HR Case Studies & Practical Application 4 — Questions and Answers
Question 1: A company implements a chatbot to handle routine HR inquiries. Employees begin sharing sensitive personal information with the chatbot, assuming it's confidential. What should HR have done proactively?
- Restricted the chatbot to non-sensitive topics only
- Published a clear disclosure on data handling and privacy before deployment (Correct answer)
- Monitored all chatbot conversations in real time
- Required manager approval before any employee uses the chatbot
Correct answer: Published a clear disclosure on data handling and privacy before deployment
Proactive privacy disclosure ensures employees understand how chatbot data is stored, processed, and accessed before they share sensitive information.
Question 2: A company's succession planning software identifies internal candidates for the VP of Engineering role based solely on tenure. Three strong external candidates are ignored by the tool. What is the likely problem?
- The company should only consider internal candidates for leadership roles
- The algorithm is not configured to incorporate performance and potential data (Correct answer)
- External candidates should apply through a separate system
- The software vendor should update its succession criteria
Correct answer: The algorithm is not configured to incorporate performance and potential data
Succession tools must be configured with multi-dimensional criteria including performance, potential, and skills — not just tenure.
Question 3: An HR software vendor proposes using employees' biometric clock-in data to train its AI model for other clients. What should HR do?
- Allow it if employees have already consented to biometric data collection
- Refuse unless explicit, separate consent for AI training is obtained from each employee (Correct answer)
- Allow it since the vendor owns the data once it is submitted
- Consult only senior leadership, not employees, before deciding
Correct answer: Refuse unless explicit, separate consent for AI training is obtained from each employee
Biometric data use for AI training is a separate purpose requiring distinct, informed consent beyond standard time-and-attendance consent.
Question 4: A company's onboarding software sends new hire paperwork to personal email addresses because corporate accounts aren't yet active. This practice continues for six months. What is the key risk?
- New hires may delay completing paperwork
- Sensitive documents transmitted via personal email may violate data security policies (Correct answer)
- Corporate email setup will be delayed further
- New hires will prefer personal email and resist switching to corporate accounts
Correct answer: Sensitive documents transmitted via personal email may violate data security policies
Sending tax forms, direct deposit, and I-9 data via personal email creates significant data security and compliance risks.
Question 5: A company's HR software calculates overtime pay using a 40-hour standard workweek for all states, but California law requires daily overtime calculations. What is the likely consequence?
- California employees will be overpaid, which is acceptable
- California employees will be underpaid, exposing the company to wage claims (Correct answer)
- Federal law preempts California's daily overtime requirement
- The software will automatically adjust once enough complaints are filed
Correct answer: California employees will be underpaid, exposing the company to wage claims
California's daily overtime rules require separate configuration; a standard weekly calculation will systematically underpay California employees.
Question 6: An employee relations case management system accidentally makes all open investigations visible to all HR users due to a permission misconfiguration. What is HR's FIRST action?
- Notify all employees whose cases were exposed
- Immediately restrict access and contain the breach before assessing exposure (Correct answer)
- Delete the open investigations to prevent further exposure
- Wait for IT to fix the permissions before taking any action
Correct answer: Immediately restrict access and contain the breach before assessing exposure
Containment is the first step in any data breach — access must be restricted immediately before assessing impact or notifying affected parties.
Question 7: A company purchases an HR analytics platform that benchmarks its workforce metrics against industry peers. The benchmark data shows the company's benefits costs are 30% above average. What should HR do with this finding?
- Immediately reduce benefits to match the industry average
- Analyze whether premium benefits contribute to lower turnover or higher performance before deciding (Correct answer)
- Present the finding to the CFO as justification for immediate cuts
- Ignore the benchmarks since every company's workforce is unique
Correct answer: Analyze whether premium benefits contribute to lower turnover or higher performance before deciding
Higher benefits costs may yield offsetting gains in retention and productivity — ROI analysis must precede any cost-reduction decision.
A company implements a chatbot to handle routine HR inquiries.
Employees begin sharing sensitive personal information with the chatbot, assuming it's confidential.
What should HR have done proactively?