Daily Archives: 5th September 2017

Privacy and the Monitoring of Communications in the Employment Setting

On 5th September 2017 the Grand Chamber of the European Court of Human Rights issued its decision in the case of Bărbulescu v. Romania, which considers the application of the right to a private and family life contained in Article 8 of the European Court of Human Rights to the monitoring of a person’s communications by their employer.

The background to the case is that an employee was dismissed by his employer for making use of company equipment and services (internet connection and computer) for personal purposes during working hours; in particular, he had been sending personal messages (some of which were of an “intimate nature”) to his brother and fiancée.  The company’s internal policies prohibited this use and after following the disciplinary process required by Romanian domestic law, he was dismissed.  He brought a case in the domestic courts and was unsuccessful in all of those courts.  He then brought a case before the European Court of Human Rights which ultimately ended up with the Grand Chamber issuing its decision on 5th September 2017.  The procedural background to the case is more fully set out in the Court’s judgment.

The Court stated that the relationship between an employee and their employer “is contractual, with particular rights and obligations on either side, and is characterised by legal subordination.” (paragraph 117) The court went on to state, at paragraph 118, that “labour law leaves room for negotiation between the parties to the contract of employment.  Thus, it is generally for the parties themselves to regulate a significant part of the content of their relations.”

In terms of the margin of appreciation afforded to States under the European Convention of Human Rights, the Court decided, at paragraph 119, that States “must be granted a wide margin of appreciation in assessing the need to establish a legal framework governing the conditions in which an employer may regulate electronic or other communications of a non-professional nature by its employees in the workplace.”  However, the Court went on to state, in paragraph 120 of its judgment, that “the discretion enjoyed by States in this field cannot be unlimited.  The domestic authorities should ensure that the introduction by an employer of measures to monitor correspondence and other communications, irrespective of the extent and duration of such measures, is accompanied by adequate and sufficient safeguards against abuse.”  These adequate and sufficient safeguards, the court stated at paragraph 121, “are essential.”

The Court sets out five factors which it considers domestic authorities should treat as being relevant:

  1. What notification has been given to the employee regarding the possibility that the employer might take measures to monitor their correspondence and other communications, and what notification the employee has been given regarding the implementation of these measures;
  2. The extent of the monitoring by the employer and the degree of intrusion into the employee’s privacy (a distinction should be drawn between simply monitoring the flow of communications and the monitoring of the content of the communications);
  3. The reasons the employer has provided to justify the monitoring of their communications and their actual content – greater justification will be required for monitoring the content as opposed to just the flow;
  4. Whether it would have been possible for the employer to have in place a monitoring system that was based on less intrusive methods and measures than simply directly accessing the content of the employee’s communications;
  5. The consequences of the monitoring for the employee subjected to it, and the use made by the employer of the results of the monitoring operation, in particular whether the results were used to achieve the declared aim of the measure;
  6. Whether there were adequate safeguards in place; especially when the employer’s monitoring operations are of an intrusive nature.

This case makes it clear that it can be legitimate for an employer to monitor, not only the flow of private communications made by an employee on company systems, but also the actual content of the correspondence.  However, employers do not have an unlimited right.

Employers will have to think carefully about what aims they are trying to achieve by the monitoring of communications by employees on company systems and whether their proposed method of monitoring is proportionate with that aim.  Furthermore, employees should be given clear and fair notice of what monitoring is taking place and the purpose for the monitoring.

Employers will also need to give careful consideration to the safeguards that they need to have in place with regards to the monitoring procedures they have in place and ensure that what safeguards they do have in place are adequate.  With regards to safeguards, the court specifically stated that employers should not have access to the actual content of the correspondence concerned unless the employee has been notified in advance.

The court has also said that domestic authorities should ensure that any employee whose communications have been monitored has access to a remedy before a judicial body and that judicial body should have jurisdiction to determine, at least in substance, how the six criteria set out in its judgment have been observed and whether the impugned measures were in fact lawful.

This decision doesn’t really change the law as it already operated.  The decision does not prevent employers from undertaking the monitoring of communications by their employees on the employer’s systems.  However, the decision does act as a useful reminder that the ability to conduct such monitoring activities is not wholly unrestrained.  The decision, coupled with the forthcoming applicability of the General Data Protection Regulation, may well provide a good opportunity for employers to review their policies in this area to ensure that they are compliant with the law.

Alistair Sloan

If you would like advice on a matter concerning data protection or privacy, then you can contact our Alistair Sloan on 0345 450 0123 or by completing the contact page on this blog.  Alternatively, you can send him an E-mail directly.

GDPR and Accountability

The Data Protection Act 1998 (“the DPA”) provides a legislative framework that is principle based, rather that one which is centred around lots of prescriptive rules.  This approach is continued under the GDPR and Article 5(1) of the GDPR sets out 6 principles that are broadly similar to the 8 principles currently found in Schedule 1 to the DPA.  The idea of accountability has been implicit in the field of data protection and privacy for some time now; however, the GDPR introduces explicate requirements around accountability, which can be found in Article 5(2).

The accountability principle means that data controllers will not only be responsible for ensuring compliance with the principles in Article 5(1) of the GDPR, but will also be responsible for being able to demonstrate compliance with the principles in Article 5(1).  The GDPR also ends the current position whereby the statutory obligations all fall upon the data controller; data processors have certain statutory obligations under the GDPR and they will also have to demonstrate complaince with their obligations.

The accountability principle essentially means that there is an expectation that organisations will have in place comprehensive, but proportionate, governance measures. Many aspects of good practice that the ICO has recommended for a long time, such as privacy impact assessments (known as “Data Protection Impact Assessments” under the GDPR) and privacy by design, will be required in certain circumstances under the GDPR.  They, of course, remain good practice where there is no legal obligation.

Under the DPA, data controllers are subject to a notification requirement which means that they must register with the ICO every year and pay a fee.  As part of the notification procedure, data controllers give the ICO certain information about what personal data they are processing and how they are using it.  The GDPR does away with the requirement to notify the ICO (it should be noted that the UK Parliament has already passed legislation which, if formally commenced, would re-introduce the registration requirement), but part of the accountability requirements under the GDPR requires certain data controllers to keep internal records of their processing activities.  It is likely that the ICO will want to see these records when conducting any of its responsibilities as the supervisory authority.  It would probably be considered good practice for all data controllers to keep such records, even if the GDPR does not require it.

All organisations with 250 or more employees are required to keep records of their processing activities.  Furthermore, organisations with fewer than 250 employees are required to maintain records of activities related to higher risk processing, such as processing personal data that could result in a risk to the rights and freedoms of individual; or processing of special categories of personal data or criminal convictions and offences.

Accountability under the GDPR is all about being able to demonstrate compliance with the law.  This will require organisations to have in place good policies and procedures and also a strong culture around record keeping.

Alistair Sloan

If you would like advice on the accountability principle of the General Data Protection Regulation, or any other information law matter, then you can contact Alistair  on 0345 450 0123 or by completing the form on the contact page of this blog.  Alternatively, you can send him an E-mail directly.