need to talk to your technical people to confirm that the same process is applied to backups or off-site versions of the same data. What good is it disposing of the data in the database, when you still have three copies in backup tapes and off-site storage? Finally you need to be able to have a record that the disposal took place, so while you may dispose of the records you may need to keep some audit logs.

Disposing of physical data is more straightforward. You should use a data destruction service that will provide you with ‘certificates of destruction’ for the physical files that you are destroying. It is also possible to use similar service providers (often from the same vendor) to physically destroy hard drives, CDs, DVDs, and tapes of all kinds. From an audit perspective the use of a reputable third party for destruction creates an audit trail for positive assurances.

Now comes the tricky part. It may be that you need to exclude some data from disposal. Say, for example, you have an ex-employee that is suing for wrongful dismissal. In that case, the employee’s HR and payroll records are likely to be relevant to the court proceeding and can not be disposed of until the matter is complete. You need to be able to put a ‘hold’ on the disposal of all records that might be germane to the case. It may be that your software is able to flag certain records, or it may be that you need to make copies of either that employee’s data. It could be as simple as retaining a copy of the database backup. You need to ensure that your IT people understand what you need and that you verify that what they propose will work. It will not go well if a year down the road you are told that, “Well yes we have the backups, but we’ve updated the system and the new system can’t read the old backups”.

If the case goes to trial, there is a process called ‘discovery’ in which each side’s lawyers request documentation from the other side in order to prepare their cases. If presented with a discovery motion, for example, to produce all attendance and payroll details for the ex-employee, your organization will need to produce said documents. If the suit was brought after the retention period for the requested records has expired, and providing you have the retention schedule and some record of the disposal of the records, that’s fine. If, however, the retention period ends while the case is in progress you can not dispose of records that might be relevant.

You should consider setting the minimum retention period for all HR and payroll data to the time limits for litigation in your jurisdiction. For example, if a person can not bring a wrongful dismissal suit if two years have passed since their dismissal that provides a business case for retaining detailed records for two years. If you have other, reasonable, business reasons for retention beyond that period that’s fine, but you should know the cause of action limits for your data.

At the end of the day disposal must be as carefully thought through as collection at the start of the information life-cycle. You need to be able to provide assurances to your employees you that their data will only be retained while it’s useful and legally required and that it will be properly disposed of when no longer needed.

Metrics

November/December 2012

Read column

Measured Success

How do you know you’ve done well.

In the course of this year’s column’s I’ve discussed the privacy of employee personal data from an information life cycle perspective. The sixth and concluding column of this series will describe the metrics that you might us to measure your successes. But first I need to talk about metrics and measurement. In a book entitled “How to measure anything: Finding the value of intangibles in business” Douglas Hubbard states that:

1) Management cares about measurements inform uncertain decisions

2) For any decision or set of decisions, there are a large combination of things to measure and ways to measure them - but perfect certainty is rarely a realistic option

3) Therefore, management needs a method to analyze options for reducing uncertainty about decisions

So what are the uncertain decisions that management, or yourself, might need to make in respect of privacy? Do you know, or only have an opinion, about whether the self-service system you are contemplating increases or decreases your privacy risk because of the way it collects employee personal information? Do you know, or only have an opinion, about whether payroll data is being accessed and used by too many people or for purposes other than payroll? Do you know, or only have an opinion, about whether outdated payroll details reports have been destroyed properly and on time? These three questions each address a different portion of the information life cycle that I have been discussing in prior columns. You may well have policies about these issues and practices in place to implement them, but you will also need some metrics to determine if what you have done is working.

When people first start thinking about metrics, they start with the numbers that they have. For example, if you run a large national payroll across multiple sites, it may be the case that a certain number of pay statements get mis-delivered each pay period and then get returned to you. If, as might be the case, each pay statement is labelled with the employee’s name and home address. That qualifies the pay statement as personal information that should be protected and means that mis-delivered pay statements could be counted as a privacy breach. In such circumstances each month you could count the instances of mis-delivered pay statements and come up with a privacy metric related to information disclosure. But unless you are implementing a new process to reduce mis-deliveries does such a metric add value? I would suggest not. Using Hubbard’s list above this metric does not inform a management decision and it probably doesn’t reduce uncertainty all that much. It’s a useful metric to track, nonetheless, to manage the performance of your delivery systems, but is probably not a good measure of the effectiveness of your privacy program.

Another number that is easy to gather is the number of people that have received privacy training. Your organization might have on-boarding training, refresher training, and special training for individuals with special access to confidential data. That would be excellent. What would not be excellent would be to report on the number of attendees at the training, and to think that that is a measure of effectiveness. Instead of reporting the number that attended, conduct quizzes or surveys after the training to evaluate how much information is retained. “100% of staff attended a privacy seminar” is less meaningful than “87% of staff surveyed correctly identified 80% or more of the privacy questions correctly”. It’s not enough to have metrics, they should be good metrics.

In “Security Metrics: Replacing Fear, Uncertainty, and Doubt” Andrew Jaquith states that, “Good metrics facilitate discussion, insight, and analysis; bad metrics prompt furious arguments about methodology. Metrics should never require a rocket scientist, witch doctor, or polymath to explain; they should be transparent enough that their calculations are easy to understand.” If that is the case what are some good metrics for privacy in payroll?

Metric|Discussion|

Percentage of data fields collected with an identified purpose|By going through your software and identifying each data element that is collected from employees to ensure that there is a legal authority for the collection of that data element or that the data element is necessary for the processing of payroll, you ensure that you minimize the risk of ‘over-collecting’ information.

This is a static metric that only needs to be reviewed and updated periodically. |

Quarterly random privacy quiz of personnel.|The results of a standardized quiz will provide the ability to do trend-line analysis on the levels of privacy awareness, which may be used to improve the quality of privacy training delivered.

This is a metric that can be taken at regular intervals and may serve as a proxy for evaluating the likelihood that some employees may be using their access to information inappropriately.|

Random checks of stored payroll reports.|The result of such random tests, when supplemented with a review of certificates of destruction for information that has been disposed of, will provide insight into the effectiveness of your data retentions schedule.|

If you implement metrics that are self-explanatory in your organization, and provide you with information that enables you to make better decisions about protecting the privacy of your employees, you will be well on the road to eliminating uncertainty with respect to how well you are protecting your employees’ privacy. This is a good news story and, if you share it with your staff, can lead to improved morale and organizational commitment.

TMI about Employees

January/February 2013

Read column

Can you know too much about your employees?

What is ‘none of your business’ in the employee-employer relationship?

HR and IT professionals generally recommend that organizations make it very clear to their employees that they have no right to privacy when using company equipment. This is typically to enable scanning of email and computers for viruses and other security related issues. Recent decisions and investigations mean that this approach may need to be reconsidered as the courts and privacy commissioners tell us that Canadians don’t have to check all their privacy rights at the door to the workplace.

I was reminded of this a couple of times recently. The first was when the Supreme Court held that employees may have a reasonable expectation of privacy on employer supplied equipment like laptop computers. You can look up the May/June 2011 issue of Dialog the details of the original court decision. The second reminder was when the Privacy Commissioner of Canada was reported to be investigating a reportedly intrusive survey that border guards, or applicants to become border guards, were being asked to complete.("scrivcmt://ED376933-0004-4388-9CB4-79F6C0A4FE13") According to the coverage about the survey, “The questions touch on everything from substance abuse and sexual deviance to drinking and gambling habits and crimes individuals may have committed but were never charged for.”

In both of the cases above I was struck by the dichotomy between the view that the employer is entitled to collect and use employee personal information, including information unrelated to work performance or statutory deductions, and the view that an employee is entitled to protect their privacy in the workplace, even when using the employers information systems. These seem to be contradictory views, and I’m sure that there are extremists on both sides. Realistically, however, few employers expect their employees to be automatons disconnected from their lives outside work and just as few employees expect to be able to go to work and pay no attention to the needs of the organization. Somewhere between these extremes should lie a reasonable compromise. And by reasonable I mean what an average person on the street would think. In other words, asking our peers if they agree with what we are doing is NOT a test of reasonableness. We’ve all drunk the same Kool-aid, as it were.

Here’s another change that’s coming. Increasing numbers of employers are using social network research to investigate prospective employees and in some cases are asking prospective employees to share the contents of the private portions of the social networking sites that they participate in.("scrivcmt://CA3B0EB3-E365-41A9-AB7E-D8F7813869FD") A number of states in the U.S. Have already passed laws forbidding this practice, because it appears to many to be an egregious invasion of individual privacy. Given the extent of information that some people share on social networks it seems likely that these kinds of laws will be popular, and proactive payroll and HR professionals should be working to ensure that their practices and policies will not need to be radically updated should such a law be passed in their jurisdiction.

Finally I’d like to point out that, in Ontario, it is now possible to be sued in civil court for a breach of privacy.("scrivcmt://8EDD46AF-74B7-4610-836A-65A284BD1012") In other words, privacy compliance is no longer a ‘simple’ matter of putting policies and processes in place that align with legislation. Any one of your staff that can access personal information may be in a position to make an error and create a liability. It’s not likely, I hope, but it is possible.

It’s time for some payroll professionals to take a step back and take a look at the nature of the relationship between employee and employer. It is still the case that employers need to minimize and justify the personal information about employees that they collect, use, and disclose. It is now the case that employers need to take into account the employees’ opinions about whether those uses are reasonable in the context of the employment relationship. This means increased transparency about employee data management practices, and increased training of employees about the issues relating to employee data management. Finally, it means that whatever you do, there is always the possibility of a privacy complaint, requiring a complaint management process.

I’ll leave you with this thought. A colleague of mine has suggested that what is needed is the equivalent of a workplace or occupational safety regime, except for workplace privacy. As liability for managing employee data increases, and the costs for managing that risk also increases, it may soon be time to consider sectoral or broader ways to address this risk.

It's Midnight, do you know where your employees are?

March/April 2013

Read column

It’s Midnight, do you know where your employees are?

Location, location, location

In the last issue of this column I talked about having TMI (too much information) about your employees, and how that opens an employer up to new kinds of risk. This month’s column is an extension of that thought, but specifically focussed on your employees’ location, even after hours.

Vehicle Data Recorders

You may or may not be aware that if you have a late model vehicle, it is becoming increasingly likely that you have an event data recorder (EDR), or ‘black box’, that records much of what your vehicle is doing, in a way similar to the flight recorders used in airplanes. As of December 1st, U.S. Regulations require that IF a manufacturer installs an EDR in a car, then they must also provide a commercially available tool to extract data from the same. This is a boon for adding evidence to insurance claims, “…going forward, at least three out of every four vehicles sold in Canada will contain some form of black box that can be interrogated after a collision to provide useful information about what was happening in the moments leading up to the crash.” http://www.claimscanada.ca/issues/article.aspx?aid=1001963283 Some argue that these regulations have been put in place without sufficient consultation or without policies to prevent the misuse of this information. http://bigstory.ap.org/article/black-boxes-cars-raise-privacy-concerns("scrivcmt://E394F969-23B7-49E1-BB98-205589E73B89")

The case in B.C.

What about the case where employees use employer supplied vehicles, equipped with GPS tracking devices? Does an employer have the right to collect the information from the GPS tracker and engine monitoring system for the purposes of managing employees? In a recent case in B.C. Involving an elevator company (Schindler) and its field mechanics, the B.C. Information and Privacy Commissioner thought so:

Schindler collects information using a GPS and engine status data system installed in its service vehicles, which are assigned exclusively to its mechanics. Mechanics do not report to work at an office; they travel from their homes to job sites on assigned routes. The GPS component of the system records a vehicle’s location and movements, as well as the time and date of its locations. The engine status component records the vehicle engine’s start and stop times, as well as things like excessive speeding, braking and acceleration. Among other things, Schindler collects and uses this information for employment management purposes; the information is personal information and employee personal information. Schindler is in the circumstances, including the policies it follows as to how and when it collects and uses this information, authorized to collect and use it. Information and Privacy Commissioner of B.C. Order P12-01("scrivcmt://F1995553-55DE-4806-9DA8-0CE794684DCC")

There are a couple of interesting things about this decision that HR and payroll professionals should pay attention to. In jurisdictions where employee privacy is protected the definition of what is and is not employee personal information can be important in determining both the level of protection needed, and how that information may be used or disclosed by the employer. The order considered a number of issues that I will deal with here, including,

  • Is the information collected by the technologies Schindler uses ‘personal information’?
  • Does the BC legislation authorize the employer to collect and use that information?

Please refer to the order for a complete description of these and other issues.

In their response to the complaint the company argued that the information on the vehicle information system was not personal information in the sense defined by the Act in B.C. and was therefore not protected by the B.C. Act. It was not ‘information about an identifiable person’, according to this argument. In addition the company argued that the information was ‘work product’ and therefore also not covered by the B.C. Act. In her discussion of this issue the Commissioner stated that, “…the definition of personal information covers information that is ‘about’ the individual in a wider sense…” Order P12-01 s. 76 and refuted the narrow interpretation of the personal information that the employer had argued for. The Commissioner said instead that, “…‘personal information’ is information that is reasonably capable of identifying a particular individual, either alone or when combined with other available sources of information, and is collected, used or disclosed for a purpose related to the individual.” Order P12-01 s.85("scrivcmt://34D82695-FB97-4F6B-B300-1DE434A42167") In other words personal information isn’t only that information about a person in a private or intimate sense. Further, the Commissioner argues that this information is not ‘work product’ because it was not generated by the employees in the course of their work but rather was generated automatically by the system. Since the company explicitly uses the information obtained from the system, such as engine start and stop times or excessive braking and acceleration, to provide evidence of employee conformance to company policies related to driving and to confirm employee attendance at job sites, these data about the engine and location of the vehicle are also personal information relating to the individual, and the Commissioner so concludes.

In other arguments that I do not have space to include the Commissioner also found that the data is ‘employee personal information’ as per the B.C. Act. The employer collected this information to manage employee performance—to manage productivity, manage hours of work, and ensure they drive safely and lawfully. The Commissioner points out that, “These are legitimate, reasonable, business purposes. A business is entitled to ensure, subject to applicable laws and agreements, that its employees meet productivity standards. It is also a reasonable purpose for a business to collect personal information to ensure that its employees are actually working the hours for which they are paid. It is, at least reasonable for a business to be able to ensure that its employees are, in the course of their employment, driving company vehicles lawfully and with reasonable care.93 I therefore find that the information is collected for purposes reasonably required to manage an employment relationship.” Order P12-01 s.121("scrivcmt://CECCC0C1-B0C9-4BFC-A75C-79648D5D5265")

At the end of the day, despite disagreeing with the company’s argument that the data was either not personal information or that it was work product, the Commissioner found that the collection and use of this employee personal information was reasonable for it’s purposes. And it is this last from which payroll and HR professionals should draw an important lesson. In the words of the Hitchhikers Guide to the Galaxy, “DON’T PANIC”. Just because information is personal information, or employee personal information, doesn’t mean that you have to get bent out of shape. If you’ve done you’re homework, and you are using the information that you collect in ways that are reasonable in the employment context, you’re probably OK. You may not even need a towel.

When is a closed bin an open problem?

May/June 2013

Read column

When is a closed bin an open problem?

You are accountable, even when you’re not responsible

Most of us are familiar with the shredding bins that have become ubiquitous in cubicle farms across the country. Typically located near printers in the office, they provide us all with the opportunity so shovel ill conceived print outs from printer tray to oblivion at record speed. Most of us assume that that is the end of the story, and usually we would be right. Recently, however, the Office of the Information and Privacy Commissioner of Saskatchewan (OIPC/S) reported on an investigation where a document destruction company failed to meet expectations.

The short version of the story is that an employee of the destruction facility did not secure the top of a bin when moving it between two buildings and some documents escaped into the wild. They were discovered by passers by, who called in the media. The Regina Police Service become involved and when it became clear that the records fell into their jurisdiction, the OIPC/S took responsibility. Here are the points, relevant to today’s column:

  • The data on the documents was highly sensitive personally identifiable information
  • The data processor (the entity who had contracted the data destruction company) was within its rights to outsource data destruction to a service provider
  • The data processor had a contract with the service provider, which included security and privacy provisions of which the Commissioner paid particular attention to the following:

⁃ Employees sign a confidentiality agreement

⁃ The service provider will train its employees

⁃ The service provider will provide an audit of its compliance with the contract on reasonable notice

⁃ The service provider will have policies, procedures and safeguards in place

  • The agreement that employees of the service provider signed includes a reference that the employee agrees to, “Keeps cargo compartments on trucks locked at all times when transporting confidential documents.”

Right about now, if you use a service provider, you may be nodding your head and going, “Check, we’ve got that, and that, and that. It likes they covered the right bases.” Were that true, of course, you wouldn’t be reading this so you may be wondering what the problem is. Good question. It’s an especially good question when you consider that the report does not name the service provider but does name the data processor and further, finds that it failed to provide sufficient protection for this data.

The final piece of the puzzle is that the investigation report indicates that, shortly after the incident occurred, the risk management and privacy officer of the data processor visiting the service provider and noted some deficiencies in the practices of the service provider. Despite this, and despite the recommendation of the Privacy Commissioner, the data processor informed the Commissioner that they would not be conducting audits on a regular and ongoing basis. As the Commissioner notes, “There is little comfort to be had if the contracts provides for proper safeguards such as audits but are not put into practice. How can [the data processor] be sure that the document destruction company is fulfilling its duties listed in the contract without audits? In my view, it cannot be sure.”

At the end of the day, the Commissioner found that the data processor did not have sufficient safeguards in place to reasonably protect against a similar incident from occurring again. He recommended improvements in written procedures for dealing with the types of information lost in the incident AND that the data processor actually conduct the audits that were allowed in their contract with the document destruction company.

Lessons for HR and Payroll Professionals

“You can’t manage what you don’t document and measure”

It’s not enough to have a contract. It’s not enough to have policies in place. Unless and until the hard, and detailed, work of creating and managing processes to implement the provisions of the contract and the policies you have signed and created. This means working with line staff to create workflows that identify each step in the process. This may involve special cabinets, internal audits, and including measures of compliance in managers’ performance management. To people that respond that, “This isn’t part of my job” explain that for knowledge workers, proper procedures for secure document and information management are ALWAYS part of their job.

“Trust but Verify”

Just because you did the due diligence to ensure that you engaged an industry leading outsourcer to do some work for you, doesn’t mean that they will deliver. It’s up to you to make sure that you understand the outsourced process well enough to look at the way that it performs and to be able to evaluate it’s performance. That means establishing service metrics and reporting, for sure, but even more importantly it requires auditing. Someone needs to verify, in a trusted and reliable way, that what is said to be done is what is actually done.

“You can’t outsource accountability”

It’s ironically the case that an organization should not outsource a function it does not understand. The organization is accountable for what is done in its name or on its behalf. Handing the job over to an expert is often a good way to ensure that the job is done well, but you need to know enough to judge for yourself that the job was done well. If your organization is doing something ineffectively or insecurely and you outsource that, you run a real risk of paying someone a lot of money to do the same thing you are doing - ineffectively and insecurely.

Reference: Office of the Information and Privacy Commissioner of Saskatchewan, Investigation Report H-2013-002

Union Dues or Due to the Union

July/August 2013

Read column

Column text not recovered from the source archive.

The Weakest Link

September/October 2013

Read column

The weakest link

Technology can’t prevent inattention.

Say you’re driving down the road in a pricey neighbourhood to look at the Halloween decorations. You notice that all the houses have 6 foot chain link fences around the properties, including the gates of their entrances. Then you drive by a house that has an iron gate mounted in a stone arch. The rest of the lot is surrounded by a three foot tall picket fence. Which estate has the better security: the one with a 6’ chain link around everything, or the one with an impressive gate and a low fence? Despite the big spend on a fancy gate, the properties that have set a higher minimum security have better security. Protecting the privacy of your employees involves the same kind balanced approach. If you focus all your resources on a big technology spend, and expend minimal efforts elsewhere, you are more likely to have a fancy gate that alerts the bad guys that you have something to protect, and lets them jump the picket fence to get at it.

Privacy Principle #7 in the CSA model code is “Safeguards”, by which we usually mean “Security”. The principle outlines three kinds of safeguards: organizational, physical, and technical. Technical safeguards are things like passwords and anti-virus software. Physical safeguards are thinks like locked doors and fire alarm systems. Organizational safeguards can be the picket fences of security. What good is a fancy encryption system if someone can talk their way past a security guard and get a copy of your latest secret design from people in the graphics department? What good is an anti-virus when an employee clicks on an attachment containing malware because they believe that the email was meant for them? These are examples of social engineering and spear phishing respectively.

In the most recent IBM Cyber Security Index includes a description of an attack that combined social engineering with spear phishing. The circumstances were that the attackers wanted to gain access to a large financial institution by attacking a smaller institution that had a trusted connection to the larger institution. The report describes the incident in some detail:

Hackers took advantage of social networking and known PDF exploits in order to plant malware on the targeted user’s machine. This was accomplished by conducting a social engineering campaign against the specific target. Over time, the attacker was able to learn the victim’s position within the company, office location and work schedule. Eventually the attacker knew enough about the victim to create a spear phishing message that would not be viewed as suspicious. Once the victim opened the attached malicious PDF, the attacker gained access to the user’s workstation and the user’s network as well as the network of the company’s larger partner. Once a foothold was gained, covert communication channels were established for use in sneaking data out of the company’s networks.

At this point you should be asking yourself whether or not you have opened a PDF from someone you know at work in the last week? If you have then you are susceptible to this kind of attack.

There is some debate in the security community about whether the way to address this problem is by better training or by better technology. I don’t think it’s a binary choice - we can develop better technology AND we can strive to be more security conscious. That being said, as a payroll or HR person it’s unlikely that you’ll be the decision maker with respect to security technology.

Every person, and especially every manager, should know that they cannot depend on their technology for 100% risk avoidance. There is an arms race between attackers and security systems designers so no system can guarantee complete protection.

This means that payroll professionals, like other guardians of sensitive information, have to be aware of the policies and procedures that their security and technology have put in place. It’s the flip side of expecting that every employee will know and comply with basic HR policies. Both HR and IT/Security cross organizational boundaries. If necessary, ask for special training focussed on the applications and risks that are particular to payroll and HR. Since you handle their payroll and benefits too, it seems likely that IT and security will be motivated to help you once you make it clear that you want to be part of the solution.

Here are some questions you might like to ask and answer:

  • Is there a security training program for all employees with access to sensitive information?
  • Have all payroll and HR personnel taken security training?
  • Is there an HR/payroll training program for IT personnel with access to HR/payroll data?
  • Have all IT people taken the HR/payroll training program

At the end of the day front line staff at your enterprise look at both IT and payroll as something that should be 100% perfect and run completely in the background. Both payroll and IT staff are well aware that this is an unattainable goal. Both of you know that a moment of inattention by a person in a critical role can lead to disaster. Returning to the metaphor at the start of this article, if HR is responsible for the gate, and IT is responsible for the fence, you need to work together to make sure that both gate and fence provide comparable levels of security. Common policies, practices, and training will help to minimize the risks that you share.

Privacy by Design

November/December 2013

Read column

Payroll Privacy by Design

Building privacy in can free you to focus on your work.

Introduction

Sometimes I say that privacy is the first issue on everyone’s secondary to-do list. This is a recognition that, almost without exception, people know that privacy is important for themselves and for their stakeholders and if only they could get past their current work crises, or free up some time, why then they would be happy to address privacy issues. But in the meantime, they focus on fighting fires and meeting impossible deadlines. One way to deal with this contradiction is to build privacy into your IT systems and your business processes. When done correctly it means that privacy ceases to be something to ADD to your workload. Your work is inherently privacy protective.

Privacy by Design (privacybydesign.ca("http://privacybydesign.ca")) is encapsulated by seven foundational principles laid out below. For each principle, I’ve set out an example of how the principle might be applied in a payroll setting. Once you’ve read the principles, I invite you to think of your own examples.

Freedom of Expression

January/February 2014

Read column

Privacy and the right of freedom of expression

Rights don’t exist in a vacuum.

Readers of this column, and those that are generally familiar with privacy, will know that the heart of privacy rights come to this, “I have a right to some control over how information about me is collected, used, and disclosed.” This right is not, however, absolute. We know that, for example, in an employment context that an employees’ rights to privacy have to be balanced against the employers’ rights to manage their business and against the privacy rights of the customers whose information employees may have access to in the course of their employment.

A recent Supreme Court decision (Alberta (Information and Privacy Commissioner) v. United Food and Commercial Workers, Local 401, 2013 SCC 62) has shed more light on how this kind of rights balancing will and should be applied. In the course of a strike by the Union, both the union and the employer captured video and still images of individuals on and crossing the picket line. The Union placed signs around the site that images so captured might be placed on a Web site. This led to complaints by some of these individuals to the Alberta Privacy Commissioner, whose Adjudicator concluded that the Union’s collection, use, and disclosure of of the information was not authorized by the Alberta Personal Information Protection Act (PIPA).

The Union appealed this decision, and the Court of Appeal agreed and granted the Union a constitutional exemption from the application of PIPA. The Supreme Court agreed with the Appeal Court and declared the statute to be invalid, but allowed 12 months for the legislature to consider PIPA as a whole. The key elements of the decision are captured in the following paragraph:

“PIPA establishes a general rule that organizations cannot collect, use or disclose personal information without consent. None of PIPA’s exemptions permit the Union to collect, use and disclose personal information for the purpose of advancing its interests in a labour dispute. The central issue is whether PIPA achieves a constitutionally acceptable balance between the interests of individuals in controlling the collection, use and disclosure of their personal information and a union’s freedom of expression. To the extent that PIPA restricts collection for legitimate labour relations purposes, it is in breach of s. 2(b) of the Charter and cannot be justified under s. 1”

There are two elements here that are worth stressing. PIPA sets up a general rule that organizations cannot collect, use, or disclose personal information without consent, and then sets out the exceptions to this rule. Because the Union’s activities were not a specified exemption, the Adjudicator found the Union’s actions in violation of PIPA. It was this that the Appeals Court and the Supreme Court found two broad because, “ The reviewing judge and the Court of Appeal both recognized that the collection, use and disclosure of personal information by the Union in the context of picketing during a lawful strike is inherently expressive. We agree.”

Fair enough. Union activities on the picket line are ‘expressive’ and are therefore protected as freedom of expression under the Charter. But so too are individuals’ privacy rights. How did the Supreme Court determine that in this case the balance tilted to expression and not privacy? It’s not because the Court minimizes privacy. It said that, “ PIPA’s objective is increasingly significant in the modern context, where new technologies give organizations an almost unlimited capacity to collect personal information, analyze it, use it and communicate it to others for their own purposes. There is also no serious question that PIPA is rationally connected to this important objective.” The problem is that, according to this judgement, “…PIPA deems virtually all personal information to be protected regardless of context.” And that’s the problem.

The context here was that, “The personal information was collected by the Union at an open political demonstration where it was readily and publicly observable.  Those crossing the picketline would reasonably expect that their image could be caught and disseminated by others such as journalists, for example.  Moreover, the personal information collected, used and disclosed by the Union was limited to images of individuals crossing a picketline and did not include intimate biographical details.  No intimate details of the lifestyle or personal choices of the individuals were revealed.”

In essence, the Court was doing the same balancing that any organization does when it infringes on the privacy of its’ employees to claim the right to monitor their email, or collect some information about the employees without consent because there are statutory requirements for the collection of that information.

There is clearly no reason to panic, or to rush to change policies or procedures. PIPA remains in affect in Alberta. It’s quite likely that that staff at a number of Commissioners’ offices are reviewing the decision and preparing recommendations for their respective legislatures. If logic and reason are any guide (and they may not be in these circumstances), we can look forward to amendments to a number of privacy laws in 2014, particularly in relation to Unions, picket lines, and expression but also more generally in providing guidance on how privacy may be balanced against other rights in the workplace. In the meantime, payroll professionals and HR practitioners can continue to apply the laws and regulations still in effect.

Self Service

March/April 2014

Read column

Self Serve or Self Serving?

Deciding what risk to manage is critical in privacy evaluations of self service systems

Many, if not most, web based HR products will include self service modules that allow employees access to elements of their HR records including, in some cases, the ability to add, change of deleter parts of that record. What are the privacy implications and risks to organizations that enable self service modules? It might seem contradictory to say so, but there can be solid privacy related reasons to implement self service HR applications for employees. The reason that this is surprising is that, more often or not, organizations view privacy first through the lens of security and confidentiality.

Privacy savvy readers will recognize security and confidentiality as the purview of Privacy Principle 7 - Safeguards. Those responsible for privacy will know that they spend a lot of time working with security professionals to make sure that administrative, technical, and physical safeguards are in place to protect personally identifiable information. That being said, we should remind ourselves that the key elements of a definition of privacy is that an individual should be able to know and control what information elements about themselves are being collected, used and disclosed and for what purposes. What could fulfill that requirement more clearly than putting control directly into the hands of the person whose information it is?

Clearly safeguards need to be put in place to ensure that there is no unauthorized, or unauthenticated, access to personally identifiable information using a self serve portal. However, every enterprise is already selectively authenticating and authorizing access to sensitive resources. If those tools and techniques can not be applied to ensuring that employees only have access to their own information, and can only alter information that they have been authorized to change, then the enterprise security team may well have bigger problems to deal with.

Self service software, or modules, need to be evaluated against a stringent set of standards. This means Threat Risk Assessments (TRAs), Privacy Impact Assessments (PIAs), Vulnerability Assessments (VAs) and perhaps most important on a web facing system - Penetration Tests. TRAs and PIAs can be conducted at a conceptual level (assessing the proposed architecture and design), the logical level (assessing the data flows and network design & protocols), and at a physical level (assessing an installed system). But it is the case that this is normal and appropriate due diligence for ANY system that will process personally identifiable information.

So the question of whether or not to install or implement an employee self serve module should not be preemptively rejected on the basis of privacy risk. In fact, once security and confidentiality concerns have been addressed the ability of a self serve system to add openness to the operation of an HR system is a privacy plus.

Why does this seem counterintuitive? I would suggest that the reason that this seems off kilter is that HR professional are used to being ‘owners’ of the data about employees, and are therefore uncomfortable with relinquishing any element of control. It may also be the case that employees themselves will be uncomfortable because they may not feel competent or comfortable being responsible for whatever data elements the self serve system exposes. This will be somewhat alleviated by engaging employees in the evaluation of the self serve system and providing them sufficient information about the security elements of the system to enable them to believe that their security has been addressed.

A quick web survey of some of the major self service providers shows a focus on cost savings and increased efficiencies created by allowing staff and managers to directly enter and view information. These are sound financial reasons for proposing and implementing employee self service. I would suggest that there are also HR reason - particularly trust and engagement.

When employees know what information is being collected about them, including their financial information, their demographic information, and their time-keeping ‘notice’ automagically accomplished. This also empowers employees to audit for accuracy, which should add feelings of both control and trust. By feeling in control, and by being able to trust that their HR information is as up to date and accurate as they themselves can make it, employee levels of engagement and commitment are likely to increase. HR professionals will know that employers can not ‘make’ employees happy or more engaged. It’s like pushing a string. It doesn’t work that way. On the other hand, if employers provide employees better tools or other support to enable them to do their jobs better or more effectively, morale or commitment will increase. It will have been ‘pulled’ up. Properly implemented employee self service can be another tool to pull up engagement. It enables employees to know more about the information collected, used and disclosed about them. This helps to address a number for privacy principles like ‘identifying purposes’ and ‘openness’, in addition to ‘safeguards’.

When all is said and done, each employer will need to determine for themselves if the risks to security are outweighed by the business efficiencies and increased privacy controls that can be brought in by using employee self service. But this evaluation need to start from a recognition that passing control over the elements of personal information to employees can be a positive privacy design.

Education

May/June 2014

Read column

Learning Privacy

A primer for payroll professionals

Here is the short course on implementing privacy:

Collect the minimum information necessary to accomplish the purposes for which you collect personally identifiable information, use that information solely for the identified purposes, and dispose of the information as soon as its utility is dat an end.

Like many things that are easy to say, or to conceptualize at a high level, actually delivering on this high level promise is a matter of getting the details right. Think about the same high level statement for payroll:

Calculate gross pay from salary or wage information for time worked, and calculate gross to net based on deductions for hours not worked, benefits and statutory deductions. Pay the employee the remainder.

It is the case the if an employee looks at their pay statement, payroll seems a simple exercise. After all, they know their own rate of pay, their own benefits, and their own deductions. It seems simple - and for a single individual, it is. Trying to do the same calculation for an entire payroll - maybe not so much. The same applies to privacy. Protecting the privacy of any individual employee seems to them a simple matter of ensuring the confidentiality of some information and not sharing information with others. Trying to figure out those boundaries for all employees - not so simple.

That’s why we do privacy training. I teach a half day course, for CPA credit, on privacy for payroll professionals. It’s also the case that I have a number of certifications related to privacy. Since the focus of this issue of Dialogue is on education I thought I’d try and pass long the key learning objectives for a privacy course. I’ll end with a summary of privacy resources on the web for those that want to pursue some self study.

Short course on Privacy

Part 1. Identify the rules that apply to you

Employee personal data is not governed in all jurisdictions, so you should ask yourself the following questions

i. Am I under federal or provincial jurisdiction?

ii. Am I public sector, private sector, or in the health sector?

iii. Do I have a unionized workforce?

Armed with the answers to the above questions, you can determine if your employees have enforceable privacy rights. The high level version is that private sector federal, some private sector provincial, and most unionized employees have enforceable privacy rights under legislation or by contract.

Part 2. Decide if you’re focus is risk or compliance

Managing risk will require that you have sufficient understanding of the information in your organization to collect metrics to measure and manage the collection, use, and disclosure of personally identifiable information. Managing compliance works at a higher level and depends on a policy and procedure framework, with training and enforcement to demonstrate due diligence. This is simpler and cheaper, but not as effective.

Part 3. Write your policies and procedures

You will need a privacy policy, a security policy, an acceptable use policy and a breach management policy to start with. Each one should have matching procedures to ensure that employees and managers are aware of the obligations and responsibilities. You will need on boarding training, with annual refreshers, to demonstrate minimum levels of compliance. If you want to demonstrate “Privacy by Design” you will need to inject privacy considerations into your companies project management, development, and HR systems. If you want to inculcate a ‘culture of privacy’ you should build expectations for a 1 to 3 year transition.

Part 4. Implement your policies and procedures

Start with training and awareness. Start by measuring what you can (training sessions, breaches, response times to complaints). Build processes that generate meaningful metrics the enable business decisions to be made about privacy.

Part 5. Privacy Operations

Take a look at the plan-do-check-act (PDCA) model for continuous improvement. Above all, inculcate these mottos:

1. Good privacy protection today is better than perfect privacy in the future

2. Good privacy protection today is likely to be insufficient tomorrow

It’s critical that senior managers and staff understand that effective privacy protection is a process and a journey, not a project with a finite end.

Certifying organizations relevant to privacy("scrivcmt://62879495-5925-4559-B3AA-69FB694A8C21")

International Association of Privacy Professionals (https://www.privacyassociation.org/("https://www.privacyassociation.org/")) - The IAPP is the premier organization for corporate privacy professionals. It’s certifications are the Certified Information Privacy Professional (which includes CIPP/IT for technology and CIPP/C for Canada).

Privacy & Access Council of Canada (http://www.pacc-ccap.ca/("http://www.pacc-ccap.ca/")) - PACC is the premier organization for public sector privacy professionals. It’s certificates are Associate, Chartered, or Master Access and Privacy Professional (AAPP, CAPP, MAPP).

Information Systems and Audit Control Association (https://www.isaca.org/("https://www.isaca.org/")) - ISACA certifies individuals to audit or manage auditing of IT and Security. The best known certification is the Certified Information System Auditor (CISA). ISACA also provides governance frameworks such as COBIT (Control Objectives for IT).

If you want to dive even deeper, you can get a certificate in Information Access and Protection of Privacy from the University of Alberta (http://www.extension.ualberta.ca/study/government-studies/iapp/). Finally, if you have a desire to go to grad school in privacy you might consider looking at the Identity, Privacy and Security Institute at the University of Toronto (http://www.ipsi.utoronto.ca("http://www.ipsi.utoronto.ca")).

Education

September/October 2015

Read column

Title

Subtitle

In the world of risk management, which can include privacy, we often talk about ‘controls’. Privacy controls are measures that address privacy risks by reducing their likelihood or their impact.("scrivcmt://D5BB8420-F54E-43BF-9688-DA39CEB88449") In the world of privacy, which can include risk management, we often talk about ‘safeguards’. Safeguards and Controls in these contexts are synonyms. Safeguards are often categorized as administrative, physical or technical.

  • Administrative Safeguards are policies and procedures implemented by an organization to reduce privacy risk.
  • Physical Safeguards are steps taken by an organization to prevent unauthorized access to personal information.
  • Technical Safeguards are measures implemented in an organization’s information technology infrastructure to reduce privacy risk.

Controls, on the other hand, are often categorized as preventative or detective.

  • Preventative controls are measures taken by an organization to reduce the likelihood of a privacy risk before it can occur.
  • Detective controls are measures taken by an organization to reduce the impact of a privacy risk after it has occurred.

These categorizations lead to the following table, with some basic examples.

|Administrative|Physical|Technical|

Preventative| • Education| • Locked File Cabinets| • Data Loss Prevention (DLP) systems|

Detective| • Incident Management Procedures| • Surveillance| • Audit Log Monitoring|

Education is a preventative control that provides an administrative safeguard. This means that education is probably your best value investment in privacy risk management. That’s because it preventative - which means that it can reduce the likelihood of a privacy breach happening. Further, it is administrative which means that you provide it without invest in expensive physical modifications to your space, or by buying/leasing expensive software.

This doesn’t mean that you can avoid investing in physical locks, security software or preparing for breaches. After all, your defences are only as strong as your weakest point. But the sad truth is that in most organizations the weakest point is the individual user. It could be someone clicking on a link in an email, or surfing to an innocuous web site where they are served an ad containing malware or someone mailing payroll data to their home email to work on in the evening. The likelihood of any of these occurring can be reduced by an education and awareness program that produces a culture of privacy.

Would you rather see a pharmacist that discusses your medical issues at that counter where others can overhear or a pharmacist that first offers to take you to a quiet corner to discuss your issues? Both pharmacists are equally qualified to assist you, and both pharmacies give you the same medication. But one pharmacy ensures that its staff have been trained to respect patient privacy. How different is it in payroll and HR? The subjects of the conversations are different, but can be just as sensitive.

But who should get the training? According to one article, “… it appears that the emerging consensus amongst Canadian privacy regulators is that privacy training should be delivered to all employees of an organization.”("scrivcmt://047A83A8-98C3-405E-AB09-4ED50F6CA958") When I design or deliver privacy training as part of an overall organization program (as opposed to targeted training related to a single project) I start with the following assumptions:

1) Everyone in the organization should get basic privacy awareness training as part of their on-boarding, with regular (typically yearly) refreshers thereafter. This training will include:

⁃ General privacy awareness and background

⁃ What are the regulatory requirements for the organization

⁃ A review of the organization’s privacy and security policies

⁃ How to recognize a privacy issue

⁃ Who to report a privacy issue to

⁃ A reminder that privacy is everyone’s responsibility

2) People in the organization that have access to personal information as part of their job duties (IT personnel or HR/Payroll staff for example) should get a more advanced training course. Where information is particularly sensitive, this training should precede access to information. This training will extend the basic privacy training by discussing privacy risks in relation to the normal workflows in the various areas where the training is delivered.

3) Manager’s and executive whose responsibilities include areas that collect, use or disclose personally identifiable information should be provided with training or support materials to understand privacy risk management. These are the people who need to make business decisions about projects involving privacy risk. This training should encompass how to estimate or evaluate privacy risks and benefits. For example, executives should understand what a Privacy Impact Assessment is, and when it should be required as part of a project.

For an example of a short course on privacy, see this column in Dialogue’s May/June 2014 issue. If you provide privacy training for your staff, and bolster that with a general privacy awareness program (newsletters, posters, screen savers, etc) you may experience a bump in reported privacy issues. That is to be expected as personnel start paying more attention to privacy. Don’t panic. The uptick in reporting is just that, not an uptick in privacy issues. Those issues were always there. But now you will know about them and can start to priories and address them proactively, rather than after a breach. And that’s the real advantage of educating your staff about privacy - reduced risk.

Phishing

November/December 2015

Read column

Phishing your staff

Should you extend penetration testing to social engineering?

According to the RCMP, “Phishing is a general term for e-mails, text messages and websites fabricated and sent by criminals and designed to look like they come from well-known and trusted businesses, financial institutions and government agencies in an attempt to collect personal, financial and sensitive information.“ It is a variant of social engineering which generally refers to the deliberate manipulation of people to get them to divulge sensitive information. A phishing email will typically ask the recipient to click on a link - usually with unfortunate consequences. For more examples see the Canadian Anti-Fraud Centre("scrivcmt://E7AAF920-9B34-4538-B575-27E4A1616909"). These kinds of schemes can be responsible for major leaks of information, and if the person that falls prey to them is in HR or payroll, the bad guys may get access to your employees’ personal, health and financial information.

When the phishing email arrives in the inbox of a person at work, the link can result in allowing the hacker access to the user’s corporate computer and perhaps access to the corporate network - in some ways bypassing the perimeter controls of the corporate network. This is why almost every corporate security training and awareness program will include directives to employees to not click on links in their emails unless they know the source and are expecting an email with a clickable link.("scrivcmt://B5A5F401-0722-45C7-8884-1E0959BFF17F") So let’s assume that you’ve trained your users and that you have an awareness campaign about phishing (posters, screen savers and so on). How do you know it’s working? How strongly would your training hold if an employee received an email saying that their work email is in the Ashley Madison hacked database and that they should click on a link in the mail or face having their boss find out. It hardly matters whether the employee had been user of Ashley Madison or not. The temptation to click would be almost overwhelming.

One option to test the efficacy of your training is to go to a company that will try and phish your employees for you, rather than let the bad guys do your training for you. As one service describes their service, it is “…a full-spectrum advanced attach simulation solution that improves the security of your organization by changing user behavior and delivering actionable security metrics.” In the couple of services that I looked at for this column the service would send phishing emails to employees work emails and, if the employee fell for the scam, deliver on the spot training to employees. This service provides both metrics and training. Intuitively, it seems that this kind of service could provide useful information and, perhaps, reduce your exposure to malware. Finding out what percentage of your employees would click on a link or reveal confidential company information in response to a phishing email will give you an important metric. But does it infringe on your employees’ privacy?

Let us assume that you have done your homework and identified a reputable service. What steps should you take? I would propose the following:

  • Review your existing training and awareness program.

⁃ Make sure that you have provided training about the kind of phishing that the service company will deliver. Otherwise the test program could be viewed as unfair and generate resentment.

⁃ Make sure that any employee who could receive the phishing email will have received the training.

  • Provide clear scope and goals.

⁃ Work with the service provider to clearly identify the kind of test you are conducting so that you can measure its success.

⁃ Make sure that you only provide business contact information and that any personal information revealed must remain confidential with them and not be revealed back to your organization.

  • Don’t surprise people.

⁃ The purpose of the training and the testing is not to ‘trip up’ or embarrass people. The purpose is to train them and make them resistant to phishing. Letting the entire company know lets them know that this is serious and will provide an extra element of awareness even to those that don’t receive a phishing email.

  • Let your IT and service desk people know if there is going to be a spike in phishing

⁃ If your training has gone well, people will notify your security and operations people that they are receiving phishing mails. If the security group doesn’t know that a test is going on, they will go into incident management mode.

  • Provide an update to your employees - but only aggregate numbers.

⁃ Keeping them in the loop will build engagement and remind them that security is everyone’s business.

⁃ By reporting aggregate numbers and assuring them that individual results are only seen by the third party contractor you will be providing them with assurances that you respect their privacy.

HR and payroll professionals well understand the need to preserve confidentiality and protect privacy. Using this kind of service as a capstone for a privacy and security program can validate the effectiveness of your training, identify gaps in your security and provide assurances to all of your stakeholders that you are proactively addressing privacy and security. But using this kind of service as a form of ‘gotcha’ management is as likely to do more damage to employee morale and engagement.

Finance

January/February 2016

Read column

Finance, Payroll and Risk

It’s easy to blur the lines between confidentiality and privacy, but there can be a cost.

Accountants and the entire finance function are probably the most trusted personnel in an organization. Executives depend on finance for analysis and advice that can easily determine the fate of the enterprise. And in some organizations payroll, which can account for a significant amount of an organization’s expenses, is part of the finance organization, reporting to the Chief Financial Officer (CFO). It seems to me that the relationship between Finance and Payroll should be characterized by two main questions:

1. Is the payroll function running efficiently, delivering value for money?

2. Is the payroll function managing risk appropriately, including privacy risk?

The first of these is a question best dealt with by accountants and business analysts in consultation with the business leadership of payroll. But the second question - managing risk in payroll - relates directly to this column. Until recently, I suspect that the only risk consideration with respect to payroll had to do with fraud. Most payroll fraud schemes will generally fall under one of five categories; false wages fraud, commission fraud, workers’ compensation fraud, ghost employees or false expense claims. But the risk profile around privacy is evolving and the downside costs have, potentially, increased significantly in Canada over the last few years. This is because of the emerging tort of privacy which, when combined with increasing numbers of headlines about privacy, is putting some significant numbers into the equation. In a worst case scenario, a 100 person payroll could theoretically expose you to a more than $2,000,000 class action liability.("scrivcmt://BEC66AF0-905D-4434-8CD3-6DEABC79EE05") Fraud may no longer be the largest impact financial risk. It is likely to remain the case that fraud is more likely the liability in the courts, but because of the potentially large numbers, finance may start asking questions about privacy management to understand the organization’s exposure to risk. Does that mean also giving finance personnel more access to personally identifiable information?

Clearly, financial analysts and accountants need to have full access to all the information they deem necessary if there is a suspected case of fraud - including the personally identifiable information of any employees who are suspected of being involved in, or whose information may be used in, the perpetuation of the fraud. It is also the case that when auditors come calling, they have a reasonable basis for requesting access to at least some types personally identifiable information. Similarly, if finance is doing a risk assessment to determine the likelihood of a civil suit, and you don’t have results of privacy impact assessment("scrivcmt://C7F2D06E-F4AB-412C-ACDB-E70C329702CB") (PIA) or some other form of evidence, you will probably have to share your processes and maybe your data to the person(s) doing the risk assessment.

Notwithstanding reasonable claims of access by finance, the payroll department is still accountable for ensuring that employee data remains appropriately protected even after it has been shared with the finance department or disclosed to auditors. There are a number of tools available to help payroll professionals maintain their commitments to employees. These include disclosing the minimum necessary data set, applying administrative controls, and privacy training and role based controls for finance personal. Needless to say, these tools can be useful for similar purposes with other stakeholders with similar requirements for access to personal information.

It’s entirely likely that the first time you encounter someone who would like to get access to some data for which you are accountable, it will be presented as a ‘need’. Your job is to validate that ‘need’ to make sure firstly that it is not actually a ‘want’, and secondly, that their need aligns with with your accountabilities. This is the ‘need to know’ test. For access to personally identifiable information there are really only two acceptable justifications; consent or legislative authority.

If the person or organization requesting access has legislative authority it can come from a statutory authority, such as the Canadian Revenue Agency with respect to investigations related to taxes, or from a judicial order like a warrant. You have a due diligence requirement to validate the authority, and to keep some form of evidence that you have done so. This could be an email, or a copy of a warrant. You may also need to notify the person or persons whose data has been requested that you have disclosed their information pursuant to a legal request. The privacy protective default position is to notify the individual unless the authority that has requested the information also has the authority to request that you not notify the individual and that they exercise the authority.

With respect to employee personal information it is the case that consent is generally not required for information or purposes that are reasonably necessary for the purposes of creating, maintaining or terminating the employment relationship. In that case, where an audit for the purposes of insuring the financial integrity of the payroll system is being conducting, or some similar employment related purpose, it is reasonable to disclose the information to the auditors

But if the person that is requesting the data does not have legislative authority or is not fulfilling an employment related purpose, then you must have employee consent for the release of the information. In that case you need to ask whether the requestor, in the fulfillment of their duties, also meets one of the purposes for which consent was granted. This is the “need to know” standard that has to be met. The person may ‘need’ the information for their job duties, or for a project to which they’ve been assigned, but unless those duties or the project charter align with the purposes for which the employee has already granted consent then the requestor does NOT have a need to know the information about the employee or employees.

Once you have determined that you can release the information due to legislative authority, necessity for the employment relationship, or employee consent that does not end your accountabilities. For example, sending the information as a non-encrypted attachment in an email to an external requestor would, in most cases, be inappropriate and a potential privacy breach. Similarly, if you securely transfer the information to an external auditor and then they lose an unencrypted USB with all your employee’s data on it, you could still be held accountable.

Think about it this way. If you receive a phone call from some hauling company saying that they just scattered your banking records over a highway for anyone to read. They were on a contract from some records storage company, who in turn had been contracted by your bank. Who would you be mad at? More often than not people will hold their bank to account. In payroll you are in the same position. If payroll data is breached most employees will hold you to blame. Therefore, once you have determined that you have to, or may, disclose employee information consider the following:

  • Apply administrative controls. These include contractual clauses (or letters of intent or memoranda of understanding or statements of work) requiring recipients to acknowledge their receipt of personally identifiable information and their commitment to hold it confidential and to use it only for specified purposes. Further, they should be bound to apply the same conditions to any entity that they share the information with. The clauses should include a mandatory notification clause in the event of a breach and a requirement to return or destroy the data when the business use is complete. Prove of destruction in the form of a Certificate of Destruction would be appropriate.
  • Ensure that the recipient is qualified to handle personally identifiable information. This could include asking questions about their privacy training & whether they apply role based access, encryption or other controls to limit access to your data. The weaker their privacy program and controls are, the stronger your requested administrative controls should be. You can ask for the ability to audit their controls from time to time if the recipient is getting a data feed (like a benefits provider) instead of a one time request (CRA).

At the end of the day, remember that you have made a commitment either explicitly or implicitly to your employees and that they have had no choice but to trust you. Make sure you enforce your accountability with anyone who requests access to your employees’ data.

Technology

March/April 2016

Read column

Payroll & Privacy

By John Wunderlich

Mmm/Mmm, 2016

Career Planning

September/October 2016

Read column

Career planning is the process of matching your interests and abilities with the options available to you. Succession planning is the process for identifying and developing personnel to fill positions as they become available. The advantages of promoting from within include less risk of a culture mismatch, reduced on boarding time and cost and a likely increase in the organizational commitment of the promoted person. Disadvantages include disruptions and possible resentment from failed internal applicant and the possibility of promoting an effective employee into a position where they will be ineffective("scrivcmt://277AD121-51EB-417D-BC4A-5CEA7807203D"). With an external hire, organizations are willing to take the risk of a bad fit in return for the benefit of a potentially ideal candidate. But this issue of Dialog is about career planning so we will focus on the internal hire. What are the privacy issues related to career and succession planning that individuals seeking career advancement, and the privacy and HR professionals who make determinations about them, have to take into account?

At first blush, it might appear to be a simple matter from the point of view of the individual. A naive candidate might think that revealing everything that there is know about their work history, their education, their training and their aspirations is the most effective way to advance their career. But revealing or sharing information that is irrelevant to the job selection process provides opportunities for the hiring manager or committee to see something that would make the candidate a ‘bad fit’. A cynical candidate might think that a carefully crafted and targeted presentation of a pruned version of themselves might be effective. In the short run this might be true, but bad information is likely to lead to bad outcomes. And finally, a privacy sensitive candidate might not enter into the process for fear of revealing too much about themselves and deprive both themselves and their employer of the opportunities of advancement. Both successful career planning and successful succession planning require that privacy issues be addressed.

Consent is generally not required for the collection of personal information about an individual in the employment context in so much as the information is necessary to establish, maintain or terminate an employment relationship. Notice to the employee or prospective employee is required in lieu of consent.("scrivcmt://EC89A9FB-789C-4F21-958D-E095B0EA354D") The question arises here in relation to education, training and other related information in an employee’s file. If an employee is aware of a potential promotion and applies for it then the hiring manager and other individuals involved in the selection process could reasonably be granted access to the employee’s information as part of the maintenance of the employment relationship. But what happens if a the company is planning a confidential new product and wants to recruit qualified individuals to participate. Is it reasonable, with consent or notice, for the selection committee to have access to any employee’s file? Presumably not every file viewed will result in an offer. Employees in a situation like this may have their employee files viewed and never now that they were not considered for a position. Effectively this becomes a use of personal information with neither consent nor notice. Employers should consider including and entry in the employee file, to be allowed for employee viewing when the period of sensitivity for the special project has diminished.

From the employee side, they may be asked to consent to background checks, criminal records checks or social networking reviews. It would be contrary to the views of freedom in a democratic society to suggest to individuals that they be required to change or adjust their off duty, non job related behaviour if they are seeking advancement in their career. Further, it is the case that if employees gather too much information about their employees they may build erroneous profiles or views about those employees and select sub-optimal candidates for positions as they arise. There are some occupations that are exceptions, such as individuals with access to children, but such exceptions are rare and often have specific legislative requirements the take precedence over privacy law.

At the end of the day, our old friend ‘data minimization’ comes to the rescue. From the employee point of view they should share information about themselves that they believe is necessary to make their case for promotion but no more lest they talk themselves out of the promotion. Similarly employees should only collect or use the minimal amount of information available to them to determine qualifications and fit for a role. Any more than that increases the risk of selecting the wrong employee for the promotion and, even worse, alienating the employee that would have been right for the role. Just because revealing, or collecting, everything seems the easy and transparent way forward doesn’t make the case. Prudence, and data minimization, are more likely to lead to good outcomes.

Year End

November/December 2016

Read column

Year-End

The inexorable one second per second form of time travel that we experience most of the time seems to go out of whack at year-end. Too much work, too many deadlines and too much uncertainty all add up to a recipe for becoming a “Reaction Superhero.” And, by the way, year-end doesn’t mean you get to take a break from the regular payroll you have to deliver every pay period. On time. And to the penny. No pressure.

Your desk and your computer become littered with notes, files and correspondence about your current employees, your terminated employees, your retirees and all the things that you need to get done, and done right, to close 2016 and make sure that the first payroll of 2017 is also on time and to the penny. There is no forgiveness in payroll, especially from employees that have just overspent on Christmas and are dreading the bills that will come due in January.

You already know this. And you probably don’t want, or need, to be reminded that you have privacy responsibilities as well. After, what does year-end have to do with privacy? The last time I did a privacy column on year-end was 2010. I wrote about making sure that software is updated with the right tax tables and any other updates. I also wrote about get tax forms out. This time I’d like to look how organizations approach year-end. Is it an all hands evolution where the office goes into overdrive for two to six weeks? Or is it a carefully planned project delegated to a few people that focus on nothing but year-end? In either event - overdrive or project - has your department factored privacy into its processes, projects or planning? It’s easy to assume that the day to day privacy and security procedures will work. And that may be true. But year-end is an extraordinary time period for payroll. Why shouldn’t that include privacy? The shear volume of information involved in processing year-end is sufficient to raise the associated privacy risk. There are processes that are only used once a year. That increases risk. Given that, one of more of the following issues are likely to apply to any organization. Review and consider the following to enable you to cast a privacy sensitized eye over your year-end processes.

Printed Output

It used to be that the payroll office was awash in paper at year-end and tax time. Production printing may now be outsourced, or most production output is processed electronically - including year-end statements, registers and tax forms. But even in offices that have converted it is likely that they will produce a lot of interim, working or test output on paper. Last week’s test output with the new tax tables needs to be compared with this week’s test output. It starts to stack up. What happens to an office ‘clean desk policy’ when there are hundreds or thousands of pages of output on desks? Is all this sensitive and personal and financial information locked up every night? Or kept in locked offices where only payroll staff have access? The privacy risk here is that cleaning staff, or part time staff will ‘clean’ the office resulting in a headline about sensitive payroll information being found in a dumpster.

  • Ensure increased paper production is proactively matched by increased secure waste paper storage and paper shredding capacity.

Extra Staff

Some offices bring in extra staff to help out. If possible these temporary works should be internal staff that already have access to HR data. Otherwise training time needs to be allocated. Security and privacy training needs to be delivered. And supervision needs to be provided. New people using systems they are not familiar with are more likely to have accidental breaches than veteran staff. Any new person in a time of increased tempo is an increase in risk. If you have to bring in extra staff;

  • Start with internal staff with payroll/HR experience; or
  • Use external support, but with experience with your payroll/HR system; or
  • Use external support, but bring them in early for training and validation.

Addresses

A payroll/HR system should have the current addresses, emails, or electronic deposit information on all current employees and retirees. That guarantee cannot be made for the individuals that have terminated, especially those that terminated earlier in the year. Failing to get T4 or Releve information to individuals is both a violation of CRA rules. If mis-delivered it could also be a privacy breach. And where there is a performance or other bonus payment system in place, ensuring correct addressing is critical.

  • Put together an address list for year-end well in advance and test the data.

Conclusion

Year-end is a frantic scrambling time of the year. It is not a time to invent new procedures or to be researching things like the Sales VP’s Christmas address for bonus delivery. By the time this magazine is printed and delivered, or shortly thereafter, the measures discussed above or measures like them for your particular situation should be in place.

Have a productive and easy year-end.

Human Resources

January/February 2017

Read column

Human resources can have a significant impact on the privacy posture of an organization, for good or for ill. HR personnel have access to some of the most sensitive personally identifiable information in a context where they can have a real and significant impact on people’s lives. Let’s look at the up side first.

The human resources function in an organization can be a significant factor in boosting organizational performance. This includes not just organizational commitment, which might be expected, but also key areas like financial performance and innovation. If you’re interested do a web search for “Human resources practices as predictor of performance” or some such. If this is the case, then a not unreasonable predecessor question might be, “How to I hire or identify human resources professionals who will be more likely to be part of, or want to build, a high performing HR function?” What I’d like to suggest here is that one characteristic of such professionals is that they will respect the autonomy and privacy of employees.

High performing HR functions in innovation companies work to recruit and train talent based on intelligence, the capability to work towards identified goals and the capability to work without close supervision. In some cases this might be results oriented workplace environments. HR and payroll professionals that deal with people that have been recruited and trained like this will need to use the most up to date HR research, tools and processes to maximize both retention and performance. Current HR practices include both security measures to protect the confidentiality of HR records and measures to respect the privacy of individual employees. Note the difference between security and privacy here. You need both to have full protection and respect of employee personal information. Organizations where employees believe that their employer protects their information and respects their privacy are likely to see 5% or better reported levels of organizational committment than organizations where employees don’t hold such beliefs.

So that’s the good news. Respecting privacy is a way of improving the impact that the HR function has on the organization. What’s the bad news?

Policies are not enough. Most organizations, especially those based on knowledge workers, pay lip service to the notion that their employees are their most valued resource. Such policies are meaningless unless put into practice. I remember talking to someone at a privacy conference, and telling them that my background was in operations for outsourced payroll and HR. Their unsolicited response was that they found it very hard to find good HR people because too many went into the field because it as a shorter journey to the C-suite, or it gave them an opportunity to exercise petty authority, or that they couldn’t ‘cut it’ in real business. Harsh, and an unfair judgement from someone outside the industry. But also a bit of a cliché in that I’d heard before.

Clichés aside, what risks to privacy need to be managed in HR. First and foremost is information leakage or, in fewer cases, information theft. Systems, process and training need to be in place to protect an organization. For example, the information of about 700 people was stolen from Snapchat when an attacker called in, pretended to be the company CEO and persuaded someone to email them their information. This suggests a failing at multiple levels. There is security software that can scan outgoing mails, for example. By the way, putting those kinds of software in place is one reason why employees need to be told that their email is NOT private. But in addition to missing software security, there may have been missing policies to forbid the sending of sensitive information by email. But this incident would have never happened if the HR person that received the call had a privacy protective mindset. Not everyone has such a mindset naturally, and not every organization would support a staff member refusing a request from their CEO based on a security or privacy policy. If your organization doesn’t have the technology tools or the right policies, your last best line of defense is ensuring that your HR and payroll staff are trained and supported to protect confidentiality and privacy.

Technology

March/April 2017

Read column

Privacy and Technology

We are in the middle of a technology revolution. But that's been true since the first application of technology to payroll in the 1950's. The technology headlines today are about big data, artificial intelligence (AI) and the Internet of Things (IoT). What is the impact of these technologies on payroll in the context of privacy for payroll professionals? Or what is the impact of technology developments on privacy?

Sally gets up every morning and checks in for work. She doesn't know what work is in store for her today. She may be called in to work as a retail clerk on Main Street. She could be called in to stock shelves in a warehouse on the outskirts of the city. If she has to go to work, she will call a self driving vehicle to take her where she needs to go. Or she could be occupied all day on her computer in her apartment doing a variety of graphic design projects that she has bid on. In all cases her hours and net pay are processed by a personal payment processor that calculates Sally's net pay based on the statutory remittances that apply to the jobs that she is doing that day. Tomorrow could be completely different.

The technological infrastructure for this scenario is mainly in place, and some people are living lives not far removed from this. It's a hypothetical next year scenario, not a science fiction novel, and it is rife with implications for payroll and privacy. I'll look at just three of those below, the impact of online private life on employment, the use of sensors and devices by employers, and artificial intelligence for payroll processing.

Blurring personal and work lives

Employees and employers are already dealing with the impact of social networking on employment. People that are active on social networks are engaged with those networks at work and away from work. Some peoples' jobs are to do social networking for their employers. Using third party background checks it's now technically possible for an employer to quietly define a 'good fit' with inclusion and exclusion factors that are much more narrow than before. After all, web marketing can target ads based on age, gender,sexual preference, income or disposable income, marital status and whether or not you have children. Clearly applying these kinds of tools in this way creates significant risks relating to employment standards and privacy.

IoT tracking of employees

Time and attendance is being revolutionized by technology. The decline in the price of sensors and the increase in their capabilities can generate a much more comprehensive and detailed view of an employer's physical space and the people within it. It is now entirely possible to use sensors, ID cards and/or telephone apps to provide a second by second accounting of an employee's location. If the employee is using a computer this can be linked the second by second activities on their computer. And if the employee is wearing a smart watch or fitness device you can add health data to the mix. Is it the case that employers can collect all this information and use big data and artificial intelligence to profile 'good' and 'bad' employees? Good this be used as a filter for promotions despite the inherent invasion of privacy? Does this actually work? Payroll professionals will need to educate themselves to ensure that they are not being sold big data and artificial intelligence snake oil.

Artificial Intelligence processing

When an employee looks at their pay statement they see something that seems simple. There is gross pay, a series of deductions and net pay. And any individual employee's pay is simple. The complexity arises when you have hundreds or thousands of employees, each with their unique mix of rates, salaries, benefits and deductions. Becoming a payroll professional means, in part, learning the rules and complexities for calculating and explaining payroll. But just as basic payroll calculations in the 1950's were an obvious candidate for automated processing, is it the case that the current functions of a payroll professional are a likely candidate for artificial intelligence? There was a recent news story about a group of insurance adjusters being replaced by an artificial intelligence computer system in Japan. If that turns out to be cost effective, it will become a technology searching for a market.

Is privacy still more human than technology?

But privacy (as opposed to confidentiality) remains difficult to translate into code. It's fuzzy and contextual. Payroll and HR professionals need to bring emotional engagement and a commitment to respecting employees to their work to respect privacy. HR staff can add value above and beyond that available through artificial intelligence. An engaged HR and payroll department will enable employers to build high performing organizations and better engagement from employees (or contractors as the case may be).

Tax and Legislative Compliance

May/June 2017

Read column

Tax and legislative compliance is an interesting interesection of the individual rights represented by privacy and a company's legal obligations to generate and collect personal data. On the one hand, the personal financial information contained in an HRIS/Payroll system is rightfully regarded as highly confidential data which requires the best efforts of a company's security team. Only authorized and authenticated users can be allowed access to this information - and then only in fulfilment of their job duties related to the processing of that data.

On the other hand, certain elements of personal financial data in the HRIS/Payroll system are inputs to statutory remittances and companies are required by law to provide taxing authorities with this information about individuals. This appears to be a violation of the third of Canada’s 10 fair information principles("http://https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/p_principle/"). It says,

The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.

The key here is "inappropriate". The right to privacy is not absolute. For example, employees typically do not have a right of privacy with respect to their use of, and access to, company resources. Companies may look at employee web use, email or files to ensure that employees are not violating the privacy or confidentiality of customers, for example. Similarly, the information required to calculate and submit statutory remittances is 'inappropriate' for consent. This has a number of consequences:

What you need to know:

  • Do NOT ask for consent where the employee may not say no to the collection, use or disclosure of their personal information.

⁃ Use information collected without consent ONLY for the purposes to which legislative or similar authority applies.

⁃ You may use information collected without consent for other purposes IF you ask for consent for using that data for those purposes.

  • The authority to collect, use or disclose information without consent does not allow you to bypass your responsibilities to limit other collections or to limit the uses and disclosures of that information (principles 4 and 5 of the fair information principles.)
  • Employee personal data is protected by statutes

⁃ in most public sectors (with the exception of Ontario)

⁃ In the private sector in BC, Alberta and Québec as well as for organizations operating under the Federal Labour Code.

  • Employee personal data is also protected where there is a collective agreement
  • Even if you employees' personal data is not protected by statute or arbitral jurisprudence it may be that your company can be sued for violating the privacy of employees. Privacy is recognized as a basis for a civil suit in a number of provinces' legislation, and there are also emerging common-law bases for such a suit. You should seek advice from your counsel to understand your current risks.

HR and payroll best practices are to protect the privacy of individuals. This is bolstered - in some jurisdiction by statutory or other protections. Your company is required to provide statutory remittances for tax purposes. To meet this apparently contradictory requirements you need to do an inventory of the information in your HR/Payroll system to determine those elements that are required for remittances. Then you need to ensure that you haven't made consent based committments to employees that you can't keep. This may trigger going back to employees with a notice, or updating your employee information package so that your company is clear with respect to what information is collected without consent because it is required for taxes, what informaiton is collected without consent to create, maintain and terminate the employment relationship and what leftover information requires consent from the employee. At the end of the data you should have a data inventory that includes or incorporates consent management and tracking.

For further information and to aid you in your determination of the best path forward for you I have identified 31 different privacy laws in the table below. They are sorted by sector (Health, Private or Public) and then by jurisdiction.

Management

July/August 2017

Read column

The roles and responsibilities of management can vary widely relating to industry, function or level in the organization. Management texts suggest that management responsibilities can be grouped into interpersonal leadership, informational communication and decisions about resources roles.("scrivcmt://092CF0ED-0772-46B6-ADD8-BC4822C6E71F") But one responsibility that all managers have in common is that they manage people. Having an understanding of privacy facilitates the fulfilment of that responsibility across all roles. Leaders should understand that respecting employee privacy builds trust and enhances their leadership. Communications to and about employees should be sensitive to, and respect, their personal boundaries and the privacy of clients and customers. And finally managers have to understand the costs and risks associated with failing to deal with privacy issues promptly or proactively to avoid damaging regulatory or legal consequences. So what are management (and manager) responsibilities for privacy in a Canadian context?

Line managers are accountable for operations in their area, including following policies set elsewhere in the organization. This includes but is not restricted to accounting, workplace safety, and employment standards. These responsibilities are on top of their responsibilities for meeting their performance targets. Their day to day focus is tactical and operational. Typical privacy responsibilities are to ensure that company privacy policies are followed, that only authorized personnel access personal data - and then only for approved tasks and ensuring that staff maintain their privacy awareness and training.

From the privacy practitioners perspective privacy advice and guidance at this level needs to be practical, immediate and aligned with the operational goals of the team. Managers will need to depend on privacy analysts and/or privacy engineers to stay focussed if and when privacy issues arise in their area. These are people that are trained in privacy from a policy or an IT perspective who can help the manager meet both their privacy performance targets and their privacy requirements.

Privacy Engineering: “Privacy engineering as a discrete discipline or field of inquiry and innovation may be defined as using engineering principles and processes to build controls and measures into processes, systems, components, and products that enable the authorized, fair, and legitimate processing of personal information.”

Excerpt From: Michelle Finneran Dennedy, Jonathan Fox and Thomas R. Finneran. “The Privacy Engineer’s Manifesto.”

Line of business owners or departmental managers have a broader set of responsibilities and therefore a greater risk exposure with respect to privacy. At this level managers should be working with their counterparts in privacy to ensure that the training and awareness programs for line managers and employees are appropriate and applicable to their duties. They should conduct regular reviews of privacy policies and procedures to proactively ensure that privacy and their line of business requirements are aligned. At the same time privacy analysts and privacy officers need to maintain an understanding of the business processes and data flows in the line of business to be able to provide privacy protective business enhancing solutions forward as issues arise or regulations change. Privacy professionals must be able to present privacy risks in terms relevant to the particular line of business with which they are working in order to ensure that business decision makers are able to make informed risk decisions.

Executive management is the home of privacy accountability and ‘tone at the top’. If an organization, or part of an organization, operates in a jurisdiction that has a privacy commissioner or a data protection authority it is very likely that the organization will have an obligation to designate a person to be accountable for privacy or data protection. This person should be part of, or report directly to, the executive team that leads the organization. A common title for this person is “Chief Privacy Officer” or CPO. The privacy office will set out the organization privacy policies and should work with the various levels of management to ensure that managers have the ability to access tools, training and expertise as necessary to meet their privacy responsibilities. This is a crucial leadership role that, if done properly, will build trust with employees, customers, and other stakeholders to enhance the organization’s reputation and reduce risk across the board.

Education

September/October 2017

Read column

Who is entitled to view, access, change or disclose employee data?

Every single person in your organization should be able to provide a basic answer to this question. Most employees should say something like, “The only people that can look at my employee data are my manager and authorized HR/Payroll personnel.” All HR/Payroll personnel should say something like, “I can only access employee information if it is directly related to the performance of my job duties.” If this is not the case you may have gaps in your HR/Payroll privacy practice or gaps in your privacy education. This column assumes that you have a compliant practice and that the issue is in education and awareness.

Education and awareness as a control

When security or privacy assessments or audits identify risks to personal data, one of the ways that an organization can mitigate a risk is by implementing a ‘control’ - some mechanism by which the organization can reduce risk. Indeed, part of an assessment is usually a review of existing controls. Education and awareness programs are a standard organizational control for both privacy and security. For example, in the Privacy by Design Assessment Control Framework("http://www.ryerson.ca/content/dam/pbdi/Certification/Privacy%20by%20Design%20Certification%20Program%20Assessment%20Methodology20161011.pdf"), one of the key criteria is “Privacy Training” and one of its controls is that “The organization periodically educates staff on privacy matters and current issues. Specialized privacy training is provided to individuals with privileged access to personal information and/or whose job function involves elevated privacy risks.”

The content of education and awareness.

If you are thinking about privacy training and awareness for your organization a natural starting place might be the web site of the Office of the Privacy Commissioner of Canada, specifically the Privacy at Work page. Even more specifically, you can find a list of the “Ten things human resources professionals need to know about privacy("https://www.priv.gc.ca/en/privacy-topics/privacy-at-work/02_05_d_53_hr/")”. Your provincial regulator is likely to have training materials relevant to your province. If you have an industry association, it may be able to provide security related materials, and so on. Other online resources for privacy and security include:

https://cippic.ca/en/privacy("https://cippic.ca/en/privacy")

https://www.infosecindustry.com/("https://www.infosecindustry.com/")

https://iapp.org/train/("https://iapp.org/train/")

https://netalert.me/("https://netalert.me/")

https://pacc-ccap.ca/("https://pacc-ccap.ca/")

https://securingthehuman.sans.org/("https://securingthehuman.sans.org/")

https://www.privacytools.io/("https://www.privacytools.io/")

https://www.teachprivacy.com/("https://www.teachprivacy.com/")

The delivery of education and awareness.

A good practice for all organizations, irrespective of size or sector, would be to have basic training on privacy delivered to all employees at on-boarding and refreshed annually. In addition, all organizations should consider enhanced training for managers, IT staff, HR personnel and others whose job are likely to require them to use or have access to personal information. The amount and extant of training should be tailored for the types of information that an organization will have, or will have access to. This needs to be thought through thoroughly as it may be too easy to assume that your organization has limited privacy exposure. For example, a kitchen appliance manufacturer might have specialized privacy training for it’s designers and programmers so that when it builds Internet connected appliances for customer homes, it takes into account customer privacy desires and country specific regulations about where such data can flow. The HR requirement may be to ensure that all programmers take courses and get certifications in secure software development or Privacy by Design. Training can be in-person, on-line, in-house or outsourced. It should be designed for all types of learners and should be an ongoing effort. Above all it should reinforce the messages that management takes privacy seriously and that every employee shares responsibility for protecting privacy.

Measuring success

The success of training initiatives can be measured through a number of mechanisms. For example, a week after privacy training has been delivered, all attendees could be sent an online quiz to both reinforce and test the effectiveness of the training. If employees receive training about how to avoid e-mail scams, there are organizations that can send test phishing emails to measure how well employees respond. Some privacy programs run contests. An example of this might be a photograph of a desktop with some visible issues (like a password on a sticky note) sent to staff. Those that can identify all the issues get a small gift or recognition.

Conclusion

When a privacy training program is in place and effective it acts as a multiplier to the effectiveness of other privacy controls. Once an organization has a privacy policy for employee data, implementing training is a logical next step. And feedback & suggestions from employees that have just received the training may be your best guide for future work.

CRA

November/December 2017

Read column

Thinking about the CRA at Year-End

As the calendar and personal tax year-end approaches, a number of things start (or stop) happening in the world of payroll. Payroll people wait for tax tables, make sure that Records of Employment are all done, get ready for bonus payments, and all of the other minutiae that make December through March such a joy.

There is a noticeable increase in the amount of information that goes to the Canada Revenue Agency (CRA) at this time of year. For a privacy person that triggers concerns about any additional personal information that has to be processed or disclosed in order to close year end. Employees trust (or hope) that the payroll professionals that collect all of their personal data protect that information from prying (AKA unauthorized) eyes and that authorized eyes only use the information appropriately. In the normal course of events, when your organization considers using a service provider to process personal data (like back-up services), part of the due diligence process will be to evaluate the service provider’s capability to protect the data supplied to them.

But what about personal information that employers can’t control - information that is required to be collected for statutory remittances? I thought about this because of occasional headlines about the CRA and privacy. Earlier this year, for example, we saw headlines that eight CRA employees were for fired for their roles in privacy breaches. According to one story, “…one employee improperly accessed the accounts of 1,264 taxpayers.("scrivcmt://CE9FF66E-A577-40C2-A19B-AD714D2FAC04")” Further, the same story noted that the agency has not always been as open about privacy breaches. I was as disappointed as anyone in finding out that eight civil servants betrayed their trust. But it is the case that no system is perfect, people make mistakes, and that privacy breaches are inevitable. In other words, we should not expect perfection. In a perfect world, there would be no privacy breaches. But a more reasonable expectation is that there will be small number of breaches, that most or all breaches will be detected, and that the CRA will take appropriate steps to mitigate the affects of those breaches.

According to Statistics Canada("scrivcmt://1430A803-1352-472C-8056-5975EEEA4CDC"), there are almost 29 million Canadians aged 20 or higher. So what is a small number of breaches for an organization that processes taxes for 29 million Canadians? Using standard business statistical measures, a process success rate of 99.7% would be a best practice. 99.7% of 29 million is still 87,000. The most recent story about the CRA says that one former employee accessed the account 1,264 taxpayers. In February of this year the CRA reported that it had lost the a DVD containing 2014 tax information on 28,000 Yukon taxpayers, but that the DVD was encrypted. Based on this, it seems reasonable to assume that on an annual basis the CRA may have incidents involving some 10’s of thousands of Canadians tax records. What should employers think of this, and what should they tell their employees?

I contacted the CRA to tell them I was working on a story about privacy and asked about what they could share about how employee privacy was protected. In addition to the expected response about how seriously the CRA takes privacy, the media relations person pointed out some concrete resources that are available on the CRA site. This includes their “Internal controls to ensure privacy and security” page which includes references to their code of integrity("https://www.canada.ca/en/revenue-agency/corporate/careers-cra/information-moved/code-integrity-professional-conduct-we-work.html") and their directive on discipline. Further, the CRA does personnel screening, has an employee awareness program, and has implemented a number of technical controls. In other words, the CRA has implemented a reasonable standard set of privacy and security measures.

I’m not suggesting that the CRA is perfect, and I’m not suggesting that any breach is acceptable. After all, even if the CRA breaches the privacy of only 0.3% of the population, it has a 100% impact on the affected individuals. I am suggesting, however, that the only way to minimize the number of breaches - and to continuously improve privacy processes - is to be transparent and open.

Canada has not (yet) suffered a government breach on the scale of the Office of Personnel Management (OPM) in the US (18 million people) or a private sector breach like Equifax (143 million people), but that doesn’t mean breaches of such a scale are impossible. With latest press release actually identifying the number of employees terminated and the number of records viewed, the CRA may be setting a standard for continuous privacy improvement to help reduce the possibility of an OPM scale breach in Canada. Can your organization make the same case?

Communications

January/February 2018

Read column

<$Scr_H::1>Communications and Privacy

<!$Scr_H::1>A communications plan for privacy should identify the who, what, when, where, and how of communications. For payroll professionals the ‘who’ means communications for staff. The privacy office should have communications plans for training, awareness, external stakeholders, customers, and regulators. In the payroll and/or HR departments it is simpler. You need a communications plan that has two element. The first is to ensure that all of the HR and payroll staff have a common understanding of privacy and understand the key message for staff. The second element is to provide employees with a consistent and coherent set of messages related to their privacy in respect of the HR and payroll in your organization.

<$Scr_H::2>Key messages

<!$Scr_H::2>Employees should understand that while their privacy will be respected, there will also be limitations. This should be matched with a message to HR and payroll staff that while they have access to employee personal information, any access to that information also has limitations. The success of your communications plan about privacy can be measured if both your employees and your HR/Payroll staff have a similar view of those limitations. If an employee asks for a copy of their HR file, and a list of who has accessed it, in most cases there should be not surprises. So the key messages are:

Messages to employees

  • The organization collects information about them to manage the employement relationship and to fulfill legal obligations.
  • If any information about an employee is collected or used for a purposes other than for managing the employment relationship or to fulfil legal obligations, employees will be asked for their consent and they will be able to say no without fear of reprisals
  • You have a right to access the information that the company has about you (with some limitations), and to challenge whether the information is correct or should be in your file at all

Messages to HR/Payroll staff

  • You can only access employee information when you are acting on behalf of the organization, fulfilling your HR or payroll duties. Those duties should align with committments to employees
  • If you think that an HR/Payroll process or system is inappropriately accessing or using employee personal information you should notify your management and your compliance/privacy office.
  • There is zero tolerance for accessing employee personal information for personal or other reasons.
  • There is zero tolerance for discussing employee personal information except as required for fulfilling your job duties.

<$Scr_H::2>Communications with staff

<!$Scr_H::2>These messages can and should be communicated on a regular basis to ensure that everyone is on the same page. That means training and awareness programs which include training for people when they on-board as well as regular refresher training on employee privacy. This could also include things like cubicle cards for everyone’s desks to remind them, in a job specific way, how they can help protect employee privacy. It could also include screensaver messages about privacy on everyone’s screens. It may be worthwhile working with the privacy office to provide material to employees to educate or to train them how to protect their privacy in their personal lives. Employees are more likely to pay attention to privacy safeguards if they can relate, or have practice, in implementing them for themselves at home.

<$Scr_H::2>Collateral benefits

<!$Scr_H::2>Many of your organization’s elaborate and expensive cyber defenses and privacy safeguards can be bypassed by an employee with access to sensitive material not paying attention or by an employee’s malicious action. A recent case in England, for example, found an employer vicariously liable in a class action for a criminal breach of payroll data by one of their employees. You should also know that in the case that created a right to sue for privacy in Ontario (Jones v Tsige("scrivcmt://F166A796-BA44-4E5A-9619-3176FE1059D1")) the employer had implemented training and privacy policies. In other words the privacy violation that was at the heart of the matter was an individual behaving badly, not the organization.

At the end of the day, if you communicate openly with employees about their privacy it will build trust and employee engagement. Good employee rivacy communications are part of a solid HR/Payroll business strategy.

Technology

March/April 2018

Read column

<$Scr_H::1>Introduction

<!$Scr_H::1>Payroll has processing has been on forefront of new technology since the first payroll systems of the 1950’s. This article looks at a couple of innovative technologies and how they might be applied in a payroll or HR context

<$Scr_H::2>Facial Recognition

<!$Scr_H::2>We have come a long way from a mechanical punch clock. There are now biometric time and attendence systems based on facial recognition. Such systems seek to replace fingerprint, iris scan and hand reader time clocks. They can link to payroll systems and therefore automate multiple processes. These systems can also be used for secure environments.

You can also use facial recognition in the latest version of Windows with a ‘feature’ called Windows Hello. For workplaces where employees’ time is allocated between departments this has the potential to make job costing and distribution of time much easier.

If you want to invest in face recognition, you can track your employees in real time and track the amount of time that they are sitting in front of their computers, when they enter and leave meeting rooms, and any other tracking you might choose to implement. You could consider applying the same technologies that are being introduced in cars to track drivers to ensure that they are paying attention. Or you could use an “Emotion API” (an API is an Application Programming Interface so that software can easily implement new capabilities) that allow computers to read the emotion of the person whose image has been scanned.

In this scenario, using software that is available now, you are able to pinpoint your employees movements and emotions throughout their workday. The question you have to ask yourself is whether this is the employer you want to be?

From a privacy perspective, I would suggest that any facial recognition system should be limited, encrypted, and done transparently with the employees or their representatives. Otherwise any claims of ‘respecting’ or ‘valuing’ your employees will ring hollow and you are likely to see decreased organizational committment. I’ll note that you will need to look closely at your province’s employement standards. Biometrically encrypted facial recognition to replace punch clocks is feasible. Anything beyond that smacks of Big Brother.

<$Scr_H::2>Big Data

<!$Scr_H::2>When are your employees at their most productive? What is the optimum time or duration for a meeting? Can you predict attendence days, weeks, or month in advance to predict staff requirements? It used to be that you might be able to do these kind of analytics for staff that were involved in repititive or routine tasks using specialized software - like data entry clerks using data entry software. But it is the case now that you can collect much more detailed informaiton about your employees performace from system logs, call logs, and reports from the software they use. The “time and motion” approach that used to be used on factory floors can now be considered for the office work place. And the more data that you collect based on employees’ digital work records, the more you can infer about your employees and the more you may be able establish work processes and work flows that maximize the value of each employee. If you do this secretly, or from the top down, it is very likely to backfire and lead to an employee backlash.

If done transparently, in cooperaton with employees - and in a manner that is senstive to their privacy - these kind of analytics have the potential to be a win-win for companies that are willing to be flexible. You may find employees that are most effective working reduced hours for 6 days, and other employess that prefer and respond to the possibility of 3 day weekends and work extended hours for 4 days. Some employees will be night owls, and some will be early birds. And this is just hours of work. The same techniques can be applied to learning about floorplans, space allocation, or even amenities. If labour costs and labour productivity is a large factor in your organization’s success, and you pay attention to the data and to your employees, you can be providing the best tools to your employees. And it is the case that you can’t do things to make employees happy, but if you do things to make them more effective, they are likely to be happier.

Whether it is facial recognition or big data, when you use the technology WITH your employees and show them that you respect their privacy, new technologies can create a much more high performing workplace.

Tax and Legislative Compliance

May/June 2018

Read column

With this month’s theme being Tax and Legislative Compliance I thought it might be useful to remind people that employee personal information may or may not be covered by privacy legislation. This will depend on whether your organization is federally or provincially regulated with respect to employees and also whether your employees are covered by a collective agreement.

<$Scr_H::2>Federal Privacy Legislation

<!$Scr_H::2>Federal Works, Undertakings, and Businesses (FWUBs for a fun acronym) are organizations that fall within the legislative authority of the federal Parliament. Generally that means organizations governed by the federal labour code. If this is you, then you have obligations to protect the privacy of your employees. The relevant legislation is the Personal Information Protection and Electronic Documents Act (PIPEDA). You may collect, use, and disclose personal employee information without the consent of the employee (whether current, prospective, retired, or terminated) IF and ONLY IF the purpose is for the purpose of establishing, managing, or terminating an employment relationship. You will need consent from your employees for any other purposes - even if you already have the data. The Privacy Act, which sets out the rules for the use Canadian citizens’ data by the federal government and its institutions, includes some privacy protections for federal civil servants, many of whom are covered by collective agreements.

<$Scr_H::2>Provincial Privacy Legislation

<!$Scr_H::2>Three provinces have private sector privacy laws that have been deemed to be equivalent to the PIPEDA and have elements that apply to employee personal data. These are Britich Columbia, Alberta, and Quebec. All provinces public sector privacy laws, with the exception of Ontario also include protection for provincial civil servants.

<$Scr_H::2>Collective Agreements

<!$Scr_H::2>Arbitral jurisprudence (the decisions of arbitrators in disputes) have resulted in the ability of individuals to claim privacy protections roughly equivalent to those provided by privacy laws.

<$Scr_H::2>General Data Protection Regulation

<!$Scr_H::2>The GDPR, the EU wide data protection law, goes into affect on May 25th, 2018. Any organization with personnel in the EU will need to ensure that their EU employees privacy is protected in accordance with this new legislation. It allows for the collection, use, and disclosure of personal information for a number of basis including consent, legal requirements, contractual requirements, and so on.

<$Scr_H::2>Managing the risk?

<!$Scr_H::2>In order to manage your risk, you need to start with a couple of inventories by asking the following questions:

1) What personal data do I have about employees?

⁃ Which data is necessary to calculate payroll?

⁃ Which data is required by legislation (statutory remittances)?

⁃ Which data is collected for other purposes, such as optional benefits?

⁃ Which data is not currently used for any purpose?

⁃ Which data is provided to the goverment, to benefits providers, or to other entities?

2) What jurisdictions apply to my employees (countries, provincies, states, municipalities)

⁃ What data does each jurisdiction require by statute?

⁃ What data does each jurisdiction request?

A complete inventory based on the questions above will enable to set out you basic compliance requirements. One ‘simple’ way to capture this might be to create a table like the following:

Data Type|Data Purpose|Jurisdictions|Required/Consent|

SIN|Statutory Remittances|Federal|Required|

Home Phone|Social Committee|N/A|Consent|

Some Data Types may appear in multiple rows, because there are multiple purposes for the data. By enumerating the data types and purposes like this you can ensure that your employee data rules match the employee data that you already have, enable you to communicate clearly with your staff (and their union) about the data you collect and for what purpose.

Another benefit of doing this inventory is that you can use it as the basis for communicating with your IT staff to ensure that employee personal data is identified and secured in IT systems.

Create a data inventory table will also help you to determine whether it is reasonable to treat all of your employee personal data under one set of rules, or whether it makes more sense to divide your employee personnel processing to match the requirements of each jurisdiction individually. The ‘one set of rules’ will need to match the highest set of standard, and is operationally more simple. However it is also the case that there may be contrary requirements between jurisdictions and you may need to implement jurisdictionally distinct payrolls.

At the end of the day, being clear on your varied tax and privacy legisative requirements will help ensure that you meet minimum requirements to avoid regulatory entablements while meeting reasonable employee expectations around the protection of their data.

Management

July/August 2018

Read column

So, you have just taken on the mantle of managing your organization’s (or your department’s) privacy program. Lucky you. What will you have to do to be a success? If we assume, for the moment, that there is an organizational vision for privacy and that you are taking over an established privacy program, what do you need to know to hit the ground running as a privacy program manager? A good place to start is by developing an understanding of your organization’s privacy program framework. At one level this consists of the policies and procedures that your predecessors have developed (or not) to provide guidance to your organizations staff. At a more practical level your privacy program is composed of people and their activities related to privacy.("scrivcmt://93B5FAEB-9789-4E81-805C-63F9A8671D03")

<$Scr_H::2>Policies and procedures

<!$Scr_H::2>Your written privacy policy should provide guidance to staff, contractors, and vendors with respect to the proper processing of data that is within the scope of the policy. Note that this policy may well be significantly different from the ‘privacy policy’ that your organization will have on its web-site. This is because the two documents have very different purposes. The external ‘privacy policy’ is normally a statement or claim regarding how your organization collects, uses, and discloses data about people who use the web site. It is an assertion for external consumption. Depending on the jurisdiction, and on what the external privacy policy says, it may or may not be binding on your organization. The ‘internal’ privacy policy is actually a policy. It should be signed by senior management, reviewed or updated regularly, and be presented to employees, contractors and vendors on a regular basis. This is because the internal policy is the document that actually sets out what your organization can, and cannot, do with personal information. It should set out the governance and reporting structure with respect to data protection, the privacy principles & legislation (if any) that apply to personal data inside the organization, privacy related roles & responsibilities, incident management guidance, and other such information as is appropriate for your organization. Where appropriate, the policy statements should be supported by documented procedures and practices to ensure consistent and manageable processing of personal data. Do not forget to include training & awareness materials, along with processes and procedures for identifying and handling privacy related inquiries and complaints. In addition, the policies and procedures should be clear and consistent with respect to guidance related to employee personal data. A mature privacy organization will include data inventories, risk assessments, and risk statements in its documentation.

<$Scr_H::2>Privacy Program Activities

<!$Scr_H::2>As a privacy manager, it will be your responsibility to manage privacy related activities throughout your organization. The Body of Knowledge (BOK) for the Certified Information Privacy Manager identifies the following key privacy program activities:

i. Education and awareness: Ensure that training materials remain current and are delivered in a timely manner. This should include more intensive training for those that have direct access to personal data, risk training for managers who are responsible for areas that process personal data, and procedures to ensure that new employees receive training at or shortly before the commencement of employment.

ii. Monitoring and responding to the regulatory environment: Laws and regulations change. Privacy managers are expected to be current with respect to which privacy related laws have a business impact on the processing of information by the organization - preferably well in advance of legislative changes going into effect.

iii. Internal policy compliance: It’s not enough to write policies and procedures. They must be socialized, monitored and enforced.

iv. Data inventories, data flows, and classification: It’s normally the case that you can’t manage what you don’t measure (or vice versa). If you don’t know that personal data you have, how it moves through your organization and who has access to it, you will end up managing privacy by breach.

v. Risk Assessment: Privacy Impact Assessment and other risk management tools are there to help you implement disciplined and repeatable processes for identifying risks and gaps in your program.

vi. Incident response and processes: When someone says that they have not had a privacy breach, it is clear that they have either been misled by their people or processes, or that their people and processes are not detecting incidents. Minor incidents happen regularly. Failing to identify minor incidents is a small gap, but if it means that major incidents are also missed, the consequences could be substantive.

vii. Remediation: Whether gaps are identified in risk assessments or as a result of an incident, it is crucial that there is a documented and monitored procedure to identify what needs to be done, who is responsible for getting it done, and a timeline for delivery.

viii. Program assurance and audits: No one can identify their own blind spots. That is why it is occasionally necessary to take steps to have an external review or audit to validate that a privacy program is operating within the scope of its mandate with appropriate criteria for success.

For each of the above areas you should identify, collect and monitor the key metrics to ensure that each area of activity is controlled and delivering the expected level of protection. If you are able to collect such metrics and develop a meaningful dashboard it will be easier to convince senior management to take you seriously should you identify a significant risk or gap in the privacy program. In the absence of good metrics, you will have an opinion without data - usually not a good place to be when asking for senior management support.

Education

September/October 2018

Read column

The theme of this month’s Dialogue is “Education”. A quick look back will reveal that I’be dealt with various aspect of privacy and education in prior education issues. Last year’s education column was about educating your staff about privacy so that they could answer employee questions about privacy. The column in the 2015 education issue talking about education as a privacy control in the context of risk management. And the 2014 education issue contained a primer on privacy, elements of which I will include below.

One thing this column has not focused on is certification. Members of the Canadian Payroll Association are familiar with the benefits of certification, and many readers of this column will be certified Payroll Compliance Practitioners (PCP’s) or Certified Payroll Managers (CPM’s). I will have seen a number of readers who have either attended a training session on privacy for payroll professionals or at the CPA’s annual conference. Staying on top of your profession takes work and dedication. Certification is a recognition of that work and dedication. For some of you, data protection and privacy will be more than one of the things that you do as a payroll or HR professional. Because of personal interest, or perhaps because you work in an organization or a sector that is particularly sensitive to the need to protect employee personal data, some of you may want to seek certification relating to your expertise in data protection or privacy. In this column I’ll point you to some resources and possibilities for further education and potential certification in this area.

There are a number of options for learning more about privacy so as to be able to be certified and become a subject matter expert. In terms of organizations focused on privacy and able to provide some training and certification, there is the International Association of Privacy Professionals, known as the IAPP. As an IAPP member you can become a Certified Information Privacy Professional (CIPP) which demonstrates your expertise in the laws, regulations and standards of privacy in your jurisdiction or discipline. This includes the CIPP/C designation where the trailing “C” stands for Canada. The IAPP also has training and certification for managers (the CIPM designation) and technologists (the CIPT) designation. For more information about the IAPP privacy certifications, check out https://iapp.org/certify/programs/("https://iapp.org/certify/programs/").

If your focus is in the public sector you should check out the Privacy and Access Council of Canada. They have designations for Associate (AAPP), Chartered (CAPP), or Master (MAPP) Privacy Professionals. These certifications are for Canadians, and include freedom of information components (Access) as well as privacy components in their training and certifications. For more information about the PACC-CCAP certifications, check https://pacc-ccap.ca/certification/("https://pacc-ccap.ca/certification/").

You should also check out your local University or Community College. There may be professional or continuing education related to privacy and data protection that you can take advantage of. For example, I just completed teaching a course on privacy protection, data security, and risk management at the University of Guelph as part of a certificate in Information, Privacy and Access (more about that here: https://courses.opened.uoguelph.ca/public/category/courseCategoryCertificateProfile.do?method=load&certificateId=129924). Similarly, Ryerson University offers a course series in Privacy, Access and Information Management (see: https://ce-online.ryerson.ca/ce/calendar/default.aspx?id=5&section=program&mode=program&sub=atd&cert=CSIAPP01). For a more academic approach, there is the Identity, Privacy and Security Institute at the University of Toronto where you can get a Master’s degree in Security Technology from the Engineering Department or a Master of Information with a focus in Identify, Privacy and Security. See http://www.ipsi.utoronto.ca/ for more information. Similarly the University of Aberta offers a fully online 5 course certificate in Information Access and Protection of Privacy at https://www.ualberta.ca/extension/continuing-education/programs/public-sector/iapp("https://www.ualberta.ca/extension/continuing-education/programs/public-sector/iapp").

In other words, if privacy (and possibly access) is a skill that you thing would enhance your career, or is something that you want to consider as a career option, there is no shortage of options for you to consider. Good luck.

Postscript: If you have similar interests related to security, these are some of the better known options in the security domain:

CEH (Certified Ethical Hacker): https://www.eccouncil.org/programs/certified-ethical-hacker-ceh/("https://www.eccouncil.org/programs/certified-ethical-hacker-ceh/")

CISA (Certified Information Systems Auditor): https://www.isaca.org/Certification/CISA-Certified-Information-Systems-Auditor/Pages/default.aspx("https://www.isaca.org/Certification/CISA-Certified-Information-Systems-Auditor/Pages/default.aspx")

CISSP (Certified Information Systems Security Professional): https://www.isc2.org/Certifications/CISSP("https://www.isc2.org/Certifications/CISSP")

CompTIA Security+: https://certification.comptia.org/certifications/security("https://certification.comptia.org/certifications/security")

CSX (CyberSecurity Fundamentals): https://cybersecurity.isaca.org/csx-certifications("https://cybersecurity.isaca.org/csx-certifications")

GIAC certifications from SANS: https://www.giac.org/("https://www.giac.org/")

OSCP (Offensive Security Certified Professional): https://www.offensive-security.com/information-security-certifications/oscp-offensive-security-certified-professional/("https://www.offensive-security.com/information-security-certifications/oscp-offensive-security-certified-professional/")

Year End

November/December 2018

Read column

<$Scr_H::1>Breach Notifications: The Other Deadline

<!$Scr_H::1>As I write this last column of the year, my inbox is suffering an onslaught of emails reminding me of a critical deadline. It may be the last thing that a payroll person needs to hear, but even as you go into the year-end season you should remember that November 1st means that breach notification regulations go into force. You will be required to notify individuals, the Office of the Privacy Commissioner (OPC) and possibly other organizations if there is a breach. PIPEDA defines a breach of security safeguards as, “…the loss of, unauthorized access to or unauthorized disclosure of personal information...”. One of the most likely situations that may give rise to an unauthorized access to personal information is year-end. This is because year-end is a time of high volumes of work, a time of special handling and time of hard deadlines. In other words you have too much work with special year end rules on a tight deadline. In some organizations these circumstance mean that normal procedures put in place to secure information and protect privacy may be set aside or enforced less rigourously. A simple example might be stacks of year end forms left on desks overnight, in violation of a ‘clean desk’ policy. Higher risk examples might include taking files home on USB sticks or transferring files using personal use public cloud services. Any ‘shortcut’ to enable you to do the work that needs to be done more simply may increase the risk of a breach. As of November 1st, you have new obligations when that breach happens.

<$Scr_H::2>Real risk of significant harm

<!$Scr_H::2>The first thing you should understand is that breach notification is required, “…if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual.” In order to determine if this threshold has been crossed, the OPC says that you should look at two factors, the sensitivity of the information and the probability that the information will be misused. Payroll and HR information is, almost by default, highly sensitive data in most circumstances so the real test for payroll data breach notification is the probabilty that it will be misused. The guidance for this comes from Alberta where the provincial privacy law also has a ‘real risk of significant harm’ test. In a finding related to the theft of an unencrypted memory stick containing a backup of payroll data, an investigator said, “The personal information at issue is highly sensitive. The type of harm that could result from unauthorized access to the personal information in this instance is identity theft and fraud. In my view, these are significant harms.”("scrivcmt://D987D1B6-0526-4794-BDFE-C8DF2E75BE5F") You will have to exercise your judgement for any incident you discover, but on a practical level you may want to consider whether providing notifications that turn out to be unnecessary has worse consequences than not providing notfication when significant harms occur. Once you have determined that a breach has occured you are required to notify individuals as soon as feasible to allow individuals to take steps to reduce harms.

Who to notify

In addition to each individual affected by the breach, each organization will submit a report to the OPC. In addition, other organizations or government institutions should be notifed if you believe that they can help reduce the risk of harm or mitigate that harm.

<$Scr_H::2>What is included in the notification

<!$Scr_H::2>You should refer to the regulations for specifics, but the notfication should include what happened (the circumstances of the breach), the steps you have taken to reduce the risk of harm, steps that affected individuals can take to reduce their risk and contact information to allow individuals to follow up.

<$Scr_H::2>Keeping a log

<!$Scr_H::2>You also need to keep a, “..record of every breach of security safeguards involving personal information under it’s control”. The real risk of significant harm test does NOT apply to these records. In other words you have to keep a record of every breach. And this log must be shown to to the Privacy Commissioner on request.

<$Scr_H::2>Conclusion

<!$Scr_H::2>Failing to report when required and a failure to keep breach records can result in a penalty of up to $100,000 per incident. Payroll and HR personnel should work with their privacy office and their security teams to ensure that privacy policies and security procedures have been updated to address breach notification requirements. If your organization has an enterprise risk management program it should be updated to incorporate these provisions. It’s not unreasonable to assume that in some industries, the incorporation of breach notfication rules may also increase the risk of class action law suits.

Human Resources

January/February 2019

Read column

“Human Resources” is a term that can have, applied incorrectly, appalling consequences. If you treat people as ‘resources’ the same way that you treat capital equipment as a ‘resource’ you are not doing yourself, your company and, most of all, your personnel any good. Diligent and ethical human resources professionals know this. In my view the term ‘human resource’ is a term of art that makes more sense as in a “human resources department” than it does as a synonom for personnel. Human resources departments should treat the organisation’s personnel with respect, reinforced by codes of conducts, employment standards and - to the point of this column - privacy.

The rubber meets the road when the human resources department makes decisions about personnel records. What information do you collect? Why do you collect it? How do you collect it? What do you do with it? Who do you share it with? When do you delete it? All of these questions should be articulated in your Human Resources Policy for Employee Data. If you don’t have such a document, that’s probably a sign that you have some issues to deal with. If you do have such a document, is it easy for employees to access and understand? Can you explain it easily? If not, then maybe you should consider a plain language version of the policy, plus some training materials for both HR and all employees. And if you have written and rolled out the policy, have you set up metrics to monitor how well you are doing? Do you log who is looking at human resource records? Do you review the logs to make sure that when people do look at HR records they are doing so solely for job related purposes? If an HR clerk has recently broken up with another employee, would you be able to detect if they start ‘stalking’ the other employee through their HR records?

Your ability to respect your employees’ privacy and deliver an effective human resources program can be challenging in some business and technical environments. The dominant business model on the Internet is advertising which can, as Google and Facebook are finding out, lead companies astray. Let’s take time and attendence as an example. Old school punch clocks are being replaced, or have been replaced, by systems that connect directly to payroll or human resources information systems. The advantages are obvious. Time keeping is accurate and automation allows for more options around things like job costing and departmental hours. But here is something interesting. The old school punch clock is based on trust. You trust that employees will punch their own cards only and that you pay them on that basis. But punch cards need to be entered which has a cost and has transcription error risks. It makes good business sense, therefore, to automate the system. How should that be done in a privacy protective way?

One option is to replace the time clock with a biometric reader. So instead of each employee having to punch a clock, they will put their hand, or eye or face in front of a reader that verifies their presence and logs the time when they check in and check out. These kinds of biometric readers can be implemented in a privacy protective way by not storing a copy of the biometric, but by storing an encrypted deriviative of the biometric. But note that this kind of system also addresses another business problem - buddy punching, where someone’s buddy punches them in or out even though they aren’t on premise. Biometric clocks can address buddy punching, and enable automated time tracking, but they may also send a message to the work force - we don’t trust you. And if employees don’t feel trusted, they may be motivated to work around the system.

Another technology solution is for employees to install a time tracking application on their phone. Such an application can use a smart phone’s capability to locate a person. From an HR perspective, this works really well. There is no cash outlay for biometric readers or clocks. Employees will mostly already have smart phones. The data will be collected automatically as the employees move around the plant or office. But the message of distrust has been elevated, and now employees can reasonably be expected to ask, “Does your time keeping application report to you where I am when I’m off the job?” Depending on the answer to that question - which is something you need to ask your vendor in the procurement process - you may run afoul of privacy law or collective agreements.

At the end of the day, human resources departments have obligations to do workforce management effectively to meet business goals. Attracting and retaining top talent, building high performance teams, and becoming a desired employer will depend less on the automated technology systems you use and more on the trust you invest in and build with your employees. Respecting their privacy will be a key tool in your tool box for building that trust.

Technology

March/April 2019

Read column

This issue of Dialogue, and this column, are based on a theme of “Technology”. It’s early 2019 and the current technology buzzword is Blockchain, followed closely by Artificial Intelligence and Big Data. Let’s take a look at what some of this might mean in payroll and HR.

Blockchain is a particular type of what is called distributed ledger technology. This has three characteristics that define it. There is a single copy of a ledger that is shared between the users of the system. The ledger is append only and tamper resistent (you can only write to it, and you can’t change what’s been written). Finally nothing can be written to the ledger without a consensus amongst all participants that the next page (or block) of the ledger is correct. These kind of systems are designed to provide audit trails and allow transactions between parties that don’t necessarily know each other. In employment this might be a way to record hours worked by independent suppliers in a global supply chain. Because the contents of the ledger are visible to all participants and can’t be erased this is not a good system to consider where there is a risk that personal data may end up on the ledger.

The most common branch of artificial intelligence in commercial use today is Machine Learning (ML). Machine learning uses a pool of data such as a history of resumes and hiring decisions as training data to ‘learn’ how to identify candidates for hiring. The learning is done a variety of different types of algorithms. This takes some effort to ensure that bias is not introduced in the training data. For example, Amazon recently had to abandon an AI recruiting tool after it was determined that the tool showed a bias against women. “That is because Amazon’s computer models were trained to vet applicants by observing patterns in resumes submitted to the company over a 10-year period. Most came from men, a reflection of male dominance across the tech industry.” From a privacy perspective one has to wonder if losing candidates whose resumes might be in the pool of training data will have provided meaningful consent for the use of their data in this fashion. Getting the unbiased data, selecting the right algorithm and finally ensuring the privacy of the training data make for a risky proposition. Exercise due caution when considering machine learning.("scrivcmt://275DD7CD-0107-4F36-B3B7-418DFD60F247")

You should be aware that your privacy or data protection obligations start with recruitment, not with employment, and extend to all information that you obtain or collect related to potential new employees. In a nutshell you need to provide the same level of privacy protection to recruitment data as you do to employement data. Even if you are not currently looking for new hires and someone sends you a resume out of the blue, you are obliged to protect that resume as if it were employee personal data. The good news is that most privacy rule in Canada do not require consent for personal information collected, used or disclosed for the purpose of creating, maintaining or terminating an employment relationship. That being said, the price of not having to depend on consent is an obligation for transparency and an expectation of security. Make sure that you can explain how you use machine learning and be prepared to explain to a losing candidate why another candidate with a similar skill set was selected instead of them.

The final technology buzzword I mentioned above is “Big Data”. Big data refers to data sets that are too large for ‘traditional’ data processing. Good examples include global weather simulations based on hundreds of thousands of weather stations and data points or Google’s indexing and sorting of over 40,000 searches a second. It’s not clear to me that employment data will rise to the level of big data. That being said, the analytic techniques developed for big data (including machine learning) may have value for what passes for large data sets in employment. The privacy risks associated with this kind of analytics is that it is often the case that the data scientists want to have unrestricted access to pools of data to search for new insights. Making sure that you have the appropriate consent or authority to conduct these analytics is key to reducing the privacy risks associated with big data analytics.

At the end of the day remember that the type of technology you use to process information about your prospective employees, your employees and your retiree’s does not affect your obligatons to protect their privacy and to be able to demonstrate how you protect their privacy. By all means consider every technological tool at your disposal to increase the effectiveness of your payroll and HR functions, but only use the tools that can demonstrate that the appropriate controls are in place.

Compliance vs Trust

May/June 2019

Read column

If the theme of this issue is “Tax and Legislative Compliance” why is the title of this column, “Compliance vs. Trust”? Compliance is the process(es) of identifying the legislation and standards that apply to a particular enterprise, system or process and translating those into requirements or controls that an organization can apply and audit. This is not necessarily easy, but it is clear.

Trust, on the other hand, is more vague or more complex. When people trust an organization they tend to be willing to share information more easily, or work with simpler processes. There is another, more technical, version of trust related to identity proofing and cryptography. That kind of trust is more like compliance and is not what I’m talking about here.

Maintaining compliance is an ongoing effort to make sure that all compliance requirements are identified and that appropriate controls are identified and implemented. Every time there is a regulatory change, or proposed change, organizations have to adjust their internal processes and controls to address the changes. Further, if the organization is multi-national it has to monitor and implement possibly contradictory controls in different regulatory regimes. For example, the Office of the Privacy Commissioner of Canada launched a consultation on transborder dataflows.("scrivcmt://3416CEF3-B5B8-4B77-A6F4-21745D592B97") Regular readers of this column will be struck by the following:

In the absence of an applicable exception, the OPC’s view is that transfers for processing, including cross border transfers, require consent as they involve the disclosure of personal information from one organization to another. Naturally, other disclosures between organizations that are not in a controller/processor relationship, including cross border disclosures, also require consent.

This appears to be a significant change in the view of the OPC. Prior to this consultation it was understood that organizations remained accountable for data processed by their subcontractors, but that consent was not required for that processing - regardless of whether a border was crossed.

Depending on the results of this consultation and the dialog with stakeholders, organizations may have to undertake significant change initiatives to remain compliant.

Where organizations are trusted by their customers or clients, the necessary changes - if any - can be accomplished in straightforward manner. If new or updated consents will be required organizations that are trusted will find that a high percentage of their customers will consent and that their business processes should be able to continue relatively unimpeded.

Where organizations are not trusted by their customers, a process that requires a new or upgraded consent may well create risks of losing a significant number of customers.

This lesson is generalizable. If you need to use audit reports, assessments or attestations to prove that you are trustworthy you have already lost the struggle for trust. It’s not that you shouldn’t do audits, conduct assessessments or procure attestations. You clearly need to do that as a matter of due diligence. But that is table stakes in the struggle to build trust. You need to go above and beyond table stakes to be trustworthy.

People trust organizations when they assume that their information will be respected and that the organization will act on their behalf most of the time. People don’t trust organizations when they feel that they have no realistic choice except to use that organization’s services. Social networking is a case in point. It is clearly the case - given recent headlines and publicity - that a number of large provides of services to individuals are no longer trusted by increasing numbers of people. If or when a privacy protective alternative shows up that people believe can be trusted, the result could stampede away from the current market leaders. Or not. The market - and people - can be fickle.

Payroll and human resources providers can be particularly susceptible to this privacy paradox. Because consent is not required for basic payroll and HR functions, an organization could take the route of compliance only, and sacrifice employee trust. This approach minimizes change and operational costs and provides ease of reporting.

This approach is also, in my view, a mistake. Building trust with employees through transparency and the use of consent where possible will also result in heightened employee engagement, reduced turnover and and increase in the reputation of the company. In other words, building trust increases an organizations capacity to attract and retain top tier talent. Compliance just keeps you out of the headlines. I know which approach I prefer.

Management

July/August 2019

Read column

Management is about making decisions with incomplete information and ensuring that those decisions are executed. In the domain of privacy decisions need to be made about how to collect, use and process personal data. These decisions are usually captured and disseminated as policies. Decisions also need to be made about whether an organization's approach to privacy is as a compliance exercise or whether there may be a business reason to treat the processing of personal information as a source of competitive advantage. If so, then privacy may become part of an organizations strategic plan. And finally decisions need to be made about what to do when (not if) there is a signficant breach. This should be captured in an incident response or breach response plan. You could summarize these decisions as compliance, strategy and risk management.

Most organizations will have privacy policies and some will have employee privacy policies. These policies should be based on the regulatory requirements for the organization and be couched in such a fashion that they provide meaningful guidance to staff. A privacy policy that says, "All staff must adhere to appropriate regulations" is both true and useless. Management is responsible for ensuring that the policy and - hopefully - matching procedures empower and inform staff. They are your first line of defense and you need to equip them with the tools that they will need to succeed. Execution on the decision to be compliant will require that procedures and processes are available, are tested, are measured, and are regularly updated. A 10 year old privacy policy that hasn't be reviewed or updated is almost surely an indicator of a failure of execution. It may be time to implement an annual regulatory review and policy update process. Payroll professionals will be familiar with this kind of process in relation to regular updates to employment standards and tax tables.

If your organization has determined that a compliance or 'check-box' approach to privacy is insufficient or inapproprate then the responsibility for execution may move beyond the privacy team and engage other parts of the busines, such as marketing. Organization wide training and awareness of how execution on privacy will contribute to brand value will demonstrate management's committment to privacy and enable staff to meet or exceed customer expectations. Key metrics for managing and measuring your success with respect to privacy should link to business success metrics. An example would be a customer survey question such as, “Would your recommend us to your colleagues?”. This kind of customer survey will allow you to drill down on your communications, marketing and customer facing processes to simultaneously improve your privacy posture and your competitive advantage. But all of that competitive advantage can be lost if you mishandle a breach.

Having a incident or breach management policy is essential for any organization or department that processes personal data. The policy will set out who is responsible for managing breaches and who should be notified about breaches. The policy should be buttressed by procedures and training to ensure that when the breach happens, the people involved in managing the breach will be comfortable with what they have to do, when they have to do it and who else they will need to engage. And further than policies and procedures, organizations that need to manage breach risk closely will also do regular simulated breaches (often called ‘table top exercises’) where the people and roles that have been identified for incident management get together and walk through of a mock breach. This gives everybody a chance to understand what their specific responsibilities are and work through them. The last time you want to figure this out is when you are dealing with an actual breach. Execution of the decisions made at the table can still be difficult. For example it is relatively easy to agree that if there is a breach it is better for the organization to get ahead of the problem make a public announcement. But when the breach actually happens it is almost guaranteed that there will be real push-back against such a revelation. Management will need to intervene and make sure that execution matches policy decisions.

At the end of the day, if you are managing privacy or managing people who process personal data, execution of executive or management decisions will lead to better data protection and reduced risk for your organization.