Employment and HR

HR & Employment Privacy Law

The workplace is a unique privacy environment where employers' legitimate business interests intersect with employees' privacy rights. From the hiring process through employment and beyond, HR departments collect, use, and store vast amounts of personal information about current, former, and prospective employees. Navigating this complex landscape requires understanding federal and state employment laws, privacy regulations, and best practices for protecting sensitive employee data.

The Framework Employers Operate Under

There is no single employment privacy statute in the United States. Employers operate under a patchwork: the FCRA for background checks, the ADA for medical information, GINA for genetic information, the ECPA for electronic monitoring, the NLRA for concerted activity, state personnel records statutes for access rights, state social media statutes for account credentials, state biometric statutes for identifiers, and state comprehensive privacy laws that increasingly cover employee data outright.

The default position is more permissive than employees generally assume. On employer-owned systems, in an employer-controlled workplace, an employer has broad latitude to monitor. Most of the meaningful constraints come from state law and from specific statutes attaching to specific categories of information, rather than from any general right of privacy at work.

Background Checks and the FCRA Sequence

Where an employer uses a third party to compile information about an applicant or employee, that report is a consumer report and the FCRA applies. The sequence is prescribed and the order matters. Before obtaining the report, the employer must provide a clear and conspicuous written disclosure in a document consisting solely of that disclosure, and obtain written authorisation. The standalone requirement is enforced strictly: including a liability waiver or extraneous text in the same document has itself been the basis for litigation.

If the employer intends to act adversely on the basis of the report, it must first provide a pre-adverse action notice with a copy of the report and the Summary of Consumer Rights, then allow a reasonable period for the applicant to respond, then issue the adverse action notice identifying the reporting agency and stating that the agency did not make the decision. Separately, ban-the-box statutes in many states and cities delay when criminal history may be asked about, several states restrict credit history for most roles, and EEOC guidance addresses the disparate impact risk of blanket criminal history exclusions under Title VII.

Medical and Genetic Information

The ADA restricts disability-related inquiries and medical examinations by reference to the stage of the process. Before a conditional offer, they are prohibited. After a conditional offer and before employment begins, they are permitted if required of all entering employees in the same job category. For current employees, they are permitted only where job-related and consistent with business necessity. Medical information obtained at any stage must be maintained in separate confidential files, apart from the personnel file, with access limited to defined circumstances.

GINA prohibits requesting, requiring or purchasing genetic information, which is defined to include family medical history. This is where employers most often stumble inadvertently: a medical inquiry that is otherwise lawful can capture family history in the response, and the regulations provide safe harbour language directing the provider not to supply genetic information. Employer-sponsored group health plans engage HIPAA separately, but that reaches the plan rather than the employer in its capacity as employer, and the firewall between the two is a compliance obligation in itself.

Monitoring Communications and Devices

The ECPA prohibits interception of electronic communications subject to exceptions an employer typically relies on: the provider exception for systems it supplies, the ordinary course of business exception, and consent. Several states require all-party consent for recording, which changes the analysis for call recording and for tools that capture audio.

Notice obligations are increasingly explicit. New York requires employers to notify employees of monitoring of telephone, email and internet access on hiring and to post notice. Connecticut requires notice of electronic monitoring. Delaware has its own requirement. Beyond communications, the scope of monitoring now extends to location tracking through company vehicles and devices, keystroke and screenshot capture in productivity software, and automated assessment of performance, and several jurisdictions have begun regulating automated decision tools used in employment specifically, including New York City’s bias audit requirement for automated employment decision tools.

Biometrics in the Workplace

Fingerprint and facial recognition timekeeping is where employment privacy has generated the most litigation, almost entirely under one statute. Illinois’s Biometric Information Privacy Act requires a private entity to inform the subject in writing that a biometric identifier is being collected and of the specific purpose and length of term, obtain a written release, publish a retention schedule and destruction guidelines, and refrain from selling or profiting from the identifiers.

What distinguishes BIPA is the private right of action with statutory damages per violation, available without proof of actual injury. The Illinois Supreme Court has held that a person need not allege harm beyond the statutory violation itself, and has addressed how claims accrue on repeated scans. Texas and Washington regulate biometric identifiers on similar principles but reserve enforcement to the state, which is why the litigation is concentrated in Illinois rather than distributed across the states that regulate the practice.

Employee Data Under State Privacy Statutes

California’s temporary exemption for employment-related information expired on 1 January 2023. Employees, applicants and independent contractors now hold the same rights as consumers against their employer: access, deletion, correction, portability, and the right to limit use of sensitive personal information. Employers must serve a notice at collection specifying the categories collected and the purposes, and must respond to rights requests from their own workforce.

Most other state comprehensive statutes exclude data processed in an employment context, so this is currently a California-specific obligation rather than a national one. That asymmetry is itself an operational problem for multi-state employers, since a single HR system holds records subject to different rules depending on where the employee sits.

Records, Access and Retention

State personnel file statutes give employees a right to inspect their own records, and they vary on scope, timing, whether copies must be provided, whether a former employee retains the right, and whether a rebuttal statement may be added to a disputed document. There is no federal equivalent, so this is determined entirely by the state of employment.

Retention obligations pull in the opposite direction from privacy minimisation. Different federal rules set different minimum periods for payroll records, benefit plan records, I-9 forms, medical and exposure records, and records relevant to an anticipated or pending claim, and a litigation hold overrides a routine deletion schedule. The practical result is that a defensible retention schedule has to be built from the specific obligations attaching to each record category, rather than from a single organisation-wide period.

Frequently Asked Questions

Can my employer read my work email?

Generally yes on employer-owned systems, subject to state law. Connecticut and New York require notice of electronic monitoring, and other states impose their own conditions. Federal wiretap law contains business-use and consent exceptions that employers typically rely on.

Is a fingerprint or face-scan timeclock legal?

In Illinois, BIPA requires written notice, a written release, a published retention and destruction schedule, and bars profiting from biometric identifiers. It carries a private right of action, which is why most biometric litigation is filed there. Texas and Washington regulate biometrics but leave enforcement to the state.

Does an employer need consent to run a background check?

Under FCRA an employer must provide a standalone written disclosure and obtain authorization before obtaining a consumer report, then give a pre-adverse action notice with a copy of the report and a summary of rights before acting on it.

Are employees covered by the CCPA?

Yes. The exemption for employment-related data expired on 1 January 2023, so California employees, applicants and contractors hold access, deletion, correction and opt-out rights against their own employer.

Can an employer ask about medical conditions?

The ADA restricts disability-related inquiries and medical examinations. For current employees they are permitted only where job-related and consistent with business necessity, and medical information must be kept in separate confidential files. GINA separately restricts requesting genetic information, which includes family medical history.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.