If you run a small business in California and you thought consumer privacy law was something for tech giants to worry about, 2026 is the year that assumption stops holding. The employee and job-applicant data your business collects every day — Social Security numbers on a W-4, a fingerprint punch clock, a doctor's note for FMLA leave, even the résumé an applicant emailed you — is now squarely inside California's privacy law, and a fresh round of state regulations taking effect January 1, 2026 raises the bar again for how that data has to be handled.
How Employee Data Ended Up Covered by a "Consumer" Privacy Law
When the California Consumer Privacy Act (CCPA) first passed, employers got a break: an exemption meant that data about your own employees, job applicants, and contractors was mostly carved out while lawmakers figured out separate employment-specific rules. That exemption was always temporary, and it expired on January 1, 2023, when the California Privacy Rights Act (CPRA) amendments took full effect. Since then, HR files, payroll records, benefits enrollment data, and applicant-tracking systems are treated the same way as a customer's purchase history: as personal information subject to the law's access, deletion, correction, and disclosure rules.
That single expiration date reshaped a huge amount of ordinary business paperwork. Every I-9, every direct-deposit form, every performance review, every biometric time clock scan — all of it is now personal information an employee has a legal right to see, correct, and in many cases delete.
Who Actually Has to Comply
Not every small business is on the hook, and the thresholds matter more than the headlines suggest. The CPRA applies to a for-profit business that does business in California and collects California residents' personal information (including employees) if it meets at least one of these:
- Annual gross revenue over $25 million (as of January 1 of the calendar year), or
- Buys, sells, or shares the personal information of 100,000 or more California consumers, households, or devices annually, or
- Derives 50% or more of annual revenue from selling or sharing consumers' personal information
A lot of genuinely small employers fall under all three thresholds and aren't covered. But the second test — 100,000 consumers, households, or devices — catches more businesses than owners expect, because "devices" can include website visitors tracked by cookies, not just customers or employees. A ten-person consulting firm with a popular blog or a high-traffic e-commerce storefront can trip that threshold well before it ever hires its hundredth employee. If you're not sure which side of the line you're on, that's worth confirming with counsel before assuming the law doesn't apply to you — the penalty exposure below is real enough to make guessing a bad strategy.
What Rights Employees Actually Have Now
For covered employers, current and former employees, job applicants, and independent contractors get the same core rights California gives consumers:
- Right to know what categories of personal information you collect about them and why
- Right to access a copy of the specific data you hold on them
- Right to correct inaccurate information
- Right to delete their personal information, subject to exceptions (you can still keep what you need for tax records, legal compliance, or an active legal claim)
- Right to limit use of sensitive personal information — a category that includes Social Security numbers, financial account details, precise geolocation, racial or ethnic origin, health information, and biometric data collected for identification purposes
That last category is where a lot of small employers get caught off guard. Biometric time clocks are common in retail, restaurants, warehouses, and construction because they cut down on buddy-punching. Under the CPRA, a fingerprint or hand-scan used to clock someone in is "sensitive personal information," which means it comes with tighter notice and use-limitation obligations than an ordinary timesheet.
Practically, compliance means a written privacy notice explaining what you collect and why, a process for employees to submit requests, and — this is the part that trips people up — at least two designated methods for submitting those requests, one of which generally needs to be a toll-free phone number, plus something like a web form or email address as a second option. A sticky note that says "email HR" doesn't satisfy the rule.
The New Rules That Kick In January 1, 2026
On top of the baseline CPRA requirements, the California Privacy Protection Agency finalized a fresh set of regulations in 2025 that phase in starting January 1, 2026, and they specifically touch how employers use technology to manage their workforce:
- Risk assessments before high-risk processing. Before a covered business starts (or continues) an activity that poses "significant risk" — selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for a significant decision, or using biometrics for identity verification — it has to complete a documented risk assessment. If the activity was already underway before January 1, 2026, the assessment deadline is pushed to December 31, 2027, which gives existing programs some runway.
- Automated decision-making technology (ADMT) rules, phased in with a compliance date of January 1, 2027. This is the one HR departments should watch closely: AI-assisted résumé screening, algorithmic scheduling tools, and automated performance-scoring systems used for "significant decisions" about employment, compensation, or discipline will require consumer notice, an opt-out right, and an access right.
- Annual independent cybersecurity audits, phased in by revenue starting with the largest businesses in 2028 and working down to smaller covered businesses by 2030.
None of this demands a Fortune 500 compliance department. But it does mean that a small business using an off-the-shelf applicant-tracking tool with AI resume ranking, or a payroll vendor's biometric clock-in feature, needs to actually read what that vendor is doing with the data — because as the employer, you're the one accountable to your employees and to regulators, not the vendor.
A Realistic Scenario: The Restaurant Group With a Fingerprint Clock
Picture a 40-person restaurant group with three locations in Los Angeles County. It uses a biometric time clock to stop buddy-punching, an applicant-tracking platform with AI-powered résumé screening to handle a high volume of hourly applicants, and a payroll provider that stores direct-deposit and tax-withholding data. On its own, none of that sounds unusual — it's standard operations for a multi-location food business. But look at it through the CPRA lens: the fingerprint scans are sensitive personal information requiring a specific notice and use-limitation disclosure; the AI résumé screening is exactly the kind of automated decision-making technology the 2026–2027 regulations are aimed at; and every W-4 and direct-deposit form in the payroll system is now personal information an employee can request, correct, or ask to have deleted.
If this group crosses the CPRA's revenue or data-volume thresholds, none of those three systems can keep running exactly as-is without a privacy notice, a documented process for handling employee requests, and — once the ADMT rules phase in — a way to notify applicants that an algorithm is scoring their résumé and let them opt out. None of this requires ripping out the technology. It requires documenting what the technology does and giving employees the visibility and control the law now guarantees them.
Job Applicants Get the Same Protections as Hires
It's easy to think of "employee privacy" as something that starts on day one of employment, but the CPRA's definition of "employee" for these purposes reaches back further than that. Job applicants are covered too, which matters for any business running background checks, resume-parsing software, or pre-employment assessments. A rejected candidate has the same right to know what personal information you collected during the hiring process, and — subject to exceptions like an active legal hold — the same right to ask you to delete it. If your applicant-tracking system keeps rejected résumés indefinitely "just in case," that retention practice is exactly the kind of thing a privacy risk assessment is designed to surface.
Where the Automated Decision-Making Rules Bite Hardest
The ADMT requirements deserve extra attention because they target exactly the tools small businesses adopted to save time on hiring and scheduling: algorithmic résumé ranking, automated interview scoring, shift-scheduling software that assigns hours based on a productivity score, and performance-monitoring tools that flag employees for review without a human in the loop first. None of these tools are banned. But starting January 1, 2027, using them for a "significant decision" — hiring, promotion, discipline, or termination — requires giving the affected person clear notice that ADMT was used, an opt-out right in most cases, and a way to request what factors went into the decision. If your HR stack includes any tool that markets itself as "AI-powered," that's a strong signal it belongs on your risk-assessment list well before the 2027 deadline arrives.
Penalties Are Real, Even for Small Operations
Enforcement here isn't hypothetical. Violations can draw civil penalties of up to $2,500 per unintentional violation and up to $7,500 per intentional violation, and penalties are typically assessed per affected individual — which means a mishandled data request or an unencrypted breach touching a few hundred employee records can add up fast for a business that size. The California Attorney General and the California Privacy Protection Agency both have enforcement authority, and unlike some state laws, California doesn't require a formal cure period before every type of violation.
A Practical Starting Checklist
If you're a covered employer (or think you might be close to the threshold), here's where to start:
- Inventory what you actually collect. Payroll, benefits, biometric time clocks, background checks, performance reviews, applicant-tracking data — get it all in one list before you write a notice about it.
- Flag sensitive personal information separately. SSNs, health information, biometric data, and financial account numbers get extra handling requirements.
- Write (or update) your employee privacy notice to reflect current categories of data, purposes, and retention periods.
- Set up at least two request-submission channels, including a toll-free number if you're required to have one.
- Ask your HR tech and payroll vendors directly whether their tools use automated decision-making for hiring or performance decisions, and get that in writing.
- Calendar the risk-assessment deadline relevant to your business — January 1, 2026 for new high-risk processing, December 31, 2027 for processing that predates the rule.
Keep Your Financial Records as Clean as Your Data Privacy Program
Getting employee data handling right often exposes the same gap that shows up in bookkeeping: nobody can produce a clear, auditable record of what happened and when. The same discipline that makes a privacy request easy to answer — knowing exactly what you have, where it lives, and who touched it — is what makes tax season painless too. Beancount.io gives you plain-text accounting that's fully transparent and version-controlled, so every payroll expense and benefits cost has a clear, auditable trail instead of a black box. Get started for free and see why developers and finance-minded business owners are switching to plain-text accounting.