Can an employee request access to their personnel and payroll files?

The short answer is yes. In Canada, employees have the right to access information in their personnel and payroll files, provided that it does not interfere with another employee’s privacy rights.

How does privacy law affect an employee’s right to access her or his personnel and payroll files?

Statutory requirements as to the confidentiality and privacy of employee information are slowly spreading. The federal Personal Information Protection and Electronics Documents Act (PIPEDA) was enacted in 2001. It covers employees under federally regulated jurisdiction and purports to govern all privacy rights in Canada, except in employment and where the provinces have enacted corresponding legislation. British Columbia, Alberta, Saskatchewan and Quebec either have, or are developing, privacy legislation that corresponds to PIPEDA. In other provinces, there is no privacy legislation covering the private sector.
Organizations must assess their current practices and make appropriate changes in policies to comply with PIPEDA, except in those provinces that have developed their own legislation (in which case compliance with the provincial legislation is required). In any case, employers with operations in a province with privacy legislation will want to ensure consistent policies across the company.
PIPEDA requires that federally regulated companies inform employees that they are collecting personal information and obtain the employees’ consent to collect the information. The information collected must be limited to that necessary for purposes defined by the company. The employee must be informed as to the existence of the personal information and be given access to it. There must be adequate security over the personal information, and it must be destroyed when it is no longer required.

10 best practice principles for privacy

Whether or not a statute applies, organizations should analyze their privacy practices following 10 principles first articulated by the Canadian Standards Association, and since adopted by the various privacy statutes:

  1. Accountability: One person in the organization should be clearly accountable for privacy issues and systems.
  2. Identifying purpose: The reasons for information being collected should be clearly stated.
  3. Consent: Consent should be obtained for the collection of personal information, except where collection is required by statute. Consent may be implied (such as by the submission of a résumé to a prospective employer).
  4. Limited collection: Collection of information should be specific, relevant and necessary, and only for the purposes specified.
  5. Limited use, disclosure and retention: Information should only be used for its intended purpose, disclosure should be limited and information only retained as long as necessary.
  6. Accuracy: Information should be accurate and processes should be in place to keep it up to date.
  7. Safeguards: Information should be safeguarded during use, storage and disposal.
  8. Openness: Privacy policies should be open and clear regarding accountabilities and rights of access.
  9. Individual access: Individuals should be informed of the existence of information, and of their rights to access it and correct it, subject to appropriate constraints (such as protecting the privacy of other employees).
  10. Challenging compliance: There should be a process to challenge compliance with these principles to the person accountable for privacy.

I discuss employee records further in the payroll section of Finance and Accounting PolicyPro, published by First Reference Inc. Steve Goldwaser and I discuss the technical side of privacy controls in chapter 8 of Information Technology PolicyPro. Find more information and take a free trial at of these two comprehensive publications at www.firstreference.com.
Jeffrey D. Sherman, BComm, MBA, CIM, FCPA, FCA
Author of Finance and Accounting PolicyPro®

access to information
accountability
accuracy
challenging compliance
compliance
consent
destroying information
disclosure and retention
employee access to information
Employee records
employment law
employment records
HR Law
identifying purpose
individual access
limited collection
limited use
openness
Payroll
payroll information
Personal Information Protection and Electronics Documents Act
PIPEDA
policy
privacy practices
privacy principles
privacy rights
private sector privacy legislation
safeguards
substantially similar legislation
Share

Related Posts

Imagen 1

Addressing domestic violence in the workplace – some insights

The Ontario Occupational Health and Safety Act violence and harassment prevention provisions (Bill 168) require an employer to take all reasonable precautions in the circumstances for the protection of all employees if a domestic violence situation is likely to expose a worker to physical injury in the workplace and the employer becomes aware or ought reasonably to be aware of the situation.

But what does that imply? The law states the requirement but provides little guidance on what employers need to do to prevent domestic violence from spilling into the workplace. In addition, many employers are not comfortable addressing a situation of such a personal nature. It is not an easy task to complete and might never be.

Marie-Yosie Saint-Cyr, LL.B. Managing Editor

Read more
Imagen 1

Disclosing persons with a history of violence

The Ontario Occupational Health and safety Act violence and harassment prevention provisions (Bill 168) require employers to provide information, including personal information, about a person with a history of violent behaviour if:

Marie-Yosie Saint-Cyr, LL.B. Managing Editor

Read more
Imagen 1

Sleeping on the Job? What do you have to do to get fired in Canada, anyway?

Employees can be dismissed for cause, and therefore without notice or severance, when their misconduct or performance is so egregious that the employment relationship has been irreparably harmed. In assessing this issue, employers must adopt a contextual approach, which considers not only the misconduct in question, but the entirety of the employment relationship.

Rudner Law, Employment / HR Law & Mediation

Read more