← University
Privacy in the Workplace: PIPA, PIPEDA, and Employee Information
0 of 6

A request for personal information arrived on the desk of the human resources director at a mid-sized software development company based in the lower mainland of British Columbia. The request came from a senior developer who had worked for the organization for 7 years and who had recently been placed on a performance improvement plan following concerns raised by her team lead about productivity and collaboration. The employee's written request cited her rights under British Columbia's Personal Information Protection Act and asked for copies of all personal information the company held about her, including performance evaluations, internal communications referencing her, any monitoring data collected from company systems, and medical documentation she had submitted over the years in connection with accommodation requests.

The human resources director recognized that responding to this request would require the organization to confront how it had managed employee information since its founding 12 years earlier. The company had grown from a 5-person startup to an operation employing 87 staff across 3 offices, accumulating personnel files, digital records, and system-generated data without a consistent framework for organizing or retaining that information. Over the years, the organization had implemented various monitoring tools on company devices and networks, including software that logged application usage, tracked keystroke patterns during work hours, and captured screenshots at intervals throughout the day. The employee's request would require disclosure of what these systems had collected about her specifically, raising questions about whether the monitoring had been implemented with appropriate notice and consent.

The situation grew more complex when the human resources director discovered that 4 months earlier, a departing employee in the IT department had inadvertently exposed a folder containing personnel records for 23 current and former staff members to an external cloud storage service during a system migration. The breach had been identified and contained within 48 hours, but no formal breach response protocol had been followed, no affected individuals had been notified, and no report had been made to the Office of the Information and Privacy Commissioner. The senior developer's file was among those exposed.

The company's executive team now faced overlapping obligations under provincial privacy legislation. They needed to respond to the access request within the statutory timeframe, determine what notification and reporting duties arose from the earlier breach, and assess whether their existing policies and practices around employee information collection, monitoring, and retention could withstand regulatory scrutiny. The organization had no dedicated privacy officer and had never conducted a formal audit of its HR information practices.

What Employee Information Employers Can Collect, Use, and Disclose

Every employer in Canada holds a significant volume of information about the people who work for them. From the moment a candidate submits a resume to the day an employee departs, organizations accumulate personal details that range from the mundane to the deeply sensitive. Social insurance numbers, banking information, performance evaluations, medical documentation, emergency contacts, disciplinary records, and increasingly, biometric data and digital communications all flow into employer files. The question of what information employers can legitimately collect, use, and disclose about employees sits at the intersection of privacy law, employment law, and fundamental respect for human dignity. Understanding the boundaries of lawful information handling is not merely a compliance exercise but a cornerstone of ethical people management and organizational trust.

Privacy legislation in Canada establishes the framework within which employers must operate when handling employee personal information. At the federal level, the Personal Information Protection and Electronic Documents Act governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities. However, the application of this legislation to employee information is nuanced and depends significantly on whether the employer falls under federal or provincial jurisdiction. For federally regulated employers, which include banks, telecommunications companies, interprovincial transportation firms, and broadcasting operations, the Personal Information Protection and Electronic Documents Act applies directly to employee personal information. These employers must comply with the ten fair information principles embedded in Schedule 1 of the legislation, including obtaining meaningful consent, limiting collection to what is necessary, and ensuring appropriate safeguards.

For provincially regulated employers, which constitute the vast majority of Canadian businesses, the picture becomes more complex. British Columbia and Alberta have enacted their own private-sector privacy statutes, each titled the Personal Information Protection Act, which apply to employee personal information within those provinces. Quebec operates under An Act respecting the protection of personal information in the private sector, which has undergone substantial amendments that took effect in stages beginning in September 2022 and continuing through September 2024, as of the date of authorship. These provincial statutes have been deemed substantially similar to the federal legislation, meaning they take precedence within their respective jurisdictions. In Ontario, Saskatchewan, and other provinces without substantially similar private-sector privacy legislation, employee personal information in the provincially regulated private sector exists in something of a legislative gap. The Personal Information Protection and Electronic Documents Act does not apply to employee information in these provinces for provincially regulated employers, though it continues to govern commercial activities involving customer and client data. This creates a patchwork reality where an Ontario-based technology company must comply with federal privacy law when handling customer information but faces no equivalent statutory privacy obligations regarding its employee data, though common law principles, employment contracts, and human rights legislation still impose meaningful constraints.

The foundational principle across all Canadian privacy legislation is that organizations may only collect personal information for purposes that a reasonable person would consider appropriate in the circumstances. This reasonableness standard permeates every aspect of employee information handling. When an employer collects information, it must be for a purpose that is directly connected to the employment relationship and necessary for legitimate business operations. The concept of necessity operates as a limiting principle, requiring employers to ask whether they genuinely need specific information to achieve a lawful purpose, rather than simply whether having the information might prove convenient or useful at some future point.

Consider the information that flows during the hiring process. Employers routinely collect resumes, cover letters, references, and interview notes. They may conduct background checks, verify educational credentials, and confirm previous employment. Each of these activities involves personal information, and each must be justified by a legitimate purpose connected to assessing the candidate's suitability for the position. An employer seeking to fill a financial management role has a reasonable basis for conducting a credit check, as the position involves fiduciary responsibilities and financial decision-making. The same employer hiring for a warehouse position would struggle to demonstrate that a credit check serves any purpose that a reasonable person would consider appropriate. Similarly, while criminal record checks may be justified for positions involving vulnerable populations or significant trust, conducting them for every position regardless of job duties exceeds what is necessary and may also engage human rights considerations regarding discrimination on the basis of record of offence.

Once employment begins, the information collection continues. Payroll administration requires social insurance numbers, banking details, and tax-related information. Benefits administration necessitates information about dependents, beneficiary designations, and potentially health-related details. Performance management generates documentation about job performance, disciplinary matters, and developmental conversations. Each category of information serves distinct purposes, and employers must ensure that information collected for one purpose is not repurposed for another without fresh consideration of whether such use is appropriate and, where required, whether consent has been obtained.

The question of consent in the employment context presents particular challenges. The inherent power imbalance between employers and employees means that consent in employment relationships does not operate in the same manner as consent between parties of equal bargaining power. An employee who refuses to provide information requested by their employer may face negative consequences, making the voluntariness of their consent questionable. Privacy legislation addresses this reality by allowing employers in certain circumstances to collect, use, and disclose employee personal information without consent where it is reasonable to do so for purposes related to establishing, managing, or terminating the employment relationship. This exception, found in both the British Columbia and Alberta Personal Information Protection Acts, recognizes that employment necessarily involves information exchange and that requiring individual consent for every legitimate employment-related purpose would be impractical. However, the exception is not unlimited. Employers must still provide notice to employees about their information practices, the collection must be reasonable, and sensitive information categories such as health data often require express consent or stricter justification.

Quebec's privacy framework, following the amendments that modernized An Act respecting the protection of personal information in the private sector, imposes distinct obligations that employers operating in that province must understand. The Quebec legislation requires explicit consent for sensitive personal information, which includes health information, biometric data, and information that could lead to discrimination. It establishes specific requirements for privacy impact assessments when implementing technology systems that involve personal information, and it grants individuals expanded rights to access, correct, and in certain circumstances, have their information de-indexed or deleted. The legislation also imposes significant breach notification requirements, with mandatory reporting to Quebec's Commission d'accès à l'information when a confidentiality incident poses a risk of serious injury. Employers with operations or employees in Quebec must ensure their information handling practices meet these enhanced standards.

The use of technology in the workplace has dramatically expanded the scope of information employers can potentially collect about their workforce. Electronic monitoring of employee communications, keystroke logging, website tracking, GPS location data from company vehicles, and video surveillance all generate vast quantities of personal information. Biometric time clocks that capture fingerprints or facial geometry add another layer of sensitive data collection. The legal analysis for each of these technologies requires employers to assess whether the collection is necessary for a legitimate purpose, whether less privacy-intrusive alternatives exist, whether employees have been informed, and whether appropriate safeguards protect the information gathered. The principle of proportionality applies with particular force in the monitoring context. An employer concerned about productivity might monitor internet usage statistics in aggregate without needing to capture the specific content of every employee communication. An employer with genuine concerns about theft might implement video surveillance in stockrooms without extending cameras into break rooms or washrooms where employees have heightened privacy expectations.

A distribution company based in Edmonton faced exactly these challenges when it decided to implement a comprehensive fleet management system for its delivery vehicles. The system would track vehicle location in real time, monitor driving behaviour including speed, braking patterns, and route adherence, and generate detailed reports on each driver's performance. The stated purposes were legitimate: improving fuel efficiency, ensuring customer service by providing accurate delivery estimates, and promoting driver safety. However, the implementation raised significant privacy questions. Drivers would be tracked throughout their shifts, including during lunch breaks if they remained in their vehicles. The data collected would reveal not just driving behaviour but detailed patterns of movement that could disclose personal information such as medical appointments if drivers visited healthcare facilities during breaks. The granularity of the data far exceeded what was necessary for the stated business purposes.

The human resources manager recognized that proceeding without careful attention to privacy obligations would create risk for the organization. Working with operations leadership, she developed an approach that addressed the legitimate business needs while respecting employee privacy. The system was configured to pause tracking during designated break periods, with a simple dashboard toggle that drivers could activate. Location data would be retained for thirty days for customer service purposes and then aggregated for longer-term fuel efficiency analysis with individual identification removed. Driving behaviour data that triggered safety alerts would be addressed through coaching conversations rather than automatic discipline, with clear policies about how repeated safety events would be handled. Critically, the company provided clear written notice to all drivers before implementation, explaining what information would be collected, how it would be used, how long it would be retained, and what safeguards protected it. Drivers received this information in a meeting where they could ask questions, and written acknowledgment of the policy became part of their employment records.

This scenario illustrates several principles that apply broadly to employee information handling. First, the purposes for collection must be clearly defined before implementation, not rationalized afterward. The distribution company identified specific business objectives and evaluated whether the proposed technology served those objectives in a proportionate manner. Second, the scope of collection should be limited to what is genuinely necessary. By excluding break periods and aggregating historical data, the company reduced its privacy footprint without sacrificing its operational goals. Third, transparency with employees is both a legal requirement and a trust-building practice. Employees who understand what information is being collected and why are more likely to accept monitoring as legitimate rather than viewing it with suspicion or resentment. Fourth, the retention period should be defined and limited. Personal information should not be kept indefinitely simply because storage is inexpensive. The thirty-day retention for detailed location data reflected an assessment of how long the information served its stated purpose.

The disclosure of employee information to third parties requires equally careful attention. Employers routinely share employee information with payroll providers, benefits administrators, pension plan administrators, and other service providers who assist with employment-related functions. Each of these disclosures must be supported by a legitimate purpose and, where the third party is located outside Canada, may require assessment of whether the foreign jurisdiction provides adequate privacy protection. Employment references present a common disclosure situation where employers must balance their obligations. When a former employee applies for a new position, the prospective employer may contact the previous employer for a reference. Providing a reference inherently involves disclosing personal information about the former employee's performance, conduct, and suitability for employment. The safest practice is to provide references only with the employee's express consent, typically obtained as part of the departure process or indicated by the employee's listing of the former employer as a reference contact. Even with consent, the information disclosed should be limited to what is relevant to the reference request and should be accurate and fair.

Disclosure obligations may also arise from legal requirements that override ordinary privacy principles. Employers must provide information to the Canada Revenue Agency for tax administration purposes, to workers compensation boards for claims administration, and to regulators in response to lawful investigations. Subpoenas and court orders may compel production of employee records in litigation. In these situations, the employer should comply with the legal requirement while ensuring that disclosure is limited to what the legal demand actually requires. A broadly worded subpoena seeking "all employee records" should prompt consultation with legal counsel about whether the scope can be appropriately narrowed.

The security of employee information constitutes an independent obligation under privacy legislation. Organizations must implement safeguards appropriate to the sensitivity of the information they hold. Social insurance numbers, health information, and financial data require stronger protections than less sensitive information such as work contact details. Security measures include physical safeguards such as locked filing cabinets and restricted access to HR offices, technical safeguards such as encryption, access controls, and secure password practices, and administrative safeguards such as policies governing information handling and training for staff who work with personal information. When security breaches occur, employers in most Canadian jurisdictions face mandatory breach notification requirements. Under the Personal Information Protection and Electronic Documents Act, organizations must report breaches that create a real risk of significant harm to affected individuals and to the Office of the Privacy Commissioner of Canada. British Columbia, Alberta, and Quebec have their own breach notification requirements with varying thresholds and procedures. The failure to report a notifiable breach can itself constitute a compliance violation, compounding the harm from the underlying incident.

For human resources professionals and business leaders, practical application of these principles requires systematic attention to information practices throughout the employment lifecycle. At the hiring stage, organizations should review their application forms and interview processes to ensure they collect only information necessary for making hiring decisions, avoiding premature collection of information such as social insurance numbers that will only be needed if the candidate is hired. Background checking processes should be tailored to the requirements of specific positions rather than applied uniformly across all roles. During employment, organizations should maintain clear policies about what information is collected, how it is used, and how employees can access their own records. Performance documentation should be kept in appropriately secured personnel files with access limited to those with a legitimate need. Monitoring technologies should be implemented only after careful assessment of necessity and proportionality, with clear notice to affected employees. At separation, organizations should have processes for returning personal belongings that may contain personal information, providing departing employees with copies of records they may need, and appropriately archiving or destroying information that is no longer required.

Documentation of information practices serves multiple functions. It demonstrates compliance if the organization faces a complaint or investigation. It provides clarity for HR staff about proper procedures. And it creates institutional memory that persists even as personnel change. Privacy policies should be living documents, reviewed and updated as technology evolves and business practices change. The policy drafted in 2020 likely does not address remote work monitoring, artificial intelligence tools in recruitment, or other developments that have become common in subsequent years.

Training is equally essential. Privacy obligations attach to the organization, but they are implemented by individuals. Managers who conduct interviews, HR coordinators who maintain personnel files, IT staff who administer employee accounts, and supervisors who document performance all handle personal information in the course of their duties. Each must understand the basic principles of lawful information handling and know when to escalate questions to those with greater expertise. A supervisor who casually shares details of an employee's medical accommodation needs with colleagues has created a privacy breach regardless of whether they intended any harm.

Questions that HR professionals should regularly ask themselves include whether every piece of information collected from employees or about employees serves a clearly defined and legitimate purpose, whether employees have been informed about information practices in a manner that provides genuine understanding rather than merely checking a compliance box, whether information collected for one purpose is being used for different purposes without appropriate justification, whether retention schedules exist and are being followed so that information is not kept indefinitely, whether access to employee information is appropriately limited to those who need it for their job functions, and whether service providers who receive employee information are bound by appropriate contractual protections. These questions do not have one-time answers. They require ongoing attention as organizations evolve, technologies change, and workforce expectations shift.

The effective management of employee information ultimately reflects broader organizational values. Employers who handle personal information with care, transparency, and respect demonstrate to their workforce that they recognize employees as individuals with legitimate privacy interests, not merely resources to be monitored and measured. This recognition builds trust, which in turn supports engagement, retention, and organizational effectiveness. Compliance with privacy legislation is the floor, not the ceiling. Organizations that aspire to be employers of choice will often exceed legal minimums, providing greater transparency, implementing stronger safeguards, and granting employees meaningful agency over their own information. In doing so, they create workplaces where privacy and productivity coexist, where necessary information flows freely, and where employees can trust that their personal details are handled with the care and respect they deserve.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options