Monitoring software can help California businesses protect customer information, investigate misconduct, and manage remote work. But access to a company laptop does not give an employer unlimited permission to record conversations, track locations, or collect personal information. Employee monitoring laws in California draw different lines depending on the technology, the setting, and the information collected. This article explains the main rules and practical steps to consider before introducing or expanding workplace monitoring.
Employee monitoring laws in California: the starting point
California does not have one statute that answers every workplace surveillance question. Employers must consider constitutional privacy protections, recording laws, employee data requirements, and restrictions on particular locations or activities.
Article I, section 1 of the California Constitution protects privacy. That protection can apply to private employers. In Hernandez v. Hillsides, Inc., 47 Cal.4th 272 (2009), the California Supreme Court examined workplace video surveillance by considering employees’ reasonable expectations of privacy, the seriousness of the intrusion, and the employer’s justification.
The practical lesson is that context matters. A visible security camera at a public entrance raises different concerns from hidden surveillance inside an office where employees expect privacy. A legitimate security objective does not automatically justify every method of collecting information.
A workplace policy can help explain expectations, but it is not a blanket waiver of employee rights. Employers should identify a specific business purpose and choose monitoring that is appropriately limited.
Different monitoring tools create different risks
Before purchasing software or installing equipment, identify exactly what the system captures. Features enabled by default may collect more than the employer intended.
- Email and internet activity: Monitoring business accounts and company networks may be appropriate for security or operational purposes. Policies should describe the scope, including whether message content, browsing activity, or only security alerts are reviewed.
- Screenshots and keystrokes: These tools can capture passwords, medical information, personal messages, and unrelated third-party information. Consider whether less intrusive activity reports would meet the same need.
- Video: Security cameras require careful placement. Labor Code section 435 prohibits an employer from causing an audio or video recording to be made of an employee in a restroom, locker room, or room designated for changing clothes unless authorized by court order. A recording made in violation of the section may not be used by the employer for any purpose. The section applies to private and public employers except the federal government.
- Location tracking: Tracking a delivery vehicle during a shift differs from continuously tracking an employee’s personal phone. Ownership, consent, tracking method, and off-duty collection all require review.
- Personal devices: A bring-your-own-device policy should separate business access from personal content. Installing workplace software should not become unrestricted access to an employee’s private accounts.
Employers should also check whether a video system records sound. Adding audio can introduce consent requirements that do not apply in the same way to silent video.
Recording conversations requires particular care
Penal Code section 632 generally prohibits intentionally recording a confidential communication without the consent of all parties. Confidentiality depends on whether the circumstances reasonably indicate that a party wants the communication confined to the participants; not every workplace conversation qualifies.
Other California provisions govern recording certain telephone communications. Employers should not assume that a business call, customer-service purpose, or company-issued phone eliminates consent requirements.
For recorded calls and meetings, use a consent process appropriate to the communication. Give clear notice before recording begins and establish what happens if a participant declines. Employees, customers, applicants, and outside vendors may all be participants whose consent matters.
A signed employee policy does not necessarily establish consent from everyone on a call. Likewise, a general statement that company systems may be monitored should not be treated as permission to record every confidential conversation. Review the actual recording workflow, not just the policy language.
Employee data can fall under the CCPA
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, generally applies to workforce personal information collected by businesses that meet its coverage requirements, subject to applicable statutory and regulatory exceptions. The former employment-related exemption expired on December 31, 2022, so these protections generally apply beginning January 1, 2023. Not every California employer is covered, so coverage should be assessed before deciding which obligations apply.
For covered businesses, Civil Code section 1798.100 requires notice at or before collection. Section 1798.100(c) limits the collection, use, retention, and sharing of personal information to what is reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or another disclosed purpose compatible with the context in which it was collected, subject to applicable statutory exceptions and implementing regulations.
A monitoring program may collect personal information such as identifiers, activity records, communications, and location data. Some information, including precise geolocation, can qualify as sensitive personal information.
- Explain the categories collected, purposes, and applicable retention information.
- Provide the notices and rights-request procedures required for the particular workforce information, business, and processing activity, taking account of the CCPA’s statutory exemptions and the California Privacy Protection Agency regulations governing employment-related information.
- Restrict access and assess the monitoring vendor’s contract, security practices, and data uses.
- Evaluate whether changing the system or its purpose requires updated disclosures.
Access, correction, and deletion rights are subject to statutory limits and exceptions. Employers should not promise to delete records they must retain by law.
Build a policy around necessity and limits
A workable policy should match actual practices. Before launch, document the following:
- The business problem the monitoring addresses.
- The devices, accounts, locations, and working hours covered.
- The information collected and features intentionally disabled.
- Who may review records and under what circumstances.
- Retention periods, security controls, and employee notice procedures.
Also consider whether surveillance could interfere with protected employee activity, including lawful discussions about wages or working conditions. Managers need clear instructions about authorized uses and escalation procedures. An attorney reviewing California regulatory compliance can help evaluate both the written policy and the technology’s settings.
Talk to a California business attorney
Itkin Law offers a free consultation for businesses evaluating workplace monitoring and individuals concerned about workplace privacy. Schedule a free consultation or call (424) 603-8888.
This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. The law changes, and this article reflects the law as of its publication date. Every situation is different — contact us to discuss how the law applies to your exact circumstances. See our full disclaimer.

