California’s Consumer Privacy Act now covers employee data in full. When the CCPA’s employee and business-to-business exemptions expired on January 1, 2023, workforce personal information stopped being a special case: applicants, current employees, contractors, and their dependents hold the same privacy rights as any other California consumer, and covered employers owe the same notices, response deadlines, and security duties.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act
Which Employers Are Covered
The law reaches for-profit businesses that operate in California and hit at least one of three thresholds:2California Legislative Information. California Civil Code 1798.140 – Definitions
- More than $25 million in annual gross revenue in the preceding calendar year, a figure that adjusts annually for inflation.
- Buying, selling, or sharing personal information of 100,000 or more consumers or households in a year.
- Deriving 50 percent or more of annual revenue from selling or sharing consumers’ personal information.
A parent, subsidiary, or affiliate that shares common branding and personal information with a covered business is pulled in as well, even if it wouldn’t clear the thresholds on its own. Nonprofits and government agencies sit outside the CCPA entirely.
What Counts as Employee Personal Information
The definition is deliberately wide: anything that identifies, relates to, or could reasonably be linked to a specific person.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act In the workplace, that pulls in Social Security numbers, driver’s license numbers, home addresses, salaries, performance reviews, and educational background. It also pulls in browsing history on a company-issued laptop and activity logged by internal software.
A subcategory called sensitive personal information carries stronger protections. In an employment setting, sensitive data includes:3California Privacy Protection Agency. What is Personal Information?
- Racial or ethnic origin, religious beliefs, and union membership.
- Health information and sexual orientation.
- Precise geolocation, such as tracking from a company vehicle or mobile device.
- Biometric identifiers like fingerprints or facial recognition used for building access.
Background checks, benefits enrollment, wellness programs, and monitoring tools routinely produce this kind of data. If a data point can be traced back to a specific worker, it almost certainly falls under the statute.
Notices Employers Must Provide
Notice at Collection
Before collecting any personal information from an applicant, employee, or contractor, the employer has to deliver a Notice at Collection. It must identify the categories of data being collected, the specific business purposes for each category, and whether any of it will be sold or shared with third parties.4California Legislative Information. California Code CIV 1798.100 – General Duties of Businesses that Collect Personal Information If the employer later adds a new category or wants to use existing data for a materially different purpose, an updated notice has to go out first.
Privacy Policy
Employers also need an accessible privacy policy that goes deeper than the collection notice.5California Privacy Protection Agency. What General Notices Are Required By The CCPA? It should spell out retention periods for each category, how sensitive data is processed, and the specific rights workers can exercise. The California Privacy Protection Agency has said employers may need to tailor these notices to the employment context rather than recycle a consumer-facing document.
Data Minimization
Section 1798.100(c) limits how much an employer can collect in the first place. Collection, use, retention, and sharing must be “reasonably necessary and proportionate” to the purposes that justified gathering the data.6California Privacy Protection Agency. Enforcement Advisory No. 2024-01 The CPPA advises employers to ask what the minimum amount of information actually needed is, whether the business already holds the data before requesting more, and what harm over-collection could cause. Grabbing employee data “just in case” is the practice this standard exists to stop.
Rights Workers Can Exercise
The rights below apply to all personal information the employer holds, not only what it collected after the exemption ended.
- Know and access. A worker can ask the employer to disclose the specific pieces of personal information it has collected about them, delivered in a portable, readily usable format.7California Legislative Information. California Code CIV 1798.110 – Consumers Right to Know What Personal Information is Being Collected
- Correct. If a record contains a factual error, the worker can direct the employer to fix it, and the employer must make commercially reasonable efforts to do so.8California Legislative Information. California Code CIV 1798.106 – Consumer Right to Request Correction of Inaccurate Personal Information
- Delete. A worker can ask for deletion of information the employer collected from them. This right isn’t absolute at work: the employer can keep records needed to meet a legal obligation or finish an ongoing business transaction, which covers tax records, payroll data, and labor-law documentation.9California Legislative Information. California Code CIV 1798.105 – Consumers Right to Delete Personal Information
- Limit use of sensitive data. A worker can direct the employer to use sensitive personal information only for purposes necessary to perform the services reasonably expected. Health data, biometrics, and precise location can be pinned back to the narrower purpose that justified collecting them.10California Privacy Protection Agency. California Consumer Privacy Act of 2018 – Section 1798.121
- Opt out of sale or sharing. If the employer sells or shares worker personal information with third parties, the worker can tell it to stop. The employer has to honor that direction and cannot resume without fresh consent.11California Privacy Protection Agency. California Consumer Privacy Act of 2018 – Section 1798.120
Retaliation is prohibited. An employer cannot demote, terminate, cut pay, or otherwise discriminate against a worker for submitting a privacy request.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act
How to Submit a Request and What to Expect Back
Covered employers have to offer at least two intake methods, one of which must be a toll-free phone number. Many also accept requests through an online portal or a dedicated email address. Once a verifiable request comes in, the employer has 45 calendar days to respond. It can extend that by another 45 days if it notifies the worker of the extension within the first window. No fee can be charged for processing the request.
Verification is required before disclosing or deleting anything. For current employees this tends to be straightforward, since identity mechanisms are already in place. Former employees and applicants may need to provide more. If the employer cannot verify the request, it can deny it, but it has to explain why.
Where Federal Law Displaces the CCPA
The CCPA does not override federal privacy regimes that already cover certain employee data:
- Protected health information handled by a HIPAA-covered entity or business associate stays under HIPAA. An employer’s group health plan that already runs on HIPAA’s privacy and security rules keeps that data outside the CCPA.12California Legislative Information. California Code CIV 1798.145 – Exemptions
- Information collected, maintained, or used by a consumer reporting agency under the Fair Credit Reporting Act is exempt. Third-party background check data typically travels under the FCRA instead.12California Legislative Information. California Code CIV 1798.145 – Exemptions
- Financial data subject to the Gramm-Leach-Bliley Act is exempt from most CCPA provisions, though the private right of action for data breaches under Section 1798.150 still reaches it.12California Legislative Information. California Code CIV 1798.145 – Exemptions
These carve-outs are narrower than they look. They apply to the specific data governed by the federal law, not to the employer as a whole. Payroll, performance reviews, geolocation logs, and everything else outside the federal regime stays fully within CCPA reach.
Security Duties and Breach Lawsuits
Employers must maintain reasonable security procedures appropriate to the volume and sensitivity of the workforce data they store. The statute doesn’t hand out a technology checklist, but encryption, access controls, and other industry-standard protections come up when reasonableness is measured.13California Legislative Information. California Code CIV 1798.150 – Personal Information Security Breaches
This is one of the few areas where employees can sue the employer directly. When unencrypted personal information is accessed without authorization because the employer failed to keep reasonable security, affected workers can bring a civil suit for statutory damages. The base range is $100 to $750 per person per incident, or actual damages if greater. For 2025 the CPPA adjusted the range for inflation to $107 to $799 per person per incident.14California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties The figures adjust annually with CPI. Across a breach that hits thousands of employees, even the low end multiplies quickly.
Before filing, a worker has to give the employer 30 days’ written notice identifying the specific violation. If the employer cures within that window and provides a written statement that no further breaches will occur, the suit may be barred. The cure option does not save the employer where harm has already occurred that cannot be undone.
Administrative Fines
The CPPA can pursue administrative penalties for any CCPA violation, separate from breach litigation. Base amounts are $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving a minor under 16. The 2025 adjusted figures are $2,663 and $7,988, and they continue to rise with inflation.14California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties
The per-violation structure is where exposure gets sharp. Each affected worker, each mishandled category of data, and each missing or deficient notice can count separately. An employer that skips the Notice at Collection for 500 employees has not committed one violation; it has potentially committed 500. Through its early enforcement, the CPPA has signaled it takes workforce obligations as seriously as consumer-facing ones, and the arithmetic of the fine schedule is built to make that point stick.