<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.lexblog.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>Workplace Privacy Counsel</title>
      <link>http://privacyblog.littler.com/</link>
      <description />
      <language>en</language>
      <copyright>Copyright 2012</copyright>
      <lastBuildDate>Wed, 09 May 2012 13:43:35 -0800</lastBuildDate>
      <pubDate>Wed, 09 May 2012 13:43:35 -0800</pubDate>
      <generator>http://www.movabletype.org</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <feedburner:info uri="workplaceprivacycounsel" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://privacyblog.littler.com/index.xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fprivacyblog.littler.com%2Findex.xml" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fprivacyblog.littler.com%2Findex.xml" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fprivacyblog.littler.com%2Findex.xml" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://privacyblog.littler.com/index.xml" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fprivacyblog.littler.com%2Findex.xml" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fprivacyblog.littler.com%2Findex.xml" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fprivacyblog.littler.com%2Findex.xml" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item>
         <title>Littler Mendelson's Privacy and Data Protection Practice Group Chair Philip Gordon Interviewed About Maryland Facebook Password Law</title>
         <description>&lt;p&gt;&lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip Gordon&lt;/a&gt;, Chair of Littler Mendelson's Privacy and Data Protection Practice Group Chair and a frequent contributor to this blog, was recently interviewed by The Lexblog Network about Maryland's recently-enacted &lt;a target="_blank" href="http://privacyblog.littler.com/2012/04/articles/social-networking-1/maryland-facebook-law-raises-new-obstacles-for-employers-vetting-applicants-and-investigating-employees-but-with-important-exceptions/"&gt;Facebook password law&lt;/a&gt; and what it accomplishes.&lt;/p&gt;
&lt;p&gt;&lt;iframe height="315" src="http://www.youtube.com/embed/qDEBCGkiqJo" frameborder="0" width="560" allowfullscreen=""&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;Video courtesy of &lt;/span&gt;&lt;a target="_blank" href="http://lxbn.lexblog.com/"&gt;&lt;span style="font-size: xx-small"&gt;The Lexblog Network&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/CfjdcenTreQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/CfjdcenTreQ/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/05/articles/state-privacy-legislation/littler-mendelsons-privacy-and-data-protection-practice-group-chair-philip-gordon-interviewed-about-maryland-facebook-password-law/</guid>
         <category domain="http://privacyblog.littler.com/tags">Employment Policies</category><category domain="http://privacyblog.littler.com/tags">Facebook</category><category domain="http://privacyblog.littler.com/tags">Login Information</category><category domain="http://privacyblog.littler.com/tags">Password</category><category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category><category domain="http://privacyblog.littler.com/articles">State Privacy Legislation</category>
         <pubDate>Wed, 02 May 2012 08:22:07 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/05/articles/state-privacy-legislation/littler-mendelsons-privacy-and-data-protection-practice-group-chair-philip-gordon-interviewed-about-maryland-facebook-password-law/</feedburner:origLink></item>
            <item>
         <title>Enforcement Guidance on the Use of Criminal Records in Employment Approved by EEOC</title>
         <description>&lt;p&gt;On Wednesday the Equal Employment Opportunity Commission (EEOC) approved in a 4-1 vote updated enforcement guidance governing the legality of considering a job applicant&amp;rsquo;s or employee&amp;rsquo;s criminal history when making hiring or other employment decisions. Commissioner Victoria Lipnic (R) joined the Democrat Commissioners in support of the guidance, while Constance Barker (R) was the lone member to vote against the new guidance. Although the use of credit history for employment screening had been a topic of discussion during an earlier Commission meeting, the Commission has not issued guidance on this topic. Given Commissioner Stuart Ishimaru&amp;rsquo;s (D) impending resignation, it is likely that any new guidance on credit history would need to be a bipartisan effort with only four Commissioners if such guidance is issued at all anytime soon. To learn more about the revised guidance and its implications for employers, please &lt;a target="_blank" href="http://www.dcemploymentlawupdate.com/2012/04/articles/eeoc-1/eeoc-approves-enforcement-guidance-on-the-use-of-criminal-records-in-employment/"&gt;continue reading&lt;/a&gt; at Littler's D.C. Employment Law Update.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/a_Kg2UZhrpw" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/a_Kg2UZhrpw/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/04/articles/background-checks/enforcement-guidance-on-the-use-of-criminal-records-in-employment-approved-by-eeoc/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category>
         <pubDate>Thu, 26 Apr 2012 09:49:11 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/04/articles/background-checks/enforcement-guidance-on-the-use-of-criminal-records-in-employment-approved-by-eeoc/</feedburner:origLink></item>
            <item>
         <title>Maryland "Facebook Law" Raises New Obstacles For Employers Vetting Applicants And Investigating Employees, But With Important Exceptions</title>
         <description>&lt;p&gt;&lt;em&gt;By &lt;/em&gt;&lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip L. Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The momentum in the media made it almost inevitable: the first state law to expressly restrict employers from asking applicants and employees for social media account log-in credentials has been passed. Not surprisingly, Maryland, where the issue first burst onto the scene in April 2011, wins the &amp;ldquo;honor.&amp;rdquo; However, Maryland likely has opened the floodgates. Bills currently are pending in &lt;a target="_blank" href="http://www.littler.com/publication-press/publication/though-not-yet-banned-requiring-social-media-information-bad-idea"&gt;California, Illinois, Minnesota, New Jersey, and Washington&lt;/a&gt;. Employers seeking to understand the implications of the Maryland law must look beyond the blaring headlines to the details of the statute.&lt;/p&gt;
&lt;p&gt;To begin with, the &lt;a target="_blank" href="http://mlis.state.md.us/2012rs/billfile/sb0433.htm"&gt;law&amp;rsquo;s general prohibition is both broad and narrow&lt;/a&gt;. Effective October 1, 2012 (assuming the Governor signs the law), employers are prohibited from requiring, or even asking, that applicants or employees disclose &amp;ldquo;any means for accessing,&amp;rdquo; such as a user name or password, for &amp;ldquo;any personal account or service&amp;rdquo; accessed through &amp;ldquo;computers, telephones, personal digital assistants, and other similar devices.&amp;rdquo;&amp;nbsp; In other words, the prohibition extends far beyond Facebook and other social media sites to include personal e-mail accounts, personal online banking accounts, and any other online communications or service account.&lt;/p&gt;&lt;p&gt;The Maryland law prohibits an employer from taking or threatening any form of adverse action based on an employee&amp;rsquo;s or applicant&amp;rsquo;s refusal to provide a user name or password to a personal account accessed through a communications device. An employer cannot discharge, discipline or otherwise penalize an employee. An employer cannot reject an applicant for engaging in the protected conduct.&lt;/p&gt;
&lt;p&gt;Notably, the Maryland law contains&lt;em&gt; no &lt;/em&gt;enforcement provision. The law does not authorize applicants or employees to sue. The law does not even delegate authority to the Maryland Department of Labor, Licensing and Regulation, or any other government agency, to enforce it. It is possible that an employee terminated in violation of the law might have a claim for wrongful discharge in violation of public policy. However, because that claim typically applies only to discharge, it is unclear whether an employee who is disciplined short of discharge would have a claim. It also is uncertain whether an applicant who is denied employment in violation of the law would be able to assert a claim.&lt;/p&gt;
&lt;p&gt;While the law seems overly broad at first blush, it is critical for employers to understand the types of conduct that the law does&lt;em&gt; not &lt;/em&gt;prohibit. Some of these exceptions are expressed in the statute itself; others are implicit.&lt;/p&gt;
&lt;ol&gt;
    &lt;li&gt;&lt;u&gt;Access To Employer&amp;rsquo;s Internal Systems&lt;/u&gt;: The law expressly permits employers to require that employees disclose log-in credentials &amp;ldquo;for accessing nonpersonal accounts or services that provide access to the employer&amp;rsquo;s internal computer or information systems.&amp;rdquo; In other words, employees cannot rely on the law to prevent employers from gaining access to information stored on the employer&amp;rsquo;s own information systems.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Violations Of Securities Or Financial Laws, Or Regulatory Requirements&lt;/u&gt;: If an employer receives information that an employee is using a personal online account for business purposes, the law &amp;ldquo;does not prevent&amp;rdquo; an employer from conducting an investigation to ensure that the employee is complying with &amp;ldquo;securities or financial law, or regulatory requirements.&amp;rdquo; This exception appears intended to apply in a situation where an employee of a financial services company uses a personal online account to trade securities or engage in other financial transactions on the employer&amp;rsquo;s behalf.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Protection Of Trade Secrets&lt;/u&gt;: If an employer receives information that an employee has downloaded the employer&amp;rsquo;s proprietary information, without authorization, to a personal online account, the law &amp;ldquo;does not prevent&amp;rdquo; an employer from conducting an investigation into such suspected misconduct.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Passwords To Devices&lt;/u&gt;: While the Maryland law bars employers from requesting log-in credentials for &amp;ldquo;accessing a personal account or service,&amp;rdquo; the law does not prohibit employers from requesting or requiring log-in credentials to access an employee&amp;rsquo;s personal device, such as a smartphone or tablet. This distinction is critical as employers increasingly are implementing &amp;ldquo;Bring-Your-Own-Device&amp;rdquo; policies.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Nonpersonal Accounts&lt;/u&gt;: The law protects log-in credentials only for &amp;ldquo;personal&amp;rdquo; accounts. Maryland employers should clearly define which accounts are personal and which are nonpersonal. For example, if an employee uses a corporate e-mail address to establish a LinkedIn profile or Twitter account, the employer should ensure that employees know from the outset that such an account is &amp;ldquo;nonpersonal&amp;rdquo; for purposes of the Maryland law.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Because the Act&amp;rsquo;s restrictions on its face arguably apply only to the disclosure of log-in credentials, it remains to be seen through judicial interpretation whether the Act&amp;rsquo;s restrictions bar an employer from, for example, asking an employee or applicant to log into a personal account without disclosing the log-in credentials to the employer so the employer can observe the content of the personal account or asking an employee or applicant to print the content of a personal account. Before an employer chooses this route, they should speak with their employment counsel to educate themselves about the legal risks of doing so. While Maryland is the first jurisdiction to enact this legislation, it is not likely to be the last. Indeed, bills proposing similar restrictions currently are pending in various states, including but not limited to California, Illinois, Minnesota, New York, and Washington. In addition, U.S. Senator Richard Blumenthal (D&amp;ndash;CT) has stated his plan to introduce similar legislation &amp;quot;in the very near future.&amp;quot;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/7mhQo0U1hdo" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/7mhQo0U1hdo/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/04/articles/social-networking-1/maryland-facebook-law-raises-new-obstacles-for-employers-vetting-applicants-and-investigating-employees-but-with-important-exceptions/</guid>
         <category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category>
         <pubDate>Wed, 11 Apr 2012 07:16:45 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/04/articles/social-networking-1/maryland-facebook-law-raises-new-obstacles-for-employers-vetting-applicants-and-investigating-employees-but-with-important-exceptions/</feedburner:origLink></item>
            <item>
         <title>Requiring Social Media Information Is a Bad Idea</title>
         <description>&lt;p&gt;Employers continue to wrestle with the issue of whether to require employees and prospective employees to divulge their social media passwords. A recent spike in interest by the media, by advocacy groups, legislators and the general public has refocused attention on the issue. Although it may not be unlawful to seek the information to conduct background checks, deter and investigate harassment of coworkers, and discourage employees from posting online content that disparages the employer's products or services, in most situations, it is inadvisable. To learn more about the pitfalls of social media information requests, proposed federal and state bills prohibiting such requests and their potential implications for employers, please continue reading Littler's ASAP, &lt;em&gt;&lt;a target="_blank" href="http://www.littler.com/publication-press/publication/though-not-yet-banned-requiring-social-media-information-bad-idea"&gt;Though Not Yet Banned, Requiring Social Media Information Is a Bad Idea&lt;/a&gt;&lt;/em&gt; by &lt;a target="_blank" href="http://www.littler.com/people/chris-m-leh"&gt;Chris Leh&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/f3vxZKtFGjE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/f3vxZKtFGjE/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/03/articles/background-checks/requiring-social-media-information-is-a-bad-idea/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category>
         <pubDate>Wed, 28 Mar 2012 09:00:00 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/03/articles/background-checks/requiring-social-media-information-is-a-bad-idea/</feedburner:origLink></item>
            <item>
         <title>Finding the Messages to Employers in $1.5M HIPAA Settlement</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip L. Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img hspace="2" alt="" vspace="2" align="right" width="300" height="199" src="http://privacyblog.littler.com/uploads/image/ResponsibilityAheadSignIV.jpg" /&gt;Yesterday&amp;rsquo;s &lt;a href="http://privacyblog.littler.com/uploads/file/BCBST Resolution Agreement.pdf"&gt;$1.5M &amp;ldquo;Resolution Agreement&amp;rdquo;&lt;/a&gt; between Blue Cross Blue Shield of Tennessee (&amp;ldquo;BCBST&amp;rdquo;) and the U.S. Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;), the agency responsible for enforcing HIPAA, is the fourth major settlement announced by HHS in the past&amp;nbsp;15 months and the third to exceed seven figures. This settlement has several important messages for employers.&lt;/p&gt;
&lt;p&gt;Before turning to those messages, here are the key facts as set forth in the Resolution Agreement. BCBST stored, in a network data closet, computer equipment which included servers and 57 hard drives. The hard drives were part of a system that recorded customer service calls and contained the protected health information (PHI) of more than one million participants, including member names, member ID numbers, diagnosis codes, dates of birth, and Social Security numbers. The network data closet &amp;ldquo;was secured by biometric and keycard scan security with a magnetic lock and an additional door with a keyed lock.&amp;rdquo; The property management company for the leased spaced where the network data closet was located provided security services.&lt;/p&gt;
&lt;p&gt;After BCBST vacated most of its office space, but while it still leased the space containing the network data closet, thieves stole the&amp;nbsp;57 hard drives from the closet. The hard drives were not encrypted. BCBST notified HHS of a security breach in accordance with the HITECH Act&amp;rsquo;s requirements.&lt;/p&gt;&lt;p&gt;To resolve HHS&amp;rsquo;s investigation, BCBST agreed not only to pay $1.5 million but also to enter into a corrective action plan (CAP). The CAP requires BCBST to do the following: (a) conduct a risk assessment and engage in a risk management process with respect to electronic PHI (ePHI) in BCBST&amp;rsquo;s possession; (b) develop facility access controls and a facility security plan to safeguard information systems and equipment containing ePHI; (c) develop physical safeguards for electronic storage media containing ePHI; (d) train all workforce members with access to ePHI in the policies and procedures embodying items (a) through (c); (e) monitor compliance with the policies and procedures; and (f) report to HHS concerning compliance with the CAP.&lt;/p&gt;
&lt;p&gt;Employers can draw several lessons from this incident and its resolution:&lt;/p&gt;
&lt;p&gt;First, to date, HHS&amp;rsquo;s &lt;a target="_blank" href="http://privacyblog.littler.com/2011/02/articles/hipaa-1/lessons-galore-from-eyepopping-43-million-hipaa-penalty/"&gt;monetary settlements&lt;/a&gt; with covered entities have &lt;a target="_blank" href="http://privacyblog.littler.com/2011/03/articles/hipaa-1/hhs-onetwo-hipaa-penalty-punch-sends-a-message-to-employers-and-providers/"&gt;focused on health care providers&lt;/a&gt;, such as hospitals and pharmacies. This is the first monetary settlement of which we are aware involving a covered health plan. Insurers and self-insured employers offering HIPAA-covered benefits should take note.&lt;/p&gt;
&lt;p&gt;Second, this is the first monetary settlement triggered by a covered entity&amp;rsquo;s report of a security breach to HHS in compliance with the HITECH Act. It is critical for employers with HIPAA-covered plans, as well as other covered entities, to recognize that notifying HHS of a security breach in accordance with the HITECH Act could trigger an investigation into the circumstances underlying the breach and could ultimately result in an enforcement action.&lt;/p&gt;
&lt;p&gt;Third, the underlying incident involved the theft of unencrypted hard drives. Had those hard drives been encrypted, BCBST would not have had an obligation to notify HHS of the theft. In other words, the Resolution Agreement highlights the importance of considering the feasibility of encrypting any movable storage media which contain ePHI.&lt;/p&gt;
&lt;p&gt;Finally, HHS seems to have set a fairly high standard for adequate physical safeguards. The Resolution Agreement suggests that BCBST had in place fairly robust physical security for the stored hard drives, including &amp;ldquo;biometric and keycard scan security with a magnetic lock and an additional door with a key card lock&amp;rdquo; in addition to building security. HHS, nonetheless, appears to have taken the position that this security was inadequate. Consequently, the Resolution Agreement emphasizes the need for covered entities to pay as close attention to physical safeguards for ePHI as they do to administrative and technical safeguards.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;i&gt;Photo credit:&lt;/i&gt; &lt;/span&gt;&lt;a target="_blank" href="http://www.istockphoto.com/user_view.php?id=469721"&gt;&lt;span style="font-size: xx-small"&gt;MBPHOTO, Inc.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/nYCV7B2beZ0" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/nYCV7B2beZ0/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/03/articles/hipaa-1/finding-the-messages-to-employers-in-15m-hipaa-settlement/</guid>
         <category domain="http://privacyblog.littler.com/tags">Covered Health Plan</category><category domain="http://privacyblog.littler.com/articles">Data Security</category><category domain="http://privacyblog.littler.com/tags">Department of Health and Human Services</category><category domain="http://privacyblog.littler.com/tags">Encryption</category><category domain="http://privacyblog.littler.com/tags">Enforcement Action</category><category domain="http://privacyblog.littler.com/tags">HHS</category><category domain="http://privacyblog.littler.com/articles">HIPAA</category><category domain="http://privacyblog.littler.com/tags">HITECH Act</category><category domain="http://privacyblog.littler.com/tags">Hard Drive</category><category domain="http://privacyblog.littler.com/tags">Investigation</category><category domain="http://privacyblog.littler.com/tags">PHI</category><category domain="http://privacyblog.littler.com/tags">Protected Health Information</category><category domain="http://privacyblog.littler.com/tags">Resolution Agreement</category><category domain="http://privacyblog.littler.com/tags">Security Breach</category><category domain="http://privacyblog.littler.com/tags">Vendor</category>
         <pubDate>Wed, 14 Mar 2012 12:11:09 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/03/articles/hipaa-1/finding-the-messages-to-employers-in-15m-hipaa-settlement/</feedburner:origLink></item>
            <item>
         <title>New Obligations for Massachusetts Employers Conducting Criminal Background Checks</title>
         <description>&lt;p&gt;Effective May 4, 2012, the Massachusetts Criminal Offender Record Information (&amp;quot;CORI&amp;quot;) Reform Act (the Act), which was &lt;a target="_blank" href="http://privacyblog.littler.com/2010/08/articles/background-checks/multistate-employers-must-revise-job-applications-to-address-new-massachusetts-background-check-law/"&gt;enacted in August 2010&lt;/a&gt; with the controversial &amp;quot;ban the box&amp;quot; legislation, will significantly change the way employers access, use and maintain information obtained through the Commonwealth's CORI system. The Act will allow all employers access to a new online records system, but also imposes obligations on employers that acquire criminal history information from private sources, such as consumer reporting agencies (background report vendors). Employers should review their hiring and background check policies now to determine whether any updates are necessary. To learn about the Act and its potential implications for employers, please &lt;a target="_blank" href="http://www.littler.com/publication-press/publication/massachusetts-employers-face-new-obligations-when-conducting-backgroun"&gt;continue reading&lt;/a&gt; Littler's ASAP, &lt;i&gt;Massachusetts Employers Face New Obligations When Conducting Background Checks Involving Criminal History Records&lt;/i&gt;, by &lt;a target="_blank" href="http://www.littler.com/people/christopher-b-kaczmarek"&gt;Christopher Kaczmarek&lt;/a&gt;, &lt;a target="_blank" href="http://www.littler.com/people/carie-torrence"&gt;Carie Torrence&lt;/a&gt;, and &lt;a target="_blank" href="http://www.littler.com/people/joseph-lazazzero"&gt;Joseph Lazazzero&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/AV2lA-K_Y1M" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/AV2lA-K_Y1M/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/03/articles/background-checks/new-obligations-for-massachusetts-employers-conducting-criminal-background-checks/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Criminal History</category><category domain="http://privacyblog.littler.com/tags">Massachusetts</category><category domain="http://privacyblog.littler.com/articles">State Privacy Legislation</category>
         <pubDate>Thu, 08 Mar 2012 15:28:43 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/03/articles/background-checks/new-obligations-for-massachusetts-employers-conducting-criminal-background-checks/</feedburner:origLink></item>
            <item>
         <title>NLRB Report Challenges Validity of Many Commonly Used Social Media Policies</title>
         <description>&lt;p&gt;&lt;i&gt;By&lt;/i&gt; &lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img hspace="2" alt="" vspace="2" align="right" width="250" height="245" src="http://privacyblog.littler.com/uploads/image/NLRBLOGOIII(1).jpg" /&gt;In its most recent effort to draw lines on the self-described &amp;ldquo;hot topic&amp;rdquo; of the &amp;ldquo;lawfulness of employers&amp;rsquo; social media policies and rules,&amp;rdquo; the National Labor Relations Board&amp;rsquo;s (NLRB) Office of General Counsel has taken the position that many policy provisions commonly seen in employers&amp;rsquo; social media policies violate the National Labor Relations Act (NLRA). This most recent shot across the bow came on January 24, 2012, in the form of a &lt;a href="http://privacyblog.littler.com/uploads/file/NLRBGCMemoJanuary242012.pdf"&gt;report&lt;/a&gt;, issued to senior regional staff, on&amp;nbsp;14 cases which, according to the General Counsel, &amp;ldquo;present emerging issues in the context of social media.&amp;rdquo; This report follows a &lt;a target="_blank" href="http://privacyblog.littler.com/2011/08/articles/social-networking-1/more-guidance-from-the-nlrb-on-social-media-when-must-employers-not-fire-an-employee-for-an-offensive-facebook-post/"&gt;previous General Counsel report&lt;/a&gt;, dated August 18, 2011, which discussed&amp;nbsp;14 prior NLRB cases involving social media issues.&lt;/p&gt;
&lt;p&gt;The cases treated in the report also contain the General Counsel&amp;rsquo;s opinion on whether the employer in each case violated the NLRA by imposing discipline based on social media conduct. We will cover this aspect of the report in a separate and forthcoming blog post. Here, we will focus on the thicket that the NLRB has created for employers who are trying to gain some reasonable control over what employees publish in social media, often to the world, about co-workers, supervisors, the workplace, and the employer&amp;rsquo;s products and services.&lt;/p&gt;&lt;p&gt;Each of the headings below reviews the General Counsel&amp;rsquo;s current position on a particular type of commonly used policy provision. Employers should carefully review their existing policies and any new policy in light of the General Counsel&amp;rsquo;s most recent report. With careful drafting and the use of examples and limiting language, employers should still be able to achieve their objectives of gaining limited control over the Wild West of social media content while staying within the parameters of the NLRA.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;No Defamation/Non-Disparagement:&lt;/strong&gt;&lt;/u&gt; No employer likes seeing its employees or organization trashed in social media, but, according to the General Counsel, a broad non-disparagement policy violates the NLRA on a &lt;em&gt;per se&lt;/em&gt; basis because it could inhibit employees from making negative comments about the terms and conditions of their employment. For example, the General Counsel opined in the report that the following policy prohibition is illegal: &amp;ldquo;[m]aking disparaging comments about the company through any media, including online blogs, other electronic media or through the media.&amp;rdquo; The General Counsel reached the same conclusion on a policy which prohibits &amp;ldquo;discriminatory, defamatory, or harassing web entries about specific employees, work environment, or work-related issues on social media sites.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;While the General Counsel&amp;rsquo;s opinion sounds frustrating, employers should not despair. The General Counsel explains that by including non-disparagement policy language within a list of other forms of unprotected conduct, an employer&amp;rsquo;s non-disparagement policy will comply with the NLRA. To illustrate the point, the General Counsel pointed to the NLRB&amp;rsquo;s holding that a policy prohibiting &amp;ldquo;statements which are slanderous or detrimental to the company&amp;rdquo; was lawful when it &amp;ldquo;appeared on a list of prohibited conduct including &amp;lsquo;sexual or racial harassment&amp;rsquo; and &amp;lsquo;sabotage.&amp;rsquo;&amp;rdquo; Following this authority, the General Counsel gave its stamp of approval in the report to a policy which &amp;ldquo;prohibited the use of social media to post or display comments about coworkers or supervisors or the Employer that are vulgar, obscene, threatening, intimidating, harassing, or a violation of the Employer&amp;rsquo;s workplace policies against discrimination, harassment, or hostility on account of age, race, religion, sex, ethnicity, nationality, disability, or other protected class, status, or characteristic.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Confidentiality:&lt;/strong&gt;&lt;/u&gt; Protecting confidential information and trade secrets from competitors is critical to every organization. According to the General Counsel, however, a confidentiality policy is illegal if it would impinge on employees&amp;rsquo; ability to discuss their wages and working conditions with others inside or outside the organization. Consistent with that reasoning, the General Counsel&amp;rsquo;s report rejected a provision in an employer&amp;rsquo;s social media policy that prohibited employees from &amp;ldquo;disclosing or communicating . . . confidential, sensitive, or non-public information concerning the company on or through company property to anyone outside the company without prior approval of senior management or the law department.&amp;rdquo; By contrast, the General Counsel approved a policy provision that &amp;ldquo;prohibited employees from using or disclosing confidential and/or proprietary information, including personal health information about customers or patients&amp;rdquo; as well as &amp;ldquo;&amp;lsquo;embargoed information,&amp;rsquo; such as launch and release dates and pending reorganizations.&amp;rdquo; The General Counsel approved of this policy language based on the following reasoning: &amp;ldquo;Considering that the Employer sells pharmaceuticals and that the rule contains several references to customers, patients, and health information, employees would reasonably understand that this rule was intended to protect the privacy interests of the Employer's customers and not to restrict Section 7 protected communications.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The General Counsel&amp;rsquo;s distinction between the two confidentiality provisions suggests a potential litmus test for confidentiality language in a social media policy: if the policy reasonably could be read to prevent employees from disclosing the amount of their compensation to family members, the General Counsel likely would find the policy to be overbroad.&amp;rdquo; Employers should note that this same issue could apply to confidentiality agreements signed by hourly workers, and not just to confidentiality requirements in a social media policy.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Logos/Trademarks:&lt;/strong&gt;&lt;/u&gt; Organizations understandably want to control use of their logo and trademarks. Nonetheless, a social media policy which prohibits &amp;ldquo;use of the company&amp;rsquo;s name or service marks outside the course of business without prior approval of the law department&amp;rdquo; is, according to the General Counsel, unlawful. The General Counsel takes the position that employees have the right under the NLRA to use the company&amp;rsquo;s name and logo &amp;ldquo;while engaging in protected concerted activity, such as in electronic or paper leaflets, cartoons, or picket signs in connection with a protest involving the terms and conditions of employment.&amp;rdquo; The General Counsel reasoned that such protected use of a company&amp;rsquo;s name and logo does not &amp;ldquo;remotely implicate[]&amp;rdquo; the company&amp;rsquo;s interests protected by trademark law, &amp;ldquo;such as the trademark holder&amp;rsquo;s interests in protecting the good reputation associated with the mark from the possibility of being tarnished by inferior merchandise sold by another entity using the trademark and in being able to enter a related commercial field and use its well-established trademark.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;This reasoning is wrong. An employee easily could damage brand reputation and engender customer confusion by, for example, creating a Facebook page with the corporate name and logo. At a minimum, an employer should be able to prohibit employees from using the company name or logo when engaging or depicting in social media any conduct which violates the Company&amp;rsquo;s policies or is unlawful; such a policy would not encompass activity protected by Section 7 of the NLRA. Employers also should consider consulting intellectual property counsel about logo and trademark issues and not necessarily develop a marketing strategy based solely on NLRA issues. However, the General Counsel&amp;rsquo;s analysis (which is not law, but rather the Office&amp;rsquo;s view of the law) should not be fully ignored either.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Employee Disclaimers:&lt;/strong&gt;&lt;/u&gt; Social media policies commonly mandate that employees must include a disclaimer in any social media content that relates to the employer. For example, in one of the cases discussed in the General Counsel&amp;rsquo;s report, the employer&amp;rsquo;s social media policy required that employees &amp;ldquo;expressly state that their comments are their personal opinions and do not necessarily reflect the Employer&amp;rsquo;s opinions.&amp;rdquo; The General Counsel opined that this policy requirement violates the NLRA because it &amp;ldquo;would significantly burden the exercise of employees&amp;rsquo; Section 7 rights to discuss working conditions and criticize the Employer&amp;rsquo;s labor policies.&amp;rdquo; Fortunately, employers can achieve a similar result with a policy that prohibits employees from representing in any way that they are speaking on the Company&amp;rsquo;s behalf without prior written authorization to do so.&lt;/p&gt;
&lt;p&gt;It is worth noting that the General Counsel did approve an employee disclaimer requirement in the section of a social media policy addressing product promotions. The General Counsel explained that in context, this provision could not be read to interfere with Section 7 rights because the policy focused on product promotions and endorsements and was intended to avoid potential liability for unfair and deceptive trade practices under guidance issued by the Federal Trade Commission.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Discussions of Work-Related Concerns:&lt;/strong&gt;&lt;/u&gt; The aphorism, &amp;ldquo;Don&amp;rsquo;t hang out your dirty laundry,&amp;rdquo; may seem antiquated but many employers still say just that in their social media policy. By way of illustration, one policy discussed in the General Counsel&amp;rsquo;s report &amp;ldquo;required employees to first discuss with their supervisor or manager any work-related concerns, and it provided that failure to comply could result in corrective action, up to and including termination.&amp;rdquo; The General Counsel concluded that this policy violated the NLRA because of the threat of discipline. Employers can avoid this potential pitfall by urging, but not mandating, that employees use internal channels, rather than social media, to resolve workplace concerns. In that regard, the General Counsel&amp;rsquo;s opinion is nothing new, but rather is in line with traditional NLRA law on protected, concerted activity in general.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Communications with the Media:&lt;/strong&gt;&lt;/u&gt; Social media policies often tell employees not to discuss with the media their social media content related to the company. The General Counsel&amp;rsquo;s report finds such prohibitions illegal. (&amp;ldquo;An employer&amp;rsquo;s rule that prohibits employee communications to the media or requires prior authorization for such communications is therefore unlawfully overbroad.&amp;rdquo;) However, a similar report issued by the General Counsel on August 18, 2011, recognized that &amp;ldquo;a media policy that simply seeks to ensure a consistent, controlled company message and limits employee contact with the media only to the extent necessary to effect that result cannot be reasonably interpreted to restrict Section 7 communications.&amp;rdquo; In light of that principle, the General Counsel blessed the media policy in question because the &amp;ldquo;policy repeatedly stated that the purpose of the policy was to ensure that only one person spoke for the company&amp;rdquo; and even though &amp;ldquo;employees were instructed to answer all media/reporter questions in a particular way.&amp;rdquo; In other words, it appears that employers can still carefully craft a provision on media relations in a social media policy which complies with the NLRA.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;&amp;ldquo;Unprofessional&amp;rdquo; Content:&lt;/strong&gt;&lt;/u&gt; In several of the reported cases, the General Counsel took issue with policy terms that were undefined, vague, or subjective. These terms included prohibitions on &amp;ldquo;insubordination or other disrespectful conduct,&amp;rdquo; &amp;ldquo;inappropriate conversation,&amp;rdquo; &amp;ldquo;unprofessional communication that could negatively impact the Employer&amp;rsquo;s reputation or interfere with the Employer&amp;rsquo;s mission,&amp;rdquo; and &amp;ldquo;nonprofessional/inappropriate communication regarding members of the Employer&amp;rsquo;s community&amp;rdquo; as well as the requirement that social media activity occur in an &amp;ldquo;honest, professional, and appropriate manner.&amp;rdquo; Employers can achieve the intended objectives of this disfavored language by using terms that are defined in the social media policy or other policies or by providing examples of prohibited conduct with examples that do not include conduct protected by the NLRA.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Employee&amp;rsquo;s Self-Identification:&lt;/strong&gt;&lt;/u&gt; Some employers have tried to protect their organization by telling employees not to identify their affiliation with the organization when engaging in social media activity unless there is a legitimate business reason for doing so. In its report, the General Counsel took the position that this type of policy violates the NLRA &amp;ldquo;because personal profile pages serve an important function in enabling employees to use online social networks to find and communicate with their fellow employees at their own or other locations.&amp;rdquo; Employers should not view the General Counsel&amp;rsquo;s position here as a particular setback. Telling employees not to mention their employer by name in a personal profile is akin to telling them not to do the same at a cocktail party; the rule would be honored in the breach.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Securities Blackouts:&lt;/strong&gt;&lt;/u&gt; Publicly traded companies are rightfully concerned that employees may let slip on social media highly sensitive information about a corporate transaction, new product launch, or non-public financial information. Among the few policy provisions with which the General Counsel did not take issue was one which stated that the employer might &amp;ldquo;request employees to confine their social networking to matters unrelated to the company if necessary to ensure compliance with securities regulations and other laws.&amp;rdquo; The General Counsel reasoned that &amp;ldquo;employees reasonably would interpret the rule to address only those communications that could implicate security regulations,&amp;rdquo; as opposed to the terms and conditions of their employment.&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Employer Disclaimers:&lt;/strong&gt;&lt;/u&gt; In the wake of the NLRB&amp;rsquo;s aggressive position since &lt;a target="_blank" href="http://privacyblog.littler.com/2011/02/articles/social-networking-1/settlement-in-nlrbs-amrfacebook-case-contains-message-for-employers-about-social-media-policies/"&gt;the AMR case&lt;/a&gt; in late 2010 on social media policies and employee discipline based on social media conduct, many employment and labor law practitioners have recommended the inclusion of a disclaimer in social media policies. The disclaimer explains that the employer&amp;rsquo;s policies are not intended to interfere with employees&amp;rsquo; rights under the NLRA. In its first public review of a disclaimer in a social media policy, the Board somewhat surprisingly took the position that such a disclaimer was ineffective. In that case, the disclaimer stated as follows: &lt;br /&gt;
&amp;nbsp;&lt;/p&gt;
&lt;p style="margin-left: 40px"&gt;[T]he policy [will] not be interpreted or applied so as to interfere with employee rights to self-organize, form, join, or assist labor organizations, to bargain collectively through representatives of their choosing, or to engage in other concerted activities for the purpose of collective bargaining or other mutual aid or protection, or to refrain from engaging in such activities.&lt;/p&gt;
&lt;p&gt;According to the General Counsel, this disclaimer could not &amp;ldquo;save&amp;rdquo; a policy provision prohibiting employees from posting &amp;ldquo;inappropriate&amp;rdquo; content because &amp;ldquo;an employee could not reasonably be expected to know that this language encompasses discussions the Employer deems &amp;lsquo;inappropriate.&amp;rsquo;&amp;rdquo; Given the detailed nature of the disclaimer in question, this conclusion suggests the General Counsel, and possibly the Board itself, will view skeptically any effort by an employer to rely upon a disclaimer to protect an otherwise overbroad social media policy. That is an unfortunate result for employers, as a disclaimer seemed to be the answer to keeping a policy simple and uncluttered, without violating the NLRA. Now employers should consider instead replacing such a disclaimer with a list of specific limitations or examples, such as those discussed above which can transform an otherwise overbroad (at least in the eyes of the General Counsel) non-disparagement provision into one that complies fully with the NLRA.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/k9TaZzFlExI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/k9TaZzFlExI/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/01/articles/labor-relations/nlrb-report-challenges-validity-of-many-commonly-used-social-media-policies/</guid>
         <category domain="http://privacyblog.littler.com/tags">Employment Policies</category><category domain="http://privacyblog.littler.com/articles">Labor Relations</category><category domain="http://privacyblog.littler.com/tags">NLRA</category><category domain="http://privacyblog.littler.com/tags">NLRB</category><category domain="http://privacyblog.littler.com/tags">Social Media</category>
         <pubDate>Fri, 27 Jan 2012 15:29:31 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/01/articles/labor-relations/nlrb-report-challenges-validity-of-many-commonly-used-social-media-policies/</feedburner:origLink></item>
            <item>
         <title>What Does The Supreme Court's "GPS Decision" Mean For Private Employers?</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip L. Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img hspace="2" alt="United States Supreme Court" vspace="2" align="right" width="300" height="225" src="http://privacyblog.littler.com/uploads/image/Supreme Court Building XX.jpg" /&gt;The Supreme Court &lt;a href="http://privacyblog.littler.com/uploads/file/UnitedStatesVsJones.pdf"&gt;ruled unanimously&lt;/a&gt; yesterday that law enforcement must obtain a search warrant before placing a Global Positioning System (GPS) device on a suspect&amp;rsquo;s vehicle for purposes of tracking the vehicle&amp;rsquo;s location. The decision effectively overturned Antoine Jones&amp;rsquo;s life sentence for drug trafficking which was obtained, in part, through the use of location tracking information generated by a GPS device secretly placed by the FBI, without a search warrant, on Jones&amp;rsquo;s wife&amp;rsquo;s Jeep Grand Cherokee. Although the Court&amp;rsquo;s analysis focuses exclusively on the Fourth Amendment to the U.S. Constitution, which applies only to government actors, the decision has potentially important implications for private employers who are turning increasingly to location-tracking capabilities in vehicles, smartphones, and even laptops to track employees for management and investigative purposes.&lt;/p&gt;
&lt;p&gt;To begin with, the Court&amp;rsquo;s decision highlights the dearth of legislation in the area. None of the Court&amp;rsquo;s three opinions &amp;mdash; the lead opinion by Justice Scalia, a concurrence in that opinion by Justice Sotomayor, and an opinion by Justice Alito concurring in the result but not with Justice Scalia&amp;rsquo;s reasoning &amp;mdash; cited a single federal or state law which regulates location tracking. California&amp;rsquo;s statute prohibiting the installation of a tracking device on a vehicle without the consent of the vehicle&amp;rsquo;s owner or lessor appears to be&amp;nbsp;only one of two&amp;nbsp;laws (the other is&amp;nbsp;Texas)&amp;nbsp;on the subject with a significant impact on private employers. In the wake of the Supreme Court&amp;rsquo;s decision, employers should expect legislative activity in the area.&lt;/p&gt;&lt;p&gt;The decision also is important for private employers because five justices &amp;mdash; Justice Alito (joined in his concurrence by Justices Ginsberg, Breyer, and Kagan) as well as Justice Sotomayor &amp;mdash; rejected the majority position in the state and federal judiciary on the privacy of location data. Under that view, location tracking does not infringe any privacy interest because the location of a vehicle or a person in a public place is fundamentally not private. This majority view effectively leaves private employees without any remedy for an employer&amp;rsquo;s use of location tracking because a common law invasion of privacy claim can be asserted only for the breach of a recognized privacy interest, and a statutory remedy for unauthorized location tracking is rarely available.&lt;/p&gt;
&lt;p&gt;In rejecting the majority view, the five justices found a protected privacy interest in the patterns of private activity that can be derived from continuous location tracking notwithstanding the public nature of any particular data point. In the words of Justice Sotomayor, &amp;ldquo;GPS monitoring generates a precise, comprehensive record of a person&amp;rsquo;s public movements that reflects a wealth of detail about her familial, political, professional, religious, and sexual associations.&amp;rdquo; This view likely will have a significant influence on the thinking of trial and appellate court judges when confronted with an invasion of privacy claim based on an employer&amp;rsquo;s unauthorized tracking of an employee during &lt;em&gt;non-working&lt;/em&gt; hours. An employer might be tempted to engage in such tracking, for example, to check for abuse of paid or unpaid leave or to investigate suspected moonlighting or a potentially fraudulent workers&amp;rsquo; compensation claim.&lt;/p&gt;
&lt;p&gt;Consequently, the most important lesson for private employers to draw from the Court&amp;rsquo;s decision is the importance of limiting location tracking to working hours when the pattern of location data should not reveal details of an employee&amp;rsquo;s private life, and if it does, the employer has a legitimate business reason for knowing what the employee is doing other than earning his or her compensation. The New York appellate decision that we covered in &lt;a target="_blank" href="http://privacyblog.littler.com/2012/01/articles/location-tracking/is-it-legal-for-an-employer-to-secretly-track-an-employees-personal-vehicle-247-for-one-month-perhaps/"&gt;last week&amp;rsquo;s blog post&lt;/a&gt; illustrates the point. In that case, the majority did not take issue with the New York State Department of Labor&amp;rsquo;s 24/7 tracking of a high-level employee&amp;rsquo;s personal vehicle because the employer had a reasonable suspicion that the employee was not working when he said that he was. Under that reasoning, tracking an employee during working hours clearly would be permissible. On the other hand, the dissenting judges in the New York case found that tracking the employee during non-working hours was excessively intrusive, particularly because the GPS device reported the employee&amp;rsquo;s location during a week-long family vacation.&lt;/p&gt;
&lt;p&gt;Employers should note that many GPS devices are either on at all times or off. In these circumstances, employers should develop controls that will limit access to location tracking information to employees&amp;rsquo; scheduled working hours.&lt;/p&gt;
&lt;p&gt;Finally, private employers should note Justice Scalia&amp;rsquo;s reliance on the notion of trespass in finding that the government&amp;rsquo;s warrantless installation of the GPS device on Jones&amp;rsquo;s wife&amp;rsquo;s Jeep violated the Fourth Amendment. Similarly, an employer&amp;rsquo;s unauthorized placement of a GPS device on an employee&amp;rsquo;s personal vehicle might support a claim based on a common law trespass theory. As a result, employers should be particularly cautious when using any form of location tracking not associated with company-owned equipment.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/BXDN4gmr85Y" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/BXDN4gmr85Y/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/01/articles/location-tracking/what-does-the-supreme-courts-gps-decision-mean-for-private-employers/</guid>
         <category domain="http://privacyblog.littler.com/tags">California</category><category domain="http://privacyblog.littler.com/tags">Fourth Amendment</category><category domain="http://privacyblog.littler.com/tags">GPS</category><category domain="http://privacyblog.littler.com/tags">Location Privacy</category><category domain="http://privacyblog.littler.com/articles">Location Tracking</category><category domain="http://privacyblog.littler.com/articles">Surveillance</category><category domain="http://privacyblog.littler.com/tags">US Supreme Court</category>
         <pubDate>Tue, 24 Jan 2012 11:48:27 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/01/articles/location-tracking/what-does-the-supreme-courts-gps-decision-mean-for-private-employers/</feedburner:origLink></item>
            <item>
         <title>Is It Legal for an Employer to Secretly Track an Employee's Personal Vehicle 24/7 for One Month? Perhaps!</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip L. Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img hspace="2" alt="" vspace="2" align="right" width="275" height="182" src="http://privacyblog.littler.com/uploads/image/LocationTrackingII.jpg" /&gt;A &lt;a target="_blank" href="http://blogs.wsj.com/digits/2011/11/23/new-york-court-state-gps-tracking-of-worker-was-justified/"&gt;recent decision&lt;/a&gt; by a New York appellate court is one of the first cases to address the surreptitious use of location tracking for employment purposes. The &lt;a href="http://privacyblog.littler.com/uploads/file/ConnunighamVsNewYorkStateDepartmentOfLabor(1).pdf"&gt;3-2 split decision&lt;/a&gt; highlights the on-going disagreement among judges over the lawful use of Global Positioning Systems (GPS). The New York case is particularly noteworthy because the U.S. Supreme Court in &lt;em&gt;&lt;a target="_blank" href="http://privacyblog.littler.com/2010/08/articles/surveillance-2/dc-circuit-decision-ratchets-up-the-risk-for-employers-who-use-location-tracking/"&gt;U.S. v.&amp;nbsp;Jones&lt;/a&gt;&lt;/em&gt; (argued November 7, 2011)&amp;nbsp; (Note: the&amp;nbsp;lower court case is&lt;em&gt; U.S. v. Maynard&lt;/em&gt;, on &lt;em&gt;cert&lt;/em&gt; to the U.S. Supreme Court the case&amp;nbsp;is &lt;em&gt;U.S. v. Jones&lt;/em&gt;, referring to respondent Antoine Jones) is currently considering virtually the same issue addressed by the New York court, but in the criminal context. Given the increasing use of GPS in the workplace, employers need to understand the legal risks associated with this highly effective management and investigative tool.&lt;/p&gt;
&lt;p&gt;The subject of the New York case was a 30-year employee of New York&amp;rsquo;s Department of Labor, serving most of that time as the Department&amp;rsquo;s Director of Staff and Organizational Development. Despite his high-level position, he had been a &amp;ldquo;problem employee&amp;rdquo; for nearly a decade, having been disciplined on several occasions. The dispute that ultimately led to the appellate court decision had its inception in the Labor Department&amp;rsquo;s investigation of the employee for falsifying time records. The Department initially tried to track him the &amp;ldquo;old-fashioned way,&amp;rdquo; &lt;em&gt;i.e.&lt;/em&gt;, by tailing him, but the employee spotted and evaded the tail. The state&amp;rsquo;s Inspector General, to whom the Labor Department referred the investigation, then secretly planted a GPS device on the employee&amp;rsquo;s personal vehicle and collected location data 24/7 for a one-month period. Based, in part, on the location data collected, a Labor Department hearing officer recommended the employee&amp;rsquo;s termination for, among other things, falsifying time records.&lt;/p&gt;&lt;p&gt;Although the employee was a public employee, his case has relevance for private employers for the following reason. On appeal, the employee contended that the Labor Department could not lawfully rely on the location-tracking data to discipline him, invoking the exclusionary rule in New York&amp;rsquo;s civil service law. Under that rule, the hearing officer and the appellate court had to determine whether the Inspector General&amp;rsquo;s use of surreptitious location tracking was reasonable at inception and in its scope. That standard is similar to (albeit somewhat lower than) the standard that a court would apply to determine whether a private employer&amp;rsquo;s use of GPS to track an employee constituted a common law invasion of privacy. Given that no state other than California has enacted a law that prohibits a private employer from tracking an employee&amp;rsquo;s personal vehicle, a private employee terminated based on location information most likely would rely on a common law invasion of privacy claim to obtain a remedy.&lt;/p&gt;
&lt;p&gt;The appellate court&amp;rsquo;s split decision on the reasonableness of the Inspector General&amp;rsquo;s use of location tracking highlights the difficult balancing that private employers must conduct when considering whether to use GPS as an investigative tool. All five judges agreed that use of the GPS was reasonable at inception because the Labor Department had a reasonable suspicion of the employee&amp;rsquo;s wrongdoing. The three-judge majority further concluded that 24/7 location tracking for one month was reasonable because the employee had intentionally undermined less intrusive investigative methods and because &amp;ldquo;the GPS devices were not constantly monitored;&amp;rdquo; instead, the Inspector General extracted only location information revealing the employee&amp;rsquo;s whereabouts during working hours. Rejecting this reason, the two dissenters emphasized that the Labor Department&amp;rsquo;s &amp;ldquo;valid interest in [the employee&amp;rsquo;s] whereabouts extended only to the hours of his workday and yet the tracking had continued for one month.&amp;rdquo; The dissenters found it particularly troubling that the Inspector General had tracked the employee&amp;rsquo;s location during a week-long family vacation.&lt;/p&gt;
&lt;p&gt;The reasoning on both sides of the decision provides useful guidance for private employers seeking to use location tracking as an investigative tool. At least until the courts provide more guidance, it would be prudent for employers to use surreptitious location tracking only when other, less intrusive methods would be unsuccessful. In addition, where technically feasible, location tracking should be limited to working hours. When not technically feasible, employers should access only location data recorded during working hours.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;em&gt;Photo credit:&lt;/em&gt; &lt;/span&gt;&lt;a target="_blank" href="http://www.istockphoto.com/user_view.php?id=3082996"&gt;&lt;span style="font-size: xx-small"&gt;rrocio&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/YJ46KtjopuQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/YJ46KtjopuQ/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2012/01/articles/location-tracking/is-it-legal-for-an-employer-to-secretly-track-an-employees-personal-vehicle-247-for-one-month-perhaps/</guid>
         <category domain="http://privacyblog.littler.com/tags">GPS</category><category domain="http://privacyblog.littler.com/tags">Location Privacy</category><category domain="http://privacyblog.littler.com/articles">Location Tracking</category><category domain="http://privacyblog.littler.com/tags">New York</category><category domain="http://privacyblog.littler.com/articles">Surveillance</category>
         <pubDate>Fri, 20 Jan 2012 14:05:01 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2012/01/articles/location-tracking/is-it-legal-for-an-employer-to-secretly-track-an-employees-personal-vehicle-247-for-one-month-perhaps/</feedburner:origLink></item>
            <item>
         <title>Upcoming Privacy Events</title>
         <description>&lt;p&gt;&lt;img hspace="2" alt="" vspace="2" align="right" width="200" height="233" src="http://privacyblog.littler.com/uploads/image/Microphone(1).jpg" /&gt;Philip Gordon will be speaking on a range of privacy and data protection issues at the following upcoming events:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; January 11, 2012&lt;br /&gt;
&lt;strong&gt;Conference:&lt;/strong&gt; BNA&lt;br /&gt;
&lt;strong&gt;Location:&lt;/strong&gt; Webinar&lt;br /&gt;
&lt;strong&gt;Topic:&lt;/strong&gt; Phil Gordon and Michael McGuire, Shareholder and Chief Information Security Officer at Littler, will co-present &amp;ldquo;The Challenges of Bring Your Own Device (BYOD) to Work Policies&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;Description:&lt;/strong&gt; With employees demanding the ability to use their personal smart phones and tablets for business purposes and employers looking for new ways to reduce cost and increase productivity, the trend towards &amp;ldquo;dual-use devices&amp;rdquo; in the workplace will undoubtedly continue to pick up stream. This webinar will provide practical recommendations for both areas so that your organization understands the risks of saying &amp;ldquo;yes&amp;rdquo; to requests from C-level executives or department chiefs to connect their smartphones or tablets to the corporate network. &lt;br /&gt;
&lt;strong&gt;&lt;em&gt;For more information and to register, please visit:&lt;/em&gt;&lt;/strong&gt; &lt;a target="_blank" href="http://www.bna.com/own-device-19107/"&gt;www.bna.com/own-device-19107/&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; February 1, 2012&lt;br /&gt;
&lt;strong&gt;Conference:&lt;/strong&gt; ACI Privacy &amp;amp; Security of Consumer and Employee Information (pdf)&lt;br /&gt;
&lt;strong&gt;Location:&lt;/strong&gt; The Westin Washington, DC City Center, Washington D.C.&lt;br /&gt;
&lt;strong&gt;Topic:&lt;/strong&gt; &amp;ldquo;Mobile Devices, Applications, and Workforces: Minimizing the Threats Posed Through Proven Security Measures&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;Description:&lt;/strong&gt; Phil Gordon will moderate a panel of experts discussing, among other things, how to:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Raise employee awareness and educate employees in the handling of sensitive data&lt;/li&gt;
    &lt;li&gt;Safeguard company equipment and wireless devices and minimize damage in the event of breach&amp;nbsp;&lt;/li&gt;
    &lt;li&gt;Protect corporate networks from the use of multiple portable devices while preserving employee rights&lt;/li&gt;
    &lt;li&gt;Establish policies and procedures to strengthen and maintain data security&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;For more information and to register, please &lt;a target="_blank" href="http://privacyblog.littler.com/uploads/file/ACI11thPrivacyAndSecurityComplianceForum.pdf"&gt;click here&lt;/a&gt;&amp;nbsp;(pdf).&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; February 9-10, 2012&lt;br /&gt;
&lt;strong&gt;Conference:&lt;/strong&gt; Littler Global Employer &amp;ndash; Latin America Conference&lt;br /&gt;
&lt;strong&gt;Location:&lt;/strong&gt; Miami, Florida&lt;br /&gt;
&lt;strong&gt;Topic:&lt;/strong&gt; &amp;ldquo;The Legal and Operational Challenges of Complying with New Latin American Data Protection Laws&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;Description:&lt;/strong&gt; In the past two years, Colombia, Costa Rica, Mexico, Peru, and Uruguay have enacted broad data protection laws which generally follow the E.U. Model but also have a distinct Latin flavor. These laws require employers to fundamentally rethink the way that they handle employees&amp;rsquo; personal data in these countries and impose significant restrictions on the transfer of employees&amp;rsquo; personal data within the corporate group. This presentation will provide a detailed explanation of the key requirements of Mexico&amp;rsquo;s new privacy law and pending regulations, identify key similarities and differences among the new privacy laws in these five countries, and make practical recommendations for harmonizing multi-national compliance efforts from a legal and operational perspective. Joining in the discussion are speakers Michael McGuire, Shareholder and Chief Information Officer at Littler, Javiera Medina, Shareholder in Littler&amp;rsquo;s Mexico office and Dr. Rainer Lorenzo, Senior Director, Legal &amp;amp; Business Affairs, HBO Latin America.&lt;br /&gt;
&lt;strong&gt;&lt;em&gt;For more information and to register, please visit:&lt;/em&gt;&lt;/strong&gt; &lt;a target="_blank" href="http://www.littler.com/events/global-employer-latin-america"&gt;www.littler.com/events/global-employer-latin-america&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; March 9, 2012&lt;br /&gt;
&lt;strong&gt;Conference:&lt;/strong&gt; IAPP Global Privacy Summit &lt;br /&gt;
&lt;strong&gt;Location:&lt;/strong&gt; Washington Marriott Wardman Park, Washington D.C.&lt;br /&gt;
&lt;strong&gt;Topic:&lt;/strong&gt; &amp;ldquo;Who Are Your Applicants and Employees Anyway? Conducting Lawful Social&lt;br /&gt;
Media, Criminal History and Credit Checks&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;Description:&lt;/strong&gt; This session will examine background checks against the backdrop of vendor limitations, social media, new state laws, and FTC regulation. The presentation will cover recent legal developments affecting the permissible scope of background checks and provide practical steps an organization can take to conduct lawful background checks. &lt;br /&gt;
&lt;strong&gt;&lt;em&gt;For more information and to register, please visit:&lt;/em&gt;&lt;/strong&gt; &lt;a target="_blank" href="https://www.privacyassociation.org/events_and_programs/global_privacy_summit/"&gt;www.privacyassociation.org/events_and_programs/global_privacy_summit/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;em&gt;Photo credit:&lt;/em&gt; &lt;/span&gt;&lt;a target="_blank" href="http://www.istockphoto.com/user_view.php?id=1193096"&gt;&lt;span style="font-size: xx-small"&gt;CrackerClips&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/NnX6FJkC5Jc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/NnX6FJkC5Jc/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/12/articles/events/upcoming-privacy-events/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Cell Phones</category><category domain="http://privacyblog.littler.com/tags">Data Breach</category><category domain="http://privacyblog.littler.com/articles">Data Security</category><category domain="http://privacyblog.littler.com/articles">Electronic Resources Policy</category><category domain="http://privacyblog.littler.com/articles">Events</category><category domain="http://privacyblog.littler.com/tags">FTC</category><category domain="http://privacyblog.littler.com/tags">International</category><category domain="http://privacyblog.littler.com/tags">Portable Storage Devices</category><category domain="http://privacyblog.littler.com/tags">Privacy</category><category domain="http://privacyblog.littler.com/tags">Privacy Protection Policy</category><category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category><category domain="http://privacyblog.littler.com/tags">State Privacy Laws</category>
         <pubDate>Tue, 20 Dec 2011 10:10:24 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/12/articles/events/upcoming-privacy-events/</feedburner:origLink></item>
            <item>
         <title>New Littler Blog: Employee Benefits Counsel</title>
         <description>&lt;p&gt;&lt;img hspace="2" alt="" vspace="2" align="right" width="260" height="172" src="http://www.wageandhourcounsel.com/uploads/image/ExtraExtraII(1).jpg" /&gt;We are pleased to announce a new addition to Littler's blogroll:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;a target="_blank" href="http://www.employeebenefitscounsel.com"&gt;Employee Benefits Counsel&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Brought to you by Littler's &lt;a target="_blank" href="http://www.littler.com/practice-areas/employee-benefits"&gt;Employee Benefits&lt;/a&gt;, &lt;a target="_blank" href="http://www.littler.com/practice-areas/erisa-and-benefit-plan-litigation"&gt;ERISA and Benefit Plan Litigation&lt;/a&gt;, and &lt;a target="_blank" href="http://www.littler.com/practice-areas/executive-compensation"&gt;Executive Compensation&lt;/a&gt; practice groups, this blog covers:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Legislative and regulatory developments in the employee benefits arena, including the topics of health care reform; plan design and administration; employee benefits litigation; and&lt;/li&gt;
    &lt;li&gt;Executive compensation, providing insight and analysis on legal developments that warrant discussion.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;During this time of significant governmental change and shifts in the strategy and style of benefits litigation, Littler's depth of experience in employee benefits, litigation, and executive compensation matters gives our attorneys a distinctly broad perspective with which to provide insight and useful analysis of the latest developments. To subscribe to receive email alerts of new blog posts, please enter your email address in the Subscribe box on the right side of the Employee Benefits Counsel blog homepage.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;i&gt;Photo credit:&lt;/i&gt; &lt;a target="_blank" href="http://www.istockphoto.com/user_view.php?id=437590"&gt;&lt;span style="font-size: xx-small"&gt;IdeaBug Media&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/7NVzoHfNCJY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/7NVzoHfNCJY/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/11/articles/announcements-2/new-littler-blog-employee-benefits-counsel/</guid>
         <category domain="http://privacyblog.littler.com/articles">Announcements</category>
         <pubDate>Wed, 30 Nov 2011 17:04:13 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/11/articles/announcements-2/new-littler-blog-employee-benefits-counsel/</feedburner:origLink></item>
            <item>
         <title>EEOC Advisory Opinion on Employer Use of Arrest &amp; Conviction Records During Hiring Process</title>
         <description>&lt;p&gt;The Equal Employment Opportunity Commission's Office of Legal Counsel released an advisory opinion on employer use of arrest and conviction records during the hiring process. The non-binding letter provides some insight into the Commission's current enforcement position and suggests the Commission: (1) will continue to differentiate between arrest and conviction records; (2) may not be prepared to adopt a presumption of disparate impact in this context; and (3) will in the event of a finding of disparate impact, closely scrutinize the employer's policy with regard to both how long convictions are disqualifying and whether the underlying criminal conduct is related to the job duties for the position in question. To learn more about the EEOC's advisory opinion and its potential impact on employers, please continue reading Littler's Insight, &lt;em&gt;&lt;a target="_blank" href="http://www.littler.com/publication-press/publication/eeoc-advisory-guidance-offers-insight-use-arrest-and-conviction-record"&gt;EEOC Advisory Guidance Offers Insight on the Use of Arrest and Conviction Records&lt;/a&gt;, &lt;/em&gt;by &lt;a target="_blank" href="http://www.littler.com/people/rod-m-fliegel"&gt;Rod Fliegel&lt;/a&gt; and &lt;a target="_blank" href="http://www.littler.com/people/jennifer-l-mora"&gt;Jennifer Mora&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/F9YrxZuoupE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/F9YrxZuoupE/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/10/articles/background-checks/eeoc-advisory-opinion-on-employer-use-of-arrest-conviction-records-during-hiring-process/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Conviction</category><category domain="http://privacyblog.littler.com/tags">Criminal History</category><category domain="http://privacyblog.littler.com/tags">EEOC</category>
         <pubDate>Tue, 25 Oct 2011 15:37:50 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/10/articles/background-checks/eeoc-advisory-opinion-on-employer-use-of-arrest-conviction-records-during-hiring-process/</feedburner:origLink></item>
            <item>
         <title>California Restricts Employer Use of Credit Reports</title>
         <description>&lt;p&gt;On October 10, 2011, the Office of California Governor Jerry Brown announced that Governor Brown had signed AB 22, legislation that adds a new provision to the California Labor Code and amends the state's Consumer Credit Reporting Agencies Act to restrict the discretion that private and public sector employers have to use &amp;quot;consumer credit reports&amp;quot; for hiring and personnel decisions. Together, the new laws, which take effect on January 1, 2012, limit when employers lawfully can use consumer credit reports and impose notice and disclosure obligations on employers who intend to do so. To learn more about the laws and their implications for employers, please continue reading Littler's ASAP, &lt;em&gt;&lt;a target="_blank" href="http://www.littler.com/publication-press/publication/california-joins-states-restricting-use-credit-reports-employment-purp"&gt;California Joins States Restricting Use of Credit Reports for Employment Purposes&lt;/a&gt;&lt;/em&gt;, by &lt;a target="_blank" href="http://www.littler.com/people/rod-m-fliegel"&gt;Rod Fliegel&lt;/a&gt; and &lt;a target="_blank" href="http://www.littler.com/people/jennifer-l-mora"&gt;Jennifer Mora&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/4doiC4dsfhc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/4doiC4dsfhc/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/10/articles/background-checks/california-restricts-employer-use-of-credit-reports/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Credit History</category><category domain="http://privacyblog.littler.com/tags">Credit Report</category><category domain="http://privacyblog.littler.com/tags">State Privacy Laws</category><category domain="http://privacyblog.littler.com/articles">State Privacy Legislation</category>
         <pubDate>Mon, 10 Oct 2011 09:53:22 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/10/articles/background-checks/california-restricts-employer-use-of-credit-reports/</feedburner:origLink></item>
            <item>
         <title>NLRB Opens Useful Escape Hatch for Employers Responding to Obnoxious Social Media Conduct</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/people/philip-l-gordon"&gt;Philip L. Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Selling luxury cars in a down economy can be tough enough without employees mocking a company-sponsored sales event on their Facebook page. An administrative law judge (ALJ) with the National Labor Relations Board (NLRB) issued an opinion last week holding that the National Labor Relations Act (NLRA) protected an employee&amp;rsquo;s sarcastic post, but nonetheless upheld the dealership&amp;rsquo;s termination decision because it was based on other, unprotected Facebook content. The decision is an important reminder for employers that when protected and unprotected content appear on the same Facebook wall, the protected content does not shield the employee from discipline based on the unprotected content.&lt;/p&gt;
&lt;p&gt;The Knauz BMW dealership in Lake Bluff, Illinois, planned the &amp;ldquo;Ultimate Driving Event&amp;rdquo; to introduce the redesigned BMW 5 Series to its customers. At the event, the dealership not only offered BMW representatives, rather than the dealership&amp;rsquo;s sales staff, to take customers for a test drive, but also served hot dogs from a hot dog car as well as chocolate chip cookies, small bags of Doritos, and water. Upon learning of the dealership&amp;rsquo;s plans for the event, salesman Bobby Becker, and at least one other salesperson questioned the culinary selection. After the event, Becker tweaked the dealership on his Facebook page: &amp;ldquo;The small 8 oz. bags of chips, and the $2.00 cookie plate from Sam&amp;rsquo;s Club, and the semi fresh apples and oranges were such a nice touch . . . but to top it all off . . . the Hot Dog Cart. Where our clients could attain a over cooked weiner and a stale bunn . . . &amp;rdquo;&lt;/p&gt;&lt;p&gt;Becker&amp;rsquo;s rag on the Ultimate Driving Event did not stand alone. On the same day, he also posted about a potentially serious mishap at the nearby Land Rover dealership also owned by Knauz BMW. Becker described the drama on his Facebook page, alongside a photograph with the following comment: &amp;ldquo;This [photograph shows] what happens when a sales Person sitting in the front passenger seat (Former Sales Person, actually) allows a 13 year old boy to get behind the wheel of a 6000 lb. truck built and designed to pretty much drive over anything. The kid drives over his father&amp;rsquo;s foot and into the pond in all about 4 seconds and destroys a $50,000 truck. OOOPS!&amp;rdquo;&lt;/p&gt;
&lt;p&gt;In deciding whether Knauz BMW violated the NLRA by discharging Becker, the ALJ agreed with the NLRB&amp;rsquo;s General Counsel that Becker&amp;rsquo;s Facebook comments about the food at the Ultimate Drive Event were protected concerted activity, a position previously expressed by the General Counsel in its August 2011 report on the NLRB&amp;rsquo;s social media cases which we discussed in an &lt;a target="_blank" href="http://privacyblog.littler.com/2011/08/articles/social-networking-1/more-guidance-from-the-nlrb-on-social-media-when-must-employers-not-fire-an-employee-for-an-offensive-facebook-post/"&gt;earlier blog post&lt;/a&gt;. The ALJ reasoned that Becker&amp;rsquo;s comments were protected because it was possible, albeit not likely, that the food selection could have had an impact on Becker&amp;rsquo;s commission-based compensation. In the words of the ALJ, &amp;ldquo;some customers [possibly] were turned off by the food offerings at the sales event and [perhaps] did not purchase a car because of it.&amp;rdquo; The ALJ also found that Becker&amp;rsquo;s Facebook posting was concerted activity &amp;mdash; even though no co-worker participated in, or commented on, the post &amp;mdash; because the post was the &amp;ldquo;logical outgrowth of&amp;rdquo; the criticisms by Becker and at least one other co-worker of the food selection during the sales force&amp;rsquo;s meeting with management before the event. This result demonstrates just how broadly the NLRB interprets the concept of &amp;ldquo;protected concerted activity&amp;rdquo; which cannot properly be the subject of employee discipline.&lt;/p&gt;
&lt;p&gt;Notably, the ALJ rejected Knauz BMW&amp;rsquo;s argument that Becker&amp;rsquo;s Facebook post should lose its protection under the NLRA because the post disparaged the dealership. Without much analysis, the ALJ noted that the NLRB had previously rejected the same argument in cases where employees&amp;rsquo; protected speech was mocking, sarcastic, satirical, ironic, demeaning or even degrading. It appears that an employee&amp;rsquo;s protected speech will need to reach a high level of injuriousness before the Board will strip that speech of the NLRA&amp;rsquo;s protections.&lt;/p&gt;
&lt;p&gt;Although Becker had engaged in protected concerted activity, the ALJ still determined that Knauz BMW&amp;rsquo;s decision to axe Becker was lawful. The ALJ found persuasive the testimony of management employees that Becker&amp;rsquo;s facetious comments about the serious and potentially deadly Land Rover mishap triggered the termination decision. The ALJ then determined that this post did not constitute protected concerted activity because &amp;ldquo;it was posted solely by Becker,&amp;rdquo; &amp;ldquo;without any discussion with any other employee,&amp;rdquo; and &amp;ldquo;had no connection to any other employees&amp;rsquo; terms and conditions of employment.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The lesson for employers? Employees who post some protected social media content do not protect themselves with impunity from adverse employment action. Employers can rely on unrelated, unprotected social media posts to justify termination;they just need to be prepared to prove that the unprotected speech was the driving force behind the disciplinary decision.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/ylyq-NNTtCY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/ylyq-NNTtCY/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/10/articles/labor-relations/nlrb-opens-useful-escape-hatch-for-employers-responding-to-obnoxious-social-media-conduct/</guid>
         <category domain="http://privacyblog.littler.com/tags">Facebook</category><category domain="http://privacyblog.littler.com/articles">Internet Communications</category><category domain="http://privacyblog.littler.com/articles">Labor Relations</category><category domain="http://privacyblog.littler.com/tags">NLRA</category><category domain="http://privacyblog.littler.com/tags">NLRB</category><category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category>
         <pubDate>Mon, 03 Oct 2011 12:40:22 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/10/articles/labor-relations/nlrb-opens-useful-escape-hatch-for-employers-responding-to-obnoxious-social-media-conduct/</feedburner:origLink></item>
            <item>
         <title>California Amends its Security Breach Notification Law</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=03474"&gt;Ellen M. Giblin&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img hspace="2" alt="" vspace="2" align="right" width="300" height="199" src="http://privacyblog.littler.com/uploads/image/DataSecurity.jpg" /&gt;On August 31, 2011, Governor Jerry Brown signed &lt;a target="_blank" href="http://www.leginfo.ca.gov/pub/11-12/bill/sen/sb_0001-0050/sb_24_bill_20110831_chaptered.html"&gt;Senate Bill 24&lt;/a&gt;, amending &lt;a target="_blank" href="http://www.leginfo.ca.gov/cgi-bin/displaycode?section=civ&amp;amp;group=01001-02000&amp;amp;file=1798.80-1798.84"&gt;California&amp;rsquo;s security breach notification law&lt;/a&gt;. That law was the nation&amp;rsquo;s first to require data owners to disclose a data breach to any California resident whose unencrypted personal information is reasonably believed to have been acquired by an unauthorized person. Senate Bill 24 applies to breaches occurring on or after January 1, 2012, and makes several important changes to the landmark law.&lt;/p&gt;
&lt;p&gt;First, SB 24 enhances the security breach notifications sent to affected individuals. Whereas before the notice law did not impose any requirements for the content of the notice, the amended law requires that the notice contain specific information regarding the breach, including the following: (a) the name and contact information of the reporting person or business; (b) the types of personal information subject to the breach; (c) the date or date range of the breach; (d) whether notification was delayed due to law enforcement investigation; (e) a general description of the breach; and (f) the toll-free telephone numbers and addresses of the three major credit bureaus, if the breach exposed a social security number, driver&amp;rsquo;s license or California identification card number.&lt;/p&gt;&lt;p&gt;Second, SB 24 adds a requirement to notify the state&amp;rsquo;s attorney general about a breach. More specifically, the notice law now requires any agency, person, or business that sends a security breach notice to more than 500 California residents to electronically submit a single sample copy of that security breach notification to the attorney general, &lt;u&gt;excluding&lt;/u&gt; any personally identifiable information. This change adds California to the list of states that require some type of notice to the state&amp;rsquo;s primary regulator of security breaches.&lt;/p&gt;
&lt;p&gt;Third, this bill deems any HIPAA-covered entity to have complied with California&amp;rsquo;s new notification requirements if the covered entity complied with the similar breach notification requirements in Section 13402(f) of the federal Health Information Technology for Economic and Clinical Health Act (&amp;ldquo;HITECH Act&amp;rdquo;). However, the covered entity is not exempt from any other provision of California&amp;rsquo;s notice law.&lt;/p&gt;
&lt;p&gt;Finally, SB 24 also amends &lt;a target="_blank" href="http://www.leginfo.ca.gov/cgi-bin/displaycode?section=civ&amp;amp;group=01001-02000&amp;amp;file=1798.80-1798.84"&gt;Section 1798.82(j)&lt;/a&gt; of California&amp;rsquo;s security breach notification law regarding substitute notice. Reporting entities which seek to notify individuals of a security breach through the state&amp;rsquo;s media, rather than directly, must now also notify the Office of Privacy Protection within the State and Consumer Services Agency.&lt;/p&gt;
&lt;p&gt;In light of these changes, employers will need to update their incident management plans and add these new requirements into their notification policies to ensure compliance with the many state data breach notification requirements.&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://www.leginfo.ca.gov/pub/11-12/bill/sen/sb_0001-0050/sb_24_bill_20110831_chaptered.html"&gt;California SB 24 takes effect January 1, 2012&lt;/a&gt;, providing enhanced notification requirements similar to those required under the federal Health Insurance Portability and Accountability Act of 1996 (&lt;a target="_blank" href="http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr;sid=5ce90879452693ef1e6dfb046a91d954;rgn=div5;view=text;node=45%3A1.0.1.3.77;idno=45;cc=ecfr"&gt;HIPAA&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Hard copy breaches are still not covered under the California law.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;em&gt;Photo credit:&lt;/em&gt; &lt;/span&gt;&lt;a target="_blank" href="http://www.istockphoto.com/user_view.php?id=362802"&gt;&lt;span style="font-size: xx-small"&gt;dra_schwartz&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/0x5IphzpQNs" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/0x5IphzpQNs/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/09/articles/state-privacy-legislation/california-amends-its-security-breach-notification-law/</guid>
         <category domain="http://privacyblog.littler.com/tags">California</category><category domain="http://privacyblog.littler.com/tags">Data Breach</category><category domain="http://privacyblog.littler.com/articles">Data Security</category><category domain="http://privacyblog.littler.com/articles">HIPAA</category><category domain="http://privacyblog.littler.com/tags">HITECH Act</category><category domain="http://privacyblog.littler.com/tags">Security Breach</category><category domain="http://privacyblog.littler.com/tags">State Privacy Laws</category><category domain="http://privacyblog.littler.com/articles">State Privacy Legislation</category>
         <pubDate>Fri, 09 Sep 2011 12:55:55 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/09/articles/state-privacy-legislation/california-amends-its-security-breach-notification-law/</feedburner:origLink></item>
            <item>
         <title>More Guidance from the NLRB on Social Media: When Must Employers Not Fire an Employee for an Offensive Facebook Post?</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=01956"&gt;Philip Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="199" alt="" hspace="2" width="300" align="right" vspace="2" src="http://privacyblog.littler.com/uploads/image/reportII.jpg" /&gt;In a &lt;a target="_blank" href="http://privacyblog.littler.com/2011/08/articles/social-networking-1/when-can-employers-lawfully-fire-an-employee-for-an-offensive-facebook-post-ask-the-nlrb/"&gt;recent blog post&lt;/a&gt;, we addressed three Advice Memos issued by the National Labor Relations Board&amp;rsquo;s (NLRB or the &amp;ldquo;Board&amp;rdquo;) Division of Advice, which provided useful guidance on the types of social media conduct that do &lt;u&gt;not&lt;/u&gt; enjoy protection under the National Labor Relations Act (NLRA). On August 18, 2011, not long after the publication of those Advice Memos, the NLRB&amp;rsquo;s General Counsel issued a &lt;a href="http://privacyblog.littler.com/uploads/file/NLRBAugust18Memo.pdf"&gt;lengthy memorandum&lt;/a&gt; to all Regional Directors that summarizes the Board&amp;rsquo;s resolution of more than one dozen &amp;ldquo;social media cases,&amp;rdquo; including the three cases discussed in our prior blog post. As a contrast to that post, this post will focus on the cases in the August 18, 2011, Memorandum where the General Counsel found that an employer&amp;rsquo;s discharge of an employee violated the NLRA. The August 18, 2011, Memorandum also provides useful guidance on social media policies, which are addressed below as well.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;When Not to Fire an Employee Based on a Social Media Post&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The August 18, 2011, Memorandum summarizes four cases that concluded that the employer&amp;rsquo;s discipline violated the NLRA. In a nutshell, these cases involved the termination of one or more employees based on the following social media conduct:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&amp;nbsp;While preparing for a meeting with management, an employee asked coworkers on her Facebook page for their reaction to another employee&amp;rsquo;s complaints about work quality and staffing levels at the employer;&lt;/li&gt;
    &lt;li&gt;An employee complained on her Facebook page about her supervisor&amp;rsquo;s refusal to permit a union representative to assist her in responding to a customer complaint about the employee;&lt;/li&gt;
    &lt;li&gt;A salesmen at a car dealership criticized on his Facebook page the dealership&amp;rsquo;s handling of a sales event intended to promote a new car model and posted mildly mocking photographs that included his coworkers;&lt;/li&gt;
    &lt;li&gt;Employees posted on Facebook about the employer&amp;rsquo;s failure to withhold state income taxes, resulting in the employees&amp;rsquo; receiving payment demands from state tax authorities.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In all of these cases, employees posted on their own Facebook page, on their own time, and using their own equipment.&lt;/p&gt;
&lt;p&gt;When viewed as a group, these cases have a common thread that provides substantial insight into how the Board analyzes social media cases. Most importantly, the subject matter of each of these posts related to the terms and conditions of employment, the exercise of rights conferred by the NLRA, or other matters traditionally considered &amp;ldquo;protected activity&amp;rdquo; under the Boards&amp;rsquo; precedent. The topics included: (a) preparation for a discussion with management about employees&amp;rsquo; job performance and the employer&amp;rsquo;s staffing levels; (b) the right in a unionized workplace to union representation during an investigatory interview by the employer; (c) conduct by the employer (a sales event) that could have an impact on employees&amp;rsquo; compensation (their sales commissions); and (d) the employer&amp;rsquo;s administration of income tax withholdings.&lt;/p&gt;
&lt;p&gt;Of equal significance, in each of these situations, the General Counsel concluded that employees were collaborating, otherwise known as &amp;ldquo;concerted activity.&amp;rdquo; In the first case, the employee was seeking assistance from coworkers in preparation for a discussion with management. In the second case, the employee was discussing supervisory actions with coworkers who were her Facebook friends. In the third case, the employee was expressing the sentiment of his coworkers about the sales event. In the fourth case, employees were sharing concerns about the employer&amp;rsquo;s failure to withhold state income taxes. None of these cases could be said to involve individual gripes.&lt;/p&gt;
&lt;p&gt;While the fulcrum of these cases is the General Counsel&amp;rsquo;s determination that the disciplined employees were discussing protected subject matters and doing so in concert with their coworkers, there is one other common thread that can help employers weigh risks when deciding whether an employee&amp;rsquo;s social media post justifies discipline. In each of the cases, the offending Facebook post was either the culmination of an on-going dispute with the employer or the continuation of a pre-existing conversation among employees. In contrast to these fact patterns, the Facebook posts discussed in our previous blog entry and upon which the Division of Advice relied to justify discipline were relatively spontaneous and had no real history behind them.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Profanity Generally Will Not Justify Discipline for Protected Concerted Activity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;According to the General Counsel, the offending Facebook posts in these cases included &amp;ldquo;swearing and/or sarcasm,&amp;rdquo; use of a &amp;ldquo;short-hand expletive,&amp;rdquo; and references to management personnel as an &amp;ldquo;asshole&amp;rdquo; and a &amp;ldquo;scumbag.&amp;rdquo; Nonetheless, in each case, the General Counsel concluded that the employer&amp;rsquo;s termination violated the NLRA.&lt;/p&gt;
&lt;p&gt;The General Counsel&amp;rsquo;s analysis in these cases seems to give employees a license to curse. In finding that an employee did not lose the NLRA&amp;rsquo;s protections after calling her supervisor a &amp;ldquo;scumbag,&amp;rdquo; the General Counsel relied on the following facts: (a) &amp;ldquo;the Facebook posts did not interrupt the work of any employee because they occurred outside the workplace and during nonworking time;&amp;rdquo; (b) &amp;ldquo;the comments were made during an online employee discussion on supervisory action;&amp;rdquo; (c) &amp;ldquo;the name-calling was not accompanied by verbal or physical threats;&amp;rdquo; (d) &amp;ldquo;the Board has found more egregious name-calling protected;&amp;rdquo; and (e) &amp;ldquo;the employee&amp;rsquo;s Facebook postings were provoked by the supervisor&amp;rsquo;s unlawful&amp;rdquo; conduct.&lt;/p&gt;
&lt;p&gt;In social media cases, the first three or four factors listed above typically will be present. Thus, the Board effectively is telling employers that they must have a thicker skin when it comes to employees&amp;rsquo; raunchy social media posts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disclaimers and Carefully Crafted Policies Are Critical&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Throughout the August 18, 2011, Memorandum, the General Counsel identified social media policy provisions that the General Counsel deemed overbroad and in violation of the NLRA. At first blush, these determinations are portentous for employers because employers routinely include the challenged provisions in their social media policy. However, the August 18, 2011, Memorandum suggests &amp;mdash; at least implicitly &amp;mdash; how employers can retain these commonly used policy provisions without running afoul of the NLRA.&lt;/p&gt;
&lt;p&gt;The list of policy provisions found to be overbroad is lengthy but worthy of repetition. The list includes the following:&lt;/p&gt;
&lt;ol&gt;
    &lt;li&gt;&lt;u&gt;Inappropriate Discussions&lt;/u&gt;: Prohibition against &amp;ldquo;inappropriate discussions about the company, management, and/or coworkers;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Defamation&lt;/u&gt;: Prohibition on any social media post that &amp;ldquo;constitutes embarrassment, harassment or defamation of the [company] or of any [company] employee, officer, board member, representative, or staff member;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Disparagement&lt;/u&gt;: Prohibition against &amp;ldquo;employees making disparaging comments when discussing the company or the employee&amp;rsquo;s superiors, coworkers and/or competitors;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Privacy&lt;/u&gt;: Prohibition on &amp;ldquo;revealing, including through the use of photographs, personal information regarding coworkers, company clients, partners, or customers without their consent;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Confidentiality&lt;/u&gt;: Prohibition on &amp;ldquo;disclosing inappropriate or sensitive information about the Employer;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Contact Information&lt;/u&gt;: Prohibition on &amp;ldquo;using the company name, address, or [related] information on [employees&amp;rsquo;] personal profiles;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Logo&lt;/u&gt;: Prohibition on using &amp;ldquo;the Employer&amp;rsquo;s logos and photographs of the Employer&amp;rsquo;s store, brand, or product, without written authorization;&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Photographs&lt;/u&gt;: Prohibition against &amp;ldquo;employees posting pictures of themselves in any media . . . which depict the Company in any way, including company uniform [or] corporate logo.&amp;rdquo;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Removing all of the prohibitions described above would eviscerate most social media policies. Fortunately, such drastic action does not appear to be necessary.&lt;/p&gt;
&lt;p&gt;In finding these rules unlawful, the General Counsel emphasized not only their overbreadth (&lt;em&gt;i.e.&lt;/em&gt;, &amp;ldquo;the [rules] utilized broad terms that would commonly apply to protected criticism of . . . terms and conditions of employment&amp;rdquo;), but also that &amp;ldquo;&lt;em&gt;the rule[s] contained no limiting language to inform employees that [the rules] did not apply to Section 7 activity&lt;/em&gt;.&amp;rdquo; This italicized language suggests that the rules quoted above will &lt;em&gt;not&lt;/em&gt; violate the NLRA as long as the policy contains a disclaimer which explicitly informs employees that the policy will not be construed or applied in a manner that improperly interferes with employees&amp;rsquo; rights under Section 7 of the NLRA.&lt;/p&gt;
&lt;p&gt;The General Counsel also provided some guidance for policy drafting by rejecting challenges to several other policy provisions. One upheld policy, for example, provided that &amp;ldquo;no employee could ever be pressured to &amp;lsquo;friend&amp;rsquo; or otherwise connect with a coworker via social media.&amp;rdquo; The General Counsel reasoned that this policy was &amp;ldquo;sufficiently specific,&amp;rdquo; &amp;ldquo;clearly applied only to harassing conduct,&amp;rdquo; and could not be read to prohibit employees from friending for purposes of engaging in activity protected under the NLRA.&lt;/p&gt;
&lt;p&gt;In a second example, the General Counsel approved of a policy that required employees to &amp;ldquo;maintain confidentiality about sensitive information&amp;rdquo; and to direct all media inquiries to the company&amp;rsquo;s public affairs office after stating that the employee was not authorized to comment. The General Counsel determined that this policy did not violate the NLRA because it was intended only &amp;ldquo;to ensure a consistent, controlled company message,&amp;rdquo; was not a blanket prohibition on all contact between employees and the media, and &amp;ldquo;did not convey the impression that employees could not speak out on the terms and conditions of their employment.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;These examples suggest that an employer can increase the likelihood that its social media policy will survive the NLRB&amp;rsquo;s scrutiny if the policy emphasizes the legitimate purposes that it seeks to achieve, such as protecting the employer&amp;rsquo;s good will and brand reputation. In addition, restrictions in the policy on employees&amp;rsquo; social media conduct should, where practicable, be narrowly tailored to meet those legitimate objectives.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;i&gt;Photo credit:&lt;/i&gt; &lt;/span&gt;&lt;a target="_BLANK" href="http://www.istockphoto.com/user_view.php?id=814005"&gt;&lt;span style="font-size: xx-small"&gt;TommL&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/9idBMtIuEsQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/9idBMtIuEsQ/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/08/articles/social-networking-1/more-guidance-from-the-nlrb-on-social-media-when-must-employers-not-fire-an-employee-for-an-offensive-facebook-post/</guid>
         <category domain="http://privacyblog.littler.com/tags">Employment Policies</category><category domain="http://privacyblog.littler.com/articles">Internet Communications</category><category domain="http://privacyblog.littler.com/articles">Labor Relations</category><category domain="http://privacyblog.littler.com/tags">NLRA</category><category domain="http://privacyblog.littler.com/tags">NLRB</category><category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category>
         <pubDate>Mon, 22 Aug 2011 15:05:08 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/08/articles/social-networking-1/more-guidance-from-the-nlrb-on-social-media-when-must-employers-not-fire-an-employee-for-an-offensive-facebook-post/</feedburner:origLink></item>
            <item>
         <title>Telework - The Crisp New Term for "Working from Home"</title>
         <description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=03474"&gt;Ellen M. Giblin&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="300" alt="Seal of the Office of Personnel Management" hspace="2" width="300" align="right" vspace="2" src="http://privacyblog.littler.com/uploads/image/OPMII.jpg" /&gt;&lt;a href="http://www.telework.gov/guidance_and_legislation/telework_guide/telework_guide.pdf"&gt;The Guide to Telework in the Federal Government&lt;/a&gt; informs and provides guidance on the Telework Enhancement Act of 2010, which was signed into law on December 9, 2010. The Act establishes baseline expectations for the federal telework program and is a key factor in the federal government&amp;rsquo;s ability to achieve greater flexibility in managing its workforce. The Telework Guide is an understandable roadmap for other employers to the future of a remote and plugged-in workforce, while complying with the myriad of laws that govern the traditional workplace.&lt;/p&gt;
&lt;p&gt;The &lt;em&gt;&lt;a href="http://www.gpo.gov/fdsys/pkg/BILLS-111hr1722enr/pdf/BILLS-111hr1722enr.pdf"&gt;Telework Enhancement Act of 2010&lt;/a&gt; &lt;/em&gt;defines &amp;quot;telework&amp;quot; as a work flexibility arrangement under which an employee performs his or her duties and responsibilities from an approved worksite other than the location from which the employee would otherwise work. The fundamental principle of the telework program is clear: telework is not an employee right. Federal law requires agencies to establish telework programs, but does not give individual employees a legal right to telework. Importantly, the Telework Guide states that telework may not be used as a substitute for dependent care [the Guide specifically states that it may be used as a reasonable accommodation], and that employee participation in telework is voluntary.&lt;/p&gt;&lt;p&gt;Telework is primarily an arrangement established to facilitate the accomplishment of work. Private employers, like federal agencies, retain the discretion and obligation to determine employee eligibility for telework subject to business-related needs. For private employers this guide is a gem; it provides guidance on the policies and procedures that the federal government considers necessary to address the risks and rewards of a remote workforce.&lt;/p&gt;
&lt;p&gt;With respect to privacy and information security, the Telework Guide provides guidance on the proper handling of confidential information and training on appropriate safeguards for customer and employee information. The Telework Guide states, under the section entitled &amp;ldquo;Safeguarding Information and Data,&amp;rdquo; that &amp;ldquo;[e]mployees must take responsibility for the security of the data and other information they handle while teleworking.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Interestingly, the basis of the work relationship is a &amp;ldquo;Telework Agreement.&amp;rdquo; Each eligible employee authorized to telework enters into a written agreement with his/her supervisor which includes an interactive telework training program provided to eligible employees and their managers. The program must be successfully completed by employees before entering into the written telework agreement.&lt;/p&gt;
&lt;p&gt;Private employers will benefit from the guidance provided in The Telework Guide. Although the Guide applies only to federal employers, there are strong parallels between telework in the private and public sectors, particularly when it comes to safeguarding sensitive customer and employee information.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/SNUMvU_yEhA" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/SNUMvU_yEhA/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/08/articles/telecommuting/telework-the-crisp-new-term-for-working-from-home/</guid>
         <category domain="http://privacyblog.littler.com/tags">Federal Privacy Laws</category><category domain="http://privacyblog.littler.com/tags">Office of Personnel Management</category><category domain="http://privacyblog.littler.com/articles">Telecommuting</category><category domain="http://privacyblog.littler.com/tags">Telework</category><category domain="http://privacyblog.littler.com/tags">Telework Enhancement Act of 2010</category>
         <pubDate>Mon, 22 Aug 2011 13:04:18 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/08/articles/telecommuting/telework-the-crisp-new-term-for-working-from-home/</feedburner:origLink></item>
            <item>
         <title>When Can Employers Lawfully Fire an Employee for an Offensive Facebook Post? Ask the NLRB</title>
         <description>&lt;p&gt;&lt;i&gt;By&lt;/i&gt; &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=01956"&gt;Philip L. Gordon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="245" alt="National Labor Relations Board Seal" hspace="2" width="250" align="right" vspace="2" src="http://privacyblog.littler.com/uploads/image/NLRBLOGOIII.jpg" /&gt;Ever since the National Labor Relations Board (NLRB) &lt;a target="_blank" href="http://www.laborrelationscounsel.com/labor-management-relations/case-to-watch-nlrb-challenges-employers-termination-of-employee-based-on-violation-of-social-media-p/"&gt;filed a complaint&lt;/a&gt;, last November, against ambulance service provider AMR for firing an employee who had called her supervisor a &amp;ldquo;mental patient&amp;rdquo; on her Facebook wall, employers have been forced to ask themselves the following question: Do I really need to worry that the NLRB will knock on my door every time I discipline an employee for an obnoxious or offensive Facebook post related to work? Until two weeks ago, there was no easy answer to that question. The AMR case and virtually all of the other &amp;ldquo;Facebook cases&amp;rdquo; initiated by the NLRB had either &lt;a target="_blank" href="http://privacyblog.littler.com/2011/02/articles/social-networking-1/settlement-in-nlrbs-amrfacebook-case-contains-message-for-employers-about-social-media-policies/"&gt;settled&lt;/a&gt; or had not yet resulted in a published decision. Then, last month, the NLRB&amp;rsquo;s Office of General Counsel issued three Advice Memoranda in rapid succession that provide at least some guidance for employers trying to navigate the intersection of social media and labor law.&lt;/p&gt;&lt;p&gt;Two of the Advice Memoranda draw the same bright line rule: an employee who communicates about work through Facebook but only with family or friends cannot invoke the protections of the National Labor Relations Act (NLRA) to avoid dismissal. In one of these two cases, an employee of a residential home for homeless individuals with significant mental illness posted facetious comments about residents on her Facebook wall. Only a personal friend responded to the Facebook posts, and none of the employee&amp;rsquo;s coworkers were her Facebook friends. The &lt;a target="_blank" href="http://mynlrb.nlrb.gov/link/document.aspx/09031d458056e73e"&gt;General Counsel concluded&lt;/a&gt; that the employee&amp;rsquo;s Facebook posts were not protected because the employee was merely communicating with personal friends about work. In addition: (a) her posts did not relate to the terms or conditions of employment; (b) the employee did not discuss her posts with coworkers, and no coworkers responded to them; and (c) the employee was not seeking to induce collective action and her posts were not an outgrowth of collective concerns.&lt;/p&gt;
&lt;p&gt;The second case was a slightly tougher one. There, a bartender complained through Facebook to his step-sister about this employer&amp;rsquo;s policy barring him from sharing in tips given to servers even though the bartenders helped to serve food. The &lt;a target="_blank" href="http://mynlrb.nlrb.gov/link/document.aspx/09031d458055b9c6"&gt;General Counsel concluded&lt;/a&gt; that the bartender could not rely on the NLRA to reverse his firing, even though the post related to the terms of employment, for the same reasons that the employee of the residential home could not do so &amp;ndash; the employee did not discuss his post with coworkers and the employee was not seeking to induce collective actions.&lt;/p&gt;
&lt;p&gt;The third case provides the most useful guidance, drawing the line between individual gripes (unprotected) and collective activity (protected). In that case, the employee made the following comments about her store&amp;rsquo;s Assistant Manager:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I swear if this tyranny doesn&amp;rsquo;t end in this store, they are about to get a wakeup call because lots are about to quit.&lt;br /&gt;
* * * *&lt;br /&gt;
[Assistant Manager] is being a super mega puta! Its retarded I get chewed out cuz we got people putting stuff in the wrong spot and then the customer wanting it for that price . . . . I&amp;rsquo;m talking to [Store Manager] about this shit because if it don&amp;rsquo;t change [Company] can kiss my royal white ass.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The &lt;a target="_blank" href="http://mynlrb.nlrb.gov/link/document.aspx/09031d458056e73d"&gt;General Counsel concluded&lt;/a&gt; that the employer could lawfully fire the employee because the posts expressed only an individual gripe, &lt;em&gt;i.e.&lt;/em&gt;, the employee&amp;rsquo;s own &amp;ldquo;frustration regarding his individual dispute with the Assistant Manager over mispriced or misplaced sale items.&amp;rdquo; The General Counsel also concluded that the responses to the posts by the employee&amp;rsquo;s coworkers did not convert these individual gripes into collective action because those comments reflected the coworkers&amp;rsquo; understanding that the employee was speaking only on behalf of himself. One coworker laughed (&amp;ldquo;bahaha like!&amp;rdquo;); one coworker asked why the employee was so &amp;ldquo;wound up;&amp;rdquo; and a third expressed only emotional support (&lt;em&gt;i.e.&lt;/em&gt;, &amp;ldquo;hang in there&amp;rdquo;).&lt;br /&gt;
In each of the three Advice Memoranda, the General Counsel referred to the same or similar legal standards. These standards also provide useful guidance and include the following&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;u&gt;Protected&lt;/u&gt;: When the employee &amp;ldquo;acting with or the authority of&amp;rdquo; coworkers (a) &amp;ldquo;seeks to initiate, induce or prepare for group action,&amp;rdquo; or (b) &amp;ldquo;brings truly group complaints to the attention of management.&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Protected&lt;/u&gt;: The employee&amp;rsquo;s activities are &amp;ldquo;the logical outgrowth of concerns expressed by the employees collectively.&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Unprotected&lt;/u&gt;: The employee is engaging in activity &amp;ldquo;solely by and on behalf of the employee himself.&amp;rdquo;&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;Unprotected&lt;/u&gt;: The employee&amp;rsquo;s comments are &amp;ldquo;mere griping&amp;rdquo; as opposed to &amp;ldquo;group action.&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While these guidelines and the Advice Memoranda obviously do not address the full range of Facebook conduct that intersects with the workplace, they do at least provide some guideposts for employers when deciding whether to discipline or fire an employee based on his or her obnoxious or offensive Facebook post.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/p0DMDWB_Hl0" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/p0DMDWB_Hl0/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/08/articles/social-networking-1/when-can-employers-lawfully-fire-an-employee-for-an-offensive-facebook-post-ask-the-nlrb/</guid>
         <category domain="http://privacyblog.littler.com/tags">Facebook</category><category domain="http://privacyblog.littler.com/articles">Internet Communications</category><category domain="http://privacyblog.littler.com/tags">NLRA</category><category domain="http://privacyblog.littler.com/tags">NLRB</category><category domain="http://privacyblog.littler.com/tags">Social Media</category><category domain="http://privacyblog.littler.com/articles">Social Networking</category>
         <pubDate>Mon, 01 Aug 2011 11:00:24 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/08/articles/social-networking-1/when-can-employers-lawfully-fire-an-employee-for-an-offensive-facebook-post-ask-the-nlrb/</feedburner:origLink></item>
            <item>
         <title>EEOC Holds Meeting on Use of Arrest and Conviction Records During Hiring Process</title>
         <description>&lt;p&gt;&lt;img height="250" alt="" hspace="2" width="250" align="right" vspace="2" src="http://privacyblog.littler.com/uploads/image/EEOCIII.jpg" /&gt;On Tuesday, July 26, 2011, the Equal Employment Opportunity Commission (EEOC) held its latest meeting on the topic of protections for job applicants with arrest and conviction records under Title VII of the Civil Rights Act of 1964. The full Commission heard remarks from the panelists related to three areas: &amp;quot;Best Practices From Employers,&amp;quot; &amp;quot;An Overview of Local, State and Federal Programs and Policies&amp;quot; and &amp;quot;Legal Standards Governing Employers' Consideration of Criminal Arrest and Conviction Records.&amp;quot;&lt;/p&gt;
&lt;p&gt;Although for the past few years the EEOC has renewed its focus on the hiring process, including Title VII protections for ex-offenders, the current Commissioners (Jaqueline Berrien, Stuart Ishimaru, Constance Barker, Chai Feldblum and Victoria Lipnic) have not indicated whether the EEOC will update its 1987 Policy Statement on the Issue of Conviction Records under Title VII, and did not do so at the July 26 meeting. As a result, it remains important for employers who may be the target of disparate impact claims or charges challenging their conviction-based screening policies to: (1) understand the current state of the case law; and (2) continue to closely monitor developments at the federal, state and local levels in this dynamic area of the law.&lt;/p&gt;
&lt;p&gt;To learn more about the EEOC's meeting on&amp;nbsp;employers' use of criminal arrest and conviction records during the hiring process, and the potential implications for employers, please continue reading Littler's ASAP, &lt;a target="_blank" href="http://www.littler.com/PressPublications/Lists/ASAPs/DispAsaps.aspx?id=1648&amp;amp;asapType=National"&gt;&lt;em&gt;The EEOC's Priorities Still Include Regulating the Use of Criminal Records by Employers&lt;/em&gt;&lt;/a&gt;, by &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=01616"&gt;Rod Fliegel&lt;/a&gt; and &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=03442"&gt;Barry Hartstein&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/sy-HEkPrTDQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/sy-HEkPrTDQ/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/07/articles/background-checks/eeoc-holds-meeting-on-use-of-arrest-and-conviction-records-during-hiring-process/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Conviction</category><category domain="http://privacyblog.littler.com/tags">Criminal History</category><category domain="http://privacyblog.littler.com/tags">EEOC</category>
         <pubDate>Wed, 27 Jul 2011 13:34:42 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/07/articles/background-checks/eeoc-holds-meeting-on-use-of-arrest-and-conviction-records-during-hiring-process/</feedburner:origLink></item>
            <item>
         <title>Connecticut Law Restricts Employer Use of Credit Reports</title>
         <description>&lt;p&gt;&lt;img height="199" alt="" hspace="2" width="300" align="right" vspace="2" src="http://privacyblog.littler.com/uploads/image/Credit HistoryIV.jpg" /&gt;Effective October 1, 2011, employers in Connecticut will face new restrictions on the use of credit reports regarding current or prospective employees as a result of the recent enactment this month of Connecticut Public Act 11-223. In enacting the new law, Connecticut becomes the sixth state limiting employers' use of credit reports, following Hawaii, Washington, Oregon, Illinois, and Maryland. Similar laws are pending in several other states and at the federal level. The Equal Employment Opportunity Commission (EEOC) is also conducting related investigations and pursuing at least one disparate impact claim based on the use of credit reports. Thus, employers who use credit history information to inform hiring or personnel decisions in states that have enacted credit check laws should review their policies for compliance, and employers everywhere should continue to monitor developments in this evolving area of the law. To learn more about the Connecticut law and its implications for employers, please continue reading Littler's ASAP, &lt;em&gt;&lt;a target="_blank" href="http://www.littler.com/PressPublications/Lists/ASAPs/DispASAPs.aspx?id=1647"&gt;Use of Credit Reports by Employers Will Soon Be Restricted in Connecticut&lt;/a&gt;&lt;/em&gt;, by &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=01616"&gt;Rod Fliegel&lt;/a&gt; and &lt;a target="_blank" href="http://www.littler.com/Lists/Attorneys/DispAttorney.aspx?tkid=03123"&gt;William Simmons&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: xx-small"&gt;&lt;em&gt;Photo credit:&lt;/em&gt; &lt;/span&gt;&lt;a target="_blank" href="http://www.istockphoto.com/user_view.php?id=1477541"&gt;&lt;span style="font-size: xx-small"&gt;Pawel Gaul&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyCounsel/~4/Dk5OAZk9MZg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyCounsel/~3/Dk5OAZk9MZg/</link>
         <guid isPermaLink="false">http://privacyblog.littler.com/2011/07/articles/background-checks/connecticut-law-restricts-employer-use-of-credit-reports/</guid>
         <category domain="http://privacyblog.littler.com/articles">Background Checks</category><category domain="http://privacyblog.littler.com/tags">Connecticut</category><category domain="http://privacyblog.littler.com/articles">Credit</category><category domain="http://privacyblog.littler.com/tags">Credit History</category><category domain="http://privacyblog.littler.com/tags">Credit Report</category><category domain="http://privacyblog.littler.com/tags">EEOC</category><category domain="http://privacyblog.littler.com/tags">Hawaii</category><category domain="http://privacyblog.littler.com/tags">Illinois</category><category domain="http://privacyblog.littler.com/tags">Maryland</category><category domain="http://privacyblog.littler.com/tags">Oregon</category><category domain="http://privacyblog.littler.com/articles">State Privacy Legislation</category><category domain="http://privacyblog.littler.com/tags">Washington</category>
         <pubDate>Mon, 25 Jul 2011 08:14:21 -0800</pubDate>
         <dc:creator>Privacy and Data Protection Practice Group</dc:creator>
      
      <feedburner:origLink>http://privacyblog.littler.com/2011/07/articles/background-checks/connecticut-law-restricts-employer-use-of-credit-reports/</feedburner:origLink></item>
      
   </channel>
</rss>

