How the European Court of Human Rights verdict on privacy of employees impacts India

How the European Court of Human Rights verdict on privacy of employees impacts India

The European Court of Human Rights

Story highlights

Emerging markets like India that are determining the contours of their right to privacy and data protection cannot afford to adopt a notion of privacy that denies innovation and curtails other rights.

In a manner that has become emblematic of the privacy discourse in Europe, the European Court of Human Rights, today ruled in favor of denying employers access to their employees’ communications. The judgment further drives home the point of the differential treatment of privacy by various jurisdictions and notably, how the expectation of privacy varies significantly.

Article 8 provides for the right to respect for private and family life, the home and correspondence.

The case before the Grand Chamber of 17 judges first arose in 2007 and involved the termination of a Romanian national Bogdan Mihai Barbulescu by his then employer. Barbulescu was dismissed by his employer for using is Yahoo! Messenger account for his personal communications. Finding that the employer had not given prior notice to Barbulescu that his communications would be monitored and that the extent of monitoring was too intrusive, the Court held that his dismissal violated Article 8 of the European Convention on Human Rights. Article 8 provides for the right to respect for private and family life, the home and correspondence.

In its ruling, the Court balanced the need to protect the right to privacy of an individual against a company’s imperative to ensure that its IT systems are not damaged or used for illegal activities. The judgment, however, in dismissing the latter as hypothetical harms appears to have inadequately applied its judicial mind to the issue. Much of the contours of the right to privacy along with the reasonable restrictions therein are decided on hypothetical harms. In part, this is because of the nature of technology and the impossibility of predicting the ways in which intrusive technology can evolve.Violations of the right to privacy are often not as easy to detect and remedy as other rights – illustrated by the NSA’s unauthorised snooping that was brought to the light bySnowden.

In a world where the Internet is ubiquitous and, vast amounts of personal activity is conducted online, denying access to personal information is no longer an option for most.

The answer to this, however, does not lie in an evangelical conception of privacy where the only way of safeguarding rights is by denying access to information. In a world where the Internet is ubiquitous and, vast amounts of personal activity is conducted online, denying access to personal information is no longer an option for most. As Prof. Helen Nissenbaum, of the New York University, argues, privacy strengthening frameworks should focus on the manner in which information is used rather than controlling the flow of information or denying access to information.

Frameworks that advocate for securing information in a manner that renders it inaccessible, can not only stifle data-dependent innovation but also strike an unfair balancing act between the right to privacy and it’s interaction with other rights. Take, for instance, an absolutist understanding of privacy that denies the state any interference with one’s private/marital life. This can have the effect of enabling domestic violence and systemic abuse.

This is a central contribution when it comes to informational privacy. Due to the transient nature of the medium, often real time monitoring of communication is the only means of identifying foul play. This monitoring should necessarily be authorised by law and in keeping with the principles of necessity and proportionality, however, denying access to information altogether should not be the only recourse.

Monitoring should necessarily be authorised by law and in keeping with the principles of necessity and proportionality, however, denying access to information altogether should not be the only recourse.

In its judgement, the Court considered whether the stated objectives of the employer – ensuing safety of its IT systems and preventing illegal activity – could have been achieved through less intrusive means. The court found that the company had not employed means that were less intrusive and had thus run afoul of Article 8. This may not hold true in all cases.

Sensitive crimes such as transfer of trade secrets, unauthorised access to company servers etc. which are commonplace, can often only be detected by logging keystrokes or real time monitoring of employees’ activities.

The ways in which the judgement will affect the evolution of privacy in Europe remains to be seen, however, the rest of the world has much to learn from this understanding of the right. Emerging markets like India that are determining the contours of their right to privacy and data protection cannot afford to adopt a notion of privacy that denies innovation and curtails other rights.