An HR director reads that twenty states now have comprehensive privacy laws and assumes the employee file just became a compliance project in twenty places. In most of those states, it did not. The statutes define the protected individual as a "consumer" and then expressly exclude people acting in an employment or commercial context — job applicants, employees, contractors, directors, and business contacts.
California is the exception that changes the plan for national employers. Its law covers workforce and business-contact data on essentially the same terms as consumer data. And underneath both, a layer of older, narrower rules — biometric statutes, monitoring-notice laws, background-check rules, medical-confidentiality duties — applies to every employer regardless of what the comprehensive statutes say.
Why most states leave employee data out
The Virginia-model statutes that most states copied define "consumer" as a resident acting in an individual or household context, and expressly not as someone acting in a commercial or employment context. The result is that access, deletion, correction, and opt-out rights do not attach to the personnel file in those states, and the required processing notices do not either.
That exclusion is a legislative choice, not a statement that employee data is unregulated. Employment law already governs much of the same territory through recordkeeping duties, medical-confidentiality rules, and wage-and-hour documentation requirements. Which statutes reach your business in the first place — thresholds, revenue tests, and sector carve-outs — is worked through in the guide to state consumer privacy laws.
| Question | Virginia-model states | California |
|---|---|---|
| Are employees covered? | No — employment context excluded | Yes — employees, applicants, and contractors |
| Business contacts? | No | Yes |
| Notice at collection | Not required for HR data | Required, by category and purpose |
| Access and deletion rights | Not applicable to HR data | Applicable, with employment-record exceptions |
| Sensitive data limits | Consumer context only | Applies to workforce data, with a use-limitation right |
| Vendor contract terms | Required for consumer data flows | Required for HR data flows too |
What California asks of employers
Since the CPRA amendments took effect, California employers must treat workforce data much as they treat customer data. That means a notice at collection given at or before the point of collection, describing the categories of personal information collected, the purposes, retention periods, and any sale or sharing. It means honoring access, deletion, and correction requests, subject to exceptions that protect employment records, legal holds, and investigations. It means offering a right to limit the use of sensitive personal information, and honoring opt-outs where data is sold or shared.
It also means the HR technology stack needs proper contracts. Applicant tracking systems, payroll and benefits administrators, background-check firms, engagement-survey tools, and workforce analytics vendors all process personal information on the employer's behalf, and each needs terms with the statutorily required content — the substance covered in data processing agreements. The California Attorney General's CCPA pages remain the reference point for current requirements and enforcement posture.
Watch out: Deletion requests from employees are not a licence to purge. Payroll records, tax filings, safety records, benefits data, and anything under litigation hold generally must be retained. Build a documented exception analysis into the response workflow so denials are consistent and explainable.
The rules that apply no matter which state you are in
These predate the comprehensive statutes and are, in practice, where most workplace privacy liability actually arises.
- Biometric data. Fingerprint timeclocks, face-based access control, and voiceprints are regulated by several state biometric statutes requiring written notice and consent before collection, published retention schedules, and limits on disclosure. Illinois's statute is the most consequential because it allows individuals to sue directly.
- Electronic monitoring. A number of states require advance written notice — sometimes at hire, sometimes posted — before monitoring email, internet use, or telephone calls. Requirements vary by state and are worth confirming individually.
- Call and video recording. Consent rules split between one-party and all-party states. A recorded support line staffed across several states is a common compliance gap.
- Background checks. Federal fair-credit rules require standalone disclosure, written authorization, and a pre-adverse-action process with a copy of the report before a decision is finalized.
- Medical and genetic information. Disability-related records must be kept confidential and separate from the personnel file, and genetic information carries its own federal restrictions.
- Social media and personal accounts. Many states prohibit demanding personal account credentials from applicants or employees.
- Personnel file access. A number of states give employees a statutory right to inspect or copy their own file within a set period.
- Breach notification. Every state's breach law covers employee records as readily as customer records; workforce data is a frequent notification trigger.
Automated tools add another layer. Where an employer uses algorithmic screening or evaluation, some jurisdictions now require candidate notice, bias auditing, or a disclosure about the tool's use — obligations that sit alongside ordinary discrimination law and are treated at length in the guide to governance for automated and AI-assisted decisions.
Building one workforce data program
- Inventory the HR stack. List every system holding worker data, what it holds, who can see it, where it is hosted, and how long it retains records. Include spreadsheets and shared drives — that is where the surprises live.
- Map by state. Note where your workers actually sit, including remote hires, and flag California, biometric-statute states, and monitoring-notice states.
- Write the notices. One collection notice for California, plus monitoring and biometric notices wherever required, delivered at the right moment — offer letter, onboarding, device issuance.
- Set retention rules. Give each record type a defined period tied to a legal basis, and automate disposal. Indefinite retention is the most common finding in an HR data review.
- Fix the vendor paperwork. Contract terms, subprocessor lists, breach clocks, and deletion duties for every HR system.
- Rehearse the request workflow. Identity verification, exception analysis, response deadlines, and a log. Practice on an internal test request before a real one arrives.
- Align the handbook. Policies on monitoring, device use, and personal data should match what the systems actually do — the discipline described in handbooks that match workplace practice.
Practical step: Use a recognized structure to organize the work rather than inventing categories. The NIST Privacy Framework maps identification, governance, control, and communication activities in a way that translates cleanly to an HR data inventory and makes gaps visible to non-lawyers.
Security expectations run alongside all of this. Payroll files, immigration verification documents, and benefits data are prime targets, and the FTC's privacy and security guidance describes the kind of reasonable safeguards regulators expect any custodian of sensitive records to maintain.
Quick answers
We are a small employer with a few California remote workers. Are we covered?
Only if the business meets California's applicability thresholds, which turn on revenue, the volume of California personal information handled, or revenue derived from selling data. Employee headcount is not itself the test, but employee records count toward the data volume. Run the threshold analysis on total California data — customers and workers together — rather than assuming a few remote hires are immaterial.
Can we monitor company laptops and email?
Generally yes, on company systems and for legitimate business purposes, but notice requirements and scope limits vary by state and monitoring of protected concerted activity raises separate labor-law issues. Give clear written notice at hire and at device issuance, describe what is monitored, avoid capturing personal accounts and non-work locations, and apply the policy uniformly rather than selectively.
An employee asked for everything we hold about them. What now?
Determine first whether a right applies — in most states it does not for employment data, in California it does. Then check the state's personnel file access law, which may create a separate and narrower right. Verify identity, define the search scope, apply exceptions for privileged material and third-party information, respond within the applicable deadline, and log the whole sequence.
Do these rules reach data about contractors and applicants?
In California, yes — independent contractors, job applicants, and former employees fall within the same coverage as current staff. Elsewhere, the employment-context exclusion generally covers them too, so no consumer rights attach. Background-check rules, biometric statutes, and breach-notification duties apply to applicants and contractors regardless of state.
A sensible order of operations
Inventory first, then map your workforce by state, then write the notices the states you touch actually require. Treat California as the demanding case and build the rights workflow there, because a workflow that handles California handles the rest. Give equal weight to the always-on rules — biometrics, monitoring notice, recording consent, background checks, medical confidentiality — since those carry the private lawsuits. Fix retention and vendor contracts last, but do fix them. Related material on vendors, transfers, and interface obligations sits in the technology, privacy, and IP pathway.