Data Ethics and Privacy: The New Manager’s Guide

What are my responsibilities when handling team and customer data?

Hey there!

Ever wondered if the way reports are generated in your company is fair or correct from an ethical point of view? Would you be OK with a tracking system implemented in your day-to-day work, something that would track your every single click? How about when you get a team report and everyone is there, with all their results, all out in the open for all to see?

These are only some of the questions we need to ask ourselves when dealing with data ethics and privacy. Today we will talk about these 2 fundamental and very important aspects of data management. Here’s the overview:

  • Why should I care about ethics as a new manager?
  • Data privacy basics
  • The dangers of micromanagement while using employee tracking
  • Confidentiality like a Pro
  • Sensitive performance metrics: the ethical way
  • Keeping your team compliant and safe

Why should I care about ethics?

This is a great question, and one that doesn’t have a simple answer. To understand it better we need to go back a bit and look at the bigger picture. In a previous article we did an Intro to Statistics: A First-Time Manager’s Guide, and we spoke about some of the basic concepts behind the usage of data. Ever wondered about who is behind all this data? We talk so much about using data, how to manipulate it, how to represent it, how to create so many things from it, but do we really understand what is behind it?

People.

Behind every single byte, every 0 and 1, every text, and every dashboard, we have people. While the realization isn’t yet kicking in, let me put it into a different perspective: everything that happens in a company is connected to a person. Every possible action is a direct or indirect result of a real human. Because of this we have a very big dilemma: should we manage data in an ethical way?

Yes, we should!

I don’t say this just because it sounds “new-age”, I say it because I believe it and because along the way I saw what unethical data management can do. I saw people promoted because of it, people that lost their jobs, people that never got the promotion they deserved, and people that completely gave up on doing better, just because at one point or another something happened that was not ethical.

Our responsibility as leaders, as people managing other people, is to be 100% sure that whatever actions we are taking have a strong ethical background. There’s an old saying that goes “the easiest way to lie is with statistics,” and it’s kind of true: a good data wizard can make anything with data and present whatever narrative they want to present. Now, the fact that we can doesn’t mean we should.

It’s also a matter of trust. From the first day in the new role, our team, customers, and upper management start building up a level of trust in us. If we don’t take precautions when dealing with data, we might end up losing that trust very fast.

So, what is ethics anyway?

The simple answer goes like this: just because you can collect or use a piece of data, should you? It’s that very thin line between the legal, which might permit you to do it, and the right thing to do. In essence we have 4 pillars around data ethics in management:

  • Transparency over stealth: never collect information in secret; if you must do it, put it out in the open so that everyone on the team is aware of it.
  • Context over raw numbers: you see lower productivity in a deck from a team member and immediately write them up as non-productive, instead of doing a proper deep dive and understanding the context.
  • Purpose Limitations: data should be used as a guide, not a weapon. Yes, it’s perfectly fine to collect data to improve a process, but using the same data to catch someone off-guard and punish them? Not so much!
  • Stewardship and Privacy: as a people manager you are provided with a lot of personal information about people (salary, history, performance, 1-on-1s, etc.), and using it as a “company asset” to be talked about in management chats or used as leverage is not right.

Data Privacy Basics

Privacy in this case is about every data-related aspect that falls under sensitive data. According to BigID, sensitive data is any information that must be safeguarded because its exposure, misuse, or unauthorized access could cause significant harm, discrimination, financial loss, or a breach of privacy for an individual or an organization. Our regular personal data has very basic identifiers like work email, name, etc., while sensitive data has much more. Let’s break them down into categories to see each one and what it’s about.

Special Category: High-Risk Individual Data

Data protection laws like GDPR will classify some personal details as a “special category” of data because any situation where this data gets out when it shouldn’t can lead to discrimination, harassment, or safety risks:

  • Health & Medical Info: Physical or mental health records, sick leaves, medical conditions, and disability status. Biometric & Genetic Data: Fingerprints, facial recognition profiles, voiceprints, or DNA records. Personal Beliefs & Identity: Political opinions, religious or philosophical beliefs, racial or ethnic origin, and trade union memberships. Intimate Details: Sexual orientation or details regarding a person’s sex life.
  • Confidential and Performance-Related Data: As a manager you have complete access to this information, and it’s essential you know how and when to use it. Discretion is key. I can’t tell you the number of times I saw leads sharing productivity reports with an entire team, just out there in the open. This is a big, big no-no. We can’t just share this type of information because it can cause very deep emotional issues, legal problems, and team disruptions.
  • HR & Financial Details: Salary information, bonus allocations, bank details, government ID numbers (SSNs), and home addresses. Managerial Notes: Private 1:1 discussion logs, performance improvement plans (PIPs), disciplinary records, and grievance reports. Access Credentials: Passwords, API keys, security tokens, and administrative system access.

Property and Business Data

For these, most companies (or so I want to think) have implemented a strict NDA (Non-Disclosure Agreement) making you liable to penalties and much more drastic measures in case it’s broken.

  • Intellectual Property: Unreleased product specs, source code, trade secrets, and research.
  • Customer Data: Client lists, payment card details, contract terms, and user behavioral data.

The dangers of micromanagement while using employee tracking

With the advances of technology, unfortunately the human experience can also change in a less than pleasant way. In recent years, all sorts of employee tracking systems have been put to work in companies. While some are not that dangerous, some can have very real and very drastic effects.

A tracking system is software that allows the company to monitor any click, any movement, basically anything you do while working. I saw many of them across my tenure, some presented to upper management, some to clients, but they all had a single purpose: extract as much information about what the employee is doing as possible. Luckily, some countries have created specific laws and regulations to combat this, and depending on where you live you might be familiar with them. For example, in the EU these tools are a very sensitive topic: use is permitted under very strict circumstances and only if the employee agrees to them. Some jobs, of course, have this as a fundamental description due to the nature of said job (mostly around very critical or high-risk functions), but for day-to-day corporate work, things are less about special cases and more of a “if the employee agrees” scenario.

Now let’s say your team and company have this tracking system. The danger here is that between tracking and micromanagement we only have a very thin line, and we must take care not to step over it. It’s so simple when you have all these details about employees (clicks, time spent on tasks, breaks, pages viewed, non-productive time, etc.) to fall for the micromanagement impulse. This is not something you want to do as it is the exact opposite of core management principles. When we micromanage, we lose employee trust, we create a very bad working environment, and we set ourselves up for failure in the future.

This is why we need to be less tempted to use all of this information, even if we have it available. In cases where we must use it because reports and other processes depend on it, we should take extra steps to make sure we are avoiding the less than pleasant side effects.

Confidentiality like a Pro

We have established by now that as a leader you get access to all sorts of things: salary, feedback, 1-on-1s, performance, employee history, etc. These must be managed with a lot of care: don’t go around telling people left and right about them. One single slip of the tongue can have really nasty side effects, so mind it: keep things between yourself and the person in question.

Sometimes we might get into a very special, high-pressure type of situation and feel the temptation to share private conversations.

Don’t!

This was something private and should remain as such. This isn’t some type of court case where you are on the stand. While you might think it’s a good idea because it helps with whatever issue you have in the moment, the minute that’s over and people find out, they will never trust you again. You don’t want to be the blabbermouth boss who takes private conversations outside. The goal is for you to build trust with the team.

When someone is sharing data they should not, check your company’s internal rules: do not make exceptions, not even if it was a mistake and they did not know about it. The more you try to bury such scenarios, the worse it gets. Just be honest, check what to do according to your HR and compliance policies, and see if you can get this taken care of with minimal repercussions for the employee. Always remember to train your team on what sensitive data they manage and how to do it properly: who to share it with, what to ask in case of suspicion, who to talk to if they have questions, etc.

Sensitive performance metrics: the ethical way

When you think about performance, what comes to mind? What is performance to you?

Performance is everything an employee does compared to a set target, for example: 50 emails to answer per day minimum. As leaders we use performance metrics to establish how each person is doing and how close or far they are from these targets. Because this is a data-driven approach, we must take care not to be unethical. Remember: use data as a guide, not as a weapon. If a person is having a bad week or month, don’t immediately go for the jugular. Look at the context and help the person do better. Sometimes people just have bad days, and this doesn’t mean they should immediately be placed on a Performance Improvement Plan.

A common mistake new managers make is the tendency to look strictly at the numbers and nothing else. Evaluating people is as much an art as it is a science: you use the data to get the basic idea of what is going on, but you check the context to see if you have the full narrative. Sometimes good performance can mask very bad habits (cheating, non-compliance issues, etc.), and sometimes bad performance can be triggered by deeper underlying issues (flaws in the procedures, lack of training, improper workload balance, bias, etc.). Always check the context after reviewing data, and only then take action.

The hardest thing to do is navigating the evaluation process without bias and as fairly as possible. Listen, many LinkedIn posts will tell you this narrative: “it’s not OK to have a favorite when you lead.” While that’s all fine in theory, the reality is completely different: everyone has people they connect with more than others. How can we not? We are all human, and this is the most natural thing. The problem is how you separate your natural preference from the rest of the team to make sure you are evaluating everyone fairly.

Here is what I do:

  • I have a data-driven, performance-based framework covering all SLAs, KPIs, and anything that forms part of the quantitative and qualitative aspects of the team’s work.
  • I always share the approach with the team right as the new year starts: how the evaluation will go, what we look at, how I approach targets, expectations, etc.
  • Each quarter I send out an individual performance check, letting them know where they stand regarding the yearly evaluation.
  • Additional context, such as going 10% above 100%, is something I always share with the team: if someone is doing a great job and doing more than the rest, I make sure this is recognized publicly. This way we don’t have any surprises at the end of the year.
  • Monthly, I reinforce the same message: if you want a better evaluation, you need to show you are willing to put in the work.
  • I start working on the yearly evaluation right after the first 3 months and keep building from there. I do this to avoid being influenced positively or negatively by events in the last 1 to 2 months before year-end.

Keeping your team compliant and safe

As a leader, it’s your job to keep people compliant and safe. If you think the standard company training they need to complete (and probably pass using AI) is enough, you are very mistaken. You need to establish a solid structure for compliance and safety when dealing with data:

  • Ensure weekly checks with the team on how they are managing data.
  • Establish proper checks before any important or sensitive data is shared.
  • Host awareness sessions with them to talk through gray areas.
  • Do random audits to see if processes are being followed, and run refresher sessions if needed.

Another thing you must do is create an environment where people can be open about their mistakes: a true no-fear policy. If you create a safe place where people can come forward without fear of saying they made a mistake, you have won. If they are afraid to come clean, something you are doing is not working and needs to change ASAP.

All in all, this is a massive topic, but ethics and privacy are never easy, and we must do the best we can to make sure our teams are protected and decision-making remains fair.

Until next time, stay safe, healthy, and happy!

Scroll to Top