Employee Monitoring Law Planner
Laws

Employee monitoring laws California: what applies

What Employee Monitoring Law Planner sets out for a monitoring practice at a site in California: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.

Location
California
Laws placed
US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523); US Stored Communications Act (18 USC 2701 to 2713); California Penal Code sections 632 and 632.7 (recording confidential communications); California Consumer Privacy Act, as amended by the CPRA
Guidance placed
ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law
Read on
30 Sep 2026
Conditions
California Consumer Privacy Act, as amended by the CPRA is placed when you say the business meets the CCPA thresholds; "not sure" places it as a question.

What each practice needs here

20 practice classes
PracticeRepresentative stepNotice and policyRecording consentNot allowedPaperwork
AI emotion or sentiment detectionnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Keystroke loggingnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldstatutory requirementrisk assessment (when you say the business meets the CCPA thresholds)
Screenshots or screen recordingnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldstatutory requirementrisk assessment (when you say the business meets the CCPA thresholds)
Productivity or activity scoringnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldstatutory requirementrisk assessment (when you say the business meets the CCPA thresholds)
Idle-time trackingnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldstatutory requirementrisk assessment (when you say the business meets the CCPA thresholds)
Webcam or presence checksnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldstatutory requirementrisk assessment (when you say the business meets the CCPA thresholds)
Email and messaging reviewnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
DLP and email content filteringnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Website or email blockingnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Web and app usage loggingnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Biometric time clocknone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldstatutory requirementright to limit (when you say the business meets the CCPA thresholds)
Access control logsnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
CCTV (break, change or wash rooms)none heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
CCTV (work areas)none heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
GPS or vehicle telematicsnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Mobile device locationnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Call or speech analyticsnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)statutory requirementevery party consentsone party's consentnone heldnone held
Call recordingnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)statutory requirementevery party consentsone party's consentnone heldnone held
Social media monitoringnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held
Background checks as ongoing monitoringnone heldstatutory requirementnotice at collection (when you say the business meets the CCPA thresholds)none heldnone heldnone held

Every requirement held here

Findings a line here can raise

9 of 13

Named, not quoted

Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.

The provisions cited here

23 provisions
ILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not law

Where workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.

What a reviewer asks to see: Consultation record for each monitoring system, dated before introduction, with the representatives' views and the employer's response
Where monitoring plans usually fall short: Monitoring tool piloted without consulting the representatives
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
CCPA 1798.130(a)(5)(C)Notice at Collection

At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.

What a reviewer asks to see: Notice text displayed on forms, mobile app onboarding, point-of-sale, telephone scripts; Offline notice via signage or printed handout; Retention disclosures per category; Sale/share disclosure
Where monitoring plans usually fall short: Notice exists only in main privacy policy; Offline collection (call centers, in-store) lacks notice; Retention disclosed only as 'as long as necessary'
Source: California Consumer Privacy Act, as amended by the CPRA, read 30 Sep 2026
CCPA 1798.100General Duties of Businesses that Collect Personal Information

Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.

What a reviewer asks to see: Notice at collection text on web forms and physical points of collection; Privacy policy disclosures of categories and purposes; Data inventory mapping categories to purposes and retention periods; Information security program documentation; Retention schedule with criteria and disposal evidence
Where monitoring plans usually fall short: No notice at offline collection points; Purposes described vaguely (e.g. business operations); Retention periods absent or stated as indefinite; Security controls not mapped to PI categories
Source: California Consumer Privacy Act, as amended by the CPRA, read 30 Sep 2026
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not law

Before any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.

What a reviewer asks to see: Monitoring notice per system stating reasons, schedule, methods and data collected, issued before monitoring starts; Proportionality assessment showing less intrusive options considered
Where monitoring plans usually fall short: Notice states only that monitoring may occur, without schedule or methods; Screenshots captured continuously when sampling would serve the purpose
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.8Keep workers and representatives informed official guidance, not law

Workers and their representatives should be told about every data collection process, the rules governing it and their rights.

What a reviewer asks to see: Worker privacy notice covering each collection process, its rules and workers' rights; Record of the information given to worker representatives
Where monitoring plans usually fall short: Notice covers HR records but not monitoring systems
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not law

Covert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.

What a reviewer asks to see: Authorization record for each covert monitoring exercise with the suspicion and grounds, or the legal provision relied on; End date and review of each exercise
Where monitoring plans usually fall short: Covert monitoring used for general performance concerns
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
Cal. Penal Code 632(a)Obtain the consent of all parties before recording or eavesdropping on a confidential communication

A person may not, intentionally and without the consent of all parties to a confidential communication, use an electronic amplifying or recording device to eavesdrop on or record it, whether the parties are together in person or talking by telegraph, telephone or another device (radio excepted). Penalty: a fine of up to 2,500 dollars per violation, up to one year in county jail or state prison, or both; up to 10,000 dollars per violation after a prior conviction under ss. 631, 632, 632.5, 632.6, 632.7 or 636.

What a reviewer asks to see: Inventory of recording and listening tools (call recording, contact centre QA, meeting recorders, AI note-takers, body-worn or CCTV audio); Call-start announcement script or meeting banner telling every party the conversation is recorded, with configuration evidence it plays on every call; Consent or notice records for in-person recordings, such as interviews and disciplinary meetings
Where monitoring plans usually fall short: Recording announced to external callers but not on internal or outbound calls; AI note-taker joins meetings without all participants being told; Supervisor silent-listen (eavesdropping) with no notice to the parties
Source: California Penal Code sections 632 and 632.7 (recording confidential communications), read 30 Sep 2026
Cal. Penal Code 632.7(a)Obtain the consent of all parties before recording calls involving cellular or cordless phones

A person may not, without the consent of all parties, intercept or receive and intentionally record, or help to intercept or receive and record, a communication transmitted between two cellular radio telephones, a cellular and a landline telephone, two cordless telephones, a cordless and a landline telephone, or a cordless and a cellular telephone. Unlike s. 632, the communication need not be confidential. Penalty: a fine of up to 2,500 dollars, up to one year in county jail or state prison, or both; up to 10,000 dollars after a prior conviction under ss. 631, 632, 632.5, 632.6 or 636.

What a reviewer asks to see: List of mobile and softphone recording (company mobiles, field sales apps, contact centre calls to mobiles); Recording notice played at the start of every recorded call regardless of the device type, with configuration evidence
Where monitoring plans usually fall short: Recording notice omitted on calls to mobiles because the call is not considered confidential; Personal devices used for work calls recorded by a work app without notice to the other party
Source: California Penal Code sections 632 and 632.7 (recording confidential communications), read 30 Sep 2026
ECPA 2511(1)(a)Do not intercept wire, oral or electronic communications

Unless the chapter specifically provides otherwise, no person may intentionally intercept, try to intercept, or procure anyone else to intercept or try to intercept, any wire, oral or electronic communication. For an employer this covers real-time capture of calls, email or messages in transit, keystroke or screen tools that acquire message contents as they are sent, and listening devices, unless an exception (provider, business extension, consent) applies.

What a reviewer asks to see: Register of every tool that captures communication contents in real time (call recording, voice analytics, email or chat journaling, DLP inspection, keyloggers), with the exception relied on for each; Legal sign-off per tool recording why the interception is lawful (party consent, provider exception or business-extension use)
Where monitoring plans usually fall short: Monitoring software deployed with no documented legal basis; Personal accounts or personal calls captured by the same tools as business traffic
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ECPA 2511(2)(d)One-party consent: be a party or have a party's prior consent, and never for a criminal or tortious purpose

A person not acting under color of law may intercept a wire, oral or electronic communication where that person is a party to it or one of the parties has given prior consent, unless the interception is for the purpose of committing a criminal or tortious act against the Constitution or the laws of the United States or any State. Employers commonly obtain the employee's prior consent through a signed monitoring policy; consent must cover the monitoring actually carried out, and state all-party consent laws can still apply.

What a reviewer asks to see: Signed or electronically accepted monitoring consent from each employee, describing the communications and methods monitored; Mapping of the consent wording to each monitoring tool in the register; Check of state law for locations where all-party consent is required
Where monitoring plans usually fall short: Consent wording covers email but the tool also captures calls or personal messaging; Consent relied on for calls with outside parties in all-party consent states
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ECPA 2510(5)(a)Business-extension exclusion: provider-furnished equipment used in the ordinary course of business

The prohibition turns on the use of an electronic, mechanical or other device. Telephone or telegraph equipment or facilities, or their components, furnished to the subscriber or user by a provider in the ordinary course of its business and used by the subscriber or user in the ordinary course of its business (or furnished by the subscriber or user to connect to the service and so used), and equipment used by a provider in the ordinary course of its business, are not such a device. An employer's use of its phone system to monitor business calls can fall outside the prohibition where the monitoring is in the ordinary course of business; hearing aids are also excluded.

What a reviewer asks to see: Description of the phone system and the monitoring features used, showing they are part of the service equipment; Business justification for call monitoring (quality, training, compliance) and the rule for ending monitoring once a call is personal
Where monitoring plans usually fall short: Monitoring continues after a call is identified as personal; Add-on recording hardware not furnished as part of the service relied on as business extension
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
CCPA 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information

Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.

What a reviewer asks to see: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation; Use restriction enforcement controls
Where monitoring plans usually fall short: No separate sensitive PI inventory; Limit mechanism not offered when uses go beyond permitted purposes; Permitted purpose claimed without documentation
Source: California Consumer Privacy Act, as amended by the CPRA, read 30 Sep 2026
CCPA 1798.100(c)Data Minimisation, Necessity and Proportionality

A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.

What a reviewer asks to see: Record of processing showing, per data element, the purpose it was collected for; Documented necessity and proportionality assessment for each collection purpose; Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds; Compatibility analysis for any secondary use, referencing the context of collection; Approval record showing a new use was assessed before it went live
Where monitoring plans usually fall short: A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose; Necessity assessed once at launch and never revisited as the product changed; Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner; Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected; Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
Source: California Consumer Privacy Act, as amended by the CPRA, read 30 Sep 2026
CCPA 1798.185(a)(15)Risk Assessments for High-Risk Processing

Businesses whose processing of PI presents significant risk to consumers privacy or security must submit risk assessments to the CPPA on a regular basis. Risk assessments must weigh the benefits to the business, consumer, other stakeholders, and the public against the potential risks to consumer rights.

What a reviewer asks to see: Risk assessment template covering benefits, risks, mitigations, processing purposes, categories of PI, retention, automated decisionmaking; Submitted assessment to CPPA per cadence; Risk assessment register
Where monitoring plans usually fall short: Risk assessments not conducted for high-risk activities (sensitive PI, training AI, profiling, minors); No standardised methodology; CPPA submission not scheduled
Source: California Consumer Privacy Act, as amended by the CPRA, read 30 Sep 2026
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not law

Monitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.

What a reviewer asks to see: Register of continuous monitoring (CCTV, telematics, always-on tracking) with the health, safety or property ground for each
Where monitoring plans usually fall short: Always-on webcam or activity tracking for remote staff justified by productivity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not law

Output from electronic surveillance should never be the sole input when a worker's performance is judged.

What a reviewer asks to see: Appraisal procedure listing the evidence sources considered besides monitoring data; Sample appraisals showing other inputs (manager review, outputs, feedback)
Where monitoring plans usually fall short: Productivity scores from activity tracking used as the whole appraisal
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not law

Keep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.

What a reviewer asks to see: Retention schedule for worker data including monitoring records, citing purpose, legal requirement or proceedings; Deletion logs
Where monitoring plans usually fall short: Monitoring recordings kept indefinitely; Unsuccessful applicants' data kept without their agreement
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
SCA 2701(a)Do not access a communication service facility without authorization to reach stored communications

Unless subsection (c) applies, no person may intentionally access without authorization a facility through which an electronic communication service is provided, or intentionally exceed an authorization to access it, and thereby obtain, alter or prevent authorized access to a wire or electronic communication while it is in electronic storage in that system. Penalties (2701(b)): for commercial advantage, malicious destruction, private gain or in furtherance of a criminal or tortious act, up to 5 years (10 for a repeat); otherwise up to 1 year (5 for a repeat after a prior conviction). For an employer this reaches logging into an employee's personal email, social media or messaging account, for example with a saved password on a work device, without the employee's authorization.

What a reviewer asks to see: Investigation procedure prohibiting access to employees' personal accounts (webmail, social media, messaging) without their authorization; Record of the authority for each access to stored communications made in an investigation (employer-provided system, user consent); Guidance to IT on handling personal account sessions or saved credentials found on work devices
Where monitoring plans usually fall short: Manager reads an employee's personal webmail left logged in on a work laptop; Former employee's personal account accessed with a remembered password after departure
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
SCA 2701(c)(1)Authorization by the service provider: access to the employer's own communication service

Subsection (a) does not apply to conduct authorized by the person or entity providing the wire or electronic communications service. An employer that provides its own email or messaging service to employees can authorize access to communications stored on that service; the authorization does not extend to services the employer does not provide, such as an employee's personal webmail.

What a reviewer asks to see: List of communication services the organization itself provides (email, chat, voicemail) and who may authorize access to stored content; Access authorization records for reviews of stored communications on those services
Where monitoring plans usually fall short: Provider authorization relied on for a third-party personal account; No record of who authorized a mailbox search
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
SCA 2701(c)(2)Authorization by the user for that user's own communications

Subsection (a) does not apply to conduct authorized by a user of the service with respect to a communication of, or intended for, that user. Access to an employee's stored messages with that employee's authorization is outside the offense; access to a third party's messages needs that user's authorization or another exception.

What a reviewer asks to see: Written authorization from the account user for access to the user's stored communications, stating the scope; Check that the person authorizing is the user of the communications accessed
Where monitoring plans usually fall short: Authorization obtained from a coworker to read another employee's private messages; Authorization obtained by pressure or as a condition of employment without legal review
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law

5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.

What a reviewer asks to see: Register of worker data processing activities, each with its employment-related reason and legal basis
Where monitoring plans usually fall short: Data collected for reasons unrelated to the job, such as off-duty social media activity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not law

Employers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.

What a reviewer asks to see: Data inventory confirming these categories are not collected, or the documented exception and legal basis where they are
Where monitoring plans usually fall short: Criminal record checks for every role regardless of relevance
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.6No data on union membership or activities unless required official guidance, not law

Employers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.

What a reviewer asks to see: Review of HR and monitoring systems confirming union data are not collected except under a stated legal or agreement basis
Where monitoring plans usually fall short: Monitoring tools flag union-related email or chat
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026

See the specimen plan run Plan your own list