Showing posts with label Employee Social Media Privacy law. Show all posts
Showing posts with label Employee Social Media Privacy law. Show all posts

Court Finds Airport Cannot Fly Under the Radar on Employee’s Email Privacy Claims

Friday, November 4, 2016

A federal district court in Virginia recently grounded an airport’s attempt to escape liability for accessing an employee’s email account. (Hoofnagle v. Smyth-Wythe Airport Commission.) The decision, which delivered a mixed result for the airport, provides important guidance for both public and private sector employers.

The employee was the airport’s operations manager and was responsible for its day-to-day operations, including responding to email from the public. To this end, the manager created a Yahoo! email account, which he used for both airport and personal business. Although the account became the airport’s official email contact, the airport did not have an email policy or any other technology policy that governed how the account was to be used.

Events came to a head when the manager, an NRA member, used the account to send a strongly worded email to U.S. Senator Tim Kaine regarding gun control. The manager signed the email using his official airport title. After learning of the email, the airport terminated the manager based not on the email’s content, but on the manager’s decision to sign it in his official capacity. The airport then used a password provided by the airport’s secretary to gain access to the account to search for business records. The manager sued and claimed that the airport’s access of the email account without his authorization violated the Fourth Amendment’s protection against unreasonable governmental searches, as well as the Stored Communications Act.

Dealing with the Fourth Amendment claim first, the court applied a two-part test used by the U.S. Supreme Court in another case involving the scope of employee privacy in electronic communications. That test looks first at the “operational realities” of a workplace to determine whether a reasonable expectation of privacy exists, and then examines whether the search was reasonable under all the circumstances.

In this case, the court found that the manager did have a reasonable expectation of privacy in the email account – primarily because the account was not clearly owned by the airport, and because the airport did not have an electronic communications policy that would have limited the manager’s expectation of privacy. Nonetheless, because the airport’s search of the account related to a non-investigatory work-related purpose, and because it was limited in scope, the search was reasonable and therefore did not violate the Fourth Amendment.

Turning to the Stored Communications Act, however, the court found that the airport could not escape liability. The SCA is a federal law that prohibits the unauthorized access to stored email and other electronic communications. But the SCA exempts “providers” of electronic communications services and end “users” of those services – and it was under these two exemptions that the airport sought refuge, arguing that the exemptions applied because the airport had provided the computer through which the manager had used the Yahoo! account. The court found neither exemption applied, though, because it was Yahoo! that provided the electronic communications service where the emails were stored, and it was the manager, who had created the account, that was the “user” of the service.

So – what guidance does this case provide for employers? First, it demonstrates that employers must be careful when using, or allowing employees to use, a third-party email provider (e.g., Yahoo!, Gmail, etc.) for company business. In those situations, employers must be sure to have clear policies in place that address the scope of employee privacy in electronic communications and the monitoring of email on workplace computers, and the policies should also clarify who it is – employer or employee – that owns the account and is authorized to access it. Had the airport in this case maintained such a policy, it would have been in a far better position. Second, this case demonstrates that an employee’s use of a work computer does not entitle an employer to access virtually any account used by the employee on the computer – even if the account is used for work purposes. Finally, the case serves as an important reminder for employers to keep abreast of changes in technology and how that technology is used in the workplace.

New Social Media Privacy Law in Maine

Wednesday, August 12, 2015

Maine has a new Employee Social Media Privacy law that prohibits employers from requiring employees and job applicants to provide access to their social media accounts. In passing the law, Maine joins at least twenty other states with similar legislation. The new law goes into effect on October 15, 2015.

The Employee Social Media Privacy law follows previous efforts by the Maine Legislature to protect the privacy of social media accounts, which efforts we have summarized here and here. Under the newly enacted law, a social media account is defined as an account with an electronic medium or service through which a user creates, shares, and views user-generated content, including emails, videos, blogs, text messages, and other similar content. Expressly excluded from the definition, however, are social media accounts that are opened at the request of an employer, provided by an employer, or intended for use primarily on behalf of an employer.

In general, the new law prohibits employers from requiring employees and job applicants to provide access to personal social media accounts, and prohibits employers from taking adverse action against an employee or applicant who refuses to provide access. The law also specifically prohibits so-called “shoulder surfing,” or the practice of requiring an employee or applicant to sign into an account in the presence of the employer. In addition, employers may not require employees or applicants to disclose any personal social media account information, add any individuals to the employee’s or applicant’s list of social media contacts, or alter account settings that would affect the ability of third-parties to view the contents of an account. Employers found in violation of the law are subject to fines assessed by the Department of Labor.

The new law does provide some exceptions and does not, for example, apply to information about an employee or applicant that is publicly available, or restrict the ability of an employer to require the disclosure of certain information that the employer reasonably believes to be relevant to an investigation of employee misconduct or workplace violations. The Employee Social Media Privacy law also clarifies that nothing in the law prevents employers from implementing policies governing the use of employer-owned electronic devices and communication systems.

Going forward, employers should review their social media policies to ensure they are consistent with the Employee Social Media Privacy law. In addition, although the new law creates an exception for social media accounts that are created or used at the request of an employer, employers may need to revisit how such accounts are used and clarify the ownership in such accounts. Failure to do so may lead to complications, not only under the Employee Social Media Privacy law, but other privacy-related laws such as the federal Stored Communications Act.