Showing posts with label workplace. Show all posts
Showing posts with label workplace. Show all posts

Wednesday, August 13, 2014

Implementing a Global Whistleblowing Program

Last month, I co-presented a short webinar with Jana Anderson, Partner, Foley & Lardner on implementing a global whistleblowing program with the Health Law Committee of ACC. If you are a member of the Association of Corporate Counsel, you can download the slides and materials here.

You may be asking yourself, why is a privacy attorney speaking to whistleblowing?

Believe it or not, many of the impediments to an effective (and legal) whistleblowing program are related to privacy laws and/or underlying privacy reasons.

Here are some of the highlights:

What is a whistleblower?

  • Ralph Nader coined the phrase in the early1970s to avoid the negative connotations found in words such as "snitches” or “tattle-tells.” 
  • Whistleblowers report perceived violations of a law by an entity (govt., private, educational, etc.) 
  • Whistleblowers are typically employees due to the need for insider knowledge. 
    • Internal – acts within entity to prevent/report violations 
    • External – reports externally, reward system 
Recent cases:

  • Medtronic Inc.’s recent settlement involved a business development manager as the whistleblower, who will receive $1.73 million as part of a $9.9 million settlement. 
  • Omnicare’s recent FCA actions involve a former collection manager and a former customer support employee as whistleblowers. 
  • Halifax Health Medical System’s recent Stark settlement for $85 million was a result of a qui tam suit brought by a former compliance officer for the system. 
The views on whistleblowing between the U.S. and other countries are vastly different. Here in the U.S. we view it as the right to keep businesses honest, to expose fraud, and to enforce compliance. Other countries view it as betrayal and that the U.S. is trying to govern business in their countries.

The laws that impact a global whistleblowing program fall into six categories. I give credit to the fabulous Don Dowling, Jr. of White and Case for his work in this area. Most of my knowledge in this area comes from intense study of his work.)

The six areas of laws that should be evaluated when implementing a global whistleblower program:
  • Mandating whistleblower procedures specifically
  • Requiring disclosures and cooperation with authorities
  • Restricting reporting hotlines (most especially anonymous reports or minor misbehavior)
  • Retaliation laws
  • Laws around internal investigations
  • Laws silent on whistleblowing, but programs possibly triggering data protection laws or work rules
Most of the legal implications are in Europe, which is no surprise given their fundamental right to personal data privacy.

Global whistleblowing programs fall into one of these categories:
  • One global program 
    • Meet both US law requirements and EU restrictions 
  • Two hotlines 
    • one in EU (meet SOX and most conservative EU country); another everywhere else 
  • Tailored hotlines to each local jurisdiction 
  • No EU hotline 
  • Informal EU reporting 
Last, a short checklist to implementing a global whistleblowing program (drawn heavily from Mr. Dowling's work):
  • Pay attention to EU particularly 
  • Check whistleblowing laws and privacy laws 
  • Disclose hotlines where required 
  • Secure data (calls, reports, investigations) 
    • That includes destroying the file after investigating 
  • Adhere to data transfer requirements 
  • Limit reporting topics to ensure proportionality
    • several nations only permit reporting of potential major criminal activity
    • Have routing for other reports that are not major crimes to a less formal process
  • Enable alternate reporting channels 
    • phones, emails, supervisor, HR, online
  • Do not encourage anonymity 
    • if you cannot bar anonymous in applicable countries, at least do not encourage or advertise it
  • Have a list of due process rights for accused 
  • Translations and multi-lingual operators should be easily available
  • Verify compliance, knowledge, capability of hotline vendor 

Thursday, April 3, 2014

Job Security?

In 2013 at the IAPP fall conference, Lisa Sotto (a renowned privacy and cybersecurity attorney with Hunton & Williams and member of the Board for IAPP) remarked during an open session to the attendees that if she heard one more person exclaim "Job Security" she might have to punch them - I may be paraphrasing. I think she was kidding. But she was not exaggerating the repetitiveness of the sentiment by the attendees.

Is there job security for privacy professionals?  Probably yes. Oh, what the heck - let's abandon the pretense of being objective: yes. Yes. YES!  The world of privacy and data protection is growing by leaps and bounds. And not just in one area of the globe. Privacy and data protection is growing everywhere.

You may recall the somewhat recent headlines containing words like Snowden, NSA, and leak. These headlines, or rather the actions behind them, have created some additional headlines involving European Union and the U.S. trade. I will not address whether Snowden is a hero or a traitor - or whether what he did is even right or wrong. The end result is that the European Commission and various data protection authorities seemed to question their faith in the U.S./EU Safe Harbor program.

I do not really believe that the EU will completely withdraw it's determination in the adequacy of the Safe Harbor program if only because international trade would suffer tremendously. But on the other hand, I would not brush off their concerns either. Recently, the U.S. FTC Commissioner and the U.K.'s Information Commissioner signed a memorandum of understanding to work together to protect the privacy rights of consumers. Rather contemporaneously, the FTC initiated actions against 13 U.S. companies for violations of their safe harbor certification statements, as this author wrote about in an earlier post. So international cooperation is on the table and probably not disappearing anytime soon although there is a lot of work to be done.

Which segues rather nicely back to job security. Privacy is probably the hottest area of law right now, but privacy professionals can not allow themselves to get cocky or complaisant. We must be strategists and visionaries; we must foster understanding and better understand the business case; and we must see the trees and the forest. Privacy law is growing faster than any one person can track. There are multiple think tanks and watch dog groups dedicated to the topic.

I laugh - usually out loud - when I hear other compliance professionals complain that they run from fire to fire. We all do. It's the nature of compliance. I dream of a day when I am notified that some area is suffering a drought and we can proclaim a high alert for the potential for fire. And even ban burning. Ha. Are you following me in this analogy?  Privacy professionals are like the forest rangers on lookout towers. There is a lot of landscape to watch, we are usually alone, we have to track winds, investigate smoke, and be able to call the troops when needed....but only when needed.

It's not glamorous. It's a hard job, but someone needs to do it. In fact, lots of someones need to do it. 

If I were to counsel someone who was interested in either entering the privacy profession or growing within it, there are three things I recommend:

  • Learn the technical aspect of the job. Yes, there are Information Security Professionals who generally originate in IT, but it would benefit the privacy professional to learn to speak intelligently about the technology.
  • Partner with the Information Security professional. This person should be your other half. They need to respect your knowledge and be able to depend on you and vice-versa.
  • Never think you know it all or that you are an expert. There is simply too much untested in the courts and much too much being changed every day - from laws to technology. 

I would not proclaim job security except when joking. Half the time I am afraid I am failing at the job because there is so much to do. The other half does a victory dance when a co-worker knows what the letters PII mean. It's the small things that make me happy - and the big things that keep me employed.

Sunday, February 2, 2014

When can Employers share your Information?

My daughter, Dazlin, asked this question on privacy..."Under what circumstances can or should my employer share my information?"

What a brilliant inquiry.

And I have no brilliant, quick responses, yet I am forcing her to wait for the answer on here even though I am currently comfortably ensconced in her apartment, sitting across from her. 

First, for me, the easy answer is about medical information. Any information in the medical context, whether as part of disability accommodation, employment prescreening, genetic information, employer medical coverage, or workers' compensation must be kept confidential. This means, generally, in HR, there are two files for each employee or a bifurcated file where the health information is kept separated from discipline, hiring and firing, pay, etc.

Can they ever share it? Of course they can. They can share it with people and entities who have a need to know, such as benefit managers, health care professionals who are treating you, risk management, and so forth. But in general, the information should not be shared anywhere without a legitimate reason. Most of the protection here is federal - EEOC (disability, genetic information), OSHA (injuries on the job) - but there is also state law that applies (workers' comp, HR law, data breach law).

I am not going into a terrible amount of detail here if for no other reason than it is a blog and not a legal treatise. Some factors also depend on whether your employer is a public or private entity and/or what job you hold. But if anyone is curious, write me and let me know that you have questions. I'll see what I can do.

Now, for the sharing...in almost all laws, there are exceptions and privacy law is no exception to that. In general, the exceptions are around subpoenas, law enforcement, public health, emergencies, and business operations that require disclosures. Business operations could include mergers, account houses, and other entities that are contracted to perform some duty on your employer's behalf, like mailing 1099s. To do so, the other entity has your information. Do you also remember all the stories about how many subpoenas and requests for information are being served on internet service providers? If information is part of an investigation, your employer will likely give it up.

Other than medical information, employers are required to keep certain information secure - like your date of birth and social security number. In countries other than the U.S., who have data protection laws, certain information is considered sensitive information. Sensitive information includes ethnicity, political views, member of professional organizations, etc. Now here in the U.S., race, age, gender is also considered confidential, but mainly because an employer can be sued for discrimination if negative decisions are based on race, gender, being over 40, disabled - things that make you a member of a protected class. Also, credit reports and background checks must be performed and retained securely. In fact, after the financial troubles of 2008, several states placed background check laws in place - mainly either the employer could not ask certain questions in an application or could not do a background check before meeting the person.

Many states have laws protecting certain information, although Massachusetts with 17 CMR 201 is the strongest. In Massachusetts, if you have information on their residents, to include name (either first name/initial with last name) plus some other elements (SSN, driver license number, or financial account number), then you are required to have a security program in place and provide certain data protections.

Mainly states have data breach notification laws, meaning that if your data is breached somehow, your employer must let you know (these are general law not employment laws, but apply to entities that collect certain information). Thus, if your employer wants to be excluded in most of these states from notification provisions, then they need to encrypt and take precautions with your information. Not all states recognize encryption as an exception, but most do - and of course, this only applies to electronic information.

Speaking of electronic information: analyzing whether employers can access your electronic communications such as email, texts, and social media is a full blog on its own. Morality consideration is another - think of teachers fired for posting naked party pictures on their own facebook or sports figures who get into scandals and lose endorsements. And last, lifestyle (which includes morality) is also a very deep discussion of law. 

So this is part of her answer. In reality, not all employers follow the laws - and certainly not all employees of your employer will follow the law. Training and awareness are huge for data protection and training is not generally a high budget item for many employers, especially towards protecting their employees' data.

So my advice point coming out of this is to be careful of your own information in the workplace. It is not necessarily a good idea to friend people on social media that you work with - you just may have information disclosed to your employer that you wish was not - and if a negative action is taken towards you based on this information, then you likely will have a very hard time proving it.

Saturday, February 1, 2014

What is a Privacy Counsel, anyway?

My name is K and I am a privacy counsel.

Most of the time when people ask what I do, they have no clue when I say "I am a privacy counsel." Confession time, I usually only say I'm an attorney, but sometimes they want to know what I practice. I don't practice. I am in-house. For those that don't know, in-house means that I am not with a law firm and do not take clients. I work for a company as an employee. The company is my client.

And given that I blog about privacy, I have to always disclaim that my views are not those of my employer.

But back to the question, what is a privacy counsel anyway? If I said I was an employment counsel or IP counsel, people would not be confused. I work in privacy. That is what is confusing, because people in the U.S. don't get privacy and I'm a dork.

Working in Silicon Valley does make for a little more acceptance. With the number of global companies here, they all pretty much have people doing what I do. It's kinda cool. There are lots of other privacy counsels.

Okay, Okay - back to the question. It means I make sure that the laws of the nations who have privacy laws are followed. Every other country who has privacy laws at all approach privacy vastly different than does the U.S.  We look at data on a sectoral level - health care, education, financial. There is no national privacy law in the U.S. and no national protections for general data on individuals. The states are a little different. 46 states have data breach laws - and they have many commonalities and some differences. The strongest data protection laws are in California, Texas, and Massachusetts. 

So in the U.S., I make sure we abide by sectoral laws and state laws. Globally, I deal with the laws of the European Union (28 or so different sets of law for the various countries, if you include the EEA 30 or so), APAC, Canada, Mexico, etc. etc. And I love it.

As stated above, I love privacy law. I caution people not to think of it as privacy, because most people tend to have tunnel vision. Think of it as personal data management - and in many cases, the most sensitive data I deal with (and thus, protect) is that of employees.

But like any area of compliance, it is always an uphill battle. Compliance is a cost center not a money maker. Ensuring certain protections are in place can slow down innovation and development. And especially given that most would prefer to build the house, then add the fence for privacy - we (privacy professionals) would prefer you to bring us the blueprints and make sure you are not building on someone else's property and/or get the right permits. Privacy by Design, or Privacy by Default. Build the product right to begin with. Then I am not a roadblock, I am a roadsign. I can point you in the right direction if you come to me early. If you come to me when you are ready to roll it out...well, I have to come up to speed on the product, check the contracts, vet the vendors, and know every data element you collect, how, when, what, where you get it, share it, and store it, how to send it, back it up, and delete it. 

So that is what a privacy counsel does.

It is one of the fastest growing fields in the world.

And when it is me - you get all this personality with the package. fun time, my friends, fun times.

Friday, August 17, 2012

Writing Papers to Publish

This week, I have been working on finishing papers to submit for publication.  It is a rite of passage and a way of life for those in academia.  A year ago, I would have stated that being an academia was my one goal. Now, I have a job I love, pays well, in a great area albeit an expensive one, and I am not sure I want to give this up to be in academia.  But I still want to publish to have that option open to me.  Unfortunately, part of my rationale is to prove a professor wrong. He spent an awful amount of time reiterating to us students that working in academia at a research institution was stressful and difficult.  That if he had to start over now, he would not do so. It's a tremendous amount of work.

Considering that the people he was talking to worked full-time jobs, high-stress ones, and attended a PhD program part-time...I'm thinking that not even a tenure-track professorship at a research university could be more demanding than an average of 60-70 hours on the job, plus school, kids, home, animals, chronic disabilities, volunteer work, mentoring, and well - whatever else I had going on at the same time. So I'd like to show him that he should not judge how un-busy we are not. Good googli moo.

But back to the topic.  The two papers are vastly different and wonderfully interesting.  One is on electronic communications in the workplace that the professor volunteered to help me prep for submission for publication as long as he could be co-listed.  Sure - he had good feedback and hopefully, connections.

The other is related to my desired dissertation topic, jury decision-making and reform. I asked a friend of mine from law school to join with me on this paper - cause I like the way she thinks and writes.  She has two published papers already, so apparently, she knows the formula.  I want to know the formula. So together, we are writing a paper on how civic education can improve jury decision making as part of the jury reform movement.  It's turning out to be a heck of a paper.

Monday, August 13, 2012

E-communications: an introduction


Technology has had a profound effect on both the workplace and communication. Electronic communication has been well-established as a mainstay of today’s workforce.  However, this generation is seeing virtual communication become the default interaction method.   While we may lament the loss of formal communication skills, such as hand-written notes, we must realize that a certain population has an immediate gratification attitude towards interpersonal relations.  Before text messaging, there remained a cautionary principle of “think twice before sending” to prevent hasty reactions.  With this current always-connected existence, the new generation of professionals may have little concept of boundaries or communication prudence.  Further, critical non-verbal cues that people learn through in-person interaction may be overlooked in this era of electronic communication.  We have started seeing issues of e-communication infringe upon the workplace.  There have been lawsuits on privacy expectations of e-mail and texting, harassment via electronics quaintly termed “textual harassment,” and corporate policies on social media.  Employees are frequently expected to be available electronically outside traditional work hours and in some cases, to use personal devices for business purposes.  It is critical to understand these issues when considering personnel policies, disciplinary issues, risk management, and corporate strategy regarding communication both internally and externally.


Prevalence of electronic communications
Electronic communication devices and means have become ubiquitous in American life. 83% of American adults own some kind of cell phone, indicating slightly over 100 million people in the U.S. over the age of 18 people have cell phones.  More than half of the respondents indicated that their cell phones were useful for accessing information quickly, to the extent that when not available, 27% said they were unable to accomplish some task.  42% use cell phones to relieve boredom and 13% pretend to use cell phones in order to avoid some social interaction. Almost a third of us have turned off our cell phones just to take a break from them.  Over ten billion videos were streamed in the U.S. in one month last year (Nielson Wire 2010).  This is a staggering statistic when one considers that the world population just reached seven billion (U.S. Census Bureau). A recent study by the International Center for Media & the Public Agenda in 2010 showed that American college students are addicted to the internet, cell phones, social media and show symptoms similar to drug and alcohol withdrawal when asked to “unplug” for 24 hours.

Social Media has a penetration rate of 98% in young adults, with only a 7% less rate among Americans in general (Experian 2011).  129 million Americans use social media in some capacity each month, with 20% using mobile technology, i.e. cell phone, to access their social media sites (Experian 2011).  Increasing social media use equates to an increase in email usage.  Additionally, studies show that most videos watched online are between 12 pm and 2 pm, during a typical workday.  Nielson reports that in September, 2011, 164 million individuals spent an average of five hours watching 18 billion videos in the U.S. alone.  This was a significant increase from the 10 billion videos streamed in June, 2010, indicating the growth rate and prevalence of online media use.  60% of Americans with smartphones and/or tablet PCs checked email while watching television at home.  This last figure speaks to the potential of performing work duties on private time.