Full transcript
0:00I think that's really where these laws
0:02have originated from and it's the
0:04primary focus is consumers who are
0:06turning over their information for the
0:09purpose of receiving Services receiving
0:11Goods whatever it might be uh credit
0:14card companies Etc consumers are really
0:17have have primarily been the focus of
0:19these us laws and the European laws
0:22historically but that's shifting a
0:24little bit even to the uh to the
0:26non-consumer and to individuals who are
0:28you know mainly their providing their
0:30information perhaps just for the purpose
0:32of getting a job or applying for a
0:38job good morning HR I'm Mike coffee
0:41president of imperative bulletproof
0:43background checks with fast and friendly
0:45service and this is the podcast where I
0:47talk to Business Leaders about bringing
0:49people together to create value for
0:51shareholders customers and the community
0:54please follow rate and review good
0:56morning HR wherever you get your podcast
0:59you can also find us on Facebook
1:01Instagram YouTube or atg good morning
1:04hr.com many Business Leaders are
1:07familiar with privacy laws like the
1:09health insurance portability and
1:10accountability act the Graham Leach
1:12blyly Act and the Fair Credit Reporting
1:15Act each of those when they were passed
1:17were groundbreaking and required
1:19significant changes to how businesses
1:21stored and shared individuals data but
1:24information about consumers interactions
1:27with businesses what you buy from Amazon
1:30what you search in Google or the
1:32information you provide in an employment
1:34application have largely been considered
1:36the property of the businesses who
1:38collect that data but that's changing at
1:42both the state and federal level
1:44legislators and Regulators are taking
1:46action to give individuals more control
1:48over information concerning themselves
1:51joining me today to discuss the growing
1:53Labyrinth of data privacy laws across
1:56the United States is Jason Barrett Jason
1:59is an attorney based in Houston Texas
2:01and he's the principal and founder at
2:04Jame Consulting where he helps clients
2:06with issues concerning employment law
2:08intellectual property and data privacy
2:11compliance welcome to Good Morning HR
2:14Jason thank you so much Mike it's great
2:16to be here thanks for having me so let's
2:19start by painting that big picture
2:21what's driving all this concern about
2:24personal data
2:25privacy well that's a good question I
2:27think largely it's based on cultural
2:30shift uh especially here in the United
2:32States I would say that really
2:35foundationally Europe has had a quite a
2:38significant focus on pii or personally
2:41identifiable information going back many
2:43years but it's really only within the
2:45last 10 years or so that the US has
2:47adopted what I would describe as a more
2:50overarching model um like the gdpr which
2:54we'll talk about here probably in the
2:56next few minutes over the last few years
2:59the US has really adopted that and
3:01there's really been the result of a
3:02cultural shift from corporate owned
3:05information to personally owned
3:07information and the regulations
3:09surrounding that what do you think's
3:10driving that why why why are the
3:13politics and and just kind of the
3:15Zeitgeist around that
3:17changing I think the stakes are just so
3:19much higher there's so much information
3:21out there that's available there's so
3:23many different forums of information uh
3:26we see on the news so often Mike that
3:28the data breaches that are are coming
3:31fast and furious and I think individuals
3:33are just um fed up quite honestly with
3:36it and and there's a need for in the in
3:38the US and other countries have seen the
3:40need for more regulation around security
3:43and the expectations that companies
3:46really need to have imposed upon them to
3:47protect that information so you talked
3:50about pii so is is that you know person
3:53identifiable information is that
3:55primarily the kind of information we're
3:56talking about or is there other are
3:57there other kinds of information well I
3:59know there are so what are the other
4:00kinds of you know why don't you tell
4:02tell us what pii is and then into the
4:04you know what that sensitive personal
4:06information kind of
4:07ranges sure I really do think it kind of
4:10falls into two primary buckets as it
4:12relates to these kinds of data privacy
4:14laws there's pii or personally
4:16identifiable information how I describe
4:19that typically is anything that you
4:20might see on a business card quite
4:22honestly or on a LinkedIn profile
4:24someone's name someone's perhaps their
4:27address even their job title perhaps
4:29perhaps any kind of other kinds of
4:31location related data that again you
4:34might just see on a normal business card
4:37and then as you move into sensitive
4:38personal information it's as it as it
4:40would suggest to be it's information
4:43that's a little bit more sensitive but
4:45that individuals uh might need to
4:47provide their employer or other third
4:49parties things like race and religion
4:52genetic data health or medical
4:54information that's really where you get
4:56into that sensitive data and it's really
4:59both of those buckets that are being
5:00regulated by these state of privacy laws
5:04and
5:05so people put so much of that
5:07information online already and with all
5:10the data breaches that have happened I
5:12mean I'm a licensed private investigator
5:14in addition to being an HR guy and the
5:18databas is I mean you know in our due
5:20diligence projects or even when we're
5:21working in implment related background
5:24investigation it's all out there I can
5:26get you know just from you know you
5:29relatively low price database is that
5:32you know I have to have a glb or a dppa
5:35a permissible purpose but it's all there
5:38and it's all been breached at some point
5:40I mean you know you can go find my stuff
5:41on the dark web I get alerts from from
5:44my credit card companies and all these
5:45other sources all the time so if the
5:47horse is out of the barn just how much
5:49do you think the average consumer needs
5:52to worry about about their data
5:55being breached or you know released and
5:59used used against them well there are to
6:02your point there are so many different
6:04notices that we're getting pres almost
6:06on a daily basis about certain kinds of
6:09data breaches it's available in so many
6:11different areas as you said I do think
6:14though especially relating to kind of
6:16the cultural shift that I had mentioned
6:18earlier as it relates to employers and
6:21their need to be aware of these
6:23different laws I do think that there
6:25there is a need uh for there to be a
6:27real awareness and an education exercise
6:30within the employment context and for
6:32individuals uh as I said earlier I think
6:34the Europeans in general have been much
6:37more sensitive to this and much more
6:39aware of this and and focused on their
6:42their personal information and being
6:44more protective of releasing that
6:45information and I think in the US in
6:48particular uh there really needs to be a
6:50little bit more protection and a little
6:52bit more for thought into the kinds of
6:55information that we're generally and
6:57have historically just made available
6:59really without asking why why do you
7:01need this information yeah I mean every
7:03time I go into my doctor's office they
7:06still hand me a um a sheath of forms to
7:11fill out yet again right and they always
7:13want my social security number there is
7:15no reason for them to know my social
7:16secur number they got my insurance card
7:18they've got all that and they're
7:19collecting that and then you can see you
7:21know just a whole wall of manila folders
7:24back there behind them that aren't
7:25locked up and uh you know you know every
7:27one of those has that social security
7:28number so that you know that's a data
7:31breach waiting to happen and you're
7:33right Europe is you know we we do work
7:35in Europe for for some of our clients
7:37and and the data transfer laws in Europe
7:39are really pretty strict and and the
7:41kind of access you have in to is pretty
7:45pretty challenging and so a lot of these
7:47laws though then are really a lot
7:50about making the consumers feel better
7:53even if maybe their their data is out
7:55there I don't want to give it have yet
7:57another breach I don't want you know I
7:58don't want uh or or you know I don't
8:02want people just Willy nearly sharing my
8:04information all over there's a I think
8:06we do
8:08have the sense that we've lost a certain
8:10amount of privacy I mean you know the
8:12the saying in the early odds was you
8:14know privacy is dead and uh and I think
8:18to a certain extent that's probably true
8:19for most people but we've killed it
8:21ourselves we put all our stuff out there
8:23and uh and made it available but when
8:25we're talking about these privacy laws
8:27these regulations
8:29they're they kind of categorize people
8:32in three different buckets right data
8:33controllers data processors and then
8:36these consumers talk about what each of
8:38those roles are who those people are and
8:42and you know what does it mean to be a
8:43controller versus a processor those kind
8:45of issues sure and it's a good way to
8:48think about it in terms of kind of the
8:50the the purpose for which these laws are
8:52are set up so when you think about it
8:54and I'm going to I'm going to describe
8:55it sort of from the context of a of an
8:57employment situation so so let's say
9:00you're a company and and you have uh
9:03those three different roles that we
9:04talked about so from a processing side
9:07it might be anyone for instance in an HR
9:10role um or a third party even that's
9:13supporting an organization in terms of
9:17employee counts employee reports the
9:19kinds of information that an
9:21organization might have with respect to
9:23applicants with respect to their
9:25employees uh performance related reviews
9:27so that's kind of the data we're talking
9:29about really for the purpose of managing
9:31the business so the processing is really
9:34those individuals that are that are
9:36tasked with helping to manage the
9:39information share the information
9:41potentially make uh reports of that
9:44information and that context the
9:47controller uh would really be the
9:49organization itself and those that are
9:51in a decision making uh Authority or or
9:54position I should say to decide how
9:57we're going to use that information as
9:58an organization how are we going to uh
10:01make use of that information with
10:03respect to managing benefits with
10:05respect to payroll with respect to
10:07whatever fill-in-the blank purpose there
10:09might be it's those controllers that are
10:11making that decision and typically an
10:14organization or the company in this
10:16particular context will be thought of as
10:18the controller and you mentioned
10:19onethird term Mike remind me and I
10:21consumers yeah justers absolutely yeah
10:24consumers first and foremost I think
10:26that's really where these laws have or
10:29inated from and it's the primary focus
10:31is consumers who are turning over their
10:33information for the purpose of receiving
10:36Services receiving Goods whatever it
10:38might be uh credit card companies Etc
10:41consumers are really have have primarily
10:44been the focus of these us laws and the
10:47European laws historically but that's
10:50shifting a little bit even to the uh to
10:52the non-consumer and to individuals who
10:54are you know mainly they're providing
10:56their information perhaps just for the
10:58purpose of getting a job or applying for
11:00a job and so like so a data controller
11:05would be like an employer who wants
11:09to aggregate all their applicant data
11:12into a database for statistical purposes
11:14and they decide we're going to do this
11:16we're going to pull all the applicants
11:17in and come up with some you know things
11:20about you know General maybe we're going
11:21to feed our AI feed it into RI to tra
11:24train our employee selection process and
11:27so here's all our employee information
11:28here's what the pool looks like and
11:30we're going to use it to train the AI
11:32That's the company making that decision
11:34but then that processor if they if they
11:36had an HS system that made that
11:39available the processor would be the HRS
11:41system is that
11:44or yes I think the individuals maybe
11:47that are working within that data data
11:49data entry or or exporting reports or
11:52whatever it might be um would generally
11:54be considered your processor but I think
11:56the hris system or Andor those that
11:59manage that system would be the best um
12:02example of a processor from the the
12:05employer
12:06perspective so when we talk about gdpr
12:10then in the EU the general data
12:12protection regulation what does it say
12:15how does it control uh how that
12:17information gets used well I think one
12:20thing to think about in terms of the
12:21gdpr because it's really followed
12:23through with some of these us laws gdpr
12:25is really based on seven foundational
12:27principles it's sort of the purpose for
12:30which this law that law was put in place
12:32and and the US laws have followed
12:35there's a principle of limiting the
12:37purposes for which a particular
12:40organization might be using information
12:42or use it for the The Limited purpose
12:45for which you need it in a similar vein
12:47there's data minimization which is only
12:50use that data that you absolutely
12:52positively need not throwing everything
12:54in the kitchen sink into that data
12:56repository there are the principles of
12:59accountability you know who ultimately
13:01is accountable for managing this data
13:03securing the data and then on a similar
13:06vein confidentiality and security that's
13:08one of the principles as well as storage
13:10limitation figuring out how an
13:12organization is going to dispose of that
13:14data once it's it's brought into the
13:15fold how an or how an individual can be
13:18sure that that data is accurate so
13:20accuracy is another foundational
13:22principle and then finally it's the
13:24lawfulness piece is are you using this
13:27data for the purpose uh that's for for a
13:29purpose that is lawful and for which
13:31I've provided it to you to use and in
13:35the employment
13:37context that would be in order to be
13:40evaluated as an employee to be hired to
13:42be managed as an employee what would
13:45some uses that an employer might not
13:48think of that might fall outside that
13:50they may you know have thought they
13:52could use information for that might
13:53fall outside of that narrow you know
13:57scope sure so I think you know probably
14:00that consumer example is a good example
14:02a lot of individuals when they're
14:05applying for a job when they're knowing
14:07that their organization is going to need
14:08to have their information for purposes
14:10of managing payroll benefits etc those
14:12those those obvious purposes but let's
14:15say an employer decides that they're
14:17going to they're going to have a
14:18collaborative partnership with some kind
14:19of a third-party insurance provider um
14:22that wants to make available uh a
14:25certain tool or resource to that
14:28employee
14:29population that's really not within the
14:32the primary business practice or
14:35relationship of the employer in that in
14:37that third party uh it's an add-on if
14:39you will that can kind of get into that
14:41category really of of something that was
14:43turned over by an individual for the
14:46purpose of HR management only that then
14:49moved over into a little bit more of a
14:51consumer practice if their employer
14:53makes that decision to uh make their the
14:56employee roster available to third part
14:59parties outside of the context that that
15:02primary relationship is based upon and
15:04so what are the so that's Europe
15:09and except to the extent that a us well
15:12let me ask let's say we' got a us uh an
15:15EU citizen who's here on a Visa and is
15:17working in the US does gdpr have any
15:21impact on employers who are us-based for
15:24an employee who's currently us-based I I
15:27would say yes now admittedly my my
15:29Approach has always been pretty
15:30conservative when you think about the
15:32the global operations of an organization
15:35and so I I would think about it more
15:37from the standpoint of where are where
15:39are you operating from a Global
15:41Perspective not necessarily well we only
15:44have individuals based in the US and
15:47therefore we probably don't need to
15:48think about gdpr if you are operating
15:51and you have a business um that extends
15:54outside of the US even if your employees
15:56are are sitting only in the US I think
15:59you absolutely need to be familiar with
16:01gdpr and you need to make sure that
16:04you're following the different protocols
16:05because of of how you're operating on a
16:08global basis including within the EU or
16:10the UK and you talked about the Seven
16:12Pillars of like the gdpr's data privacy
16:16framework as far as the at the federal
16:19level in the US what rules do we have in
16:22place right
16:23now uh I mean I mentioned Hippa and glba
16:27and dppa the Fair Credit Reporting Act
16:30uh when those are all all about you know
16:32protecting people's personal data are
16:34there other laws at the federal level or
16:37are we mostly dealing with it this more
16:39at a state level in the US well of
16:41course as you mentioned there's the
16:43industry or sector specific laws that
16:45we're all pretty familiar with with
16:47HIPPA the FC the Graham Graham leech
16:50biley act there's the Federal Trade
16:52Commission that by and large has being
16:54the federal enforcement body as it
16:56relates to data privacy um on things
16:59like children's information
17:02telemarketing rules Etc as you've moved
17:05over the years more and more states have
17:07adopted what I would describe as
17:10probably focused laws um initially for
17:13instance like in Illinois and Texas as
17:15an example you you have biometric
17:17Privacy Act laws uh a lot of people
17:19weren't familiar with the Texas law
17:21until there was a very recent large
17:23enforcement uh action um by the Texas
17:26Attorney General and that particular
17:29biometric identifier act from Texas goes
17:32back to 2009 uh so that was an early
17:35adopter I guess Texas could be seen to
17:37be an early adopter in that capacity so
17:40it's really kind of spanned and and made
17:41a transition from industry sector
17:44specific laws of the kinds that we were
17:47mentioning uh now into more State
17:49specific laws that are drilling down in
17:51into a little bit more detail on how
17:54organizations are are using information
17:56either biometric data or that that pii
17:59and sensitive data that we talked about
18:02earlier and let's take a quick break
18:05good morning HR is brought to you by
18:07imperative bulletproof background checks
18:09with fast and friendly service 25 years
18:12ago I found it imperative to help risk
18:15averse clients make well-informed
18:16decisions about the people they involve
18:18in their business because we don't cut
18:21Corners our research is more thorough
18:23and our reporting more robust our
18:26clients make better hiring decisions
18:29however employers often don't know what
18:31to ask Beyond price when evaluating a
18:34background screening partner so we've
18:36compiled a short list of six questions
18:38that you should ask any prospective
18:40screening partner including imperative
18:42to ensure that you understand what
18:44they're really trying to sell you these
18:47questions identify the most common ways
18:48background check companies cut Corners
18:51that impact the quality accuracy and
18:53depth of the information they provide
18:56employers you can review the six
18:58questions you should ask of your
18:59background check partner at imperative
19:03info.com
19:05sl6 and of course you can always reach
19:07out to imperative to discuss your
19:09background check process through our
19:11website at imperative
19:14info.com if you're an hrci or sh
19:17certified professional this episode of
19:19good morning HR has been pre-approved
19:21for 1 half hour of recertification
19:23credit to obtain the recertification
19:26information visit good morning HR
19:29and click on Research credits then
19:31select episode
19:33178 and enter the keyword data that's da
19:38ta and now back to my conversation with
19:41Jason
19:43Barrett talk about the Texas biometric
19:45law what does it what does it entail and
19:48and how how does it really affect
19:50employers yeah so it really kind of goes
19:52to making sure that organizations or
19:55anybody that's collecting biometric data
19:57could be face ID type information could
19:59be uh fingerprints Etc things of that
20:01nature it goes in and it regulates how
20:05um uh organizations are using that and
20:07the kinds of information that needs to
20:08be provided to those individuals before
20:12you collect it that particular case was
20:15pretty interesting that came down it's
20:17actually had gone back quite a few years
20:20but it was a$ 1.4 billion settlement
20:23that the Texas Attorney General entered
20:25into with meta uh that goes back quite a
20:28few years and then there's another
20:29lawsuit that's pending under the similar
20:32law the same law I should say uh with
20:34Google right now and that probably
20:36surprises people what how is meta how
20:38are meta and Google collecting my
20:40biometric information right so that's
20:43that's the thing is I think they were
20:44they had not been transparent with how
20:46they're doing that and and that was one
20:47of the the findings as I understand it
20:50in the in the in the law and in the
20:51penalty and so much about these laws is
20:54about transparency if you're going to
20:55collect this particular kind of data you
20:57need to let people know you need to tell
20:59them how you're collecting it why you're
21:01collecting it and and the and the use of
21:03that data and that's so they were just
21:06what were they they were just collecting
21:09what my face looks like and is that is
21:12that primarily what the biometric
21:14information was or yeah I think in that
21:17particular case I would need to go back
21:19and look at all the the Dig beneath the
21:20surface on all the the details of that
21:22one but but it was kind of a land
21:25Landmark type ruling uh that relates to
21:28information that they were really
21:30collecting without notifying people and
21:32so now they're probably notifying us and
21:33we're click click click click yes yes
21:35yes accept except except and moving
21:37right past it anyway but at least now
21:39they're telling us right interesting so
21:43you know Texas and California at are
21:45opposite ends of the political Spectrum
21:47pretty much but I mean certainly in the
21:51last legislative session Texas had some
21:53privacy bills and I we know the session
21:56starts again in January
21:58and I know the State Chamber of Commerce
22:01the Texas Association of business has
22:03been working for the last two years with
22:05representative krig On's uh office and
22:09other legislators around their you know
22:13Privacy Law part two from you know
22:15following up from last session and then
22:17California obviously has had a lot of
22:19issues uh on on the Privacy front
22:22too what are typical you know state
22:26level privacy things that you see are
22:29kind of Cutting Edge between Cal you
22:31know California Texas Florida whoever
22:33else is having those what do you think
22:34we're going to be dealing with in the
22:36next few
22:38years well I think the Texas Attorney
22:40General for one is kind of signaled with
22:43that particular finding that we just
22:44talked about that they're going to be
22:45aggressive and there was a recent
22:47conference where they they all bet said
22:49you know get ready we're going to be
22:50looking to enforce these particular laws
22:53including the Texas data privacy and
22:54secret secrecy act uh there's also the
22:58Texas data broker act that went into
22:59place more recently and that's more
23:01focused on consumers as we were talking
23:03about earlier um and organizations that
23:07collect information really for the sole
23:09purpose of monetizing that particular
23:12that that set of information but I think
23:15probably the the primary focus area is
23:17going to be what kind of notifications
23:19what kind of communications and
23:21transparency are organizations that
23:24collect this information providing to
23:26consumers or to the indiv idual or the
23:29data subjects that they're collecting
23:31it's going to be really key that uh
23:33those notifications are made there's
23:35privacy policies that are communicated
23:37that individuals are given the
23:39opportunity to to opt in as it relates
23:42to the collection of that information
23:44especially on the on the consumer side U
23:46but I think it's going to be primarily a
23:49focus on communication transparency and
23:52notification as it relates to any
23:55individual whether they employee or a
23:57consumer turning over that
24:00information and I think the Texas data
24:03Private Security Act exempts if and
24:07correct me if I'm wrong I'm thinking
24:09that from the you know remembering the
24:10conversations during session is that it
24:12exempts
24:14information that's gathered and
24:17used by for employment by employers is
24:21is is that right or there is an
24:23exemption if it's if it's truly just
24:25used for for processing for employment
24:28compensation Etc California had a
24:31similar exemption but that that was
24:33sunset uh with the with the the newer
24:35law that went into place which was kind
24:37of took Folks by surprise there are
24:39other exemptions under Texas law
24:41including or organizations that are
24:43nonprofit small businesses as an example
24:47as defined into the small business act
24:49as well as other organizations that
24:53might already be regulated under laws
24:55like Hippa uh or some of the banking and
24:57consumer law laws and so with the idea
25:01being pretty straightforward that you
25:02don't want to duplicate or overreach in
25:05terms of organizations that are already
25:07covered by some of those other laws um
25:10but so there are exemptions in in those
25:12particular cases but that doesn't mean
25:16that an employer who has employee you
25:18know applicant information or employee
25:19information can just go sell that
25:21information that pii or that sensitive
25:23data about their employees to a third
25:25party for marketing purposes or whatever
25:27else right that's correct yeah I think
25:29that's still going to potentially be
25:31something that might be covered under
25:32the Texas data broker act if you're
25:34moving into territory that was
25:37previously really just collecting for
25:39the purposes of HR Administration and
25:42then you're moving it into a little bit
25:43more of a uh Monet monetization exercise
25:47uh that's going to be a a pretty
25:49high-risk scenario in in especially with
25:51these new
25:52laws so if we're dealing with let's say
25:56we're a Texas based company we're
25:58dealing with a consumer who lives in
26:00Iowa which state's data privacy laws
26:03apply in those circumstances if you got
26:06two states with different or California
26:08and Texas for that matter two states
26:09with different laws how do how does an
26:11employer know when you know which laws
26:15apply is it you know if if I'm if I'm
26:17considering it let's start with the
26:18applicant who lives in in California is
26:21moving to Texas for the job if they get
26:23the job does California's Privacy Law
26:26apply to them because there resident in
26:29California or just Texas I would take
26:32the approach uh of both really need to
26:35look at out of an abundance of caution
26:36both because there are so many different
26:39things that are the same about these
26:40laws but there's also some overlapping
26:42uh implications as well and the other
26:45thing certainly if you look at it from
26:48the perspective of where an applicant or
26:49an employee is based yes that's one
26:52differenti differentiating factor but
26:55you also have to look at where the
26:56organization has operations if you have
26:58an organization that you know might have
27:00employees in six seven eight different
27:02states but operations in 47 or 48
27:05different states you know you really
27:07have to look at how those particular
27:10States interact with each other in terms
27:12of data privacy laws and other other
27:14aspects that might regulate that
27:16particular data privacy matter so you're
27:19looking kind of at the to be safe the
27:22lowest common denominator or the most
27:24strict rules and just applying that
27:27absolutely and that's kind of you know
27:29the approach that I've taken in in my my
27:30history with different organizations
27:32that I've worked for is we' recognized
27:34that okay well wow we operate in these
27:36however many different countries where
27:38do we start Where Do We Begin how do we
27:40look at this from a from a um compliance
27:44standpoint and what we ended up doing
27:46was kind of to your point we looked at
27:48what's the most U prescriptive uh what's
27:52the most overarching and and broadest
27:56regulatory regime that we might be
27:58operating in and if we can comply with
28:01those particular laws and regulations
28:03that we feel comfortable that we're
28:04going to be in a much better position
28:08globally so if I'm an HR leader or just
28:12a a the you know the business who has
28:15these employees I probably have
28:18information in a bunch of different
28:20silos right I've got applicant tracking
28:22information then I've got you know
28:24employee information in my HRS maybe
28:26I've got a separate payroll provider
28:27who's got employee information maybe you
28:31know my benefits are you know I have a
28:32you know I've got a system uh for
28:35managing our health insurance that may
28:37be my broker
28:38provides
28:40how keeping track of what data is where
28:44and and how we're categorizing it are
28:48there best practices to kind of get your
28:51arms around where the data is and making
28:54sure that you've got some accountability
28:57for it
28:58absolutely and one thing that I would
29:01recommend is that whomever is going to
29:04be responsible for your data privacy
29:06your data protection in your
29:08organization really takes a deep dive
29:11into understanding really it's the who
29:14what when where why and how of data
29:16within the organization and and in terms
29:19of the where as you were mentioning
29:20earlier there could be many
29:23different applications many different
29:26storage facilities Etc
29:28where this data is housed and so
29:31probably early on if an organization
29:34hasn't started to do this and especially
29:36if they're growing by acquisition You'
29:38got multiple uh other thirdparty
29:40companies that are now becoming part of
29:42your organization that might have
29:43different systems might have different
29:44individuals that have been responsible
29:46for this I would say start there is
29:49really try to come up with the the data
29:51mapping as best you can for what data
29:54you hold why you hold it and who has
29:58responsibility for it and then certainly
30:00to your point you have to know where
30:02it's stored uh for purposes of putting
30:04the best data privacy regulations in
30:08place because of the data providers we
30:11work with on the background
30:13investigation side of our business the
30:15you know one of the things that we see a
30:17lot is that certain data we keep data in
30:20certain different states uh you know
30:22that we've got data that's active then
30:24we've got data that is for all you know
30:27t purposes will probably not ever need
30:29to access we've never needed to access
30:31before but we keep it for up to seven
30:33years for litigation purposes and that's
30:35you know in an archive State and then at
30:38some point after that depending on what
30:39the data is we may delete it all
30:41together and not record it do the laws
30:43address that or is are those just kind
30:45of standard practices or best practices
30:47for for deciding what information to
30:50keep on hand and where to keep it well
30:52the the laws address that in I guess two
30:55ways one is
30:58putting requirements out there that
31:00share and provide notice to individuals
31:03or data subjects on why the information
31:05is being collected and then the second
31:08kind of goes back to one of those
31:09foundational princip principles that I
31:11mentioned earlier with the gdpr that's
31:13followed through with these us laws and
31:15that's the principle of data
31:17minimization only maintain that amount
31:20of data the question that some of these
31:22regulatory authorities will ask is are
31:25you only maintaining the data that you
31:27absolutely need
31:28not the nice to have data but also you
31:31know the have to have you know primarily
31:33looking at that from a data minimization
31:35perspective so you might have
31:38information that to your point that's
31:39spread out all over different states
31:41perhaps all over different
31:43applications but there's really need to
31:46do a deeper dive and Analysis of the
31:49data minimization piece and you know who
31:52has access to that
31:53information one of the things I know
31:56gdpr gives consumer or individuals is
31:59the right to in some cases the right to
32:01be forgotten and in other cases just the
32:04right to have access to know what what's
32:08being stored do we have any of those
32:10kind of Rights uh in the US yes yeah
32:14similar rights have transferred over
32:16into these us laws there's the rights to
32:19some of which you mentioned the rights
32:21to access if I'm an individual how do I
32:23access my information where are you
32:25holding it how do I correct it um do I
32:28take it with me you know if I'm leaving
32:29the organization I want to make sure
32:31that it's it's coming with me and that
32:33there's there's not an unnecessary need
32:36for the information to be retained for
32:38too long of a period of time there's
32:40also these rights of of of notification
32:43of how the information can be
32:45deleted and um who has access to the
32:48information so these notific
32:49notification rights have really
32:51transferred over into the US data
32:54privacy laws as well and from an
32:56employer point of view I mean the answer
32:59except with the exception of a few
33:00States when an employee wants a copy of
33:02their employee file the answer has
33:03always been that's employer's property
33:06no you can't have a copy of your you
33:07know especially a departing employeer um
33:11has that changed under any of these laws
33:14to some extent I would say that
33:16generally speaking that an employer can
33:18still say look that's our employee file
33:20yes it's your information but that's
33:22information and that's a file that we
33:24need for purposes of processing
33:26employment including someone who's
33:29leaving the organization now where
33:31things may may have changed a little bit
33:33is there can be a a data access request
33:36under most of these laws where someone
33:38can come forward whether they're moving
33:41on or whether they're still with the
33:42company they can make a a data access
33:45request to say to their employer look I
33:47want to see what information you have on
33:49me and there's nothing that that says
33:51that an employer can't say fine come
33:53into this office have a look at the
33:56information it doesn't necessarily mean
33:58you have to you know make a copy of all
34:00of their files and and and provide it
34:02over to them if you're concerned in that
34:05respect I do think the companies need to
34:07be more aware of those kinds of
34:10protections under the US data privacy
34:12laws because it's a little bit of of a
34:14new scenario typically in the US that
34:16would really only come up in the context
34:19of litigation where someone might be
34:20suing the company it's a third party
34:22subpoena that comes in through through
34:24an attorney but in this case with these
34:26laws it can be the individual themselves
34:28him or herself making that request for
34:31information and it's important to make
34:33sure that organizations know who's going
34:36to be the point of contact and what are
34:38the different dos and don'ts as it
34:40relates to those requests and right now
34:42that would be a state byst state basis
34:44right figuring out what the the
34:46applicable laws wherever you are so if
34:48you're in Texas you have to look at
34:50Texas uh data Privacy Act versus
34:53California's multiple Acts or Virginia
34:55or wherever you are try to figure that
34:57out uh as an employer which is you know
35:00Pro the problem with uh you know a
35:03federal system where we got 50 states
35:05regulating issues uh it's harder for
35:07employers who are operating in multiple
35:08states to know exactly what they need to
35:10do that's right but I I brought up AI
35:14earlier and let's end with this because
35:16it's you know we can't talk about
35:18anything today without bringing up AI so
35:21what do you think the impact of AI is
35:24going to be uh on data privacy see um do
35:29we you know you know we want all this
35:31data to train these large language
35:32models and all of that but obviously
35:35nobody wants their data TR they want to
35:37use the tools but they don't want their
35:38data in their training the tools so
35:41where do you think that's going what are
35:42you seeing on the AI front I I know
35:45California's had a lot of concerns but
35:47Governor Nome vetoed their AI bill this
35:50week so what do you think is going to
35:52happen with
35:53AI well I think to your point AI is most
35:57definitely here to stay so it's a matter
35:59of of you know how do we how do we
36:01manage that somewhat like we were
36:04talking about in terms of the gdpr
36:06making its way to the US I think the EU
36:09and the UK right now are kind of at the
36:10Forefront as it relates to putting
36:12regulations in place for AI there are
36:15some laws that have been passed over
36:17there and I'd say some best practices
36:20the states have not yet made to your
36:22point you know California again kind of
36:24being the pioneer as it related to the
36:27GD PR moving over into their state law I
36:30would expect you know they'd probably be
36:31leading the way in many respects as in
36:34terms of the laws for AI over in the US
36:38I think that there are so many states
36:40considering that right now and things
36:43being considered at the federal level as
36:45well I think companies realistically we
36:48know that they're going to want to
36:49continue to leverage AI I think it's
36:52just a matter of keeping those same
36:54foundational principles that we talked
36:56about earlier at the Forefront of your
36:59mind in terms of making sure that you
37:01again you're maintaining it for the
37:03right purposes that you're allowing
37:05employees to know what is being
37:08collected and that you're being very
37:10transparent with your your employees and
37:12then on the consumer side with consumers
37:15about the kinds of information and the
37:17purposes for which it's being collected
37:19and
37:20managed well great well that's that's
37:22all the time we have thanks for joining
37:23me Jason thank you for having me I
37:25really appreciate it and and thank you
37:28for listening you can comment on this
37:30episode or search our previous episodes
37:32at good morning hr.com or on Facebook
37:35Instagram or YouTube and don't forget to
37:38follow us wherever you get your podcast
37:40Rob Upchurch is our technical producer
37:43and you can reach him at robm makp
37:45pods.com and thank you to imperatives
37:48marketing coordinator Maryann Hernandez
37:51who keeps the trains running on time and
37:53I'm Mike coffee as always don't hesitate
37:56to reach out if I can be of service to
37:58you personally or professionally I'll
38:00see you next week and until then be well
38:04do good and keep your chin up
38:08[Music]