Privacy and preparation
Which state privacy laws cover employee data?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
California's CCPA is the main comprehensive state privacy law that covers employee data, including job applicants and contractors. Most other comprehensive state laws exclude people acting in an employment context. That exclusion is narrow: biometric, recording, breach and sector laws still reach workplace records, so licensing decisions should rest on record type, not state alone.
Key takeaways
- California treats employees, applicants and contractors who live there as consumers, with notice and rights obligations.
- Most other comprehensive state privacy laws define consumers to exclude people acting in an employment context.
- Biometric, call recording, breach and sector laws can reach employee data in any state.
- Personnel, payroll, medical and background check records should stay out of a licensed corpus entirely.
- Applying one removal standard to all employees is usually simpler than sorting records by state of residence.
The short answer: California, then everything else#
California is the state whose comprehensive privacy law clearly covers employee data, because the CCPA treats employees, job applicants and independent contractors who are California residents as consumers. Its temporary exemptions for employee data have ended, so the full set of notice and rights obligations applies to them.
Most other comprehensive state laws, including those in Virginia, Colorado, Connecticut and Texas, define a consumer as someone acting in an individual or household context and exclude people acting in an employment context. Under those laws, a technician's name in a dispatch note or an engineer's comment in a code review is generally outside scope when the person acted as an employee.
That is a general pattern, not a guarantee. Wording varies, laws are amended, and some exclusions reach only data used within the employment relationship. Confirm the current text of each law that may apply with counsel.
How state laws treat employee and workplace data#
Comprehensive privacy laws are only one layer of workplace privacy, and the table separates them from the other rules that reach employee records.
For licensing, the second row often matters less than it seems. Even where a state law excludes employee data, buyer policies, your own contracts and the plain risk of exposing people usually lead to removing names anyway.
| Law or law type | Covers employee data? | Where it shows up in licensing |
|---|---|---|
| California CCPA | Yes, for California residents | Notice at collection, rights requests, sale and sharing rules, limits on sensitive information |
| Comprehensive laws in most other states | Generally no, for people acting in an employment context | Lighter privacy-law burden for work records, but check each law's wording |
| Biometric privacy laws, such as Illinois BIPA | Yes | Voiceprints in call recordings, face images, fingerprint timeclocks |
| Call recording and wiretap laws | Yes | Recorded support or dispatch calls where consent rules applied |
| Electronic monitoring notice laws in some states | Yes | Email, chat and phone records the employer monitors or retains |
| Breach notification and identifier laws | Yes | Social Security numbers, account numbers and IDs held in HR systems |
| Federal rules for specific records, such as HIPAA and FCRA | For those records | Health plan data and background check reports |
What California adds for employee information#
California adds notice, rights and use limits for employee information. Employers covered by the CCPA must tell employees at collection what personal information they collect and why, respond to requests to know, delete and correct, and apply extra limits to sensitive information such as government IDs and account log-ins.
For a licensing project, that means three checks. Does the existing employee notice describe the use? Is the purpose so far from why the information was collected that California's regulations may require consent rather than notice alone? And would the license disclose employee personal information to a third party for value, which could be a sale with opt-out duties? Deidentifying employee details before release usually answers all three, provided the method is documented.
Employee records that stay out of a licensed corpus#
Some employee records stay out of any licensed corpus regardless of state, because their sensitivity outweighs any training value.
Exclude these at the system level. Leaving an HRIS, payroll platform or benefits portal out of the inventory entirely is far safer than trying to filter its contents record by record.
- Personnel files, performance reviews and disciplinary records.
- Payroll, compensation, tax forms and bank details.
- Benefits, medical, leave and accommodation records.
- Background checks and drug test results.
- Immigration and identity documents.
- HR investigation files and complaints.
- Biometric data from timeclocks or access systems.
Where employee details hide in operational systems#
Employee details hide in operational systems far from the HR stack, which is why excluding the HRIS is necessary but not sufficient. Every system that records who did the work also records something about that person.
Map these fields before preparation starts. A system-by-system list keeps the removal rules consistent and gives counsel a concrete picture of what employee information the package would otherwise carry.
| System | Employee details inside | Usual treatment |
|---|---|---|
| Helpdesk such as Zendesk or Intercom | Agent names, signatures, internal notes about colleagues | Role tokens for agents; remove signatures and personal remarks |
| Jira, GitHub or GitLab | Usernames, commit author emails, review comments | Random author tokens, with the mapping destroyed before release; scrub emails from commit metadata |
| Field service platforms such as ServiceTitan | Technician names, GPS traces, timesheets, performance flags | Tokens for technicians; drop location trails and timesheets |
| Email and chat | Signatures, mobile numbers, personal conversations | Remove signatures and numbers; exclude direct messages unless reviewed |
| CRM | Sales rep names, commission notes, territory assignments | Role labels for reps; drop compensation fields |
Work product is not personnel data#
Work product written by employees, such as tickets, code reviews, design notes and dispatch comments, is different from personnel data, and it is usually what buyers want. The privacy issue in work product is the author: names, signatures, user IDs and details that point to one person.
Replace author names with stable role tokens such as Engineer A or Technician B, strip email signatures and personal phone numbers, and remove comments about an individual's performance. Direct messages and private channels need a separate decision, since employees may reasonably expect them to stay private.
Engineering records carry an extra layer. Commit metadata stores author names and email addresses outside the visible text, and code review tools keep user handles on every comment, so author removal has to reach the metadata, not only the message bodies.
Illustrative: a mechanical contractor with offices in two states#
Illustrative: a fictional commercial mechanical contractor operates in California and Texas. It wants to license ServiceTitan job histories, technician notes and estimates, plus the Microsoft 365 email threads that coordinate large service jobs.
Counsel notes that California technicians are covered by the CCPA, while Texas technicians acting as employees generally fall outside the Texas law's consumer definition. Rather than split the archive by state, the company applies the California-level standard to everyone: technician names become tokens, personal phone numbers and home addresses are removed, and payroll and HR systems are excluded.
The company also reviews its California employee notice with counsel before release. One standard keeps preparation simple and leaves no record whose treatment depends on guessing where an employee lived.
How SourceX treats employee information#
SourceX addresses employee information in the Rights and Preparation steps of the SourceX five-step transaction. HR, payroll and benefits systems are excluded during scoping, and author names and personal details in work records are removed during preparation.
Exclusions and removal methods are written into the privacy record of the SourceX Evidence Packet, which the supplier approves before release.
Frequently asked questions
Does an employee's home state or work location decide coverage?
Coverage under comprehensive state laws generally turns on residency, so a remote employee living in California can bring California rules into a company based elsewhere. Because residence data is often incomplete, many companies apply one standard to every employee's records.
Are contractors treated like employees?
In California, independent contractors who are residents are covered much like employees. Elsewhere, the employment-context exclusion may or may not reach contractors, depending on each law's wording. Treat contractor names and details the same way as employee details in a licensed package.
Do former employees still count?
Yes. Records about former employees remain personal information under the laws that cover them, and former employees can still make rights requests where the law allows. Historic archives are full of former staff, so removal methods need to cover them too.
Does company size change any of this?
It can. Comprehensive state laws apply only above certain thresholds, usually tied to revenue or to how many people's data a company processes, and the thresholds differ by state. Check which laws apply to your company before relying on any exclusion or obligation.
Do we need employee consent to license work records?
Consent is not the usual mechanism for employee data, partly because of the power imbalance at work. Notice, deidentification and exclusion of sensitive records are the common tools. Consent may still be required for some data, such as biometrics, and California's rules may call for it if identifiable records are used for an unrelated new purpose.
Do employee rights requests reach records we already licensed?
If the licensed records were deidentified, a later request generally has nothing to attach to, because the records no longer identify the employee. Requests still apply to the source systems you keep. If identifiable records were licensed, counsel should review how requests pass to the buyer under the contract.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.