Friday, December 17, 2010
Firing An Employee Bad Mouthing the Company on Social Media? Better Think Twice.
According to attorney John R. Lanham, in the January 2010 edition of Morrison Foerster’s (mofo.com) Employment Law Commentary, “employees’ online communications may gain legal protection based on either the privacy or the substance of the communications.” Mr. Lanham’s article brought to light two very real risks for organizations: 1) the growth of social media-related lawsuits; and, 2) current and developing legislation intended to protect employees from employment-related actions on the basis of things said on social media platforms.
In Pietrylo, et al. v. Hillstone Restaurant Group d/b/a Houston’s, two employees of a Hackensack, New Jersey Houston’s Restaurant successfully sued their former employer in an unlawful termination case that stemmed from the employees’ use of social media to disparage the restaurant and its management. In this case, the two employees were terminated for establishing an invitation-only MySpace page for the purpose of allowing employees to vent their dissatisfaction with their employer. Those invited to join the group were existing and former employees – none of which included management.
Management eventually became aware of the MySpace page through an employee that belonged to the MySpace group. The employee provided management with the login ID and password to access the invitation-only MySpace page. In response to the derogatory information posted on the MySpace page about Houston’s management and the company, the two employees that created the MySpace page were terminated for violating the restaurant’s “core values.” The two employees sued Houston’s in federal court and received a favorable ruling in June 2009 when the court found that management had violated the federal Stored Communications Act as well as a comparable state law. The violations were based on the manner in which management gained access to the site. According to the court, the employee that provided management with the user ID and password was perceived to be under duress and feared retaliatory action by management if the user ID and password were not provided.
In another case in October 2010, the National Labor Relations Board (“NLRB”) filed a complaint in Connecticut against American Medical Response of Connecticut, Inc (“AMRC”). The complaint alleges that AMRC violated the National Labor Relations Act (“NLRA”) when it terminated an employee for making disparaging comments on her Facebook page regarding a supervisor. The NLRB alleges that AMRC’s social media policy, which prohibits employees from depicting adversely AMRC in any way on Facebook or other social media sites where pictures of the employees can be posted, violates the NLRA.
The NLRA prohibits employers from punishing workers – whether or not they are union members – for discussing working conditions or unionization. The NLRB claims that this is a case of employees utilizing a social media platform for the purpose of discussing jointly matters related to working conditions, a permissible activity under the NLRA. The NLRB alleges that AMRC’s social media policy was overly broad and denied employees’ right to discuss working conditions among themselves.
These two examples illustrate the challenges that employers currently face in balancing social media risks with human resource risks. According to survey results contained in Proofpoint, Inc.’s (ProofPoint.com) report, “Outbound Email and Data Loss Prevention in Today’s Enterprise, 2010,” the number of firms that reported social media-related terminations in 2010 remained consistent at seven percent compared to eight percent reported in the 2009 survey. However, this figure is nearly double the rate of four percent cited in the 2008 survey. This data suggests that there is definitely a need for organizations to consider the impact that social media will play in managing employees. The challenge for organizations is establishing the appropriate environment in which an organization can justifiably terminate an employee with the confidence of knowing that it will not likely experience a legal backlash.
Another issue related to employee terminations is the topic of reference letters. While many organizations look favorably upon reference letters for terminated employees, some organizations struggle with the issue. Based upon the popularity of social media platforms such as LinkedIn, it is important for organizations to address instances in which reference letters are permitted. In today’s environment it is very likely that a terminated employee will seek an online reference from a past manager or co-worker. In developing a policy statement regarding reference letters, it is important for the organization to convey to employees through training that online recommendations such as those provided through LinkedIn, are equivalent to reference letters. As such, guidance should be provided to employees to ensure that they comply with the organization’s policy.
Employment law is an extremely complex and evolving area of law. As such, this article cannot adequately address all of the issues that organizations may face when it comes to social media. This post is intended to provide examples of actual cases in an effort to demonstrate the importance of developing a human resources policy that addresses social media use by employees. Unfortunately, employment law relative to social media usage is currently taking shape. As such, it is somewhat difficult to fully define best practices. Regardless, a well thought out approach that incorporates existing best practices with evolving case law will provide for the best protection. Incorporating these practices into the formal written social media policy will provide the best possible protection against claims for unlawful termination.
[This post was edited on December 30, 2010 to add the YouTube videos embedded within.]
Wednesday, December 15, 2010
Social Media and Information Security
If there is one overall benefit that social media has brought to bear, it is that social media has made us all more open and willing to share. There is much to be said about a society that values trust, openness and sharing. Through social media, users are increasingly sharing more and more of themselves. From family photos to what they’re buying, reading or eating to where they’re currently located as well as what exactly they’re doing there. Prior to social media the world was a place made of personal silos where people were more than satisfied keeping their private lives private. Once social media became broadly adopted the world generally became a more open society. In the grand scheme of human relations, this is surely a positive outcome.
Unfortunately, no good deed goes unpunished. And social media’s effect on society is no exception. While society has become more transparent in its online interactions, social media users have also become too trusting. Since most social media interactions are conducted with trusted parties such as friends, classmates, co-workers and other known persons, social media users tend to lower their guard when interacting on social media platforms. As such, social media platforms have become extremely attractive to criminals that seek to exploit the trusting nature of social media users. Further, the fact that millions of users congregate on these sites daily, provides an attractive return on investment for the criminal element. As a result, social media users are at a greater risk of exposure to the exploits of criminals. Internet security experts at Kaspersky Lab (http://usa.kaspersky.com) believe that malicious code distributed through social media is up to ten times more effective than similar attacks using e-mail.
A social media user’s confidential personal information includes everything from passwords to social security numbers to birth dates to items such as mother’s maiden name. This information is regarded as the Holy Grail to criminals who seek to takeover a user’s identity or account. In today’s digital age, this information is maintained by many organizations, including social media platforms. Through the use of sophisticated software programs such as keyloggers and techniques such as phishing attacks, criminals can easily gain access to the social media credentials (ID and password) of their victims. Once they gain access to a social media account, the criminals may deploy various strategies to carry out their plans. For example, it is commonly known that people use the same password for multiple computer systems. As such, once a criminal has access to a single social media account, the criminal may use the same credentials to attempt to access other social media accounts, online banking accounts, corporate computer systems, etc.
Another approach that may be taken by criminals is to use a hijacked social media account to gain access to other users’ accounts by sending a message from the hijacked account to the accounts of people within the hijacked user’s social network with the intent of tricking those individuals into visiting Web sites that install malicious software utilized to steal the login IDs and passwords. These information security breaches are generally successful for two main reasons – users assuming that messages sent within the social media platforms are legitimate and users not understanding how their actions can be exploited by criminals. While the techniques may differ, the goal is generally the same – to gain access to social media accounts that contain valuable information that the criminals can use for financial gain.
A complete discussion of information security is beyond the scope of this book. What is important to note from the perspective of developing an effective social media policy is that social media poses information security risk just as any other Internet-based application. The ultimate question regarding information security is whether organizations with large workforces can reasonably expect to protect themselves from the criminal element that seeks to exploit social media. The short answer is, “it depends.” Organizations can best protect themselves by not becoming the “low hanging fruit.” Ultimately it comes down to assessing the risk, mitigating the risk, training the staff and monitoring the results. All of which should be described in a formal written social media policy.
Sunday, December 5, 2010
Expectation of Privacy and the Social Media Policy
Social media by name and design is a “social” media. It is not called “private media” for a very specific reason – there is nothing private about it. Regardless of privacy settings and other controls, increasingly courts around the Country are sending the following message to American workers: “employees using social media should not be under the false impression of a right and expectation of privacy in the workplace.” These court cases are concluding that social media in the workplace is not protected by the Fourth Amendment and as such, information contained within social media platforms may be subject to discovery during the legal process as well as part of other procedures such as audits, background checks and similar activities that benefit from the use of information contained on social networks.
The Fourth Amendment provides a “reasonable” expectation of privacy. However, the standard upon which reasonableness is judged depends upon the current standards of society. In today’s open and social media-enabled society, we live our lives more openly and transparently than ever before, sharing everything from our choice of breakfast cereal in the morning to photos of our children to our location in real-time. For the most part, there are fewer and fewer secrets being kept as more and more of us become increasingly comfortable giving up more of our information than ever before. While the evidence does not suggest that every life should be an open book, judicial decisions appear to take a practical approach when it comes to information contained on social media platforms. In other words, employees are not going to be allowed to act to the detriment of an organization and then hide behind a form of social media immunity.
From the organization’s point of view, the assumption of the lack of privacy plays a key role in managing employees’ use of social media within the workplace. Based upon the current direction of case law, it is in every organization’s best interest to disclose the organization’s right to inspect social media-based records to the extent such records originated through the use of the organizational assets, including computers, network infrastructure and company-controlled/owned social media accounts. The social media policy should be clear about its right to monitor social media interactions in real-time (network monitoring), in stored files (caches, temporary files, etc), while on “company time” and using the organization’s equipment. Such a policy statement will assist the organization in defeating opposition to demands for information during the legal process and will provide protection against claims of invasion of privacy. Once the formal written policy is in place, the organization must ensure that employees are informed of the policy and comply with its requirements. Deviation from the written policy may result in questioning whether or not the employee had an expectation of privacy due to “practices” that are inconsistent with the written policy.
In City of Ontario v. Quon, a California police officer had his case ultimately reach the United States Supreme Court when the police officer was verbally told by a supervisor that he indeed did have an expectation of privacy when using for personal use a department-issued digital device – a statement that contradicted the written policy. While a lower court supported Officer Quon’s assertion that his personal electronic messages were protected based upon the verbal assurance, the U.S. Supreme Court eventually determined that the officer did not have an expectation of privacy on the basis that 1) a formal written policy existed, 2) the device used was provided by the police department and as such, the police department had certain rights to monitor appropriate usage of its assets, and, 3) there was no less invasive practical manner of monitoring general activity on the device.
In Romano v. Steelcase, Inc., a New York trial concluded that an employee had no reasonable expectation of privacy regarding information posted on social networks – despite the restricted privacy settings established by the user.
Another important piece of federal legislation that affects organizations’ access to employee information is the Stored Communications Act (“SCA”). The SCA prohibits employers from, among other things, accessing employee accounts maintained by third-party hosts such as social networks. The SCA generally allows organizations to access stored communications such as emails and other information stored within its own computer network. The SCA, however, limits an organization’s ability to access such information (without the employee’s authorization) if it is stored by a third party service provider. A further complication is that even in instances where an employee has granted an employer access to third-party sites, such access may be deemed to be done under duress and as such, a violation of the SCA. As such, experts generally recommend that employers not extend their reach beyond information contained within their systems in order to prevent violations of the SCA.
In drafting this section of the social media policy, organizations should check with their legal departments in order to determine how to best describe an organization’s policy regarding monitoring of social media activities. Further, each organization should work with its legal department to determine the various local, state and federal laws that may be applicable.
Wednesday, December 1, 2010
Social Media and the Recruiting Process
Yes, social media is a great tool to identify and interact with potential applicants. Yes, social media is a great tool to learn more about applicant’s professional backgrounds, experiences, and goals. And yes, social media provides access to applicant information that is generally not available through the traditional interview process. However, as we have come to learn throughout this book, nothing with social media comes without a cost.
The general consensus among HR professionals is that the extraneous information accessible through social media should not be considered as part of the recruiting process in order to avoid complications in the hiring process that may run afoul of human resources laws. Generally, to the extent that organizations scour social media for recruiting purposes, employers and recruiters should stay focused on capturing and evaluating the information that addresses the applicant’s qualifications and expertise. Reliance on unrelated information can lead to false impressions of applicants, resulting in lost opportunities at hiring qualified candidates as well as possible judgments based on prohibited information. Unless the information suggests highly inappropriate or illegal activity, the information should be dismissed. Everyone is different. Some people have unique and quirky interests and activities that they participate in outside of work. There is nothing wrong with that and it certainly should not be the basis for passing up on an otherwise strong candidate.
To the extent an organization decides to utilize social media as part of the employment process it is wise to provide applicants with written notice that the background check may involve a review of any publicly-available social media sites. Once the disclosure is made it is important to keep any inquiry limited to information that is “publicly available.” In other words, the process should not require that applicants provide passwords to social media sites nor should it require that applicants “friend,” “like” or otherwise grant the organization access to information that would not otherwise be readily accessible. Such demands, besides being extraordinarily invasive, may violate federal and state privacy statutes as well as may lead to violations of “legal activities” laws that may prohibit employers from taking certain actions based on the “personal time” activities of employees and applicants.
The February 2010 issue of Practical Law: The Journal lists the following risks associated with social media usage as part of the recruiting process:
• Discrimination violations due to adverse employment decisions based on protected class information learned through social media.
• National Labor Relations Act ("NLRA") violations due to employment actions inconsistent with the NLRA.
• Violation of the Fair Credit Reporting Act (“FCRA”) and its state equivalents as a result of the use of consumer reports in conducting background checks without providing the required adverse action disclosure.
Based upon the potential legal pitfalls it is essential that bank HR departments establish a formal written social media policy that specifically addresses how social media may be utilized. Further, human resources personnel should be well trained to understand not only the social media policy but also the applicable laws such as the NLRA, FCRA and any other applicable laws, rules and regulations.
Sunday, November 28, 2010
Monitor Your Brand
Wednesday, November 24, 2010
Social Media Policies Are Not An Option
Organizations, regardless of their involvement in social media activities, should implement a social media policy to protect against the internal and external risks posed by social media. Regardless of the strong case for social media policies, there are a lot of opinions against their use in the workplace. Try Google-ing “social media policy” and you will get around 32,900,000 opinions! If you read what is being said you will find good arguments on both sides. But the bottom line is this: any organization interested in protecting its brand and reputation must ensure that it has in place some form of social media policy to protect against the many risks that are posed by social media. Social media risks originate both internally and externally and exist regardless of an organization’s decision to participate in social media activities.
Critics of social media policies say “you can’t control what is uncontrollable!” Agreed. And that’s exactly why a social media policy is necessary. Contrary to critics’ beliefs, a social media policy is not intended to “control” anything. Its purpose is to give employees guidance, keep them from making severe errors in judgment and allow the organization to identify potential issues before they elevate to the status of a crisis. No policy, regardless how well written, can “control” the risks. The best a policy can do is mitigate the risks. Policies work for organizations that understand that risk happens.
In a perfect world organizations hire individuals that are smart, capable and masters of common sense. Unfortunately we don’t live in that world. In our world, smart, capable and generally common sensical employees make dumb decisions from time-to-time. Further, for many companies, the youngest employees, while smart and capable, many times lack the experience and maturity needed to make all the right decisions all the time. And unfortunately it is these employees that are likely the most experienced and active users of social media. In these situations, formal written social media policies provide employees with the guidance to navigate difficult or unknown situations.
In a perfect world, every organization provides world class products, services and gives each customer the attention they demand to keep them happy. In the real world, no matter how hard organizations try, mistakes are made, customers are disgruntled and dissatisfaction is voiced. Historically such dissent was limited to irate phone calls and letters and possibly the loss of business of the unhappy customer. Today with the use of social media, customers have the ability to reach and influence current and potential customers on a scale that can invoke real pain and suffering.
Businesses are not only in the business of making or servicing widgets. Businesses are also in the business of making and servicing the organization’s brand. The stronger the brand, the greater the revenues. Organizations can enhance their brand and competitive advantage and potentially generate greater revenues and profits with a well crafted social media strategy. However, before unleashing a social media strategy, organizations should craft a social media policy that provides the necessary guidance to ensure that social media risks are properly mitigated. The social media policy is the key to ensuring that social media risks area kept under control and to acceptable levels.
Lack of attention to social media risks can have the opposite effect. Companies that take a laissez faire approach to social media risks stand a greater likelihood of experiencing major embarrassments, reputational harm and the need for a major incident response. As such, it is in every company’s best interest to establish guidelines for social media usage through the implementation of a social media policy.
Social media poorly managed has the potential to adversely affect the organization, its brand, reputation and revenues. The upside to participating in social media is an enhanced brand and increased revenues and profitability. While social media does pose risks, if well managed, social media provides benefits that far outweigh the costs. The key to managing the risks is a well-crafted formal written social media policy and training program that is understood and adhered to by employees. A social media policy will not eliminate all of the risk but it goes a long way in allowing everyone to sleep at night. Ultimately, whether an organization undertakes a social media strategy will depend on its appetite for risk. Since many social media risks exist regardless of an organization’s decision to participate in social media, it is in the best interest of organizations to implement some form of social media policy.
Thoughts?
Tuesday, December 1, 2009
Yes, Press Releases Are Now Part of Social Media and VERY Viral
This post has been created to make you aware that, yes, press releases ARE social media and ARE definitely viral. I'm not a publicist by schooling but I have had years of experience using press releases in the pre- and post-Web 2.0 world. Something I noticed about a year ago was how the press release outlets, including the majors such as BusinessWire, started Web 2.0-enabling their releases. The following is an example of the social media functionality added to press releases to enable their VIRAL distribution.

As you can see under the "Sharing" section on the left side of the page, the press release outlet (in this case BusinessWire) added a series of common social media platforms with which this press release could very easily be shared. This is only one outlet, but I've seen most outlets incorporate this "viral accelerator" to their pages.
As a result of a recent press release, I achieved immediate and broad distribution on Twitter illustrated by the sampling below:
As you can see, just on Twitter alone there were nearly 100 retweets of the press release. Multiply that number by the number of followers that read each retweet and you can see how a traditional press release can achieve viral distribution.
Now consider how these traditional press releases are distributed to hundreds of online media outlets by the wire services, resulting in greater viral potential. Below is a snapshot of a small number of the media outlets that received the press release from the wire service and began serving up copies of the press release - again, each with a similar "sharing" feature.
Now, keep in mind that simply having a "viral accelerator" does not mean a press relaese will achieve viral results. The material has to possess certain qualities. Press releases in of themselves are not great for creating viral buzz. But press releases tied to good viral content will do the job. I recommend reading the chapter of Viral Marketing in The Community Banker's Guide to Social Network Marketing for more details.
In any case, to answer the question posed by the tweet mentioned above, the fact that press releases have Web 2.0 funtionality means that, YES, press releases ARE about viral distribution.
