After six months’ notice that they had to be prepared, all provincially-regulated employers with more than 25 workers today must have a written policy describing how they electronically monitor staff. Among those to be included in the worker count are homeworkers and probationary employees, some trainees, employees on definite term or specific task contracts of any length and those on a leave of absence.
Daniel Michaluk, who focuses on privacy and cybersecurity law at Borden Ladner Gervais, said today he believes most medium and large firms in the province are prepared, judging by the number of requests to review proposed policies he has received. He’s not sure, however, about the readiness of small firms.
It shouldn’t be hard to create a policy with a list of the types of IT monitoring and what each does in generic terms, he added. A company could create a chart of its tools (for example “endpoint detection”) and a brief description of what each does (“monitors the use of workstations and compares it against a baseline to detect abnormal use”).
“The trick is to get a balance between detail and high-level information.”
“I think you can achieve meaningful information without getting into technical specifications,” he added.
But a policy that has only a brief sentence that says ‘We monitor the network and therefore you should have no expectation of privacy’ is “inadequate,” he said.
The policy “is not necessarily the end of the dialogue between an employer and their...
Read Full Story:
https://www.itworldcanada.com/article/ontarios-employee-electronic-monitoring...