Policy required document Information security
Employee Data Privacy Policy
An employee data privacy policy tells staff and applicants what personal information the company collects about them, why, who it is shared with, how long it is kept, and what rights they have over it. In the United States this was mostly a courtesy until California's consumer privacy law reached the workforce.
The exemption for employee and applicant data expired on January 1, 2023, and the Attorney General announced in July 2023 that covered businesses must comply with the CCPA's requirements for employee data, including providing notice of privacy practices and fulfilling requests to access, delete and opt out of the sale or sharing of personal information, and sent inquiry letters to employers about their compliance.
A business meeting the CCPA thresholds now owes its own employees a notice at collection and a process for their requests, the same as its customers.
The policy is also where several older duties are collected in one place. Medical information obtained through the ADA, the FMLA and drug testing must be kept in separate confidential files (29 CFR 1630.14). Background reports have their own use and disposal rules under the FCRA.
Every state breach-notification law treats employee records, with their Social Security numbers and bank details, as covered data, so the same breach plan that protects customers has to reach the HR system. New York's monitoring notice and the electronic communications policy tell employees what the company looks at; this policy tells them what it keeps.
A short, accurate document that names the categories of data, the purposes, the retention periods and the request route is what the CCPA asks for, and it is what an employee asks for when a dispute starts.
Obligation ledger
Who requires it, and what each one says.
| Source | Applies when | What it requires | Status |
|---|---|---|---|
| California Consumer Privacy Act, notice at collection and consumer rights, applied to employees Cal. Civ. Code 1798.100 and following; former 1798.145(m) exemption expired January 1, 2023 | Businesses meeting CCPA thresholds, for employees, applicants and contractors in California | Notice at or before collection of the categories of personal information and the purposes; a privacy policy; processes to honor requests to know, delete, correct and opt out of sale or sharing; no retaliation for exercising rights. The Attorney General's July 14, 2023 release confirmed the duties apply to employee data and announced inquiry letters to employers. Legally required. | Mandatory |
| ADA regulations, confidentiality of medical information 29 CFR 1630.14 | Employers with 15 or more employees | Medical information obtained through examinations and inquiries must be collected and maintained on separate forms and in separate medical files and treated as a confidential medical record, with narrow exceptions for supervisors, first aid and government investigators. Legally required. | Mandatory |
| Fair Credit Reporting Act, disposal of consumer information 15 U.S.C. 1681w and 16 CFR Part 682 | Any employer that obtains consumer reports | Take reasonable measures to protect against unauthorized access to consumer report information in connection with its disposal. Legally required. | Mandatory |
| New York Civil Rights Law, electronic monitoring notice NY Civ. Rights Law 52-c | New York employers that monitor | Written notice and acknowledgment at hiring of electronic monitoring; the collection side of the same disclosure. Covered on the electronic communications policy page. | Mandatory |
Required sections
- The categories of personal information collected about applicants, employees and contractors, with examples, and the sources
- The purposes for each category, in the business-purpose terms the CCPA uses
- Who the information is shared with: payroll, benefits, insurers, background screeners, government agencies, and whether any of it is sold or shared for advertising (almost always no, and the policy should say so)
- Retention periods by category, tied to the legal minimums (payroll three years, I-9 three years or one year after separation, medical files for the ADA period, and the state pay-record periods)
- How to make a request to know, delete or correct, who handles it, and the timeline, for employers under the CCPA
- Medical information: the separate confidential file and who may see it
- Background report information: use and disposal
- Monitoring: a cross-reference to the electronic communications policy and the state notices
- Breach response: that employee data is within the incident response plan and how employees will be told
- No retaliation for exercising privacy rights
What the examiner asks for
What changed
Change log.
Frameworks
Where this document is required.
Need a hand implementing it?
Find a Consultant for Employee Data Privacy Policy
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Manage This Document in AllyMatter
Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.
Questions
What people ask.
We are a 40-person company. Does the CCPA reach us?
Only if you meet a threshold: revenue over the adjusted figure, personal information of 100,000 or more consumers or households, or half your revenue from selling or sharing data. Most 40-person companies do not. The ADA medical-file rule, the FCRA disposal rule and the breach laws apply to you regardless, and a short notice costs little.
What is a notice at collection, in practice?
A paragraph on the application form and in the onboarding packet listing the categories of information collected, the purposes, whether any is sold or shared, how long it is kept, and a link to the full policy. It has to be given before or at the moment the data is collected, which is why it lives on the form and not only in the handbook.
An employee asked for a copy of everything we hold on them. Do we have to comply?
Under the CCPA, if you are covered, yes, within the statutory period, with limited exceptions. Several other states give employees a right to see their personnel file regardless of the CCPA. The policy names who handles the request and how, so it does not land on a manager unprepared.
Where do medical certifications go?
In a separate confidential medical file, not the personnel file, with access limited to the people the ADA regulation allows. The same rule reaches FMLA certifications, drug test results and accommodation records. Storing them in the general file is a violation on its own, before any breach.
Sources
California Attorney General, press release on employer CCPA compliance, July 14, 2023Cal. Civ. Code 1798.100, CCPA general duties and notice at collection (California Legislative Information)29 CFR 1630.14, ADA medical examinations and inquiries, confidentiality (Cornell LII)15 U.S.C. 1681w, FCRA disposal of records (Cornell LII)NY Civil Rights Law 52-c, electronic monitoring notice (NY Senate)