Employee Computer Monitoring Laws: A State-by-State Compliance Map (2026)

Three US states have statutes that specifically require notice before electronic monitoring of employees. Every other state operates under a mix of federal law, wiretap statutes, and general privacy rules — which is why "is monitoring legal here" almost always resolves into "what kind of monitoring, and did you tell them."
This map covers the layers that actually govern deployment: the federal baseline, the three notice statutes, audio recording consent, biometric rules, and the areas where requirements are shifting. Organisations deploying employee computer monitoring software across multiple states usually discover that the binding constraint is not the strictest state — it is the fact that a single policy has to satisfy several regimes at once.
This is general information for planning purposes, not legal advice. Statutes are amended, penalties change, and application depends on facts. Confirm your obligations with employment counsel in each state where you have employees.
The layer that decides everything: employee location
Monitoring law follows the worker, not the company. A business incorporated in Florida with an employee working from Connecticut applies Connecticut's requirements to that employee.
For remote teams this has an unglamorous consequence: every state you hire in adds a rule set, and an employee who relocates changes your obligations without anyone updating a document.
Federal baseline: the ECPA
The Electronic Communications Privacy Act governs interception of electronic communications nationally. For employers it does two things.
It permits monitoring on company-owned systems where there is a legitimate business purpose. Federal law does not itself require notifying employees about monitoring on company equipment.
It draws a line at personal accounts and devices. Accessing an employee's personal email, private social media, or personal device without authorisation falls outside the business-purpose exception. Reported penalties for violations run to damages plus attorney fees, and can carry criminal exposure.
A second federal layer gets overlooked: the National Labor Relations Board has taken the position that continuous, always-on monitoring can be unlawful where it interferes with employees' protected right to discuss working conditions. This applies regardless of union status and is a live consideration for organisations running continuous capture.
The three notice states
These are the jurisdictions with statutes written specifically for electronic monitoring. The requirements differ from each other in ways that matter operationally.
Connecticut has the broadest scope, reaching collection by means other than direct observation, and prohibits monitoring in break rooms, restrooms, and health areas. Covert monitoring is allowed where there's reasonable belief of legal violations or a hostile work environment. Enforcement sits with the state labour commissioner.
Delaware offers a choice: daily notice (e.g., a login banner) or one-time notice with acknowledgment — useful for employers who can't collect signatures easily. Penalties are lower than Connecticut's, assessed per violation.
New York requires notice and acknowledgment from new hires, plus conspicuous posting for existing staff. It took effect 7 May 2022 and is enforced by the Attorney General.
Note: some vendor guides list Texas as a fourth notice state; legal sources consistently describe three. Verify before relying on the four-state framing.
Audio recording: a separate rule set
Recording calls follows wiretap law.
One-party consent states (the majority) allow recording if the employer, as a call participant, consents. All-party consent states — commonly including California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington — require everyone's agreement, with severe penalties in some (Maryland: up to $10,000 and imprisonment).
For multi-state calls, follow the strictest applicable rule. This layer rarely affects screen or activity monitoring — mainly call/meeting recording and microphone capture.
Biometric data: the fastest-moving layer
Illinois BIPA is the strictest US biometric statute, requiring written consent, a retention/destruction schedule, and allowing private lawsuits. It applies to fingerprint clock-ins and facial recognition login, not just surveillance.
Texas and Washington have their own biometric regimes, enforced by the state rather than private suits. The trap: a fingerprint time clock counts as biometric collection even when it's not framed as "security."
What applies in the other 47 states
Absence of a monitoring statute does not mean absence of obligation. Four things still apply.
Wiretap law governs any interception of communications content.
State privacy statutes increasingly grant employees rights over personal data. California's consumer privacy framework extends employee rights to know what is collected and how it is used — a disclosure obligation arriving from a different direction than the notice statutes.
Common law privacy claims turn on reasonable expectation of privacy. Monitoring in break rooms, bathrooms, or on personal devices creates exposure regardless of statute.
Off-duty conduct statutes in several states restrict employer action based on lawful activity outside work — relevant where always-on monitoring captures personal time.
Where requirements are moving
2026 sources report tightening in California and Maine around continuous capture, data minimisation, and employee access rights, with screenshot monitoring under particular scrutiny. Analysts project roughly 15 states will have specific monitoring disclosure laws by 2028, up from three or four today. The trend: more disclosure, more minimisation, more employee access. Building to the stricter standard now is cheaper than retrofitting later.
Practical compliance across multiple states
Write one policy at the strictest applicable standard — meeting Connecticut's and New York's requirements generally covers the rest. Collect acknowledgment from everyone, not just where required; it costs nothing and simplifies records. Post notices visibly (intranet page plus onboarding document covers Connecticut and New York). Map your workforce by work location, not payroll address. Configure conservatively: company devices only, working hours only, no keystroke content. Session-based tools that capture only between clock-in and clock-out sidestep off-hours questions entirely. Exclude prohibited areas like break rooms and restrooms as a sensible default everywhere. Document your business purpose before deployment, since every notice statute and the ECPA exception assume you can articulate why.
Configuration choices that reduce exposure
Legal risk tracks capture type more than it tracks tool choice.
Tools differ meaningfully. Monitask records no keystroke content — activity levels come from whether keyboard or mouse input occurred in each ten-minute window — and captures only between clock-in and clock-out, which keeps off-duty activity out of scope by design. Platforms that log keystrokes and run continuously carry materially more of the exposure in the lower half of that table.
Frequently asked questions
Which states require notice before monitoring employees?
Connecticut, Delaware, and New York have statutes specifically requiring notice for electronic monitoring. Some vendor guides list Texas as a fourth; legal sources generally describe three. Several other states impose disclosure obligations through broader privacy legislation.
Do I need employee consent to monitor company computers?
Federal law generally does not require consent on company-owned equipment with a legitimate business purpose. Notice is a different matter — Connecticut, Delaware, and New York require it by statute, and New York and Delaware require acknowledgment in specified circumstances.
Can I monitor employees in another state from my headquarters?
The employee's work location governs. A company headquartered anywhere must follow Connecticut's rules for a Connecticut-based employee. Most multi-state employers write a single policy meeting the strictest applicable standard.
Is it legal to record employee phone calls?
Depends on the state and on who is party to the call. One-party consent states allow recording where the employer participates. All-party consent states require everyone's agreement, and penalties there can be severe. For multi-state calls, follow the strictest applicable rule.
Are screenshots legal for employee monitoring?
Generally yes on company devices with appropriate notice, though some states have been reported to tighten requirements around necessity and continuous capture. Screenshots carry higher exposure than activity or application data because they capture incidental personal content.
What about monitoring personal devices?
Substantially riskier. The ECPA business-purpose exception attaches to company-owned systems. Monitoring employee-owned hardware requires explicit written consent and should be scoped narrowly to work applications. Issuing company devices is the cleaner approach.
Does Illinois BIPA apply to time clocks?
Yes, where the clock collects fingerprints or facial geometry. BIPA requires written consent and a published retention schedule, and provides a private right of action. This catches organisations that think of biometrics as a security-system issue rather than an HR one.
What happens if we monitor without required notice?
Penalties vary by state and are enforced by labour departments or attorneys general, with reported ranges from around $100 per violation in Delaware to escalating civil penalties in Connecticut and New York. ECPA violations carry separate federal exposure including damages and attorney fees.
Verify current requirements with employment counsel before deploying monitoring. Statutes in this area are actively changing.