CIPP/US Workplace Privacy & Employee Monitoring 1 — Questions and Answers
Question 1: Under the Electronic Communications Privacy Act (ECPA), which exception most commonly allows employers to monitor employee email on company systems?
- The business extension exception (Correct answer)
- The law enforcement exception
- The prior consent exception
- The national security exception
Correct answer: The business extension exception
The business extension exception under ECPA permits employers to monitor communications over equipment provided in the ordinary course of business.
Question 2: An employer wants to conduct pre-employment background checks. Under the Fair Credit Reporting Act (FCRA), what must the employer provide to the applicant before taking adverse action based on the report?
- A pre-adverse action notice and a copy of the report (Correct answer)
- Only a final adverse action notice
- A written explanation without the report
- No notice is required for employment purposes
Correct answer: A pre-adverse action notice and a copy of the report
FCRA requires employers to provide a pre-adverse action notice, a copy of the consumer report, and a summary of consumer rights before taking adverse action.
Question 3: Which of the following best describes the general legal standard for employee privacy expectations in the workplace?
- Employees have a diminished expectation of privacy compared to the general public (Correct answer)
- Employees retain full Fourth Amendment protections in private workplaces
- Employers may never monitor employee communications without a court order
- Employees and employers share equal privacy rights in the workplace
Correct answer: Employees have a diminished expectation of privacy compared to the general public
Courts generally recognize that employees have a reduced expectation of privacy in the workplace, particularly when using employer-owned equipment and systems.
Question 4: A company implements keystroke logging software on all employee computers. What is the most important step the company should take to limit privacy risk?
- Provide clear notice to employees through an acceptable use policy (Correct answer)
- Obtain a court order before deploying the software
- Limit monitoring to only remote workers
- Encrypt all logged keystrokes and never review them
Correct answer: Provide clear notice to employees through an acceptable use policy
Providing clear notice through an acceptable use or monitoring policy reduces privacy risk and supports the business extension exception under ECPA.
Question 5: Under the ADA (Americans with Disabilities Act), when may an employer require a medical examination of a current employee?
- Only when it is job-related and consistent with business necessity (Correct answer)
- At any time as part of annual performance reviews
- Whenever the employer suspects drug or alcohol use
- Only after the employee has been employed for at least one year
Correct answer: Only when it is job-related and consistent with business necessity
The ADA allows medical examinations of current employees only if they are job-related and consistent with business necessity, protecting employee medical privacy.
Question 6: Which federal law primarily governs the privacy of employee polygraph testing in the private sector?
- The Employee Polygraph Protection Act (EPPA) (Correct answer)
- The Fair Labor Standards Act (FLSA)
- The National Labor Relations Act (NLRA)
- The Privacy Act of 1974
Correct answer: The Employee Polygraph Protection Act (EPPA)
The Employee Polygraph Protection Act (EPPA) generally prohibits most private employers from using polygraph tests for pre-employment screening or during employment.
Question 7: An employer in California wants to monitor employee social media accounts. Which California law most directly addresses this practice?
- California Labor Code Section 980, which prohibits employers from demanding access to personal social media accounts (Correct answer)
- The California Consumer Privacy Act (CCPA), which treats employee social media as personal data
- The California Confidentiality of Medical Information Act (CMIA)
- California's unfair business practices statute under Business & Professions Code Section 17200
Correct answer: California Labor Code Section 980, which prohibits employers from demanding access to personal social media accounts
California Labor Code Section 980 prohibits employers from requiring employees or applicants to disclose their personal social media usernames or passwords.
Under the Electronic Communications Privacy Act (ECPA), which exception most commonly allows employers to monitor employee email on company systems?