As Canada's federal and provincial health authorities address the novel coronavirus (COVID-19), various questions have arisen regarding the role that organizations should play in balancing the privacy of its employees, contractors, and guests against the overall safety of the workplace and the broader general public. In particular, organizations are determining:
While the COVID-19 response represents uncharted waters, the analytical framework to collect, use and disclose personal information remains the same—organizations seeking to adopt any COVID-19 screening should answer the following four questions:
An organization typically has an obligation to take reasonable steps to protect the health and safety of its employees, contractors and guests. In light of the current COVID-19 outbreak, it may be reasonable for an employer to adopt certain screening methods that are designed to assess the risk of any individual attending the workplace carrying COVID-19. Such methods may include: (i) taking an individual's temperature at the time they enter into the workplace; or (ii) a questionnaire asking, for example, if the individual or someone in their household has recently traveled outside of Canada, or is experiencing any COVID-19-related symptoms.
The type of information an employer gathers should be strictly limited to assessing whether an individual attending the workplace may be carrying COVID-19. Care should be taken to ensure that the personal information collected would be effective in meeting the organization’s need. To this end, an organization should consult with a recognized resource (e.g., a medical consultant) to design or verify any screening method to be adopted. As it does so, it should consider whether there are less invasive means of achieving the same ends (at comparable cost and with comparable benefits).
Canadian private sector privacy legislation generally permits an organization to collect, use and disclose personal information about an individual without consent in certain situations. In Alberta, for example, an organization is not required to obtain consent where the use or disclosure of information is necessary to respond to an emergency that threatens the life, health or security of an individual or the public.
But, care needs to be exercised as these exemptions are not uniform within each statute. For example, the aforementioned "life, health or security" exemption in Alberta applies to the use and disclosure of personal information—it does not apply to the collection thereof. It is also important to note that such exemptions are not uniform among each of these "substantially similar" privacy laws in Canada. For example, the federal privacy legislation differs from Alberta in that the "life, health or security" exemption does not expressly include the public.
As a result, it will be important for each organization to:
To the extent that an organization cannot rely on the aforementioned exemption to collect, use or disclose an individual's personal information, it will need to provide notice and, if required, obtain consent to do so.
A jointly issued Guidance from the Office of the Privacy Commissioner of Canada and the Offices of the Information and Privacy Commissioner of Alberta and British Columbia identified several principles underlying meaningful consent, including the need to provide an individual with information about:
The commissioners stressed that it is important for organizations to consider the appropriate form of consent to use (express, deemed or implied) for any collection, use or disclosure of personal information for which consent is required. When making this determination, organizations need to take into account the sensitivity of the information and the reasonable expectations of the individual. Both of these will depend upon context.
Given the potential limitation in the exemption discussed above, we recommend that appropriate notices be present at the point of any COVID-19 screening to ensure that notice is given, and where consent is required, consent is obtained from each individual by their participation in such screening.
The impact of COVID-19 could be very significant to organizations. If you have any questions regarding the information in this article, please contact a member of the Bennett Jones Privacy and Data Protection team. In addition, please visit our COVID-19 resource centre for other COVID-19-related materials.