Your responsibility for keeping certain personnel information private is not excused because you keep the information electronically. You must closely guard access to electronic files that contain sensitive information. You can be held liable for negligently failing to protect your system from unauthorized access. Consider hiring a security professional to examine your company’s computer network to determine if your network is vulnerable to an outside attacker. In some situations, you may need encryption technology. Encryption scrambles data to make the information unreadable to anybody who does not have the key to decrypt the data. But encryption technology can also allow the message sender to disguise the message’s origin. As a result, it can be impossible to discover which employee is, for example, sending sexually suggestive messages in violation of your company’s anti-harassment policy. Similarly, encryption technology can prevent you from accessing and monitoring email messages between employees.
California law requires all companies and state agencies that own or license computerized data that includes personal information to provide reasonable security for that information.1 Personal information is defined as a person’s first name or initial and last name combined with any of the following:
Personal information also includes a user name or email address in combination with a password or security question and answer that would allow access to an online account.
If a security breach involves any of this personal data, the company must notify all affected California residents of the breach. You must give notice by one of several approved methods and within specified time limits.
Businesses must also disclose breaches of encrypted personal information if the encrypted information was, or is reasonably believed to have been, breached and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person that could “render that personal information readable or useable.”3
The law also requires any person or business that becomes aware of a security breach to notify the data’s owner or licensee immediately. Allowances are made for delay in giving notice at the direction of a law enforcement agency.4
1. Civ. Code sec. 1798.82
2. Civ. Code sec. 1798.80
3. Lab. Code 1708.29(a)
4. Civ. Code secs. 1798.29, 1798.82