Back to Blog
Compliance GuidesMarch 29, 202615 min readReviewed by the PrivacyLawMap editorial teamLast reviewed June 15, 2026

Workplace Privacy Laws by State 2026: Employee Data Compliance Guide

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

Quick answer

As of June 15, 2026, only California fully extends consumer privacy rights to employee data — the CCPA's HR exemption expired December 31, 2022. Other comprehensive privacy laws usually exclude employment-context data. Separate workplace privacy laws still matter: Illinois BIPA covers workplace biometrics with $1,000–$5,000 per violation and a private right of action; New York, Connecticut, and Delaware require advance notice of electronic monitoring; New York City requires annual bias audits and notices for automated employment decision tools; Colorado SB 26-189 reaches covered ADMT used for employment-opportunity decisions starting January 1, 2027.

Do State Privacy Laws Protect Employee Data?

If you're a business owner or HR professional, you might assume that the wave of state privacy laws sweeping the US applies only to customer data. For most states, you'd be right — but the exceptions are significant and growing.

Understanding the employee data privacy landscape is critical because getting it wrong can result in lawsuits, regulatory fines, and eroded employee trust. This guide breaks down which state privacy laws cover employee data, what obligations they create, and how to build a compliance framework for workplace information.

Workplace Privacy Laws by State at a Glance (June 15, 2026)

For HR teams, the practical question is not just "does a comprehensive privacy law apply?" It is which workplace data stream triggers a concrete obligation. This matrix separates full employee personal-information coverage from narrower monitoring, biometric, and automated-employment-tool rules.

State / law Employee data covered What HR should do first
California CCPA/CPRAEmployment-related personal information is in scope for covered businesses because the statutory HR and B2B exemptions expired December 31, 2022.Give notice at collection, map HR data, support employee DSARs, and document sensitive-data use limits.
Illinois BIPABiometric identifiers and biometric information, including workplace fingerprints, hand scans, face geometry, and voiceprints.Get a written release before collection, publish a retention/destruction policy, and avoid sharing biometric data unless a statutory condition applies.
New York Civil Rights Law § 52-cTelephone, email, and internet-access monitoring by private employers with a New York place of business.Give prior written notice on hiring and post the monitoring notice where affected employees can see it.
Connecticut Gen. Stat. § 31-48dElectronic monitoring of employees' activities or communications, subject to statutory exceptions.Give prior written notice and post the types of monitoring used; penalties escalate from $500 to $3,000 for repeated violations.
Delaware Code tit. 19, § 705Telephone, email, and internet monitoring or interception involving Delaware employees.Provide either daily electronic notice or a one-time written/electronic notice acknowledged by the employee.
New York City Local Law 144Automated employment decision tools used for hiring or promotion decisions involving New York City jobs or workers.Confirm an independent bias audit within the past year, publish the audit summary, and give required AEDT notices before use.
Colorado SB 26-189 ADMT lawCovered automated decision-making technology that materially influences employment or employment-opportunity decisions for Colorado residents.Prepare developer documentation, deployer notices, post-adverse-outcome explanations, record retention, correction, and meaningful human-review workflows before the January 1, 2027 effective date.
Maryland MODPANot an employee-data rights law under current Maryland OAG guidance; it protects consumers acting in an individual or household context, not employment context.Do not promise employee MODPA rights. Keep separate HR controls for biometrics, monitoring, records retention, and security.

Employer Compliance Timeline: When Each Workplace-Privacy Duty Takes Effect

As of June 15, 2026, an HR team operating nationwide has to track at least seven separate workplace-privacy effective dates — and the three most consequential AI-in-hiring duties (California ADMT, Colorado SB 26-189, and NYC Local Law 144 bias-audit renewals) cluster in 2026 and 2027. Most employee-privacy guides list the laws; few line up when each obligation actually bites. This timeline does, so HR and legal teams can build a dated roadmap instead of a flat checklist.

Effective date Workplace-privacy obligation Who it hits
December 31, 2022CCPA/CPRA employment-related personal-information exemption expiredCovered businesses with California employees — full employee DSAR, notice-at-collection, and sensitive-data duties have applied since January 1, 2023.
July 5, 2023NYC Local Law 144 enforcement began: annual independent bias audit, published audit summary, and AEDT noticesEmployers using automated employment decision tools for New York City hiring or promotion; civil penalties run up to $1,500 per violation per day.
October 1, 2025Maryland MODPA took effect — a consumer law that, per Maryland OAG guidance, does not cover employment-context dataEmployers should keep HR controls but not promise Maryland employees MODPA DSAR rights.
January 1, 2026California ADMT “significant decisions” framework live; employment decisions (compensation, hiring, work allocation, promotion/demotion, suspension) are expressly in scopeCalifornia businesses must begin building toward full covered-ADMT compliance.
January 1, 2027California ADMT full-compliance deadline for businesses already using covered ADMT; Colorado SB 26-189 ADMT duties take effect for employment-opportunity decisionsEmployers using AI or ADMT for California or Colorado employment decisions need notices, opt-out/appeal, and meaningful human-review workflows in place.
December 31, 2027Initial California ADMT risk assessments due for processing already underwayCalifornia ADMT deployers must have documented risk assessments completed (then refreshed every three years or within 45 days of a significant change).
April 1, 2028California businesses must submit information on their 2026–2027 ADMT risk assessments to the CPPACalifornia ADMT deployers file risk-assessment attestations with the regulator.

The practical takeaway: the employee-privacy compliance calendar is now front-loaded into 2027. If your organization uses AI or automated tools anywhere in the hiring, promotion, or workforce-management pipeline, the California and Colorado deadlines belong on your 2026 planning roadmap, not deferred to the year they take effect.

The Employee Data Exemption — and Its Limits

Most comprehensive state privacy laws follow the Virginia model, which explicitly exempts data collected in an employment context. If you look at the state law comparison, you'll see that states like Virginia, Colorado, Connecticut, Indiana, and many others include an employment exemption. This means employee data such as resumes, performance reviews, payroll information, and background checks fall outside the scope of these laws.

But there are major exceptions to this pattern.

California: The CCPA Covers Employee Data

California is the most important exception. Since January 1, 2023, the CCPA/CPRA fully applies to employee personal information. The employee data exemption that existed under the original CCPA expired, and it was not renewed. This means that California employees have the same privacy rights as consumers, including:

  • Right to know what personal information their employer collects and how it's used
  • Right to delete personal information (with business-necessity exceptions)
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information (including biometric data, precise geolocation, race, and union membership)
  • Right to non-discrimination for exercising privacy rights

For employers, this means you must provide a privacy notice at or before the point of collection, respond to employee data subject access requests (DSARs), and implement reasonable security measures for employee data. Use our Privacy Law Calculator to check whether the CCPA's thresholds apply to your organization.

Maryland: MODPA Is a Consumer Law, Not an Employee Rights Law

The Maryland Online Data Privacy Act (MODPA), which took effect on October 1, 2025, is a useful caution point because it is easy to misread broad data-minimization language as applying to HR records. Current Maryland Attorney General guidance says MODPA protects consumers acting in an individual or household context and does not protect an individual acting in an employment context. Employers should still apply strong HR security and retention practices, but they should not promise Maryland employees MODPA-style DSAR rights unless another law, policy, contract, or collective bargaining obligation creates them.

Illinois BIPA: Biometric Data in the Workplace

Even in states with broad employee data exemptions, Illinois BIPA applies to employee biometric data. If you use fingerprint time clocks, facial recognition for building access, or any other biometric system for your Illinois workforce, you must obtain written informed consent before collection and maintain a publicly available retention policy. The massive settlements in cases like BNSF Railway ($228 million) stemmed from employee biometric data violations — not consumer data. See our biometric privacy laws guide for details, then run the employee biometric compliance checker for the states where your workforce operates.

What Employee Data Are We Talking About?

Employee data privacy covers a broad range of information that employers routinely collect and process:

  • Recruiting data — resumes, applications, interview notes, background checks, reference checks
  • Onboarding data — Social Security numbers, tax forms, I-9 verification, bank account details for payroll
  • Performance data — reviews, disciplinary records, goal tracking, productivity metrics
  • Health and benefits data — health plan enrollments, disability accommodations, FMLA records, wellness program participation
  • Monitoring data — email surveillance, internet usage logs, keystroke logging, GPS tracking, video surveillance
  • Biometric data — fingerprint scans, facial recognition data, voice recordings
  • Device data — data collected from company-owned devices, BYOD policies, mobile device management

Employee Data Compliance Regulations: 7 HR Tech Checks

Before buying or renewing HR technology, map each tool to the specific workplace privacy law it can trigger. This is the gap most generic employee-privacy checklists miss: the risk usually depends on the data stream, not the vendor category.

HR data stream Law signal to check Control to put in the buying checklist
California HRIS, payroll, benefits, and personnel filesCCPA/CPRA employee personal information coverage; CPPA FAQ confirms employment-related exemptions expired December 31, 2022.Add California employee DSAR handling, notice-at-collection fields, sensitive-data limits, retention tags, and identity-verification steps.
AI resume screening, promotion scoring, or workforce-ranking toolsNYC Local Law 144 if the AEDT is used for covered New York City hiring/promotion; Colorado SB 26-189 for covered ADMT that materially influences employment decisions beginning January 1, 2027; California ADMT obligations begin January 1, 2027 for significant decisions such as employment.Require vendor documentation for bias audits, model inputs, human review, notices, appeal/alternative-process workflows, and data used to test the tool.
Fingerprint time clocks, facial building access, voiceprints, and palm scansIllinois BIPA written release + public retention/destruction policy; Texas CUBI and Washington biometric requirements may also apply.Block collection until written consent/release is stored, retention period is configured, and deletion can run when employment or the collection purpose ends.
Email, chat, telephone, browser, or network monitoringNew York, Connecticut, and Delaware monitoring-notice laws; California CCPA notice duties if monitored workers are California residents.Publish the exact monitoring categories, delivery channel, acknowledgment method, and posting location before enabling the tool.
Screenshot, keystroke, productivity, or location-tracking softwareMonitoring-notice statutes plus sensitive-data obligations where precise geolocation, biometric patterns, or inferred performance profiles are collected.Separate security logging from productivity scoring, minimize collection, define retention, and require manager approval before higher-sensitivity settings are enabled.
Background checks and recruiting recordsUsually outside comprehensive consumer privacy laws except California, but still sensitive HR data with retention and access-control expectations.Limit access to recruiting/HR roles, separate rejected-candidate retention from employee files, and document lawful-use purpose before sharing with vendors.
Offboarding archives and legal-hold recordsCalifornia employee deletion/correction requests can conflict with payroll, tax, litigation, and security-retention needs.Tag each record with the statutory/business reason for retention so DSAR teams can explain what is deleted, corrected, retained, or withheld.

Workplace Monitoring: The Growing Privacy Concern

Employee monitoring has surged since the shift to remote and hybrid work. Employers increasingly deploy tools that track keystrokes, take periodic screenshots, monitor application usage, and analyze email content. While these practices may be legal in most states, they raise significant privacy concerns and may trigger obligations under existing laws.

Several states and cities are moving to regulate employee monitoring specifically:

  • New York — Requires employers to provide written notice of electronic monitoring to new hires (Section 52-c of the Civil Rights Law)
  • Connecticut — Requires employers to inform employees of electronic monitoring (Public Act 98-142)
  • Delaware — Requires employers that monitor email or internet usage to give prior written notice
  • California — The CCPA's requirement to disclose data collection purposes at or before collection applies to employee monitoring tools

Best Practices: Protecting Employee Data in 2026

1. Create a Clear Employee Privacy Notice

Regardless of whether your state's privacy law covers employee data, providing a clear privacy notice to employees is a best practice that builds trust and reduces legal risk. In California, it's a legal requirement. Your notice should explain what data you collect, why, how long you keep it, and who you share it with. See our privacy policy requirements guide for state-specific language recommendations.

2. Apply Data Minimization to HR Data

Collect only the employee data you genuinely need. Many organizations hoard employee information "just in case" without a clear business purpose. Apply the data minimization principle: if you don't need it, don't collect it. This reduces both your compliance burden and your exposure in a data breach.

3. Implement Retention and Destruction Schedules

Employee data should not be kept indefinitely. Develop a data retention schedule that specifies how long each category of employee data is retained and when it's destroyed. Account for legal hold requirements, tax record retention periods, and state-specific rules.

4. Get Consent for Biometric Collection

If you collect employee biometric data anywhere — fingerprint time clocks, facial recognition access systems, voice recordings — get written consent first. Even if your state doesn't mandate it today, the trend is clearly toward requiring consent, and obtaining it proactively protects you from future liability.

5. Train Your HR Team

Employee data privacy training is essential. HR professionals handle the most sensitive employee information and need to understand their obligations around data access, sharing, retention, and destruction. Regular training also helps prevent accidental disclosures and ensures your organization can respond to employee data requests efficiently.

6. Prepare for DSARs From Employees

In California, employees can submit data subject access requests just like consumers. Even if your state exempts employee data today, building DSAR infrastructure now prepares you for the inevitable expansion of employee privacy rights. Use our DSAR guide to understand the process.

The Future of Employee Data Privacy

The trend is not uniform, but it is moving toward more workforce-specific privacy duties. California already removed its broad HR exemption. Maryland is the counterexample: the Maryland OAG currently frames MODPA as protecting individual and household consumers, not people acting in an employment context. For multi-state employers, the safer operating model is to build one HR privacy inventory and then tag each obligation by source: CCPA/CPRA rights, biometric consent laws, electronic monitoring notices, records-retention rules, and security duties.

Additionally, the rise of AI in the workplace — from resume screening to performance analytics to monitoring tools — is accelerating calls for employee data protections. New York City already requires bias-audit and notice steps for covered automated employment decision tools, Colorado SB 26-189 covers ADMT that materially influences employment opportunities beginning January 1, 2027, and California's ADMT rules add notice, opt-out, and meaningful-information duties for significant decisions such as employment beginning January 1, 2027.

Smart businesses are getting ahead of this trend by implementing employee data protections now, rather than scrambling to comply after new laws take effect.

Primary sources checked June 6, 2026: California OAG and CPPA CCPA FAQs on the expired employment-related personal-information exemption and ADMT timing (oag.ca.gov/privacy/ccpa; cppa.ca.gov/faq, date_retrieved: 2026-05-23); Maryland OAG MODPA FAQ stating the law does not protect individuals acting in an employment context (oag.maryland.gov/resources-info/Pages/data-privacy.aspx, date_retrieved: 2026-05-23); New York Civil Rights Law § 52-c monitoring notice text (nysenate.gov/legislation/laws/CVR/52-C%2A2, date_retrieved: 2026-05-23); Connecticut Gen. Stat. § 31-48d monitoring notice text (cga.ct.gov/current/pub/chap_557.htm, date_retrieved: 2026-05-23); Delaware Code tit. 19, § 705 monitoring notice text (delcode.delaware.gov/title19/c007/sc01/index.html, date_retrieved: 2026-05-23); Illinois BIPA statutory text (ilga.gov/Legislation/ILCS/Articles, date_retrieved: 2026-05-23); NYC DCWP Local Law 144 AEDT guidance (nyc.gov/site/dca/about/automated-employment-decision-tools.page, date_retrieved: 2026-05-23); Colorado General Assembly SB 26-189 enacted bill page and Colorado AG Automated Decision-Making Technology rulemaking page (leg.colorado.gov/bills/sb26-189; coag.gov/ai, date_retrieved: 2026-06-06); CPPA final ADMT regulations confirming the California compliance calendar — significant-decision framework live January 1, 2026, full compliance for businesses already using covered ADMT by January 1, 2027, initial risk assessments due December 31, 2027, and risk-assessment submissions to the CPPA by April 1, 2028 (cppa.ca.gov/regulations, date_retrieved: 2026-06-15); and NYC DCWP Local Law 144 enforcement start of July 5, 2023 with penalties up to $1,500 per violation per day (date_retrieved: 2026-06-15).

Frequently Asked Questions

Which states have employee data privacy laws?

California is the main comprehensive state privacy law that covers employee personal information in full for covered businesses because the CCPA/CPRA employment-related exemption expired at the end of 2022. Illinois BIPA covers employee biometric data specifically, with a private right of action and $1,000–$5,000 per-violation statutory damages. New York, Connecticut, and Delaware require notice for specified employee electronic monitoring. Maryland is often confused with this group, but current Maryland OAG guidance says MODPA does not protect individuals acting in an employment context. Beyond these, most comprehensive state privacy laws (VCDPA, CPA, CTDPA, OCPA, etc.) exempt employee/B2B data, while state-specific employee monitoring and biometric laws may still apply.

Does the CCPA apply to my employees?

If your business meets the CCPA’s thresholds and you have employees in California, yes. The CCPA’s employee data exemption expired on January 1, 2023. California employees now have the same privacy rights as consumers, including the right to know, delete, correct, and limit the use of their personal information — with potential fines of $2,663 per unintentional violation and $7,988 per intentional violation (2026 inflation-adjusted). Use our calculator to check applicability.

Can I monitor my employees’ email and internet usage?

In most states, yes — but with conditions. You should provide clear, written notice to employees that monitoring occurs. Some states (New York, Connecticut, Delaware) legally require this notice. In California, monitoring data collection is subject to CCPA disclosure requirements. Best practice is to have employees acknowledge a written monitoring policy and treat any biometric measurements (keystroke patterns, facial-cam check-ins) as opt-in sensitive data.

Do I need consent to use fingerprint time clocks?

Yes, if you have employees in Illinois (BIPA), Texas (CUBI), Washington, or any state with a comprehensive privacy law that classifies biometric data as sensitive. In Illinois, the stakes are highest because employees can sue directly for violations, with statutory damages of $1,000–$5,000 per incident. The BNSF Railway $228M verdict and Meta $650M settlement both stemmed from employee biometric data violations.

What are common employee privacy rights examples?

The most common employee privacy rights employers must support today are: (1) right to know what personal data the employer collects (California CCPA/CPRA); (2) right to delete personal data, with business-necessity exceptions (California); (3) right to correct inaccurate records (California); (4) right to limit use of sensitive personal data — biometrics, geolocation, race, union membership (California); (5) right to advance written notice of electronic monitoring (NY Civil Rights Law § 52-c, Connecticut Gen. Stat. § 31-48d, Delaware Code tit. 19 § 705); (6) right to refuse biometric enrollment until opt-in consent is collected where biometric laws apply (IL BIPA, TX CUBI, WA, plus sensitive-data rules in comprehensive-law states); (7) right to non-discrimination for exercising covered CCPA/CPRA rights (California).

What’s the biggest employee data privacy risk for employers?

Biometric data collection without consent is currently the highest-risk area, given BIPA litigation. Beyond that, employee monitoring without adequate notice, failing to respond to California employee DSARs within the 45-day window, and retaining employee data longer than necessary are the most common compliance gaps we see. The trend lines all point the same direction: more states will remove HR exemptions over the next few years.

What workplace privacy laws by state should HR teams check first?

Start with the state-specific obligations that create concrete HR workflows: California CCPA/CPRA for employee notices and DSARs; Illinois BIPA for biometric time clocks or access systems; New York, Connecticut, and Delaware for electronic monitoring notice; New York City Local Law 144 for automated employment decision tools; and Colorado SB 26-189 for covered ADMT in employment decisions beginning January 1, 2027. Then confirm whether any other state law, contract, union agreement, or sector rule adds a stricter employee-data duty.

What employee data compliance regulations apply when HR uses AI screening tools?

For AI screening, hiring, promotion, or workforce-ranking tools, check at least three layers. New York City Local Law 144 requires a recent independent bias audit, public summary, and notices before using a covered AEDT. Colorado SB 26-189 applies when covered ADMT materially influences employment opportunities beginning January 1, 2027. California's ADMT rules require businesses to provide notice, opt-out where applicable, and meaningful information for significant decisions such as employment beginning January 1, 2027.

When do employers have to comply with California's ADMT (AI hiring) rules?

California's ADMT framework for “significant decisions” — which expressly includes employment decisions such as compensation, hiring, work allocation, promotion, demotion, and suspension — went live January 1, 2026. Businesses already using covered ADMT have until January 1, 2027 to fully comply; businesses that adopt covered ADMT after that date must be compliant before they deploy it. Initial risk assessments for processing already underway are due by December 31, 2027, and businesses must submit information about their 2026–2027 risk assessments to the CPPA by April 1, 2028. Colorado SB 26-189 adds parallel ADMT duties for employment-opportunity decisions beginning January 1, 2027.

Should I treat employee data the same as customer data?

As a best practice, use the same control framework — inventory, notice, purpose limitation, minimization, security, retention limits, and request workflows — but do not tell employees they have customer-style statutory rights unless a law actually grants them. California already removed its broad employment exemption; Maryland currently says MODPA does not cover employment-context data; New York City AEDT rules, Colorado SB 26-189, and California ADMT rules show how employment-specific AI duties are becoming their own compliance layer.

Published: March 29, 2026. Last verified: June 15, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly