An arbitrator has partially upheld the Queen’s University Faculty Association’s (QUFA) grievance over the University’s mandatory Endpoint Protection software.
The ruling, issued Nov. 7 by sole arbitrator William Kaplan, follows a Nov. 4 hearing in Kingston and responds to QUFA’s June 25 grievance claiming the University’s device security requirements were unreasonable, infringed privacy rights, and violated provisions of the Collective Agreement.
READ MORE: Faculty files grievance against University
The union argued the University’s rollout of Endpoint—a requirement that faculty, librarians, and archivists install Microsoft Defender for Endpoint and Intune on any device used for work—failed to balance cybersecurity needs with members’ privacy. QUFA said the policy risked granting Queen’s access to personal devices and contravened protections around discipline, privacy, and academic freedom under Articles 20, 23, and 14 of the Collective Agreement.
In his decision, Kaplan directed the University to reimburse faculty under Article 36.3 for purchasing Queen’s funded devices. Term Adjunct faculty must also be reimbursed for eligible purchases and will no longer be required to install Endpoint on personal devices. Instead, they’ll use alternative “compensating security measures,” such as more frequent authentication or access restrictions.
The ruling further establishes a new Standing Joint Committee on Technology (SJCT), consisting of QUFA-appointed faculty members, the University’s Chief Information Officer, and representatives from the Provost’s office. The committee will meet quarterly beginning January 2026 to review technology that affects QUFA members’ working conditions.
Kaplan ordered the SJCT to revise the University’s Endpoint FAQs to ensure “clear, accurate, and comprehensive” information, with Queen’s required to consider QUFA’s recommendations in good faith. The University must also provide quarterly reports to the committee detailing every instance in which Endpoint identified a security threat requiring analyst intervention.
The decision also requires Queen’s IT Services to host in-person information sessions at least four months before introducing any “transformative technological requirements.” The sessions must meaningfully address questions from faculty and be discussed through SJCT and the Joint Committee to Administer the Agreement (JCAA).
Queen’s must also consults QUFA before finalizing several major technology and monitoring policies—including the new Exceptional Access Authorization Procedure, which replaces the 2014 Access Authorization Procedure—and upcoming cybersecurity and electronic monitoring policies.
Within 30 days, both parties must attempt to jointly select a third-party provider to conduct a fresh Privacy Impact Assessment of Microsoft Defender, Intune, and Assessment as used in the Endpoint system. If they can’t agree, Kaplan will choose from a list of potential assessors submitted by both sides.
Tags
Endpoint Protection, grievance, QUFA
All final editorial decisions are made by the Editor(s) in Chief and/or the Managing Editor. Authors should not be contacted, targeted, or harassed under any circumstances. If you have any grievances with this article, please direct your comments to eic@queensjournal.ca.