We’ve updated our Subprocessor List, effective September 17, 2026. Please review the update to our Data Processing Addendum

Compliance

US Workplace Monitoring Laws & Privacy Requirements : A State-by-State Guide

US Workplace Monitoring Laws & Privacy Requirements : A State-by-State Guide
Tony Lynn
Chief Operating Officer of CurrentWare
Updated on 5 min read
Share this article

The location from which employees log in remained the same with the introduction of hybrid working; instead, it was the level of visibility that employers believed was necessary and the amount of scrutiny that this visibility drew that changed. In six states, laws require notice and consent for workplace monitoring; in Connecticut, rules became stricter on October 1, and Maine’s new law took effect this July. For any company that uses endpoint monitoring, web filtering, or data loss prevention tools, saying that ‘we bought good software’ is no longer a sufficient compliance strategy.

This article is not legal advice and is intended to provide general information only. The character, scope, and frequency of requirements and practices relating to employee monitoring vary by jurisdiction, number of employees, technology in use, and purpose. Companies should seek advice from legal experts in employment and privacy law before implementing a monitoring program.

What is a Privacy-Compliant Worker Tracking System?

A compliant employee monitoring solution collects only the information the organization needs to achieve a legitimate business objective, and nothing more.

It should be noted here that a solution which is privacy-conscious might be able to obtain this information without recording all of what the employee does, for example, through the use of a video feed, keylogging, or constant screen capture, having first established a reason for doing so.

Start with: What information do you actually need to achieve this business goal? In a workplace monitoring scenario, this might be to investigate data exfiltration by:

  • Websites visited and applications run on the company’s computers.
  • Transfers to portable storage devices
  • Overuse of restricted programs
  • Network traffic
  • Active and idle periods
  • Violations of security policies

It does not have to involve recording everything an employee types or logging every mouse movement during working hours.

Federal Legal Architecture: ECPA, SCA, and NLRA

1. Electronic Communications Privacy Act (ECPA)

The first part of the ECPA, known as the Federal Wiretap Act and set out in 18 U.S.C. §§ 2510–2522, prohibits the real-time interception of electronic communications. Employers are able to do so only through one of two exceptions:

  • The exception based on business purpose (18 U.S.C. 2511(2)(a)(i)) involves the use of monitoring tools supplied by the employer, such as auditing email, keeping an eye on internet activity, and employing application analytics to track the use of various programs.
  • The consent exception (as set out in 18 U.S.C. 2511(2)
    (d)) allows real-time activity tracking if at least one party to the communication has given consent (for example, through a signed AUP acknowledged at the time of hiring).

2. Stored Communications Act (SCA)

The limitation under the ECPA’s Title II (18 U.S.C. 2701) is on access to stored messages such as web-based archived emails; the only exception provided in subsection (c)(1) is for the communication service provider, which means that employers who have an email tenant or who run a local email server are entitled to access the records kept on the employer’s own servers.

3. National Labour Relations Act (NLRA) & 2026 Jurisprudence

At this point, most compliance guidelines tend to change most slowly. In October 2022, then-General Counsel Jennifer Abruzzo published memo GC 23-02, in which she strongly advocated for a legal presumption that continuous electronic monitoring infringes upon employees’ Section 7 rights to associate and discuss the terms and conditions of their employment.

However, on February 14, 2025, the acting General Counsel, William B. Cowen, issued memo GC 25-05, officially canceling GC 23-02 and 29 other enforcement memos issued during the Biden administration

This rescission, however, did not undo the presumption in GC 23-02, but it did not take away general legal issues relating to employee monitoring. Employers should still be cautious about monitoring activities that could involve protected union activity or concerted workplace discussions.

In 2026, focus on business activity rather than employees’ talks about terms and conditions, and make sure you don’t blur the line.

2026 State-by-State Statutory Notice & Consent Landscape

State laws drive most of the compliance work, and they are changing rapidly this year. Here are the positions of five key states.

New York Civil Rights Law § 52-c May 7, 2022 Written notice upon hiring, posted conspicuously, acknowledged in writing Up to $500 / $1,000 / $3,000 for first, second, third+ offenses
Delaware Del. Code tit. 19 § 705(c) In force One-time written/electronic notice with acknowledgement, or a daily login banner Civil penalties under state labor law
Connecticut Conn. Gen. Stat. § 31-48d, amended by Public Act 26-73 Oct. 1, 2026 Notice must name monitoring types and specific locations; new hires get a plain-language statement on unannounced monitoring Enforced by the Labor Commissioner
California Cal. Civ. Code § 1798.100 (CPRA) Employee exemption expired Jan. 1, 2023 Notice at Collection detailing categories, purpose, and retention before data collection begins CPPA enforcement action
Maine 26 M.R.S. § 620-A July 14, 2026 Notice before monitoring starts, annual written notice, disclosure during interviews; audiovisual monitoring restricted in homes/personal vehicles; employees can decline apps on personal devices $100–$500 per violation, enforced by Maine DOL

The 6-Phase Technical Implementation Framework for IT & HR

In order to be defensible in different jurisdictions, IT administrators and HR directors must establish a standard operating procedure for the deployment of any computer monitoring program.

Phase 1: Legitimate Business Purpose & Scope Determination

Before endpoint agents are deployed there should be valid business reasons and a clear definition of the scope; the organization should establish a number of operational justifications for taking this step, for example in the areas of cybersecurity and data loss prevention (in order to prevent the exfiltration of HIPAA PHI or CUI), resource optimization (so as to eliminate software shelfware), and defensible billing/payroll verification.

Phase 2: Draft an Acceptable Use Policy That Actually Says Something

The Acceptable Use Policy should clearly state that the company’s devices, networks, and email are corporate assets and that employees have no privacy rights; it should also specify what is collected, namely, URL categories, the difference between idle time and active time, and logs of USB transfers.

Phase 3: Synchronized Daily Login Notices

States including Delaware and Maine consider a daily login banner adequate notice; the banner should therefore be pushed through your Group Policy Objects or endpoint agent so it appears each day, rather than requiring employees to sign an acknowledgement in their handbook at the time of hiring.

Phase 4: Build for Privacy by Design

Continuous screen recording and logging every keystroke are unnecessary; take screenshots only if there is a breach of policy. When this is absolutely required, use network-based attendance signals instead of device-level GPS tracking.

Phase 5: Zero-Trust Data Sovereignty & Storage

When workforce telemetry data is used in self-hosted deployments on-premises or within a private VPC, the data never comes into the possession of a third-party SaaS vendor. This is crucial for meeting GDPR data minimization requirements and complying with state laws that require you to identify who can access your monitoring logs.

Phase 6: Role-Based Access Control (RBAC) & Retention Windows

Restrict access to the monitoring console by role to specific HR and IT compliance staff. The retention periods should be as short as possible within the limits set by the most stringent relevant compliance regulation to which your organization is subject.

Ethical Compliance with the CurrentWare Suite

The various products that make up the CurrentWare suite are based on the same privacy-by-design principle that underlies this system, rather than having a simple on/off setting for monitoring.

The suite aligns perfectly with major compliance frameworks:

  • HIPAA Security Rule: AccessPatrol blocks unapproved USB and removable media usage – especially pertinent when considering how many IP theft cases are centred on employee termination. Research shows that, in all likelihood, about 70% of IP theft happens within 90 days of an employee departing.
  • NIST SP 800-171 / CMMC 2.0: BrowseReporter logs web and application activity for audit purposes without continuous screen capture.
  • ISO/IEC 27001:2022: BrowseControl enforces application and website blacklisting from a single console, supporting the RBAC and retention practices outlined above.
  • GDPR: A self-hosted deployment can give organizations greater control over where employee monitoring data is stored and who can access it. Organizations must still assess their broader GDPR obligations, including lawful processing, transparency, data minimization, retention, and security.

Examples of companies that have used this method are available. The IT administrators at First Choice Health state that “AccessPatrol has been an easy solution for us; we need not worry about what might occur when a device is plugged into a PC.”

Also, the IT manager of EHOB emphasises the need to monitor the right things without using spyware: “We wanted something robust enough to obtain the data we need without having the more intrusive features such as keylogging; we want to keep an eye on our staff, but we don’t want to become Mr Smith from The Matrix!”

Actionable Acceptable Use Policy Checklist for Employers

Before activating any endpoint tracking, confirm your organization has completed the following checklist:

  1. Find all federal, New York, Delaware, Connecticut, California, Maine, and international (GDPR) employee notice rules that apply.
  2. Make it clear in the Acceptable Use Policy(AUP) that company devices, networks, and emails are subject to monitoring.
  3. Obtain signed electronic or written acknowledgements from all current employees and newly hired employees.
  4. Post the statutory electronic monitoring notices in physical work areas and on internal employee portals or intranets.
  5. Deploy daily login banner via GPO/endpoint agent
  6. Set up the monitoring software in Transparent Mode, or put clear governance rules in place for investigative use cases.
  7. Limit screenshot capture to cases triggered by predefined rules, rather than continuous screen recording.
  8. Apply Role-Based Access Control (RBAC) so that only authorized HR/IT compliance staff are able to access the activity reports.
  9. Monitor the host database on self-managed infrastructure (whether on-premises or in a private VPC) to ensure data sovereignty is maintained.
  10. Annual audits should be carried out to adhere to the statutory retention requirements specific to the industry.

Final Thoughts on the 2026 Regulatory Landscape

When greater regulation is introduced and all aspects are subject to examination, companies can no longer rely on the IT department to handle employee monitoring software on its own; it has to be included in a well-thought-out policy that conforms to the law and incorporates the best practices of cybersecurity as well as protections for employee privacy. By adopting a thorough Acceptable Use Policy, implementing strict access controls based on role, and using tools that put privacy first, organizations will be able to gain the full advantages of having complete visibility over their business.

Keep reading

More articles
Start Free Trial Book a Demo
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Privacy Policy