Ontario’s employee electronic monitoring law comes into effect today

Share post:

After six months’ notice that they had to be prepared, all provincially-regulated employers with more than 25 workers today must have a written policy describing how they electronically monitor staff. Among those to be included in the worker count are homeworkers and probationary employees, some trainees, employees on definite term or specific task contracts of any length and those on a leave of absence.

Daniel Michaluk, who focuses on privacy and cybersecurity law at Borden Ladner Gervais, said today he believes most medium and large firms in the province are prepared, judging by the number of requests to review proposed policies he has received. He’s not sure, however, about the readiness of small firms.

It shouldn’t be hard to create a policy with a list of the types of IT monitoring and what each does in generic terms, he added. A company could create a chart of its tools (for example “endpoint detection”) and a brief description of what each does (“monitors the use of workstations and compares it against a baseline to detect abnormal use”).

“The trick is to get a balance between detail and high-level information.”

“I think you can achieve meaningful information without getting into technical specifications,” he added.

But a policy that has only a brief sentence that says ‘We monitor the network and therefore you should have no expectation of privacy’ is “inadequate,” he said.

The policy “is not necessarily the end of the dialogue between an employer and their employees,” he stressed. “It could be the starting point … You invite inquiries and you should be prepared to answer them.”

An employer can have different policies for different employees. For example, provincial guidance says, a retail employer may have one policy that applies to its office staff and a different policy that applies to its in-store sales staff.

The obligation to have a policy is part of the Employment Standard Act. Note that as of January 1, 2023, business consultants and information technology consultants will no longer be covered by that act and will no longer be subject to electronic monitoring policy requirements.

The act doesn’t establish a right for employees not to be electronically monitored by their employer. Nor does it create any new privacy rights for employees. The government of Doug Ford has talked about bringing in privacy legislation but hasn’t so far.

Nor does the legislation define electronic monitoring. However, provincial guidance released in August says it includes all forms of employee and assignment employee monitoring that is done electronically. Some examples include where an employer:

  • uses GPS to track the movement of an employee’s delivery vehicle
  • uses an electronic sensor to track how quickly employees scan items at a grocery store check-out
  • tracks the websites that employees visit during working hours

The policy must state

  • a description of how and in what circumstances the employer may electronically monitor employees
  • the purposes for which the information obtained through electronic monitoring may be used by the employer
  • the date the policy was prepared
  • the date any changes were made to the policy.

In a blog earlier this year the Bennett Jones law firm noted the law does not limit the employer’s use of the information gathered through electronic monitoring. An employer can rely on the information to discipline or terminate an employee.

The post Ontario’s employee electronic monitoring law comes into effect today first appeared on IT World Canada.

Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Google Play introduces new biometric verification with a user warning

Google has recently announced updates to the biometric verification process for Google Play purchases, aiming to bolster security...

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways