Free YouTube Transcribe

Video transcript

Good Morning, HR #178: Evolving Data Privacy Regulations and Expectations (Business Credit)

ImperativeInfo · 6,569 words · 30 min read

Want to search this transcript, jump the video from any line, or download it as TXT, SRT, or VTT?

Open in the transcript tool

Full transcript

0:00I think that's really where these laws

0:02have originated from and it's the

0:04primary focus is consumers who are

0:06turning over their information for the

0:09purpose of receiving Services receiving

0:11Goods whatever it might be uh credit

0:14card companies Etc consumers are really

0:17have have primarily been the focus of

0:19these us laws and the European laws

0:22historically but that's shifting a

0:24little bit even to the uh to the

0:26non-consumer and to individuals who are

0:28you know mainly their providing their

0:30information perhaps just for the purpose

0:32of getting a job or applying for a

0:38job good morning HR I'm Mike coffee

0:41president of imperative bulletproof

0:43background checks with fast and friendly

0:45service and this is the podcast where I

0:47talk to Business Leaders about bringing

0:49people together to create value for

0:51shareholders customers and the community

0:54please follow rate and review good

0:56morning HR wherever you get your podcast

0:59you can also find us on Facebook

1:01Instagram YouTube or atg good morning

1:04hr.com many Business Leaders are

1:07familiar with privacy laws like the

1:09health insurance portability and

1:10accountability act the Graham Leach

1:12blyly Act and the Fair Credit Reporting

1:15Act each of those when they were passed

1:17were groundbreaking and required

1:19significant changes to how businesses

1:21stored and shared individuals data but

1:24information about consumers interactions

1:27with businesses what you buy from Amazon

1:30what you search in Google or the

1:32information you provide in an employment

1:34application have largely been considered

1:36the property of the businesses who

1:38collect that data but that's changing at

1:42both the state and federal level

1:44legislators and Regulators are taking

1:46action to give individuals more control

1:48over information concerning themselves

1:51joining me today to discuss the growing

1:53Labyrinth of data privacy laws across

1:56the United States is Jason Barrett Jason

1:59is an attorney based in Houston Texas

2:01and he's the principal and founder at

2:04Jame Consulting where he helps clients

2:06with issues concerning employment law

2:08intellectual property and data privacy

2:11compliance welcome to Good Morning HR

2:14Jason thank you so much Mike it's great

2:16to be here thanks for having me so let's

2:19start by painting that big picture

2:21what's driving all this concern about

2:24personal data

2:25privacy well that's a good question I

2:27think largely it's based on cultural

2:30shift uh especially here in the United

2:32States I would say that really

2:35foundationally Europe has had a quite a

2:38significant focus on pii or personally

2:41identifiable information going back many

2:43years but it's really only within the

2:45last 10 years or so that the US has

2:47adopted what I would describe as a more

2:50overarching model um like the gdpr which

2:54we'll talk about here probably in the

2:56next few minutes over the last few years

2:59the US has really adopted that and

3:01there's really been the result of a

3:02cultural shift from corporate owned

3:05information to personally owned

3:07information and the regulations

3:09surrounding that what do you think's

3:10driving that why why why are the

3:13politics and and just kind of the

3:15Zeitgeist around that

3:17changing I think the stakes are just so

3:19much higher there's so much information

3:21out there that's available there's so

3:23many different forums of information uh

3:26we see on the news so often Mike that

3:28the data breaches that are are coming

3:31fast and furious and I think individuals

3:33are just um fed up quite honestly with

3:36it and and there's a need for in the in

3:38the US and other countries have seen the

3:40need for more regulation around security

3:43and the expectations that companies

3:46really need to have imposed upon them to

3:47protect that information so you talked

3:50about pii so is is that you know person

3:53identifiable information is that

3:55primarily the kind of information we're

3:56talking about or is there other are

3:57there other kinds of information well I

3:59know there are so what are the other

4:00kinds of you know why don't you tell

4:02tell us what pii is and then into the

4:04you know what that sensitive personal

4:06information kind of

4:07ranges sure I really do think it kind of

4:10falls into two primary buckets as it

4:12relates to these kinds of data privacy

4:14laws there's pii or personally

4:16identifiable information how I describe

4:19that typically is anything that you

4:20might see on a business card quite

4:22honestly or on a LinkedIn profile

4:24someone's name someone's perhaps their

4:27address even their job title perhaps

4:29perhaps any kind of other kinds of

4:31location related data that again you

4:34might just see on a normal business card

4:37and then as you move into sensitive

4:38personal information it's as it as it

4:40would suggest to be it's information

4:43that's a little bit more sensitive but

4:45that individuals uh might need to

4:47provide their employer or other third

4:49parties things like race and religion

4:52genetic data health or medical

4:54information that's really where you get

4:56into that sensitive data and it's really

4:59both of those buckets that are being

5:00regulated by these state of privacy laws

5:04and

5:05so people put so much of that

5:07information online already and with all

5:10the data breaches that have happened I

5:12mean I'm a licensed private investigator

5:14in addition to being an HR guy and the

5:18databas is I mean you know in our due

5:20diligence projects or even when we're

5:21working in implment related background

5:24investigation it's all out there I can

5:26get you know just from you know you

5:29relatively low price database is that

5:32you know I have to have a glb or a dppa

5:35a permissible purpose but it's all there

5:38and it's all been breached at some point

5:40I mean you know you can go find my stuff

5:41on the dark web I get alerts from from

5:44my credit card companies and all these

5:45other sources all the time so if the

5:47horse is out of the barn just how much

5:49do you think the average consumer needs

5:52to worry about about their data

5:55being breached or you know released and

5:59used used against them well there are to

6:02your point there are so many different

6:04notices that we're getting pres almost

6:06on a daily basis about certain kinds of

6:09data breaches it's available in so many

6:11different areas as you said I do think

6:14though especially relating to kind of

6:16the cultural shift that I had mentioned

6:18earlier as it relates to employers and

6:21their need to be aware of these

6:23different laws I do think that there

6:25there is a need uh for there to be a

6:27real awareness and an education exercise

6:30within the employment context and for

6:32individuals uh as I said earlier I think

6:34the Europeans in general have been much

6:37more sensitive to this and much more

6:39aware of this and and focused on their

6:42their personal information and being

6:44more protective of releasing that

6:45information and I think in the US in

6:48particular uh there really needs to be a

6:50little bit more protection and a little

6:52bit more for thought into the kinds of

6:55information that we're generally and

6:57have historically just made available

6:59really without asking why why do you

7:01need this information yeah I mean every

7:03time I go into my doctor's office they

7:06still hand me a um a sheath of forms to

7:11fill out yet again right and they always

7:13want my social security number there is

7:15no reason for them to know my social

7:16secur number they got my insurance card

7:18they've got all that and they're

7:19collecting that and then you can see you

7:21know just a whole wall of manila folders

7:24back there behind them that aren't

7:25locked up and uh you know you know every

7:27one of those has that social security

7:28number so that you know that's a data

7:31breach waiting to happen and you're

7:33right Europe is you know we we do work

7:35in Europe for for some of our clients

7:37and and the data transfer laws in Europe

7:39are really pretty strict and and the

7:41kind of access you have in to is pretty

7:45pretty challenging and so a lot of these

7:47laws though then are really a lot

7:50about making the consumers feel better

7:53even if maybe their their data is out

7:55there I don't want to give it have yet

7:57another breach I don't want you know I

7:58don't want uh or or you know I don't

8:02want people just Willy nearly sharing my

8:04information all over there's a I think

8:06we do

8:08have the sense that we've lost a certain

8:10amount of privacy I mean you know the

8:12the saying in the early odds was you

8:14know privacy is dead and uh and I think

8:18to a certain extent that's probably true

8:19for most people but we've killed it

8:21ourselves we put all our stuff out there

8:23and uh and made it available but when

8:25we're talking about these privacy laws

8:27these regulations

8:29they're they kind of categorize people

8:32in three different buckets right data

8:33controllers data processors and then

8:36these consumers talk about what each of

8:38those roles are who those people are and

8:42and you know what does it mean to be a

8:43controller versus a processor those kind

8:45of issues sure and it's a good way to

8:48think about it in terms of kind of the

8:50the the purpose for which these laws are

8:52are set up so when you think about it

8:54and I'm going to I'm going to describe

8:55it sort of from the context of a of an

8:57employment situation so so let's say

9:00you're a company and and you have uh

9:03those three different roles that we

9:04talked about so from a processing side

9:07it might be anyone for instance in an HR

9:10role um or a third party even that's

9:13supporting an organization in terms of

9:17employee counts employee reports the

9:19kinds of information that an

9:21organization might have with respect to

9:23applicants with respect to their

9:25employees uh performance related reviews

9:27so that's kind of the data we're talking

9:29about really for the purpose of managing

9:31the business so the processing is really

9:34those individuals that are that are

9:36tasked with helping to manage the

9:39information share the information

9:41potentially make uh reports of that

9:44information and that context the

9:47controller uh would really be the

9:49organization itself and those that are

9:51in a decision making uh Authority or or

9:54position I should say to decide how

9:57we're going to use that information as

9:58an organization how are we going to uh

10:01make use of that information with

10:03respect to managing benefits with

10:05respect to payroll with respect to

10:07whatever fill-in-the blank purpose there

10:09might be it's those controllers that are

10:11making that decision and typically an

10:14organization or the company in this

10:16particular context will be thought of as

10:18the controller and you mentioned

10:19onethird term Mike remind me and I

10:21consumers yeah justers absolutely yeah

10:24consumers first and foremost I think

10:26that's really where these laws have or

10:29inated from and it's the primary focus

10:31is consumers who are turning over their

10:33information for the purpose of receiving

10:36Services receiving Goods whatever it

10:38might be uh credit card companies Etc

10:41consumers are really have have primarily

10:44been the focus of these us laws and the

10:47European laws historically but that's

10:50shifting a little bit even to the uh to

10:52the non-consumer and to individuals who

10:54are you know mainly they're providing

10:56their information perhaps just for the

10:58purpose of getting a job or applying for

11:00a job and so like so a data controller

11:05would be like an employer who wants

11:09to aggregate all their applicant data

11:12into a database for statistical purposes

11:14and they decide we're going to do this

11:16we're going to pull all the applicants

11:17in and come up with some you know things

11:20about you know General maybe we're going

11:21to feed our AI feed it into RI to tra

11:24train our employee selection process and

11:27so here's all our employee information

11:28here's what the pool looks like and

11:30we're going to use it to train the AI

11:32That's the company making that decision

11:34but then that processor if they if they

11:36had an HS system that made that

11:39available the processor would be the HRS

11:41system is that

11:44or yes I think the individuals maybe

11:47that are working within that data data

11:49data entry or or exporting reports or

11:52whatever it might be um would generally

11:54be considered your processor but I think

11:56the hris system or Andor those that

11:59manage that system would be the best um

12:02example of a processor from the the

12:05employer

12:06perspective so when we talk about gdpr

12:10then in the EU the general data

12:12protection regulation what does it say

12:15how does it control uh how that

12:17information gets used well I think one

12:20thing to think about in terms of the

12:21gdpr because it's really followed

12:23through with some of these us laws gdpr

12:25is really based on seven foundational

12:27principles it's sort of the purpose for

12:30which this law that law was put in place

12:32and and the US laws have followed

12:35there's a principle of limiting the

12:37purposes for which a particular

12:40organization might be using information

12:42or use it for the The Limited purpose

12:45for which you need it in a similar vein

12:47there's data minimization which is only

12:50use that data that you absolutely

12:52positively need not throwing everything

12:54in the kitchen sink into that data

12:56repository there are the principles of

12:59accountability you know who ultimately

13:01is accountable for managing this data

13:03securing the data and then on a similar

13:06vein confidentiality and security that's

13:08one of the principles as well as storage

13:10limitation figuring out how an

13:12organization is going to dispose of that

13:14data once it's it's brought into the

13:15fold how an or how an individual can be

13:18sure that that data is accurate so

13:20accuracy is another foundational

13:22principle and then finally it's the

13:24lawfulness piece is are you using this

13:27data for the purpose uh that's for for a

13:29purpose that is lawful and for which

13:31I've provided it to you to use and in

13:35the employment

13:37context that would be in order to be

13:40evaluated as an employee to be hired to

13:42be managed as an employee what would

13:45some uses that an employer might not

13:48think of that might fall outside that

13:50they may you know have thought they

13:52could use information for that might

13:53fall outside of that narrow you know

13:57scope sure so I think you know probably

14:00that consumer example is a good example

14:02a lot of individuals when they're

14:05applying for a job when they're knowing

14:07that their organization is going to need

14:08to have their information for purposes

14:10of managing payroll benefits etc those

14:12those those obvious purposes but let's

14:15say an employer decides that they're

14:17going to they're going to have a

14:18collaborative partnership with some kind

14:19of a third-party insurance provider um

14:22that wants to make available uh a

14:25certain tool or resource to that

14:28employee

14:29population that's really not within the

14:32the primary business practice or

14:35relationship of the employer in that in

14:37that third party uh it's an add-on if

14:39you will that can kind of get into that

14:41category really of of something that was

14:43turned over by an individual for the

14:46purpose of HR management only that then

14:49moved over into a little bit more of a

14:51consumer practice if their employer

14:53makes that decision to uh make their the

14:56employee roster available to third part

14:59parties outside of the context that that

15:02primary relationship is based upon and

15:04so what are the so that's Europe

15:09and except to the extent that a us well

15:12let me ask let's say we' got a us uh an

15:15EU citizen who's here on a Visa and is

15:17working in the US does gdpr have any

15:21impact on employers who are us-based for

15:24an employee who's currently us-based I I

15:27would say yes now admittedly my my

15:29Approach has always been pretty

15:30conservative when you think about the

15:32the global operations of an organization

15:35and so I I would think about it more

15:37from the standpoint of where are where

15:39are you operating from a Global

15:41Perspective not necessarily well we only

15:44have individuals based in the US and

15:47therefore we probably don't need to

15:48think about gdpr if you are operating

15:51and you have a business um that extends

15:54outside of the US even if your employees

15:56are are sitting only in the US I think

15:59you absolutely need to be familiar with

16:01gdpr and you need to make sure that

16:04you're following the different protocols

16:05because of of how you're operating on a

16:08global basis including within the EU or

16:10the UK and you talked about the Seven

16:12Pillars of like the gdpr's data privacy

16:16framework as far as the at the federal

16:19level in the US what rules do we have in

16:22place right

16:23now uh I mean I mentioned Hippa and glba

16:27and dppa the Fair Credit Reporting Act

16:30uh when those are all all about you know

16:32protecting people's personal data are

16:34there other laws at the federal level or

16:37are we mostly dealing with it this more

16:39at a state level in the US well of

16:41course as you mentioned there's the

16:43industry or sector specific laws that

16:45we're all pretty familiar with with

16:47HIPPA the FC the Graham Graham leech

16:50biley act there's the Federal Trade

16:52Commission that by and large has being

16:54the federal enforcement body as it

16:56relates to data privacy um on things

16:59like children's information

17:02telemarketing rules Etc as you've moved

17:05over the years more and more states have

17:07adopted what I would describe as

17:10probably focused laws um initially for

17:13instance like in Illinois and Texas as

17:15an example you you have biometric

17:17Privacy Act laws uh a lot of people

17:19weren't familiar with the Texas law

17:21until there was a very recent large

17:23enforcement uh action um by the Texas

17:26Attorney General and that particular

17:29biometric identifier act from Texas goes

17:32back to 2009 uh so that was an early

17:35adopter I guess Texas could be seen to

17:37be an early adopter in that capacity so

17:40it's really kind of spanned and and made

17:41a transition from industry sector

17:44specific laws of the kinds that we were

17:47mentioning uh now into more State

17:49specific laws that are drilling down in

17:51into a little bit more detail on how

17:54organizations are are using information

17:56either biometric data or that that pii

17:59and sensitive data that we talked about

18:02earlier and let's take a quick break

18:05good morning HR is brought to you by

18:07imperative bulletproof background checks

18:09with fast and friendly service 25 years

18:12ago I found it imperative to help risk

18:15averse clients make well-informed

18:16decisions about the people they involve

18:18in their business because we don't cut

18:21Corners our research is more thorough

18:23and our reporting more robust our

18:26clients make better hiring decisions

18:29however employers often don't know what

18:31to ask Beyond price when evaluating a

18:34background screening partner so we've

18:36compiled a short list of six questions

18:38that you should ask any prospective

18:40screening partner including imperative

18:42to ensure that you understand what

18:44they're really trying to sell you these

18:47questions identify the most common ways

18:48background check companies cut Corners

18:51that impact the quality accuracy and

18:53depth of the information they provide

18:56employers you can review the six

18:58questions you should ask of your

18:59background check partner at imperative

19:03info.com

19:05sl6 and of course you can always reach

19:07out to imperative to discuss your

19:09background check process through our

19:11website at imperative

19:14info.com if you're an hrci or sh

19:17certified professional this episode of

19:19good morning HR has been pre-approved

19:21for 1 half hour of recertification

19:23credit to obtain the recertification

19:26information visit good morning HR

19:29and click on Research credits then

19:31select episode

19:33178 and enter the keyword data that's da

19:38ta and now back to my conversation with

19:41Jason

19:43Barrett talk about the Texas biometric

19:45law what does it what does it entail and

19:48and how how does it really affect

19:50employers yeah so it really kind of goes

19:52to making sure that organizations or

19:55anybody that's collecting biometric data

19:57could be face ID type information could

19:59be uh fingerprints Etc things of that

20:01nature it goes in and it regulates how

20:05um uh organizations are using that and

20:07the kinds of information that needs to

20:08be provided to those individuals before

20:12you collect it that particular case was

20:15pretty interesting that came down it's

20:17actually had gone back quite a few years

20:20but it was a$ 1.4 billion settlement

20:23that the Texas Attorney General entered

20:25into with meta uh that goes back quite a

20:28few years and then there's another

20:29lawsuit that's pending under the similar

20:32law the same law I should say uh with

20:34Google right now and that probably

20:36surprises people what how is meta how

20:38are meta and Google collecting my

20:40biometric information right so that's

20:43that's the thing is I think they were

20:44they had not been transparent with how

20:46they're doing that and and that was one

20:47of the the findings as I understand it

20:50in the in the in the law and in the

20:51penalty and so much about these laws is

20:54about transparency if you're going to

20:55collect this particular kind of data you

20:57need to let people know you need to tell

20:59them how you're collecting it why you're

21:01collecting it and and the and the use of

21:03that data and that's so they were just

21:06what were they they were just collecting

21:09what my face looks like and is that is

21:12that primarily what the biometric

21:14information was or yeah I think in that

21:17particular case I would need to go back

21:19and look at all the the Dig beneath the

21:20surface on all the the details of that

21:22one but but it was kind of a land

21:25Landmark type ruling uh that relates to

21:28information that they were really

21:30collecting without notifying people and

21:32so now they're probably notifying us and

21:33we're click click click click yes yes

21:35yes accept except except and moving

21:37right past it anyway but at least now

21:39they're telling us right interesting so

21:43you know Texas and California at are

21:45opposite ends of the political Spectrum

21:47pretty much but I mean certainly in the

21:51last legislative session Texas had some

21:53privacy bills and I we know the session

21:56starts again in January

21:58and I know the State Chamber of Commerce

22:01the Texas Association of business has

22:03been working for the last two years with

22:05representative krig On's uh office and

22:09other legislators around their you know

22:13Privacy Law part two from you know

22:15following up from last session and then

22:17California obviously has had a lot of

22:19issues uh on on the Privacy front

22:22too what are typical you know state

22:26level privacy things that you see are

22:29kind of Cutting Edge between Cal you

22:31know California Texas Florida whoever

22:33else is having those what do you think

22:34we're going to be dealing with in the

22:36next few

22:38years well I think the Texas Attorney

22:40General for one is kind of signaled with

22:43that particular finding that we just

22:44talked about that they're going to be

22:45aggressive and there was a recent

22:47conference where they they all bet said

22:49you know get ready we're going to be

22:50looking to enforce these particular laws

22:53including the Texas data privacy and

22:54secret secrecy act uh there's also the

22:58Texas data broker act that went into

22:59place more recently and that's more

23:01focused on consumers as we were talking

23:03about earlier um and organizations that

23:07collect information really for the sole

23:09purpose of monetizing that particular

23:12that that set of information but I think

23:15probably the the primary focus area is

23:17going to be what kind of notifications

23:19what kind of communications and

23:21transparency are organizations that

23:24collect this information providing to

23:26consumers or to the indiv idual or the

23:29data subjects that they're collecting

23:31it's going to be really key that uh

23:33those notifications are made there's

23:35privacy policies that are communicated

23:37that individuals are given the

23:39opportunity to to opt in as it relates

23:42to the collection of that information

23:44especially on the on the consumer side U

23:46but I think it's going to be primarily a

23:49focus on communication transparency and

23:52notification as it relates to any

23:55individual whether they employee or a

23:57consumer turning over that

24:00information and I think the Texas data

24:03Private Security Act exempts if and

24:07correct me if I'm wrong I'm thinking

24:09that from the you know remembering the

24:10conversations during session is that it

24:12exempts

24:14information that's gathered and

24:17used by for employment by employers is

24:21is is that right or there is an

24:23exemption if it's if it's truly just

24:25used for for processing for employment

24:28compensation Etc California had a

24:31similar exemption but that that was

24:33sunset uh with the with the the newer

24:35law that went into place which was kind

24:37of took Folks by surprise there are

24:39other exemptions under Texas law

24:41including or organizations that are

24:43nonprofit small businesses as an example

24:47as defined into the small business act

24:49as well as other organizations that

24:53might already be regulated under laws

24:55like Hippa uh or some of the banking and

24:57consumer law laws and so with the idea

25:01being pretty straightforward that you

25:02don't want to duplicate or overreach in

25:05terms of organizations that are already

25:07covered by some of those other laws um

25:10but so there are exemptions in in those

25:12particular cases but that doesn't mean

25:16that an employer who has employee you

25:18know applicant information or employee

25:19information can just go sell that

25:21information that pii or that sensitive

25:23data about their employees to a third

25:25party for marketing purposes or whatever

25:27else right that's correct yeah I think

25:29that's still going to potentially be

25:31something that might be covered under

25:32the Texas data broker act if you're

25:34moving into territory that was

25:37previously really just collecting for

25:39the purposes of HR Administration and

25:42then you're moving it into a little bit

25:43more of a uh Monet monetization exercise

25:47uh that's going to be a a pretty

25:49high-risk scenario in in especially with

25:51these new

25:52laws so if we're dealing with let's say

25:56we're a Texas based company we're

25:58dealing with a consumer who lives in

26:00Iowa which state's data privacy laws

26:03apply in those circumstances if you got

26:06two states with different or California

26:08and Texas for that matter two states

26:09with different laws how do how does an

26:11employer know when you know which laws

26:15apply is it you know if if I'm if I'm

26:17considering it let's start with the

26:18applicant who lives in in California is

26:21moving to Texas for the job if they get

26:23the job does California's Privacy Law

26:26apply to them because there resident in

26:29California or just Texas I would take

26:32the approach uh of both really need to

26:35look at out of an abundance of caution

26:36both because there are so many different

26:39things that are the same about these

26:40laws but there's also some overlapping

26:42uh implications as well and the other

26:45thing certainly if you look at it from

26:48the perspective of where an applicant or

26:49an employee is based yes that's one

26:52differenti differentiating factor but

26:55you also have to look at where the

26:56organization has operations if you have

26:58an organization that you know might have

27:00employees in six seven eight different

27:02states but operations in 47 or 48

27:05different states you know you really

27:07have to look at how those particular

27:10States interact with each other in terms

27:12of data privacy laws and other other

27:14aspects that might regulate that

27:16particular data privacy matter so you're

27:19looking kind of at the to be safe the

27:22lowest common denominator or the most

27:24strict rules and just applying that

27:27absolutely and that's kind of you know

27:29the approach that I've taken in in my my

27:30history with different organizations

27:32that I've worked for is we' recognized

27:34that okay well wow we operate in these

27:36however many different countries where

27:38do we start Where Do We Begin how do we

27:40look at this from a from a um compliance

27:44standpoint and what we ended up doing

27:46was kind of to your point we looked at

27:48what's the most U prescriptive uh what's

27:52the most overarching and and broadest

27:56regulatory regime that we might be

27:58operating in and if we can comply with

28:01those particular laws and regulations

28:03that we feel comfortable that we're

28:04going to be in a much better position

28:08globally so if I'm an HR leader or just

28:12a a the you know the business who has

28:15these employees I probably have

28:18information in a bunch of different

28:20silos right I've got applicant tracking

28:22information then I've got you know

28:24employee information in my HRS maybe

28:26I've got a separate payroll provider

28:27who's got employee information maybe you

28:31know my benefits are you know I have a

28:32you know I've got a system uh for

28:35managing our health insurance that may

28:37be my broker

28:38provides

28:40how keeping track of what data is where

28:44and and how we're categorizing it are

28:48there best practices to kind of get your

28:51arms around where the data is and making

28:54sure that you've got some accountability

28:57for it

28:58absolutely and one thing that I would

29:01recommend is that whomever is going to

29:04be responsible for your data privacy

29:06your data protection in your

29:08organization really takes a deep dive

29:11into understanding really it's the who

29:14what when where why and how of data

29:16within the organization and and in terms

29:19of the where as you were mentioning

29:20earlier there could be many

29:23different applications many different

29:26storage facilities Etc

29:28where this data is housed and so

29:31probably early on if an organization

29:34hasn't started to do this and especially

29:36if they're growing by acquisition You'

29:38got multiple uh other thirdparty

29:40companies that are now becoming part of

29:42your organization that might have

29:43different systems might have different

29:44individuals that have been responsible

29:46for this I would say start there is

29:49really try to come up with the the data

29:51mapping as best you can for what data

29:54you hold why you hold it and who has

29:58responsibility for it and then certainly

30:00to your point you have to know where

30:02it's stored uh for purposes of putting

30:04the best data privacy regulations in

30:08place because of the data providers we

30:11work with on the background

30:13investigation side of our business the

30:15you know one of the things that we see a

30:17lot is that certain data we keep data in

30:20certain different states uh you know

30:22that we've got data that's active then

30:24we've got data that is for all you know

30:27t purposes will probably not ever need

30:29to access we've never needed to access

30:31before but we keep it for up to seven

30:33years for litigation purposes and that's

30:35you know in an archive State and then at

30:38some point after that depending on what

30:39the data is we may delete it all

30:41together and not record it do the laws

30:43address that or is are those just kind

30:45of standard practices or best practices

30:47for for deciding what information to

30:50keep on hand and where to keep it well

30:52the the laws address that in I guess two

30:55ways one is

30:58putting requirements out there that

31:00share and provide notice to individuals

31:03or data subjects on why the information

31:05is being collected and then the second

31:08kind of goes back to one of those

31:09foundational princip principles that I

31:11mentioned earlier with the gdpr that's

31:13followed through with these us laws and

31:15that's the principle of data

31:17minimization only maintain that amount

31:20of data the question that some of these

31:22regulatory authorities will ask is are

31:25you only maintaining the data that you

31:27absolutely need

31:28not the nice to have data but also you

31:31know the have to have you know primarily

31:33looking at that from a data minimization

31:35perspective so you might have

31:38information that to your point that's

31:39spread out all over different states

31:41perhaps all over different

31:43applications but there's really need to

31:46do a deeper dive and Analysis of the

31:49data minimization piece and you know who

31:52has access to that

31:53information one of the things I know

31:56gdpr gives consumer or individuals is

31:59the right to in some cases the right to

32:01be forgotten and in other cases just the

32:04right to have access to know what what's

32:08being stored do we have any of those

32:10kind of Rights uh in the US yes yeah

32:14similar rights have transferred over

32:16into these us laws there's the rights to

32:19some of which you mentioned the rights

32:21to access if I'm an individual how do I

32:23access my information where are you

32:25holding it how do I correct it um do I

32:28take it with me you know if I'm leaving

32:29the organization I want to make sure

32:31that it's it's coming with me and that

32:33there's there's not an unnecessary need

32:36for the information to be retained for

32:38too long of a period of time there's

32:40also these rights of of of notification

32:43of how the information can be

32:45deleted and um who has access to the

32:48information so these notific

32:49notification rights have really

32:51transferred over into the US data

32:54privacy laws as well and from an

32:56employer point of view I mean the answer

32:59except with the exception of a few

33:00States when an employee wants a copy of

33:02their employee file the answer has

33:03always been that's employer's property

33:06no you can't have a copy of your you

33:07know especially a departing employeer um

33:11has that changed under any of these laws

33:14to some extent I would say that

33:16generally speaking that an employer can

33:18still say look that's our employee file

33:20yes it's your information but that's

33:22information and that's a file that we

33:24need for purposes of processing

33:26employment including someone who's

33:29leaving the organization now where

33:31things may may have changed a little bit

33:33is there can be a a data access request

33:36under most of these laws where someone

33:38can come forward whether they're moving

33:41on or whether they're still with the

33:42company they can make a a data access

33:45request to say to their employer look I

33:47want to see what information you have on

33:49me and there's nothing that that says

33:51that an employer can't say fine come

33:53into this office have a look at the

33:56information it doesn't necessarily mean

33:58you have to you know make a copy of all

34:00of their files and and and provide it

34:02over to them if you're concerned in that

34:05respect I do think the companies need to

34:07be more aware of those kinds of

34:10protections under the US data privacy

34:12laws because it's a little bit of of a

34:14new scenario typically in the US that

34:16would really only come up in the context

34:19of litigation where someone might be

34:20suing the company it's a third party

34:22subpoena that comes in through through

34:24an attorney but in this case with these

34:26laws it can be the individual themselves

34:28him or herself making that request for

34:31information and it's important to make

34:33sure that organizations know who's going

34:36to be the point of contact and what are

34:38the different dos and don'ts as it

34:40relates to those requests and right now

34:42that would be a state byst state basis

34:44right figuring out what the the

34:46applicable laws wherever you are so if

34:48you're in Texas you have to look at

34:50Texas uh data Privacy Act versus

34:53California's multiple Acts or Virginia

34:55or wherever you are try to figure that

34:57out uh as an employer which is you know

35:00Pro the problem with uh you know a

35:03federal system where we got 50 states

35:05regulating issues uh it's harder for

35:07employers who are operating in multiple

35:08states to know exactly what they need to

35:10do that's right but I I brought up AI

35:14earlier and let's end with this because

35:16it's you know we can't talk about

35:18anything today without bringing up AI so

35:21what do you think the impact of AI is

35:24going to be uh on data privacy see um do

35:29we you know you know we want all this

35:31data to train these large language

35:32models and all of that but obviously

35:35nobody wants their data TR they want to

35:37use the tools but they don't want their

35:38data in their training the tools so

35:41where do you think that's going what are

35:42you seeing on the AI front I I know

35:45California's had a lot of concerns but

35:47Governor Nome vetoed their AI bill this

35:50week so what do you think is going to

35:52happen with

35:53AI well I think to your point AI is most

35:57definitely here to stay so it's a matter

35:59of of you know how do we how do we

36:01manage that somewhat like we were

36:04talking about in terms of the gdpr

36:06making its way to the US I think the EU

36:09and the UK right now are kind of at the

36:10Forefront as it relates to putting

36:12regulations in place for AI there are

36:15some laws that have been passed over

36:17there and I'd say some best practices

36:20the states have not yet made to your

36:22point you know California again kind of

36:24being the pioneer as it related to the

36:27GD PR moving over into their state law I

36:30would expect you know they'd probably be

36:31leading the way in many respects as in

36:34terms of the laws for AI over in the US

36:38I think that there are so many states

36:40considering that right now and things

36:43being considered at the federal level as

36:45well I think companies realistically we

36:48know that they're going to want to

36:49continue to leverage AI I think it's

36:52just a matter of keeping those same

36:54foundational principles that we talked

36:56about earlier at the Forefront of your

36:59mind in terms of making sure that you

37:01again you're maintaining it for the

37:03right purposes that you're allowing

37:05employees to know what is being

37:08collected and that you're being very

37:10transparent with your your employees and

37:12then on the consumer side with consumers

37:15about the kinds of information and the

37:17purposes for which it's being collected

37:19and

37:20managed well great well that's that's

37:22all the time we have thanks for joining

37:23me Jason thank you for having me I

37:25really appreciate it and and thank you

37:28for listening you can comment on this

37:30episode or search our previous episodes

37:32at good morning hr.com or on Facebook

37:35Instagram or YouTube and don't forget to

37:38follow us wherever you get your podcast

37:40Rob Upchurch is our technical producer

37:43and you can reach him at robm makp

37:45pods.com and thank you to imperatives

37:48marketing coordinator Maryann Hernandez

37:51who keeps the trains running on time and

37:53I'm Mike coffee as always don't hesitate

37:56to reach out if I can be of service to

37:58you personally or professionally I'll

38:00see you next week and until then be well

38:04do good and keep your chin up

38:08[Music]

More from ImperativeInfo

Recently added transcripts

Browse the whole transcript library

This transcript was generated from the captions YouTube publishes for this video. Get the transcript of any YouTube video atfreeyoutubetranscribe.com, free, unlimited, no sign-up.