Employee Data Privacy: What US Employers Must Do
Employee data privacy for US employers: the state law patchwork, why California is different, medical and biometric rules, breach duties, disposal.
Employee Data Privacy
What a US employer must do with the personal data it holds about its own staff
The first time an employee asked me exactly what personal data we held about him, I did not have a good answer. I knew where his signed offer letter was. I could not have told you, without an afternoon of digging, every place his home address, his bank details and a scanned copy of his passport had been copied to over eighteen months.
That was not a compliance failure in any technical sense. Nobody had breached anything. But it was the moment I understood that the file cabinet metaphor most small employers carry around is wrong. Employee data is not in a file. It is in a payroll system, a benefits portal, three shared drives, an email thread from the week he was hired, and a spreadsheet a manager built and never told anyone about.
This guide covers what a US employer owes its own staff on privacy: where the obligations come from when there is no single law, which state rules reach your workforce records and which ones deliberately do not, what you must be able to do when someone exercises a right, and the categories of data that carry their own rules no matter where you operate. I built the document handling in FirstHR around this problem, because the honest state of most small companies is not carelessness. It is not knowing where anything is.
What Employee Data Privacy Requires of an Employer
Employee data privacy is the set of duties an employer owes regarding the personal information it collects about its own workforce: collect only what you need, tell people what you collect, keep the sensitive categories separate, protect it, hand it over or delete it when someone has a legal right to ask, and notify people when it leaks. Those six duties are the whole of it.
What makes this hard is not the concept. It is that no single statute states those six duties in one place. An employer in the European Union reads one regulation. An employer in the United States reads a federal medical confidentiality rule, a federal background check statute, a state breach law, possibly a state biometric law, possibly a state comprehensive privacy law, and a contract with a payroll provider.
The result is that most small employers do privacy by accident. They keep medical notes in the wrong folder because nobody told them the ADA cared. They email a scanned driver license to a manager because it was faster. They hold a terminated employee’s bank details for six years because deleting things takes effort. None of that is malicious, and all of it is exposure.
The upside is that the underlying work is finite. A small business can build a defensible privacy posture in a few focused sessions, and most of it is one-time setup rather than ongoing labor. The trick is to organize around data categories rather than around laws, because a category can be handled once while the laws keep changing.
Why There Is No Single US Employee Privacy Law
There is no federal employee privacy statute because Congress never passed one. What exists instead is a set of laws each written to solve one narrow problem, layered over state laws written at different times for different reasons, layered over contract terms and common law tort claims. Five distinct sources of obligation reach the same employee record.
Reading that list, the useful insight is that the sources do not overlap cleanly. The ADA reaches medical data whether or not any state privacy law applies. A breach notification law reaches every employer in the state regardless of revenue. A comprehensive privacy law may reach nothing in your HR file at all. Compliance is not a single test you pass.
One recurring confusion is worth clearing up early. HIPAA does not govern your personnel records. The privacy rule excludes employment records held by a covered entity in its role as employer from the definition of protected health information, which means the health plan side is regulated and the HR side is not.
The practical translation: an employer who says "we are not covered by HIPAA, so employee health data is unregulated" has drawn the wrong conclusion from a correct premise. The ADA still applies, state medical confidentiality laws still apply, and a breach of health information still triggers notification. HIPAA is simply not the statute doing the work.
State Privacy Laws and Why California Is the Outlier
Roughly twenty states now have comprehensive consumer privacy laws in force, and with a single exception none of them reach employee data. Each one defines the protected "consumer" as an individual acting in a personal or household capacity and expressly excludes people acting in a commercial or employment context, which puts employees, applicants and contractors outside the law.
California is the exception, and the exception is total. The California Consumer Privacy Act originally carried a temporary carve-out for workforce data. That carve-out expired at the end of 2022 and was not renewed, so a covered California employer now owes its employees, applicants, independent contractors, directors and their beneficiaries the same rights it owes a retail customer. The California Attorney General publishes the current rights list.
Three more state-level layers ignore the employment exemption entirely, and these are the ones that catch small employers by surprise. Biometric statutes reach employers directly. Breach notification statutes exist in all fifty states plus the District of Columbia and apply to any business holding resident data. Personnel file access laws in roughly half the states give employees a right to inspect their own file.
So the correct mental model is not "does my state have a privacy law." It is a two-part question. First, does a comprehensive privacy law reach my workforce data, which for now means: do I have California staff and do I meet the thresholds. Second, which sector-specific state rules apply to the data types I actually hold, which is a question every employer has to answer.
| Layer of law | Does it reach employee data? | What triggers coverage | What you owe |
|---|---|---|---|
| California CCPA | Yes, in full since the exemption lapsed | Revenue, resident volume or data-sale revenue thresholds | Notice at collection plus access, deletion, correction, opt-out and limitation rights |
| Other state comprehensive privacy laws | No, employment context is excluded | Not applicable to workforce records | Nothing for staff data, though customer data may still be covered |
| State breach notification laws | Yes, everywhere | Holding personal data about a resident of that state | Notice to affected individuals, often to the attorney general above a threshold |
| State biometric laws | Yes, and aimed squarely at employers | Collecting fingerprints, face or voice scans | Written policy, informed consent before collection, retention schedule, destruction |
| State personnel file access laws | Yes, in roughly half the states | Being an employer in that state | Let the employee inspect or copy the file within the statutory window |
| State SSN protection laws | Yes, in most states | Holding Social Security numbers | Restrictions on display, transmission and disposal |
What the Rights Mean in Practice and How to Answer a Request
Four rights matter operationally: notice at collection, access, deletion and correction. Notice is the one you owe before anyone asks. The other three are reactive, and each requires you to be able to find every copy of a person’s data across every system inside a fixed window.
Notice at collection means a written statement, delivered at or before the moment you collect, listing the categories of personal information you collect, the purpose of each category, whether any of it is sold or shared, and the retention period or the criteria you use to set one. For an employer this belongs in the new hire paperwork packet, acknowledged and filed alongside the rest of the personnel file.
Access means the employee can ask what you hold and receive it. Deletion means they can ask you to erase it, subject to a long list of exceptions that let you keep what the law requires you to keep. Correction means they can require you to fix inaccurate information. None of the three is absolute, and all three require documented reasoning when you say no.
The request itself is where small employers fail, and the failure is almost never legal. It is logistical. The clock starts when the request arrives, not when you get around to it, and the search has to reach systems you do not control. Here is the sequence that actually works.
Two details deserve emphasis. Verify identity before you disclose anything, because handing an employee record to someone impersonating that employee is itself a breach. And suspend routine deletion the moment a request lands, because destroying responsive records after a request is a much worse fact pattern than holding data too long.
Outside California, the analogous right usually comes from a state personnel file access statute rather than a privacy law. Those are narrower: they cover the personnel file specifically, set their own deadlines, and often permit a copying charge. The process above still serves you, because a single well-run intake path handles both without you having to remember which law is in play.
The Data Categories That Carry Their Own Rules
Five categories of employee data carry federal or near-universal state rules that apply regardless of whether any comprehensive privacy law reaches you: medical information, immigration documents, background check data, Social Security numbers and biometric identifiers. Getting these five right resolves most of your exposure.
Medical information is the strictest and the most commonly mishandled. Under the ADA, anything obtained through a medical inquiry or examination must be collected on separate forms, held in separate medical files, and treated as a confidential medical record. That requirement sits in 29 CFR 1630.14, and it is not a best practice. It is the rule.
The scope is broader than people expect. Accommodation requests, doctor’s notes, fitness-for-duty certifications, workers’ compensation records, drug and alcohol test results, health plan enrollment forms and anything from a wellness program all belong in the confidential medical file. GINA extends the same separation to genetic information, including family medical history you learn about incidentally.
Immigration documents follow their own logic. Form I-9 must be retrievable on demand for a government inspection, which is why almost every practitioner keeps I-9s in a separate binder or folder for all employees rather than inside individual files. Copies of the underlying documents, if you take them, must be kept consistently for everyone.
Background check data is governed by the Fair Credit Reporting Act whenever the report comes from a screening company. The FCRA requires a standalone written disclosure, separate authorization, a pre-adverse action notice with a copy of the report before you act, and a final adverse action notice after. The Federal Trade Commission publishes the employer guidance.
Social Security numbers are the highest-value item in your file and the one most employers treat most casually. There is no single federal statute restricting employer use, but most states restrict public display, transmission over unsecured channels and printing on documents. Treat the SSN as encrypted-at-rest, visible to payroll only, and never in an email body or a spreadsheet column.
| Data category | What rule governs it | Where it must live | How long you keep it |
|---|---|---|---|
| Medical, accommodation, workers’ comp | ADA, 29 CFR 1630.14; state medical confidentiality laws | Separate confidential medical file, restricted to one or two people | Per the record-specific rule, then destroy; never merged into the personnel file |
| Genetic and family medical history | GINA Title II, 29 CFR 1635.9 | Same confidential medical file as ADA material | Same as other medical records, kept apart from performance data |
| Form I-9 and supporting copies | IRCA; USCIS inspection rules | Separate I-9 file or binder covering all staff | Three years after hire or one year after termination, whichever is later |
| Background check reports | FCRA, 15 USC 1681b; FTC Disposal Rule, 16 CFR 682 | Separate confidential file, not the personnel file | Long enough to defend the hiring decision, then disposed of by shredding or wiping |
| Social Security numbers | State SSN protection and disposal laws | Payroll system field, encrypted, role-restricted | As long as tax and payroll rules require, then purged from ad hoc copies |
| Biometric identifiers | State biometric statutes, notably Illinois BIPA | Vendor system under a written policy and signed consent | Per your published retention schedule, destroyed when the purpose ends |
| Payroll and bank details | State breach and SSN laws; vendor contract | Payroll provider only, never in email or a shared sheet | Per payroll record rules, then removed from any secondary copies |
Note the pattern running through that table. Almost every category has a natural home outside the main personnel file, and almost every failure happens when someone puts it in the main file for convenience.
Biometric Data Is Where the Litigation Risk Actually Lives
Biometric data is the one employee privacy category that reliably produces expensive litigation, because Illinois gives employees a private right of action and most other privacy rules do not. If you use a fingerprint time clock, a face scan for door access or voiceprint authentication, this is the section that matters most.
The Illinois Biometric Information Privacy Act requires a written policy that is publicly available, states a retention schedule and destruction guidelines, and obtains informed written consent before the first collection. Statutory damages run to $1,000 per negligent violation and $5,000 per intentional or reckless violation, and the plaintiff does not have to show any actual harm.
An amendment signed in 2024 narrowed the exposure considerably. Repeated collection of the same identifier from the same person by the same method now counts as one violation rather than one per scan, which had been the theory driving nine-figure demands, and an electronic signature counts as a valid written release. The statute remains the most dangerous in the country for employers, but the arithmetic is no longer absurd.
Other states regulate the same conduct without the private right of action. Texas imposes notice and consent duties under its capture of biometric identifiers statute. Washington does the same, and RCW 19.375.030 states plainly that the chapter may be enforced solely by the attorney general. Colorado added employer biometric obligations to its privacy act effective July 1, 2025, and those provisions apply to employees even though the rest of the Colorado statute exempts employment data.
The operational rule is short. Before you switch on any device that reads a body part, check the states where your staff physically work, publish a policy, collect a signed consent from every person enrolled, and confirm in writing what your vendor does with the templates. A time clock is not worth a class action.
Breach Notification: What You Must Do and How Fast
Every state plus the District of Columbia has a breach notification law, and every one of them applies to employee data the same way it applies to customer data. If personal information about a resident of that state is acquired by an unauthorized person, you owe notice, and the deadline is set by the law of the employee’s state rather than yours.
Most statutes use a standard of the most expedient time possible and without unreasonable delay. Several set a hard outside limit. Colorado and Florida both require notice within thirty days of determining that a breach occurred, and both require notice to the state attorney general when five hundred or more residents are affected. Florida allows an additional fifteen days for good cause submitted in writing.
The scenario that catches employers is not a hacker. It is a laptop left in a car, a payroll file emailed to the wrong address, an ex-employee whose access was never revoked, or a vendor incident that surfaces weeks later. Two of those four are prevented entirely by a proper offboarding checklist, and a third by treating payroll security as a separate discipline.
Retention and Secure Disposal
Privacy law and records law point in opposite directions, and holding both ideas at once is the whole discipline. Records law sets floors: keep this document for this long. Privacy law sets a ceiling: do not hold personal data past the purpose you collected it for. Your schedule lives in the space between the two.
I am not going to restate the retention periods here, because they belong in one place and that place is our record retention guide. What matters for privacy is the other half of the schedule: the disposal column. A retention schedule with no disposal step is not a schedule. It is an accumulation policy with better formatting.
Secure disposal has a specific legal meaning for some data. The FTC Disposal Rule at 16 CFR Part 682 requires reasonable measures to protect against unauthorized access when you dispose of information derived from a consumer report, which for an employer means background check results. Shredding, burning or pulverizing paper. Wiping or destroying electronic media. Handing a box to the recycling company does not qualify.
Most states add their own disposal requirements for records containing Social Security numbers or other identifiers, and the standard is similar: render the information unreadable. The practical version for a small business is a cross-cut shredder for paper, a documented wipe procedure for drives, and a written note of what was destroyed and when.
One rule overrides the entire schedule. The moment you reasonably anticipate litigation, an agency charge or an audit, you place a legal hold and stop destroying anything potentially relevant, including automated deletion routines. Destroying records after a claim becomes foreseeable turns a defensible case into spoliation, and courts punish that far harder than they punish the underlying dispute.
Monitoring and What You Have to Disclose First
You can monitor company systems in most circumstances, but in several states you must tell employees in writing before you start, and everywhere you are far better off having disclosed it. Monitoring conducted without notice is the fastest route from an ordinary employment dispute to a privacy claim.
New York requires employers who monitor telephone conversations, email or internet usage to provide written notice upon hiring, acknowledged by the employee in writing or electronically, with civil penalties that escalate from five hundred dollars for a first offense to three thousand for repeat offenses, enforced by the attorney general. Connecticut and Delaware impose their own notice requirements with different mechanics.
The federal baseline is more permissive. The Electronic Communications Privacy Act permits interception where one party consents and provides a business use exception for equipment used in the ordinary course of business. Consent is much easier to prove when it is a signed acknowledgment than when it is an inference from a handbook nobody opened.
Two boundaries hold almost everywhere. Do not monitor what you did not disclose, and do not claim monitoring rights you never exercise, because an overbroad policy invites the argument that you were reading things you had no business reading. Restrooms, changing areas and personal devices you do not manage stay off limits regardless of what the handbook says.
Vendors: What Your Payroll or Benefits Provider Does With the Data
Your vendors hold the same sensitive data you do, and in most states the notification duty after their breach lands on you rather than on them. Breach statutes typically place the obligation on the entity that owns or licenses the data and require the holder to notify the owner so the owner can notify the affected people.
That single legal detail should change how you buy software. A payroll provider, a benefits administrator, a background screening company and an HR platform each hold names, Social Security numbers, bank details and sometimes health information. If any of them is compromised, your employees receive a letter with your company name at the top, and your contract decides who pays for it.
There are six questions worth asking before you sign anything that touches employee data, and any provider worth using answers all six without hesitation. Ask them in writing, keep the answers, and revisit them at renewal rather than never.
| Ask the vendor | What a good answer looks like | What should worry you |
|---|---|---|
| Which subprocessors touch our employee data? | A current written list with locations, updated when it changes | A vague reference to trusted partners with no names |
| What is your breach notification commitment to us? | A specific number of hours from determination, written into the contract | Prompt notice with no defined time frame |
| Can we see your security documentation? | A current independent audit report or certification, provided under NDA | Marketing pages about bank-level encryption and nothing else |
| Where is the data stored and who can access it? | Named regions, role-based access controls, logged administrative access | Cannot say, or support staff have standing access to production data |
| What happens to our data when we leave? | Export in a usable format, then deletion within a stated window, confirmed in writing | Data retained indefinitely or deleted on an unspecified schedule |
| Who indemnifies notification costs after your incident? | The vendor, with a cap you can live with | You do, or liability is capped at one month of fees |
Two structures deserve extra scrutiny. If you use a professional employer organization, the co-employment relationship means a third party holds your entire workforce record set, so read the data terms in the service agreement rather than assuming. And consolidating systems is itself a privacy control, since fewer copies means fewer places to search and fewer places to lose, which is the quiet argument for a single HRIS over five disconnected tools.
The Privacy Program a Small Business Can Actually Run
A realistic employee privacy program for a company without a dedicated HR department has seven parts, takes a few focused sessions to build, and is mostly one-time setup. It is not a policy binder. It is a map, a set of walls between data categories, a schedule, and two short playbooks.
The sequencing matters. Steps one and two produce most of the risk reduction and can be done in an afternoon. Steps three through five formalize what you did. Steps six and seven are what separate a company that survives an incident from one that improvises through it badly.
Where the software helps is in collapsing the map. A single system holding employee records with role-based permissions, separate confidential storage, and an audit trail of who opened what removes most of the search problem before it starts. That is the connection between document management and privacy: they are the same project viewed from two angles, and doing one well delivers the other.
Run the whole thing past a review once a year, alongside whatever else you check in an HR audit. Privacy obligations change faster than most employment rules, state legislatures keep passing new ones, and a program built two years ago and never revisited is a program that describes a company you no longer are.
Frequently Asked Questions
Do US employers have to comply with data privacy laws for employee data?
Yes, but not through a single statute. The United States has no general employee privacy law, so the duties arrive from several directions at once. Federal statutes govern specific data types: the ADA covers medical information, GINA covers genetic information, and the FCRA covers anything a screening company sends you. State laws add breach notification in every state, biometric consent rules in a handful, Social Security number restrictions in most, and personnel file access rights in about half. Contracts with your payroll and benefits vendors add more. The practical effect is that no employer is exempt. Even a company with a dozen people on the books has to notify affected staff after a breach, keep medical records separate, and dispose of background check data securely.
Does the CCPA apply to employees and job applicants?
Yes. California is the only state whose comprehensive privacy law reaches workforce data in full. The temporary exemption for employee, applicant, contractor, director and beneficiary data expired at the end of 2022, so from January 2023 onward a covered employer owes its California staff the same rights it owes a customer. That means a notice at collection before or at the moment you collect, plus rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation for asking. Coverage depends on the business thresholds, not on headcount: gross annual revenue above the statutory figure, or buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning half of revenue from selling or sharing personal information.
What must an employer do when an employee asks for a copy of their data?
It depends on which law gives them the right, and the answer starts with identifying that law. In California, a covered employer has 45 calendar days to respond to a verifiable request, extendable once by another 45 days with written notice, and must verify identity before disclosing anything. Outside California, the right usually comes from a state personnel file access law, which is narrower: it covers the personnel file itself, sets its own deadline, and often lets you charge a copying fee. Either way, run the same process. Log the request, verify who is asking, suspend routine deletion of anything responsive, search every system including the payroll and benefits providers, redact other people’s personal data, and document your reasoning for anything you withhold.
Can an employer keep medical information in the personnel file?
No. Under the ADA, information obtained from a medical inquiry or examination must be collected on separate forms, kept in separate medical files, and treated as a confidential medical record. That rule sits in 29 CFR 1630.14 and applies to every covered employer, regardless of which state you operate in and regardless of whether any privacy statute reaches your workforce data. GINA imposes the same separation on genetic information, including family medical history picked up incidentally. In practice this means a second locked file or a separately permissioned folder that the hiring manager cannot open. Doctor’s notes, accommodation paperwork, workers’ compensation records, drug test results and health plan enrollment forms all belong there. Supervisors get told about work restrictions and accommodations only, never the underlying diagnosis.
Do we need consent before collecting fingerprints for a time clock?
In several states, yes, and the consent has to be written and informed before the first scan. Illinois is the state that matters most because its Biometric Information Privacy Act carries a private right of action, which means employees can sue directly rather than waiting for a regulator. Illinois requires a written, publicly available policy with a retention schedule and destruction guidelines, plus a signed release before collection. Texas and Washington impose notice and consent duties too, but both reserve enforcement to the state attorney general. Colorado added employer biometric obligations to its privacy act effective July 1, 2025, and those provisions apply to employees even though the rest of the Colorado law exempts employment data. Before you switch on a fingerprint or face scan clock, check the states where your staff actually work.
Who is responsible if our payroll vendor has a data breach?
Legally, you usually are, at least to your employees. Most state breach notification statutes place the notice duty on the entity that owns or licenses the data, and require the vendor holding it to notify you so that you can notify the affected people. So a breach at your payroll provider becomes your notification project, on your deadline, with your name on the letter. Your contract determines who pays for it. Before you sign with any provider that touches employee data, ask for their security documentation, a written breach notification commitment with a specific hour count, confirmation of where the data is stored and which subprocessors touch it, and an indemnity that covers notification costs. Ask what happens to your data after you leave, and get the deletion commitment in writing.
How long should we keep employee personal data?
Long enough to satisfy the longest legal retention rule that applies to that specific record, and no longer. Privacy law and records law pull in opposite directions here. Records law sets floors: keep this document for this many years. Privacy law sets a ceiling: do not keep personal data beyond the purpose you collected it for. The right answer is a written schedule that names each record type, the rule that governs it, the retention period, and the disposal method. Then actually run the disposal, because an old record you no longer need is pure liability in a breach. The one exception overrides everything: the moment you reasonably anticipate litigation, a charge or an audit, you place a legal hold and stop all destruction of anything potentially relevant.
Do we have to tell employees we monitor their email?
In several states you must, in writing, and you should do it everywhere regardless. New York requires employers who monitor telephone, email or internet usage to give written notice on hiring, acknowledged by the employee, with civil penalties that escalate for repeat offenses. Connecticut and Delaware have their own notice requirements. Federal law is more permissive: the Electronic Communications Privacy Act allows interception with the consent of one party and provides a business use exception, but consent is far easier to prove when it is signed. The practical rule is simple. Put the monitoring policy in the handbook, describe what you actually monitor rather than claiming rights you never exercise, collect a signed acknowledgment during onboarding, and do not monitor anything you did not disclose.