opc: social media risks to enterprises

11
Understanding Social Media Privacy Risks to Enterprises Louisa Garib Legal Services, Policy and Parliamentary Affairs

Upload: lgarib

Post on 21-May-2015

167 views

Category:

Documents


0 download

DESCRIPTION

Also posted at: http://www.priv.gc.ca/speech/2009/sp-d_090430_lg_e.cfm

TRANSCRIPT

Page 1: OPC: Social Media Risks to Enterprises

Understanding Social Media Privacy Risks to EnterprisesLouisa GaribLegal Services, Policy and Parliamentary Affairs

Page 2: OPC: Social Media Risks to Enterprises

“Social Media is a conversation”• Online content generated by users

• Uses accessible technologies• Not organized• Not controlled• Many voices• Social dynamic• Mainstream – here to stay

It is a social dynamicIt is a social dynamic

Page 3: OPC: Social Media Risks to Enterprises

Blogs

Wikis

Podcasts

RSS

Mashups

Social Networks

Page 4: OPC: Social Media Risks to Enterprises

Features of Social Media that can give rise to Privacy Risks

• Users misunderstand privacy risks• Intimacy and immediacy– promotes

disclosures• Users underestimate scope of disclosures• Used for Work and for Fun – blurs line• Control once information is posted

Page 5: OPC: Social Media Risks to Enterprises

How serious are the Risks to Enterprises?

• Don’t know full extent of risk • Just beginning to understand technology,

use by people, impact on privacy• Rapidly changing• Beginning to construct appropriate rules of

engagement to understand and mitigate risks

Page 6: OPC: Social Media Risks to Enterprises

What are the Risks of SM?• Illegal/unauthorized/inappropriate disclosure

of personal or confidential information• The employment relationship – internal/discl.• Lack of policies, protocols, training, errors • Customer Relationship – external/collection• Malware, hacking - external/ breach

Consequences:• Liability under PIPEDA and other laws• Harm to corporate reputation

Page 7: OPC: Social Media Risks to Enterprises

PIPEDA and Social Media• Collection, use and disclosure of personal

information• Course of commercial activity• Employment relationship if FWUB• Notice, Consent, Reasonable purpose

• BUT – other private or confidential information and situations not caught by privacy legislation

• Still risks to enterprise – Best practices• PIPEDA minimum standard - guidance

Page 8: OPC: Social Media Risks to Enterprises

Disclosures by Employees using SM

• Personal or corporate SM • On or off duty – lines blurred• PI about other employees – examples• Unionized workplace – neg’n, elections• Human rights, harassment, defamation• Obscene materials, copyright • Clients / customers• Business partners• Confidential corporate information • Reputation and publicity

Page 9: OPC: Social Media Risks to Enterprises

Collection, Use and Disclosure of Personal Information using SM

• Recruitment and staffing• Monitoring• Investigations• Change day to day management of the

employment relationship • Customers – service delivery, managing

relationship, marketing information• Requests from law enforcement; litigation

Page 10: OPC: Social Media Risks to Enterprises

How to manage risks?

• Understand technology – aware of privacy implications for enterprise

• Aware of information flows – in and out• Express policy guidelines on SM and handling

PI; understandable; consequences of violation; disseminate widely - OPC Fact sheet

• Use allowed in the workplace? Will it reduce risks? Create other issues?

• Education – avoid privacy misunderstandings

Page 11: OPC: Social Media Risks to Enterprises