California
California Employee Monitoring Laws: Employer Rules (2026)
Independently fact-checked against primary sources (last audited August 17, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 17, 2026. · 7 primary sources cited on this page. How we verify our legal content

California employers face some of the strictest monitoring rules in the country. Labor Code § 980 bars demanding an employee's social media password, Labor Code § 435 bans cameras in restrooms and locker rooms, and the CPRA gives employees of businesses that meet its coverage thresholds CCPA-style notice and access rights over monitoring data since 2023.
Information last verified on July 9, 2026. This article has not yet been reviewed by a licensed lawyer.
This article covers what California law says specifically about an employer's ability to monitor its employees, as distinct from the general recording-consent rules covered in California Recording Laws and its workplace recording page. This cluster's focus is the employer side: social media password protections, surveillance limits, and how California's privacy statutes now reach employee data.
Jurisdiction scope: This article addresses California state law on employer monitoring of employees, including Cal. Lab. Code § 980 (social media passwords), Cal. Lab. Code § 435 (restroom and locker room recording), and the CPRA's employee-data provisions, together with the federal ECPA baseline. It does not re-derive California's two-party consent recording rules or general GPS-tracking law in depth; for those, see the linked California recording law and GPS tracking law pages.
How Federal and California Recording Law Apply to Employer Monitoring
California is a two-party, or all-party, consent state for recording confidential communications under Penal Code § 632, meaning every participant in a confidential conversation must consent before it can be recorded. This article does not re-derive that framework; for the full rules on consent, penalties, and exceptions, see California Recording Laws and the site's dedicated workplace recording guide.
A separate federal rule governs employer monitoring of business communications specifically. Under the Wiretap Act, the business-extension exemption in 18 U.S.C. § 2510(5)(a) excludes communications equipment a business furnishes and uses "in the ordinary course of business" from the Act's definition of an interception device, so a business that owns its phone or computer system can monitor communications on that system without needing a party's consent at all. The Eleventh Circuit narrowed that exception in Watkins v. L.M. Berry & Co., 704 F.2d 577 (11th Cir. 1983): an employer can monitor a business call, but once a call is identified as personal, continued listening falls outside the exception, and the employer is expected to stop listening or rely on spot checks instead. In California, this federal exception operates alongside, not instead of, the state's stricter two-party consent rule for confidential communications.
California Has No Dedicated Monitoring Notice Law, But the CPRA Fills Part of the Gap
California has not enacted an electronic-monitoring notice statute in the style of Connecticut, Delaware, New York, or Maine. Instead, the state's principal notice mechanism for employee monitoring runs through its consumer privacy law. The California Consumer Privacy Act and its amendment, the California Privacy Rights Act (CPRA), originally exempted employee and job-applicant data. That exemption expired on January 1, 2023, when the Legislature declined to extend it, and employees of a covered employer now have the same core rights as any other California consumer with respect to their employer's data practices.
Coverage is the threshold question, and it excludes most California employers. Civ. Code § 1798.140(d) defines a "business" as an entity "organized or operated for the profit or financial benefit of its shareholders or other owners" that also meets at least one of three tests: annual gross revenues in excess of $25,000,000, annually buying, selling, or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of its annual revenues from selling or sharing consumers' personal information. A nonprofit employer of any size, and a for-profit employer that clears none of the three thresholds, is not a CCPA business and owes none of the duties described in this section.
In practice, for an employer that does meet those thresholds, this means providing a notice at collection describing the categories of personal information it collects about employees, including monitoring, surveillance, and location data, and the purposes for which it is used. Employees of such an employer can request to know what has been collected, request deletion of information no longer needed for a disclosed purpose, request correction of inaccurate information, and opt out of the sale or sharing of their personal information. New CPPA regulations add risk-assessment obligations beginning January 1, 2026, for covered employers whose monitoring activities involve significant use of employee data, including any use of automated decision-making technology (ADMT) for a significant employment decision; employers with pre-existing covered activities have until December 31, 2027 to complete an initial assessment, and ADMT-specific notice and opt-out mechanics phase in January 1, 2027.
California's Social Media Password Law
Cal. Lab. Code § 980 prohibits an employer from requiring or requesting that an employee or applicant disclose a username or password for the purpose of accessing personal social media, access personal social media in the employer's presence, or otherwise divulge personal social media content. An employer that retaliates against a worker for refusing, by discharging, disciplining, or threatening to do either, violates the statute, though it can still take a lawful adverse action for other, independent reasons.

Two exceptions matter for employers. First, under subsection (c), an employer may require disclosure of personal social media reasonably believed relevant to investigating allegations of employee misconduct or a violation of law or regulation, but only for use in that investigation or a related proceeding. Second, under subsection (d), the statute does not restrict an employer's ability to require login credentials for a device it actually issued to the employee, such as a company phone or laptop account.
Video and Audio Surveillance Limits: Labor Code 435 and Hernandez v. Hillsides
Cal. Lab. Code § 435 is a bright-line rule: no employer may cause an audio or video recording to be made of an employee in a restroom, locker room, or room designated for changing clothes, unless authorized by a court order. Employee consent cannot substitute for a court order, any recording made in violation cannot be used by the employer for any purpose, and a violation is an infraction. This is one of the clearest statutory limits on workplace surveillance in the country and applies to nearly every private and public employer in the state.
Outside those specifically protected spaces, California courts evaluate workplace video surveillance under a reasonable-expectation-of-privacy and highly-offensive-intrusion standard. The California Supreme Court's decision in Hernandez v. Hillsides, Inc., 47 Cal.4th 272 (2009), remains the leading case: the Court found that two employees had a reasonable expectation of privacy in their shared, closed-door office even though the employer had a legitimate reason (identifying who was accessing inappropriate websites) for installing a hidden camera, but held the employer was not liable because the camera was never activated while the employees were present and the intrusion, on the facts, was not highly offensive to a reasonable person. The case illustrates that a legitimate business reason for surveillance does not eliminate the need to weigh the manner and scope of the intrusion against the employee's privacy interest.
GPS and Vehicle Tracking
California's general anti-tracking statute, Penal Code § 637.7, makes it a misdemeanor to use an electronic tracking device to determine the location or movement of a person. The statute reaches vehicle tracking through its definition of the device rather than its statement of the prohibition: subdivision (d) defines an "electronic tracking device" as any device attached to a vehicle or other movable thing that reveals its location or movement by the transmission of electronic signals. Subdivision (b) then provides that the section does not apply where "the registered owner, lessor, or lessee of a vehicle has consented to the use of the electronic tracking device with respect to that vehicle." Because an employer is typically the registered owner or lessee of its own fleet vehicles, this consent exception is why employers can generally track company-owned vehicles without violating § 637.7. For the fuller rules on GPS and vehicle tracking in California, including how this interacts with personal vehicles and the state's general privacy framework, see California GPS Tracking Laws.
Biometric Monitoring
California does not have an Illinois-style Biometric Information Privacy Act with a standalone private right of action for mishandled fingerprint or facial-recognition data. Biometric identifiers are instead treated as a category of "sensitive personal information" under the CPRA, which gives employees of a covered business the right to limit certain uses of that data and requires the same notice-at-collection and risk-assessment obligations described above when such an employer's monitoring program processes biometric data, such as a fingerprint time clock or facial-recognition access system. For more detail on how California defines and protects biometric data generally, see California Biometric Privacy Laws.

Recent Developments: Failed and Pending Surveillance Bills, and the Meta Example
California's Legislature has repeatedly tried and failed to pass a comprehensive workplace-surveillance notice law. AB 1221, the Workplace Technology Accountability Act, would have required 30 days' written notice before deploying a new workplace surveillance tool and would have barred certain uses of AI-driven monitoring, such as facial or gait recognition, but it failed on February 2, 2026 when it was filed with the Chief Clerk under Joint Rule 56 without advancing out of the Legislature. A related bill, AB 1331, which would have restricted surveillance in employee-only break areas, was ordered to the inactive file in the Senate on September 13, 2025 and had not been revived as of this writing. Neither bill is currently law, so the CPRA notice-at-collection framework and the statutes described above remain the operative rules.
Real-world monitoring disputes continue to test these boundaries even without new legislation. In 2026, Meta's internal Model Capability Initiative, a program that logged employee keystrokes, mouse activity, and app usage on company devices to train AI models, drew an internal petition from more than 1,600 employees after the company disclosed in June 2026 that sensitive data the program collected, including private prompts and internal discussions, had been broadly accessible inside the company. Meta subsequently paused the program after the security review; reporting on the episode describes no option for employees to opt out of the tracking on company devices. The episode is a useful illustration of the kind of employer monitoring program that California's CPRA notice and risk-assessment rules, and any future legislation modeled on AB 1221, are aimed at.
Disclaimer
This article provides general legal information about employee monitoring law in California as of July 9, 2026. It is not legal advice and does not create an attorney-client relationship. Workplace privacy and employment law involve fact-specific analysis; consult an attorney licensed in California about your specific situation before acting on anything in this article.
Related articles
- Employee Monitoring Laws by State
- California Recording Laws
- California Workplace Recording Laws
- California GPS Tracking Laws
- California Biometric Privacy Laws

Last updated: July 9, 2026. Statutes cited reflect their in-force version as of July 9, 2026.
More California Laws
Frequently Asked Questions
Does my California employer have to tell me before monitoring my computer?
California has no dedicated electronic-monitoring notice statute, and the CPRA notice duty reaches only employers that qualify as a CCPA 'business': a for-profit entity with more than $25 million in annual gross revenue, or that handles the personal information of 100,000 or more consumers or households, or that makes 50 percent or more of its revenue from selling or sharing personal information. If your employer meets one of those tests, then since the CPRA's employee exemption expired in 2023 it must provide a notice at collection describing what personal information it collects, including through monitoring, and why. A nonprofit employer or a smaller for-profit employer owes no such notice. There is no separate 30-day advance-notice requirement for anyone; a bill that would have added one, AB 1221, failed in February 2026.
Can my employer ask for my Instagram password in California?
No, not for personal use. Cal. Lab. Code § 980 bars an employer from requiring your social media username or password, except when your account is reasonably believed relevant to a misconduct investigation or the account is one the employer itself issued to you.
Can my employer put a camera in the restroom or locker room in California?
No. Cal. Lab. Code § 435 bans employer audio or video recording of employees in restrooms, locker rooms, or changing rooms without a court order, and your consent cannot substitute for one. Any footage recorded in violation cannot be used for any purpose.
Can my California employer install a hidden camera in my office?
It depends on the facts. In Hernandez v. Hillsides, Inc. (2009), the California Supreme Court held employees had a reasonable expectation of privacy in a shared, closed-door office, but found the employer not liable because the camera was never activated while they were present and the intrusion was not highly offensive on those specific facts. Courts weigh the manner and scope of the surveillance against the employee's privacy interest.
Can my employer track a company car with GPS in California?
Generally yes. Penal Code § 637.7 exempts tracking consented to by the vehicle's registered owner, lessor, or lessee, and an employer is typically the registered owner or lessee of its own fleet vehicles. See California GPS Tracking Laws for the fuller framework, including personal-vehicle scenarios.
Do I have a right to see what monitoring data my employer collected about me in California?
Only if your employer qualifies as a CCPA 'business.' Civ. Code § 1798.140(d) limits that term to for-profit entities that also clear at least one threshold: more than $25 million in annual gross revenue, handling the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information. If your employer meets one of those tests, then since the CPRA's employee exemption expired on January 1, 2023 you have the right to know what personal information, including monitoring and location data, it has collected, and rights to request deletion or correction, subject to the same exceptions that apply to other CCPA/CPRA rights. If you work for a nonprofit or a smaller for-profit employer, the CCPA gives you no such right.
Updates
Clarified that the CCPA/CPRA employee notice, access, and deletion rights apply only to employers that meet the statute's for-profit revenue and data-volume thresholds, corrected the description of Penal Code § 637.7 (it prohibits tracking a person, with vehicles reached through the device definition), and fixed a related link that pointed to a news story instead of the California recording laws guide.
Corrected a claim about Meta's employee-tracking program that was contradicted by its own cited source (the source reports no opt-out option, not a 30-minute pause option), and re-pointed the CPPA risk-assessment/ADMT deadline citation to the actual rulemaking document; the dates themselves (Jan. 1 2026, Dec. 31 2027, Jan. 1 2027) were independently confirmed accurate.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the source of the employer 'ordinary course of business' monitoring exception: it comes from the 18 U.S.C. 2510(5)(a) business-extension exemption, not the service-provider exception in 2511(2)(a)(i).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.100In forcecited in 13 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Employee Data Privacy: Employer Obligations by State (2026), Privacy Policy Requirements: What You Must Include (2026)
California Labor Code
§ 435In forcecited in 7 of our articles
(a) No employer may cause an audio or video recording to be made of an employee in a restroom, locker room, or room designated by an employer for changing clothes, unless authorized by court order. (b) No recording made in violation of this section may be used by an employer for any purpose. This section applies to a private or public employer, except the federal government. (c) A violation of this section constitutes an infraction.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2006
Opinions citing this section in our collection:
- Trujillo v. City of Ontario (District Court, C.D. California 2006, 428 F. Supp. 2d 1094)“…See, e.g., Cal.Penal Code §§ 647(k), 653(n); Cal. Labor Code 435. While the laws concerning video survei…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Security Camera and Surveillance Laws: Rules for Home and Business (2026), California Surveillance Camera Laws: Complete 2026 Guide, Workplace Surveillance Camera Laws: Employee Guide
§ 980In forcecited in 2 of our articles
(a) As used in this chapter, “social media” means an electronic service or account, or electronic content, including, but not limited to, videos, still photographs, blogs, video blogs, podcasts, instant and text messages, email, online services or accounts, or Internet Web site profiles or locations. (b) An employer shall not require or request an employee or applicant for employment to do any of the following: (1) Disclose a username or password for the purpose of accessing personal social media. (2) Access personal social media in the presence of the employer. (3) Divulge any personal social media, except as provided in subdivision (c). (c) Nothing in this section shall affect an employer’s existing rights and obligations to request an employee to divulge personal social media reasonably believed to be relevant to an investigation of allegations of employee misconduct or employee violation of applicable laws and regulations, provided that the social media is used solely for purposes of that investigation or a related proceeding.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2016
Opinions citing this section in our collection:
- People v. Lopez CA6 (California Court of Appeal 2016)“…duc. Code, § 99120.)2 A similar definition is also found in Labor Code section 980, subdivision (a).3 The People do…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
California Penal Code
§ 637.7In forcecited in 3 of our articles
(a) No person or entity in this state shall use an electronic tracking device to determine the location or movement of a person. (b) This section shall not apply when the registered owner, lessor, or lessee of a vehicle has consented to the use of the electronic tracking device with respect to that vehicle. (c) This section shall not apply to the lawful use of an electronic tracking device by a law enforcement agency. (d) As used in this section, “electronic tracking device” means any device attached to a vehicle or other movable thing that reveals its location or movement by the transmission of electronic signals. (e) A violation of this section is a misdemeanor. (f) A violation of this section by a person, business, firm, company, association, partnership, or corporation licensed under Division 3 (commencing with Section 5000) of the Business and Professions Code shall constitute grounds for revocation of the license issued to that person, business, firm, company, association, partnership, or corporation, pursuant to the provisions that provide for the revocation of the license as set forth in Division 3 (commencing with Section 5000) of the Business and Professions Code.
Official text (excerpt) · last checked 2026-08-26 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 17 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):California courts have applied Penal Code 637.7 to GPS trackers. Simmons v. Bauer Media Group USA, LLC held a suit over an investigator's tracker was not protected newsgathering under the anti-SLAPP statute; People v. Agnelli, a superior court appellate division, reversed a tracking conviction as vague for a consenting co-owner.
Opinions citing this section in our collection:
- People v. Agnelli (California Court of Appeal 2021)✓A man placed a GPS tracker on a car he co-owned with his estranged wife and was convicted under section 637.7(a); the court reversed, holding the statute unconstitutionally vague as applied because it does not say whether every registered co-owner must consent.
- Simmons v. Bauer Media Group USA, LLC (California Court of Appeal 2020)✓A tabloid publisher's hired private investigator put a tracker on Richard Simmons's caretaker's car; the court held the claims, built on that section 637.7 violation, arose from illegal conduct rather than protected newsgathering, and left the anti-SLAPP denial in place.
- The People v. Barnes (California Court of Appeal 2013, 216 Cal. App. 4th 1508)✓Police pinged a robbery victim's stolen cell phone with her consent and stopped the man carrying it; the court decided the case on Fourth Amendment grounds and cited section 637.7 only as instructive, noting its exceptions for owner consent and lawful law enforcement use.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: GPS Tracking Laws by State: Is It Legal to Put a Tracker on a Car? (2026), California GPS Tracking Laws: Is It Legal to Put a Tracker on a Car? (2026)
United States Code Title 18
§ 2510DefinitionsIn forcecited in 126 of our articles
As used in this chapter— “wire communication” means any aural transfer made in whole or in part through the use of facilities for the transmission of communications by the aid of wire, cable, or other like connection between the point of origin and the point of reception (including the use of such connection in a switching station) furnished or operated by any person engaged in providing or operating such facilities for the transmission of interstate or foreign communications or communications affecting interstate or foreign commerce; “oral communication” means any oral communication uttered by a person exhibiting an expectation that such communication is not subject to interception under circumstances justifying such expectation, but such term does not include any electronic communication; “State” means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, and any territory or possession of the United States; “intercept” means the aural or other acquisition of the contents of any wire, electronic, or oral communication through the use of any electronic, mechanical, or other device.1 So in original. The period probably should be a semicolon.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 2,382 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States v. New York Telephone Co. (1977) held that pen registers fall outside Title III because they do not acquire the contents of a communication as Section 2510(4) and (8) define interception. Forsyth v. Barr (1994) applied the same definitions, treating the defendant officers as law enforcement officers under Section 2510(7).
Opinions citing this section in our collection:
- Forsyth v. Barr (Court of Appeals for the Fifth Circuit 1994, 19 F.3d 1527)✓Neighbors tapped an informant's home line and the overheard charges reached Dallas internal affairs; the Fifth Circuit saw no evidence the police defendants intercepted anything and held they were 2510(7) law enforcement officers, so 2517(1) and (2) allowed their use of it.
- Nixon v. Administrator of General Services (Supreme Court of the United States 1977, 433 U.S. 425)“…of the Omnibus Crime Control and Safe Streets Act of 1968, 18 U. S. C. §§ 2510 et seq. 408 F. Supp., at 363 . We…”
- Gannett Co. v. DePasquale (Supreme Court of the United States 1979, 443 U.S. 368)“…of the Omnibus Crime Control and Safe Streets Act of 1968, 18 U. S. C. § 2510 et seq., be preserved prior to the d…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Surveillance Camera Laws by State (2026 Guide), US Recording Laws by State (2026): All 50 States Explained, Georgia Recording Laws (2026): One-Party Audio, All-Party Video
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 18 U.S.C. § 2510(5)(a), Electronic Communications Privacy Act (business-extension exemption / ordinary course of business exception)(law.cornell.edu).gov
- Watkins v. L.M. Berry & Co., 704 F.2d 577 (11th Cir. 1983)(law.resource.org)
- California Labor Code § 980, social media privacy protections(leginfo.legislature.ca.gov).gov
- California Labor Code § 435, recording employees in restrooms, locker rooms, and changing rooms(leginfo.legislature.ca.gov).gov
- California Penal Code § 637.7, electronic tracking devices(leginfo.legislature.ca.gov).gov
- Hernandez v. Hillsides, Inc., 47 Cal.4th 272 (2009)(scocal.stanford.edu)
- CPPA Final Statement of Reasons, CCPA Updates, Cybersecurity Audits, Risk Assessment, and Automated Decisionmaking Technology Regulations (2025)(cppa.ca.gov).gov
- AB 1221, Workplace surveillance tools, California Legislature (failed February 2, 2026)(leginfo.legislature.ca.gov).gov
- AB 1331, Workplace surveillance, California Legislature (inactive file September 13, 2025)(leginfo.legislature.ca.gov).gov
- Meta pauses controversial employee-tracking program after security review, Malwarebytes(malwarebytes.com)
- California Civil Code § 1798.140(d), CCPA definition of "business" and its coverage thresholds(leginfo.legislature.ca.gov)