sb-as logo
Story image

The murky world of Australia & Singapore's workforce monitoring laws

16 Feb 2018

Australia is one of the least complex countries in the world for workforce monitoring - second only to the United States, says a Forcepoint-sponsored study by legal firm Hogan Lovells.

The study examines the fine balance between the need for IP and data protection with employees’ privacy and legal rights, particularly when applied to regulations such as the GDPR.

Forcepoint claims this is the first published review of the international legal landscape that looks specifically at cyber-focused workforce threat program implementation.

The report ranks 14 countries including Australia and Singapore for 10 different monitoring activities.

Those activities include monitoring internet browsing, keylogging, social media monitoring, monitoring employee-owned devices and higher-level IT activities including monitoring temporal metadata (eg logons and session length) and monitoring privileged access use.

Workforce monitoring activities are also governed by a variety of data protection, data privacy, communications secrecy, and employment laws.

“Numerous recent events have shown how cyber incidents can disrupt operations, damage reputation, and expose organisations to regulatory consequences and private litigation,” comments Hogan Lovells partner Harriet Pearson.

Australian organisations need express consent for monitoring social media and employee-owned devices, however does not need higher levels of consent besides required notice for monitoring other areas.

The report mentions that some Australian states such as New South Wales and Victoria have regulations that require employees must obtain express consent to monitor employee activities on non-company devices when the employee is not working or at the workplace.

However, “The Privacy Act generally supports the use and disclosure of information collected via monitoring activities when an employer has reason to suspect that an employee has engaged in unlawful activities or otherwise serious misconduct,” the report says.

In contrast, Singapore put significant levels of effort into capturing on-screen activities, keylogging, monitoring social media and employee-owned devices.

“Employers need not obtain consent for monitoring activities that reasonably support the management or termination of employment relationships, including activities that are necessary to evaluate the suitability, eligibility, or qualifications of an employee for promotion or continued employment or for evaluation purposes,” the report says.

Both countries are described as requiring a ‘basic’ level of compliance to implement comprehensive workforce monitoring, however other countries such as Finland and Italy require far more effort and compliance.

Finland, for example requires significant levels of effort in most categories, however temporal metadata and privileged access monitoring are less complex. Employers are often prohibited from accessing communications contents sent or received by employees.

In the United States, federal law provides that organisations are exempt from liability to the extent that they monitor their information systems for cybersecurity purposes.

“Any workforce monitoring program must be proportionate, respectful and transparently deployed to ensure the continued trust of the workforce,” comments Forcepoint CISO Allan Alford.

Forcepoint believes that traditional tools are failing to provide human risk information with context. As a result, behaviours where data, users and networks intersect, are growing in demand.

 “It’s a careful balancing act: employees and employers must work hand-in-hand to protect each other. We all want better protection for ourselves and our important information and data, but monitoring when, how and why employees interact with various corporate data has some clear and important privacy implications,” Alford concludes.

The Managing Workforce Cyber Risk in a Global Landscape analysed regulations in Australia, Singapore, the United States, Canada, Finland, France, Germany, Italy, the Netherlands, Spain, Sweden, Switzerland, the United Kingdom and Turkey.

Story image
WatchGuard uncovers top cyber threat trends of Q4 2020
“The rise in sophisticated, evasive threat tactics last quarter and throughout 2020 showcases how vital it is to implement layered, end-to-end security protections."More
Story image
Kroll completes Redscan acquisition, expands cyber risk portfolio
With the addition of Redscan and its extended detection and response (XDR) enabled security operations centre (SOC) platform, Kroll expands its Kroll Responder capabilities to support a wider array of cloud and on-premise telemetry sources.More
Story image
Gartner: Top security and risk management trends for 2021
“CISOs are keen to consolidate the number of security products and vendors they must deal with."More
Link image
Virtual demo: Diagnose network cabling problems with the LinkIQ Cable+Network Tester
If you’re finding it difficult to install access points and cabling, or if you can’t pinpoint an issue with a video camera or end user, the LinkIQ Cable+Network Tester could be exactly what you need. Try a free, fully interactive demo now.More
Story image
Why a more secure organisation is a collective responsibility
With vast volumes of data moving to the cloud, many IT professionals are frequently challenged to protect their enterprise environment, and there is a greater focus being placed on advancing cybersecurity strategies.More
Story image
Data transparency increasingly important, Kaspersky study states
“It is clear from the data that people have developed a sense of control and they are now demanding openness about how and where their data is being managed."More