← University
Privacy in the Workplace: PIPA, PIPEDA, and Employee Information
0 of 6

A request for personal information arrived on the desk of the human resources director at a mid-sized software development company based in the lower mainland of British Columbia. The request came from a senior developer who had worked for the organization for 7 years and who had recently been placed on a performance improvement plan following concerns raised by her team lead about productivity and collaboration. The employee's written request cited her rights under British Columbia's Personal Information Protection Act and asked for copies of all personal information the company held about her, including performance evaluations, internal communications referencing her, any monitoring data collected from company systems, and medical documentation she had submitted over the years in connection with accommodation requests.

The human resources director recognized that responding to this request would require the organization to confront how it had managed employee information since its founding 12 years earlier. The company had grown from a 5-person startup to an operation employing 87 staff across 3 offices, accumulating personnel files, digital records, and system-generated data without a consistent framework for organizing or retaining that information. Over the years, the organization had implemented various monitoring tools on company devices and networks, including software that logged application usage, tracked keystroke patterns during work hours, and captured screenshots at intervals throughout the day. The employee's request would require disclosure of what these systems had collected about her specifically, raising questions about whether the monitoring had been implemented with appropriate notice and consent.

The situation grew more complex when the human resources director discovered that 4 months earlier, a departing employee in the IT department had inadvertently exposed a folder containing personnel records for 23 current and former staff members to an external cloud storage service during a system migration. The breach had been identified and contained within 48 hours, but no formal breach response protocol had been followed, no affected individuals had been notified, and no report had been made to the Office of the Information and Privacy Commissioner. The senior developer's file was among those exposed.

The company's executive team now faced overlapping obligations under provincial privacy legislation. They needed to respond to the access request within the statutory timeframe, determine what notification and reporting duties arose from the earlier breach, and assess whether their existing policies and practices around employee information collection, monitoring, and retention could withstand regulatory scrutiny. The organization had no dedicated privacy officer and had never conducted a formal audit of its HR information practices.

Employee Access to Their Own Information: Rights and Employer Obligations

When employees work for an organization, they generate and contribute to a substantial body of personal information. From the moment a person submits a job application through to the end of their employment relationship and beyond, employers accumulate records that document virtually every aspect of that individual's professional life. These records might include performance evaluations, disciplinary notes, medical documentation, payroll information, communications with supervisors, incident reports, and countless other documents that paint a detailed picture of the employment relationship. Canadian privacy legislation recognizes that individuals have a fundamental interest in understanding what information is held about them and ensuring that information is accurate. This recognition forms the foundation of employee access rights, which create corresponding obligations for employers to respond to requests for personal information in a timely, complete, and transparent manner.

The legal framework governing employee access to personal information in Canada operates across federal and provincial jurisdictions, creating a layered system that employers must navigate carefully. At the federal level, the Personal Information Protection and Electronic Documents Act establishes the baseline requirements for organizations subject to federal private sector privacy law. As of the date of authorship, this legislation applies to federally regulated employers such as banks, telecommunications companies, interprovincial transportation firms, and broadcasting operations. It also applies to organizations engaged in commercial activity in provinces that have not enacted substantially similar provincial legislation. British Columbia and Alberta have both enacted their own Personal Information Protection Acts, which are recognized as substantially similar to the federal statute and therefore govern private sector employers operating within those provinces. Quebec's approach to privacy in the employment context is governed by its Act respecting the protection of personal information in the private sector, which has undergone significant modernization in recent years and contains distinct requirements that employers operating in that province must understand. For public sector employers and organizations in provinces without substantially similar legislation, the federal statute or applicable provincial public sector privacy laws determine the scope of employee access rights.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $149 course — purchasing unlocks it, or sign in if you already have access.