General Counsel Should Update Cyber, Data Privacy Policies as Employees Return to Offices
"The best advice is to make sure you have a consistent policy to apply across the board," Michelle Reed, a partner at Akin Gump Strauss Hauer & Feld in Dallas, said. "If you're consistent, you're less likely to face regulatory scrutiny. That's not to say that you won't be sued, but if you limit the risk you can nip that kind of litigation in the bud."
May 04, 2020 at 06:18 PM
3 minute read
As states begin the process to open up their economies and employees return to work, general counsel should update their company policies on handling health information if they choose to screen employees and map out what kind of data may be on employees' personal devices to mitigate the risk of a hack.
In an email to Corporate Counsel, Susanna McDonald, the chief legal officer of the Association of Corporate Counsel in Washington, D.C., said she expects one of the challenges general counsel will face will be "the balance of keeping employee's health information private, while also notifying other employees if someone in the office tests positive, and if they might have been exposed."
Michelle Reed, a partner at Akin Gump Strauss Hauer & Feld in Dallas, said she has been fielding questions on how to best handle health data that employers may collect.
"If you send an employee home because of a fever and then have some kind of a data breach, you can only imagine what that kind of backlash that could have," Reed said.
Generally speaking, the best thing to do is collect as little data as possible and retain it for the least amount of time, Reed said. She said general counsel should begin focusing on updating their employee privacy policies to inform employees what kind of data the company is holding on to.
"The best advice is to make sure you have a consistent policy to apply across the board," Reed said. "If you're consistent, you're less likely to face regulatory scrutiny. That's not to say that you won't be sued, but if you limit the risk you can nip that kind of litigation in the bud."
McDonald said general counsel should be looking at the guidance that the Equal Opportunity and Employment Commission and the Centers for Disease Control and Prevention on employees returning to work.
"GCs will need to be prepared with mitigating costs by having their policies closely align with these guidelines and document how the organization made its decision," McDonald said.
|Back And Forth
Michelle Hon Donovan, a partner at Duane Morris in San Diego, said companies will likely stagger schedules when they allow employees to come back into the office.
"There you have all of the security issues of still working from home plus the issues of transferring files," Donovan said. "This poses an increased risk."
She explained that cyberattacks have gone up during the pandemic as employees use more personal devices or work on unsecured networks.
Christopher Ghazarian, general counsel of Los Angeles-based DreamHost, said in an email to Corporate Counsel that legal leaders should note what kind of information is on employee personal devices.
"Today, lots of people use their personal laptops and phones for work. It's much harder to mitigate these risks when devices are not managed by a company's [information technology] department, but rather by the individual employee," Ghazarian said.
He said company files and credentials should be deleted from personal devices when employees come back to the office.
"It's possible that your employees downloaded company files or saved credentials on these personal devices that have not been updated and aren't managed by your IT department," Ghazarian said.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllElon Musk Names Microsoft, Calif. AG to Amended OpenAI Suit
Ben & Jerry’s Accuses Corporate Parent of ‘Silencing’ Support for Palestinian Rights
3 minute read'It's Not About Speed': Forging Strong Legal Department-Law Firm Relationships Starts With Humility, Trust
6 minute readNLRB Bans 'Captive Audience' Meetings, Yanking Away Platform Employers Used to Combat Unionizing
Law Firms Mentioned
Trending Stories
- 1Trying a Case for Abu Ghraib Detainees Two Decades After Abuse
- 2The Distribution of Dangerous Products Via Online Marketplaces
- 3The Products Liability Case Against Tianeptine: The Deadly ‘Dietary Supplement’ Found at Your Local Store
- 4The Evolving Landscape of Joint and Several Liability in Pa.: A Post-'Spencer' Analysis
- 5A Deep Dive Into the Product-Line Exception in Pennsylvania
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250