Proposed Ontario employee electronic monitoring disclosure law may help firms: Lawyer

Share post:

Ontario employers should use a broad definition of the term “employee electronic monitoring” if they don’t want to run afoul of proposed changes to provincial labour law, says a Toronto privacy lawyer.

That, said Daniel Michaluk, is because there isn’t a definition in the proposed act of “electronic monitoring”.

“It will create issues for employers trying to implement this,” predicted Michaluk, a partner in the Borden Ladner Gervais law firm who practices in privacy and cybersecurity law, unless the proposed legislation is amended in committee before being passed.

Section 41.1.1 of the proposed Bill 88 — known as the Working for Workers Act, introduced last week, obliges any employer in the province with more than 25 employees to have a written policy explaining how and in what circumstances the firm electronically monitors employees. The policy also has to state how the data collected is used.

To be safe, Michaluk said employers should assume the term includes data collected from a wide range of technologies: Standard endpoint data, data from endpoint detection and response (EDR) agents, data generated from mobile device management (MDM) applications, company-owned vehicle telematics, and, of course, network behaviour analytics and video surveillance footage. It could even include logging website traffic on a web server, he said.

Note that mobile device management applications could cover not only company-owned devices but also employee-owned devices if that is mandated by the employer.

Employers must provide copies of the policy to all employees, as well as to employees assigned by temporary help agencies.

“What’s interesting is before the province created any legislation that governs privacy in the workplace, they created a more targeted piece of legislation,” Michaluk said. The Conservative government of Doug Ford has talked about bringing in a provincial private sector privacy law, but no legislation has as yet been introduced.

Among Canadian jurisdictions, only B.C., Alberta and Quebec have private sector legislation obliging firms to give notice to employees of the collection of personal information.

Ontario employers shouldn’t find the obligation onerous, Michaluk said. “It should be feasible to inventory of all these technologies without too much work and display them to employees. If we have mature systems for network security we should have inventoried this already.”

In fact, he said, it would be a matter of good data governance. “We ought to be governing our use of these technologies and more specifically the network [in the workplace] anyway.”

“If we don’t have an immediate view of what data we’re collecting across the network, let’s go do that as a matter of governance. Forget compliance. Even disclosing that [to employees] is good governance because you’re telling your users what’s going on.

“The real benefit is it may cause your users’ behaviour to change. It may cause them to understand you’ve got a network that records all sorts of data of users for legitimate uses and they should take their personal use of the network somewhere else.”

In a blog Michaluk and an associate offered detailed advice to employers on the proposed legislation. For example, for security reasons, there’s no need to disclose the software the company uses. To comply with the proposed law – unless it changes – employers could create a simple table like the one below:

Graphic from Canadian law firm describing how a company's electronic monitoring technology can be described
Source: Borden Ladner Gervais

They also noted that electronic monitoring in Ontario is permissible unless there is an agreement with employees that forbids it.

To meet the law, firms should update their hardware and software inventory, Michaluk said, as well as their acceptable use of corporate networks policies.

The post Proposed Ontario employee electronic monitoring disclosure law may help firms: Lawyer first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Broadcom backs down on VMWare pricing: Hashtag Trending for Wednesday, April 17, 2024

YouTube clamps down on third party apps that block ads. Experts predict a new cyber-war between Iran and Israel. Elon Musk backs down on his fight with the Brazilian government and Broadcom makes concessions in the face of customer outrage and European regulatory scrutiny of its new VMWare pricing. All this and more on the

The US government and Its Microsoft dependency: A cybersecurity dilemma

Microsoft's series of high-profile cybersecurity failures has once again spotlighted the complex relationship between the tech giant and...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways