CSC323 Society and Ethics in Information Technology

Society and Ethics in Information TechnologyUnit 913 min read

Workplace Ethics: Monitoring, SLAs, Privacy & Professional Conduct

Unit 9 of Society and Ethics in Information Technology: explores ethical dilemmas in IT workplaces, including employee monitoring, service level agreements (SLAs), privacy rights, and professional conduct frameworks to balance productivity and individual rights.

TAKEAWAYS:

  • Workplace ethics in IT governs professional conduct, privacy, and accountability in digital work environments.
  • Service Level Agreements (SLAs) define measurable performance standards between IT providers and clients, ensuring reliability and accountability.
  • Electronic employee monitoring (e.g., keystroke logging, email tracking) raises privacy concerns but is justified for security and productivity.
  • Privacy laws (e.g., GDPR, Nepal’s Data Protection Act) protect employee data while allowing ethical monitoring for business needs.
  • Professional conduct codes (e.g., ACM Code of Ethics) guide ethical decision-making in IT careers.
  • Balancing monitoring and privacy requires transparency, consent, and proportionality to avoid ethical violations.

1. Introduction to Workplace Ethics in IT

Workplace ethics in IT refers to the moral principles and standards that govern behavior, decision-making, and professional conduct in technology-driven workplaces. Unlike general ethics, IT workplace ethics specifically addresses challenges like data privacy, monitoring, intellectual property, and accountability in digital environments.

Why Does It Matter?

  • Trust and reputation: Ethical misconduct (e.g., unauthorized monitoring) can destroy employer-employee trust and damage a company’s reputation.
  • Legal compliance: Many countries (e.g., Nepal’s Data Protection Act, 2075) mandate ethical handling of employee data.
  • Employee well-being: Unethical monitoring can lead to stress, anxiety, and reduced productivity.
  • Career growth: Ethical professionals are more likely to advance in leadership roles.

2. Service Level Agreements (SLAs): Definitions and Importance

An SLA is a formal contract between an IT service provider and a client (or employer) that defines:

  • Performance metrics (e.g., uptime, response time, error resolution).
  • Penalties for non-compliance (e.g., financial compensation for downtime).
  • Support levels (e.g., 24/7 helpdesk availability).
024.7549.574.2599Internal SLA (IT-HR)99External SLA (Vendor)95Customer SLA (Daraz)98
Average SLA compliance percentages for different types (hypothetical data based on real-world examples)

How SLAs Work

SLAs are measurable promises that ensure accountability. For example:

  • A bank’s IT department might guarantee 99.9% uptime for online transactions.
  • A cloud service provider (e.g., AWS) promises 99.95% availability for storage.

Types of SLAs

Type Description Example
Internal SLA Between departments (e.g., IT and HR) IT ensures HR’s payroll system is up 99% of the time.
External SLA Between a company and a third-party vendor (e.g., outsourced helpdesk) A Nepalese bank outsources customer support to a call center with an SLA for response time.
Customer SLA Between a company and its end-users (e.g., Daraz’s delivery promises) Daraz guarantees delivery within 2 days or refunds the order.

Why Are SLAs Important?

  • Ensures reliability: Clients know what to expect (e.g., Ncell’s 4G network uptime).
  • Reduces disputes: Clear terms prevent misunderstandings (e.g., Pathao’s ride cancellation policy).
  • Drives continuous improvement: Companies must meet SLAs, pushing them to innovate (e.g., eSewa’s fraud detection systems).

3. Electronic Employee Monitoring: Techniques and Ethical Dilemmas

Employee monitoring involves tracking employee activities (e.g., emails, internet use, keystrokes) to ensure productivity, security, and compliance. However, it raises privacy concerns.

Common Monitoring Techniques

flowchart TD
    A["Employee Monitoring Methods"] --> B["Keystroke Logging"]
    A --> C["Email/Chat Monitoring"]
    A --> D["Web/Browser Tracking"]
    A --> E["Time and Attendance Tracking"]
    A --> F["Camera Surveillance"]
  • Keystroke logging: Records every key pressed (used for security but can invade privacy).
  • Email monitoring: Checks work-related emails (e.g., banks monitoring fraud alerts).
  • Web tracking: Blocks non-work websites (e.g., NTC monitoring employee internet use).
  • Time tracking: Logs hours worked (e.g., freelancers using Toggl).
  • Camera surveillance: Used in call centers (e.g., Khalti’s customer service teams).
Aspect Pros Cons
Productivity Ensures employees focus on work. Can lead to distrust and burnout.
Security Prevents data leaks (e.g., NEPSE monitoring insider trading risks). May violate privacy laws (e.g., Nepal’s Data Protection Act).
Compliance Helps meet regulatory requirements (e.g., GDPR in multinational firms). Over-monitoring can discourage innovation.
Fairness Ensures equal treatment (e.g., no favoritism in promotions). False accusations can damage careers.

Real-World Example: NTC’s Employee Monitoring

Nepal Telecommunications Corporation (NTC) monitors employee internet use to:

  • Prevent cybersecurity threats (e.g., phishing).
  • Ensure productivity (e.g., blocking non-work sites during peak hours). However, employees argue that constant surveillance reduces morale.

4. Privacy in the Workplace: Laws and Best Practices

Privacy in the workplace is protected by laws and ethical guidelines to prevent misuse of personal data.

classDiagram
    class DataProtectionAct {
        +Prohibits unauthorized data collection
        +Requires employee consent
    }
    class GDPR {
        +Right to erasure
        +Transparency obligations
    }
    class FCRA {
        +Regulates credit checks
    }
    DataProtectionAct --> GDPR : "Inspired by"
    GDPR --> FCRA : "Stricter standards"
Legal framework comparison for workplace privacy laws

Key Privacy Laws

Country/Region Law Key Provisions
Nepal Data Protection Act, 2075 Prohibits unauthorized collection of employee data; requires consent.
EU General Data Protection Regulation (GDPR) Strict rules on data storage, right to erasure, and transparency.
USA Fair Credit Reporting Act (FCRA) Regulates credit checks for employment.

Best Practices for Ethical Monitoring

  1. Transparency: Inform employees why and how they are being monitored.
  2. Consent: Get explicit agreement before monitoring (e.g., eSewa’s fraud detection policies).
  3. Proportionality: Monitor only what is necessary (e.g., Ncell tracking only high-risk employees).
  4. Data Security: Protect collected data from breaches (e.g., banks encrypting employee records).
  5. Employee Rights: Allow access to monitored data if requested (e.g., NEPSE’s whistleblower policies).

5. Professional Conduct Codes in IT

Professional conduct codes (e.g., ACM Code of Ethics, IEEE Ethics) guide IT professionals in making ethical decisions.

Key Principles of Ethical Conduct

mindmap
  root((Professional Conduct Codes))
    child_link(ACM Code of Ethics, "1. Public: Serve society, avoid harm")
    child_link(IEEE Ethics, "2. Client/Employer: Act in their best interest")
    child_link(General Principles, "3. Product: Ensure quality and safety")
    child_link(Professionalism, "4. Judgment: Avoid conflicts of interest")
    child_link(Management, "5. Improve competence: Stay updated")
    child_link(Colleagues, "6. Respect others' work")

Example: ACM Code of Ethics

  1. Public Interest: IT professionals must prioritize societal well-being (e.g., Pathao ensuring safe ride-sharing).
  2. Client/Employer: Avoid conflicts of interest (e.g., Khalti not promoting competing payment apps).
  3. Product: Ensure software reliability (e.g., banks testing for bugs before launch).
  4. Judgment: Make decisions based on ethics, not profit (e.g., NEPSE whistleblowing policies).
  5. Management: Promote ethical leadership (e.g., NTC’s cybersecurity training).
  6. Profession: Uphold integrity (e.g., eSewa’s anti-fraud measures).

6. Balancing Monitoring and Privacy: A Case Study

Scenario: Daraz’s Employee Monitoring vs. Privacy

Issue: Daraz monitors warehouse workers’ efficiency but concerns arise about excessive surveillance.

Ethical Analysis:

Aspect Monitoring Justification Privacy Concern
Productivity Ensures on-time deliveries (SLA compliance). Workers feel constant pressure.
Security Prevents theft of inventory. No clear policy on data retention.
Fairness Ensures equal treatment across shifts. No employee feedback on monitoring.

Solution:

  • Transparency: Inform workers why they are monitored (e.g., SLA requirements).
  • Consent: Allow workers to opt out of certain monitoring (e.g., camera-free zones).
  • Proportionality: Monitor only critical tasks (e.g., inventory scanning, not personal chats).

7. Worked Example: Calculating SLA Penalties

Scenario: A Ncell customer experiences 3 hours of downtime in a month. Ncell’s SLA guarantees 99.9% uptime (allowing 4.32 hours/year of downtime).

Calculation:

  1. Allowed downtime per year: (Ncell’s SLA allows 4.32 hours/month for 99.99% uptime.)
  2. Actual downtime: 3 hours (exceeds allowance).
  3. Penalty: Ncell offers a 10% discount on the next bill as compensation.

Lesson: SLAs protect customers while holding providers accountable.


8. Exam Tip: How to Score Full Marks

  1. Define clearly: Start with precise definitions (e.g., "An SLA is a contractual agreement...").
  2. Use real examples: Relate concepts to Nepalese companies (e.g., NTC, Daraz, eSewa).
  3. Compare pros/cons: For monitoring, list advantages and disadvantages in a table.
  4. Apply ethical theories: Link monitoring to utilitarianism (greatest good) or deontology (duty-based).
  5. Discuss legal compliance: Mention Nepal’s Data Protection Act or GDPR where relevant.
  6. Solve numerical problems: Practice SLA downtime calculations (as shown above).

Common Pitfalls to Avoid:

  • ❌ Vague answers: "Monitoring is bad" → Explain why (e.g., "It violates GDPR").
  • ❌ Ignoring legal aspects: Always mention laws when discussing privacy.
  • ❌ Overgeneralizing: Specify types of SLAs (internal vs. external).

In the Real World

  1. eSewa’s Fraud Detection

    • Idea: Uses real-time transaction monitoring to detect fraud (SLA: 99.9% fraud-free transactions).
    • How: Tracks unusual patterns (e.g., multiple large transfers in a short time).
    • Ethics: Employees are monitored for compliance, but customer data is encrypted.
  2. Ncell’s Network Uptime SLAs

    • Idea: Guarantees 99.9% 4G coverage in Kathmandu.
    • How: Monitors network nodes and customer complaints.
    • Ethics: Employees are penalized for downtime, but customer data is anonymized.
  3. Pathao’s Driver Monitoring

    • Idea: Uses GPS tracking to ensure safe routes.
    • How: Alerts drivers for unsafe areas (e.g., traffic jams).
    • Ethics: Drivers consent to tracking, but personal chats are private.

Visual Summary

IMAGE: service level agreement contract template | Example of an SLA document used by Nepalese banks

This shows how SLAs are legally binding and include penalties for breaches.

IMAGE: employee monitoring software dashboard | Example of a keystroke logging tool used in call centers

Highlights how monitoring tools track activity, raising privacy concerns.

IMAGE: ACM Code of Ethics infographic | Visual representation of ethical principles for IT professionals

Helps students remember key guidelines for professional conduct.


Final Note: Workplace ethics in IT is not just about rules—it’s about balancing productivity, security, and human dignity. Always consider the real-world impact of your decisions!

In the real world

  • eSewa uses SLAs to guarantee transaction uptime (99.9% during peak hours like Dashain), with financial penalties for downtime. If the system fails, users get refunds or credits.
  • NTC monitors employee internet use to block non-work sites (e.g., social media during work hours) but faces backlash for over-monitoring, violating the Data Protection Act, 2075 if not transparent.
  • Khalti implements keystroke logging for fraud detection (e.g., tracking unusual transaction patterns) but must comply with GDPR for international users, requiring clear consent policies.

Based on the TU BSc CSIT syllabus for Society and Ethics in Information Technology (CSC323), unit 9.

Discussion

Loading…