Protecting Jane Doe's Privacy: How far must employers go?
Time 3 Minute Read
Categories: News & Events

A recent decision out of the Pennsylvania courts is a caution to employers who are required to produce employee personnel information in responding to court or agency proceedings.  Jane Doe v. Wyoming Valley Health Care System, Inc., (PA Super., December 18, 2009) raised the issue of how much privacy employees can expect in the information provided to their employers and kept in their company personnel files.

Following an NLRB hearing in which “Jane Doe’s” personnel records were used to determine whether “Clinical Care Coordinators” qualified as “supervisors,” Doe sued the company for invasion of her privacy.  She claimed that a document from her confidential personnel record was improperly disseminated during the hearing in violation of her privacy rights.  A Pennsylvania trial judge allowed her claim to go to a jury that found in her favor.
 
But can releasing personnel files during a court proceeding really put a company at risk for invasion of privacy liability?  The answer is probably not, if handled carefully.  The appeals court in Jane Doe reversed the jury verdict and held that the use of the personnel files in the NLRB hearing was privileged.  The record made clear that the purpose of the disclosure was genuine and related to the NLRB proceeding.  The court focused on the fact that the lawyers, not the company’s management, selected which files to present, and that the information presented from the files was relevant to the issue in the hearing.     

This appellate ruling offers comfort, but perhaps not to the company that had to defend the case (unsuccessfully) to a jury before obtaining a reversal on appeal.  That the matter commanded this much process suggests great care in protecting the personal information of employees when companies are required to produce records in litigation or agency investigations.  For example, in Salt River Valley Water Users Association v. NLRB, 769 F.2d 639 (9th Cir. 1985), the court held it was not an abuse of discretion to limit the union’s access to only disciplinary actions and performance reviews. 

Recent amendments to the court rules require redaction of social security numbers, but the experience of the employer in Jane Doe suggests real care be taken in protecting any information not relevant to the case and that might create privacy issues for the employees whose records are produced.  It is also advisable to request from the court or agency requiring or admitting records an order that protects the affected employees’ interests.

You May Also Be Interested In

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Time 3 Minute Read

Artificial intelligence (“AI”) has become an ever-increasing presence in the workplace.  AI can help employees focus on more meaningful work by eliminating certain rote tasks including note taking or transcribing meetings.  But, as with any workplace tool, some notes of caution are necessary.

Time 2 Minute Read

On December 16, 2025, the Federal Trade Commission announced an enforcement action against Illusory Systems Inc., a Utah-based company doing business as Nomad, following a major data breach in which hackers stole $186 million from consumers.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page