Security policy in a unionised workplace
A security policy that touches employees in a unionised workplace has to work under the collective agreement as well as against attackers. Consult early, involve labour relations, keep each control proportionate to a written business need, and tell people what you do. Rules built that way tend to survive a grievance. Rules imposed quietly tend not to.
Why security policy is a labour relations issue
Because in a unionised workplace, most security rules that touch employees are also workplace rules, and the collective agreement and arbitral case law decide whether they can be enforced. That covers more than it first appears: endpoint monitoring, email and web logging, acceptable use, rules for personal phones that hold work email, badge and camera records, and discipline for breaking any of them.
In BC this is common in the public sector, health authorities, school districts, and colleges and universities, where faculty and staff are often in different bargaining units with different agreements.
How arbitrators test a new workplace rule
When an employer introduces a rule without negotiating it, Canadian arbitrators have long applied the test from the KVP case. In short, the rule must not conflict with the collective agreement, must be reasonable, clear, brought to employees’ attention before it is enforced, and enforced consistently. Where the rule is to support discharge, employees must also have been told that breaking it could lead to discharge.
Intrusive measures get closer scrutiny. In Irving Pulp & Paper (2013), the Supreme Court of Canada upheld an arbitration decision that weighed the employer’s safety interest against employee privacy and found random alcohol testing unjustified without evidence of a real problem. Arbitrators have applied similar balancing to surveillance and monitoring. Grievances under the Labour Relations Code are where that reasonableness gets tested.
How to write security rules that hold up
- Write down the business need. “Detect credential theft on accounts with payroll access” is a need. “Monitor staff” is not.
- Pick the least intrusive control that meets it. Alerting on unusual sign-ins is easier to defend than recording screens.
- Bring in labour relations before drafting is finished. They know the agreement, past grievances and the local relationship.
- Consult the union early. Share the draft and the reason for it. Changes made now are cheaper than changes ordered later.
- Tell employees plainly. What is collected, who sees it, how long it is kept, and what it will and will not be used for.
- Separate security use from performance management. Data collected to detect intrusions and later used to count breaks is how trust and grievances are lost.
Which privacy law applies to employee monitoring in BC
The collective agreement is not the only constraint. Provincially regulated private-sector employers in BC handle employee personal information under PIPA; federally regulated employers such as banks and telecoms fall under PIPEDA. Public bodies, including public universities and colleges, work under FIPPA, and a new monitoring system there usually needs a privacy impact assessment first. See privacy impact assessments and when a BC public body needs a PIA, or the wider Canadian privacy law map.
Can you discipline staff for a security policy breach
Discipline follows the agreement’s just cause and progressive discipline terms, not the security team’s view of how serious a breach felt. A clicked phishing link is rarely misconduct. Deliberately sharing credentials after training and a warning may be.
Record the training each person completed, the rule they were shown, and that they were told a breach could lead to discipline. Without that record, an arbitrator has little reason to accept that the rule or its consequence was known.
Questions we are asked
Why does a union change how we write security policy?
Because in a unionised workplace, most security rules that touch employees are also workplace rules, and the collective agreement and arbitral case law decide whether they can be enforced.
Do we have to consult the union before a new security policy?
That depends on your collective agreement, and some agreements require notice or consultation. Where yours does not, consulting early is still usually the better choice. A rule the union saw before launch is less likely to be grieved, and if it is, the record shows you acted in good faith.
Can we monitor employee devices and accounts?
Often, where the monitoring is tied to a documented business need, is proportionate to that need, and employees are told it exists. Covert or blanket monitoring is the kind most likely to be challenged. Your counsel should confirm the position under your agreement.
Is this legal advice?
No. We are not lawyers, and labour relations is its own specialty. We work alongside your labour relations staff and employment counsel on the security side of the policy.
Getting the policy right the first time
If you are rolling out monitoring or device rules in a unionised environment, tell us what you plan and who it covers. Sector context is on security for colleges and universities. Related services: identity and workplace security, vulnerability management and cyber risk and governance. More pieces are in writing.