I used to be the IT Director for a document scanning business in the UK.
Scanning paper HR records was the single most painful job we had to do. The entire file became a complete legal nightmare purely because it stopped being paper and became covered by Data Protection.
Usually the HR department had to go through every single employee file and shred any documents that might be grounds for legal action before they got scanned.
The process before scanning was:
- employee is annoyed
- employee requests their HR file
- HR sanitise file and sends it to employee
after scanning, every single page was indexed. So they couldn't react to a request by destroying pages (because there'd be holes in the index). So they had to sanitise every single file before scanning.
I understand the point of Data Protection law, but in this case it was really counter-productive. Evidence was destroyed wholesale.
That sounds like "working as intended" - after all, if instead of just requesting their file the employee had initiated legal action against you, it would have been illegal to destroy those documents. And it also raises the question of which part of your HR process is generating incriminating documents in the first place?
not so much "incriminating" as "not required to be kept and could possibly be misconstrued".
Not our HR process, our customer's. What was actually destroyed depended on their interpretation of the law.
One common one was the Data Protection requirement to not keep inaccurate data meant that all but the latest employee change of address forms had to be destroyed. Easy to implement post-scanning, pain in the arse to do pre-scanning.
Thank you. I guess I didn't articulate it well enough for the grand parent comment here. I guess we could make an exception for personal AND non-commercial diaries but if you make business decisions that affect me based on information you store about me, then I should have a right to see them.
I'm also thinking about the rights of everyone including criminal (including terror) suspects to see (I am specifically not asking permission to alter or delete, that's another conversation) all the information the government (and their agents in the private sector) stores about them.
I know it sounds onerous specially because of the issue of authentication (how does the CIA know that it is me who is asking for information about me and not someone impersonating me?) and I don't have a good solution for these questions.
This is a ridiculous idea to me. If I run a business, my internal evaluations of candidates and employees are no one's business but my own. They are my observations about the world, with the productive end of hiring better employees. Whether my decisions affect you or not is really not relevant; we make free decisions that affect other people all the time. I take issue with any claim that people have legally-binding private obligations to each other beyond abiding by contracts, and refraining from violence and fraud.
OK, what about a compromise: you can keep your conclusions private, you only need to disclose to me the raw data you used to reach such conclusions. Is that better?