Skip to content

Is Employee Monitoring Legal? A US Employer's Guide

What US law actually requires before you monitor remote employees — notice rules, state-by-state differences, and the practices that create real legal exposure.

Maria Hernandez Maria Hernandez ·
A person reviewing documents and a laptop at an office desk, working through compliance paperwork.

Short answer: in the United States, monitoring employees on company-owned equipment during work hours is generally legal. The longer answer is where employers get into trouble, because “generally legal” hides a set of notice requirements, state-specific rules, and a few practices that will create liability no matter how well you disclosed them.

This is a practical overview, not legal advice. Employment law is state-specific and changes; have counsel review your actual policy before you roll it out.

Federal wiretap law (the Electronic Communications Privacy Act) restricts intercepting electronic communications, with a significant exception for consent and for monitoring in the ordinary course of business on employer-provided systems. That exception is what most workplace monitoring rests on.

The practical consequence: consent is the foundation of the whole thing. Get it in writing, before monitoring begins, and describe what you actually collect.

States that require notice

A handful of states have gone further than the federal baseline and require affirmative notice:

  • New York requires employers to give written or electronic notice to employees upon hiring, and to obtain written or electronic acknowledgment, if they monitor telephone, email, or internet access. A notice must also be posted in a conspicuous place.
  • Connecticut requires employers who engage in electronic monitoring to give prior written notice describing the types of monitoring that may occur.
  • Delaware requires notice before monitoring or intercepting email or internet usage, either by daily notice or a one-time written acknowledgment.
  • California has no single monitoring-notice statute but has strong constitutional and statutory privacy protections, and the CCPA/CPRA gives employees rights over personal information collected about them — including, in many cases, monitoring data.

Several other states have introduced or passed related legislation, and the trend is toward more notice, not less. If you operate in more than one state, the sane approach is to write one policy that satisfies the strictest jurisdiction you operate in rather than maintaining a patchwork.

Where employers actually get sued

Notice failures cause disputes. These practices cause real liability:

Monitoring off the clock. Software that keeps recording after hours, on weekends, or during breaks is the single most dangerous configuration. It sweeps up genuinely private activity and it destroys the “ordinary course of business” argument.

Monitoring personal devices. BYOD monitoring is a different legal question with far more exposure. If you monitor, monitor company equipment.

Capturing protected activity. Under the National Labor Relations Act, employees have the right to discuss wages and working conditions. Monitoring that surveils those conversations — or that was deployed in response to organizing activity — can be an unfair labor practice regardless of what your policy says.

Collecting special-category data. Health information, union membership, banking credentials. Screenshots are indiscriminate: a screenshot taken while someone checks a medical portal captures health data you never intended to hold and now have to protect.

Keeping it forever. Data you no longer need is pure liability. It is discoverable, it is breachable, and it has no offsetting value.

A configuration that stays defensible

Whatever tool you choose, these settings do most of the compliance work:

  1. Record only while clocked in. Nothing on breaks, nothing after hours. This should not be adjustable — if your vendor lets you monitor around the clock, that is a red flag.
  2. Notice and acknowledgment before the first capture. Store what the employee actually saw, not just that they clicked yes. If you later change the policy, re-acknowledge.
  3. Exclude sensitive applications. Banking, health, HR, personal messaging — never captured.
  4. Minimize by default. Domain names rather than full URLs. Primary display only. Blur screenshots. Collect the least that answers your question.
  5. Set a retention limit and enforce it automatically. Thirty days is a defensible default.
  6. Give employees access to their own data. In several jurisdictions this is a right; everywhere else it is the practice that keeps disputes from becoming lawsuits.

Outside the US

If you have employees in the EU or UK, GDPR applies and the analysis is different in an important way: consent from an employee is generally not a valid legal basis, because the power imbalance makes it non-free. Employers typically rely on legitimate interests, which requires a documented balancing test and often a Data Protection Impact Assessment. Works councils in Germany and elsewhere may have codetermination rights over monitoring. Do not assume a US-designed policy travels.

How Klees Desk is built for this

Klees Desk was designed around the constraints above rather than retrofitted to them:

  • It captures nothing while an employee is clocked out or on break, and there is no setting that changes that.
  • It never logs keystrokes, and never touches camera, microphone, or clipboard.
  • Every employee sees a consent screen generated from your live settings — so the notice describes what you actually collect — and the exact text shown is stored with the acknowledgment. A later policy edit cannot rewrite what someone agreed to.
  • Raising the policy version forces re-acknowledgment before tracking resumes.
  • Excluded applications are never captured, and an excluded app in the foreground suppresses the screenshot too.
  • URL tracking defaults to the domain only. Screenshots default to off, and can be blurred on the employee’s own machine before upload.
  • Retention defaults to 30 days with automatic purge.
  • Employees can see everything recorded about them, and delete their own screenshots when you allow it.
Share LinkedIn Email
Maria Hernandez
Maria Hernandez · Field Operations Lead

Bilingual operations lead at Klees. 8 years managing construction and cleaning crews across Texas, Florida, and California. Specializes in EN/ES/PT workforce onboarding.

Related reads