BREAK IN TRANSCRIPT
Mr. BLUMENTHAL. Mr. President, privacy is a fundamentally and almost uniquely American value. It is the reason the Colonies rebelled--one of the major reasons they rebelled--against the British. The invasion of our homes by British soldiers without court approval, the lodging of those soldiers in our homes without permission--the invasion of the fundamental rights of privacy was one of the basic reasons this Nation sought independence from the British. So throughout our history, privacy has been a value, a fundamental right affirmed again and again in our courts, enshrined in our Constitution and ingrained in our way of life.
That is the reason so many of us were offended and regarded as reprehensible and repugnant a practice that was revealed recently--a practice involving employers coercing and compelling the disclosure of log-in information, user names, and passwords to private accounts and private systems by job applicants. And the same kind of coercion and compulsion applied to current or existing employees as a condition of their continuing in their jobs. That kind of practice is abhorrent, and it is the reason that yesterday I, along with a number of my colleagues from both this body and others from the House of Representatives, introduced the Password Protection Act of 2012.
These practices are unacceptable for a number of reasons. An employer has plenty of ways other than accessing private accounts--Gmail, storage data, and accounts on Facebook or other social networking sites--to obtain information that is relevant to employer needs and interests in offering a position to someone. There are other means that are adequate and acceptable. What is not acceptable is coercing and compelling access to an applicant's e-mail account, which could contain all kinds of personal information that is inappropriate and unnecessary for an employer to know, information that is irrelevant, in fact, to the terms and duties of a person's employment.
Second, the disclosure itself endangers the security of that applicant's personal data as well as the Web sites themselves. Too many careless companies too often have lost customer data or employee information, allowing it to be breached through poor security practices. That is the reason I have proposed a measure that would require safeguards of that data--a separate measure that is before this Chamber now--to ensure adequate remedies when there are breaches and to require systems in place by employers to guard that information. An applicant who takes care to use encrypted networks or other personal safeguards may find his or her personal information--financial data, medical information--breached through no fault of his or her own simply because the company fails to take adequate steps to safeguard it.
There is another reason these practices are abhorrent; that is, identity theft by the employer itself--a continuing danger. That kind of potential danger is a real one that certainly raises this interest very squarely.
But maybe as important as any of these other interests is the danger of compromising the security of third parties--loved ones, family, friends--who have entrusted the person who is applying for a job or who is employed by a company that breaches its responsibility by demanding this information. When an employer logs in to an employee's personal account, he sees that employee's e-mails with his or her spouse or Facebook pictures of siblings and children. Those parties are completely unaware that one of their friends' or family members' employers may be reading their correspondence or looking at their pictures. Imagine a daughter who tells her mother of a pregnancy, a son who acknowledges an addiction to a parent, a father who speaks of his wife's illness in confidence to his children. Each has an expectation of privacy that is betrayed and violated when an employer demands log-in information, user names, or passwords from a job applicant or a current employee. The impact is not only on that employee or job applicant but on innocent loved ones--friends, family--whose confidential information, e-mails, and other data may be exposed.
Of course, when information is exposed in this way, there is the danger of discrimination based on marital status, sex, gender, and other kinds of prohibited categories. So barring the compelled disclosure of this information actually is an aid to the employer because it ensures that none of these hiring or firing decisions is based on a prohibited category or discrimination.
The Password Protection Act addresses all these concerns and prohibits employers from forcing prospective or current employees to hand over personal, private financial information that has no place in the hiring process. The bill prohibits an employer from compelling or coercing an employee or prospective employee to provide access to a private system as a condition of employment. This means an employer cannot compel a prospective or current employee to provide his Gmail password, and an employer cannot force an employee or prospective employee to log on to a password-protected account so the employer may browse the account's content.
The Password Protection Act also very importantly prohibits retaliation, which is a danger with current employees. That retaliation could take all kinds of forms, but the demand for log-in information, user names, or passwords certainly creates a kind of presumption that the refusal to do so prompts action that can be regarded as retaliation. An employer who violates these legally required duties is subject to a penalty of $10,000 per violation.
This act will protect employees from unreasonable invasions of their privacy--unreasonable invasions that have no commonsense basis--and it prevents unintended consequences. It doesn't prohibit social networking within the office on a voluntary basis, it does not bar employers from conducting valid investigations of misconduct, it does not prevent an employer from controlling the company's own system--its own Facebook account, for example--and it provides that States may exempt certain categories of employees, such as individuals who deal with children who are under 13 years of age or Federal employees who may have access to classified or secure national security information. The bill also provides for reasonable exemptions that State law may make for State employees who are involved, for example, in law enforcement or corrections.
Like so many in this body, I have heard from countless Connecticut citizens who are not only offended but outraged by these practices reported in the press. Fortunately, many employers have shown they get it, they understand this deeply held value, and they have rejected these possible practices. Many who might have been contemplating engaging in them have likewise retreated and reversed their decisions. So merely shining a light, pointing the spotlight, and raising the issue has brought many employers to understand the commonsense force of objections to these practices.
I wish to thank grassroots groups, such as the 57,000 citizens at Bold Progressives, who signed a petition at ProtectOurPasswords.org to let Washington know--57,000 of them strong--they reject the idea that their employers will force them to hand over this personal, private information. I thank the activists at Access Now, who are similarly generating a groundswell of support for this initiative and working to protect employees' rights on the job. I also wish to thank companies such as Facebook, Twitter, Microsoft, and Google, which have cooperated and support this effort because they have an interest in preventing invasions of privacy, demands for information that are unnecessary, repugnant, reprehensible, and unacceptable. I thank all of them for working with us on this legislation.
Finally, I thank Senators Schumer, Klobuchar, Shaheen, Wyden, Sanders, and Akaka, as well as Representatives Heinrich and Perlmutter on the other side of this body, for working with me in introducing this bill. I am hopeful the Congress will consider it promptly and successfully because I think it sets a marker and provides a milestone in protecting individual privacy against abhorrent invasions in the workplace and elsewhere that have no place in American life.
Mr. President, I yield the floor.
BREAK IN TRANSCRIPT