EnglishEspañol

Employee Data Privacy: Employer Obligations by State (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Employee Data Privacy: Employer Obligations by State (2026)

Frequently Asked Questions

Can my employer read my work emails?

Under federal law (ECPA), employers can generally monitor email on company-provided systems under the business use exception and consent exception. Most employers establish monitoring rights through acceptable use policies and handbook acknowledgments. Connecticut and New York require prior written notice before monitoring, and Delaware requires either an electronic notice each day the employee uses the employer's email or internet services or a one-time notice the employee acknowledges. Personal email accounts are protected by the Stored Communications Act even when accessed on work devices.

Can an employer require fingerprint scans for timekeeping?

Yes, but state law may require consent and notice. Illinois BIPA requires written notice and a signed release before collecting biometric data, with statutory damages of $1,000-$5,000 per violation. Texas requires consent before capturing a biometric identifier for a commercial purpose. Washington's law is narrower than it sounds: its notice and consent duty is triggered only by enrolling a biometric identifier for a commercial purpose, which the statute defines as sale or disclosure to a third party for unrelated marketing, so it does not reach an employer using fingerprints for its own timekeeping. In states without specific biometric laws, employers generally can require biometric timekeeping, though employees may have common law privacy claims.

Can my employer ask for my social media password?

At least 28 states prohibit employers from requesting social media login credentials from employees or applicants. These laws also prohibit requiring employees to log in while the employer watches, adding the employer to contacts, or retaliating against refusal. In states without such laws, no federal statute specifically prohibits the request, though the Stored Communications Act may apply.

Does the CCPA apply to employee data in California?

Yes. The employee data exemption expired January 1, 2023. California employees now have full CCPA/CPRA rights including the right to know, delete, correct, and opt out of sale of personal information. Employers must provide a privacy notice at the point of collection and respond to employee data requests within 45 days.

Can my employer track my location with GPS?

Tracking company-owned vehicles and devices is generally legal under federal law. Tracking a personal vehicle without consent is restricted in a smaller number of states: Texas makes it an offense to place a tracking device on a vehicle owned or leased by another person without consent, and California courts have treated it as an invasion of privacy under the state constitution. New York has no employer-tracking statute, and its stalking law reaches only intentional tracking done for no legitimate purpose that causes material harm after the person was clearly told to stop. Off-duty tracking of employees raises additional privacy concerns even with company vehicles, and several states are considering legislation to restrict after-hours location monitoring.

Can employers conduct random drug tests?

Federal law does not prohibit random drug testing, but several states (Vermont, Connecticut, Minnesota, Montana, Rhode Island) restrict random testing to safety-sensitive positions. A growing number of states also prohibit adverse action based on off-duty marijuana use or positive THC tests, including California, New York, and New Jersey, with exceptions for safety-sensitive roles.

What federal laws protect employee medical information?

The ADA prohibits disability-related inquiries and medical examinations unless job-related and consistent with business necessity. Medical records must be kept in separate confidential files. GINA prohibits employers from requesting genetic information. HIPAA does not directly regulate employers but does restrict the health plans they sponsor. State laws often add further protections for employee medical data.

Can employers use AI to monitor employee performance?

No federal law specifically prohibits AI-powered employee monitoring, though the FTC has signaled that excessive surveillance may constitute unfair practices. Colorado's AI Act (as revised by SB26-189, effective January 1, 2027) will require notice when high-risk AI systems influence employment decisions. Illinois requires consent for AI analysis of video interviews. Expect more state legislation in this area in the coming years.

Updates

Corrected the state-law detail on employer monitoring and tracking: Washington's biometric consent rule applies only to enrollment for a commercial purpose and does not cover fingerprint timekeeping, Delaware's monitoring notice is an either/or choice between daily electronic notice and a one-time acknowledged notice, and New York's stalking statute is not an employer GPS-tracking restriction.

Corrected a KeyTakeaways figure that contradicted the article's own text on social-media-password laws (now 28 states throughout), updated the Colorado AI Act's effective date and description following its May 2026 amendment (now January 1, 2027, disclosure-focused), fixed a New York GPS-tracking citation that pointed to the wrong Penal Law section, repaired a New York electronic-monitoring statute link, replaced a New Jersey citation that pointed to an unrelated bill, corrected three broken Illinois ilga.gov citations (one of which had the wrong Act ID), and added a note on a 2026 Texas biometric-privacy carve-out for AI training data.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the FCRA citation for background-check disclosure, authorization, and pre-adverse-action requirements: those rules come from 15 U.S.C. § 1681b(b)(2)-(3), not § 1681 (which is only the Act's congressional findings and statement of purpose).

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Electronic Communications Privacy Act (18 USC 2510-2522)(law.cornell.edu)
  2. Stored Communications Act (18 USC 2701-2712)(law.cornell.edu)
  3. ADA Overview(ada.gov).gov
  4. ADA Employment Provisions (42 USC 12112)(law.cornell.edu)
  5. GINA (42 USC 2000ff)(law.cornell.edu)
  6. FCRA Congressional Findings (15 USC 1681)(law.cornell.edu)
  7. Connecticut Employee Monitoring Law (Conn. Gen. Stat. 31-48d)(cga.ct.gov).gov
  8. Illinois BIPA (740 ILCS 14)(ilga.gov).gov
  9. Texas Biometric Identifier Act (Tex. Bus. & Com. Code 503.001)(statutes.capitol.texas.gov).gov
  10. California Labor Code 980 (Social Media Passwords)(leginfo.legislature.ca.gov).gov
  11. CCPA Section 1798.100(leginfo.legislature.ca.gov).gov
  12. Illinois AI Video Interview Act (820 ILCS 42)(ilga.gov).gov
  13. Washington Biometric Identifiers (RCW 19.375)(app.leg.wa.gov).gov
  14. FCRA Background Check Disclosure & Pre-Adverse-Action Rules (15 USC 1681b)(law.cornell.edu)
  15. N.Y. Penal Law 120.45 (Stalking in the Fourth Degree)(nysenate.gov)
  16. Washington Biometric Identifier Definitions (RCW 19.375.010)(app.leg.wa.gov)
  17. Washington Enrollment of Biometric Identifiers for a Commercial Purpose (RCW 19.375.020)(app.leg.wa.gov)
  18. Delaware Notice of Monitoring (Del. Code tit. 19, 705)(delcode.delaware.gov)
Share: