• Deutsch

    Deutsch

  • English

    English

  • Español

    Español

  • Français

    Français

  • Italiano

    Italiano

  • Português

    Português

WorkTime US employee monitoring laws overview

July 29, 2026

21 min read

Employee monitoring laws by state: all 50 states + DC (2026)

TL;DR

  • Monitoring company devices is legal in every state with a legitimate business reason and, in almost every case, notice to employees. Federal law defaults to one-party consent.
  • Only three states have a dedicated electronic-monitoring notice law: Connecticut, Delaware, and New York. Texas is often listed as a fourth. It has no such statute.
  • Recording audio is the strictest kind of monitoring. Nine states clearly require all-party consent, and several more are disputed, so calls and meetings carry tighter rules than screen or activity tracking.
  • Illinois is the highest-risk state for biometrics. Its BIPA law carries $1,000 to $5,000 in damages per violation and lets employees win settlements up to $650 million.
  • California AB 1221 is not law. The workplace-surveillance bill that many 2026 guides call "effective January 2026" died in the legislature. Do not build a policy around it.
Employee monitoring is legal in all 50 states when it covers company-owned equipment used for a legitimate business reason. What changes from state to state is the notice you owe your team, the consent you need to record audio, and the extra rules for biometrics and social media accounts. Federal law sets a floor. State law can ask for more. At WorkTime, we have built non-invasive employee monitoring software since 1998, the kind that gives employers productivity analytics and remote-workforce visibility without capturing screenshots, keystroke content, or recordings. We work with employers in regulated industries like healthcare, finance, and government, where getting monitoring compliance right is not optional.
The article is presented by WorkTime, providing transparent, non-invasive workforce analytics with built-in compliance features that help organizations improve productivity while respecting employee privacy.
This guide maps the full legal picture: the federal baseline, the three states with a dedicated monitoring-notice law, the audio-recording consent map, biometric rules, and a citation for every state. It also corrects one error that shows up in most 2026 compliance guides, because getting the law wrong is worse than not publishing it.

Employee monitoring in the U.S., by the numbers

Employer monitoring climbed sharply through the shift to remote work, and worker backlash climbed with it. These figures are the current, sourced picture of how common monitoring is, how workers feel about it, and what the biggest legal mistakes have cost. Most surveys below sample U.S. employers and workers. Figures from global or aggregated international studies (Gartner, Microsoft, StandOutCV, and Strategic Market Research) are labeled global at first mention. Each figure is numbered so it is easy to cite.
Headline metric Figure Source

Large employers projected to monitor staff by 2025 (global)

70%

StandOutCV

U.S. employers using monitoring software

80%

ExpressVPN

Remote U.S. companies using monitoring software

96%

ResumeBuilder.com

U.S. workers who would consider leaving over more surveillance

49%

ExpressVPN

U.S. adults who say AI monitoring feels inappropriate

81%

Pew Research Center

Largest single BIPA settlement (Facebook)

$650 million

American Bar Association

Adoption and prevalence

1. Large-employer monitoring rose from 30% in 2015 to more than 50% by 2018. A global Gartner survey of 239 large corporations found more than half were using some form of nontraditional monitoring, up from just 30% three years earlier. 2. An estimated 70% of large employers monitor employees as of 2025. A global StandOutCV study projects that 70% of large employers now track their staff in some way. 3. Monitoring tools grew more invasive, with an invasiveness score rising from 45% to 53% between 2021 and 2023. The same StandOutCV study tracked the worldwide shift toward heavier data collection. 4. According to the data, 80% of U.S. employers report using employee monitoring software. An ExpressVPN survey of 2,000 U.S. employers and 2,000 employees found 80% use software to track performance or online activity. 5. The research shows that 96% of remote U.S. companies use employee monitoring software. A ResumeBuilder.com survey of 1,000 U.S. business leaders found near-universal adoption among remote employers. 6. About 40% of remote employers require employees to appear on a live video feed. ResumeBuilder.com found more than a third keep workers on camera during the day.
WorkTime remote monitoring adoption data.

Worker sentiment and turnover

7. Overall, 49% of U.S. employees would consider leaving if surveillance increased. A 2025 ExpressVPN survey of U.S. workers found nearly half would think about quitting over more monitoring. 8. Notably, 1 in 6 U.S. employees is considering quitting over invasive monitoring. The same 2025 ExpressVPN survey tied heavy surveillance directly to turnover risk. 9. According to the data, 54% of workers said they were likely to quit if their employer added surveillance. ExpressVPN reported this in its 2021 U.S. remote-workforce study. 10. Significantly, 59% of employees reported stress or anxiety about being surveilled online. The 2021 ExpressVPN study found monitoring carried a real mental health cost. 11. The 2021 ExpressVPN study found workers willing to trade real money for privacy. 48% of employees would accept lower pay to avoid surveillance, and 1 in 4 would take a 25% pay cut. 12. About 25% of employees would still take a pay cut to avoid invasive monitoring in 2025. The 2025 ExpressVPN survey showed the trade-off held years later. 13. The study shows that 32% of monitored employees feel pressured to work faster. The 2025 ExpressVPN survey found monitoring changed behavior, not just perception. 14. Across organizations, 24% of employees take fewer breaks to avoid looking idle. Nearly a quarter change how they rest because of tracking, per the 2025 ExpressVPN survey. 15. A Pew Research Center survey of 11,004 U.S. adults found broad discomfort with AI tracking. 81% of U.S. adults say AI monitoring would make workers feel inappropriately watched. 16. What’s more, 64% of U.S. adults aged 18 to 29 oppose AI tracking of work-computer activity, versus 38% of those 65 and older. Pew found the strongest opposition among younger workers. 17. Two-thirds of U.S. adults believe worker-performance data would be misused. Pew found most people expect collected data to be turned against employees. 18. ResumeBuilder.com found monitoring is used for real employment decisions, not just oversight. 73% of remote employers have let workers go based on monitoring data. 19. According to the research, 69% of companies have had employees quit because they did not want to be monitored. ResumeBuilder.com tied monitoring directly to voluntary exits. 20. Notably, 97% of leaders believe monitoring software increased productivity. ResumeBuilder.com found leaders overwhelmingly credit the tools, even as workers push back.

The productivity-paranoia gap

21. The data shows that 85% of leaders say hybrid work makes it hard to be confident employees are productive. The global Microsoft Work Trend Index named this "productivity paranoia." 22. About 90% of employees report they are productive at work. Microsoft found a wide gap between how workers see themselves and how leaders see them. 23. Only 12% of leaders have full confidence their team is productive. Microsoft found trust, not output, is the real gap driving monitoring. 24. Hybrid managers struggle to trust employees at a rate of 49% versus 36% for in-person managers. Microsoft found distance widens the trust gap. 25. Hybrid managers report less visibility into work, at 54% versus 38%. Microsoft tied the monitoring push to a visibility problem, not a productivity one.
WorkTime productivity vs trust gap data.

Market size

26. The global employee monitoring software market was valued at $1.6 billion in 2024 and is projected to reach $3.42 billion by 2030, a 13.3% compound annual growth rate. This estimate comes from Strategic Market Research. Market-size figures vary widely by firm, so treat this as one estimate.

What the legal mistakes cost

Illinois biometric law (BIPA) is the reason this section carries the largest numbers. It is the only state biometric statute that lets employees sue directly, and the results have been severe.
BIPA case Outcome

Facebook (Patel)

$650 million settlement

Google

$100 million settlement

TikTok (ByteDance)

$92 million settlement

BNSF Railway (Rogers)

$228 million jury verdict, later settled for $75 million

White Castle (Cothron)

Up to $17.1 billion exposure, settled for $9.39 million

27. Illinois BIPA carries statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation. These per-violation figures, from the National Law Review, are what make Illinois the most dangerous state for biometrics. 28. Facebook paid $650 million to settle a BIPA class action in 2021. The American Bar Association called it the largest all-cash privacy settlement at the time. 29. Google settled an Illinois biometric class action for $100 million. The National Law Review lists it among the largest BIPA payouts. 30. TikTok's parent company agreed to a $92 million BIPA settlement. The National Law Review documents the scale of face-scan litigation. 31. A BNSF Railway jury found 45,600 reckless or intentional BIPA violations and awarded $228 million. Lockton reported the first BIPA case to reach a jury. The verdict was later vacated and settled for $75 million. 32. White Castle faced up to $17.1 billion in potential BIPA exposure before settling for $9.39 million. Vinson & Elkins reported the Illinois Supreme Court ruling that allowed per-scan damages. 33. More than 1,500 BIPA lawsuits have been filed in Illinois state and federal courts. The National Law Review tracks the volume of biometric litigation. 34. The federal Wiretap Act allows civil damages of the greater of $100 per day or $10,000. Under 18 U.S.C. 2520, illegal interception carries real statutory penalties on top of any state claim. For our own current figures on adoption and productivity trends, see the WorkTime employee monitoring statistics page.
WorkTime research. Computer usage statisctics.

The legal framework at a glance

Employee monitoring law in the U.S. is a patchwork, not a single rule. Four categories cover almost every question an employer will face, and each has its own section in this guide.
  • Notice and consent. Federal law permits monitoring of company systems for legitimate business reasons and defaults to one-party consent. Connecticut, Delaware, and New York add a duty to give employees prior written notice. These states require notice. Consent is one way to satisfy that duty, not a separate blanket rule.
  • Video and audio surveillance. Most states allow workplace video where employees have no reasonable expectation of privacy, which rules out restrooms, locker rooms, and changing areas. Audio is stricter. Nine states clearly require all-party consent to record a conversation.
  • Biometrics. Illinois, Texas, and Washington regulate fingerprints, face scans, and similar data. Illinois is the only one that lets employees sue directly, which is why almost all biometric litigation happens there.
  • Data privacy. California extends its consumer privacy law (the CCPA) to employee data. Most other state privacy laws exempt employee and applicant data, so California stands alone here.

Federal law: The baseline in all 50 states

There is no single federal law that governs private-sector employee monitoring on its own. Instead, a set of federal laws applies by monitoring type, with the Electronic Communications Privacy Act and the Stored Communications Act as the spine. Federal law generally permits monitoring of company-owned systems and defaults to one-party consent, but state law can require more.
Federal law Citation What it does for monitoring

Electronic Communications Privacy Act (ECPA) / Federal Wiretap Act

18 U.S.C. 2510 to 2523

Bars intentional interception of wire, oral, and electronic communications. Two employer exceptions matter: the ordinary-course-of-business exception (18 U.S.C. 2510(5)(a)) and the one-party consent exception (18 U.S.C. 2511(2)(d)). Consent is often built into an acknowledged computer-use policy.

Stored Communications Act (SCA)

18 U.S.C. 2701 to 2712

Governs access to stored messages. Lets employers reach communications on company systems in line with a disclosed policy but bars unauthorized access to private personal accounts.

Federal Wiretap Act civil damages

18 U.S.C. 2520(c)(2)

Sets civil damages at the greater of $100 per day or $10,000, plus punitive damages and fees.

National Labor Relations Act (NLRA)

29 U.S.C. 151 (Sections 7 and 8(a)(1))

Surveillance that chills protected group activity is unlawful. This applies to non-union workplaces too.

Title VII of the Civil Rights Act

42 U.S.C. 2000e

Targeted, purposeless surveillance of a protected group can be evidence of harassment or retaliation.

Video Privacy Protection Act (VPPA)

18 U.S.C. 2710

Limited scope. Restricts disclosure of certain video-viewing records.

HIPAA

42 U.S.C. 1320d

If monitoring touches protected health information, employers must avoid improper collection or exposure of it.

Fourth Amendment

U.S. Const. amend. IV

Applies to public-sector employers only. Protects government employees from unreasonable searches. It does not bind private employers.

The practical takeaway is simple. On company-owned equipment, for a legitimate business reason, federal law lets you monitor with one party's consent, and the employer is usually that party. For a deeper federal question-and-answer breakdown, see our guide to U.S. federal employee monitoring rules.

The 3 states with dedicated monitoring-notice laws

Only three states have a statute that specifically requires employers to notify employees of electronic monitoring: Connecticut, Delaware, and New York. Some guides list Texas as a fourth. Texas has a notice practice, but no dedicated monitoring-notice statute, so the real number is three.
WorkTime monitoring laws Connecticut, Delaware, New York.

Connecticut

Connecticut requires prior written notice of electronic monitoring plus a posted notice. Under Conn. Gen. Stat. 31-48d, an employer that engages in any electronic monitoring must give prior written notice to affected employees describing the types of monitoring and must post that notice in a conspicuous place. An exception applies when the employer has reasonable grounds to believe employees are breaking the law. Civil penalties run $500 for the first offense, $1,000 for the second, and $3,000 for each after that. A 2026 amendment adds a plain-language statement requirement for employees hired on or after October 1, 2026.

Delaware

Delaware requires notice before monitoring phone, email, or internet use. Under 19 Del. C. 705, an employer must either give electronic notice each day an employee accesses company email or internet, or give a one-time written or electronic notice that the employee acknowledges. The civil penalty is $100 per violation.

New York

New York requires written notice on hire plus a signed acknowledgment. Under N.Y. Civil Rights Law 52-c, effective May 7, 2022, an employer that monitors phone, email, or internet use must give prior written notice to new hires, get their written or electronic acknowledgment, and post the notice conspicuously. The attorney general enforces it, with penalties of $500, $1,000, and $3,000 for repeat offenses, the same escalating schedule Connecticut uses. For a state-specific walkthrough, see our guide to employee monitoring in New York State.

Audio recording consent: One-party vs. all-party states

Recording calls and meetings is the strictest kind of monitoring, and it follows a different map than screen or activity tracking. Federal law and most states allow recording with one party's consent. But depending on how you count the disputed states, 11 to 12 states require all-party consent, meaning every participant must agree.

One-party consent

One-party consent means one person on the call can agree to record it. In a one-party state, an employer that is part of the conversation, or that has one participant's consent, can record legally. This is the federal default under the ECPA and the rule in most states.

All-party consent

All-party consent means everyone on the call must agree. In these states, recording a call or meeting without consent from every participant can be a crime. Nine states are clear-cut: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, and Washington. Get consent from everyone before recording any of them. Several more states are disputed or context-dependent, so treat them as all-party to be safe.
  • Connecticut is one-party under its criminal statute but all-party for telephone recording under its civil statute (Conn. Gen. Stat. 52-570d).
  • Delaware has two conflicting statutes. One reads all-party, one reads one-party. Courts have split, so the safe path is all-party.
  • Michigan's statute reads all-party, but a state court held that a participant may record their own conversation, which functions as one-party.
  • Nevada requires all-party consent for phone calls but only one-party for in-person conversations.
  • Oregon requires all-party consent for in-person conversations but only one-party consent by phone.
The practical rule for any team that records calls or meetings across state lines: get consent from everyone. The strictest reading always keeps you safe, and a simple recording disclosure at the start of a call satisfies it.

Biometric privacy laws

Three states have biometric privacy statutes that reach employers, and Illinois is by far the most dangerous because it lets employees sue directly. Biometric data means fingerprints, face scans, retina scans, and similar identifiers, often collected through fingerprint time clocks or face-recognition logins. 1. Illinois BIPA is the strictest biometric law in the country. The Biometric Information Privacy Act (820 ILCS 55) requires written consent before an employer collects biometric data, along with a written retention and destruction policy. It is the only biometric law with a private right of action, so employees can sue without waiting for a regulator. Damages run $1,000 per negligent violation and $5,000 per intentional or reckless violation. A 2024 amendment limited how per-scan violations stack and confirmed that an electronic signature counts as written consent.
WorkTime. Illinois BIPA settlement statistic
2. Texas CUBI regulates biometric capture, but only the attorney general can enforce it. The Capture or Use of Biometric Identifier law (Tex. Bus. & Com. Code 503.001) requires an employer to inform a person and get consent before capturing biometric data and sets a civil penalty of up to $25,000 per violation. There is no private right of action, so enforcement comes from the state, not employees. 3. Washington regulates commercial biometric enrollment through notice, consent, or an opt-out. Under RCW 19.375, a business may not enroll biometric data for a commercial purpose without first providing notice, getting consent, or offering a way to prevent that use. The Attorney General enforces it. Its reach over routine workplace timekeeping is narrower than BIPA. 4. California treats biometric data as sensitive personal information under the CCPA, which adds notice and data-limit duties rather than an opt-in consent rule. Illinois biometric cases have produced settlements as large as $650 million, plus one theoretical exposure of $17.1 billion. For regulated employers, this is exactly where a monitoring tool that never collects biometric or content data removes the risk at the source. WorkTime reinforces this approach with dedicated GDPR-, HIPAA-, and GLBA-safe modes that minimize the collection of regulated or sensitive information by default, helping organizations in healthcare, finance, and other regulated industries reduce compliance risks while maintaining productivity visibility.
WorkTime. GLBA-safe employee monitoring.
WorkTime. Monitoring with GLBA-safe mode/

Strengthen compliance with GLBA-safe mode, which minimizes the possibility of indirect NPI collection while supporting transparent, privacy-conscious employee monitoring.

Start free trial

Social media password protection laws

More than 20 states bar employers from demanding access to an employee's or applicant's personal social media accounts. These laws stop an employer from requiring a username and password, forcing a login, or making someone add a manager as a contact to view private posts. Maryland passed the first such law in 2012 (Md. Lab. & Empl. 3-712). New York is one of the most recent, with N.Y. Labor Law 201-i taking effect in 2024. A few laws are narrower than others. New Mexico's statute (N.M. Stat. 50-4-34), for example, applies only to job applicants, not current employees. Each state's social media statute is cited by section in the state-by-state reference that follows.

Employee monitoring laws by state: all 50 states + DC

This state-by-state reference covers all 50 states and the District of Columbia. Every legal cell points to the state's primary statute. Where a state has no monitoring-specific law, the federal ECPA one-party rule governs, and monitoring of company equipment is generally allowed with notice. States with a dedicated notice statute or an all-party audio rule are bolded.
State Dedicated monitoring-notice statute Audio recording consent Other relevant law (primary cite) Notes

Alabama

WorkTime

One-party (Ala. Code 13A-11-30)

ECPA governs; monitoring of company systems allowed with notice.

Alaska

WorkTime

One-party (Alaska Stat. 42.20.310)

Arizona

WorkTime

One-party (Ariz. Rev. Stat. 13-3005)

Arkansas

WorkTime

One-party (Ark. Code 5-60-120)

Social media: Ark. Code 11-2-124

California

No (AB 1221 failed in 2026)

All-party (Cal. Penal Code 632)

CCPA covers employee data (Cal. Civ. Code 1798.100); social media: Cal. Lab. Code 980

Strictest data-privacy state. See our California employee monitoring guide.

Colorado

WorkTime

One-party (Colo. Rev. Stat. 18-9-303)

Colorado Privacy Act (Colo. Rev. Stat. 6-1-1301); social media: C.R.S. 8-2-127

The Colorado Privacy Act is a broad data law, not a monitoring-notice statute.

Connecticut

Yes (Conn. Gen. Stat. 31-48d)

All-party for phone (civil 52-570d)

Social media: Conn. Gen. Stat. 31-40x

Prior written notice plus posting; penalty $500 / $1,000 / $3,000.

Delaware

Yes (19 Del. C. 705)

Disputed, treated as all-party (11 Del. C. 1335 vs 2402)

Social media: 19 Del. C. 709A

Daily or one-time acknowledged notice; $100 per violation.

Florida

WorkTime

All-party (Fla. Stat. 934.03)

Georgia

WorkTime

One-party (Ga. Code 16-11-62)

Hawaii

WorkTime

One-party (Haw. Rev. Stat. 803-42)

Idaho

WorkTime

One-party (Idaho Code 18-6702)

Illinois

WorkTime

All-party (720 ILCS 5/14-2)

BIPA biometric (740 ILCS 14); social media: 820 ILCS 55/10

Highest biometric-litigation risk in the country.

Indiana

WorkTime

One-party (Ind. Code 35-33.5)

Iowa

WorkTime

One-party (Iowa Code 808B.2)

Kansas

WorkTime

One-party (Kan. Stat. 21-6101)

Kentucky

WorkTime

One-party (Ky. Rev. Stat. 526.010)

Louisiana

WorkTime

One-party (La. Rev. Stat. 15:1303)

Social media: La. Rev. Stat. 51:1951

Maine

WorkTime

One-party (Me. Rev. Stat. tit. 15, 709)

Social media: 26 M.R.S. 616

Maryland

WorkTime

All-party (Md. Cts. & Jud. Proc. 10-402)

Social media: Md. Lab. & Empl. 3-712

First state to pass a social media password law, in 2012.

Massachusetts

WorkTime

All-party (Mass. Gen. Laws ch. 272, 99)

Bars secret recording; open recording is allowed.

Michigan

WorkTime

Disputed, treat as all-party (MCL 750.539c)

Social media: MCL 37.271

A participant may record their own conversation under case law.

Minnesota

WorkTime

One-party (Minn. Stat. 626A.02)

Mississippi

WorkTime

One-party (Miss. Code 41-29-531)

Missouri

WorkTime

One-party (Mo. Rev. Stat. 542.402)

Montana

WorkTime

All-party (Mont. Code 45-8-213)

Social media: Mont. Code 39-2-307

A party may give an audible warning, then record.

Nebraska

WorkTime

One-party (Neb. Rev. Stat. 86-290)

Social media: Neb. Rev. Stat. 48-3501

Nevada

WorkTime

All-party by phone (NRS 200.620), one-party in person (200.650)

Social media: NRS 613.135

Phone and in-person rules differ.

New Hampshire

WorkTime

All-party (N.H. Rev. Stat. 570-A:2)

Social media: N.H. Rev. Stat. 275:74

New Jersey

WorkTime

One-party (N.J. Stat. 2A:156A-4)

Social media: N.J. Stat. 34:6B-6

New Mexico

WorkTime

One-party (N.M. Stat. 30-12-1)

Social media: N.M. Stat. 50-4-34 (applicants only)

New York

Yes (N.Y. Civ. Rights Law 52-c)

One-party (N.Y. Penal Law 250.00)

Social media: N.Y. Lab. Law 201-i; SHIELD Act (Gen. Bus. Law 899-bb)

Notice on hire plus acknowledgment plus posting; effective May 7, 2022.

North Carolina

WorkTime

One-party (N.C. Gen. Stat. 15A-287)

North Dakota

WorkTime

One-party (N.D. Cent. Code 12.1-15-02)

Ohio

WorkTime

One-party (Ohio Rev. Code 2933.52)

Oklahoma

WorkTime

One-party (Okla. Stat. tit. 13, 176.4)

Social media: 40 Okla. Stat. 173.2

Oregon

WorkTime

All-party in person (ORS 165.540), one-party by phone

Social media: ORS 659A.330

In-person and phone rules differ.

Pennsylvania

WorkTime

All-party (18 Pa.C.S. 5704)

Rhode Island

WorkTime

One-party (R.I. Gen. Laws 11-35-21))

Social media: R.I. Gen. Laws 28-56

South Carolina

WorkTime

One-party (S.C. Code 17-30-30)

South Dakota

WorkTime

One-party (S.D. Codified Laws 23A-35A-20)

Tennessee

WorkTime

One-party (Tenn. Code 39-13-601)

Social media: Tenn. Code 50-1-1001

Texas

No (notice practice only)

One-party (Tex. Penal Code 16.02)

CUBI biometric (Tex. Bus. & Com. Code 503.001)

Broad monitoring of company equipment allowed with notice. See our Texas guide.

Utah

WorkTime

One-party (Utah Code 77-23a-4)

Social media: Utah Code 34-48-201

Vermont

WorkTime

One-party (no statute; common law)

Social media: 21 V.S.A. 495l

Only state with no wiretap statute.

Virginia

WorkTime

One-party (Va. Code 19.2-62)

VCDPA exempts employee data (Va. Code 59.1-575); social media: Va. Code 40.1-28.7:5

Washington

WorkTime

All-party (Wash. Rev. Code 9.73.030)

Biometric (RCW 19.375); social media: RCW 49.44.200; My Health My Data Act (RCW 19.373)

West Virginia

WorkTime

One-party (W. Va. Code 62-1D-3)

Social media: W. Va. Code 21-5H-1

Wisconsin

WorkTime

One-party (Wis. Stat. 968.31)

Social media: Wis. Stat. 995.55

Wyoming

WorkTime

One-party (Wyo. Stat. 7-3-702)

District of Columbia

WorkTime

One-party (D.C. Code 23-542)

Three quick counts from the table:
  1. Three states have a dedicated monitoring-notice statute: Connecticut, Delaware, and New York.
  2. Three states have a biometric statute that reaches employers: Illinois, Texas, and Washington.
  3. Only California applies its consumer privacy law to employee data. Most other state privacy laws, including those in Virginia and Colorado, exempt employee and applicant data.

California AB 1221: The “2026 law” that never passed

California AB 1221 is not law. Despite many compliance guides calling it "effective January 2026," the workplace-surveillance bill died in the 2025 to 2026 legislative session and never took effect. Building a policy around it is a mistake, and citing it as active is the single most common error in current monitoring-law content.
WorkTimeю California law.
Here is the record. AB 1221 was introduced on February 21, 2025, and last amended in May 2025. It died on January 31, 2026, and was filed with the Chief Clerk under Joint Rule 56 on February 2, 2026. You can confirm the status on the California Legislature's official bill page. Had it passed, AB 1221 would have required employers to give affected workers written notice at least 30 days before deploying a workplace surveillance tool and would have banned tools using facial recognition, gait recognition, or emotion recognition except in narrow cases. None of that is in force. California employers still follow the existing rules: all-party audio consent under Penal Code 632 and CCPA duties for employee data. One more clarification, since it causes similar confusion. The Colorado Privacy Act is a broad consumer-data law. It is not a workplace electronic-monitoring notice statute, so it does not belong in the same group as Connecticut, Delaware, and New York.

How to monitor employees legally

Legal monitoring comes down to three things: give notice, limit what you collect, and match the strictest state rule that applies to your team. These steps turn the law into a working policy. This is general guidance, not legal advice, so run your final policy past counsel for your specific situation. 1. Write a monitoring policy and get written acknowledgment. A clear policy that employees sign satisfies the notice duty in most states and creates the consent that federal law relies on. Put it in the handbook and at login. To make implementation easier, use WorkTime employee monitoring handbook and ready-to-use monitoring policy templates as a foundation for your own documentation. 2. Limit monitoring to company-owned equipment and work purposes. Personal devices and personal accounts carry far more risk. Monitoring company systems for a legitimate business reason is the safest ground. 3. Stay out of high-privacy zones. No cameras in restrooms, locker rooms, or changing areas. No reaching into private personal accounts. These are where reasonable-expectation-of-privacy claims start. 4. Get all-party consent before recording audio in strict states. A recording disclosure at the start of a call is enough. When a team spans several states, apply the strictest rule. 5. Never collect biometric data without written consent. In Illinois especially, a fingerprint time clock without a signed release is a lawsuit waiting to happen. 6. For remote teams, apply the law of the state where the employee physically works. That is the rule that generally governs, not the state where the company is based. There is a simpler way to cut most of this risk: collect less. Most of the legal exposure on this page comes from capturing content, whether that is intercepting messages, recording audio, or collecting biometrics. Non-invasive employee monitoring software avoids that category entirely. WorkTime measures productivity, active and idle time, attendance, and app usage without screenshots, keystroke content, screen recordings, or email and chat capture, which gives HR and IT the visibility they need while keeping sensitive data out of reach.
WorkTime 80+ non-invasive monitoring reports.
WorkTime. Safe employee monitoring software.

Turn activity into insights with 80+ WorkTime reports! Analyze performance clearly and safely, without collecting personal content.

Start free trial
For regulated employers, our Enterprise plan adds HIPAA-safe, GDPR-safe, and GLBA-safe modes on top of that. You can read how the non-invasive approach works on our privacy-compliant monitoring and non-invasive monitoring pages, or start with the core employee monitoring overview.

Conclusion

Employee monitoring is legal across all 50 states, and the rules are more manageable than the headlines suggest. Monitor company equipment for a real business reason, give employees notice, and you will be compliant almost everywhere. The details that trip employers up are narrow and specific: prior-notice statutes in Connecticut, Delaware, and New York, all-party audio consent in about a dozen states, and written consent for biometrics, where Illinois has turned mistakes into nine-figure settlements. The one trap to avoid is treating California AB 1221 as active law. It is not. The cleanest way to stay on the right side of these rules is to collect less. Non-invasive employee monitoring software gives you productivity analytics and remote-workforce visibility without the screenshots, keystroke content, recordings, or biometrics that create most of the legal exposure on this page. That is the approach we have built at WorkTime since 1998, and it is the one regulated employers in healthcare, finance, and government rely on. If compliance is driving your search, try WorkTime free for 14 days with no credit card, or book a demo to see the non-invasive approach in action.

Disclaimer

This guide is general information, not legal advice. Consult an employment attorney before finalizing a monitoring policy for your organization.

Frequently asked questions

Is it legal to monitor employees without telling them?

On company-owned equipment, federal law and most states require notice, not affirmative consent, so monitoring without a signed agreement is often legal if a policy is disclosed. Connecticut, Delaware, and New York go further and require prior written notice by statute. Covert monitoring with no notice at all is the riskiest approach and can violate wiretap or state law.

Do employers have the right to monitor employees?

Yes. Employers have the right to monitor employees on company-owned equipment for a legitimate business reason in all 50 states. The limits are on how you do it: notice in three states, all-party consent for audio in about a dozen, written consent for biometrics, and no monitoring in areas where employees reasonably expect privacy.

Can an employer monitor a personal device?

Monitoring a personal device generally requires the employee's consent and carries far more legal risk than monitoring company equipment. The Stored Communications Act bars unauthorized access to private accounts, and more than 20 states protect personal social media accounts. Most employers avoid monitoring personal devices and limit tracking to company-owned systems.

Which state's monitoring law applies to a remote employee?

The law of the state where the employee physically works generally applies, not the state where the company is headquartered. A company based in Texas with an employee working from Connecticut must follow Connecticut's notice statute for that worker. Teams spread across states should apply the strictest applicable rule.

Can you sue an employer for monitoring you?

It depends on the state and the type of monitoring. Illinois BIPA gives employees a direct right to sue over biometric data, which is why most monitoring lawsuits happen there. The federal Wiretap Act allows civil damages for illegal interception. For most other monitoring, enforcement comes from a state attorney general rather than a private suit.

Is employee monitoring the same as surveillance?

Not necessarily. Monitoring with notice, a clear business purpose, and limits on what is collected is lawful and common. Covert, boundless surveillance is what triggers legal and trust problems. Non-invasive monitoring that tracks productivity metrics without capturing screenshots or message content sits firmly on the lawful side of that line.

WorkTime

Employee monitoring software

WorkTime

Non-invasive - the only non-invasive software on the market

25+ years on the market

80+ reports: attendance, productivity, active time, online meetings, remote vs. in-office and more

WorkTime WorkTime WorkTime WorkTime WorkTime WorkTime WorkTime

What’s next

employee monitoring laws worktime us employee monitoring laws