Employee monitoring laws California: what applies
What Employee Monitoring Law Planner sets out for a monitoring practice at a site in California: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.
- Location
- California
- Laws placed
- US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523); US Stored Communications Act (18 USC 2701 to 2713); California Penal Code sections 632 and 632.7 (recording confidential communications); California Consumer Privacy Act, as amended by the CPRA
- Guidance placed
- ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law
- Read on
- 30 Sep 2026
- Conditions
- California Consumer Privacy Act, as amended by the CPRA is placed when you say the business meets the CCPA thresholds; "not sure" places it as a question.
What each practice needs here
20 practice classes| Practice | Representative step | Notice and policy | Recording consent | Not allowed | Paperwork |
|---|---|---|---|---|---|
| AI emotion or sentiment detection | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Keystroke logging | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | statutory requirementrisk assessment (when you say the business meets the CCPA thresholds) |
| Screenshots or screen recording | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | statutory requirementrisk assessment (when you say the business meets the CCPA thresholds) |
| Productivity or activity scoring | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | statutory requirementrisk assessment (when you say the business meets the CCPA thresholds) |
| Idle-time tracking | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | statutory requirementrisk assessment (when you say the business meets the CCPA thresholds) |
| Webcam or presence checks | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | statutory requirementrisk assessment (when you say the business meets the CCPA thresholds) |
| Email and messaging review | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| DLP and email content filtering | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Website or email blocking | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Web and app usage logging | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Biometric time clock | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | statutory requirementright to limit (when you say the business meets the CCPA thresholds) |
| Access control logs | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| CCTV (break, change or wash rooms) | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| CCTV (work areas) | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| GPS or vehicle telematics | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Mobile device location | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Call or speech analytics | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | statutory requirementevery party consentsone party's consent | none held | none held |
| Call recording | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | statutory requirementevery party consentsone party's consent | none held | none held |
| Social media monitoring | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
| Background checks as ongoing monitoring | none held | statutory requirementnotice at collection (when you say the business meets the CCPA thresholds) | none held | none held | none held |
Every requirement held here
- Noticestatutory requirementAt or before collection, tell staff the categories collected, the purposes, and how long each is kept. (when you say the business meets the CCPA thresholds) CCPA 1798.130(a)(5)(C)CCPA 1798.100
- Recording consentstatutory requirementThe consent of every party before recording a confidential communication, and before recording any call involving a cellular or cordless phone. Cal. Penal Code 632(a)Cal. Penal Code 632.7(a) California Penal Code 631, named, not quoted
- Recording consentstatutory requirementNo interception of calls or messages unless an exception applies: a party's prior consent (never for a criminal or tortious purpose), or equipment used in the ordinary course of business. Both are conditions to show, not a default. ECPA 2511(1)(a)ECPA 2511(2)(d)ECPA 2510(5)(a)
- Biometric datastatutory requirementBiometric data is sensitive personal information; staff can limit its use. (when you say the business meets the CCPA thresholds) CCPA 1798.121
- Personal devicesstatutory requirementAn employer can authorise access to messages on a service it provides; that does not reach an employee's personal webmail or accounts, which need the user's authorisation. (if personal devices are monitored) SCA 2701(a)SCA 2701(c)(1)SCA 2701(c)(2)
- Assessmentstatutory requirementCollection proportionate to its purpose; a risk assessment where processing presents significant risk. (when you say the business meets the CCPA thresholds) CCPA 1798.100(c)CCPA 1798.185(a)(15)
- Assessmentofficial guidance, not lawContinuous monitoring only for health and safety or the protection of property; monitoring output never the sole basis of a performance judgement. ILO code para 6.14(3)ILO code para 5.6 official guidance, not law
- Retentionstatutory requirementRetention periods disclosed and no longer than reasonably necessary. (when you say the business meets the CCPA thresholds) CCPA 1798.100
- Retentionofficial guidance, not lawKept only as long as the purpose justifies. ILO code para 8.5 official guidance, not law
Findings a line here can raise
9 of 13- 1 Representative step before start not recorded
- 2 Notice not recorded, or its period not met
- 4 Covert monitoring
- 7 Call recording consent
- 8 Biometric data
- 10 Continuous, keystroke or screenshot monitoring with no assessment recorded
- 11 Retention not set, or above the period you set
- 12 Personal devices monitored
- 13 Lawful basis not recorded for an EU or UK line
Named, not quoted
- National Labor Relations Act section 7: employees' rights to organise and act together (the United States; named, not quoted)
- California Penal Code 631: wiretapping (California; named, not quoted)
Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.
The provisions cited here
23 provisionsILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not lawWhere workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.
CCPA 1798.130(a)(5)(C)Notice at Collection At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.
CCPA 1798.100General Duties of Businesses that Collect Personal Information Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not lawBefore any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.
ILO code para 5.8Keep workers and representatives informed official guidance, not lawWorkers and their representatives should be told about every data collection process, the rules governing it and their rights.
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not lawCovert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.
Cal. Penal Code 632(a)Obtain the consent of all parties before recording or eavesdropping on a confidential communication A person may not, intentionally and without the consent of all parties to a confidential communication, use an electronic amplifying or recording device to eavesdrop on or record it, whether the parties are together in person or talking by telegraph, telephone or another device (radio excepted). Penalty: a fine of up to 2,500 dollars per violation, up to one year in county jail or state prison, or both; up to 10,000 dollars per violation after a prior conviction under ss. 631, 632, 632.5, 632.6, 632.7 or 636.
Cal. Penal Code 632.7(a)Obtain the consent of all parties before recording calls involving cellular or cordless phones A person may not, without the consent of all parties, intercept or receive and intentionally record, or help to intercept or receive and record, a communication transmitted between two cellular radio telephones, a cellular and a landline telephone, two cordless telephones, a cordless and a landline telephone, or a cordless and a cellular telephone. Unlike s. 632, the communication need not be confidential. Penalty: a fine of up to 2,500 dollars, up to one year in county jail or state prison, or both; up to 10,000 dollars after a prior conviction under ss. 631, 632, 632.5, 632.6 or 636.
ECPA 2511(1)(a)Do not intercept wire, oral or electronic communications Unless the chapter specifically provides otherwise, no person may intentionally intercept, try to intercept, or procure anyone else to intercept or try to intercept, any wire, oral or electronic communication. For an employer this covers real-time capture of calls, email or messages in transit, keystroke or screen tools that acquire message contents as they are sent, and listening devices, unless an exception (provider, business extension, consent) applies.
ECPA 2511(2)(d)One-party consent: be a party or have a party's prior consent, and never for a criminal or tortious purpose A person not acting under color of law may intercept a wire, oral or electronic communication where that person is a party to it or one of the parties has given prior consent, unless the interception is for the purpose of committing a criminal or tortious act against the Constitution or the laws of the United States or any State. Employers commonly obtain the employee's prior consent through a signed monitoring policy; consent must cover the monitoring actually carried out, and state all-party consent laws can still apply.
ECPA 2510(5)(a)Business-extension exclusion: provider-furnished equipment used in the ordinary course of business The prohibition turns on the use of an electronic, mechanical or other device. Telephone or telegraph equipment or facilities, or their components, furnished to the subscriber or user by a provider in the ordinary course of its business and used by the subscriber or user in the ordinary course of its business (or furnished by the subscriber or user to connect to the service and so used), and equipment used by a provider in the ordinary course of its business, are not such a device. An employer's use of its phone system to monitor business calls can fall outside the prohibition where the monitoring is in the ordinary course of business; hearing aids are also excluded.
CCPA 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.
CCPA 1798.100(c)Data Minimisation, Necessity and Proportionality A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.
CCPA 1798.185(a)(15)Risk Assessments for High-Risk Processing Businesses whose processing of PI presents significant risk to consumers privacy or security must submit risk assessments to the CPPA on a regular basis. Risk assessments must weigh the benefits to the business, consumer, other stakeholders, and the public against the potential risks to consumer rights.
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not lawMonitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not lawOutput from electronic surveillance should never be the sole input when a worker's performance is judged.
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not lawKeep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.
SCA 2701(a)Do not access a communication service facility without authorization to reach stored communications Unless subsection (c) applies, no person may intentionally access without authorization a facility through which an electronic communication service is provided, or intentionally exceed an authorization to access it, and thereby obtain, alter or prevent authorized access to a wire or electronic communication while it is in electronic storage in that system. Penalties (2701(b)): for commercial advantage, malicious destruction, private gain or in furtherance of a criminal or tortious act, up to 5 years (10 for a repeat); otherwise up to 1 year (5 for a repeat after a prior conviction). For an employer this reaches logging into an employee's personal email, social media or messaging account, for example with a saved password on a work device, without the employee's authorization.
SCA 2701(c)(1)Authorization by the service provider: access to the employer's own communication service Subsection (a) does not apply to conduct authorized by the person or entity providing the wire or electronic communications service. An employer that provides its own email or messaging service to employees can authorize access to communications stored on that service; the authorization does not extend to services the employer does not provide, such as an employee's personal webmail.
SCA 2701(c)(2)Authorization by the user for that user's own communications Subsection (a) does not apply to conduct authorized by a user of the service with respect to a communication of, or intended for, that user. Access to an employee's stored messages with that employee's authorization is outside the offense; access to a third party's messages needs that user's authorization or another exception.
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not lawEmployers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.
ILO code para 6.6No data on union membership or activities unless required official guidance, not lawEmployers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.