Most articles on this topic are written by law firms, for law firms. This one is written for the person who actually has to make the call: the manager or IT lead rolling out an analytics or monitoring tool, who needs to know what's required before the first agent is installed.
We'll cover the federal baseline, the states that add real obligations on top of it, and a short checklist you can act on. This is general information, not legal advice — but it will tell you the right questions to ask.
The federal baseline: ECPA
The Electronic Communications Privacy Act (ECPA) is the floor. Its general rule is that intercepting electronic communications is prohibited — but it carves out two exceptions that cover almost all workplace monitoring:
- The business-purpose exception — monitoring conducted in the ordinary course of business on equipment the employer provides.
- The consent exception — monitoring where at least one party has consented.
In practice, monitoring activity on a company-owned device for a legitimate business reason sits comfortably inside these exceptions. The risk areas are personal devices, personal accounts, and capturing communications content (audio, message bodies) rather than activity metadata.
This is exactly why ProdView measures activity, not content: window focus, app and category usage, idle time, and configurable screenshots — never keystroke content, message bodies, or files. Measuring less is both more respectful and lower-risk.
States that add real obligations
A minority of states layer notice or consent requirements on top of ECPA. These are the ones that change what you have to do:
| Notice required? | Form | |
|---|---|---|
| New York | Yes — at hiring | Written, employee acknowledges |
| Connecticut | Yes | Conspicuous written notice |
| Delaware | Yes | Daily notice or one-time acknowledgement |
| California | Notice + CCPA/CPRA duties | Privacy notice at collection |
| Most other states | — | Disclosure is best practice |
Two patterns are worth internalizing:
- New York, Connecticut, and Delaware have explicit electronic-monitoring notice statutes. If you employ people there, written notice isn't optional.
- California is different in kind: the CCPA/CPRA treats employee data as personal information, so you owe a notice at collection and have to honor data-subject rights. Monitoring is legal, but the data-handling bar is higher.
The remote-team trap: which state's law applies?
The most common mistake we see is a company applying its headquarters' law to everyone. The rule of thumb is the opposite: the law of the state where the employee physically works usually governs.
If you have one employee in New York and one in Texas, you meet New York's notice requirement for the New York employee — and the practical move for a distributed team is to adopt the strictest applicable standard for everyone. It's simpler to administer one transparent policy than fifty.
International: a one-paragraph warning
If you employ people in the EU or UK, GDPR changes the game entirely. Monitoring there requires a lawful basis, a documented necessity-and-proportionality assessment, and often a Data Protection Impact Assessment. "We bought a tool" is not a lawful basis. We cover this in GDPR & employee monitoring.
A practical compliance checklist
Before you deploy, you should be able to answer yes to all of these:
- We monitor on company-owned devices for a documented business purpose.
- We give written notice to every employee, and we meet the notice statute in NY/CT/DE if we operate there.
- We measure activity, not communication content.
- We applied the strictest state standard across the whole team.
- Employees can see the same data managers see.
- For CA/EU/UK staff, we completed the extra data-protection steps.
If you want the state lookup without reading the whole statute, we built a free employee monitoring law checker that walks you through your states and monitoring methods in a couple of minutes.
Why we think transparency wins
You can read this whole guide as a list of constraints. We read it as a design principle. Every requirement above points the same direction: monitor less, disclose more, and let people see their own numbers. That's not just the compliant path — it's the one that keeps the trust you need for the data to mean anything.