Employee Privacy

Employee Privacy Under State Law, in the Order the Statutes Arrived

Key Takeaways

  • The oldest layer is the right to read your own file. Delaware's 19 Del. C. § 732 lets an employee inspect the personnel file used to determine qualifications for employment, promotion, compensation, termination or discipline; California's Labor Code section 1198.5 sets a 30-calendar-day deadline for producing records after a written request.
  • California's Penal Code section 632 requires the consent of all parties to record a confidential communication, with penalties up to $2,500 per violation and a rule making the recording inadmissible.
  • Delaware's 19 Del. C. § 705 requires notice before an employer monitors email, telephone or internet usage — either daily electronic notice or a one-time written notice the employee acknowledges — with a $100 civil penalty per violation.
  • California's Labor Code section 980 bars an employer from requesting a personal social media username or password, with a carve-out for misconduct investigations and for employer-issued devices.
  • The newest layer is the largest: California's CCPA exemptions for employee and applicant data became inoperative on January 1, 2023, by their own terms, making employees consumers under the statute.

Read the Stack in Order and the Gaps Explain Themselves

Asking what privacy rights an employee has at work produces an unsatisfying answer, because the question assumes a single body of law that does not exist. No state has enacted an employee privacy act. What every state has instead is an accumulation — a handful of statutes passed decades apart, each drafted in response to a specific technology, none of them written with the others in view.

The usual way to present this material is state by state. That arrangement obscures the thing most worth understanding, which is that the layers do not fit together. A statute drafted in the era of a filing cabinet does not anticipate a laptop; a statute about passwords does not anticipate a fingerprint scanner at the door.

This guide therefore takes the layers in the order they arrived, using specific statutes as the worked example of each. Doing so makes the shape of the coverage visible: each layer solves the problem in front of it and leaves the surrounding ground untouched, and the empty ground between layers is where most workplace privacy questions actually sit.

Layer One: The Right to Read Your Own File

The earliest workplace privacy statutes were not about surveillance. They were about access — the recognition that an employer held a file that determined a person's livelihood and that the person could not see it.

Delaware's version, at 19 Del. C. § 732, provides that an employer shall at a reasonable time, on request, permit an employee to inspect their own personnel files "used to determine that employee's own qualifications for employment, promotion, additional compensation, termination or disciplinary action." The framing is narrow by design: the right attaches to the records that drive consequential decisions.

The section's surrounding provisions show how carefully the balance was struck. The employer makes records available during regular business hours at the office where they are ordinarily maintained, may require a written request form solely to identify the requester, and may require the employee to inspect on their own free time. Section 733 provides that nothing requires the employer to let the file leave the premises, permits note-taking, allows the employer to require inspection in the presence of a designated official, requires sufficient inspection time commensurate with the volume of the file, and — except for reasonable cause — permits the employer to limit inspection to once every calendar year.

Section 734 supplies the remedy for a disputed entry. Where the employee disagrees with information in the file, removal or correction may be agreed between employee and employer; failing agreement, the employee may submit a written statement explaining their position, and that statement is maintained as part of the file and "shall accompany any transmittal or disclosure from such file or records made to a third party." A correction right that cannot compel deletion still travels with the record.

California's Labor Code section 1198.5 is the same layer with tighter deadlines. Every current and former employee, or their representative, has the right to inspect and receive a copy of the personnel records the employer maintains relating to performance — including education or training records — or to any grievance concerning the employee. The employer makes the contents available for inspection at reasonable intervals and times, but not later than 30 calendar days from receipt of a written request, extendable by written agreement to no more than 35 days. Copies are provided on the same timetable at a charge not exceeding the actual cost of reproduction.

The California section has also been kept current in a way most of this layer has not: where an employer maintains education or training records, those records must include the employee's name, the training provider's name, the duration and date of the training, the core competencies covered including equipment or software skills, and any resulting certification.

Layer Two: The Recording Statutes, Which Were Never About Work

The second layer arrived from an entirely different direction. Wiretap and eavesdropping statutes were written to govern recording generally, and they apply in the workplace only because the workplace is a place where conversations happen.

California's Penal Code section 632 is the most consequential example because of the consent standard it sets. A person who intentionally and "without the consent of all parties to a confidential communication" uses an electronic amplifying or recording device to eavesdrop upon or record that communication is subject to a fine not exceeding $2,500 per violation, imprisonment, or both, with the ceiling rising to $10,000 per violation for a repeat offender.

Three features of the section matter in an employment setting. "Person" is defined at subsection (b) to include a business association, partnership, corporation or limited liability company — an employer is squarely within it. "Confidential communication" is defined at subsection (c) as a communication carried on in circumstances reasonably indicating that a party desires it to be confined to the parties, excluding communications made where the parties may reasonably expect to be overheard or recorded. And subsection (d) makes evidence obtained in violation inadmissible in any judicial, administrative, legislative or other proceeding.

That last provision is why this layer reaches further than its penalties suggest. A recording made without all-party consent is not merely unlawful; it is unusable in the proceeding the employer might have wanted it for.

The definitional question the statute leaves open is what circumstances in a workplace reasonably indicate an expectation of confidence — a question the text answers only by its standard, which turns on facts about the particular room, conversation and practice rather than on employment status.

Layer Three: Passwords, and the Line at the Device

The third layer is the first written specifically for employment, and it addresses a practice that only became possible once employees had documented lives on services the employer did not control.

California's Labor Code section 980 defines social media broadly — an electronic service or account, or electronic content, including videos, photographs, blogs, podcasts, instant and text messages, email, online services or accounts, and website profiles. It then prohibits an employer from requiring or requesting an employee or applicant to disclose a username or password for the purpose of accessing personal social media, to access personal social media in the employer's presence, or to divulge any personal social media.

Two exceptions define the boundary precisely. Subsection (c) preserves an employer's existing rights to request that an employee divulge personal social media "reasonably believed to be relevant to an investigation of allegations of employee misconduct or employee violation of applicable laws and regulations," provided the material is used solely for that investigation or a related proceeding. Subsection (d) provides that nothing precludes an employer from requiring disclosure of a username, password or other access method for an employer-issued electronic device.

Subsection (e) adds an anti-retaliation rule: the employer may not discharge, discipline, threaten or otherwise retaliate against a person for not complying with a request that violates the section, while preserving adverse action otherwise permitted by law.

The line this layer draws is ownership of the device and the account, not the content. That is a coherent rule for 2012 and an increasingly strained one now, since the same handset commonly carries both.

Layer Four: Notice Before Monitoring

The fourth layer accepts monitoring as a given and regulates disclosure of it instead — a significant shift in what the law is trying to achieve.

Delaware's 19 Del. C. § 705 provides that no employer shall monitor or otherwise intercept any telephone conversation or transmission, email or transmission, or internet access or usage of a Delaware employee unless the employer either provides electronic notice of those monitoring policies or activities "at least once during each day the employee accesses the employer-provided e-mail or Internet access services," or has first given a one-time notice of the activity or policies. The one-time notice must be in writing or an electronic record and acknowledged by the employee in writing or electronically.

The penalty is modest — subsection (c) sets a civil penalty of $100 for each violation, claimable in any court of competent jurisdiction — but subsection (d) states that this is not an exclusive remedy and does not bar other remedies under other state or federal law or the common law.

Subsection (e) carves out the automated processes that would otherwise swallow the rule: the section does not apply to processes designed to manage the type or volume of incoming or outgoing email, voicemail or internet usage, that are not targeted at a particular individual, and that are performed solely for computer system maintenance or protection. Filtering is not monitoring; watching a named person is.

The statute reaches conduct rather than merely records, but it stops at notice. Once the acknowledgment is on file, the section imposes no limit on what may be monitored or for how long.

Layer Five: Bodies, and the Problem With Workplace Consent

The fifth layer arrives with biometric time clocks and access controls, and it raises a question the earlier layers never confronted: whether consent means anything when the person asking controls the person's job.

Colorado's House Bill 24-1130, effective July 1, 2025, amended the Colorado Privacy Act to add biometric protections. It requires a controller of biometric identifiers to adopt a written policy establishing a retention schedule, including a protocol for responding to a security incident that may compromise biometric data, and including guidelines requiring deletion by certain dates. It conditions collection on satisfying disclosure and consent requirements, and requires disclosure to the consumer about collection and use.

The provision that belongs to this guide rather than to a general biometrics discussion is the employment-specific one. Per the legislature's summary of the act as enacted, it "restricts an employer's permissible reasons for obtaining an employee's consent for the collection of biometric identifiers."

That is a different regulatory technique from anything in the earlier layers. Layers three and four regulate what an employer may ask for and what it must disclose. This one narrows the grounds on which consent may validly be sought at all — an acknowledgment that in a relationship where refusal carries a cost, permission obtained is not the same as permission given.

Layer Six: Employees Become Consumers

The most consequential change in this area did not come from an employment statute. It came from the expiry of an exemption in a consumer one.

When California's consumer privacy statute was enacted, it carried carve-outs for workforce data. Civil Code section 1798.145 exempted personal information collected about a natural person acting as a job applicant, employee, owner, director, officer, medical staff member or independent contractor, to the extent collected and used solely within the context of that role. Parallel carve-outs covered emergency contact information and information necessary to administer benefits.

Those exemptions were written with an expiry date rather than as permanent policy. The section's own text states that the subdivision "shall become inoperative on January 1, 2023," and the codified note records that "Subdivisions (m) and (n) inoperative January 1, 2023, by their own provisions."

The effect is structural rather than incremental. Workforce data in California is no longer governed only by the narrow, purpose-specific statutes described in the layers above. It falls inside a comprehensive privacy statute built around notice at collection, defined consumer rights, purpose limitation and a regulator with rulemaking authority — a framework designed for a retail customer and now applied to a personnel record.

That is the single largest expansion of employee privacy obligations in the period this guide covers, and it happened by a sunset clause taking effect rather than by anyone legislating about employment.

What This Guide Does Not Cover

This guide illustrates each layer with statutes it could retrieve and read in full. It is not a fifty-state survey, and the specific sections cited bind only in the states named.

Several states have electronic monitoring notice statutes and personnel file access statutes beyond the two used as examples here, and at least two of them could not be sourced for this guide: the research session could not retrieve statutory text from the Connecticut General Assembly's server, and the Illinois legislature's site returned an access error. Those states are named as gaps rather than described from memory. A reader whose question is about a particular state will need that state's text.

Two adjacent areas are also outside this guide's scope. Background screening in hiring is governed principally by the federal Fair Credit Reporting Act and is covered separately on this site. Biometric collection generally, including the enforcement design of the state biometric statutes, is treated in its own guide; only the employment-consent provision is drawn out here.

Finally, collective bargaining is a real constraint on workplace monitoring in unionised settings and is not addressed here at all, because the sources that would support a description of it were not consulted for this guide.

Frequently Asked Questions

How long does an employer have to produce a personnel file after a request?
In California, Labor Code section 1198.5(b)(1) sets 30 calendar days from receipt of a written request, extendable by written agreement to no more than 35 days, for both inspection and copies. Delaware's 19 Del. C. § 732 instead requires inspection "at a reasonable time" during regular business hours, and § 733 permits the employer to limit inspection to once per calendar year absent reasonable cause.
Can an employer record a workplace conversation?
California's Penal Code section 632 makes it an offence to record a confidential communication without the consent of all parties, with fines up to $2,500 per violation. Subsection (c) defines a confidential communication by whether the circumstances reasonably indicate a party desired it to be confined to the parties, so the answer turns on the setting rather than on the employment relationship.
May an employer ask for an employee's social media password?
Not in California. Labor Code section 980(b) bars requiring or requesting disclosure of a username or password for personal social media, accessing it in the employer's presence, or divulging it. Subsection (d) preserves the employer's ability to require access credentials for an employer-issued electronic device.
Does an employer have to tell employees it is monitoring their email?
Delaware requires it. 19 Del. C. § 705(b) permits monitoring of telephone, email or internet usage only where the employer gives daily electronic notice or a one-time written notice acknowledged by the employee. Subsection (e) exempts non-targeted processes performed solely for system maintenance or protection.
Are employees covered by California's consumer privacy law?
Yes, since the exemptions expired. Civil Code section 1798.145 carried carve-outs for job applicant and employee data, and those subdivisions became inoperative on January 1, 2023 by their own terms, so workforce data now falls within the statute's general framework.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.