← University
Privacy in the Workplace: PIPA, PIPEDA, and Employee Information
0 of 6

A request for personal information arrived on the desk of the human resources director at a mid-sized software development company based in the lower mainland of British Columbia. The request came from a senior developer who had worked for the organization for 7 years and who had recently been placed on a performance improvement plan following concerns raised by her team lead about productivity and collaboration. The employee's written request cited her rights under British Columbia's Personal Information Protection Act and asked for copies of all personal information the company held about her, including performance evaluations, internal communications referencing her, any monitoring data collected from company systems, and medical documentation she had submitted over the years in connection with accommodation requests.

The human resources director recognized that responding to this request would require the organization to confront how it had managed employee information since its founding 12 years earlier. The company had grown from a 5-person startup to an operation employing 87 staff across 3 offices, accumulating personnel files, digital records, and system-generated data without a consistent framework for organizing or retaining that information. Over the years, the organization had implemented various monitoring tools on company devices and networks, including software that logged application usage, tracked keystroke patterns during work hours, and captured screenshots at intervals throughout the day. The employee's request would require disclosure of what these systems had collected about her specifically, raising questions about whether the monitoring had been implemented with appropriate notice and consent.

The situation grew more complex when the human resources director discovered that 4 months earlier, a departing employee in the IT department had inadvertently exposed a folder containing personnel records for 23 current and former staff members to an external cloud storage service during a system migration. The breach had been identified and contained within 48 hours, but no formal breach response protocol had been followed, no affected individuals had been notified, and no report had been made to the Office of the Information and Privacy Commissioner. The senior developer's file was among those exposed.

The company's executive team now faced overlapping obligations under provincial privacy legislation. They needed to respond to the access request within the statutory timeframe, determine what notification and reporting duties arose from the earlier breach, and assess whether their existing policies and practices around employee information collection, monitoring, and retention could withstand regulatory scrutiny. The organization had no dedicated privacy officer and had never conducted a formal audit of its HR information practices.

Building Privacy-Compliant HR Practices: Policy, Process, and Documentation

Privacy in the workplace has evolved from a peripheral concern to a central pillar of human resources management across Canada. The legal frameworks governing how employers collect, use, and disclose employee personal information have matured significantly, and as of the date of authorship, organizations face heightened expectations from regulators, employees, and the public regarding their privacy practices. The Personal Information Protection and Electronic Documents Act, which applies to federally regulated private sector employers and serves as the baseline privacy law in provinces without substantially similar legislation, establishes foundational principles that shape how all Canadian employers should approach employee information. In British Columbia and Alberta, the Personal Information Protection Act in each province governs private sector employers, while Quebec's Act respecting the protection of personal information in the private sector creates distinct obligations that often exceed federal requirements. Understanding these frameworks is essential, but the real challenge for HR professionals lies in translating legal requirements into operational practices that protect both the organization and its workforce.

The consent principle sits at the heart of Canadian privacy law, requiring employers to obtain meaningful agreement before collecting, using, or disclosing personal information. However, the employment context creates unique dynamics that complicate straightforward consent. Employees often perceive a power imbalance that makes them reluctant to refuse employer requests, which is why privacy legislation across jurisdictions recognizes that consent in employment relationships requires particular care. The concept of reasonable purpose becomes critical here, as employers must demonstrate that their collection of employee information serves legitimate business needs rather than curiosity or convenience. This means that before implementing any new data collection practice, whether installing workplace cameras, implementing productivity monitoring software, or requiring health declarations, HR professionals must ask whether the information is genuinely necessary for managing the employment relationship and whether less intrusive alternatives exist.

Documentation forms the backbone of privacy compliance, yet many organizations treat it as an afterthought rather than an integral part of their HR operations. A privacy policy that employees sign during onboarding and never see again fails to meet the spirit of privacy legislation, which emphasizes transparency and ongoing accountability. Effective documentation begins with a comprehensive privacy notice that explains to employees what information the organization collects, why it collects that information, how long it will be retained, and who might have access to it. This notice should be written in plain language that a reasonable person can understand without legal training, avoiding the dense legalese that renders many privacy policies incomprehensible. Beyond the initial notice, organizations should maintain internal documentation that maps the flow of employee information through the organization, identifying every system, process, and third party that touches personal data. This mapping exercise often reveals surprising vulnerabilities, such as employee files stored on personal devices, performance notes shared through unsecured email, or background check results accessible to individuals without legitimate need.

The retention of employee information presents ongoing compliance challenges that many organizations fail to address systematically. Privacy legislation requires organizations to retain personal information only as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law. Employment standards legislation across Canadian jurisdictions mandates minimum retention periods for payroll records and related documents, typically ranging from three to seven years depending on the province and the type of record. The Canada Labour Code requires federally regulated employers to maintain certain employment records for specific periods following the end of employment. However, these minimum requirements establish a floor rather than a ceiling, and organizations must resist the temptation to keep everything indefinitely simply because digital storage is inexpensive. Every piece of employee information retained beyond its useful life represents both a privacy compliance risk and a potential liability in litigation, as documents that no longer serve any business purpose can nevertheless be produced in legal proceedings and used in ways the organization never anticipated.

Process design requires HR professionals to think systematically about how employee information moves through the organization from collection to eventual destruction. The principle of limiting collection to what is necessary should guide every intake form, application process, and information request. Many organizations collect far more information than they need, either because forms have accumulated fields over time without periodic review or because someone once thought a particular data point might prove useful. Each piece of information collected creates obligations around security, access, retention, and eventual disposal, which means that unnecessary collection imposes real costs even if those costs are not immediately visible. HR professionals should regularly audit their collection practices, asking whether each piece of information serves a defined purpose and whether that purpose could be achieved with less sensitive information or no personal information at all.

Security measures must be proportionate to the sensitivity of the information and the risks associated with its unauthorized disclosure. Employee health information, financial details, performance evaluations, and disciplinary records all warrant stronger protection than general contact information or work schedules. The technical security measures implemented by IT departments form only part of the picture, as administrative controls such as access restrictions, training requirements, and clear protocols for handling sensitive information often prove equally important. Physical security also matters, particularly for organizations that maintain paper files containing employee information. Locked cabinets in secured rooms may seem old-fashioned in an era of cloud computing, but they remain essential for organizations that have not fully digitized their HR records. The transition from paper to digital systems creates particular risks during the migration period, when information may exist in both formats with inconsistent security controls applied to each.

Third-party service providers pose significant privacy risks that organizations often underestimate. Payroll processors, benefits administrators, background check providers, employee assistance programs, and HR information system vendors all access employee personal information in the course of providing their services. Privacy legislation requires organizations to ensure that third parties provide comparable protection for personal information transferred to them, which means that service agreements must contain appropriate privacy and security provisions. Due diligence before engaging a service provider should include reviewing their privacy practices, security certifications, and breach response capabilities. Ongoing oversight is equally important, as initial compliance can deteriorate over time if not monitored. Organizations should maintain records of their third-party arrangements and periodically verify that service providers continue to meet their contractual privacy obligations.

Consider the experience of a property management company headquartered in Calgary with operations across Western Canada. The organization employed approximately two hundred workers in a mix of administrative, maintenance, and property supervision roles. When a new HR director joined the company, she initiated a comprehensive review of existing privacy practices and discovered significant gaps in how the organization handled employee information. The previous approach had been informal and inconsistent, with different offices following different procedures and no centralized documentation of privacy practices. Personnel files contained information collected over decades without any systematic review or disposal, including medical notes from the nineteen-nineties, credit reports obtained for long-departed employees, and handwritten performance observations that had never been incorporated into formal evaluation processes. The company's employee handbook contained a brief privacy statement that had not been updated since two thousand and eight and did not reflect current legal requirements or technological practices.

The HR director recognized that addressing these issues would require a comprehensive approach rather than piecemeal fixes. She began by conducting an inventory of all employee information held by the organization, including data stored in HR systems, payroll applications, email archives, shared network drives, and paper files at each location. This inventory revealed that employee information was scattered across at least seventeen different systems and physical locations, with no consistent protocols governing access, retention, or security. Some managers maintained their own files on employees, separate from official HR records, containing notes, emails, and documents that had never been reviewed for privacy compliance. The cloud-based applicant tracking system the company had adopted three years earlier still contained complete files for every applicant who had ever applied, including those who had been rejected years ago and those who had been hired and subsequently left the organization.

Working with the IT department and outside counsel, the HR director developed a comprehensive privacy program that addressed policy, process, and documentation gaps. The project took nearly eighteen months to complete and required substantial investment in systems, training, and external expertise. A new privacy policy for employees explained in clear language what information the organization collected, the purposes for each type of information, retention periods, access controls, and employee rights regarding their personal information. The policy addressed specific scenarios that employees might encounter, such as what happens to their information when they transfer between provinces, how performance information is used in promotion decisions, and what occurs when they leave the organization. A separate internal procedures manual provided detailed guidance for HR staff and managers on handling employee information, including step-by-step protocols for responding to access requests, managing employee files during terminations, and addressing privacy breaches.

The retention schedule developed as part of this project specified retention periods for each category of employee information based on legal requirements, operational needs, and privacy principles. Payroll records would be retained for seven years following the end of employment, consistent with requirements under provincial employment standards legislation and Canada Revenue Agency guidelines. Performance evaluations would be retained for five years following the end of employment to address potential human rights complaints or wrongful dismissal claims. Recruitment files for unsuccessful candidates would be retained for one year following the hiring decision, then securely destroyed unless the candidate had consented to inclusion in a talent pool for future opportunities. Medical information collected for accommodation purposes would be retained only as long as the accommodation remained in effect, with destruction occurring within one year of the accommodation ending unless ongoing legal proceedings required continued retention.

The project also established clear protocols for handling employee access requests. Under privacy legislation across Canadian jurisdictions, employees have the right to access their personal information held by their employer and to request corrections to inaccurate information. The property management company had never received a formal access request, but the HR director recognized that this likely reflected employees' unfamiliarity with their rights rather than the absence of interest in exercising them. The new procedures established a thirty-day target for responding to access requests, consistent with legal requirements, and identified the steps required to locate, compile, and review responsive information before providing it to the employee. The procedures also addressed how to handle requests that raised concerns, such as requests that appeared to be motivated by anticipated litigation or requests for information that might reveal confidential business information intertwined with employee personal information.

Training formed a critical component of the privacy program, recognizing that policies and procedures have limited value if the people responsible for implementing them do not understand their obligations. All managers received training on privacy fundamentals, including the types of employee information they should and should not collect, how to secure information in their possession, and when to involve HR in privacy-related decisions. HR staff received more detailed training on the specific procedures they were expected to follow, including hands-on exercises involving simulated access requests and breach scenarios. New employees received privacy orientation during onboarding, and annual refresher training was built into the organization's professional development calendar. The HR director also established a privacy liaison role in each regional office, creating a network of individuals who could answer routine questions and escalate more complex issues to the head office.

The implications of this comprehensive approach extended beyond compliance risk reduction to include operational benefits that the organization had not initially anticipated. The records management improvements enabled faster and more accurate retrieval of employee information when needed for legitimate purposes. The clarified retention schedule freed up substantial physical and digital storage space that had been occupied by obsolete records. The training program reduced the frequency of privacy missteps by managers, such as discussing employee medical information inappropriately or sharing performance ratings with colleagues who had no legitimate need for the information. Perhaps most significantly, the transparent privacy practices helped build employee trust in the organization's handling of their personal information, contributing to a workplace culture where employees felt respected and valued.

Building privacy-compliant HR practices requires ongoing commitment rather than a one-time project. Organizations should establish regular review cycles for their privacy policies, procedures, and documentation to ensure continued alignment with legal requirements and operational realities. Annual privacy audits can identify emerging gaps before they become compliance problems or contribute to privacy breaches. These audits should examine not only formal policies and procedures but also actual practices, recognizing that informal workarounds and departures from documented processes often develop over time. Organizations should also monitor regulatory developments across Canadian jurisdictions, as privacy law continues to evolve in response to technological change, public expectations, and international trends. Quebec's Law 25, which substantially revised privacy obligations in that province, illustrates how quickly the regulatory landscape can shift and how organizations must be prepared to adapt their practices accordingly.

Questions that HR professionals should regularly ask themselves include whether their privacy notices accurately reflect current practices, whether they could explain to an employee why each piece of information in their file was collected and retained, whether third-party service providers are meeting their privacy obligations, and whether they would be comfortable if their privacy practices became public through a breach notification or regulatory investigation. These questions encourage the kind of ongoing reflection that sustains privacy compliance over time rather than allowing practices to drift toward convenience at the expense of principle.

Documentation serves multiple purposes in a privacy-compliant HR operation. It demonstrates accountability to regulators in the event of an investigation, provides evidence of reasonable practices in potential litigation, supports consistent application of policies across the organization, and enables knowledge transfer when personnel change. Organizations should maintain records of their privacy policies and when they were communicated to employees, training provided to managers and staff, consent obtained for specific uses of employee information, access requests received and how they were handled, third-party agreements and due diligence conducted, and any privacy breaches or near-misses along with the response taken. This documentation creates an institutional memory that supports continuous improvement and provides defence against allegations of careless or non-compliant practices.

The investment required to build privacy-compliant HR practices varies significantly depending on organizational size, complexity, and current state of privacy maturity. Small organizations may be able to address fundamental requirements with modest internal effort supplemented by template policies adapted to their circumstances. Larger organizations with complex operations, multiple jurisdictions, and extensive third-party relationships may require dedicated privacy roles, specialized systems, and ongoing external support. Regardless of organizational size, the key is to approach privacy not as a legal technicality to be minimized but as an integral aspect of respectful and effective people management. Employees who trust that their employer handles their personal information responsibly are more likely to share information that supports appropriate accommodation, effective performance management, and genuine engagement with organizational goals. Privacy compliance thus serves not only legal and risk management purposes but also the fundamental HR objective of building productive and respectful employment relationships across the Canadian workplace.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options