PLC Employee & Workplace Privacy 2 — Questions and Answers
Question 1: Biometric information collected from employees (such as fingerprints for timekeeping) is primarily regulated by:
- The ECPA at the federal level
- State biometric privacy laws such as Illinois BIPA (Correct answer)
- The ADA exclusively
- The Genetic Information Nondiscrimination Act (GINA)
Correct answer: State biometric privacy laws such as Illinois BIPA
Biometric data collection in the workplace is primarily regulated by state laws like Illinois' Biometric Information Privacy Act (BIPA), which requires written consent, a public retention policy, and limits on data sharing.
Question 2: Under the Genetic Information Nondiscrimination Act (GINA), employers are prohibited from:
- Requiring genetic testing as part of standard pre-employment physicals
- Using genetic information in hiring, firing, or compensation decisions (Correct answer)
- Offering voluntary wellness programs with health risk assessments
- Conducting mandatory workplace drug and alcohol testing
Correct answer: Using genetic information in hiring, firing, or compensation decisions
GINA prohibits employers from using genetic information in employment decisions and restricts the acquisition of genetic information about employees or their family members.
Question 3: When an employee returns from FMLA leave, their medical certification and related health information must be:
- Shared with the employee's direct supervisor to facilitate return-to-work planning
- Kept in a separate confidential medical file, apart from the general personnel file (Correct answer)
- Disclosed to HR and senior management but not line supervisors
- Retained in the general personnel file with role-based access controls
Correct answer: Kept in a separate confidential medical file, apart from the general personnel file
FMLA regulations, consistent with ADA requirements, mandate that employee medical information be maintained in separate confidential files distinct from general personnel records.
Question 4: Before disciplining an employee based on social media activity discovered through employer monitoring, the employer must first:
- Publish the findings in an internal compliance report
- Evaluate whether the activity constitutes protected concerted activity under the NLRA (Correct answer)
- Obtain a signed acknowledgment from the employee about the monitored activity
- Report the findings to the Department of Labor within 30 days
Correct answer: Evaluate whether the activity constitutes protected concerted activity under the NLRA
Employers must evaluate whether social media activity involves protected concerted activity under the NLRA before taking disciplinary action, as doing so otherwise could be an unfair labor practice.
Question 5: Under the FCRA's 'adverse action' process, when an employer intends to deny employment based on a background check report, the employer must first:
- Notify the applicant only after the final decision has been communicated
- Provide a pre-adverse action notice with a copy of the report and Summary of Consumer Rights (Correct answer)
- Obtain court approval before making the adverse employment decision
- Report the adverse decision to the relevant state labor department
Correct answer: Provide a pre-adverse action notice with a copy of the report and Summary of Consumer Rights
The FCRA requires a two-step adverse action process: a pre-adverse action notice with the consumer report and Summary of Rights, followed by a final adverse action notice after a reasonable waiting period.
Question 6: GPS tracking installed on an employee-owned personal vehicle used for work is:
- Always permissible once disclosed in a company vehicle policy
- Generally impermissible without the employee's explicit consent (Correct answer)
- Regulated exclusively by federal transportation law
- Unrestricted by privacy law during scheduled working hours
Correct answer: Generally impermissible without the employee's explicit consent
Tracking employee-owned vehicles raises significant privacy concerns, and most jurisdictions require explicit employee consent; employers have broader latitude with company-owned vehicles.
Question 7: Which privacy principle best describes the obligation to collect only the employee data strictly necessary for legitimate business purposes?
- Purpose limitation
- Data minimization (Correct answer)
- Storage limitation
- Accountability
Correct answer: Data minimization
The data minimization principle requires employers to collect only the personal data that is necessary for specified, legitimate business purposes, limiting unnecessary privacy intrusions.
Biometric information collected from employees (such as fingerprints for timekeeping) is primarily regulated by: