TL;DR
- Monitoring company devices is legal in every state with a legitimate business reason and, in almost every case, notice to employees. Federal law defaults to one-party consent.
- Only three states have a dedicated electronic-monitoring notice law: Connecticut, Delaware, and New York. Texas is often listed as a fourth. It has no such statute.
- Recording audio is the strictest kind of monitoring. Nine states clearly require all-party consent, and several more are disputed, so calls and meetings carry tighter rules than screen or activity tracking.
- Illinois is the highest-risk state for biometrics. Its BIPA law carries $1,000 to $5,000 in damages per violation and lets employees win settlements up to $650 million.
- California AB 1221 is not law. The workplace-surveillance bill that many 2026 guides call "effective January 2026" died in the legislature. Do not build a policy around it.
In this article
The article is presented by WorkTime, providing transparent, non-invasive workforce analytics with built-in compliance features that help organizations improve productivity while respecting employee privacy.This guide maps the full legal picture: the federal baseline, the three states with a dedicated monitoring-notice law, the audio-recording consent map, biometric rules, and a citation for every state. It also corrects one error that shows up in most 2026 compliance guides, because getting the law wrong is worse than not publishing it.
Employee monitoring in the U.S., by the numbers
Employer monitoring climbed sharply through the shift to remote work, and worker backlash climbed with it. These figures are the current, sourced picture of how common monitoring is, how workers feel about it, and what the biggest legal mistakes have cost. Most surveys below sample U.S. employers and workers. Figures from global or aggregated international studies (Gartner, Microsoft, StandOutCV, and Strategic Market Research) are labeled global at first mention. Each figure is numbered so it is easy to cite.| Headline metric | Figure | Source |
|---|---|---|
|
Large employers projected to monitor staff by 2025 (global) |
70% |
StandOutCV |
|
U.S. employers using monitoring software |
80% |
ExpressVPN |
|
Remote U.S. companies using monitoring software |
96% |
ResumeBuilder.com |
|
U.S. workers who would consider leaving over more surveillance |
49% |
ExpressVPN |
|
U.S. adults who say AI monitoring feels inappropriate |
81% |
Pew Research Center |
|
Largest single BIPA settlement (Facebook) |
$650 million |
American Bar Association |
Adoption and prevalence
1. Large-employer monitoring rose from 30% in 2015 to more than 50% by 2018. A global Gartner survey of 239 large corporations found more than half were using some form of nontraditional monitoring, up from just 30% three years earlier. 2. An estimated 70% of large employers monitor employees as of 2025. A global StandOutCV study projects that 70% of large employers now track their staff in some way. 3. Monitoring tools grew more invasive, with an invasiveness score rising from 45% to 53% between 2021 and 2023. The same StandOutCV study tracked the worldwide shift toward heavier data collection. 4. According to the data, 80% of U.S. employers report using employee monitoring software. An ExpressVPN survey of 2,000 U.S. employers and 2,000 employees found 80% use software to track performance or online activity. 5. The research shows that 96% of remote U.S. companies use employee monitoring software. A ResumeBuilder.com survey of 1,000 U.S. business leaders found near-universal adoption among remote employers. 6. About 40% of remote employers require employees to appear on a live video feed. ResumeBuilder.com found more than a third keep workers on camera during the day.
Worker sentiment and turnover
7. Overall, 49% of U.S. employees would consider leaving if surveillance increased. A 2025 ExpressVPN survey of U.S. workers found nearly half would think about quitting over more monitoring. 8. Notably, 1 in 6 U.S. employees is considering quitting over invasive monitoring. The same 2025 ExpressVPN survey tied heavy surveillance directly to turnover risk. 9. According to the data, 54% of workers said they were likely to quit if their employer added surveillance. ExpressVPN reported this in its 2021 U.S. remote-workforce study. 10. Significantly, 59% of employees reported stress or anxiety about being surveilled online. The 2021 ExpressVPN study found monitoring carried a real mental health cost. 11. The 2021 ExpressVPN study found workers willing to trade real money for privacy. 48% of employees would accept lower pay to avoid surveillance, and 1 in 4 would take a 25% pay cut. 12. About 25% of employees would still take a pay cut to avoid invasive monitoring in 2025. The 2025 ExpressVPN survey showed the trade-off held years later. 13. The study shows that 32% of monitored employees feel pressured to work faster. The 2025 ExpressVPN survey found monitoring changed behavior, not just perception. 14. Across organizations, 24% of employees take fewer breaks to avoid looking idle. Nearly a quarter change how they rest because of tracking, per the 2025 ExpressVPN survey. 15. A Pew Research Center survey of 11,004 U.S. adults found broad discomfort with AI tracking. 81% of U.S. adults say AI monitoring would make workers feel inappropriately watched. 16. What’s more, 64% of U.S. adults aged 18 to 29 oppose AI tracking of work-computer activity, versus 38% of those 65 and older. Pew found the strongest opposition among younger workers. 17. Two-thirds of U.S. adults believe worker-performance data would be misused. Pew found most people expect collected data to be turned against employees. 18. ResumeBuilder.com found monitoring is used for real employment decisions, not just oversight. 73% of remote employers have let workers go based on monitoring data. 19. According to the research, 69% of companies have had employees quit because they did not want to be monitored. ResumeBuilder.com tied monitoring directly to voluntary exits. 20. Notably, 97% of leaders believe monitoring software increased productivity. ResumeBuilder.com found leaders overwhelmingly credit the tools, even as workers push back.The productivity-paranoia gap
21. The data shows that 85% of leaders say hybrid work makes it hard to be confident employees are productive. The global Microsoft Work Trend Index named this "productivity paranoia." 22. About 90% of employees report they are productive at work. Microsoft found a wide gap between how workers see themselves and how leaders see them. 23. Only 12% of leaders have full confidence their team is productive. Microsoft found trust, not output, is the real gap driving monitoring. 24. Hybrid managers struggle to trust employees at a rate of 49% versus 36% for in-person managers. Microsoft found distance widens the trust gap. 25. Hybrid managers report less visibility into work, at 54% versus 38%. Microsoft tied the monitoring push to a visibility problem, not a productivity one.
Market size
26. The global employee monitoring software market was valued at $1.6 billion in 2024 and is projected to reach $3.42 billion by 2030, a 13.3% compound annual growth rate. This estimate comes from Strategic Market Research. Market-size figures vary widely by firm, so treat this as one estimate.What the legal mistakes cost
Illinois biometric law (BIPA) is the reason this section carries the largest numbers. It is the only state biometric statute that lets employees sue directly, and the results have been severe.| BIPA case | Outcome |
|---|---|
|
Facebook (Patel) |
$650 million settlement |
|
|
$100 million settlement |
|
TikTok (ByteDance) |
$92 million settlement |
|
BNSF Railway (Rogers) |
$228 million jury verdict, later settled for $75 million |
|
White Castle (Cothron) |
Up to $17.1 billion exposure, settled for $9.39 million |

The legal framework at a glance
Employee monitoring law in the U.S. is a patchwork, not a single rule. Four categories cover almost every question an employer will face, and each has its own section in this guide.- Notice and consent. Federal law permits monitoring of company systems for legitimate business reasons and defaults to one-party consent. Connecticut, Delaware, and New York add a duty to give employees prior written notice. These states require notice. Consent is one way to satisfy that duty, not a separate blanket rule.
- Video and audio surveillance. Most states allow workplace video where employees have no reasonable expectation of privacy, which rules out restrooms, locker rooms, and changing areas. Audio is stricter. Nine states clearly require all-party consent to record a conversation.
- Biometrics. Illinois, Texas, and Washington regulate fingerprints, face scans, and similar data. Illinois is the only one that lets employees sue directly, which is why almost all biometric litigation happens there.
- Data privacy. California extends its consumer privacy law (the CCPA) to employee data. Most other state privacy laws exempt employee and applicant data, so California stands alone here.
Federal law: The baseline in all 50 states
There is no single federal law that governs private-sector employee monitoring on its own. Instead, a set of federal laws applies by monitoring type, with the Electronic Communications Privacy Act and the Stored Communications Act as the spine. Federal law generally permits monitoring of company-owned systems and defaults to one-party consent, but state law can require more.| Federal law | Citation | What it does for monitoring |
|---|---|---|
|
Electronic Communications Privacy Act (ECPA) / Federal Wiretap Act |
18 U.S.C. 2510 to 2523 |
Bars intentional interception of wire, oral, and electronic communications. Two employer exceptions matter: the ordinary-course-of-business exception (18 U.S.C. 2510(5)(a)) and the one-party consent exception (18 U.S.C. 2511(2)(d)). Consent is often built into an acknowledged computer-use policy. |
|
Stored Communications Act (SCA) |
18 U.S.C. 2701 to 2712 |
Governs access to stored messages. Lets employers reach communications on company systems in line with a disclosed policy but bars unauthorized access to private personal accounts. |
|
Federal Wiretap Act civil damages |
18 U.S.C. 2520(c)(2) |
Sets civil damages at the greater of $100 per day or $10,000, plus punitive damages and fees. |
|
National Labor Relations Act (NLRA) |
29 U.S.C. 151 (Sections 7 and 8(a)(1)) |
Surveillance that chills protected group activity is unlawful. This applies to non-union workplaces too. |
|
Title VII of the Civil Rights Act |
42 U.S.C. 2000e |
Targeted, purposeless surveillance of a protected group can be evidence of harassment or retaliation. |
|
Video Privacy Protection Act (VPPA) |
18 U.S.C. 2710 |
Limited scope. Restricts disclosure of certain video-viewing records. |
|
HIPAA |
42 U.S.C. 1320d |
If monitoring touches protected health information, employers must avoid improper collection or exposure of it. |
|
Fourth Amendment |
U.S. Const. amend. IV |
Applies to public-sector employers only. Protects government employees from unreasonable searches. It does not bind private employers. |
The 3 states with dedicated monitoring-notice laws
Only three states have a statute that specifically requires employers to notify employees of electronic monitoring: Connecticut, Delaware, and New York. Some guides list Texas as a fourth. Texas has a notice practice, but no dedicated monitoring-notice statute, so the real number is three.
Connecticut
Connecticut requires prior written notice of electronic monitoring plus a posted notice. Under Conn. Gen. Stat. 31-48d, an employer that engages in any electronic monitoring must give prior written notice to affected employees describing the types of monitoring and must post that notice in a conspicuous place. An exception applies when the employer has reasonable grounds to believe employees are breaking the law. Civil penalties run $500 for the first offense, $1,000 for the second, and $3,000 for each after that. A 2026 amendment adds a plain-language statement requirement for employees hired on or after October 1, 2026.Delaware
Delaware requires notice before monitoring phone, email, or internet use. Under 19 Del. C. 705, an employer must either give electronic notice each day an employee accesses company email or internet, or give a one-time written or electronic notice that the employee acknowledges. The civil penalty is $100 per violation.New York
New York requires written notice on hire plus a signed acknowledgment. Under N.Y. Civil Rights Law 52-c, effective May 7, 2022, an employer that monitors phone, email, or internet use must give prior written notice to new hires, get their written or electronic acknowledgment, and post the notice conspicuously. The attorney general enforces it, with penalties of $500, $1,000, and $3,000 for repeat offenses, the same escalating schedule Connecticut uses. For a state-specific walkthrough, see our guide to employee monitoring in New York State.Audio recording consent: One-party vs. all-party states
Recording calls and meetings is the strictest kind of monitoring, and it follows a different map than screen or activity tracking. Federal law and most states allow recording with one party's consent. But depending on how you count the disputed states, 11 to 12 states require all-party consent, meaning every participant must agree.One-party consent
One-party consent means one person on the call can agree to record it. In a one-party state, an employer that is part of the conversation, or that has one participant's consent, can record legally. This is the federal default under the ECPA and the rule in most states.All-party consent
All-party consent means everyone on the call must agree. In these states, recording a call or meeting without consent from every participant can be a crime. Nine states are clear-cut: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, and Washington. Get consent from everyone before recording any of them. Several more states are disputed or context-dependent, so treat them as all-party to be safe.- Connecticut is one-party under its criminal statute but all-party for telephone recording under its civil statute (Conn. Gen. Stat. 52-570d).
- Delaware has two conflicting statutes. One reads all-party, one reads one-party. Courts have split, so the safe path is all-party.
- Michigan's statute reads all-party, but a state court held that a participant may record their own conversation, which functions as one-party.
- Nevada requires all-party consent for phone calls but only one-party for in-person conversations.
- Oregon requires all-party consent for in-person conversations but only one-party consent by phone.
Biometric privacy laws
Three states have biometric privacy statutes that reach employers, and Illinois is by far the most dangerous because it lets employees sue directly. Biometric data means fingerprints, face scans, retina scans, and similar identifiers, often collected through fingerprint time clocks or face-recognition logins. 1. Illinois BIPA is the strictest biometric law in the country. The Biometric Information Privacy Act (820 ILCS 55) requires written consent before an employer collects biometric data, along with a written retention and destruction policy. It is the only biometric law with a private right of action, so employees can sue without waiting for a regulator. Damages run $1,000 per negligent violation and $5,000 per intentional or reckless violation. A 2024 amendment limited how per-scan violations stack and confirmed that an electronic signature counts as written consent.


Strengthen compliance with GLBA-safe mode, which minimizes the possibility of indirect NPI collection while supporting transparent, privacy-conscious employee monitoring.
Start free trialSocial media password protection laws
More than 20 states bar employers from demanding access to an employee's or applicant's personal social media accounts. These laws stop an employer from requiring a username and password, forcing a login, or making someone add a manager as a contact to view private posts. Maryland passed the first such law in 2012 (Md. Lab. & Empl. 3-712). New York is one of the most recent, with N.Y. Labor Law 201-i taking effect in 2024. A few laws are narrower than others. New Mexico's statute (N.M. Stat. 50-4-34), for example, applies only to job applicants, not current employees. Each state's social media statute is cited by section in the state-by-state reference that follows.Employee monitoring laws by state: all 50 states + DC
This state-by-state reference covers all 50 states and the District of Columbia. Every legal cell points to the state's primary statute. Where a state has no monitoring-specific law, the federal ECPA one-party rule governs, and monitoring of company equipment is generally allowed with notice. States with a dedicated notice statute or an all-party audio rule are bolded.| State | Dedicated monitoring-notice statute | Audio recording consent | Other relevant law (primary cite) | Notes |
|---|---|---|---|---|
|
Alabama |
![]() |
One-party (Ala. Code 13A-11-30) |
|
ECPA governs; monitoring of company systems allowed with notice. |
|
Alaska |
![]() |
One-party (Alaska Stat. 42.20.310) |
|
|
|
Arizona |
![]() |
One-party (Ariz. Rev. Stat. 13-3005) |
|
|
|
Arkansas |
![]() |
One-party (Ark. Code 5-60-120) |
Social media: Ark. Code 11-2-124 |
|
|
California |
No (AB 1221 failed in 2026) |
All-party (Cal. Penal Code 632) |
CCPA covers employee data (Cal. Civ. Code 1798.100); social media: Cal. Lab. Code 980 |
Strictest data-privacy state. See our California employee monitoring guide. |
|
Colorado |
![]() |
One-party (Colo. Rev. Stat. 18-9-303) |
Colorado Privacy Act (Colo. Rev. Stat. 6-1-1301); social media: C.R.S. 8-2-127 |
The Colorado Privacy Act is a broad data law, not a monitoring-notice statute. |
|
Connecticut |
Yes (Conn. Gen. Stat. 31-48d) |
All-party for phone (civil 52-570d) |
Social media: Conn. Gen. Stat. 31-40x |
Prior written notice plus posting; penalty $500 / $1,000 / $3,000. |
|
Delaware |
Yes (19 Del. C. 705) |
Disputed, treated as all-party (11 Del. C. 1335 vs 2402) |
Social media: 19 Del. C. 709A |
Daily or one-time acknowledged notice; $100 per violation. |
|
Florida |
![]() |
All-party (Fla. Stat. 934.03) |
|
|
|
Georgia |
![]() |
One-party (Ga. Code 16-11-62) |
|
|
|
Hawaii |
![]() |
One-party (Haw. Rev. Stat. 803-42) |
|
|
|
Idaho |
![]() |
One-party (Idaho Code 18-6702) |
|
|
|
Illinois |
![]() |
All-party (720 ILCS 5/14-2) |
BIPA biometric (740 ILCS 14); social media: 820 ILCS 55/10 |
Highest biometric-litigation risk in the country. |
|
Indiana |
![]() |
One-party (Ind. Code 35-33.5) |
|
|
|
Iowa |
![]() |
One-party (Iowa Code 808B.2) |
|
|
|
Kansas |
![]() |
One-party (Kan. Stat. 21-6101) |
|
|
|
Kentucky |
![]() |
One-party (Ky. Rev. Stat. 526.010) |
|
|
|
Louisiana |
![]() |
One-party (La. Rev. Stat. 15:1303) |
Social media: La. Rev. Stat. 51:1951 |
|
|
Maine |
![]() |
One-party (Me. Rev. Stat. tit. 15, 709) |
Social media: 26 M.R.S. 616 |
|
|
Maryland |
![]() |
All-party (Md. Cts. & Jud. Proc. 10-402) |
Social media: Md. Lab. & Empl. 3-712 |
First state to pass a social media password law, in 2012. |
|
Massachusetts |
![]() |
All-party (Mass. Gen. Laws ch. 272, 99) |
|
Bars secret recording; open recording is allowed. |
|
Michigan |
![]() |
Disputed, treat as all-party (MCL 750.539c) |
Social media: MCL 37.271 |
A participant may record their own conversation under case law. |
|
Minnesota |
![]() |
One-party (Minn. Stat. 626A.02) |
|
|
|
Mississippi |
![]() |
One-party (Miss. Code 41-29-531) |
|
|
|
Missouri |
![]() |
One-party (Mo. Rev. Stat. 542.402) |
|
|
|
Montana |
![]() |
All-party (Mont. Code 45-8-213) |
Social media: Mont. Code 39-2-307 |
A party may give an audible warning, then record. |
|
Nebraska |
![]() |
One-party (Neb. Rev. Stat. 86-290) |
Social media: Neb. Rev. Stat. 48-3501 |
|
|
Nevada |
![]() |
All-party by phone (NRS 200.620), one-party in person (200.650) |
Social media: NRS 613.135 |
Phone and in-person rules differ. |
|
New Hampshire |
![]() |
All-party (N.H. Rev. Stat. 570-A:2) |
Social media: N.H. Rev. Stat. 275:74 |
|
|
New Jersey |
![]() |
One-party (N.J. Stat. 2A:156A-4) |
Social media: N.J. Stat. 34:6B-6 |
|
|
New Mexico |
![]() |
One-party (N.M. Stat. 30-12-1) |
Social media: N.M. Stat. 50-4-34 (applicants only) |
|
|
New York |
Yes (N.Y. Civ. Rights Law 52-c) |
One-party (N.Y. Penal Law 250.00) |
Social media: N.Y. Lab. Law 201-i; SHIELD Act (Gen. Bus. Law 899-bb) |
Notice on hire plus acknowledgment plus posting; effective May 7, 2022. |
|
North Carolina |
![]() |
One-party (N.C. Gen. Stat. 15A-287) |
|
|
|
North Dakota |
![]() |
One-party (N.D. Cent. Code 12.1-15-02) |
|
|
|
Ohio |
![]() |
One-party (Ohio Rev. Code 2933.52) |
|
|
|
Oklahoma |
![]() |
One-party (Okla. Stat. tit. 13, 176.4) |
Social media: 40 Okla. Stat. 173.2 |
|
|
Oregon |
![]() |
All-party in person (ORS 165.540), one-party by phone |
Social media: ORS 659A.330 |
In-person and phone rules differ. |
|
Pennsylvania |
![]() |
All-party (18 Pa.C.S. 5704) |
|
|
|
Rhode Island |
![]() |
One-party (R.I. Gen. Laws 11-35-21)) |
Social media: R.I. Gen. Laws 28-56 |
|
|
South Carolina |
![]() |
One-party (S.C. Code 17-30-30) |
|
|
|
South Dakota |
![]() |
One-party (S.D. Codified Laws 23A-35A-20) |
|
|
|
Tennessee |
![]() |
One-party (Tenn. Code 39-13-601) |
Social media: Tenn. Code 50-1-1001 |
|
|
Texas |
No (notice practice only) |
One-party (Tex. Penal Code 16.02) |
CUBI biometric (Tex. Bus. & Com. Code 503.001) |
Broad monitoring of company equipment allowed with notice. See our Texas guide. |
|
Utah |
![]() |
One-party (Utah Code 77-23a-4) |
Social media: Utah Code 34-48-201 |
|
|
Vermont |
![]() |
One-party (no statute; common law) |
Social media: 21 V.S.A. 495l |
Only state with no wiretap statute. |
|
Virginia |
![]() |
One-party (Va. Code 19.2-62) |
VCDPA exempts employee data (Va. Code 59.1-575); social media: Va. Code 40.1-28.7:5 |
|
|
Washington |
![]() |
All-party (Wash. Rev. Code 9.73.030) |
Biometric (RCW 19.375); social media: RCW 49.44.200; My Health My Data Act (RCW 19.373) |
|
|
West Virginia |
![]() |
One-party (W. Va. Code 62-1D-3) |
Social media: W. Va. Code 21-5H-1 |
|
|
Wisconsin |
![]() |
One-party (Wis. Stat. 968.31) |
Social media: Wis. Stat. 995.55 |
|
|
Wyoming |
![]() |
One-party (Wyo. Stat. 7-3-702) |
|
|
|
District of Columbia |
![]() |
One-party (D.C. Code 23-542) |
|
|
- Three states have a dedicated monitoring-notice statute: Connecticut, Delaware, and New York.
- Three states have a biometric statute that reaches employers: Illinois, Texas, and Washington.
- Only California applies its consumer privacy law to employee data. Most other state privacy laws, including those in Virginia and Colorado, exempt employee and applicant data.
California AB 1221: The “2026 law” that never passed
California AB 1221 is not law. Despite many compliance guides calling it "effective January 2026," the workplace-surveillance bill died in the 2025 to 2026 legislative session and never took effect. Building a policy around it is a mistake, and citing it as active is the single most common error in current monitoring-law content.
How to monitor employees legally
Legal monitoring comes down to three things: give notice, limit what you collect, and match the strictest state rule that applies to your team. These steps turn the law into a working policy. This is general guidance, not legal advice, so run your final policy past counsel for your specific situation. 1. Write a monitoring policy and get written acknowledgment. A clear policy that employees sign satisfies the notice duty in most states and creates the consent that federal law relies on. Put it in the handbook and at login. To make implementation easier, use WorkTime employee monitoring handbook and ready-to-use monitoring policy templates as a foundation for your own documentation. 2. Limit monitoring to company-owned equipment and work purposes. Personal devices and personal accounts carry far more risk. Monitoring company systems for a legitimate business reason is the safest ground. 3. Stay out of high-privacy zones. No cameras in restrooms, locker rooms, or changing areas. No reaching into private personal accounts. These are where reasonable-expectation-of-privacy claims start. 4. Get all-party consent before recording audio in strict states. A recording disclosure at the start of a call is enough. When a team spans several states, apply the strictest rule. 5. Never collect biometric data without written consent. In Illinois especially, a fingerprint time clock without a signed release is a lawsuit waiting to happen. 6. For remote teams, apply the law of the state where the employee physically works. That is the rule that generally governs, not the state where the company is based. There is a simpler way to cut most of this risk: collect less. Most of the legal exposure on this page comes from capturing content, whether that is intercepting messages, recording audio, or collecting biometrics. Non-invasive employee monitoring software avoids that category entirely. WorkTime measures productivity, active and idle time, attendance, and app usage without screenshots, keystroke content, screen recordings, or email and chat capture, which gives HR and IT the visibility they need while keeping sensitive data out of reach.

Turn activity into insights with 80+ WorkTime reports! Analyze performance clearly and safely, without collecting personal content.
Start free trial










