The location from which employees log in remained the same with the introduction of hybrid working; instead, it was the level of visibility that employers believed was necessary and the amount of scrutiny that this visibility drew that changed. In six states, laws require notice and consent for workplace monitoring; in Connecticut, rules became stricter on October 1, and Maine’s new law took effect this July. For any company that uses endpoint monitoring, web filtering, or data loss prevention tools, saying that ‘we bought good software’ is no longer a sufficient compliance strategy.
This article is not legal advice and is intended to provide general information only. The character, scope, and frequency of requirements and practices relating to employee monitoring vary by jurisdiction, number of employees, technology in use, and purpose. Companies should seek advice from legal experts in employment and privacy law before implementing a monitoring program.
What is a Privacy-Compliant Worker Tracking System?
A compliant employee monitoring solution collects only the information the organization needs to achieve a legitimate business objective, and nothing more.
It should be noted here that a solution which is privacy-conscious might be able to obtain this information without recording all of what the employee does, for example, through the use of a video feed, keylogging, or constant screen capture, having first established a reason for doing so.
Start with: What information do you actually need to achieve this business goal? In a workplace monitoring scenario, this might be to investigate data exfiltration by:
- Websites visited and applications run on the company’s computers.
- Transfers to portable storage devices
- Overuse of restricted programs
- Network traffic
- Active and idle periods
- Violations of security policies
It does not have to involve recording everything an employee types or logging every mouse movement during working hours.
Federal Legal Architecture: ECPA, SCA, and NLRA
1. Electronic Communications Privacy Act (ECPA)
The first part of the ECPA, known as the Federal Wiretap Act and set out in 18 U.S.C. §§ 2510–2522, prohibits the real-time interception of electronic communications. Employers are able to do so only through one of two exceptions:
- The exception based on business purpose (18 U.S.C. 2511(2)(a)(i)) involves the use of monitoring tools supplied by the employer, such as auditing email, keeping an eye on internet activity, and employing application analytics to track the use of various programs.
- The consent exception (as set out in 18 U.S.C. 2511(2)
(d)) allows real-time activity tracking if at least one party to the communication has given consent (for example, through a signed AUP acknowledged at the time of hiring).
2. Stored Communications Act (SCA)
The limitation under the ECPA’s Title II (18 U.S.C. 2701) is on access to stored messages such as web-based archived emails; the only exception provided in subsection (c)(1) is for the communication service provider, which means that employers who have an email tenant or who run a local email server are entitled to access the records kept on the employer’s own servers.
3. National Labour Relations Act (NLRA) & 2026 Jurisprudence
At this point, most compliance guidelines tend to change most slowly. In October 2022, then-General Counsel Jennifer Abruzzo published memo GC 23-02, in which she strongly advocated for a legal presumption that continuous electronic monitoring infringes upon employees’ Section 7 rights to associate and discuss the terms and conditions of their employment.
However, on February 14, 2025, the acting General Counsel, William B. Cowen, issued memo GC 25-05, officially canceling GC 23-02 and 29 other enforcement memos issued during the Biden administration
This rescission, however, did not undo the presumption in GC 23-02, but it did not take away general legal issues relating to employee monitoring. Employers should still be cautious about monitoring activities that could involve protected union activity or concerted workplace discussions.
In 2026, focus on business activity rather than employees’ talks about terms and conditions, and make sure you don’t blur the line.
2026 State-by-State Statutory Notice & Consent Landscape
State laws drive most of the compliance work, and they are changing rapidly this year. Here are the positions of five key states.
| New York | Civil Rights Law § 52-c | May 7, 2022 | Written notice upon hiring, posted conspicuously, acknowledged in writing | Up to $500 / $1,000 / $3,000 for first, second, third+ offenses |
|---|---|---|---|---|
| Delaware | Del. Code tit. 19 § 705(c) | In force | One-time written/electronic notice with acknowledgement, or a daily login banner | Civil penalties under state labor law |
| Connecticut | Conn. Gen. Stat. § 31-48d, amended by Public Act 26-73 | Oct. 1, 2026 | Notice must name monitoring types and specific locations; new hires get a plain-language statement on unannounced monitoring | Enforced by the Labor Commissioner |
| California | Cal. Civ. Code § 1798.100 (CPRA) | Employee exemption expired Jan. 1, 2023 | Notice at Collection detailing categories, purpose, and retention before data collection begins | CPPA enforcement action |
| Maine | 26 M.R.S. § 620-A | July 14, 2026 | Notice before monitoring starts, annual written notice, disclosure during interviews; audiovisual monitoring restricted in homes/personal vehicles; employees can decline apps on personal devices | $100–$500 per violation, enforced by Maine DOL |
The 6-Phase Technical Implementation Framework for IT & HR
In order to be defensible in different jurisdictions, IT administrators and HR directors must establish a standard operating procedure for the deployment of any computer monitoring program.
Phase 1: Legitimate Business Purpose & Scope Determination
Before endpoint agents are deployed there should be valid business reasons and a clear definition of the scope; the organization should establish a number of operational justifications for taking this step, for example in the areas of cybersecurity and data loss prevention (in order to prevent the exfiltration of HIPAA PHI or CUI), resource optimization (so as to eliminate software shelfware), and defensible billing/payroll verification.
Phase 2: Draft an Acceptable Use Policy That Actually Says Something
The Acceptable Use Policy should clearly state that the company’s devices, networks, and email are corporate assets and that employees have no privacy rights; it should also specify what is collected, namely, URL categories, the difference between idle time and active time, and logs of USB transfers.
Phase 3: Synchronized Daily Login Notices
States including Delaware and Maine consider a daily login banner adequate notice; the banner should therefore be pushed through your Group Policy Objects or endpoint agent so it appears each day, rather than requiring employees to sign an acknowledgement in their handbook at the time of hiring.
Phase 4: Build for Privacy by Design
Continuous screen recording and logging every keystroke are unnecessary; take screenshots only if there is a breach of policy. When this is absolutely required, use network-based attendance signals instead of device-level GPS tracking.
Phase 5: Zero-Trust Data Sovereignty & Storage
When workforce telemetry data is used in self-hosted deployments on-premises or within a private VPC, the data never comes into the possession of a third-party SaaS vendor. This is crucial for meeting GDPR data minimization requirements and complying with state laws that require you to identify who can access your monitoring logs.
Phase 6: Role-Based Access Control (RBAC) & Retention Windows
Restrict access to the monitoring console by role to specific HR and IT compliance staff. The retention periods should be as short as possible within the limits set by the most stringent relevant compliance regulation to which your organization is subject.
Ethical Compliance with the CurrentWare Suite
The various products that make up the CurrentWare suite are based on the same privacy-by-design principle that underlies this system, rather than having a simple on/off setting for monitoring.
The suite aligns perfectly with major compliance frameworks:
- HIPAA Security Rule: AccessPatrol blocks unapproved USB and removable media usage – especially pertinent when considering how many IP theft cases are centred on employee termination. Research shows that, in all likelihood, about 70% of IP theft happens within 90 days of an employee departing.
- NIST SP 800-171 / CMMC 2.0: BrowseReporter logs web and application activity for audit purposes without continuous screen capture.
- ISO/IEC 27001:2022: BrowseControl enforces application and website blacklisting from a single console, supporting the RBAC and retention practices outlined above.
- GDPR: A self-hosted deployment can give organizations greater control over where employee monitoring data is stored and who can access it. Organizations must still assess their broader GDPR obligations, including lawful processing, transparency, data minimization, retention, and security.
Examples of companies that have used this method are available. The IT administrators at First Choice Health state that “AccessPatrol has been an easy solution for us; we need not worry about what might occur when a device is plugged into a PC.”
Also, the IT manager of EHOB emphasises the need to monitor the right things without using spyware: “We wanted something robust enough to obtain the data we need without having the more intrusive features such as keylogging; we want to keep an eye on our staff, but we don’t want to become Mr Smith from The Matrix!”
Actionable Acceptable Use Policy Checklist for Employers
Before activating any endpoint tracking, confirm your organization has completed the following checklist:
- Find all federal, New York, Delaware, Connecticut, California, Maine, and international (GDPR) employee notice rules that apply.
- Make it clear in the Acceptable Use Policy(AUP) that company devices, networks, and emails are subject to monitoring.
- Obtain signed electronic or written acknowledgements from all current employees and newly hired employees.
- Post the statutory electronic monitoring notices in physical work areas and on internal employee portals or intranets.
- Deploy daily login banner via GPO/endpoint agent
- Set up the monitoring software in Transparent Mode, or put clear governance rules in place for investigative use cases.
- Limit screenshot capture to cases triggered by predefined rules, rather than continuous screen recording.
- Apply Role-Based Access Control (RBAC) so that only authorized HR/IT compliance staff are able to access the activity reports.
- Monitor the host database on self-managed infrastructure (whether on-premises or in a private VPC) to ensure data sovereignty is maintained.
- Annual audits should be carried out to adhere to the statutory retention requirements specific to the industry.
Final Thoughts on the 2026 Regulatory Landscape
When greater regulation is introduced and all aspects are subject to examination, companies can no longer rely on the IT department to handle employee monitoring software on its own; it has to be included in a well-thought-out policy that conforms to the law and incorporates the best practices of cybersecurity as well as protections for employee privacy. By adopting a thorough Acceptable Use Policy, implementing strict access controls based on role, and using tools that put privacy first, organizations will be able to gain the full advantages of having complete visibility over their business.