Showing posts with label Stored Communications Act. Show all posts
Showing posts with label Stored Communications Act. Show all posts

Employer Grabs the Driver’s Seat on Electronic Privacy Claims

Friday, June 2, 2017

Most employment laws are like a one-way street, where the only party with the ability to drive a claim is the employee.  When it comes to electronic privacy, however, some federal statutes allow for two-way traffic.  Although the Stored Communications Act (SCA) and the Computer Fraud and Abuse Act (CFAA) are often used by employees to assert claims (like this and this) against employers over unauthorized access to electronic communications, these laws also provide avenues for employers to pursue claims against employees for similar transgressions.

For example, earlier this year the Eleventh Circuit Court of Appeals affirmed a judgment against an employee for violations of the CFAA and SCA in a case called Brown Jordan International v. Carmicle.  The employee in the case, Carmicle, was an executive who became suspicious that a subordinate employee with whom he was having difficulty was communicating directly with the company’s CEO.  Acting on that suspicion, Carmicle took advantage of a generic email password to search the accounts of other employees.  From his search, Carmicle inadvertently learned about a planned buyout of the company by a select group of executives, and he also discovered that the company was scrutinizing his entertainment expenses.  Concerned that his job was in jeopardy after a poor financial year, Carmicle informed the company’s board of directors about the planned buyout and accused the group of executives of fraudulent activity.  This prompted the board to hire an independent investigator.  The resulting investigation failed to substantiate Carmicle’s accusations, but did disclose the extent of his email activities and the fact that he had spent over $100,000 in unauthorized business expenses.  After receiving these findings, the company terminated Carmicle and then sued him for violations of the CFAA and SCA.  The company prevailed at trial.

On appeal, Carmicle argued that the judgment on the CFAA claim was in error because the company had not experienced a “loss” recognized by the statute.  However, the Eleventh Circuit found that the CFAA’s definition of a “loss” encompassed payments that the company had paid to outside consultants to determine the extent of Carmicle’s hacking activity and so affirmed the judgment on that claim.  As for the SCA claim, Carmicle argued, among other things, that his access of employee email accounts was authorized because the company’s policy made clear that emails were subject to monitoring and were not private, and also because, as a member of senior management, he was not required to request access.   However, agreeing with the trial court, the Eleventh Circuit found that it was unreasonable to interpret the policy as authorizing Carmicle to “exploit a generic password” and to access email accounts without going through the proper channels, particularly where he did so without any reason to suspect wrongful or illegal conduct by the employees whose accounts he accessed.

The Brown decision serves as an important reminder of the leverage that statutes like the SCA and CFAA can provide to employers when it comes to protecting their proprietary electronic communications and systems.  Although employers are unlikely to find themselves very often in the position of needing that leverage in pursuit of a claim against an employee, these statutes nonetheless provide employers with a license to go down that road if needed.

New Social Media Privacy Law in Maine

Wednesday, August 12, 2015

Maine has a new Employee Social Media Privacy law that prohibits employers from requiring employees and job applicants to provide access to their social media accounts. In passing the law, Maine joins at least twenty other states with similar legislation. The new law goes into effect on October 15, 2015.

The Employee Social Media Privacy law follows previous efforts by the Maine Legislature to protect the privacy of social media accounts, which efforts we have summarized here and here. Under the newly enacted law, a social media account is defined as an account with an electronic medium or service through which a user creates, shares, and views user-generated content, including emails, videos, blogs, text messages, and other similar content. Expressly excluded from the definition, however, are social media accounts that are opened at the request of an employer, provided by an employer, or intended for use primarily on behalf of an employer.

In general, the new law prohibits employers from requiring employees and job applicants to provide access to personal social media accounts, and prohibits employers from taking adverse action against an employee or applicant who refuses to provide access. The law also specifically prohibits so-called “shoulder surfing,” or the practice of requiring an employee or applicant to sign into an account in the presence of the employer. In addition, employers may not require employees or applicants to disclose any personal social media account information, add any individuals to the employee’s or applicant’s list of social media contacts, or alter account settings that would affect the ability of third-parties to view the contents of an account. Employers found in violation of the law are subject to fines assessed by the Department of Labor.

The new law does provide some exceptions and does not, for example, apply to information about an employee or applicant that is publicly available, or restrict the ability of an employer to require the disclosure of certain information that the employer reasonably believes to be relevant to an investigation of employee misconduct or workplace violations. The Employee Social Media Privacy law also clarifies that nothing in the law prevents employers from implementing policies governing the use of employer-owned electronic devices and communication systems.

Going forward, employers should review their social media policies to ensure they are consistent with the Employee Social Media Privacy law. In addition, although the new law creates an exception for social media accounts that are created or used at the request of an employer, employers may need to revisit how such accounts are used and clarify the ownership in such accounts. Failure to do so may lead to complications, not only under the Employee Social Media Privacy law, but other privacy-related laws such as the federal Stored Communications Act.

Employer Ownership of Social Media Accounts

Tuesday, March 18, 2014

If you have a business with a social media footprint (and what business doesn’t, these days), ask yourself this question: "How confident are you that you own the social networking accounts through which you are building your customer base and brand recognition?"  If your answer is “confident,” you may want to think again.  A recent decision from a federal district court in Illinois shows that norms around ownership of business-related social media accounts are still evolving and remain murky at best.

In this case, Maremont v. Susan Fredman Design Group, Ltd., Jill Maremont was the director of marketing for a design firm, SFDG.  Maremont worked on social media campaigns for SFDG and established a blog that was hosted on SFDG’s website.  Maremont also created Twitter and Facebook accounts for herself, which she used for SFDG’s social media campaigns as well as for personal purposes. Often, Maremont would use her Twitter and Facebook accounts to post links to SFDG’s website and blog. At SFDG’s request, Maremont also created a Facebook page for the company, which Maremont accessed and administered through her own Facebook page.  Maremont kept all the log-in information for these social media accounts on a spreadsheet that she created on an SFDG-owned computer and saved on an SFDG-owned server.

Maremont was involved in a car accident that left her hospitalized.  While Maremont was on leave, employees at SFDG used the log-in information from her spreadsheet to access the social media accounts and continue SFDG’s social media campaigns.  SFDG was transparent about Maremont’s absence and even used Twitter to broadcast a blog entry explaining that a guest blogger would be filling in until her return.

Chagrined that SFDG was using her “personal” Twitter and Facebook accounts without her permission, Maremont filed suit against SFDG claiming violations of the Stored Communications Act (SCA).  The SCA is a federal law that prohibits unauthorized access to sites (like Facebook and Twitter) where electronic communications are stored.  SFDG argued that it had the right to access Maremont’s accounts and that it properly acquired and used the log-in information from Maremont’s spreadsheet.  However, the court found there were factual issues as to whether SFDG did, in fact, have sufficient authority to access the accounts and so ruled against SFDG on its motion for summary judgment.
 
Given the Maremont case and others like it, businesses should take affirmative steps to protect their rights with respect to business-related social media accounts.  Although companies with effective social media policies and proprietary information agreements with employees may still run into ownership issues around social media, they can likely be more “confident” of their ability to prevail should a dispute arise.