Week 7 Develop a Plan to Manage Change and Analyze SC Johnson A Family Company Social Media Policies
NEW CONCERNS IN ELECTRONIC EMPLOYEE MONITORING: HAVE YOU CHECKED YOUR
POLICIES LATELY?
Janet Ford, Western Carolina University Lorrie Willey, Western Carolina University
Barbara Jo White, Western Carolina University Theresa Domagalski, Western Carolina University
ABSTRACT
Employee monitoring is a significant component of employers’ efforts to maintain employee productivity and, to a great extent, the means by which to avoid legal liabilities and business injuries which stem from employee misconduct. From sexual harassment to commercial disparagement, employers must guard against employee injury to third parties, inside or outside of the workplace. Moreover, disgruntled employees can expose valuable business trade secrets or engage in corporate espionage or sabotage. Developing technologies allow for extensive monitoring with video, phones, internet, social media and other devices with which employee behaviors can be tracked. If an employer goes too far, or not far enough, to identify and prevent employee misconduct, the legal consequences that could befall the employer are costly to both revenue and reputation. This balancing act, and the dilemma it creates, demonstrates the need for businesses to develop effective electronic monitoring policies. However, policies, once developed, need to be periodically reviewed to ensure compliance with evolving legal changes. For example, recent legal decisions from the National Labor Relations Board and emerging trends in state legislation regarding employee monitoring necessitate review of employee monitoring policies.
INTRODUCTION Employers have long had compelling reasons to monitor employees. For example, management at Los Angeles California City Hall discovered that employees were streaming the 2012 Summer Olympics over the corporate network while at work. Management’s response: “Stop watching the Olympics at work!” (Winton, 2012). Events like the Olympics or the annual March Madness basketball tournament impact corporate networks during very specific times, but imagine an employer monitoring its network and discovering that every day employees are watching over 50,000 YouTube videos, streaming over 4,000 hours of music over the internet, or streaming movies from Netflix. This discovery, in fact, prompted Proctor & Gamble to shut down access to movies from Netflix and music from Pandora for its 129,000 employees (Schwartz, 2012).
Ensuring employee productivity is a major consideration to support the monitoring processes. But employers have also long been aware of the risk of legal liability or loss to which their organizations may be exposed as a result of inappropriate employee activities online (Papa & Bass, 2004). Lawsuits based on online harassment are typically cited as a concern that justifies employee monitoring, but these are by no means the only legal claims that can arise from
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
51
employee activity online. In recent years, employee activity on social media outlets, along with employer responses to such activity, have increasingly exposed organizations to liability for unlawful discrimination (Gaskell v. University of Kentucky, 2010), violation of labor laws (Hispanics United of Buffalo, Inc., 2012), and even violation of securities laws (Bondi & Lofchie, 2011). In addition to legal liability for employee misconduct, employers are concerned about threats to their organization’s intellectual property as vital data and information are increasingly stored in digital format that is easy for employees to access and distribute outside of the organization’s protocols (Willey, Ford, White & Clapper, 2011). To support and justify employee monitoring, employers have adopted policies that attempt to define the limits of permissible employee online activity and identify forms of impermissible online activity that might expose the organization to legal liability or loss. As with all best business practices, it is not enough to simply develop an employee monitoring policy. Successful organizations regularly review and update their policies and review the enforcement of those policies to ensure that they are addressing current concerns in a way that complies with state and federal laws (Rozwell, 2012).
The monitoring of employees’ emails, internet usage, telephone communications and social media gives rise to confusing legal responses. While some law supports the necessity of monitoring, other law exists to limit the electronic monitoring of employees to protect employee privacy, leaving employers between a rock and hard place. On top of these concerns, recent rulings by the National Labor Relations Board confound the problem for organizations by strictly interpreting monitoring policies that could impact employees’ rights under the National Labor Relations Act. Additionally, numerous states have either enacted or are considering legislation that would limit the use of social media as a monitoring tool. It’s time to take out those monitoring policies, dust them off, and be sure the organization’s policies comply with law.
AN HISTORICAL LOOK AT ELECTRONIC MONITORING AND A LOOK AT RECENT TRENDS
Business organizations are able to use hardware and software to electronically monitor a wide variety of employee behaviors both in and out of the workplace. Attendance and facility use can be monitored using video surveillance and through employee badges where entry and time spent in various access areas is logged. In addition, new applications for physical access cards provide authentication and access to digital systems which may ultimately lead to the convergence of Information Technology (IT) security and physical security (Walls, 2012a). Not only can employee access cards provide a digital record of their physical whereabouts, but also global positioning system (GPS) chips and radio frequency identification (RFID) chips have been used to monitor the location of assets, such as laptops, phones, and vehicles, used by employees (Ciocchetti, 2011). Beyond monitoring the physical location of assets or employees, organizations also monitor employee productivity (Mujtaba, 2003) including the use of communication equipment and computer equipment that their employees use daily: activity on the desktop personal computers, keystroke logs, email communications, text-messages; use of social network sites, use of the internet and search engines; and telephone use, including voicemail monitoring (Ciocchetti, 2011).
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
52
A Decade of Electronic Monitoring: 1997 – 2007 Monitoring techniques differ in both their usage in the workplace and in their usage over time. Surveys of member and client companies of the American Management Association (AMA) specifically examined workplace monitoring over the ten-year period from 1997 to 2007, though not all technologies were measured for all years (AMA, 2000; AMA, 2001; AMA, 2008; Anonymous, 2005). For example, monitoring using technologies such as social network sites and blogs were not measured prior to 2007. The surveys revealed that, for the period from 1997- 2005, some monitoring techniques, such as the recording and review of telephone conversations or voicemail messages and the review and video recording of employees to assess job performance were used by less than 21% of the businesses surveyed (AMA, 2000; AMA, 2001; Anonymous, 2005). Video recordings of employee job performance grew at the very low rate of .2% per year (AMA, 2000; AMA, 2005). Although voicemail storage and review grew at a fairly high rate of nearly 14% per year during the period, its use is not widespread, at l5% of the surveyed companies (AMA, 2005).
Other employee monitoring techniques showed more widespread usage with several of those monitoring techniques showing higher rates of growth over time (see Figure 1).
Figure 1: Monitoring methods and usage percentages over time
For example, from 1997-2007, monitoring email messages grew at the highest annual rate (17% per year) while storing and reviewing computer files and computer use show very high growth rates of 12% and 11% per year respectively. Telephone use monitoring was fairly sizeable at 45% while monitoring internet connections was quite common at 66%. Both of those techniques showed low growth rates of 3% per year with telephone use being measured for the ten-year period from 1997-2007, and monitoring internet connections as measured for the eight- year period from 2000-2007 (AMA, 2000; AMA, 2001; AMA, 2008; Anonymous, 2005). Monitoring employees on social networking sites and on the blogosphere were first measured in
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
53
2007 and show rates of usage of 10% and 12% respectively (AMA 2008). New technologies and applications will continue to affect electronic monitoring. Recent Trends in Electronic Monitoring A recent trend is the use of social media by employees or potential employees. Gartner Inc., an IT research firm, conducted a survey that showed widespread adoption of social networking sites across a variety of U.S. industries including the media industry (77%), education and telecom industries (58%), and the retail industry (52%) among others (Rozwell, 2012). Organizations monitor social media use of both employees and potential employees (Willey, White, Domagalski, & Ford, 2012). Surveys of employers over the last seven years show that in 2013, 39% of employers screened potential employees using social network sites (Grasz, 2013) up from 12% (Grasz, 2006), which represents a growth rate of 225%. Information on social network sites can both help a potential employee get hired as well as hinder a potential employee from getting hired. Current employees are also monitored as to their social media use, and Gartner recommends that organizations develop social media policies, rules and training for organization employees who might be forbidden from, encouraged to use or even asked to use and track social media sites as part of their job assignments (Mann, 2012). The social network sites that organizations are monitoring fall into four major categories: public sites such as Facebook, Twitter and LinkedIn; public sites that are not based on advertising, like MyCube; semiprivate social network sites like Yammer; and private social networks such as Mumsnet (Casper, 2011). Software such as SocialLogix is able to detect multiple social media sites employees use and uncover their user profiles. While it is not uncommon to monitor social media for employee postings, particularly in the major sites such as Facebook and LinkedIn and Twitter, recent technology capabilities make it possible to monitor other social networks even if the employee posts in multiple languages. To prevent posts that are inappropriate, organizations must first monitor and intercept them using a variety of tools including network infrastructure tools, services that integrate with social media platforms and social media management software (Walls, 2012b). A REVIEW OF THE LEGAL PRESSURES SUPPORTING EMPLOYEE MONITORING To a significant and increasing extent, organizations monitor employee activity to reduce potential exposure to legal liability to third parties and also to minimize the risk of harm resulting from employee misconduct. Not only must an organization take reasonable measures to protect third parties from the wrongful conduct of employees, it must also take measures to protect itself from employee acts that might undermine the organization’s business interests. Although these concerns over employee misconduct are not new, technological developments have provided employees with increased opportunities to divert themselves from their work obligations and engage in conduct that can be detrimental to the organization. Technology has also provided expanded tools with which organizations may monitor employee activity. The legal system, however, generally lags behind the needs of the workplace in terms of determining rights and responsibilities in the face of new technology. Courts often attempt to graft new applications of technology onto traditional legal doctrine and precedents whenever sufficient parallels exist (Ciocchetti, 2011). Occasionally, however, courts must fashion new remedies to address new harms, or await legislative action, and the results are seldom uniform.
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
54
The availability of expanded technological tools raises multiple issues, such as concerns over employee privacy, discussed below, on the one hand and the reasonableness of monitoring efforts on the other hand. If reasonable means of monitoring employee activity are available, employers may be found negligent if they fail to use those means. (Papa & Bass, 2004) Similarly, where an organization does not take advantage of available technology to protect its business interests, it may be left with no remedy in the face of employee (or ex-employee) theft of intellectual property or other harmful acts directed at the business (Willey, Ford, White & Clapper, 2011). Injury to Third Parties U.S. law often places liability on employers when employee conduct results in injury to third parties, either to those outside the organization or to other employees within the organization. Because employees are hired to act on the behalf of their employer and advance the employer’s interest, they are considered agents of the employer. Under agency principles, the organization, as the principal, has the right to control the agent-employee (Restatement Agency, § 1.01). This agency relationship therefore exposes the organization to vicarious liability, under the theory of respondeat superior, for the wrongful acts of its employees committed in the scope of employment (Restatement Agency, § 2.04). Where the wrongful acts of an employee are outside the scope of employment, the organization may still be liable for harm to a third party under tort theory if the employee is on the premises of the employer or using the property of the employer or if the employer knew or had reason to know of the employee’s propensity to engage in wrongful acts (Restatement Torts, § 317). Under the theory of respondeat superior, employees are generally considered to be acting within the scope of employment if they engage in work assigned by the employer or are subject to the employer’s control (Restatement Agency, §7.07). Under respondeat superior, employees are engaged in activities they were hired to do to advance the organization’s interest, but perform those activities in a manner that inflicts harm on a third party (Papa & Bass, 2004).
If the employee’s conduct is not directed by the employer and is not intended to benefit the organization, then the employee is acting outside of the scope of employment (Restatement Agency, § 7.07). This exposes an organization to liability for employee misconduct under the tort theory of negligent retention. Organizations have a duty to prevent intentional harm or an unreasonable risk of bodily harm to third parties resulting from an employee’s misconduct, either on the employer’s premises or while using the equipment, tools, or other resources of the employer (Restatement Torts, § 317). A negligent retention theory is also available under agency law. Negligent retention under agency theory holds the employer responsible for the employee’s conduct that causes harm to a third party if the employer is negligent “in selecting, training, retaining, supervising, or otherwise controlling the agent” (Restatement Agency, § 7.05). Unlike respondeat superior, it is not necessary for the employee to be acting in the scope of employment for liability to arise. Thus, in a situation where an employee uses workplace email to threaten or harass another, the injured third party may not be able to pursue the employer under a respondeat superior theory but might be able to assert a claim against the employer under a negligent retention theory. To avoid liability under a negligent retention theory, organizations often seek to prevent employee misconduct by monitoring their activities (Papa & Bass, 2004).
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
55
The use of workplace email systems for harassment is a phenomenon with which many organizations and courts are familiar. E-harassment often involves using email to send inappropriate messages to fellow employees or other third parties, distribute pornographic or obscene material, or otherwise humiliate or intimidate others. Failure to prevent such abusive e- mail practices has led to employer liability, which in turn has given employers a strong incentive to monitor employees’ use of the company email (Papa & Bass, 2004).
Organizations may also incur liability when employee misconduct results in economic harm to third parties under a common law tort known as commercial disparagement (sometimes also referred to as trade libel or injurious falsehood). When a party makes a false statement that is harmful to the economic interests of another, that party may be liable for the economic harm if (1) he intended for the falsehood to cause harm or recognized or should have recognized the potential of the falsehood to cause harm, and (2) he knew that the statement was false or acted “in reckless disregard of its truth or falsity” (Restatement Torts, § 623A).
In addition to the common law tort claim for commercial disparagement, an injured party may also assert a claim for violation of the federal Lanham Act. Section 1125(a) of the Lanham Act creates civil liability for the use of a “false or misleading description of fact, or false or misleading representation of fact,” including commercial advertising that “misrepresents the nature, characteristics, qualities, or geographic origin of his or her or another person's goods, services, or commercial activities” (Lanham Act, §1125(a)). Under this theory of liability, an employer may be liable for the actions of employees who carelessly or deliberately misrepresent either the employer’s products or services or a competitor’s products or services.
In a case involving common law and Lanham Act claims, a human resources software provider found itself fending off a lawsuit when an anonymous individual sent a forty-three page PowerPoint presentation denigrating a competitor’s products and services to current and prospective customers of that competitor. The question before the court was whether a preliminary injunction should be issued forbidding the continued use of the presentation. In granting the plaintiff’s request for a preliminary injunction, a federal District Court in California found that the competitor was likely to succeed on the merits of its multiple claims. Although the defendant acknowledged that the presentation originated internally, it denied authorizing its widespread anonymous release. Nevertheless, the defendant was exposed to liability for this act under a variety of legal theories, including trade libel and violation of the Lanham Act (SuccessFactors, Inc. v. Softscape, Inc., 2008). Once the court entered an injunction, the defendant organization would face contempt sanctions if an employee disregarded the terms of the injunction. Business Injury from Employee Misconduct Employers must also be on guard for employee misconduct that could result in injury to the organization. Most organizations are well aware of the business risks presented by employees who do not have the employer’s interests at heart. By virtue of their access to critical business information and resources, employees have the potential to wreak havoc by misappropriating such information or resources, by publicizing confidential information, or by leaving the employment relationship and taking with them valuable information and resources. Whether such employees are motivated by greed, spite, loyalty to another, or some other impetus, the damage done to an employer’s business interests can be devastating.
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
56
Intellectual property may be one of the most valuable assets in the portfolio of an organization. Federal copyright and patent laws protect the two forms of intellectual property with which most businesspeople are familiar, and provide remedies where the rights of a copyright or patent holder are infringed (Ford, White, & Willey, 2010). However, copyrights and patents are by no means the exclusive forms of intellectual property or confidential information that need protecting. Trade secrets consist of information, in a wide variety of forms, that carries economic value as a result of not being generally known and which an organization seeks to protect from becoming known (Uniform Trade Secrets Act, §1(4)). Technology has played and will continue to play a role in the development and protection of trade secrets, but it also presents a threat to those secrets. Trade secret information is increasingly stored in digital form, which allows it to be easily accessed and shared. This becomes a disadvantage when the trade secret is accessed and then shared with someone outside of the organization. The portability of electronic devices and the popularity of cloud computing make it easy for an employee to copy trade secret information and forward or store it in locations beyond the organization’s control. Even well- meaning employees may inadvertently leave trade secret information unguarded on a laptop, smartphone, or other mobile device that may be accessed by third parties. Disgruntled employees can have an even more destructive impact by copying or forwarding trade secret information to competitors or future employers before leaving their current employment. To combat the potential impact of employees’ disclosure of trade secrets, monitoring the access to, use of, modifications or other manipulations of trade secret information is but one of many protective measures that employers take (Willey, et al., 2011).
Civil remedies for violations of the Uniform Trade Secrets Act, which has been adopted in all but a few states, include injunctions against actual or threatened misappropriation, monetary damages reflecting the plaintiff’s actual loss or the defendant’s unjust enrichment, and in cases where the misappropriation of a trade secret is willful and malicious, the plaintiff may recover double the amount of calculated damages (Uniform Trade Secrets Act §§ 2-3). However, to prevail on a civil misappropriation of trade secrets claim, the organization must establish that it took reasonable measures to protect the secrecy of the proprietary information that was taken. Courts often balance the economic value of the trade secret against the costs of protecting that secret to determine if the steps taken were reasonable. Use of automated monitoring programs to log employee access to proprietary information may be viewed as a cost effective protective measure (Willey, et al., 2011).
The criminal side of corporate espionage is best reflected in two federal laws that seek to protect trade secrets by criminalizing their theft. When proprietary business information falls into the hands of foreign interests, national security may be implicated. Accordingly, Congress has addressed both domestic and foreign corporate espionage in a pair of laws that seek to protect trade secrets. In what is frequently referred to as the Economic Espionage Act, federal law forbids the misappropriation of trade secrets through any number of means, high-tech or low- tech, if those trade secrets could benefit a foreign entity (Economic Espionage Act § 1831). The Economic Espionage Act also contains a provision that addresses theft of trade secrets without regard to whether there is a foreign entity involved (Economic Espionage Act § 1832). These provisions impose criminal sanctions on anyone who violate their terms, including business entities. The Federal Bureau of Investigation (FBI) specifically recommends that businesses protect themselves from the theft of trade secrets by “monitor[ing] computer networks for suspicious activities.” (FBI, para. 3, n.d.).
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
57
In addition to trade secrets, organizations routinely compile and store other types of confidential information, such as personnel records, financial data, litigation materials, and other sensitive data. A patchwork of federal and state laws imposes a duty on businesses in a wide variety of industries to maintain confidentiality of certain data, and imposes sanctions on businesses who fail to prevent improper disclosures. Anyone who has sought medical care in the U.S. in recent months has probably received a Health Insurance Portability and Accountability Act (“HIPAA”) statement addressing the confidentiality of patient information (42 U.S.C. §1320d-6, (2012)). Educational institutions that receive federal funds must guard the educational records of students under the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g (2012)). Attorneys are obligated to maintain the confidentiality of their client’s information (Model Rules 1.6). Under the Graham-Leach-Bliley Act, financial institutions must protect the personal information of customers (15 U.S.C. §§ 6801-6803 (2012)). These are but a few examples of privacy laws to which organizations are subject. Given the widespread importance of confidentiality across numerous fields, employers must implement measures to prevent employees from disclosing sensitive information (Matwyshyn, 2005).
LEGAL RESTRICTIONS ON ELECTRONIC EMPLOYEE MONITORING
In spite of the clear need for employee monitoring to prevent harm to third parties or to the organization itself, monitoring policies and practices have faced numerous legal challenges from employees and government agencies responsible for regulating the workplace. These challenges often are based on common law privacy rights, federal privacy laws, labor relations statutes, and state laws limiting employer access to employees’ personal online accounts. Privacy Rights of Employees While employers face a wide range of legal liability for not monitoring employees, some scholars argue that “…the American legal system has failed to: (1) keep up with today’s powerful monitoring technology and (2) provide the necessary privacy protection for employees” (Ciocchetti, 2011, p. 289). Attempts to address this failure and to protect both employer and employee rights have been inconsistent. To the extent that employee privacy concerns are implicated in an organization’s monitoring policy, the outcome often hinges on whether an employee has a reasonable expectation of privacy as to the activity being monitored. This inquiry, in turn, requires a distinction between a public employee and a private employee. Private employees will find little in the United States Constitution to define or protect workplace privacy. While the United States Constitution does not specifically address a right of privacy, the courts have determined that public employees do have some protection from unreasonable searches and seizures from governmental employers (City of Ontario v. Quon, 2010). The Fourth Amendment puts some limits on monitoring government workers but only when the employee has a reasonable expectation of privacy. However, the Fourth Amendment protections do not translate to the private sector (Levinson, 2012). Even when a reasonable expectation of privacy exists for a public employee, the employer’s actions will be deemed lawful if the reasons for the monitoring are deemed legitimate (City of Ontario v. Quon, 2010).
State law addresses privacy disputes with a variety of privacy principles that are generally referred to as “invasion of privacy” torts. All privacy torts require the party claiming injury to have a reasonable expectation of privacy violated by the conduct of another. The
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
58
standard is not subjective; the expectation of privacy must be one that is considered by society to be reasonable (Katz v. United States, 1967). While several torts can be categorized under the umbrella of “invasion of privacy,” two widely recognized privacy torts are intrusion upon seclusion and publicity of private facts. Both of these torts require the plaintiff to establish that the privacy violation be extreme and unreasonable. Intrusion upon seclusion occurs when a person “. . . intentionally intrudes, physically or otherwise, upon the solitude or seclusion of another or his private affairs or concerns … if the intrusion would be highly offensive to a reasonable person” (Restatement Torts § 652B). The tort of publicity of private facts involves “. . . giving publicity to a matter concerning the private life of another . . . if the matter publicized is of a kind that (a) would be highly offensive to a reasonable person, and (b) is not of legitimate concern to the public” (Restatement Torts § 652E). The expectation of privacy, however, is greatly reduced in employment settings. This is particularly true where employers provide resources such as computers, email, phones, or internet access to facilitate employee productivity and where employers have notified employees that activity on company-provided resources will be monitored. Questions of unreasonableness, private affairs or offensiveness are resolved by courts on a case-by-case basis, but the workplace is not often viewed by courts as an area where a reasonable expectation of privacy is likely to exist.
Electronic Communications Privacy Act of 1986 The federal Electronic Communications Privacy Act of 1986 (ECPA) consists of two titles on which lawsuits regarding employee monitoring have been based, the Wiretap Act and the Stored Communications Act (SCA) (Electronic Communications Privacy Act). Since privacy is the intent of the law, certain applications of the ECPA support privacy in the workplace, especially for personal email accounts and social media postings. The problem is that the law is complex and courts have different views on how the law should be interpreted. The ECPA provides a civil remedy to the individual against a person or entity who intentionally intercepts an electronic communication or who obtains unauthorized access to stored electronic communications. While the statute appears to be on point when discussing workplace privacy, the interpretation of the law and its exceptions are unsettled as applied to electronic monitoring in the workplace.
The Wiretap Act prohibits interception, use and disclosure of contents of electronic communications and an interception is defined as “the aural or other acquisition of the contents of any wire, electronic, or oral communication through the use of any electronic, mechanical or other device” while the communication is in transit (Electronic Communications Privacy Act, § 2510 (4)). The “interception in transit” requirement is often discussed in monitoring cases (Global Policy Partners v. Yessin, 2010).
The second title of the ECPA, the Stored Communications Act defines “electronic storage” as “(A) any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission thereof; and (B) any storage of such communication by an electronic communication service for purposes of backup protection of such communication” (Electronic Communications Privacy Act, § 2510(17)). Overall, court opinions generally hold that when employer’s access and monitor stored emails on work computers, employees have no reasonable expectation of privacy even when using an employer’s computer for personal reasons. Use of workplace computers “…carries with it social norms that effectively diminish the
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
59
employee's reasonable expectation of privacy with regard to his use of his employer's computers” (Sporer v. UAL Corp., 2009 WL 2761329 at *5).
ECPA is not applicable to systems for electronic communications that are “configured so that such electronic communication is readily accessible to the general public” (Electronic Communications Privacy Act, § 2511(2)(g)(i)). Therefore, organizations are free to monitor and intercept communications employees make when those communications are available to the public, regardless of whether the communication is work related or not (Abril, 2012). Some courts have interpreted “readily accessible to the general public” as a broad exception that provides no protection for employee privacy. Therefore, organizations that provide electronic communications service or Internet access to employees for work-related purposes may access all communications (Abril, 2012).
Consent, authorization and the ordinary course of business are exceptions under the ECPA that are often raised by employers in ECPA litigation. In the employment area, consent is the exception to the Wiretap Act that most limits employees’ rights regarding organizational monitoring and interception of electronic communications. Courts do look at the facts of a case to determine whether the employees knew they were being monitored and whether they voluntarily consented to the monitoring (Levinson, 2011). In making these determinations, courts often refer to organizational policies. Consent cases most often involve telephone rather than email interception but the analogy is similar. Employees can authorize employers to access stored emails under the SCA through workplace policies but that authorization generally does not extend to personal and password protected email accounts stored on outside servers (Pure Boot Camp v. Warrior Fitness Boot Camp, 2008). Employer monitoring of employee electronic communications under the Wiretap Act is permitted when such monitoring is carried out in the ordinary course of business, another exception to the ECPA. Ordinary course of business consists of “a routine activity of the business in furtherance of a legitimate business interest” (Arias v. Mutual Central Alarm Services, Inc., 1998, p. 416).
Employers routinely request job candidates’ usernames and passwords to access social networking sites when considering candidates for employment (Willey, et al., 2012), but employer monitoring of social networking sites sometimes continues even after the initial hire. Accessing and monitoring social networking sites without employee authorization raises legal concerns under the ECPA. What steps the account user takes to maintain privacy on a social networking site and what posted content is meant to be private and what is meant to be public are considerations when courts review alleged ECPA violations. Use of social networking sites as the means to communicate among employees regarding work-related matters also muddies the distinction between personal content and work-related content. In most states, with proper authorization, the employer can access and monitor social networking sites, but the question of how authorization was obtained has been raised in the courts. Moreover, the public debate over the use of social media monitoring in the workplace has resulted in legislative prohibitions to its use in some states and in similar pending legislation in many other states (Employer Access, 2013).
The National Labor Relations Act (NLRA) Further complicating the balancing act between protecting an organization’s interest in monitoring employee electronic activities and protecting employees’ rights in the workplace is the National Labor Relations Act of 1935 (NLRA). Generally thought of as the law that protects
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
60
employees’ rights to organize, the NLRA includes provisions that apply to unionized and non- unionized employees. Importantly, the NLRA protects the right of employees to engage in concerted and collective activity in an effort to improve the terms and conditions of their employment. Employees have the right to discuss terms and conditions of employment with other co-workers and third parties and to take action to improve working conditions either individually or with other co-workers without retaliation by employers (National Labor Relations Act § 7). Employee conversations and expressions involving working conditions, wages, job performance issues, and problems with supervisors, for example, are protected. Such conversations are deemed lawful concerted activities. The National Labor Relations Board (NLRB) is the administrative agency responsible for implementing and enforcing the NLRA. The NLRB has dispute resolution as well as regulatory functions (National Labor Relations Act § 3). In recent decisions, the NLRB has made it clear that while employers may monitor employees’ electronic expressions, adverse action against employees for protected concerted activities or policies infringing on or chilling employees’ ability to exercise their rights are unlawful. (OM 2011). Determinations as to whether employee posts are protected by the NLRA are made by the NLRB based on whether there was concerted activity, meaning that the employee actions are taken with or on the authority of co-workers and not solely on the employee’s own behalf (Meyers Industries 1984). At the outset of this discussion, it should be noted that the validity of some of the NLRB decisions mentioned below is in question as a result of legal challenges to several of President Obama’s appointments of NLRB members. The President is entitled to make recess appointments of federal officers when the Senate is in recess, and the current challenges revolve around whether the Senate was actually in recess or was technically in session when President Obama made the appointments. The United States Supreme Court heard oral arguments on the question of these appointments in January 2014, and a decision has not yet been announced. A determination by the high court that the appointments were invalid could, in turn, invalidate NLRB decisions made when there were not enough legally appointed members to constitute a quorum (NLRB v. Noel Canning, 2013). Beyond this immediate question, NLRB policies and practices may also be subject to court challenges. With these limitations in mind, a review of the NLRB’s current philosophy regarding social media and employee monitoring is instructive to employers who are developing or reviewing their social media policies. In recent decisions, the NLRB found several employee-Facebook postings to be concerted activity and, therefore, protected under the NLRA. In one case an employee posted comments that her non-profit employer did not help clients sufficiently and that a co-workers’ job performance was lacking. Those postings were made in anticipation of a meeting with a supervisor and the employee solicited responses from her co-workers regarding her complaints thus her postings were protected (Hispanics United of Buffalo, Inc., 2012). Another case of social media postings falling within the protection of concerted activity involved comments and photographs derogatory of an employer event and the impact the disappointing event would have on sales and commissions. The Facebook postings were made after employees discussed their concerns among themselves and with a sales manager (Karl Knauz BMW, Knauz Auto Group, 2012). In addition, Facebook discussions between employees and a former employer expressing upset and concern over the employer’s failure to withhold sufficient state taxes and its inability to complete paperwork properly was also protected when one employee stated that the issue was to be discussed with management at a staff meeting (OM 2011).
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
61
However, not all employee conversations or expressions meet the concerted activity standard. Statements that are defamatory and maliciously false, disrupt business operations, or undermine supervisory authority may not be protected although that determination is dependent on the place where the discussion took place, its subject matter, the contents of an employee’s outburst and whether the expression was provoked by an unfair labor practice (Atlantic Steel 1979). In a case involving a reporter who “tweeted” offensive comments that the employer found to be unprofessional and inappropriate, the discipline imposed was lawful since the “tweets” did not involve conversations with other employees and did not relate to the terms and conditions of his employment. Moreover, disparaging comments made by an employee about her employers posted on the “wall” of her senator’s Facebook page were not protected. The employee did not discuss the issues with co-workers at any time before or after the posts were made, nor did she raise any of the issues to management (OM 2011). Employers who have drafted well-intentioned electronic communication policies have found themselves attempting to persuade the NLRB, often unsuccessfully, that their policies do not discourage protected concerted activity. To offer guidance in this often challenging area of law, the General Counsel office of the NLRB issued an Operations Management Memo on May 30, 2012. This OM Memo reviewed several social media policies that were found to have provisions that could be interpreted as unlawfully restricting protected collective activity. The OM Memo concluded with an acceptable social media policy that General Counsel found to be lawful (OM 2012). The policies found to be flawed by General Counsel typically included language that was considered overbroad in that it could be interpreted as discouraging protected concerted activity. One employer’s social media policy instructed employees “[not to] release confidential guest, team member, or company information” (OM 2012, p. 4). Although this language may seem like a reasonable attempt to protect proprietary employer information as well as the confidentiality of the organization’s guests and workers, General Counsel determined that it could be interpreted as forbidding employees from discussing the terms and conditions of their employment, rendering the policy provision unlawful. A second policy advised employees that anything employment-related that they post must be “completely accurate and not misleading” (OM 2012, p. 6). While this provision may be an attempt by the employer to avoid charges of commercial disparagement or defamation, General Counsel objected to this language because it could be interpreted to forbid discussions of the terms and conditions of employment or criticism of the employer’s policies and practices. This same policy also instructed employees to make certain that they did not post non-public information on a public site. This provision, while a seemingly reasonable attempt to address the employer’s confidentiality obligations as well as protect its proprietary information, suffered a fatal flaw in that it specifically included information about employees’ terms and conditions of employment in the definition of “non-public information.” Yet another flaw in this same policy involved a prohibition on the use of the employer’s logo in employee postings, which General Counsel determined could unlawfully prohibit employees from posting photographs of workers engaged in protected concerted activities, such as picketing with signs containing an image of the company’s logo. General Counsel did, however, find prohibitions on the posting of safety performance of its products and attorney-client privileged material to be lawful, since these did not mention employees or any potential concerted activity (OM 2012). This same employer was also apparently concerned about the potential for workplace harassment or discrimination claims, as it included a provision in its social media policy
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
62
instructing employees to avoid posting material that is “offensive, demeaning, abusive, or inappropriate” (OM 2012, p. 8). Employees were also cautioned against “friending” co-workers on outside social media sites if communication with those co-workers would be inappropriate in the workplace. The policy concluded with a “savings clause” asserting that the policy would “be administered in compliance with applicable laws and regulations (including Section 7 of the National Labor Relations Act)” (OM 2012, p. 8). General Counsel determined that the prohibition against “offensive, demeaning, abusive, or inappropriate” comments was overbroad in that it could be interpreted to include criticisms or complaints about the terms and conditions of employment. The failure of the employer to identify which communications with co-workers would be inappropriate rendered the “friending” caution ambiguous and thus an unlawful discouragement of communication among co-workers. A provision directing employees to “report any unusual or inappropriate internal social media activity was found unlawful in that it would likely discourage employees from engaging in protected concerted activity. The employer’s “savings clause” was insufficient to overcome the ambiguities and overbreadth of the objectionable policy provisions (OM 2012). Confidentiality concerns over “personal information” that were reflected in another employer’s social media policy were also found to be overbroad by General Counsel because “personal information” could be interpreted to include the employees’ “terms and conditions” of employment. A provision prohibiting employees from commenting on legal matters or disputes was also found unlawful. Unlike a more narrow provision that forbids disclosure only of attorney-client privileged information, a prohibition against commenting on legal matters or disputes could be interpreted as forbidding the protected discussion of employee concerns. The employer advised employees to adopt a professional and courteous tone in their online postings, but General Counsel found this provision to be unlawful because it might discourage discussion of controversial subjects, such as protected concerted activity (OM 2012). A provision encouraging employees to address workplace concerns directly with co-workers and supervisors, rather than airing them on social media, was also found to be unlawful, as it might discourage employees from initiating or taking part in protected concerted activity. As with the previous employer’s policy, a savings clause was determined to be insufficient to cure the flaws identified by General Counsel (OM 2012). The fourth policy reviewed by General Counsel contained an overbroad prohibition on the posting of non-public information, which could be interpreted to include information on the terms and conditions of employment. A prohibition on the posting of confidential or proprietary information was ruled to be overbroad for the same reason, as was a prohibition on postings that might harm the image or reputation of the employer. However, the employer’s prohibition on the posting of “harassment, bullying, discrimination, or retaliation” was deemed lawful, as it could not reasonably be interpreted as including protected concerted activity. A provision allowing internal concerted activity and discussions about the terms and conditions of employment while forbidding the same activity and discussions on a public forum was deemed unlawful and could not be salvaged by a savings clause (OM 2012). The fifth policy contained a requirement that employees report unsolicited or inappropriate postings to a designated company official. This was deemed unlawful because employees could interpret this provision as requiring them to report concerted action, thus chilling such protected action. General Counsel also invalidated a provision forbidding postings that disparage or defame the employer, as this could discourage criticisms of the employer’s policies or practices. A provision forbidding certain postings on company time were found
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
63
unlawful because the NLRA grants workers the right to engage in concerted activity on the employer’s premises during non-work times such as breaks (OM 2012). In the sixth policy reviewed by General Counsel, restrictions on employee contact with the media and with government agencies absent prior approval by or notice to the employer were found to be unlawful limitations on concerted activity, which includes the right to communicate with third parties concerning the terms and conditions of employment (OM 2012). The OM Memo concluded with a seventh policy that had been revised from an earlier version and which apparently cured flaws identified in the earlier version. It should be noted that the policy found to be acceptable in its entirety, attached below as Appendix A, addresses social media only and not other forms of electronic activity, and that it also references documents and policies that are not included in the OM Memo. Nevertheless, it provides useful guidance for organizations seeking to draft and implement a policy that does not inadvertently chill protected employee activity. General Counsel noted with approval that the seventh policy included examples of activity that was clearly not protected, thus clarifying and removing any potential ambiguities. The policy carefully identifies and narrowly defines prohibited communications to include only those that may properly be forbidden, such as disclosure of trade secrets or communications that would constitute unlawful harassment or create a hostile work environment. The approved policy thus strikes an appropriate balance between serving the employer’s interest in avoiding inappropriate employee online communications and also protecting the rights of employees to freely discuss the terms and conditions of their employment. (OM 2012; App. A). State Restrictions on Use of Social Media to Monitor The increasing popularity of social media in both personal and business applications has naturally led some employers to seek access to their employees’ social media accounts, whether private or workplace-related. It has become common for an employer to ask applicants for access information, such as usernames and passwords, to social media accounts. Once the applicant is employed is it also common for an employer to continue monitoring her or his social media accounts. This clearly places applicants and employees in an uncomfortable dilemma: either grant access to what one intended and wished to keep restricted to a narrow audience or refuse access, which would likely be viewed negatively by an employer or potential employer. In response to the privacy concerns of prospective and current employees, a number of states have either passed or are considering legislation forbidding employers from even inquiring as to whether these individuals have social media accounts as well as from requesting access to those accounts (Employee Access, 2013). In many of the states with current or pending legislation limiting employer access to employees’ social media accounts, there are exceptions that allow access when necessary to investigate allegations of work-related misconduct or the disclosure of proprietary information. Some states may also allow employers to monitor employee activity that takes place using employer-provided resources, such as the employer’s email system or internet server (See, e.g., Cal. Lab.Code §980).
REVISITING MONITORING POLICIES Clearly, the legal impacts associated with the failure to monitor are considerable and compel an organization to monitor employees to mitigate the reputational and financial consequences of potential unlawful and wrongful conduct. On the other hand, the operation of an
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
64
organization is dependent on its employees and their perception of trust regarding the organization for which they work. A mix of federal and state laws and court decisions, recent NLRB decisions, and state legislative actions regarding social media and monitoring mandate that the organization’s existing monitoring policies be reviewed and revisited. A logical starting point would be to review the organization’s existing policies to see whether or to what extent they address concerns about an employee’s electronic activities. Where employee monitoring policies already exist, they may be updated or modified to reflect current conditions or workplace needs. It may be helpful to include specific examples of what type of employee activities are permitted and what type of employee activities are forbidden. Critical concerns such as the importance of protecting proprietary or other confidential information should be identified and explained to employees. Ideally, a policy should provide employees with the contact information of a person or persons within the organization who can answer questions or address concerns that an employee might have concerning the policy (Mann, 2011). Employees should be made aware of the monitoring policy prior to its implementation, and should be periodically reminded of the policy. While in most cases notice of monitoring activities by an organization are not required by law unless applicable state law exists, consent of the employee to the monitoring provides the broadest protection for the organization. Implied consent such as computer screen warnings also provide consent when the employee uses the device after the warning banner is viewed (United States v. Greiner, 2007). Organizations may be successful in defending against invasion of privacy lawsuits when the monitoring policy includes a form for the employee to sign acknowledging her or his awareness of the policy and/or consenting to its provisions. Clear notice of monitoring activities and consent by the employee reduces the employee’s expectation of privacy, the basis of privacy violation claims. Notifying employees of the employer’s monitoring policies also serves an additional purpose. Should a legal dispute arise regarding wrongful employee conduct and injury to others, a monitoring policy will allow the organization to document attempts to restrict unlawful employee conduct, potentially limiting a business’s liability exposure. (Ciocchetti, 2011). Given this benefit, it might be tempting to establish a complete ban on use of electronic devices for non-work-related activities. However, such a policy may not pass legal muster due the problematic nature of enforcing such a strict policy. The lack of enforcement might prove to hinder the organization’s efforts to protect third parties from employee misconduct and also to protect the business’s own interests. A lack of enforcement might also send an unintended message to employees that the organization does not seriously enforce the policy and lacks commitment to the policy (Stengart v. Loving Care Agency, 2009). Consistent enforcement of a monitoring policy is needed to convince employees, and courts, of the seriousness of policy violations (Huth, 2013). The objective of any policy is to allow the employee to conform her or his behavior to that established within the policy. To that end, clear enforcement policies, indicating the justifications necessitating monitoring, will help avoid the uncertainty and concern employees experience in the monitored workplace environment and allow employees to align behaviors with policy (Huth, 2013). Emphasizing the importance of monitoring for the organization and the reasons supporting monitoring provide a foundation on which employees can base their workplace conduct (Henle, Kohut & Booth, 2009). Once developed or revised, any monitoring policy should be carefully reviewed, prior to its implementation, by an attorney knowledgeable of both the federal laws and the law of the states in which the business operates. An organization operating in more than one state may be
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
65
subjected to a variety of state laws concerning employee monitoring that can result in different outcomes from one state to the next, so attention to variations in state laws is crucial. Importantly, employee monitoring policies, like all employment policies, should be reviewed on a regular basis to determine their effectiveness and continued legality in the ever-changing landscape of employment law.
CONCLUSION Employers face a wide array of legal consequences for failing to reasonably track employee behavior and conduct that result in injuries to others. The competitive marketplace also makes an employer wary of employees who may injure the business by exposing trade secrets or revealing business processes to the competition. Technology has greatly expanded the means by which employers can protect themselves and others but that technology comes at a price. Overzealous monitoring of employees can result in claims of invasion of privacy or other legal violations and more recently claims of violations of the NLRA or newly created state statutes. The line between legal and illegal employee monitoring can be a fine one and it serves to place employers in a difficult and potentially costly position. In light of new legal developments, revisiting existing monitoring policies can serve to reduce potential violations of employees’ rights while maintaining the level of monitoring necessary to achieve organizational goals.
APPENDIX A: SAMPLE SOCIAL MEDIA POLICY APPROVED BY THE NLRB
The following example of a Social Media Policy was reprinted in its entirety (OM 2012, pp. 22-24).
Social Media Policy Updated: May 4, 2012 At [Employer], we understand that social media can be a fun and rewarding way to share your life and opinions with family, friends and co-workers around the world. However, use of social media also presents certain risks and carries with it certain responsibilities. To assist you in making responsible decisions about your use of social media, we have established these guidelines for appropriate use of social media. This policy applies to all associates who work for [Employer], or one of its subsidiary companies in the United States ([Employer]). Managers and supervisors should use the supplemental Social Media Management Guidelines for additional guidance in administering the policy. GUIDELINES In the rapidly expanding world of electronic communication, social media can mean many things. Social media includes all means of communicating or posting information or content of any sort on the Internet, including to your own or someone else’s web log or blog, journal or diary, personal web site, social networking or affinity web site, web bulletin board or a chat room, whether or not associated or affiliated with [Employer], as well as any other form of electronic communication. The same principles and guidelines found in [Employer] policies and three basic beliefs apply to your activities online. Ultimately, you are solely responsible for what you post online. Before creating online content, consider some of the risks and rewards that are involved. Keep in mind that any of your conduct that adversely affects your job performance, the performance of fellow associates or otherwise adversely
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
66
affects members, customers, suppliers, people who work on behalf of [Employer] or [Employer’s] legitimate business interests may result in disciplinary action up to and including termination. Know and follow the rules Carefully read these guidelines, the [Employer] Statement of Ethics Policy, the [Employer] Information Policy and the Discrimination & Harassment Prevention Policy, and ensure your postings are consistent with these policies. Inappropriate postings that may include discriminatory remarks, harassment, and threats of violence or similar inappropriate or unlawful conduct will not be tolerated and may subject you to disciplinary action up to and including termination. Be respectful Always be fair and courteous to fellow associates, customers, members, suppliers or people who work on behalf of [Employer]. Also, keep in mind that you are more likely to resolve work-related complaints by speaking directly with your co-workers or by utilizing our Open Door Policy than by posting complaints to a social media outlet. Nevertheless, if you decide to post complaints or criticism, avoid using statements, photographs, video or audio that reasonably could be viewed as malicious, obscene, threatening or intimidating, that disparage customers, members, associates or suppliers, or that might constitute harassment or bullying. Examples of such conduct might include offensive posts meant to intentionally harm someone’s reputation or posts that could contribute to a hostile work environment on the basis of race, sex, disability, religion or any other status protected by law or company policy. Be honest and accurate Make sure you are always honest and accurate when posting information or news, and if you make a mistake, correct it quickly. Be open about any previous posts you have altered. Remember that the Internet archives almost everything; therefore, even deleted postings can be searched. Never post any information or rumors that you know to be false about [Employer], fellow associates, members, customers, suppliers, people working on behalf of [Employer] or competitors. Post only appropriate and respectful content
Maintain the confidentiality of [Employer} trade secrets and private or confidential information. Trade secrets may include information regarding the development of systems, processes, products, know-how and technology. Do not post internal reports, policies, procedures or other internal business-related confidential communications.
Respect financial disclosure laws. It is illegal to communicate or give a “tip” on inside information to others so that they may buy or sell stocks or securities. Such online conduct may also violate the Insider Trading Policy.
Do not create a link from your blog, website or other social networking site to a [Employer] website without identifying yourself as a [Employer] associate.
Express only your personal opinions. Never represent yourself as a spokesperson for [Employer]. If [Employer is a subject of the content you are creating, be clear and open about the fact that you are an associate and make it clear that your views do not represent those of [Employer], fellow associates, members, customers, suppliers or people working on behalf of [Employer]. If you do publish a blog or post online related to the work you do or subjects associated with [Employer], make it clear that you are not speaking on behalf of [Employer]. It is best to include a disclaimer such as “The postings on this site are my own and do not necessarily reflect the views of [Employer].”
Using social media at work Refrain from using social media while on work time or on equipment we provide, unless it is work-related as authorized by your manager or consistent with the Company Equipment Policy. Do not use [Employer] email addresses to register on social networks, blogs or other online tools utilized for personal use. Retaliation is prohibited [Employer] prohibits taking negative action against any associate for reporting a possible deviation from this policy or for cooperating in an investigation. Any associate who retaliates against another associate for
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
67
reporting a possible deviation from this policy or for cooperating in an investigation will be subject to disciplinary action, up to and including termination. Media contacts Associates should not speak to the media on [Employer’s] behalf without contacting the Corporate Affairs Department. All media inquiries should be directed to them. For more information If you have questions or need further guidance, please contact your HR representative.
REFERENCES Abril, P. S., A. Levin, & A. Del Riego (2012). Blurred boundaries: Social media privacy and the twenty-first century
employee. American Business Law Journal, 49, 63-167. American Management Association (AMA) (2000). 2000 Workplace monitoring & surveillance survey: Summary
of key findings. American Management Association. Retrieved July 19, 2012 from http://www.jinbo.net/ maybbs/pds/www/cyberight/monitr_surv.pdf
American Management Association (AMA) (2001). More companies watching employees, American Management Association annual survey reports. American Management Association. Retrieved August 1, 2012 from http://www.keylogger.org/articles/american-management-association-ama/more-companies-watching- employees-american-management-association-annual-survey-reports-2.html
American Management Association (AMA) (2005). 2005 Electronic monitoring & surveillance survey. American Management Association. Retrieved July 10, 2013 from http://www.epolicyinstitute.com/ survey2005Summary.pdf
American Management Association (AMA) (2008). 2007 Electronic monitoring & surveillance survey: Over half of all employers combined fire workers for e-mail and internet abuse. American Management Association. Retrieved July 12, 2012 from http://press.amanet.org/press-releases/177/2007-electronic-monitoring- surveillance-survey/
Anonymous (2005). Many companies monitoring, recording, videotaping (and firing) employees. The Journal of the Connecticut Business & Industry Association, 83(6). Retrieved August 30, 2012 from http://www.cbia.com/cbianews/2005/07/200507_CompaniesMonitoring.htm
Arias v. Mutual Cent. Alarm Servs., Inc., 202 F. 3d 533 (2d Cir. 1998). Atlantic Steel, 245 NLRB 814 (1979). Bondi, B.J. & S.D. Lofchie (2011). The Law of Insider Trading: Legal Theories, Common Defenses, and Best
Practices for Ensuring Compliance. New York University Journal of Law & Business, 8, 151- 201. Cal. Lab. Code §980 (Deering 2014). Casper, C. (2011). Hype cycle for privacy, 2011. Gartner, Inc. Retrieved June 20, 2012 from
http://www.gartner.com/ id=1751128 City of Ontario v. Quon, 560 U.S. 746 (2010). Ciocchetti , C. A. (2011). The eavesdropping employer: A twenty-first century framework for employee monitoring.
American Business Law Journal, 48, 285-359. Economic Espionage Act, 18 U.S.C. §§1831-1839 (2012). Electronic Communications Privacy Act of 1986, 18 U.S.C. §§ 2510-2712 (2012). Employer Access to Social Media Passwords and Usernames (2013). National Conference of State Legislatures.
Retrieved March 28, 2013 from http://www.ncsl.org/issues-research/telecom/employer-access-to-social- media-passwords-2013.aspx
Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g (2012). Federal Bureau of Investigation (n.d.). The insider threat: An introduction to detecting and deterring an insider spy.
United States Department of Justice (no date). Ford, J. C., B. J. White, & L. Willey (2010). Software development and intellectual property: What you don’t know
can hurt you. Issues in Information Systems, 11(1), 77-84. Gaskell v. University of Kentucky, No. 09-244-KSF, 2010 U.S. Dist. LEXIS 124572 (E.D. Ky Nov. 23, 2010). Global Policy Partners v. Yessin, 686 F. Supp. 2d 642 (E.D. Va. 2009). Graham-Leach-Bliley Financial Modernization Act of 1999, 15 U.S.C. §§ 6801-6803 (2012).
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
68
Grasz, J. (2006). One-in-four hiring managers have used internet search engines to screen job candidates; one-in-ten have used social networking sites, CareerBuilder.com survey finds. Careerbuilder.com. Retrieved April 19, 2012 from http://www.careerbuilder.com/share/aboutus/pressreleasesdetail.aspx? id=pr331&ed= 12%2F 31 %2F2006&sd=10%2F26%2F2006
Grasz, J. (2013). More employers finding reasons not to hire candidates on social media, finds CareerBuilder survey. Careerbuilder.com. Retrieved September 1, 2013 from http://www.careerbuilder.com/share/aboutus/pressreleasesdetail.aspx?sd=6%2F26%2F2013&id=pr766&ed =12%2F31%2F2013
Health Insurance Portability and Accountability Act, 42 U.S.C. § 1320d-6 (2011). Henle, C. A., G. Kohut, & R. Booth (2009). Designing electronic use policies to enhance employee perceptions of
fairness and to reduce cyberloafing: An empirical test of justice theory. Computers in Human Behavior, 25(4), 902-910.
Hispanics United of Buffalo, Inc., 359 NLRB 37 (2012). Huth, C. L. (2013). The insider threat and employee privacy: An overview of recent case law. Computer Law &
Security Review, 29(4), 368-381. Karl Knauz BMW, Knauz Auto Group, 358 NLRB 164 (2012). Katz v. United States, 389 U.S. 347 (1967). Lanham Act, 15 U.S.C. § 1125(a) (2012). Levinson, A. R. (2011). Workplace privacy and monitoring: The quest for balanced interests. Cleveland State Law
Review, 59, 377-397. Levinson, A. R. (2012). Toward a cohesive interpretation of the electronic communications privacy act for the
electronic monitoring of employees, West Virginia Law Review, 114, 461-530. Mann, J. (2011, May 11). Take four initial steps toward a social media policy, Gartner, Inc. Available:
www.gartner.com/id=1664315. Mann, J. (2012, March 9). Categorize employees when creating enterprise social media policy, Gartner, Inc.
Available: http://www.gartner.com/id=1946315 Matwyshyn, A. (Fall 2005). Material Vulnerabilities: Data privacy, corporate information security, and securities
regulation. Berkeley Business Law Journal, 3, 129-203. Memorandum OM 11-74 (2011), Office of General Counsel, National Labor Relations Board. Memorandum OM 12-59 (2012), Office of General Counsel, National Labor Relations Board. Meyers Industries, 268 NLRB 493 (1984). Model Rules of Professional Conduct, American Bar Association. Available:
http://www.americanbar.org/groups/professional_responsibility/publications/model_rules_of_professional_ conduct/model_rules_of_professional_conduct_table_of_contents.html
Mujtaba, B. (2003). Ethical implications of employee monitoring: What leaders should consider. Journal of Applied Management and Entrepreneurship, 8(3), 22-47.
National Labor Relations Act, 29 U.S.C. §§ 151-169 (2012). NLRB v. Noel Canning, 705 F.3d 490 (D.C. 2013), cert. granted 133 S.Ct. 2861 (U.S. June 24, 2013) (No. 12-1281). Papa, L., & S. Bass (2004). How employers can protect themselves from liability for employees’ misuse of
computer, internet, and e-mail systems in the workplace. Boston University Journal of Science and Technology Law, 110-123.
Pure Boot Camp v. Warrior Fitness Boot Camp, 587 F. Supp. 2d 548, 555 (S.D.N.Y. 2008). Restatement of Law (Third) of Agency, American Law Institute, (2006). Restatement of Law (Second) of Torts, American Law Institute (1977). Rozwell, C. (2012). Policy is not enough to inform employees about social media engagement. Gartner, Inc.
Retrieved July 3, 2012 from http://www.gartner.com/id=1916814 Schwartz, M. J. (2012). IBM launches advanced threat detection appliances. InformationWeek. Retrieved August 13,
2012 from http://www.informationweek.com/security/management/ibm-launches-advanced-threat- detection-a/240004627
Stengart v. Loving Care Agency, 201 N. J. 300 (2009). Sporer v. UAL Corporation, No. C 08-02835, 2009 WL 2761329 (N.D. Cal. 2009). SuccessFactors, Inc. v. Softscape, Inc., 544 F.Supp.2d 975 (N.D. Cal. 2008). Uniform Trade Secrets Act (1985). United States v. Greiner, 235 Fed. Appx. 541 (9th Circuit 2007). Walls, A. (2012a). Conduct digital surveillance ethically and legally: 2012 update. Gartner, Inc. Retrieved June 29,
2012 from http://www.gartner.com/id=1965315
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
69
Walls, A. (2012b). Security tools for control of social media usage. Gartner, Inc. Retrieved June 29, 2012 from http://www.gartner.com/id=2085715
Willey, L., J. C. Ford, B. J. White, & D. Clapper (2011). Trade secret law and information systems: Can your students keep a secret. Journal of Information Systems, 22(3), 271-278.
Willey L., B. J. White, T. Domagalski, & J. C. Ford (2012), Candidate screening, information systems and the law; social media considerations, Issues in Information Systems, 13(1), 300-309.
Winton, R. (2012, August 1). L.A. City Hall employees urged to stop watching the Olympics at work. Los Angeles Times. Retrieved August 12, 2012 from http://articles.latimes.com/2012/aug/01/local/la-me-0801-city- olympics-20120801
Journal of Legal, Ethical and Regulatory Issues Volume 18, Number 1, 2015
70
Copyright of Journal of Legal, Ethical & Regulatory Issues is the property of Jordan Whitney Enterprises, Inc. and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.