Showing posts with label Social Media. Show all posts
Showing posts with label Social Media. Show all posts

Friday, August 3, 2012

Illinois Joins Maryland and Delaware in Banning Requests for Social Media Passwords

As we have previously written, numerous states have proposed legislation intended to prevent employers from demanding access to the social media accounts of employees or job applicants.  Previously only Maryland and Delaware had actually passed such legislation, although as many as fifteen states and the federal government are considering similar legislation.  See Sam Favate “Illinois Becomes Third State to Pass Social Media Privacy Law”, Wall Street Journal Law Blog (Aug. 2, 2012) (available at: http://blogs.wsj.com/law/2012/08/02/illinois-becomes-third-state-to-pass-social-media-privacy-law/?mod=djemlawblog_h).  However, on August 1 Illinois Governor Patrick J. Quinn signed the “Right to Privacy in the Workplace Act” into law, making Illinois the third state to put such legislation on the books.

The Right to Privacy in the Workplace Act provides that:
It shall be unlawful for any employer to request or require any employee or prospective employee to provide any password or other related account information in order to gain access to the employee's or prospective employee's account or profile on a social networking website or to demand access in any manner to an employee's or prospective employee's account or profile on a social networking website.
820 ILCS 55/10(b)(1).  

This prohibition differs somewhat from that found in the Maryland User Name and Password Privacy Protection and Exclusions Act, House Bill 964 (amending Md. Code Ann. Labor & Empl. 3-712), and the Delaware Higher Education Privacy Act, 14 Del. Code 9401 et seq. The Maryland law provides that: “Subject to Paragraph (2) of this subsection, an employer may not request or require that an employee or applicant disclose any user name, password, or other means for accessing a personal account or service through an electronic communications device.”  Among other differences, the Maryland law protects only current employees, while the Illinois law protects both current and prospective employees.  The Delaware law, as its name implies, applies only to “public or nonpublic academic institution[s],” but covers both current students and applicants.  14 Del. Code § 9403(a)-(b).  

Nevertheless, the Illinois law does contain potentially broad carve-outs and omissions.  Of particular note is the fact that the employer is permitted to institute and enforce lawful policies regarding internet use, social networking site use, and electronic mail use.  See 820 ILCS 55/10(b)(1).  More significantly, the Illinois statute provides:
(2) Nothing in this subsection shall limit an employer's right to:

(A) promulgate and maintain lawful workplace policies governing the use of the employer's electronic equipment, including policies regarding Internet use, social networking site use, and electronic mail use; and

(B) monitor usage of the employer's electronic equipment and the employer's electronic mail without requesting or requiring any employee or prospective employee to provide any password or other related account information in order to gain access to the employee's or prospective employee's account or profile on a social networking website.
820 ILCS 55/10(b)(2)(A)-(B).  So, while the employer is prohibited from requiring an employee to provide his or her device, this “exception” appears to make anything the employee does on an employer-provided electronic device or network fair game.    The Maryland law also contains carve-outs regarding employee use of employer devices and the employer’s ability to enforce its policies.  By contrast, the narrower Delaware law provides no such exception.  It contains only a narrow carve-out for investigations of criminal activity or investigations related to an institution’s threat assessment policy.  14 Del. Code § 9405.  

While an individual alleging a violation of the Illinois law may file a complaint with the Illinois Department of Labor which may fine the employer, the Illinois law (like the Maryland and Delaware laws) does not provide for an independent private cause of action in the courts.  Fines under the Illinois law range between $200 and $500 per affected employee, plus costs and reasonable attorneys’ fees.  820 ILCS 55/15(d)(1)-(3).  Although the Delaware law specifically details the actions which public and nonpublic academic institutions might take, it also fails to spell out an explicit penalty for violation of this mandate:
“No public or nonpublic academic institution may discipline, dismiss or otherwise penalize or threaten to  discipline, dismiss or otherwise penalize a student for refusing to disclose any information specified in subsection (a) or (b) of § 9403.  It shall also be unlawful for a public or nonpublic academic institution to fail or refuse to admit any applicant as a result of the applicant’s refusal to disclose any information specified in subsection (a) or (b) of § 9403.” 
14 Del. Code § 9404.  Apart from the fines provided for by the Illinois law, the primary method of enforcement for these laws appears to be a tort action for wrongful termination in violation of public policy.  It remains to be seen whether such an enforcement mechanism is adequate.

These laws often fail to expressly address the much larger issue of employer monitoring of employee behavior on work related electronic devices – an issue of growing consequence in a world where increasing numbers of individuals use one device for both work and personal purposes.  In fact, both the Maryland and Illinois laws contain broad carve-outs for this sort of behavior.  See 820 ILCS 55/10(b)(2)(B); Md. Code Ann. Labor & Empl. 3-712(b)(2), (e).   It remains to be seen whether, and how, this issue will be addressed.  For further information See Martha Neil, Ill. Gov. Signs ‘Facebook Bill’, ABA Journal (Aug. 1. 2012) (available at: http://www.abajournal.com/mobile/article/ill._gov_signs_facebook_bill_as_of_jan._1_employers_who_ask_for_passwords/?utm_source=maestro&utm_medium=email&utm_campaign=daily_email); Eric B. Meyer, Snoop Dog Becomes Snoop Lion! And News of a New Employee Facebook Law, The Employer Handbook (Aug. 2, 2012) (available at: http://www.theemployerhandbook.com/2012/08/illinois-becomes-the-2nd-state.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+employmentlaw-blog%2FimGSCom+%28Employment+Law+Blog%29).

Friday, May 11, 2012

Proposed Federal Legislation To Prohibit Employers From Requiring or Requesting Access to Social Media of Employees or Applicants


As we have noted in several previous blogs on this site, a number of states have either passed or are considering legislation to prevent employers from demanding access to the social media accounts of employees or job applicants.  The federal government recently joined this trend.

Congressman Engel (D-NY) introduced on April 26, 2012, H.R. 5050, the so-called “Social Networking Online Protection Act (‘SNOPA’),” which, if passed, would make it unlawful for an employer to “require or request that an employee or applicant for employment provide the employer with a username, password, or any other means for accessing a private email account of the employee or applicant or the personal account of the employee or applicant on any social networking website; or to discharge, discipline, discriminate against in any manner, or deny employment or promotion to or threaten to take any such action against any employee or applicant for employment because” the employee refuses to provide the information or the employee has filed a complaint or testified about the matter.  The proposed legislation defines a “social networking website” as any internet service, platform, or website that provides a user with a distinct account – (A) whereby the user can access such account by way of a distinct username, password, or other means distinct for that user; and (B) that is primarily intended for the user to upload, store, and manage user-generated personal content on the service, platform, or website.”  These prohibitions would be enforced by the United States Department of Labor.  The Secretary of Labor could bring a civil action seeking injunctive relief and where appropriate, employment, reinstatement, promotion, and the payment of lost wages and benefits.  There is no fee-shifting provision.  The Secretary of Labor is empowered to assess civil penalties not to exceed $10,000, taking into account the previous record of the employer and the gravity of the violation.  The civil penalty collection provisions are the same as those codified in the Migrant and Seasonal Agricultural Worker Protection Act.  See 29 U.S.C. 1853.  The proposed legislation does not provide a private cause of action.  In other words, enforcement is exclusively in the hands of the Secretary of Labor.  

               This week, Senator Richard Blumenthal (D-CT) and Representative Martin Heinrich (D-NM) introduced the “Password Protection Act of 2012”, a copy of which can be found on Senator Blumenthal’s website.  This bill, which we will analyze in greater detail next week, provides for fines for employers who violate the proposed act.

Please be sure to visit our website at http://RobertBFitzpatrick.com

Wednesday, April 11, 2012

The Spotlight is On Practice of Employers Requesting Access to the Social Media Accounts of Employees and Job Applicants



As we discussed earlier this week, both houses of the Maryland General Assembly have passed legislation that would prohibit employers in Maryland from asking current employees and job applicants for their usernames and passwords to social media sites, for example, Facebook and Twitter.  The legislation passed unanimously in the Maryland Senate and by a substantial margin in the House, and has now been sent to the Governor for his signature.  If the Governor should sign, the legislation will be the first of its kind in the country. 

The Maryland legislation was birthed as a result of a controversy that ensued between the Maryland Department of Public Safety and Correctional Services and the ACLU of Maryland when, back in 2010, the Department required job applicants to submit usernames and password information related to their social media sites, purportedly to check for gang affiliations.  The Department suspended and then dropped the requirement after protests by the ACLU.  In this correspondence, the ACLU asserted that the Department’s conduct violated the Stored Communications Act, 18 U.S.C. § 2701-11 and its Maryland analog, Md. Courts & Jud. Proc. Art., § 10-4A-01, et seq.  The ACLU also noted that the Department’s conduct may give rise to violations of the common law tort of invasion of privacy and arguably chilled the First Amendment rights of employees.  The ACLU argued that “there can be little question but that forced ‘authorization,’ such as that demanded of [the applicant], is not proper authorization under the SCA, given the disparate bargaining power of the employer and employee or applicant.”  In the wake of the ACLU’s allegations, some commentators, such as Orin Kerr of the George Washington University School of Law, have likened surrendering social media passwords to handing over the keys to one’s home. 

While the Maryland legislation attempts to resolve these concerns, as passed it does not explicitly provide for a private cause of action, complaint procedures, or criminal sanctions.  This appears to relegate enforcement of the Maryland legislation to the realm of tort suits for wrongful termination in violation of public policy under Adler v. Am. Standard Corp., 291 Md. 31 (1981) and its progeny.  Similar legislation has been introduced  in Illinois, Michigan, Minnesota, Massachusetts, and California.  More information on the Michigan bill is available in a recent blog post by Jason Shinn of the Michigan Employment Law Advisor. John Holmquist of the Michigan Employment Law Connection, Emil Protalinski of ZD Net, and Mitchell H. Rubinstein of the Adjunct Law Prof Blog recently published blogs about a Michigan teacher’s aide was fired for refusing to hand over his Facebook. New Jersey Assemblyman John Burzichelli has announced that he will introduce a bill on the subject.

Two United States Senators have requested that the Department of Justice and EEOC review the matter, citing an uptick in requests by employers for job applicants’ username and password for social media sites.  The letter to DOJ notes that this practice appears to violate Facebook’s terms of service and cites cases which, according to the authors, may subject employers who request usernames and passwords from applicants to liability.  See Konop v. Hawaiian Airlines, Inc., 302 F.3d 868 (9th Cir. 2002); Pietrylo v. Hillstone Rest. Group, Civ. No. 06-5754, 2009 U.S. Dist. LEXIS 88702 (D.N.J. Sept. 25, 2009).  The letter follows with a request that the DOJ issue a legal opinion regarding whether requesting and using job applicants’ social media passwords violates current federal law, including the Stored Communications Act and the Computer Fraud and Abuse Act.

The letter to EEOC asks it to investigate whether such requests violate the anti-discrimination laws, expressing a concern that access to such sites would give employers access to personal information about the job applicants’ religious views, national origin, family history, gender, marital status, and age.  The letter states that the two Senators “are concerned that collecting this sensitive information under the guise of a background check may simply be a pretext for discrimination.”  As with the letter to the DOJ, the letter to the EEOC asks the Commission to issue a legal opinion as to whether this practice violates current federal law. 

The two Senators, Richard Blumenthal (D-Ct) and Charles E. Schumer (D-NY) have indicated that they intend to introduce federal legislation.  It is unclear, however, whether federal legislation on this topic is necessary.  In Borchers v. Franciscan Tertiary Province of the Sacred Heart, Inc., 962 N.E.2d 29 (Ill. App. 2012), the court found that an employer had violated the Stored Communications Act by looking at an employee’s personal e-mail.  The court reached this holding even though the employee accessed the e-mail account from her work computer, and the account could be accessed without entering a username or password.  Similarly, in Shefts v. Petrakis, No. 10-cv-1104, 2011 U.S. Dist. LEXIS 136538 (C.D. Ill. Nov. 29, 2011), the court found that employee e-mails stored on the employer’s servers were in “electronic storage” under the Stored Communications Act and it was a violation for the employer to access them without authorization. 

On another front, Facebook recently threatened to sue employers who request that job applicants provide access to their Facebook profiles.  Facebook’s Chief Privacy Officer, Mr. Erin Egan, in a statement issued March 23, 2012, stated: “We’ll take action to protect the privacy and security of our users, whether by engaging policymakers or, where appropriate, by initiating legal action.”  Mr. Egan indicated that asking for someone else’s Facebook password violates Facebook’s user agreement. 

Employer requests for the username and passwords needed to access the social media accounts of employees and job applicants has kicked up a great deal of discussion throughout the legal community.  Phil Miles at Lawffice Space has made several posts on this issue, and concludes that, while the question is not yet settled, “[the] consensus amongst employment law bloggers [is] that it’s not cool and potentially not legal[.]” As a practical matter, Dave Copeland of Read Write Web, quoting career coach Ms. Sandra Lamb, believes that “[i]f your FaceBook or other social media password is requested (or required) [by an employer or potential employer] that goes beyond a red flag – it’s a deal breaker.” Jon Hyman of the Ohio Employer’s Law Blog notes that the law will affect a small number of owners because a “small percentage of employers [] engage in this practice”. Justin Keith of GreenbergTraurig’s L&E Blog points out that “[t]he law also makes it unlawful for an employer to refuse to hire an applicant who refused to disclose the same information.”

Ms. Kara Mignanelli reports that only approximately 18 percent of companies use social media to screen job applicants, 89% use it for recruiting.  Companies seeking to employ this less intrusive method of screening would, accordingly, be well advised to ensure that they employ reputable agencies that comply with all applicable laws.  In particular, if an employer outsources review of social media sites, it would appear that the requirements of the Fair Credit Reporting Act apply which would, among other things, require that the written consent of the employee or job applicant be obtained. See Fair Credit Reporting Act, 15 U.S.C. § 1681; Letter from Federal Trade Comm’n to Nixon Peabody, LLP on May 9, 2011.  Should companies decide to conduct social media screening in-house, they must be careful about how such screening is structured.  While any company considering such a program would be well advised to seek in-depth legal advice, Ms. Dawn Lomer explains that – at a minimum – the person making the hiring decision should not participate in the screening. 

Furthermore, it is as yet unclear what effect, if any, legislation such as that passed by Maryland will have on the ongoing debate in the courts regarding discovery of Facebook material. Compare Zimmerman v. Weis Mkts., Inc., No. CV-09-1535, 2011 Pa. Dist. & Cnty. Dec. LEXIS 187, 2011 WL 2065410 (Pa. C.P. Northumberland May 19, 2011); McMillen v. Hummingbird Speedway, Inc., No. 113-2010, 2010 Pa. Dist. & Cnty. Dec. LEIS 270, 2010 WL 4403285 (Pa. C.P. Jefferson Sept. 9, 2010) (both allowing discovery of Facebook materials); with Piccolo v. Paterson, No. 2009-4979, 2011 Pa. Dist. & Cnty. Dec. LEXIS 45 (Pa. C.P. Bucks May 6, 2011); Kennedy v. Norfolk S. Corp., No. 100201437 (Pa. C.P. Phila. Jan. 15, 2011) (both denying discovery of Facebook materials). 

Courts are also divided as to the discovery of social media passwords in particular.  As reported by Ethan Wall on the Richman Greer Blog, some courts have ordered individuals to supply passwords to Facebook and other websites.  See Gallion v. Gallion, FA 114116955S (Ct. Super. Ct. Sept. 30, 2011).  However, as noted by Daniel E. Cummins at the Tort Talk blog,  the court in Kalinowski v. Kirschenheiter & Nat’l Indemn. Co., No 6779 of 2010 (C.P. Luz. Co. 2011), other courts have refused to order the production of social media passwords.  Note that the court in Zimmerman, which ordered discovery of Facebook materials, emphasized that its decision should not be read to open the door to unlimited discovery of a party’s private social media accounts.  Zimmerman, 2011 Pa. Dist. & Cnty. Dec. LEXIS 187.  Having reported the foregoing, the advice of the Employment Law Bits blog is well taken: individuals should think twice about the information and pictures posted on any social media site. 

Please be sure to visit our website at http://RobertBFitzpatrick.com

Tuesday, April 10, 2012

Maryland About to Become First State to Ban Employer Requests for Social Media Passwords


Both houses of the Maryland General Assembly have passed legislation that would prohibit employers in Maryland from asking current employees and job applicants for their usernames and passwords to social media sites, for example, Facebook and Twitter.  The legislation passed unanimously in the Maryland Senate and by a substantial margin in the House, and has now been sent to the Governor for his signature.  If the Governor should sign, the legislation will be the first of its kind in the country.  

The Maryland legislation was birthed as a result of a controversy that ensued between the Maryland Department of Public Safety and Correctional Services and the ACLU of Maryland when, back in 2010, the Department required job applicants to submit usernames and password information related to their social media sites, purportedly to check for gang affiliations.  The Department dropped the requirement after protests by the ACLU.  While the Maryland legislation attempts to resolve these concerns, as passed it does not explicitly provide for a private cause of action, complaint procedures, or criminal sanctions.  This appears to relegate enforcement of the Maryland legislation to the realm of tort suits for wrongful termination in violation of public policy under Adler v. Am. Standard Corp., 291 Md. 31 (1981) and its progeny. 

Similar legislation has been introduced in Illinois, Michigan, Minnesota, Massachusetts, and California.  New Jersey Assemblyman John Burzichelli has announced that he will introduce a bill on the subject, and two United States Senators, Richard Blumenthal (D-Ct) and Charles E. Schumer (D-NY) have indicated that they will introduce federal legislation.

A more detailed analysis of these developments, will appear in this space tomorrow.

Please be sure to visit our website at http://RobertBFitzpatrick.com