1st September 2020
GDPR, Covid19 and working from home
Now here’s some thoughts that may set compliance heads banging against walls. Luke Irwin wrote an excellent IT Governance blog on the 22nd July 2020.
He covers off a myriad of GDPR issues as well as Covid induced data breach opportunities and it is well worth a detailed read.
For those who have been blissfully working from home for months, some alarm bells regarding your own privacy may start to ring after reading!
Indeed, this may be exactly why so many large employers are very happy to have you working from home and are very happy to go with the current WFH mantra of ‘being much more productive’!
Some points to ponder if you WFH:
- Is your home internet connection secure?
- Do you use your own computer or mobile devices for work?
- If so, you have your own security software and anti-virus installed?
- How safe is your own data if sharing your own computer equipment with your employer?
- How safe is your employer’s ‘data’ if using your computer, internet connection and landline or mobile telephone?
- Do you know if WFH calls you make or receive on your devices or your employers’ devices are recorded ?
- How secure is your personal data, e mail account or cloud storage, especially some that you would, perhaps, rather not be exposed to the outside world, by that I mean your employer as well as hackers?
- Can your employer monitor your online activity to measure your productivity without your knowledge?
- If your employer is providing you with computer equipment, how is your activity measured or monitored?
Luke observes: “Remote employees may well keep irregular hours and use their devices for both personal and work reasons, so it’s impossible to differentiate between monitoring an employee’s work and private life. Therefore, there’s no way of monitoring devices without violating your employees’ right to privacy.
It will also be difficult to find a lawful basis to process data. As the Article 29 Working Party writes: Technologies that monitor communications can have a chilling effect on the fundamental rights of employees to organise, set up workers’ meetings, and to communicate confidentially (including the right to seek information).
Owing to the capabilities of such technologies, employees may not be aware of what personal data are being processed and for which purposes, whilst it is also possible that they are not even aware of the existence of the monitoring technology itself”.
To protect employer provided work laptops and devices from misuse, many organisations in such a regulated industry as financial services, no doubt, will install software to track how employees (or cyber criminal attacks) use their or your device. There are loads of off the shelf software and apps that can log keystrokes or track mouse movements, but this poses problems with complying with the GDPR.
Some employers may want, even demand that your own devices are ‘protected’ in some way. In such circumstances, there’s no way of monitoring devices without violating your employees’ right to privacy.
Some employees may have decided that working from home means setting up their WFH office in another country, sunnier climes and all that! It is simply impossible to differentiate between monitoring an employee’s work and private life.
If this worries you, and it should, getting back to the office as soon as possible would be the easiest solution?
As a footnote, if WFH works so well for employers, and notwithstanding the concerns above, employees should not be surprised if the next step is for firms to replace their expensive UK hire with an equally well qualified if not better qualified, even more productive WFH individual, offshore, at a much lower cost!
The water bed effect strikes again.
You need to be logged in to comment on this article