Manage HR Magazine | Wednesday, May 24, 2023
Employers must follow the best practices to ensure compliance with diversity and inclusion laws.
FREMONT, CA: Information about an identifiable individual is considered personal information. Since diversity and inclusion surveys involve sensitive information, collecting personal information requires a careful approach. Financial, tax, health, sexuality, and criminal conviction information are considered sensitive personal information, though there is no prescribed list. Diverse and inclusion-related information is generally treated as sensitive personal information by Canadian employers and other organizations. Employers must obtain voluntary, express consent before sensitive personal information, such as diversity data, is collected.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Data security
Organizations must implement technical and organizational measures to protect the personal information an individual provides against loss, theft, or unauthorized access to, disclosure, copying, use, or modification. The security safeguards level is adjusted accordingly depending on the information's sensitivity. The key to ensuring the security of sensitive personal information is to limit access to such information to individuals within the organization who are in the right position to know. For example, a small group of people directly involved in human resources should have access to such information rather than the entire department.
An employer who engages a third party to conduct employee surveys on their behalf must agree with the third party service provider. It includes provisions relating to data security, requiring that the third-party service provider protects the information and restricts its usage of the information, as well as reporting breaches.
Guidelines and best practices
Furthermore, organizations should consider the following best practices in addition to the obligations regarding meaningful consent and data security:
De-identification: The purpose and goals of an organization should be able to be achieved with the collection of anonymous or de-identified data rather than information that can be associated with individuals.
Use of third-party firms: To avoid having sensitive information about employees accessed by human resources or other employees, consider engaging a third-party firm to safeguard sensitive employee information before it can be de-identified for reporting and analytics. There must be a robust data security provision in any agreement with a third party if it is to be used at all.
Limit retention of personal information: To ensure compliance with Canadian employment laws and the other applicable laws, organizations must limit the retention of sensitive survey information.
More in News