A professional employer organization supporting payroll, benefits, HR, workers’ compensation, retirement, and compliance needs access to substantial employee information.
Trion Solutions documents that data footprint in its Worksite Employee Privacy Policy.
The policy applies to information collected about worksite employees and can also cover information concerning dependents and beneficiaries when relevant to employment or benefits administration.
Identity Information
Trion’s policy identifies categories such as:
name;
Social Security number;
date of birth;
driver’s-license or identification information;
passport information;
employee identification numbers;
contact information.
These records can be relevant to payroll, tax, onboarding, benefits, and employment administration.
Banking and Financial Information
The policy also lists financial information, including bank-account information used for direct deposit.
This makes payroll-account security particularly important.
An employee portal containing banking details should be treated like a sensitive financial account.
Payroll and Employment Records
Trion identifies employment-related information including:
onboarding records;
I-9 and tax forms;
time and attendance;
leave records;
workplace injury records;
performance and discipline records;
compensation;
benefits;
retirement and 401(k);
COBRA;
payroll.
This breadth reflects Trion’s role across several HR functions.
Medical and Health Information Can Be Involved
Employment administration can require medical information in limited contexts.
Trion’s policy gives examples including work restrictions, leave records, accommodation processes, and benefit-related information.
Employees should therefore use designated secure processes when sending medical documentation.
A normal email chain or public support form is not an appropriate substitute.
Timekeeping Can Generate Geolocation
One of the more specific disclosures concerns geolocation.
Trion states that certain timekeeping applications may record an IP address or GPS location associated with employee clock-in or clock-out events.
That does not mean every Trion client uses GPS timekeeping.
It means employees should understand the configuration used by their own workplace.
Portal and Device Information
The policy also describes account, portal, mobile-device, system-access, and usage information.
Trion specifically references the PrismHR environment in connection with online-portal security.
PrismHR separately describes role-based access and employee self-service as core parts of its portal platform.
Information Can Move to Several Categories of Provider
Trion’s policy identifies categories of recipients that can include:
financial institutions;
government agencies;
benefit and retirement administrators;
workers’ compensation and unemployment administrators;
insurance providers;
payroll and timekeeping vendors;
HRIS providers;
the worksite employer;
IT and cybersecurity providers.
An employee record can therefore participate in a network of systems rather than one database.
Trion States It Does Not Sell Employee Data for Money
The Worksite Employee Privacy Policy states that Trion does not sell worksite employee personal information for monetary or other valuable consideration and does not share it for cross-context behavioral advertising.
That statement belongs to Trion’s published policy and should be read together with the rest of that policy and any later updates.
Retention Is Not One Universal Number
Trion’s policy says employee information is retained according to its retention schedule and that relevant business purposes, legal recordkeeping requirements, statutes of limitation, and preservation obligations can affect the retention period.
Different record categories may therefore remain for different periods.
Protect Your Employee Account
Trion’s policy tells worksite employees not to disclose passwords used for payroll and timekeeping systems to third parties.
Employees should also be cautious with:
authentication codes;
bank details;
Social Security numbers;
W-2s;
medical records.
An unsolicited request for those items should be independently verified.
Privacy Questions Depend on Where You Live
The Trion policy contains rights language associated with applicable consumer privacy laws.
Specific employee privacy rights can vary by state.
Use the current policy and applicable state-law resources when you need to exercise a formal privacy right rather than relying on a generalized article.
Know Why the Data Is Being Requested
Before providing sensitive information, ask:
Which employment function requires it?
Which system will receive it?
Who is requesting it?
How was the request delivered?
Is this the normal employer/Trion process?
PEO administration legitimately requires substantial personal information.
That makes verification of the collection channel more important, not less.
Internal Link Suggestions: