Skip to main content

State Employee Data Privacy Laws in 2026: A Small Business HR Records Guide

8 min readMike ThriftMike Thrift
State Employee Data Privacy Laws in 2026: A Small Business HR Records Guide

Twenty states now have comprehensive data privacy laws on the books, and as of January 1, 2026 that list grew to include Indiana, Kentucky, and Rhode Island. If you run a small business and your mental model of "data privacy compliance" is still "that's a California thing, and I don't have 25 million dollars in revenue, so it doesn't apply to me," it's worth a second look. The rules that matter most for a small employer aren't really about your customers anymore — they're about your own employees' Social Security numbers, bank account details, medical notes, and biometric time-clock scans sitting in a folder (or a SaaS dashboard) somewhere in your HR stack.

The confusing part is that these laws don't treat "employee data" the same way from state to state. California folds HR records into its general consumer privacy law. Colorado and Virginia mostly carve employment records out of their broad privacy statutes — but Colorado just added a narrow, aggressive exception for biometric data that catches a lot of small businesses by surprise. If you're a bookkeeper, an operations lead, or an owner who touches payroll, here's what actually changed, who it applies to, and what to do about it before an employee complaint (or a plaintiff's attorney) makes it your problem.

Why "Employee Data" Used to Be a Blind Spot

When states started passing comprehensive privacy laws — Virginia and Colorado in 2021, most of the rest in the years since — nearly all of them borrowed a similar structure: define a "consumer," give consumers rights (access, deletion, correction, opt-out of sale), and require businesses that control personal data to honor those rights.

But almost every one of those laws, except California's, explicitly defines "consumer" to exclude someone acting in an employment context. Colorado's law says so directly, and Virginia's does too. The logic was that employment relationships are already regulated by labor and employment law, so lawmakers didn't want to duplicate frameworks. The practical effect: an employee in Richmond or Denver generally cannot invoke their state's consumer privacy act to demand their employer delete their personnel file, correct a performance review, or explain what an internal analytics tool inferred about them.

California went the other way. When the California Consumer Privacy Act's employee-data exemption expired on January 1, 2023, the California Privacy Rights Act extended the full menu of consumer rights — access, deletion, correction, opt-out, and more — to employees, job applicants, and independent contractors. For a covered California employer, an employee now has essentially the same rights over their HR file that a customer has over their purchase history.

That split matters because it means "am I covered?" isn't a single national answer — it's a state-by-state, and increasingly a data-type-by-data-type, question.

California: The One State Where HR Data Is Fully in Scope

If you have any employees or contractors who are California residents, start here.

Who's covered. The CCPA/CPRA applies to a for-profit business that does business in California and meets any one of three thresholds: (1) more than $25 million in annual gross revenue, (2) buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year, or (3) derives 50% or more of annual revenue from selling or sharing personal information. A lot of small businesses assume the $25 million revenue line means they're exempt — but the second and third tests aren't about revenue at all, and a business using ad-tech pixels or analytics tools that "share" data with third parties can cross the 100,000-person threshold faster than expected once employees, job applicants, and site visitors are all counted together.

What's now required for HR data specifically. Covered employers must give employees and applicants a privacy notice describing what categories of personal information they collect and why, honor requests to access, correct, or delete personal information (subject to legal retention exceptions — you can't delete tax or payroll records you're required to keep), and get consent before certain uses of sensitive personal information like Social Security numbers, precise geolocation, or health data.

The 2026 change to watch: risk assessments for automated tools. As of January 1, 2026, California requires a documented privacy risk assessment before using automated decision-making technology (ADMT) to make a "significant decision" about a job applicant, employee, or contractor — think resume-screening software, video-interview scoring, or algorithmic scheduling and performance tools. Full ADMT compliance (things like giving workers a way to opt out of or appeal an automated decision) phases in through January 1, 2027, but the assessment obligation for pre-2026 processing is due by the end of 2027. If your business uses an applicant-tracking system with "AI-powered" resume ranking, or a workforce-management tool that auto-generates performance scores, this is the part of the law that's easy to miss because it's buried in the tooling, not the paperwork.

Colorado: Employment Records Are Exempt — Except Biometrics

The Colorado Privacy Act, like Virginia's, generally excludes information about someone in their capacity as a job applicant or employee. That exemption is still the general rule. What changed is a narrow but consequential amendment: HB24-1130, the Privacy of Biometric Identifiers and Data Act, effective July 1, 2025.

This law strips out the usual size thresholds — it doesn't matter how many Colorado residents' data you process; if you collect a biometric identifier (a fingerprint scan, a facial-recognition login, a hand-geometry time clock) from a Colorado resident, including an employee, you're covered. Before collecting it, you must provide notice and get affirmative, specific, informed consent — not a line buried in an employee handbook. Employers can only condition employment on biometric consent for narrow security purposes, like accessing a secure facility or secure hardware; you cannot require it to track an employee's location or monitor how long they spend using an application. You also need a written, publicly available policy covering retention schedules, security incident procedures, and deletion practices for biometric data.

Who this actually catches: small manufacturers, warehouses, restaurants, and clinics using fingerprint or facial-recognition time clocks instead of badge swipes — a popular way to stop buddy-punching — plus any business using biometric building access or POS logins. If that's you, the "we don't have 25 million in revenue" reasoning that shields you from most privacy laws doesn't apply here at all.

Virginia: Watch the Trend, Not (Yet) a Mandate

Virginia's Consumer Data Protection Act keeps its general exclusion for employment records, and there isn't a Virginia analog to Colorado's biometric carve-out as of 2026. The reason to pay attention anyway is the pattern: Colorado peeled off a slice of the employment exemption once a specific data type (biometrics) became a visible risk. Illinois has had a dedicated biometric privacy law with a private right of action for over a decade, and it's generated some of the largest employment-related privacy settlements in the country. Virginia, or another state, carving out its own employee-data exception — for biometrics, for AI hiring tools, or for something else — is a matter of when, not if. Building the habit of documenting what employee data you collect and why now means you're not scrambling when your state follows suit.

A Practical Checklist for Small Employers

You don't need a compliance department to get the basics right:

  1. Inventory what you actually collect. SSNs and bank details for payroll, health information for leave requests, biometric data from any time clock or access system, and anything an HR or ATS platform infers automatically (like an "engagement score" or automated candidate ranking).
  2. Check your time clock. If it scans a fingerprint or face, you likely need a written biometric policy and documented consent, regardless of your revenue.
  3. Read your vendor contracts. Payroll providers, background-check services, and applicant-tracking systems should contractually commit to protecting the data you hand them — "SOC 2 compliant" is a start, not a substitute for a written data-processing agreement.
  4. If you have California employees, build the request process now. Someone needs to own responding to an access, correction, or deletion request within the statutory window, and someone needs to know which records you're legally required to retain despite a deletion request (tax records, for instance).
  5. Don't rely on "state exempts employment records" as a permanent shield. It's true today in most states, but Colorado just showed how fast a narrow exception can appear.

Where Bookkeeping Fits Into the Compliance Story

None of this is really about accounting software — it's about knowing what sensitive data lives where, and being able to show your work if a regulator or an employee ever asks. That's a recordkeeping problem as much as a legal one. If your financial records live in opaque, proprietary formats scattered across tools, it's genuinely hard to audit who has access to what, or to prove you're not retaining data longer than your policy says you will.

Beancount.io takes the opposite approach: plain-text, version-controlled accounting where every entry is transparent, auditable, and under your control — no black-box vendor holding your financial history hostage. It won't write your biometric consent policy, but if "who can see this data, and for how long" is a question you want to be able to answer clearly across your business, starting with financial records you fully own is a good place to build that habit. Get started for free and see what plain-text accounting looks like in practice.

Share this article