Employee Data Privacy: Employer Obligations by State (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content
Employers collect vast amounts of personal data about their workers: Social Security numbers, health information, biometric scans, location data, email contents, web browsing history, and increasingly, behavioral analytics from AI-powered monitoring tools. The legal framework governing what employers can and cannot do with this data varies dramatically by state, creating a compliance challenge for multi-state employers and genuine confusion for employees about their rights.
Federal Employee Privacy Laws
While no single federal statute comprehensively addresses employee data privacy, several federal laws establish baseline protections.
Electronic Communications Privacy Act (ECPA)
The Electronic Communications Privacy Act of 1986 (18 USC 2510-2522) is the primary federal law governing employer monitoring of employee electronic communications. The ECPA generally prohibits intercepting electronic communications, but two exceptions make employer monitoring broadly permissible:
The consent exception. If an employee consents to monitoring, the interception is lawful. Most employers obtain consent through employee handbooks, acceptable use policies, or login banners stating that communications on company systems are subject to monitoring.
The business use exception (provider exception). An employer that provides the communications system (email servers, phone systems, company computers) can monitor communications conducted on those systems for legitimate business purposes. Courts have interpreted this exception broadly, allowing employers to monitor email, internet usage, and chat messages on company-provided devices and networks.
The ECPA does limit monitoring of purely personal communications even on company systems, though the boundaries of this limitation are fact-specific and vary by circuit.
Stored Communications Act (SCA)
The Stored Communications Act (18 USC 2701-2712), part of the ECPA, governs access to stored electronic communications. Under the SCA, employers generally can access emails stored on company servers. However, accessing an employee's personal email account (Gmail, Yahoo) without authorization violates the SCA, even if accessed from a company computer.
Americans with Disabilities Act (ADA)
The ADA restricts employer collection and use of medical information. Employers may not make disability-related inquiries or require medical examinations unless they are job-related and consistent with business necessity (42 USC 12112(d)). Medical records must be maintained in separate, confidential files with restricted access.
Genetic Information Nondiscrimination Act (GINA)
GINA (42 USC 2000ff) prohibits employers from requesting, requiring, or purchasing genetic information about employees or their family members, with narrow exceptions. Genetic information includes family medical history, genetic test results, and the fact that someone has sought genetic services. Violations can result in enforcement by the EEOC.
Fair Credit Reporting Act (FCRA)
The FCRA (15 USC 1681 et seq.) regulates employer use of background checks obtained from consumer reporting agencies. Before obtaining a background check, employers must provide written disclosure and obtain the employee's or applicant's written authorization (15 USC 1681b(b)(2)). If the employer takes adverse action based on the report, they must provide a copy of the report and a description of the consumer's rights before the action takes effect (15 USC 1681b(b)(3)).
Workplace Monitoring by State
Email and Computer Monitoring
Federal law permits workplace computer monitoring with minimal restrictions. State laws add modest requirements:
Connecticut (Conn. Gen. Stat. 31-48d) is the most protective state. Employers must give prior written notice to employees before monitoring email or internet activity. The notice must describe the types of monitoring that may occur. Failing to provide notice before monitoring violates the statute.
Delaware (Del. Code tit. 19, 705) requires notice before an employer monitors telephone, email, or internet use, but 705(b) gives the employer a choice of two routes: an electronic notice at least once during each day the employee accesses the employer-provided email or internet services, or a one-time notice that may be given in writing, in an electronic record, or in another electronic form and that the employee acknowledges either in writing or electronically. A violation carries a civil penalty of $100.
New York enacted the New York Civil Rights Law Section 52-c*2 effective May 7, 2022, requiring employers that monitor telephone calls, email, or internet access to provide prior written notice upon hiring. The notice must be posted in a conspicuous place and acknowledged in writing by the employee.
In all other states, employer monitoring of company-provided email and devices is largely unrestricted under federal law, provided the employer has not created a reasonable expectation of privacy (typically negated through handbook policies and login banners).
Biometric Data Collection
Biometric privacy is one of the fastest-evolving areas of employee data law. Several states have enacted specific statutes governing employer collection of fingerprints, facial geometry, retinal scans, voiceprints, and other biometric identifiers.
Illinois Biometric Information Privacy Act (BIPA). 740 ILCS 14 is the most significant biometric privacy law in the country because it provides a private right of action with statutory damages. Under BIPA, employers must:
- Provide written notice of the biometric data being collected and the purpose
- Obtain a written release from the employee before collection
- Publish a retention schedule and destruction guidelines
- Not sell, lease, trade, or profit from biometric data
Statutory damages are $1,000 per negligent violation and $5,000 per intentional or reckless violation. Following the Illinois Supreme Court's 2023 ruling in Cothron v. White Castle, each individual scan or collection event constitutes a separate violation. This has generated billions of dollars in potential exposure for employers using biometric timekeeping systems. A 2024 amendment capped damages at one violation per employee per method of collection in response.
Texas (Tex. Bus. & Com. Code 503.001) prohibits capturing biometric identifiers for commercial purposes without consent. Unlike Illinois, Texas does not provide a private right of action; enforcement lies with the Texas Attorney General, who can seek penalties of up to $25,000 per violation. The Texas Responsible AI Governance Act, effective January 1, 2026, narrowed this consent requirement: it exempts biometric identifiers an individual has made publicly available themselves, and biometric data used only to develop, train, or evaluate AI models, unless that data is used to uniquely identify a specific person.
Washington (RCW 19.375) is narrower than it first appears, and it generally does not reach workplace timekeeping. RCW 19.375.020(1) bars enrolling a biometric identifier in a database for a commercial purpose without first providing notice, obtaining consent, or providing a mechanism to prevent later commercial use. RCW 19.375.010(4) defines a commercial purpose as sale or disclosure to a third party for the marketing of goods or services unrelated to the transaction in which the identifier was first obtained. An employer that enrolls employee fingerprints for its own timekeeping is neither selling them nor disclosing them for unrelated marketing, so the statute imposes no consent duty on that practice. Enforcement is through the Washington Attorney General.
Additional states: Colorado, Virginia, Connecticut, and other states with comprehensive privacy laws include biometric data as "sensitive data" requiring consent for processing, though these laws generally do not provide private rights of action.
Social Media Password Laws
A growing number of states prohibit employers from requesting or requiring employees or job applicants to disclose social media login credentials. As of early 2026, at least 28 states have enacted such laws, including:
| State | Statute | Key Provisions |
|---|---|---|
| California | Lab. Code 980 | Prohibits requesting social media usernames or passwords; prohibits retaliation |
| Illinois | 820 ILCS 55 | Prohibits requesting access; covers applicants and employees |
| Maryland | Lab. & Empl. 3-712 | First state to pass such a law (2012); prohibits requiring disclosure |
| New Jersey | N.J.S.A. 34:6B-5 | Prohibits requiring access to personal social media accounts |
| Oregon | ORS 659A.330 | Prohibits requiring disclosure; includes civil penalty provisions |
These laws generally prohibit employers from: requesting login credentials, requiring employees to log in to personal accounts in the employer's presence, requiring employees to add the employer or its agents to their contacts, and retaliating against employees who refuse to comply.
GPS and Location Tracking
Employer tracking of employee location raises distinct legal issues depending on whether the tracking occurs on company-owned or personal devices and vehicles.
Company vehicles and devices. Employers generally can track company-owned vehicles and devices without specific employee consent under federal law. The reasoning parallels the ECPA business use exception: the employer owns the equipment.
Personal vehicles. Protection here is thinner than it is often described. It rests mostly on general criminal or constitutional law rather than on employment statutes:
- California courts have held that tracking an employee's personal vehicle without consent can constitute an invasion of privacy under the California Constitution.
- New York has no statute restricting employer GPS tracking. N.Y. Penal Law 120.45, the fourth-degree stalking statute, does define "following" to include the unauthorized tracking of a person's movements or location through a global positioning system, but that definition applies only to subdivision two of the section. Subdivision two additionally requires conduct engaged in intentionally and for no legitimate purpose that causes material harm to the person's mental or emotional health, after the actor was previously clearly informed to cease. An employer asserting a business reason for tracking would ordinarily fall outside it.
- Texas (Tex. Penal Code 16.06) prohibits installing tracking devices on vehicles owned or leased by another person without consent.
Off-duty tracking. Even where GPS tracking of company vehicles is legal, tracking employees during non-work hours raises additional concerns. California, Colorado, and New York courts have recognized employee privacy interests in off-duty location data, and several proposed state bills would explicitly restrict off-hours tracking.
Drug Testing
Drug testing privacy varies significantly by state:
- Random testing: Some states (Vermont, Connecticut, Minnesota, Montana, Rhode Island) restrict random drug testing to safety-sensitive positions only.
- Marijuana protections: As marijuana legalization expands, a growing number of states (California, New York, New Jersey, Montana, Nevada, Washington) prohibit employers from taking adverse action based on off-duty marijuana use or positive THC tests, with exceptions for safety-sensitive positions and federal requirements.
- Notice requirements: Many states require advance written notice of drug testing policies and procedures.
CCPA Employee Data Rights
The CCPA originally included a moratorium on employee data rights, which expired on January 1, 2023. California employees now have the same rights as consumers under the CCPA/CPRA, including:
- Right to know what personal information the employer collects and how it is used
- Right to delete personal information (subject to exceptions for legal obligations and employment administration)
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use of sensitive personal information
- Right to non-retaliation for exercising these rights
Under Cal. Civ. Code 1798.100, employers must provide a privacy notice to employees at or before the point of collection describing the categories of personal information collected and the purposes for each category. This is separate from the public-facing privacy policy and must address the employment context specifically.
The practical impact has been significant. Large California employers have had to build new intake systems for employee data requests, train HR departments on response procedures, and audit the flow of employee data to third parties (payroll processors, benefits administrators, background check vendors).
Common Law Privacy Torts
Beyond statutory protections, employees may bring common law tort claims against employers for privacy violations. The four traditional privacy torts, as defined in the Restatement (Second) of Torts, are:
Intrusion upon seclusion. An employer invades an employee's privacy by intentionally intruding into a matter in which the employee has a reasonable expectation of privacy. Courts have found intrusion claims viable for: searching personal belongings without cause, hidden camera surveillance in restrooms or changing areas, and accessing personal email accounts without authorization.
Public disclosure of private facts. An employer publishes embarrassing private facts about an employee. Examples include disclosing medical conditions, sharing salary information publicly (in states without pay transparency laws), or revealing the results of drug tests.
False light. An employer publishes information that places an employee in a false light. This is less common in the employment context but can arise from misleading characterizations in references or public statements.
Appropriation of name or likeness. An employer uses an employee's name or image for commercial purposes without consent. This has become more relevant with employer social media practices and the use of employee images in marketing materials.
These common law claims are available in most states and exist independently of statutory protections. They provide a legal basis for employees to challenge privacy violations even in states without specific employee privacy statutes.
Emerging Issues
AI-Powered Workplace Monitoring
The use of AI tools to monitor employee productivity, analyze communications, and predict behavior is growing rapidly. Keystroke logging, screen capture, sentiment analysis of messages, and even webcam-based "attention tracking" are now commercially available. Few existing laws directly address AI workplace monitoring, though:
- Colorado's AI Act (originally SB24-205, substantially revised by SB26-189, signed May 14, 2026) will require, starting January 1, 2027, that employers notify employees when high-risk AI systems are used in consequential decisions affecting their employment.
- Illinois' AI Video Interview Act (820 ILCS 42) requires employers to provide notice and obtain consent before using AI to analyze video interviews, and to destroy videos within 30 days of a request.
- The FTC has warned that surveillance-based management practices may constitute unfair practices under Section 5.
Reproductive Health Privacy
Following Dobbs v. Jackson Women's Health Organization (2022), several states enacted laws protecting employee reproductive health data. Washington, California, and Illinois have enacted or proposed legislation restricting employer access to reproductive health information and prohibiting adverse employment actions based on reproductive health decisions.
Sources and References
This article provides general legal information about employee data privacy across US jurisdictions. Employment law varies by state and changes frequently. Consult an attorney for advice specific to your situation.
Frequently Asked Questions
Can my employer read my work emails?
Under federal law (ECPA), employers can generally monitor email on company-provided systems under the business use exception and consent exception. Most employers establish monitoring rights through acceptable use policies and handbook acknowledgments. Connecticut and New York require prior written notice before monitoring, and Delaware requires either an electronic notice each day the employee uses the employer's email or internet services or a one-time notice the employee acknowledges. Personal email accounts are protected by the Stored Communications Act even when accessed on work devices.
Can an employer require fingerprint scans for timekeeping?
Yes, but state law may require consent and notice. Illinois BIPA requires written notice and a signed release before collecting biometric data, with statutory damages of $1,000-$5,000 per violation. Texas requires consent before capturing a biometric identifier for a commercial purpose. Washington's law is narrower than it sounds: its notice and consent duty is triggered only by enrolling a biometric identifier for a commercial purpose, which the statute defines as sale or disclosure to a third party for unrelated marketing, so it does not reach an employer using fingerprints for its own timekeeping. In states without specific biometric laws, employers generally can require biometric timekeeping, though employees may have common law privacy claims.
Can my employer ask for my social media password?
At least 28 states prohibit employers from requesting social media login credentials from employees or applicants. These laws also prohibit requiring employees to log in while the employer watches, adding the employer to contacts, or retaliating against refusal. In states without such laws, no federal statute specifically prohibits the request, though the Stored Communications Act may apply.
Does the CCPA apply to employee data in California?
Yes. The employee data exemption expired January 1, 2023. California employees now have full CCPA/CPRA rights including the right to know, delete, correct, and opt out of sale of personal information. Employers must provide a privacy notice at the point of collection and respond to employee data requests within 45 days.
Can my employer track my location with GPS?
Tracking company-owned vehicles and devices is generally legal under federal law. Tracking a personal vehicle without consent is restricted in a smaller number of states: Texas makes it an offense to place a tracking device on a vehicle owned or leased by another person without consent, and California courts have treated it as an invasion of privacy under the state constitution. New York has no employer-tracking statute, and its stalking law reaches only intentional tracking done for no legitimate purpose that causes material harm after the person was clearly told to stop. Off-duty tracking of employees raises additional privacy concerns even with company vehicles, and several states are considering legislation to restrict after-hours location monitoring.
Can employers conduct random drug tests?
Federal law does not prohibit random drug testing, but several states (Vermont, Connecticut, Minnesota, Montana, Rhode Island) restrict random testing to safety-sensitive positions. A growing number of states also prohibit adverse action based on off-duty marijuana use or positive THC tests, including California, New York, and New Jersey, with exceptions for safety-sensitive roles.
What federal laws protect employee medical information?
The ADA prohibits disability-related inquiries and medical examinations unless job-related and consistent with business necessity. Medical records must be kept in separate confidential files. GINA prohibits employers from requesting genetic information. HIPAA does not directly regulate employers but does restrict the health plans they sponsor. State laws often add further protections for employee medical data.
Can employers use AI to monitor employee performance?
No federal law specifically prohibits AI-powered employee monitoring, though the FTC has signaled that excessive surveillance may constitute unfair practices. Colorado's AI Act (as revised by SB26-189, effective January 1, 2027) will require notice when high-risk AI systems influence employment decisions. Illinois requires consent for AI analysis of video interviews. Expect more state legislation in this area in the coming years.
Updates
Corrected the state-law detail on employer monitoring and tracking: Washington's biometric consent rule applies only to enrollment for a commercial purpose and does not cover fingerprint timekeeping, Delaware's monitoring notice is an either/or choice between daily electronic notice and a one-time acknowledged notice, and New York's stalking statute is not an employer GPS-tracking restriction.
Corrected a KeyTakeaways figure that contradicted the article's own text on social-media-password laws (now 28 states throughout), updated the Colorado AI Act's effective date and description following its May 2026 amendment (now January 1, 2027, disclosure-focused), fixed a New York GPS-tracking citation that pointed to the wrong Penal Law section, repaired a New York electronic-monitoring statute link, replaced a New Jersey citation that pointed to an unrelated bill, corrected three broken Illinois ilga.gov citations (one of which had the wrong Act ID), and added a note on a 2026 Texas biometric-privacy carve-out for AI training data.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the FCRA citation for background-check disclosure, authorization, and pre-adverse-action requirements: those rules come from 15 U.S.C. § 1681b(b)(2)-(3), not § 1681 (which is only the Act's congressional findings and statement of purpose).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.100In forcecited in 11 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Privacy Policy Requirements: What You Must Include (2026), Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules
California Labor Code
§ 980In forcecited in 2 of our articles
(a) As used in this chapter, “social media” means an electronic service or account, or electronic content, including, but not limited to, videos, still photographs, blogs, video blogs, podcasts, instant and text messages, email, online services or accounts, or Internet Web site profiles or locations. (b) An employer shall not require or request an employee or applicant for employment to do any of the following: (1) Disclose a username or password for the purpose of accessing personal social media. (2) Access personal social media in the presence of the employer. (3) Divulge any personal social media, except as provided in subdivision (c). (c) Nothing in this section shall affect an employer’s existing rights and obligations to request an employee to divulge personal social media reasonably believed to be relevant to an investigation of allegations of employee misconduct or employee violation of applicable laws and regulations, provided that the social media is used solely for purposes of that investigation or a related proceeding.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2016
Opinions citing this section in our collection:
- People v. Lopez CA6 (California Court of Appeal 2016)“…duc. Code, § 99120.)2 A similar definition is also found in Labor Code section 980, subdivision (a).3 The People do…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Employee Monitoring Laws: Employer Rules (2026)
Connecticut General Statutes, Title 31 (Labor), Chapter 557
§ 31-48dEmployers engaged in electronic monitoring required to give prior notice to employees. Exceptions. Civil penalty.In forcecited in 20 of our articles
(a) As used in this section: (1) “Employer” means any person, firm or corporation, including the state and any political subdivision of the state which has employees; (2) “Employee” means any person who performs services for an employer in a business of the employer, if the employer has the right to control and direct the person as to (A) the result to be accomplished by the services, and (B) the details and means by which such result is accomplished; and (3) “Electronic monitoring” means the collection of information on an employer's premises concerning employees' activities or communications by any means other than direct observation, including the use of a computer, telephone, wire, radio, camera, electromagnetic, photoelectronic or photo-optical systems, but not including the collection of information (A) for security purposes in common areas of the employer's premises which are held out for use by the public, or (B) which is prohibited under state or federal law.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at cga.ct.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2021
In the courts (editorial summary, independently checked):Gerardi v. City of Bridgeport (2010) held that section 31-48d creates no private right of action, reading subsection (c) to delegate all enforcement of the electronic monitoring notice duty to the labor commissioner. J.P. Alexandre, LLC v. Egbuna (2012) cited that reading when rejecting an implied right of action under a tax statute.
Opinions citing this section in our collection:
- Gerardi v. City of Bridgeport (Supreme Court of Connecticut 2010, 294 Conn. 461)✓Bridgeport put GPS units in fire inspectors' city vehicles without telling them, then disciplined them; the Connecticut Supreme Court held section 31-48d creates no private right of action because subsection (c) leaves enforcement to the labor commissioner.
- Borelli v. Renaldi (Supreme Court of Connecticut 2020, 336 Conn. 1)“…(2010) (comparing electronic monitoring statute, General Statutes § 31-48d, to other employment statutes…”
- J.P. Alexandre, LLC v. Egbuna (Connecticut Appellate Court 2012, 137 Conn. App. 340)“…idgeport, supra, 294 Conn. 472 (rejecting claim that General Statutes § 31-48d [c] provided private right of action wh…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Employer Guide to Wearable Recording Device Policies (2026), Connecticut Audio Recording Laws: Mixed Consent Rules and Penalties (2026), Connecticut Dashcam Laws: Mounting Rules, Audio Recording, and Evidence (2026)
Texas Business & Commerce Code
§ 503.001CAPTURE OR USE OF BIOMETRIC IDENTIFIERIn forcecited in 9 of our articles
(a) In this section: (1) "Artificial intelligence system" has the meaning assigned by Section 551.001. (2) "Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry. (b) A person may not capture a biometric identifier of an individual for a commercial purpose unless the person: (1) informs the individual before capturing the biometric identifier; and (2) receives the individual's consent to capture the biometric identifier. (b-1) For purposes of Subsection (b), an individual has not been informed of and has not provided consent for the capture or storage of a biometric identifier of an individual for a commercial purpose based solely on the existence of an image or other media containing one or more biometric identifiers of the individual on the Internet or other publicly available source unless the image or other media was made publicly available by the individual to whom the biometric identifiers relate.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Also relied on in: Amazon Ring Sued Over "Familiar Faces" Facial Recognition (2026), Alabama Smart Glasses Recording Laws, Oklahoma Smart Glasses Recording Laws 2026
United States Code Title 42
§ 12112DiscriminationIn force
No covered entity shall discriminate against a qualified individual on the basis of disability in regard to job application procedures, the hiring, advancement, or discharge of employees, employee compensation, job training, and other terms, conditions, and privileges of employment. As used in subsection (a), the term “discriminate against a qualified individual on the basis of disability” includes— limiting, segregating, or classifying a job applicant or employee in a way that adversely affects the opportunities or status of such applicant or employee because of the disability of such applicant or employee; participating in a contractual or other arrangement or relationship that has the effect of subjecting a covered entity’s qualified applicant or employee with a disability to the discrimination prohibited by this subchapter (such relationship includes a relationship with an employment or referral agency, labor union, an organization providing fringe benefits to an employee of the covered entity, or an organization providing training and apprenticeship programs); utilizing standards, criteria, or methods of administration— that have the effect of discrimination on the basis of…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 9,203 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Board of Trustees of Univ. of Ala. v. Garrett (Supreme Court of the United States 2001, 531 U.S. 356)“…ccessible to and usable by individuals with disabilities." 42 U. S. C. §§ 12112 (5)(B), 12111(9). The ADA does except e…”
- Sutton v. United Air Lines, Inc. (Supreme Court of the United States 1999, 527 U.S. 471)“…her terms, conditions, and privileges *478 of employment” 42 U. S. C. § 12112 (a); see also § 12111(2) (“The term 'co…”
- Equal Employment Opportunity Commission v. St. Francis Xavier Parochial School and St. Francis Xavier Church (Court of Appeals for the D.C. Circuit 1997, 117 F.3d 621)“…failing to provide a wheelchair-accessible interview site, 42 U.S.C. § 12112 (b)(5)(A), and by discriminatorily refu…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 2000ffDefinitionsIn force
In this chapter: The term “Commission” means the Equal Employment Opportunity Commission as created by section 2000e–4 of this title. The term “employee” means— an employee (including an applicant), as defined in section 2000e(f) of this title; a State employee (including an applicant) described in section 2000e–16c(a) of this title; a covered employee (including an applicant), as defined in section 1301 of title 2; a covered employee (including an applicant), as defined in section 411(c) of title 3; or an employee or applicant to which section 2000e–16(a) of this title applies. The term “employer” means— an employer (as defined in section 2000e(b) of this title); an entity employing a State employee described in section 2000e–16c(a) of this title; an employing office, as defined in section 1301 of title 2; an employing office, as defined in section 411(c) of title 3; or an entity to which section 2000e–16(a) of this title applies. The terms “employment agency” and “labor organization” have the meanings given the terms in section 2000e of this title. The term “member”, with respect to a labor organization, includes an applicant for membership in a labor organization.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 126 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Russo v. Patchogue-Medford Sch. Dist. (Court of Appeals for the Second Circuit 2025, 129 F.4th 182)“…violation of the Genetic Information Nondiscrimination Act, 42 U.S.C. § 2000ff et seq. Russo further claimed that the…”
- Dumas v. Hurley Medical Center (District Court, E.D. Michigan 2011, 837 F. Supp. 2d 655)“…of the Genetic Information Nondiscrimination Act (“GINA”), 42 U.S.C. § 2000ff, et seq. Although GINA provides for a…”
- Lowe v. Atlas Logistics Group Retail Services (Atlanta), LLC (District Court, N.D. Georgia 2015, 102 F. Supp. 3d 1360)“…der the Genetic Information Nondiscrimination Act (“GINA”), 42 U.S.C. § 2000ff et seq., which generally prohibits empl…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 2000fSurvey for compilation of registration and voting statistics; geographical areas; scope; application of census provisions; voluntary disclosure; advising of right not to furnish informationIn force
The Secretary of Commerce shall promptly conduct a survey to compile registration and voting statistics in such geographic areas as may be recommended by the Commission on Civil Rights. Such a survey and compilation shall, to the extent recommended by the Commission on Civil Rights, only include a count of persons of voting age by race, color, and national origin, and determination of the extent to which such persons are registered to vote, and have voted in any statewide primary or general election in which the Members of the United States House of Representatives are nominated or elected, since January 1, 1960. Such information shall also be collected and compiled in connection with the Nineteenth Decennial Census, and at such other times as the Congress may prescribe.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 1965
Opinions citing this section in our collection:
- Lampkin v. Connor (District Court, District of Columbia 1965, 239 F. Supp. 757)“…Title VIII of the Civil Rights Act of 1964 ( 78 Stat. 266 , 42 U.S.C.A. 2000f). However, the Secretary may not compel…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
United States Code Title 15
§ 1681bPermissible purposes of consumer reportsIn forcecited in 3 of our articles
Subject to subsection (c), any consumer reporting agency may furnish a consumer report under the following circumstances and no other: In response to the order of a court having jurisdiction to issue such an order, a subpoena issued in connection with proceedings before a Federal grand jury, or a subpoena issued in accordance with section 5318 of title 31 or section 3486 of title 18. In accordance with the written instructions of the consumer to whom it relates. To a person which it has reason to believe— intends to use the information in connection with a credit transaction involving the consumer on whom the information is to be furnished and involving the extension of credit to, or review or collection of an account of, the consumer; or intends to use the information for employment purposes; or intends to use the information in connection with the underwriting of insurance involving the consumer; or intends to use the information in connection with a determination of the consumer’s eligibility for a license or other benefit granted by a governmental instrumentality required by law to consider an applicant’s financial responsibility or status; or intends to use the information,…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 963 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Pintos v. PACIFIC CREDITORS ASS'N (Court of Appeals for the Ninth Circuit 2010, 605 F.3d 665)“…lving the ... collection of an account of[ ] the consumer.” 15 U.S.C. § 1681b(a)(3)(A). The district court determined…”
- Gelman v. State Farm Mutual Automobile Insurance (Court of Appeals for the Third Circuit 2009, 583 F.3d 187)“…ase occurs for one of the permissible purposes set forth in 15 U.S.C. § 1681b(a).” Cole, 389 F.3d at 7…”
- Kennedy v. Chase Manhattan Bank USA, NA (Court of Appeals for the Fifth Circuit 2004, 369 F.3d 833)“…s, Inc., 614 F.2d 413, 414-15 (5th Cir. 1980). 6 15 U.S.C. § 1681b(c)(1)(B)(i). 7 15 U.S.C. § 1…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: New York's Clean Slate Act Takes Effect: Millions of Old Convictions Now Seal Automatically, 15 U.S.C. § 1681 (FCRA): Credit Report Rights Explained
§ 1681Congressional findings and statement of purposeIn forcecited in 14 of our articles
The Congress makes the following findings: The banking system is dependent upon fair and accurate credit reporting. Inaccurate credit reports directly impair the efficiency of the banking system, and unfair credit reporting methods undermine the public confidence which is essential to the continued functioning of the banking system. An elaborate mechanism has been developed for investigating and evaluating the credit worthiness, credit standing, credit capacity, character, and general reputation of consumers. Consumer reporting agencies have assumed a vital role in assembling and evaluating consumer credit and other information on consumers. There is a need to insure that consumer reporting agencies exercise their grave responsibilities with fairness, impartiality, and a respect for the consumer’s right to privacy.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 3,711 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts cite 1681(a)'s findings for the Act's purpose and decide under its operative sections. Spokeo, Inc. v. Robins (2016) held that a bare procedural FCRA violation divorced from concrete harm does not satisfy Article III, and TransUnion LLC v. Ramirez (2021) applied that rule to hold 6,332 class members lacked standing.
Opinions citing this section in our collection:
- Spokeo, Inc. v. Robins (Supreme Court of the United States 2016, 578 U.S. 330)✓Robins alleged Spokeo's people-search profile carried false information about him and sued under the FCRA, 15 U.S.C. § 1681 et seq.; the Court held a bare procedural violation divorced from concrete harm does not satisfy Article III injury in fact, and remanded.
- TransUnion LLC v. Ramirez (Supreme Court of the United States 2021, 594 U.S. 413)✓TransUnion flagged 8,185 consumers as potential matches to a Treasury terrorist list; suing under the FCRA, only the 1,853 whose misleading reports actually reached third parties were held concretely harmed, so the other 6,332 lacked Article III standing for damages.
- Pintos v. PACIFIC CREDITORS ASS'N (Court of Appeals for the Ninth Circuit 2010, 605 F.3d 665)✓Police had Pintos's car towed and the towing company transferred its deficiency claim to a collection agency, which pulled her Experian report; the Ninth Circuit held § 1681b(a)(3)(A) gave no permissible purpose, since neither credit she sought nor a judgment debt was involved.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Background Check Laws by State (2026 Guide), How to Opt Out of Data Brokers (2026), FTC Fines Amazon $2.25 Million for Denying Identity-Theft Victims Their Fraud Records Under the FCRA
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Electronic Communications Privacy Act (18 USC 2510-2522)(law.cornell.edu)
- Stored Communications Act (18 USC 2701-2712)(law.cornell.edu)
- ADA Overview(ada.gov).gov
- ADA Employment Provisions (42 USC 12112)(law.cornell.edu)
- GINA (42 USC 2000ff)(law.cornell.edu)
- FCRA Congressional Findings (15 USC 1681)(law.cornell.edu)
- Connecticut Employee Monitoring Law (Conn. Gen. Stat. 31-48d)(cga.ct.gov).gov
- Illinois BIPA (740 ILCS 14)(ilga.gov).gov
- Texas Biometric Identifier Act (Tex. Bus. & Com. Code 503.001)(statutes.capitol.texas.gov).gov
- California Labor Code 980 (Social Media Passwords)(leginfo.legislature.ca.gov).gov
- CCPA Section 1798.100(leginfo.legislature.ca.gov).gov
- Illinois AI Video Interview Act (820 ILCS 42)(ilga.gov).gov
- Washington Biometric Identifiers (RCW 19.375)(app.leg.wa.gov).gov
- FCRA Background Check Disclosure & Pre-Adverse-Action Rules (15 USC 1681b)(law.cornell.edu)
- N.Y. Penal Law 120.45 (Stalking in the Fourth Degree)(nysenate.gov)
- Washington Biometric Identifier Definitions (RCW 19.375.010)(app.leg.wa.gov)
- Washington Enrollment of Biometric Identifiers for a Commercial Purpose (RCW 19.375.020)(app.leg.wa.gov)
- Delaware Notice of Monitoring (Del. Code tit. 19, 705)(delcode.delaware.gov)