Skip to content

Menu

Jackson Lewis P.C.  logo
HomeAboutServicesContactSubscribe
Search
Close

Workplace Privacy, Data Management & Security Report

Louisiana Follows Wisconsin and Tennessee in Protecting Employee and Student Personal Online Account Access Information

By Joseph J. Lazzarotti on May 27, 2014
Posted in Data Security, Information Management, Information Risk, Monitoring, Photos, Videos and Surveillance, Social Networking, Workplace Privacy

Following the enactment of similar laws in Wisconsin and Tennessee earlier this year, Louisiana Governor Bobby Jindal signed HB 340, the Personal Online Account Privacy Protection Act, into law prohibiting employers and schools in Louisiana from demanding access to personal email, social media and other types of online accounts. The Act applies to just about any employer doing business in the state and any educational institution, from nursery schools to universities and business schools. The Act protects the personal online accounts of employees, applicants, students and prospective students that are unrelated to any business purpose of the employer or educational institution. In general, employees, students, job applicants and prospective students that refuse to provide access to their personal online accounts are protected from being fired, disciplined, denied employment, or otherwise penalized or threatened, and in an educational setting, being expelled, disciplined, denied admission, or otherwise penalized or threatened.

The Act does not protect personal activities on devices owned or services provided by the employer or educational institution, except in the case of an educational institution where there is an intent to permanently transfer ownership of the device to the student or prospective student. It also permits employers to discipline or fire an employee who transfers the employer’s proprietary or confidential information or financial data to the employee’s personal online account without authorization. The Act also does not prohibit employers from engaging in certain investigations, such as where the employer has specific information about activity on the employee’s personal online account and the investigation is for the purpose of ensuring compliance with applicable laws regulatory requirements, or prohibitions against work-related employee misconduct.

Employers are not prohibited from viewing, accessing, or utilizing information about an employee or applicant that is in the public domain and can be obtained without the employee’s or applicant’s username, password or other authentication information. A similar rule applies for educational institutions. In addition, the Act recognizes that through permissible monitoring of its information systems, networks, or employer-provided devices, employers may inadvertently receive an employee’s or applicant’s username, password, or other authentication information pertaining to the employee’s or applicant’s personal online account. In those cases, the employer will not be liable for having the information, but may not use the information to access the employee’s or applicant’s personal online account. Whether use of keylogging or spyware technologies will constitute inadvertent acquisition of an employee’s username or password to a personal online account remains to be seen. However, if there is a reasonably likelihood that such information would be captured by such software applications, it may diminish an employer’s ability to argue inadvertence.

As we’ve said before, employers and schools will need to be more careful in navigating these and other laws when trying to manage certain online activities in the workplace and in academia. This includes making sure managers, supervisors, professors and principals understand the limitations placed upon them in these areas.

Tags: keylogging, Louisiana, password, personal online account, social media, spyware, Tennessee, Wisconsin
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Joseph J. Lazzarotti Joseph J. Lazzarotti

Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm’s Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the…

Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm’s Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the International Association of Privacy Professionals. Trained as an employee benefits lawyer, focused on compliance, Joe also is a member of the firm’s Employee Benefits practice group.

In short, his practice focuses on the matrix of laws governing the privacy, security, and management of data, as well as the impact and regulation of social media. He also counsels companies on compliance, fiduciary, taxation, and administrative matters with respect to employee benefit plans.

Read more about Joseph J. Lazzarotti
Show more Show less
Related Posts
The Growing Cyber Risks from AI — and How Organizations Can Fight Back
June 16, 2025
Different Country, Same Challenges: Lessons from a Breach That Could Have Been Prevented
June 11, 2025
A Brief Reminder About the Florida Information Protection Act
March 4, 2025
Jackson Lewis JacksonLewis.com

Stay Connected

Subscribe to this blog via RSS Follow Us on Twitter Add us on Facebook View Our LinkedIn Profile

Topics

Archives

Editors

  • Jason C. Gavejian
  • Joseph J. Lazzarotti

Contributors

  • Christopher E. Hoyme
  • Damon W. Silver
  • Michael R. Bertoncini
  • Marlo Johnson Roebuck
  • Nathan W. Austin
  • Nicky Jatana
  • Jeffrey M. Schlossberg

Blog Authors Show/Hide

  • Joseph J. Lazzarotti
  • Jason C. Gavejian
  • Maya Atrakchi
  • Jackson Lewis P.C.
  • Mary T. Costigan
  • Damon W. Silver
  • Jeffrey M. Schlossberg
  • Michael R. Bertoncini
  • Robert Yang
  • Christopher E. Hoyme
  • Rachel E. Ehlers
  • Sean Paisan
  • Melissa Pascualini
  • Jody Kahn Mason
  • Frank J. Fanshawe
  • Gregory C. Brown Jr.
  • Delonie A. Plummer
  • Richard I. Greenberg
  • Jerel Pacis Agatep
  • Eric J. Felsberg
  • Cecilie E. Read
  • Catherine R. Tucciarello
  • Todd R. Dobry
  • Susan M. Corcoran
  • Dorothy Parson McDermott
  • Ryan J. Soscia
  • Ronald V. Sgambati
  • Phillip A. Baggett
  • Nathan W. Austin
  • Michelle L. Duncan
  • Joshua D. Allen
  • Jason Selvey
  • Michelle T. Hackim
  • Daniel J. Moses
  • Amanda A. Simpson
  • Yvonne Arvanitis Fossati
  • Teri Wilford Wood
  • Shannon Bettis Nakabayashi
  • Paul A. Friedman
  • Nikolas S. Dean
  • Marlo Johnson Roebuck
  • Michael H. Neifach
  • Joseph J. Lynett
  • Kevin B. Hambly
  • Jennifer Shoaf Richardson
  • Jackson Biesecker
  • Francis P. Alvarez
  • Cheyna Galloway
  • Amy L. Peck
  • Zachary A. Ahonen
  • John A. Snyder
  • Sierra Vierra
  • Stephanie L. Adler-Paindiris
  • Richard F. Vitarelli
  • Kathryn J. Russo
  • Philip M. Duclos
  • Laura A. Mitchell
  • Michael D. Ridenour
  • Leo P. Norton
  • Kevin D. Holden
  • Joshua M. Henderson
  • Jonathan J. Spitz
  • Jamie L. Levitt
  • Valerie K. Jackson
  • Howard M. Bloom
  • Greg Alvarez
  • Erik J. Winton
  • Elizabeth S. Walsh
  • David R. Golder
  • Craig W. Wiley
  • Clifford R. Atlas
  • Cindy Y. Huang
  • Christopher T. Patrick
  • Chai Williams
  • Chad P. Richter
  • Ashley Solowan
  • Angelika Avagian
  • Alec Nealon
  • Theron Velazquez
  • Terri Bowman
  • Robert Pfeifer
  • Regan Harrison
  • Paige
  • Nicky Jatana
  • Nicole A. Trotta
  • Melissa Ostrower
  • Mei Fung So
  • Lara Hamm
  • Kourtney Goebel
  • Kendall Melidosian
  • Gayla Kirkland
  • Kelly Heber
  • Katharine C. Weber
  • Jessica Poot
  • Jenifer M. Bologna
  • Jen Starken
  • Jonathan L. Crook
  • Haley Nystrom
  • Camille​​​​ Garcia‑Mendoza
  • Ann Albertson
  • Alitia Faccone

Recent Upates

  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • The Growing Cyber Risks from AI — and How Organizations Can Fight Back
  • Different Country, Same Challenges: Lessons from a Breach That Could Have Been Prevented
  • Managing the Managers: Governance Risks and Considerations for Employee Monitoring Platforms
  • Oklahoma Expands its Security Breach Notification Law

Jackson Lewis

Subscribe to this blog via RSS Follow Us on Twitter Add us on Facebook View Our LinkedIn Profile
Privacy PolicyDisclaimer

About Jackson Lewis

Focused on employment and labor law since 1958, Jackson Lewis P.C.’s 1,000+ attorneys located in major cities nationwide consistently identify and respond to new ways workplace law intersects business. We help employers develop proactive strategies, strong policies and business-oriented solutions to cultivate high-functioning workforces that are engaged and stable, and share our clients’ goals to emphasize belonging and respect for the contributions of every employee.

Read More...
Copyright © 2025, Jackson Lewis P.C. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo