Security is our number one priority. ContactClient loginCyberWall Shield
Guide

Employee monitoring laws in the U.S.: notice requirements by state

What federal law allows, which states require written notice, and a practical checklist for rolling out monitoring the right way.

This is not legal advice. It is a general summary written by an IT security company, not a law firm. Laws change, they apply differently depending on where your employees work and how you monitor, and local rules or union agreements may add requirements. Before you start monitoring, talk to your attorney about your specific situation.

The short version

In the United States, employers can generally monitor activity on company-owned computers and accounts used for work. No single federal law requires a monitoring notice. A small but growing number of states do, and a few add specific rules about acknowledgment, posting and where monitoring may happen. Giving clear written notice to every employee, and getting it acknowledged, satisfies the core of most of these laws and is good practice everywhere.

Federal law: the ECPA

The Electronic Communications Privacy Act of 1986 is the main federal law on electronic monitoring. It has two parts that matter to employers.

  • The Wiretap Act (18 U.S.C. § 2511) makes it unlawful to intercept wire, oral or electronic communications, with exceptions. The consent exception (§ 2511(2)(d)) permits interception where one party to the communication has consented. The ordinary-course-of-business exception (built into the definition of an intercepting device in § 2510(5)(a)) covers equipment provided to employees and used in the ordinary course of business.
  • The Stored Communications Act (18 U.S.C. § 2701) protects stored communications, but § 2701(c)(1) exempts conduct authorized by the provider of the communications service. Employers that provide the email system often rely on this exception.

In practice, a written policy that employees acknowledge is the clearest way to show consent and a legitimate business purpose.

Federal labor law also applies. The National Labor Relations Act protects employees' rights to discuss pay and working conditions, whether or not they're in a union. Monitoring should never be used to watch or discourage that kind of activity. Guidance from the National Labor Relations Board's General Counsel on this topic has changed in recent years, including memos issued in 2022 and rescinded in 2025, so ask your attorney about the current position.

State laws at a glance

The table below covers the states with explicit electronic-monitoring notice statutes for private employers, plus related state laws that commonly come up. Other states have general privacy, wiretap or biometric laws that may also apply.

StateLawWhat it requiresCitation
FederalElectronic Communications Privacy Act (Wiretap Act and Stored Communications Act)Generally prohibits intercepting communications, with exceptions employers commonly rely on: consent of a party, use in the ordinary course of business on employer-provided equipment, and access by the provider of the communications service. Does not by itself require a posted notice, but consent is easiest to show with a written, acknowledged policy.18 U.S.C. §§ 2510(5)(a), 2511(2)(d), 2701(c)(1)
New YorkCivil Rights Law § 52-c (effective May 7, 2022)Private employers that monitor phone, email or internet access or usage must give prior written notice upon hiring, get the employee's written or electronic acknowledgment, and post the notice in a conspicuous place. Penalties of $500, $1,000 and $3,000 for first, second and later violations.N.Y. Civ. Rights Law § 52-c
ConnecticutGen. Stat. § 31-48d, as amended by Public Act 26-73 (effective October 1, 2026)Employers must give prior written notice of the types of electronic monitoring, and under the 2026 amendments the specific locations on the premises where it may occur. Notice must be posted conspicuously. Employees hired after October 1, 2026 must get a plain-language written statement of prohibited activities that may be monitored without prior notice. Penalties of $500, $1,000 and $3,000.Conn. Gen. Stat. § 31-48d; P.A. 26-73
Delaware19 Del. C. § 705Before monitoring phone, email or internet access or usage, employers must either show an electronic notice at least once each day the employee uses employer email or internet, or give a one-time written or electronic notice that the employee acknowledges. $100 civil penalty per violation.Del. Code tit. 19, § 705
Maine26 M.R.S. § 620-A (P.L. 2025, ch. 524, L.D. 61; effective July 14, 2026)Employers must notify employees in writing before electronic monitoring begins, give current employees an annual written notice, and tell job applicants during the interview process. Limits audiovisual monitoring of employees' homes, personal vehicles and personal property, and lets employees decline data-collecting apps on personal devices. $100 to $500 per violation.26 M.R.S. § 620-A
CaliforniaCalifornia Consumer Privacy Act, as amended by the CPRASince January 1, 2023, covered businesses must treat employee and applicant data like consumer data: a notice at collection describing categories and purposes, a privacy policy, and rights to access, correct and delete. New CPPA rules on automated decisionmaking technology used for significant employment decisions take effect January 1, 2027.Cal. Civ. Code § 1798.100 et seq.; Cal. Code Regs. tit. 11, § 7001 et seq.
IllinoisBiometric Information Privacy ActRequires written notice and a written release before collecting biometric identifiers such as fingerprints or face geometry, plus a published retention policy. Relevant to biometric time clocks and some monitoring tools. CyberWall Insights collects no biometric data.740 ILCS 14
TexasNo general computer-monitoring notice statute for private employersWe found no Texas statute that requires private employers to give notice of computer activity monitoring. The Texas Data Privacy and Security Act excludes individuals acting in an employment context. Texas does regulate capture of biometric identifiers, which Insights does not collect.Tex. Bus. & Com. Code ch. 541 (TDPSA), § 503.001 (biometrics)

Other things to watch

  • State wiretap laws. Some states require consent of all parties before a phone call or conversation is recorded. Insights does not record calls or audio, but other tools you use might.
  • Biometrics. Illinois, Texas and Washington have biometric privacy laws. Fingerprint time clocks and face-scanning tools fall under them. Insights collects no biometric data.
  • Personal devices. Monitoring personal phones or computers raises more legal and practical issues. Maine now lets employees decline data-collecting apps on personal devices. Insights runs only on company Windows computers.
  • Sensitive information. Data that reveals health, religion, union activity or similar categories can create risk in employment decisions. Collecting less reduces that risk.
  • Pending bills. Several states have considered broader workplace surveillance bills. Check for changes at least once a year.

Practical checklist

  • List the states where your employees actually work, including remote staff.
  • Decide what you will monitor and why, in writing.
  • Write a monitoring policy. Our policy template is a starting point.
  • Have your attorney review the policy against the states on your list.
  • Give every affected employee the policy before monitoring begins, and at hire for new employees.
  • Collect a signed or electronic acknowledgment and keep it on file.
  • Post the notice where employees can see it, if your states require posting (New York and Connecticut do).
  • In Delaware, either collect a one-time acknowledgment or show a daily electronic notice.
  • In Maine, add the annual notice to your calendar and tell applicants during interviews.
  • In Connecticut, update notices for the October 1, 2026 changes, including the new-hire statement.
  • In California, if the CCPA applies to you, update your employee notice at collection and privacy policy.
  • Keep monitoring limited to company devices and business purposes.
  • Review the policy and the law every year.

How CyberWall Insights helps

No software can make you compliant on its own. Insights is designed to make the notice side easier and to keep what you collect small.

  • Employee notice. The Insights agent can show employees a monitoring notice on their computer, which supports your written notice and acknowledgment process.
  • No keystroke logging. Insights records that input happened, never which keys were pressed. No passwords, messages or typed personal details are collected.
  • Site names only. Websites are recorded by name, such as youtube.com. Never full URLs or page content.
  • No content. Insights never reads email, documents or chat.
  • Screenshots off by default. The screenshots add-on is off for every company unless you ask us to turn it on. Screenshots are never taken while the screen is locked and are deleted automatically after 7, 14 or 30 days.
  • Company Windows computers only. The agent is deployed through Microsoft Intune to computers you manage.
  • Security first. MFA on every login, each company's data isolated, and we never sell data.

Read more on our privacy by design page.

Sources

  1. 18 U.S.C. § 2510 (definitions, including the ordinary-course exception)
  2. 18 U.S.C. § 2511 (interception and the consent exception)
  3. 18 U.S.C. § 2701 (Stored Communications Act)
  4. New York Civil Rights Law § 52-c, statute text
  5. Hunton Andrews Kurth, New York State requires private employers to notify employees of electronic monitoring
  6. Connecticut General Assembly, Public Act 26-73 (Substitute S.B. 472)
  7. Workplace Privacy Report, Deadline imminent for Connecticut's expanded electronic monitoring law
  8. Wiggin and Dana, New Connecticut law targets employee monitoring and surveillance practices
  9. Delaware Code, Title 19, Chapter 7, § 705
  10. Verrill, What Maine's new employer surveillance law means for Maine employers
  11. Fisher Phillips, Maine sets new restrictions on workplace monitoring and surveillance
  12. Workplace Privacy Report, California Consumer Privacy Act FAQs for employment information
  13. Littler, California's long-awaited final regulations on automated decisionmaking
  14. Illinois Biometric Information Privacy Act, 740 ILCS 14
  15. Fisher Phillips, FAQs: Texas passes consumer privacy legislation
  16. Texas Business and Commerce Code, Chapter 503 (biometric identifiers)
  17. Ogletree, Rescinded guidance: unpacking NLRB Acting General Counsel Cowen's policy overhaul

Summaries reflect our reading of these sources as of the review date above. Always confirm current law with your attorney.

See your team's day clearly in under an hour.

Start a 14-day free trial with full access. Deploy through Microsoft Intune, set your goals, and your first reports fill in the same day.