HomePoliciesInformation securityEmployee Data Privacy Policy

Policy  required document  Information security

Employee Data Privacy Policy

An employee data privacy policy tells staff and applicants what personal information the company collects about them, why, who it is shared with, how long it is kept, and what rights they have over it. In the United States this was mostly a courtesy until California's consumer privacy law reached the workforce.

The exemption for employee and applicant data expired on January 1, 2023, and the Attorney General announced in July 2023 that covered businesses must comply with the CCPA's requirements for employee data, including providing notice of privacy practices and fulfilling requests to access, delete and opt out of the sale or sharing of personal information, and sent inquiry letters to employers about their compliance.

A business meeting the CCPA thresholds now owes its own employees a notice at collection and a process for their requests, the same as its customers.

The policy is also where several older duties are collected in one place. Medical information obtained through the ADA, the FMLA and drug testing must be kept in separate confidential files (29 CFR 1630.14). Background reports have their own use and disposal rules under the FCRA.

Every state breach-notification law treats employee records, with their Social Security numbers and bank details, as covered data, so the same breach plan that protects customers has to reach the HR system. New York's monitoring notice and the electronic communications policy tell employees what the company looks at; this policy tells them what it keeps.

A short, accurate document that names the categories of data, the purposes, the retention periods and the request route is what the CCPA asks for, and it is what an employee asks for when a dispute starts.

Also called: Employee privacy notice, Workforce data privacy policy, HR data protection policy, Notice at collection for employees
AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedEmployee Data Privacyby name, on record
The Proof is Yourswith AllyMatter
Sign It the Modern WayEvery Employee Data Privacy, acknowledged by name
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every name on record
Re-collected when the document changes, survives departure
03
Produce the record on request
From $29/mo, 20 editors, unlimited staff (published)

Obligation ledger

Who requires it, and what each one says.

SourceApplies whenWhat it requiresStatus
California Consumer Privacy Act, notice at collection and consumer rights, applied to employees
Cal. Civ. Code 1798.100 and following; former 1798.145(m) exemption expired January 1, 2023
Businesses meeting CCPA thresholds, for employees, applicants and contractors in CaliforniaNotice at or before collection of the categories of personal information and the purposes; a privacy policy; processes to honor requests to know, delete, correct and opt out of sale or sharing; no retaliation for exercising rights. The Attorney General's July 14, 2023 release confirmed the duties apply to employee data and announced inquiry letters to employers. Legally required.Mandatory
ADA regulations, confidentiality of medical information
29 CFR 1630.14
Employers with 15 or more employeesMedical information obtained through examinations and inquiries must be collected and maintained on separate forms and in separate medical files and treated as a confidential medical record, with narrow exceptions for supervisors, first aid and government investigators. Legally required.Mandatory
Fair Credit Reporting Act, disposal of consumer information
15 U.S.C. 1681w and 16 CFR Part 682
Any employer that obtains consumer reportsTake reasonable measures to protect against unauthorized access to consumer report information in connection with its disposal. Legally required.Mandatory
New York Civil Rights Law, electronic monitoring notice
NY Civ. Rights Law 52-c
New York employers that monitorWritten notice and acknowledgment at hiring of electronic monitoring; the collection side of the same disclosure. Covered on the electronic communications policy page.Mandatory

Required sections

  • The categories of personal information collected about applicants, employees and contractors, with examples, and the sources
  • The purposes for each category, in the business-purpose terms the CCPA uses
  • Who the information is shared with: payroll, benefits, insurers, background screeners, government agencies, and whether any of it is sold or shared for advertising (almost always no, and the policy should say so)
  • Retention periods by category, tied to the legal minimums (payroll three years, I-9 three years or one year after separation, medical files for the ADA period, and the state pay-record periods)
  • How to make a request to know, delete or correct, who handles it, and the timeline, for employers under the CCPA
  • Medical information: the separate confidential file and who may see it
  • Background report information: use and disposal
  • Monitoring: a cross-reference to the electronic communications policy and the state notices
  • Breach response: that employee data is within the incident response plan and how employees will be told
  • No retaliation for exercising privacy rights

What the examiner asks for

Written planThe employee privacy notice at collection and the fuller policy, each with effective dates; the data inventory behind them. Privacy counsel, HR consultants, privacy program vendors
AttestationEvidence the notice was provided at or before collection, at application and at hiring; acknowledgment of the policy. Applicant tracking systems, HRIS onboarding
Operational recordsThe request log with dates and responses, the data inventory and retention schedule, access lists for medical and background files, and disposal records. HR, privacy operations, IT
Technical controlsSegregated storage and access control for medical and background data, retention enforcement in the HRIS, and the ability to locate and export one person's records to answer a request. HRIS vendors, document management, privacy request platforms

What changed

Change log.

2023-07-14California Attorney General announced an investigative sweep of employers' CCPA compliance for employee data and confirmed the duties took effect January 1, 2023.
2023-01-01CCPA exemption for employee and applicant personal information expired; full obligations applied to workforce data from this date.

Frameworks

Where this document is required.

Need a hand implementing it?

Find a Consultant for Employee Data Privacy Policy

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Manage This Document in AllyMatter

Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Questions

What people ask.

We are a 40-person company. Does the CCPA reach us?

Only if you meet a threshold: revenue over the adjusted figure, personal information of 100,000 or more consumers or households, or half your revenue from selling or sharing data. Most 40-person companies do not. The ADA medical-file rule, the FCRA disposal rule and the breach laws apply to you regardless, and a short notice costs little.

What is a notice at collection, in practice?

A paragraph on the application form and in the onboarding packet listing the categories of information collected, the purposes, whether any is sold or shared, how long it is kept, and a link to the full policy. It has to be given before or at the moment the data is collected, which is why it lives on the form and not only in the handbook.

An employee asked for a copy of everything we hold on them. Do we have to comply?

Under the CCPA, if you are covered, yes, within the statutory period, with limited exceptions. Several other states give employees a right to see their personnel file regardless of the CCPA. The policy names who handles the request and how, so it does not land on a manager unprepared.

Where do medical certifications go?

In a separate confidential medical file, not the personnel file, with access limited to the people the ADA regulation allows. The same rule reaches FMLA certifications, drug test results and accommodation records. Storing them in the general file is a violation on its own, before any breach.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.