Privacy and data protection concerns are at an all time high. With tech giants under scrutiny for large-scale privacy breaches, much of the recent media attention has focused on companies' handling of client or consumer personal information. However, looming equally large are concerns regarding employers' handling (and mishandling) of employee personal information.

Which Privacy Laws Apply to your Workplace?

In Canada, the privacy law landscape is relatively new, but rapidly evolving. In 2000, the Personal Information Protection and Electronic Documents Act ("PIPEDA") was enacted in order to regulate private sector collection, use and disclosure of personal information in the course of commercial activity. However, PIPEDA has limited application in the employment context as it only applies to federally regulated employers.

British Columba, Alberta and Quebec have enacted privacy legislation for provincially regulated, private sector employers. However, there is currently no equivalent legislation in Ontario

What have the Courts Said?

In the absence of any privacy legislation that applies to private sector employers in Ontario, the courts have frequently addressed the issue of privacy in the workplace. In a landmark 2012 case, Jones v. Tsige1, the Ontario Court of Appeal confirmed the existence of the tort of "intrusion upon seclusion", or invasion of privacy, in Ontario. "Intrusion upon seclusion" can arise as a result of an intrusion into an individual's highly sensitive information, including financial or health records, sexual practices and sexual orientation, employment information, and diary or private correspondence. The implication is that employees in Ontario are entitled to a "reasonable expectation of privacy" even if they are using employer-provided technology. Unsurprisingly, there have been a number of cases in recent years in which employees have claimed "intrusion upon seclusion" in respect of personal employee information.

Additionally, in the unionized context, some arbitrators have recognized various workplace privacy rights, including drug and alcohol testing, employee surveillance and monitoring, and searches of employee property, although many of these decisions have referenced a collective agreement which specifically addresses these protections.

Best Practices

As federal and provincial privacy legislation and the common law continue to develop in this area, employers can follow a few best practices in order to minimize the risk of privacy breaches:

  1. Implement a detailed privacy policy that clearly defines privacy expectations (e.g. an employer's right to monitor the use of company email) and ensure that the privacy policy is applied consistently. While provincially regulated employers in Ontario are not required to abide by PIPEDA, the principles outlined in PIPEDA may provide a useful guide for drafting privacy policies.
  2. Do not disclose any personal employee information without first securing the employee's permission, unless the disclosure is for the purposes of complying with a court order or government mandate.
  3. Limit access to personal employee information to authorized staff.
  4. Ensure that personal employee information is stored securely.

What's Coming up Next?

Earlier this year, it seemed that provincial privacy legislation was on the horizon for Ontario, when Bill 14, the Personal Information Protect Act, was introduced at a first reading on March 21, 2018. While Bill 14 quickly passed second reading on March 22, 2018 and was referred to the Standing Committee on Justice Policy, it was not enacted prior to the provincial election in June and died on the Order Paper.

Bill 14 mirrored PIPEDA in many respects, however it included specific provisions which would regulate the handling of employee personal information by provincially regulated employers in Ontario. Bill 14 also granted specific enforcement powers to the Information and Privacy Commissioner of Ontario to initiate compliance investigations and audits in the private sector and conduct inquiries and make orders regarding privacy complaints.

While it is yet to be seen whether the Conservative government will re-introduce Bill 14, it is likely that Ontario will enact provincial privacy legislation in the future, as privacy and data protection concerns gain increasing prominence in the workplace. We will be following the development of any potential legislation closely and will publish any updates.

Footnotes

1 2012 ONCA 32.

For more information, visit our Employment and Labour blog at www.employmentandlabour.com

About Dentons

Dentons is the world's first polycentric global law firm. A top 20 firm on the Acritas 2015 Global Elite Brand Index, the Firm is committed to challenging the status quo in delivering consistent and uncompromising quality and value in new and inventive ways. Driven to provide clients a competitive edge, and connected to the communities where its clients want to do business, Dentons knows that understanding local cultures is crucial to successfully completing a deal, resolving a dispute or solving a business challenge. Now the world's largest law firm, Dentons' global team builds agile, tailored solutions to meet the local, national and global needs of private and public clients of any size in more than 125 locations serving 50-plus countries. www.dentons.com

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances. Specific Questions relating to this article should be addressed directly to the author.