FirstHR

Employee Data Privacy: What US Employers Must Do

Employee data privacy for US employers: the state law patchwork, why California is different, medical and biometric rules, breach duties, disposal.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Core HR
18 min

Employee Data Privacy

What a US employer must do with the personal data it holds about its own staff

The first time an employee asked me exactly what personal data we held about him, I did not have a good answer. I knew where his signed offer letter was. I could not have told you, without an afternoon of digging, every place his home address, his bank details and a scanned copy of his passport had been copied to over eighteen months.

That was not a compliance failure in any technical sense. Nobody had breached anything. But it was the moment I understood that the file cabinet metaphor most small employers carry around is wrong. Employee data is not in a file. It is in a payroll system, a benefits portal, three shared drives, an email thread from the week he was hired, and a spreadsheet a manager built and never told anyone about.

This guide covers what a US employer owes its own staff on privacy: where the obligations come from when there is no single law, which state rules reach your workforce records and which ones deliberately do not, what you must be able to do when someone exercises a right, and the categories of data that carry their own rules no matter where you operate. I built the document handling in FirstHR around this problem, because the honest state of most small companies is not carelessness. It is not knowing where anything is.

TL;DR
The United States has no single employee privacy statute. Obligations come from a patchwork: federal laws covering medical, genetic and background check data, state biometric and breach notification laws, and comprehensive state privacy laws that almost all exempt employment data. California is the exception, extending full consumer rights to employees and applicants with a 45 day response deadline.

What Employee Data Privacy Requires of an Employer

Employee data privacy is the set of duties an employer owes regarding the personal information it collects about its own workforce: collect only what you need, tell people what you collect, keep the sensitive categories separate, protect it, hand it over or delete it when someone has a legal right to ask, and notify people when it leaks. Those six duties are the whole of it.

What makes this hard is not the concept. It is that no single statute states those six duties in one place. An employer in the European Union reads one regulation. An employer in the United States reads a federal medical confidentiality rule, a federal background check statute, a state breach law, possibly a state biometric law, possibly a state comprehensive privacy law, and a contract with a payroll provider.

The result is that most small employers do privacy by accident. They keep medical notes in the wrong folder because nobody told them the ADA cared. They email a scanned driver license to a manager because it was faster. They hold a terminated employee’s bank details for six years because deleting things takes effort. None of that is malicious, and all of it is exposure.

The upside is that the underlying work is finite. A small business can build a defensible privacy posture in a few focused sessions, and most of it is one-time setup rather than ongoing labor. The trick is to organize around data categories rather than around laws, because a category can be handled once while the laws keep changing.

Why There Is No Single US Employee Privacy Law

There is no federal employee privacy statute because Congress never passed one. What exists instead is a set of laws each written to solve one narrow problem, layered over state laws written at different times for different reasons, layered over contract terms and common law tort claims. Five distinct sources of obligation reach the same employee record.

Federal statutes aimed at one data typeThe ADA governs medical information. GINA governs genetic information. The FCRA governs anything a screening company hands you. None of them is a general privacy law, and each one reaches only its own slice of the file.
State comprehensive privacy lawsConsumer privacy statutes that create notice, access, deletion and correction rights. Almost all of them define the protected person as someone acting outside an employment context, which puts your staff records out of reach.
State sector laws that ignore the exemptionBiometric statutes, Social Security number laws, personnel file access laws, monitoring notice laws and breach notification laws. These apply to employers directly, whatever the comprehensive privacy law next door says.
Contracts you already signedYour payroll provider, benefits broker, background screening company and HR software each impose duties through their agreements. Some of those contracts pass legal obligations straight back to you as the data owner.
Common law and the juryPublic disclosure of private facts, intrusion upon seclusion and negligence claims exist in most states. A privacy failure that breaks no statute can still produce a lawsuit, and juries are not sympathetic to sloppy employers.

Reading that list, the useful insight is that the sources do not overlap cleanly. The ADA reaches medical data whether or not any state privacy law applies. A breach notification law reaches every employer in the state regardless of revenue. A comprehensive privacy law may reach nothing in your HR file at all. Compliance is not a single test you pass.

One recurring confusion is worth clearing up early. HIPAA does not govern your personnel records. The privacy rule excludes employment records held by a covered entity in its role as employer from the definition of protected health information, which means the health plan side is regulated and the HR side is not.

The practical translation: an employer who says "we are not covered by HIPAA, so employee health data is unregulated" has drawn the wrong conclusion from a correct premise. The ADA still applies, state medical confidentiality laws still apply, and a breach of health information still triggers notification. HIPAA is simply not the statute doing the work.

State Privacy Laws and Why California Is the Outlier

Roughly twenty states now have comprehensive consumer privacy laws in force, and with a single exception none of them reach employee data. Each one defines the protected "consumer" as an individual acting in a personal or household capacity and expressly excludes people acting in a commercial or employment context, which puts employees, applicants and contractors outside the law.

California is the exception, and the exception is total. The California Consumer Privacy Act originally carried a temporary carve-out for workforce data. That carve-out expired at the end of 2022 and was not renewed, so a covered California employer now owes its employees, applicants, independent contractors, directors and their beneficiaries the same rights it owes a retail customer. The California Attorney General publishes the current rights list.

The California Exception, in Numbers
The CCPA applies to a for-profit business that meets any one of three thresholds: gross annual revenue above $25 million as adjusted by the California Privacy Protection Agency, which set the figure at $26,625,000 effective January 1, 2025; or buying, selling or sharing the personal information of 100,000 or more California residents or households; or deriving 50 percent or more of annual revenue from selling or sharing personal information. Note what is absent from that list: headcount. A company with a small team and large revenue is covered.

Three more state-level layers ignore the employment exemption entirely, and these are the ones that catch small employers by surprise. Biometric statutes reach employers directly. Breach notification statutes exist in all fifty states plus the District of Columbia and apply to any business holding resident data. Personnel file access laws in roughly half the states give employees a right to inspect their own file.

So the correct mental model is not "does my state have a privacy law." It is a two-part question. First, does a comprehensive privacy law reach my workforce data, which for now means: do I have California staff and do I meet the thresholds. Second, which sector-specific state rules apply to the data types I actually hold, which is a question every employer has to answer.

Layer of lawDoes it reach employee data?What triggers coverageWhat you owe
California CCPAYes, in full since the exemption lapsedRevenue, resident volume or data-sale revenue thresholdsNotice at collection plus access, deletion, correction, opt-out and limitation rights
Other state comprehensive privacy lawsNo, employment context is excludedNot applicable to workforce recordsNothing for staff data, though customer data may still be covered
State breach notification lawsYes, everywhereHolding personal data about a resident of that stateNotice to affected individuals, often to the attorney general above a threshold
State biometric lawsYes, and aimed squarely at employersCollecting fingerprints, face or voice scansWritten policy, informed consent before collection, retention schedule, destruction
State personnel file access lawsYes, in roughly half the statesBeing an employer in that stateLet the employee inspect or copy the file within the statutory window
State SSN protection lawsYes, in most statesHolding Social Security numbersRestrictions on display, transmission and disposal
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

What the Rights Mean in Practice and How to Answer a Request

Four rights matter operationally: notice at collection, access, deletion and correction. Notice is the one you owe before anyone asks. The other three are reactive, and each requires you to be able to find every copy of a person’s data across every system inside a fixed window.

Notice at collection means a written statement, delivered at or before the moment you collect, listing the categories of personal information you collect, the purpose of each category, whether any of it is sold or shared, and the retention period or the criteria you use to set one. For an employer this belongs in the new hire paperwork packet, acknowledged and filed alongside the rest of the personnel file.

Access means the employee can ask what you hold and receive it. Deletion means they can ask you to erase it, subject to a long list of exceptions that let you keep what the law requires you to keep. Correction means they can require you to fix inaccurate information. None of the three is absolute, and all three require documented reasoning when you say no.

45 days
CCPA deadline to respond to a verifiable request, extendable once
10 days
Business days to acknowledge receipt under the CCPA regulations
51
States plus DC with breach notification statutes covering employers
$5,000
Illinois BIPA statutory damages per intentional violation

The request itself is where small employers fail, and the failure is almost never legal. It is logistical. The clock starts when the request arrives, not when you get around to it, and the search has to reach systems you do not control. Here is the sequence that actually works.

Day 0: the request lands
Log the date, the person, and the exact right being exercisedSend an acknowledgment so the employee knows it was receivedConfirm identity before you send anything backFreeze any routine deletion that would destroy responsive records
Days 1 to 10: find the data
Pull from the HR system, the payroll provider and the benefits platformCheck shared drives, email folders and any manager-kept spreadsheetsFlag records you are legally required to keep despite a deletion requestSeparate the employee record from anything belonging to a third party
Days 10 to 40: decide and assemble
Decide what you disclose, what you redact and what you refuseWrite down the legal basis for every exclusionRedact other people’s personal data out of shared documentsHave one named person approve the package before it goes out
By day 45: respond
Deliver through a channel the employee can actually open securelyExplain in writing what you did not provide and whyExtend once, in writing, if the request is genuinely complexFile the whole exchange so the next request takes an hour, not a week

Two details deserve emphasis. Verify identity before you disclose anything, because handing an employee record to someone impersonating that employee is itself a breach. And suspend routine deletion the moment a request lands, because destroying responsive records after a request is a much worse fact pattern than holding data too long.

Outside California, the analogous right usually comes from a state personnel file access statute rather than a privacy law. Those are narrower: they cover the personnel file specifically, set their own deadlines, and often permit a copying charge. The process above still serves you, because a single well-run intake path handles both without you having to remember which law is in play.

The Data Categories That Carry Their Own Rules

Five categories of employee data carry federal or near-universal state rules that apply regardless of whether any comprehensive privacy law reaches you: medical information, immigration documents, background check data, Social Security numbers and biometric identifiers. Getting these five right resolves most of your exposure.

Medical information is the strictest and the most commonly mishandled. Under the ADA, anything obtained through a medical inquiry or examination must be collected on separate forms, held in separate medical files, and treated as a confidential medical record. That requirement sits in 29 CFR 1630.14, and it is not a best practice. It is the rule.

The scope is broader than people expect. Accommodation requests, doctor’s notes, fitness-for-duty certifications, workers’ compensation records, drug and alcohol test results, health plan enrollment forms and anything from a wellness program all belong in the confidential medical file. GINA extends the same separation to genetic information, including family medical history you learn about incidentally.

The Single Most Common Finding
In practice, the failure is rarely a decision. It is a filing habit. Someone drops a doctor’s note into the main folder because that is where the employee’s other paperwork lives, and a supervisor pulling a performance record now sees a diagnosis. That is an ADA problem and a discrimination claim waiting for a plaintiff. The fix is structural: a second location that the person filing cannot conveniently ignore.

Immigration documents follow their own logic. Form I-9 must be retrievable on demand for a government inspection, which is why almost every practitioner keeps I-9s in a separate binder or folder for all employees rather than inside individual files. Copies of the underlying documents, if you take them, must be kept consistently for everyone.

Background check data is governed by the Fair Credit Reporting Act whenever the report comes from a screening company. The FCRA requires a standalone written disclosure, separate authorization, a pre-adverse action notice with a copy of the report before you act, and a final adverse action notice after. The Federal Trade Commission publishes the employer guidance.

Social Security numbers are the highest-value item in your file and the one most employers treat most casually. There is no single federal statute restricting employer use, but most states restrict public display, transmission over unsecured channels and printing on documents. Treat the SSN as encrypted-at-rest, visible to payroll only, and never in an email body or a spreadsheet column.

Data categoryWhat rule governs itWhere it must liveHow long you keep it
Medical, accommodation, workers’ compADA, 29 CFR 1630.14; state medical confidentiality lawsSeparate confidential medical file, restricted to one or two peoplePer the record-specific rule, then destroy; never merged into the personnel file
Genetic and family medical historyGINA Title II, 29 CFR 1635.9Same confidential medical file as ADA materialSame as other medical records, kept apart from performance data
Form I-9 and supporting copiesIRCA; USCIS inspection rulesSeparate I-9 file or binder covering all staffThree years after hire or one year after termination, whichever is later
Background check reportsFCRA, 15 USC 1681b; FTC Disposal Rule, 16 CFR 682Separate confidential file, not the personnel fileLong enough to defend the hiring decision, then disposed of by shredding or wiping
Social Security numbersState SSN protection and disposal lawsPayroll system field, encrypted, role-restrictedAs long as tax and payroll rules require, then purged from ad hoc copies
Biometric identifiersState biometric statutes, notably Illinois BIPAVendor system under a written policy and signed consentPer your published retention schedule, destroyed when the purpose ends
Payroll and bank detailsState breach and SSN laws; vendor contractPayroll provider only, never in email or a shared sheetPer payroll record rules, then removed from any secondary copies

Note the pattern running through that table. Almost every category has a natural home outside the main personnel file, and almost every failure happens when someone puts it in the main file for convenience.

Biometric Data Is Where the Litigation Risk Actually Lives

Biometric data is the one employee privacy category that reliably produces expensive litigation, because Illinois gives employees a private right of action and most other privacy rules do not. If you use a fingerprint time clock, a face scan for door access or voiceprint authentication, this is the section that matters most.

The Illinois Biometric Information Privacy Act requires a written policy that is publicly available, states a retention schedule and destruction guidelines, and obtains informed written consent before the first collection. Statutory damages run to $1,000 per negligent violation and $5,000 per intentional or reckless violation, and the plaintiff does not have to show any actual harm.

An amendment signed in 2024 narrowed the exposure considerably. Repeated collection of the same identifier from the same person by the same method now counts as one violation rather than one per scan, which had been the theory driving nine-figure demands, and an electronic signature counts as a valid written release. The statute remains the most dangerous in the country for employers, but the arithmetic is no longer absurd.

Other states regulate the same conduct without the private right of action. Texas imposes notice and consent duties under its capture of biometric identifiers statute. Washington does the same, and RCW 19.375.030 states plainly that the chapter may be enforced solely by the attorney general. Colorado added employer biometric obligations to its privacy act effective July 1, 2025, and those provisions apply to employees even though the rest of the Colorado statute exempts employment data.

The operational rule is short. Before you switch on any device that reads a body part, check the states where your staff physically work, publish a policy, collect a signed consent from every person enrolled, and confirm in writing what your vendor does with the templates. A time clock is not worth a class action.

Breach Notification: What You Must Do and How Fast

Every state plus the District of Columbia has a breach notification law, and every one of them applies to employee data the same way it applies to customer data. If personal information about a resident of that state is acquired by an unauthorized person, you owe notice, and the deadline is set by the law of the employee’s state rather than yours.

Most statutes use a standard of the most expedient time possible and without unreasonable delay. Several set a hard outside limit. Colorado and Florida both require notice within thirty days of determining that a breach occurred, and both require notice to the state attorney general when five hundred or more residents are affected. Florida allows an additional fifteen days for good cause submitted in writing.

The scenario that catches employers is not a hacker. It is a laptop left in a car, a payroll file emailed to the wrong address, an ex-employee whose access was never revoked, or a vendor incident that surfaces weeks later. Two of those four are prevented entirely by a proper offboarding checklist, and a third by treating payroll security as a separate discipline.

1
Contain before you investigate
Revoke the credential, pull the device off the network, recall the message. Containment is not evidence destruction, and delaying it to preserve a clean investigation costs you more than it saves.
2
Determine scope and residency
Identify exactly which data elements were exposed and which state each affected person lives in. Residency, not your office location, decides which deadline and which attorney general applies.
3
Start the clock deliberately
Write down the date you determined a breach occurred. Several state deadlines run from that determination, and you will be asked to justify it later.
4
Notify individuals in plain language
State what happened, what data was involved, what you have done, and what the person should do now. Most statutes specify required content, so check the strictest state on your list.
5
Notify regulators where required
Attorney general notice kicks in above a resident threshold in many states. Credit reporting agency notice applies above a larger threshold in several.
6
Write the after-action note
One page: what failed, what you changed, who signed off. This is the document that turns a bad incident into evidence of a functioning program.
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Retention and Secure Disposal

Privacy law and records law point in opposite directions, and holding both ideas at once is the whole discipline. Records law sets floors: keep this document for this long. Privacy law sets a ceiling: do not hold personal data past the purpose you collected it for. Your schedule lives in the space between the two.

I am not going to restate the retention periods here, because they belong in one place and that place is our record retention guide. What matters for privacy is the other half of the schedule: the disposal column. A retention schedule with no disposal step is not a schedule. It is an accumulation policy with better formatting.

Secure disposal has a specific legal meaning for some data. The FTC Disposal Rule at 16 CFR Part 682 requires reasonable measures to protect against unauthorized access when you dispose of information derived from a consumer report, which for an employer means background check results. Shredding, burning or pulverizing paper. Wiping or destroying electronic media. Handing a box to the recycling company does not qualify.

Most states add their own disposal requirements for records containing Social Security numbers or other identifiers, and the standard is similar: render the information unreadable. The practical version for a small business is a cross-cut shredder for paper, a documented wipe procedure for drives, and a written note of what was destroyed and when.

One rule overrides the entire schedule. The moment you reasonably anticipate litigation, an agency charge or an audit, you place a legal hold and stop destroying anything potentially relevant, including automated deletion routines. Destroying records after a claim becomes foreseeable turns a defensible case into spoliation, and courts punish that far harder than they punish the underlying dispute.

Monitoring and What You Have to Disclose First

You can monitor company systems in most circumstances, but in several states you must tell employees in writing before you start, and everywhere you are far better off having disclosed it. Monitoring conducted without notice is the fastest route from an ordinary employment dispute to a privacy claim.

New York requires employers who monitor telephone conversations, email or internet usage to provide written notice upon hiring, acknowledged by the employee in writing or electronically, with civil penalties that escalate from five hundred dollars for a first offense to three thousand for repeat offenses, enforced by the attorney general. Connecticut and Delaware impose their own notice requirements with different mechanics.

The federal baseline is more permissive. The Electronic Communications Privacy Act permits interception where one party consents and provides a business use exception for equipment used in the ordinary course of business. Consent is much easier to prove when it is a signed acknowledgment than when it is an inference from a handbook nobody opened.

Two boundaries hold almost everywhere. Do not monitor what you did not disclose, and do not claim monitoring rights you never exercise, because an overbroad policy invites the argument that you were reading things you had no business reading. Restrooms, changing areas and personal devices you do not manage stay off limits regardless of what the handbook says.

Vendors: What Your Payroll or Benefits Provider Does With the Data

Your vendors hold the same sensitive data you do, and in most states the notification duty after their breach lands on you rather than on them. Breach statutes typically place the obligation on the entity that owns or licenses the data and require the holder to notify the owner so the owner can notify the affected people.

That single legal detail should change how you buy software. A payroll provider, a benefits administrator, a background screening company and an HR platform each hold names, Social Security numbers, bank details and sometimes health information. If any of them is compromised, your employees receive a letter with your company name at the top, and your contract decides who pays for it.

There are six questions worth asking before you sign anything that touches employee data, and any provider worth using answers all six without hesitation. Ask them in writing, keep the answers, and revisit them at renewal rather than never.

Ask the vendorWhat a good answer looks likeWhat should worry you
Which subprocessors touch our employee data?A current written list with locations, updated when it changesA vague reference to trusted partners with no names
What is your breach notification commitment to us?A specific number of hours from determination, written into the contractPrompt notice with no defined time frame
Can we see your security documentation?A current independent audit report or certification, provided under NDAMarketing pages about bank-level encryption and nothing else
Where is the data stored and who can access it?Named regions, role-based access controls, logged administrative accessCannot say, or support staff have standing access to production data
What happens to our data when we leave?Export in a usable format, then deletion within a stated window, confirmed in writingData retained indefinitely or deleted on an unspecified schedule
Who indemnifies notification costs after your incident?The vendor, with a cap you can live withYou do, or liability is capped at one month of fees

Two structures deserve extra scrutiny. If you use a professional employer organization, the co-employment relationship means a third party holds your entire workforce record set, so read the data terms in the service agreement rather than assuming. And consolidating systems is itself a privacy control, since fewer copies means fewer places to search and fewer places to lose, which is the quiet argument for a single HRIS over five disconnected tools.

The Privacy Program a Small Business Can Actually Run

A realistic employee privacy program for a company without a dedicated HR department has seven parts, takes a few focused sessions to build, and is mostly one-time setup. It is not a policy binder. It is a map, a set of walls between data categories, a schedule, and two short playbooks.

1
Map where employee data lives
List every system and location holding staff personal data, including the manager spreadsheet nobody mentions. Twenty minutes of honest listing produces the single most useful document in the program, because you cannot protect or produce what you cannot find.
2
Separate the regulated categories
Move medical, genetic, background check and immigration records out of the main file into separately permissioned storage. This one step resolves the most common finding in an HR audit and the most common ADA exposure.
3
Write a one-page notice at collection
Categories collected, purpose of each, retention approach, who to contact. Deliver it at hire, collect the acknowledgment, and keep it. Required in California, useful everywhere as evidence that you told people.
4
Restrict access by role
Managers see contact and performance data. Payroll sees bank details. One named person sees medical files. Review access whenever someone changes roles, and remove it the day they leave rather than the month after.
5
Build the retention and disposal schedule
Record type, governing rule, retention period, disposal method, and the date it was last run. Put the disposal on a recurring calendar entry, because a schedule nobody executes protects nobody.
6
Get vendor commitments in writing
Security documentation, breach notification time frame, subprocessor list, storage locations, deletion on exit, indemnity. Six questions, asked once per vendor, revisited at renewal.
7
Write two playbooks and rehearse them
One page for a data incident, one page for a rights request. Name who runs each and who approves the response. Rehearse both once, because the first time you do this should not be under a statutory deadline.

The sequencing matters. Steps one and two produce most of the risk reduction and can be done in an afternoon. Steps three through five formalize what you did. Steps six and seven are what separate a company that survives an incident from one that improvises through it badly.

Where the software helps is in collapsing the map. A single system holding employee records with role-based permissions, separate confidential storage, and an audit trail of who opened what removes most of the search problem before it starts. That is the connection between document management and privacy: they are the same project viewed from two angles, and doing one well delivers the other.

Run the whole thing past a review once a year, alongside whatever else you check in an HR audit. Privacy obligations change faster than most employment rules, state legislatures keep passing new ones, and a program built two years ago and never revisited is a program that describes a company you no longer are.

Key Takeaways
The United States has no single employee privacy statute. Duties arrive from federal data-type laws, state sector laws, comprehensive state privacy laws, vendor contracts and common law tort claims at the same time.
California is the only state whose comprehensive privacy law reaches workforce data in full. The temporary exemption for employee and applicant information lapsed at the end of 2022 and was not renewed.
Every other state comprehensive privacy law defines the protected consumer to exclude people acting in an employment or commercial context, which puts staff records outside their reach.
Coverage under the CCPA turns on revenue and data volume thresholds, not on headcount. A small team at a high-revenue company is fully covered.
Four rights drive the work: notice at collection, access, deletion and correction. A California employer has 45 calendar days to respond to a verifiable request, extendable once by another 45 with written notice.
Medical information must be collected on separate forms and kept in a separate confidential medical file under 29 CFR 1630.14, regardless of state. GINA extends the same separation to genetic information.
Background check data is governed by the FCRA and must be disposed of under the FTC Disposal Rule at 16 CFR Part 682, which means shredding or wiping rather than recycling.
Biometric data carries the sharpest litigation risk because Illinois provides a private right of action with statutory damages, while Texas, Washington and Colorado reserve enforcement to the attorney general.
Breach notification applies in all fifty states plus the District of Columbia, deadlines run from the employee’s state of residence, and a vendor incident usually becomes your notification obligation.
Retention needs a disposal column and a legal hold rule. Keep what the law requires, destroy what it does not, and stop all destruction the moment litigation or an audit becomes foreseeable.

Frequently Asked Questions

Do US employers have to comply with data privacy laws for employee data?

Yes, but not through a single statute. The United States has no general employee privacy law, so the duties arrive from several directions at once. Federal statutes govern specific data types: the ADA covers medical information, GINA covers genetic information, and the FCRA covers anything a screening company sends you. State laws add breach notification in every state, biometric consent rules in a handful, Social Security number restrictions in most, and personnel file access rights in about half. Contracts with your payroll and benefits vendors add more. The practical effect is that no employer is exempt. Even a company with a dozen people on the books has to notify affected staff after a breach, keep medical records separate, and dispose of background check data securely.

Does the CCPA apply to employees and job applicants?

Yes. California is the only state whose comprehensive privacy law reaches workforce data in full. The temporary exemption for employee, applicant, contractor, director and beneficiary data expired at the end of 2022, so from January 2023 onward a covered employer owes its California staff the same rights it owes a customer. That means a notice at collection before or at the moment you collect, plus rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation for asking. Coverage depends on the business thresholds, not on headcount: gross annual revenue above the statutory figure, or buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning half of revenue from selling or sharing personal information.

What must an employer do when an employee asks for a copy of their data?

It depends on which law gives them the right, and the answer starts with identifying that law. In California, a covered employer has 45 calendar days to respond to a verifiable request, extendable once by another 45 days with written notice, and must verify identity before disclosing anything. Outside California, the right usually comes from a state personnel file access law, which is narrower: it covers the personnel file itself, sets its own deadline, and often lets you charge a copying fee. Either way, run the same process. Log the request, verify who is asking, suspend routine deletion of anything responsive, search every system including the payroll and benefits providers, redact other people’s personal data, and document your reasoning for anything you withhold.

Can an employer keep medical information in the personnel file?

No. Under the ADA, information obtained from a medical inquiry or examination must be collected on separate forms, kept in separate medical files, and treated as a confidential medical record. That rule sits in 29 CFR 1630.14 and applies to every covered employer, regardless of which state you operate in and regardless of whether any privacy statute reaches your workforce data. GINA imposes the same separation on genetic information, including family medical history picked up incidentally. In practice this means a second locked file or a separately permissioned folder that the hiring manager cannot open. Doctor’s notes, accommodation paperwork, workers’ compensation records, drug test results and health plan enrollment forms all belong there. Supervisors get told about work restrictions and accommodations only, never the underlying diagnosis.

Do we need consent before collecting fingerprints for a time clock?

In several states, yes, and the consent has to be written and informed before the first scan. Illinois is the state that matters most because its Biometric Information Privacy Act carries a private right of action, which means employees can sue directly rather than waiting for a regulator. Illinois requires a written, publicly available policy with a retention schedule and destruction guidelines, plus a signed release before collection. Texas and Washington impose notice and consent duties too, but both reserve enforcement to the state attorney general. Colorado added employer biometric obligations to its privacy act effective July 1, 2025, and those provisions apply to employees even though the rest of the Colorado law exempts employment data. Before you switch on a fingerprint or face scan clock, check the states where your staff actually work.

Who is responsible if our payroll vendor has a data breach?

Legally, you usually are, at least to your employees. Most state breach notification statutes place the notice duty on the entity that owns or licenses the data, and require the vendor holding it to notify you so that you can notify the affected people. So a breach at your payroll provider becomes your notification project, on your deadline, with your name on the letter. Your contract determines who pays for it. Before you sign with any provider that touches employee data, ask for their security documentation, a written breach notification commitment with a specific hour count, confirmation of where the data is stored and which subprocessors touch it, and an indemnity that covers notification costs. Ask what happens to your data after you leave, and get the deletion commitment in writing.

How long should we keep employee personal data?

Long enough to satisfy the longest legal retention rule that applies to that specific record, and no longer. Privacy law and records law pull in opposite directions here. Records law sets floors: keep this document for this many years. Privacy law sets a ceiling: do not keep personal data beyond the purpose you collected it for. The right answer is a written schedule that names each record type, the rule that governs it, the retention period, and the disposal method. Then actually run the disposal, because an old record you no longer need is pure liability in a breach. The one exception overrides everything: the moment you reasonably anticipate litigation, a charge or an audit, you place a legal hold and stop all destruction of anything potentially relevant.

Do we have to tell employees we monitor their email?

In several states you must, in writing, and you should do it everywhere regardless. New York requires employers who monitor telephone, email or internet usage to give written notice on hiring, acknowledged by the employee, with civil penalties that escalate for repeat offenses. Connecticut and Delaware have their own notice requirements. Federal law is more permissive: the Electronic Communications Privacy Act allows interception with the consent of one party and provides a business use exception, but consent is far easier to prove when it is signed. The practical rule is simple. Put the monitoring policy in the handbook, describe what you actually monitor rather than claiming rights you never exercise, collect a signed acknowledgment during onboarding, and do not monitor anything you did not disclose.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial