Is Employee Monitoring Legal? A US Employer's Guide
What US law actually requires before you monitor remote employees — notice rules, state-by-state differences, and the practices that create real legal exposure.
Short answer: in the United States, monitoring employees on company-owned equipment during work hours is generally legal. The longer answer is where employers get into trouble, because “generally legal” hides a set of notice requirements, state-specific rules, and a few practices that will create liability no matter how well you disclosed them.
This is a practical overview, not legal advice. Employment law is state-specific and changes; have counsel review your actual policy before you roll it out.
The baseline: consent and notice
Federal wiretap law (the Electronic Communications Privacy Act) restricts intercepting electronic communications, with a significant exception for consent and for monitoring in the ordinary course of business on employer-provided systems. That exception is what most workplace monitoring rests on.
The practical consequence: consent is the foundation of the whole thing. Get it in writing, before monitoring begins, and describe what you actually collect.
States that require notice
A handful of states have gone further than the federal baseline and require affirmative notice:
- New York requires employers to give written or electronic notice to employees upon hiring, and to obtain written or electronic acknowledgment, if they monitor telephone, email, or internet access. A notice must also be posted in a conspicuous place.
- Connecticut requires employers who engage in electronic monitoring to give prior written notice describing the types of monitoring that may occur.
- Delaware requires notice before monitoring or intercepting email or internet usage, either by daily notice or a one-time written acknowledgment.
- California has no single monitoring-notice statute but has strong constitutional and statutory privacy protections, and the CCPA/CPRA gives employees rights over personal information collected about them — including, in many cases, monitoring data.
Several other states have introduced or passed related legislation, and the trend is toward more notice, not less. If you operate in more than one state, the sane approach is to write one policy that satisfies the strictest jurisdiction you operate in rather than maintaining a patchwork.
Where employers actually get sued
Notice failures cause disputes. These practices cause real liability:
Monitoring off the clock. Software that keeps recording after hours, on weekends, or during breaks is the single most dangerous configuration. It sweeps up genuinely private activity and it destroys the “ordinary course of business” argument.
Monitoring personal devices. BYOD monitoring is a different legal question with far more exposure. If you monitor, monitor company equipment.
Capturing protected activity. Under the National Labor Relations Act, employees have the right to discuss wages and working conditions. Monitoring that surveils those conversations — or that was deployed in response to organizing activity — can be an unfair labor practice regardless of what your policy says.
Collecting special-category data. Health information, union membership, banking credentials. Screenshots are indiscriminate: a screenshot taken while someone checks a medical portal captures health data you never intended to hold and now have to protect.
Keeping it forever. Data you no longer need is pure liability. It is discoverable, it is breachable, and it has no offsetting value.
A configuration that stays defensible
Whatever tool you choose, these settings do most of the compliance work:
- Record only while clocked in. Nothing on breaks, nothing after hours. This should not be adjustable — if your vendor lets you monitor around the clock, that is a red flag.
- Notice and acknowledgment before the first capture. Store what the employee actually saw, not just that they clicked yes. If you later change the policy, re-acknowledge.
- Exclude sensitive applications. Banking, health, HR, personal messaging — never captured.
- Minimize by default. Domain names rather than full URLs. Primary display only. Blur screenshots. Collect the least that answers your question.
- Set a retention limit and enforce it automatically. Thirty days is a defensible default.
- Give employees access to their own data. In several jurisdictions this is a right; everywhere else it is the practice that keeps disputes from becoming lawsuits.
Outside the US
If you have employees in the EU or UK, GDPR applies and the analysis is different in an important way: consent from an employee is generally not a valid legal basis, because the power imbalance makes it non-free. Employers typically rely on legitimate interests, which requires a documented balancing test and often a Data Protection Impact Assessment. Works councils in Germany and elsewhere may have codetermination rights over monitoring. Do not assume a US-designed policy travels.
How Klees Desk is built for this
Klees Desk was designed around the constraints above rather than retrofitted to them:
- It captures nothing while an employee is clocked out or on break, and there is no setting that changes that.
- It never logs keystrokes, and never touches camera, microphone, or clipboard.
- Every employee sees a consent screen generated from your live settings — so the notice describes what you actually collect — and the exact text shown is stored with the acknowledgment. A later policy edit cannot rewrite what someone agreed to.
- Raising the policy version forces re-acknowledgment before tracking resumes.
- Excluded applications are never captured, and an excluded app in the foreground suppresses the screenshot too.
- URL tracking defaults to the domain only. Screenshots default to off, and can be blurred on the employee’s own machine before upload.
- Retention defaults to 30 days with automatic purge.
- Employees can see everything recorded about them, and delete their own screenshots when you allow it.
Related reading
- Klees Desk documentation — every capture setting explained
- Security at Klees — how your data is stored and protected
- Remote & Work From Home
Bilingual operations lead at Klees. 8 years managing construction and cleaning crews across Texas, Florida, and California. Specializes in EN/ES/PT workforce onboarding.
Related reads
How to Manage Remote Employees Without Micromanaging Them
The practical difference between oversight and micromanagement, and how to get visibility into remote work without destroying the trust that makes remote work function.
How to Write a Remote Work Monitoring Policy Your Team Accepts
A monitoring policy people actually read, with the six sections that matter and language you can adapt — plus the mistakes that turn a policy into a resignation letter.
Time Tracking for Remote Employees: What Actually Works
Honor-system timesheets fail quietly and surveillance tools fail loudly. A practical look at what to track for remote staff, and what to leave alone.