Employee Data Privacy: Employer Obligations by State (2026)
Employers collect vast amounts of personal data about their workers: Social Security numbers, health information, biometric scans, location data, email contents, web browsing history, and increasingly, behavioral analytics from AI-powered monitoring tools. The legal framework governing what employers can and cannot do with this data varies dramatically by state, creating a compliance challenge for multi-state employers and genuine confusion for employees about their rights.
Federal Employee Privacy Laws
While no single federal statute comprehensively addresses employee data privacy, several federal laws establish baseline protections.
Electronic Communications Privacy Act (ECPA)
The Electronic Communications Privacy Act of 1986 (18 USC 2510-2522) is the primary federal law governing employer monitoring of employee electronic communications. The ECPA generally prohibits intercepting electronic communications, but two exceptions make employer monitoring broadly permissible:
The consent exception. If an employee consents to monitoring, the interception is lawful. Most employers obtain consent through employee handbooks, acceptable use policies, or login banners stating that communications on company systems are subject to monitoring.
The business use exception (provider exception). An employer that provides the communications system (email servers, phone systems, company computers) can monitor communications conducted on those systems for legitimate business purposes. Courts have interpreted this exception broadly, allowing employers to monitor email, internet usage, and chat messages on company-provided devices and networks.
The ECPA does limit monitoring of purely personal communications even on company systems, though the boundaries of this limitation are fact-specific and vary by circuit.
Stored Communications Act (SCA)
The Stored Communications Act (18 USC 2701-2712), part of the ECPA, governs access to stored electronic communications. Under the SCA, employers generally can access emails stored on company servers. However, accessing an employee's personal email account (Gmail, Yahoo) without authorization violates the SCA, even if accessed from a company computer.
Americans with Disabilities Act (ADA)
The ADA restricts employer collection and use of medical information. Employers may not make disability-related inquiries or require medical examinations unless they are job-related and consistent with business necessity (42 USC 12112(d)). Medical records must be maintained in separate, confidential files with restricted access.
Genetic Information Nondiscrimination Act (GINA)
GINA (42 USC 2000ff) prohibits employers from requesting, requiring, or purchasing genetic information about employees or their family members, with narrow exceptions. Genetic information includes family medical history, genetic test results, and the fact that someone has sought genetic services. Violations can result in enforcement by the EEOC.
Fair Credit Reporting Act (FCRA)
The FCRA (15 USC 1681 et seq.) regulates employer use of background checks obtained from consumer reporting agencies. Before obtaining a background check, employers must provide written disclosure and obtain the employee's or applicant's written authorization (15 USC 1681b(b)(2)). If the employer takes adverse action based on the report, they must provide a copy of the report and a description of the consumer's rights before the action takes effect (15 USC 1681b(b)(3)).
Workplace Monitoring by State
Email and Computer Monitoring
Federal law permits workplace computer monitoring with minimal restrictions. State laws add modest requirements:
Connecticut (Conn. Gen. Stat. 31-48d) is the most protective state. Employers must give prior written notice to employees before monitoring email or internet activity. The notice must describe the types of monitoring that may occur. Failing to provide notice before monitoring violates the statute.
Delaware (Del. Code tit. 19, 705) similarly requires employers to provide advance electronic notice of monitoring at least one time. The notice must be acknowledged by the employee.
New York enacted the New York Civil Rights Law Section 52-c*2 effective May 7, 2022, requiring employers that monitor telephone calls, email, or internet access to provide prior written notice upon hiring. The notice must be posted in a conspicuous place and acknowledged in writing by the employee.
In all other states, employer monitoring of company-provided email and devices is largely unrestricted under federal law, provided the employer has not created a reasonable expectation of privacy (typically negated through handbook policies and login banners).
Biometric Data Collection
Biometric privacy is one of the fastest-evolving areas of employee data law. Several states have enacted specific statutes governing employer collection of fingerprints, facial geometry, retinal scans, voiceprints, and other biometric identifiers.
Illinois Biometric Information Privacy Act (BIPA). 740 ILCS 14 is the most significant biometric privacy law in the country because it provides a private right of action with statutory damages. Under BIPA, employers must:
- Provide written notice of the biometric data being collected and the purpose
- Obtain a written release from the employee before collection
- Publish a retention schedule and destruction guidelines
- Not sell, lease, trade, or profit from biometric data
Statutory damages are $1,000 per negligent violation and $5,000 per intentional or reckless violation. Following the Illinois Supreme Court's 2023 ruling in Cothron v. White Castle, each individual scan or collection event constitutes a separate violation. This has generated billions of dollars in potential exposure for employers using biometric timekeeping systems. A 2024 amendment capped damages at one violation per employee per method of collection in response.
Texas (Tex. Bus. & Com. Code 503.001) prohibits capturing biometric identifiers for commercial purposes without consent. Unlike Illinois, Texas does not provide a private right of action; enforcement lies with the Texas Attorney General, who can seek penalties of up to $25,000 per violation.
Washington (RCW 19.375) restricts commercial use of biometric identifiers and requires notice and consent. Enforcement is through the Washington Attorney General.
Additional states: Colorado, Virginia, Connecticut, and other states with comprehensive privacy laws include biometric data as "sensitive data" requiring consent for processing, though these laws generally do not provide private rights of action.
Social Media Password Laws
A growing number of states prohibit employers from requesting or requiring employees or job applicants to disclose social media login credentials. As of early 2026, at least 28 states have enacted such laws, including:
| State | Statute | Key Provisions |
|---|---|---|
| California | Lab. Code 980 | Prohibits requesting social media usernames or passwords; prohibits retaliation |
| Illinois | 820 ILCS 55 | Prohibits requesting access; covers applicants and employees |
| Maryland | Lab. & Empl. 3-712 | First state to pass such a law (2012); prohibits requiring disclosure |
| New Jersey | N.J.S.A. 34:6B-5 | Prohibits requiring access to personal social media accounts |
| Oregon | ORS 659A.330 | Prohibits requiring disclosure; includes civil penalty provisions |
These laws generally prohibit employers from: requesting login credentials, requiring employees to log in to personal accounts in the employer's presence, requiring employees to add the employer or its agents to their contacts, and retaliating against employees who refuse to comply.
GPS and Location Tracking
Employer tracking of employee location raises distinct legal issues depending on whether the tracking occurs on company-owned or personal devices and vehicles.
Company vehicles and devices. Employers generally can track company-owned vehicles and devices without specific employee consent under federal law. The reasoning parallels the ECPA business use exception: the employer owns the equipment.
Personal vehicles. Several states restrict or prohibit employer GPS tracking of employees' personal vehicles:
- California courts have held that tracking an employee's personal vehicle without consent can constitute an invasion of privacy under the California Constitution.
- New York (N.Y. Penal Law 158.10) criminalizes the use of GPS devices to track another person without consent, which courts have applied to employer-employee contexts involving personal vehicles.
- Texas (Tex. Penal Code 16.06) prohibits installing tracking devices on vehicles owned or leased by another person without consent.
Off-duty tracking. Even where GPS tracking of company vehicles is legal, tracking employees during non-work hours raises additional concerns. California, Colorado, and New York courts have recognized employee privacy interests in off-duty location data, and several proposed state bills would explicitly restrict off-hours tracking.
Drug Testing
Drug testing privacy varies significantly by state:
- Random testing: Some states (Vermont, Connecticut, Minnesota, Montana, Rhode Island) restrict random drug testing to safety-sensitive positions only.
- Marijuana protections: As marijuana legalization expands, a growing number of states (California, New York, New Jersey, Montana, Nevada, Washington) prohibit employers from taking adverse action based on off-duty marijuana use or positive THC tests, with exceptions for safety-sensitive positions and federal requirements.
- Notice requirements: Many states require advance written notice of drug testing policies and procedures.
CCPA Employee Data Rights
The CCPA originally included a moratorium on employee data rights, which expired on January 1, 2023. California employees now have the same rights as consumers under the CCPA/CPRA, including:
- Right to know what personal information the employer collects and how it is used
- Right to delete personal information (subject to exceptions for legal obligations and employment administration)
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use of sensitive personal information
- Right to non-retaliation for exercising these rights
Under Cal. Civ. Code 1798.100, employers must provide a privacy notice to employees at or before the point of collection describing the categories of personal information collected and the purposes for each category. This is separate from the public-facing privacy policy and must address the employment context specifically.
The practical impact has been significant. Large California employers have had to build new intake systems for employee data requests, train HR departments on response procedures, and audit the flow of employee data to third parties (payroll processors, benefits administrators, background check vendors).
Common Law Privacy Torts
Beyond statutory protections, employees may bring common law tort claims against employers for privacy violations. The four traditional privacy torts, as defined in the Restatement (Second) of Torts, are:
Intrusion upon seclusion. An employer invades an employee's privacy by intentionally intruding into a matter in which the employee has a reasonable expectation of privacy. Courts have found intrusion claims viable for: searching personal belongings without cause, hidden camera surveillance in restrooms or changing areas, and accessing personal email accounts without authorization.
Public disclosure of private facts. An employer publishes embarrassing private facts about an employee. Examples include disclosing medical conditions, sharing salary information publicly (in states without pay transparency laws), or revealing the results of drug tests.
False light. An employer publishes information that places an employee in a false light. This is less common in the employment context but can arise from misleading characterizations in references or public statements.
Appropriation of name or likeness. An employer uses an employee's name or image for commercial purposes without consent. This has become more relevant with employer social media practices and the use of employee images in marketing materials.
These common law claims are available in most states and exist independently of statutory protections. They provide a legal basis for employees to challenge privacy violations even in states without specific employee privacy statutes.
Emerging Issues
AI-Powered Workplace Monitoring
The use of AI tools to monitor employee productivity, analyze communications, and predict behavior is growing rapidly. Keystroke logging, screen capture, sentiment analysis of messages, and even webcam-based "attention tracking" are now commercially available. Few existing laws directly address AI workplace monitoring, though:
- Colorado's AI Act (SB 205, effective February 2026) requires employers to notify employees when AI is used in consequential decisions affecting employment.
- Illinois' AI Video Interview Act (820 ILCS 42) requires employers to provide notice and obtain consent before using AI to analyze video interviews, and to destroy videos within 30 days of a request.
- The FTC has warned that surveillance-based management practices may constitute unfair practices under Section 5.
Reproductive Health Privacy
Following Dobbs v. Jackson Women's Health Organization (2022), several states enacted laws protecting employee reproductive health data. Washington, California, and Illinois have enacted or proposed legislation restricting employer access to reproductive health information and prohibiting adverse employment actions based on reproductive health decisions.
Sources and References
This article provides general legal information about employee data privacy across US jurisdictions. Employment law varies by state and changes frequently. Consult an attorney for advice specific to your situation.
Frequently Asked Questions
Can my employer read my work emails?
Under federal law (ECPA), employers can generally monitor email on company-provided systems under the business use exception and consent exception. Most employers establish monitoring rights through acceptable use policies and handbook acknowledgments. Connecticut, Delaware, and New York require prior written notice before monitoring. Personal email accounts are protected by the Stored Communications Act even when accessed on work devices.
Can an employer require fingerprint scans for timekeeping?
Yes, but state law may require consent and notice. Illinois BIPA requires written notice and a signed release before collecting biometric data, with statutory damages of $1,000-$5,000 per violation. Texas and Washington also require consent. In states without specific biometric laws, employers generally can require biometric timekeeping, though employees may have common law privacy claims.
Can my employer ask for my social media password?
At least 28 states prohibit employers from requesting social media login credentials from employees or applicants. These laws also prohibit requiring employees to log in while the employer watches, adding the employer to contacts, or retaliating against refusal. In states without such laws, no federal statute specifically prohibits the request, though the Stored Communications Act may apply.
Does the CCPA apply to employee data in California?
Yes. The employee data exemption expired January 1, 2023. California employees now have full CCPA/CPRA rights including the right to know, delete, correct, and opt out of sale of personal information. Employers must provide a privacy notice at the point of collection and respond to employee data requests within 45 days.
Can my employer track my location with GPS?
Tracking company-owned vehicles and devices is generally legal under federal law. Tracking personal vehicles without consent is restricted or prohibited in several states including California, New York, and Texas. Off-duty tracking of employees raises additional privacy concerns even with company vehicles, and several states are considering legislation to restrict after-hours location monitoring.
Can employers conduct random drug tests?
Federal law does not prohibit random drug testing, but several states (Vermont, Connecticut, Minnesota, Montana, Rhode Island) restrict random testing to safety-sensitive positions. A growing number of states also prohibit adverse action based on off-duty marijuana use or positive THC tests, including California, New York, and New Jersey, with exceptions for safety-sensitive roles.
What federal laws protect employee medical information?
The ADA prohibits disability-related inquiries and medical examinations unless job-related and consistent with business necessity. Medical records must be kept in separate confidential files. GINA prohibits employers from requesting genetic information. HIPAA does not directly regulate employers but does restrict the health plans they sponsor. State laws often add further protections for employee medical data.
Can employers use AI to monitor employee performance?
No federal law specifically prohibits AI-powered employee monitoring, though the FTC has signaled that excessive surveillance may constitute unfair practices. Colorado's AI Act (effective February 2026) requires notice when AI influences employment decisions. Illinois requires consent for AI analysis of video interviews. Expect more state legislation in this area in the coming years.
Updates
Governing law re-checked for recent changes
Corrected the FCRA citation for background-check disclosure, authorization, and pre-adverse-action requirements: those rules come from 15 U.S.C. § 1681b(b)(2)-(3), not § 1681 (which is only the Act's congressional findings and statement of purpose).
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 8 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.100In forcecited in 4 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Privacy Policy Requirements: What You Must Include (2026), Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules
California Labor Code
§ 980In forcecited in 2 of our articles
(a) As used in this chapter, “social media” means an electronic service or account, or electronic content, including, but not limited to, videos, still photographs, blogs, video blogs, podcasts, instant and text messages, email, online services or accounts, or Internet Web site profiles or locations. (b) An employer shall not require or request an employee or applicant for employment to do any of the following: (1) Disclose a username or password for the purpose of accessing personal social media. (2) Access personal social media in the presence of the employer. (3) Divulge any personal social media, except as provided in subdivision (c). (c) Nothing in this section shall affect an employer’s existing rights and obligations to request an employee to divulge personal social media reasonably believed to be relevant to an investigation of allegations of employee misconduct or employee violation of applicable laws and regulations, provided that the social media is used solely for purposes of that investigation or a related proceeding.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
Also relied on in: California Employee Monitoring Laws: Employer Rules (2026)
Connecticut General Statutes, Title 31 (Labor), Chapter 557
§ 31-48dEmployers engaged in electronic monitoring required to give prior notice to employees. Exceptions. Civil penalty.In forcecited in 17 of our articles
(a) As used in this section: (1) “Employer” means any person, firm or corporation, including the state and any political subdivision of the state which has employees; (2) “Employee” means any person who performs services for an employer in a business of the employer, if the employer has the right to control and direct the person as to (A) the result to be accomplished by the services, and (B) the details and means by which such result is accomplished; and (3) “Electronic monitoring” means the collection of information on an employer's premises concerning employees' activities or communications by any means other than direct observation, including the use of a computer, telephone, wire, radio, camera, electromagnetic, photoelectronic or photo-optical systems, but not including the collection of information (A) for security purposes in common areas of the employer's premises which are held out for use by the public, or (B) which is prohibited under state or federal law.
Official text (excerpt) · as of 2026-07-29 · Read the full section at cga.ct.gov
Also relied on in: Employer Guide to Wearable Recording Device Policies (2026), Connecticut Audio Recording Laws: Mixed Consent Rules and Penalties (2026), Connecticut Dashcam Laws: Mounting Rules, Audio Recording, and Evidence (2026)
United States Code Title 15
§ 1681Congressional findings and statement of purposeIn forcecited in 11 of our articles
The Congress makes the following findings: The banking system is dependent upon fair and accurate credit reporting. Inaccurate credit reports directly impair the efficiency of the banking system, and unfair credit reporting methods undermine the public confidence which is essential to the continued functioning of the banking system. An elaborate mechanism has been developed for investigating and evaluating the credit worthiness, credit standing, credit capacity, character, and general reputation of consumers. Consumer reporting agencies have assumed a vital role in assembling and evaluating consumer credit and other information on consumers. There is a need to insure that consumer reporting agencies exercise their grave responsibilities with fairness, impartiality, and a respect for the consumer’s right to privacy.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Also relied on in: Background Check Laws by State (2026 Guide), How to Opt Out of Data Brokers (2026), FTC Fines Amazon $2.25 Million for Denying Identity-Theft Victims Their Fraud Records Under the FCRA
§ 1681bPermissible purposes of consumer reportsIn forcecited in 2 of our articles
Subject to subsection (c), any consumer reporting agency may furnish a consumer report under the following circumstances and no other: In response to the order of a court having jurisdiction to issue such an order, a subpoena issued in connection with proceedings before a Federal grand jury, or a subpoena issued in accordance with section 5318 of title 31 or section 3486 of title 18. In accordance with the written instructions of the consumer to whom it relates. To a person which it has reason to believe— intends to use the information in connection with a credit transaction involving the consumer on whom the information is to be furnished and involving the extension of credit to, or review or collection of an account of, the consumer; or intends to use the information for employment purposes; or intends to use the information in connection with the underwriting of insurance involving the consumer; or intends to use the information in connection with a determination of the consumer’s eligibility for a license or other benefit granted by a governmental instrumentality required by law to consider an applicant’s financial responsibility or status; or intends to use the information,…
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Also relied on in: New York's Clean Slate Act Takes Effect: Millions of Old Convictions Now Seal Automatically
United States Code Title 42
§ 12112DiscriminationIn force
No covered entity shall discriminate against a qualified individual on the basis of disability in regard to job application procedures, the hiring, advancement, or discharge of employees, employee compensation, job training, and other terms, conditions, and privileges of employment. As used in subsection (a), the term “discriminate against a qualified individual on the basis of disability” includes— limiting, segregating, or classifying a job applicant or employee in a way that adversely affects the opportunities or status of such applicant or employee because of the disability of such applicant or employee; participating in a contractual or other arrangement or relationship that has the effect of subjecting a covered entity’s qualified applicant or employee with a disability to the discrimination prohibited by this subchapter (such relationship includes a relationship with an employment or referral agency, labor union, an organization providing fringe benefits to an employee of the covered entity, or an organization providing training and apprenticeship programs); utilizing standards, criteria, or methods of administration— that have the effect of discrimination on the basis of…
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
§ 2000ffDefinitionsIn force
In this chapter: The term “Commission” means the Equal Employment Opportunity Commission as created by section 2000e–4 of this title. The term “employee” means— an employee (including an applicant), as defined in section 2000e(f) of this title; a State employee (including an applicant) described in section 2000e–16c(a) of this title; a covered employee (including an applicant), as defined in section 1301 of title 2; a covered employee (including an applicant), as defined in section 411(c) of title 3; or an employee or applicant to which section 2000e–16(a) of this title applies. The term “employer” means— an employer (as defined in section 2000e(b) of this title); an entity employing a State employee described in section 2000e–16c(a) of this title; an employing office, as defined in section 1301 of title 2; an employing office, as defined in section 411(c) of title 3; or an entity to which section 2000e–16(a) of this title applies. The terms “employment agency” and “labor organization” have the meanings given the terms in section 2000e of this title. The term “member”, with respect to a labor organization, includes an applicant for membership in a labor organization.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Texas Business & Commerce Code
§ 503.001CAPTURE OR USE OF BIOMETRIC IDENTIFIERIn forcecited in 8 of our articles
(a) In this section: (1) "Artificial intelligence system" has the meaning assigned by Section 551.001. (2) "Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry. (b) A person may not capture a biometric identifier of an individual for a commercial purpose unless the person: (1) informs the individual before capturing the biometric identifier; and (2) receives the individual's consent to capture the biometric identifier. (b-1) For purposes of Subsection (b), an individual has not been informed of and has not provided consent for the capture or storage of a biometric identifier of an individual for a commercial purpose based solely on the existence of an image or other media containing one or more biometric identifiers of the individual on the Internet or other publicly available source unless the image or other media was made publicly available by the individual to whom the biometric identifiers relate.
Official text (excerpt) · as of 2026-07-28 · Read the full section at statutes.capitol.texas.gov
Also relied on in: Amazon Ring Sued Over "Familiar Faces" Facial Recognition (2026), Alabama Smart Glasses Recording Laws, Oklahoma Smart Glasses Recording Laws 2026
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Electronic Communications Privacy Act (18 USC 2510-2522)(law.cornell.edu)
- Stored Communications Act (18 USC 2701-2712)(law.cornell.edu)
- ADA Overview(ada.gov).gov
- ADA Employment Provisions (42 USC 12112)(law.cornell.edu)
- GINA (42 USC 2000ff)(law.cornell.edu)
- FCRA Congressional Findings (15 USC 1681)(law.cornell.edu)
- Connecticut Employee Monitoring Law (Conn. Gen. Stat. 31-48d)(cga.ct.gov).gov
- Illinois BIPA (740 ILCS 14)(ilga.gov).gov
- Texas Biometric Identifier Act (Tex. Bus. & Com. Code 503.001)(statutes.capitol.texas.gov).gov
- California Labor Code 980 (Social Media Passwords)(leginfo.legislature.ca.gov).gov
- CCPA Section 1798.100(leginfo.legislature.ca.gov).gov
- Illinois AI Video Interview Act (820 ILCS 42)(ilga.gov).gov
- Washington Biometric Identifiers (RCW 19.375)(app.leg.wa.gov).gov
- FCRA Background Check Disclosure & Pre-Adverse-Action Rules (15 USC 1681b)(law.cornell.edu)