Skip to main content

Employee Monitoring Disclosure Laws in 2026: What Small Businesses Must Tell Their Teams

8 min readMike ThriftMike Thrift
Employee Monitoring Disclosure Laws in 2026: What Small Businesses Must Tell Their Teams

If you track when employees log in, which apps they use, where a company vehicle goes, or how many keystrokes they type per hour, a new wave of state laws says you have to tell them — in writing, before you start, and in some states every single year after that. Maine's version just took effect. Connecticut's expanded version lands in October. And a California bill that would have gone even further just died in committee, which itself is a useful signal about where this is headed.

For a small business owner running monitoring software because a remote team makes trust hard to verify by feel alone, "just tell your employees" sounds simple. In practice, the notice requirements are specific enough that a vague line in the employee handbook won't cut it anymore, and the states aren't harmonized — what satisfies New York doesn't automatically satisfy Connecticut.

Here's what actually changed, which states have real (not proposed) requirements, and how to write one policy that clears all of them.

Why This Is Suddenly a Real Compliance Question

Workplace monitoring used to be a niche legal issue mostly relevant to call centers and logistics fleets. Remote and hybrid work changed that. Time-tracking software, keystroke loggers, screenshot tools, GPS on company vehicles, and AI-powered "productivity scoring" are now standard purchases for businesses with fewer than 20 employees — often bought through the same platform that runs payroll.

Lawmakers noticed the gap between how common this monitoring became and how little employees are told about it. Four states currently have laws on the books requiring specific written disclosure before an employer monitors electronic activity: Connecticut, Delaware, New York, and Colorado (the last one through the Colorado Privacy Act rather than a monitoring-specific statute). Maine just became the newest and, notably, one of the strictest — its law, "An Act to Regulate Employer Surveillance to Protect Workers," became law on January 11, 2026, and takes effect this summer.

A California bill, AB 1221, would have gone further still — requiring 30 days' advance notice before deploying any new surveillance tool and banning facial, gait, and emotion-recognition technology outright, with $500-per-violation penalties. It failed to advance in committee in early February 2026. That doesn't mean California employers are in the clear forever; similar bills tend to resurface in the next session once the political and public pressure that produced them hasn't gone away. Treat AB 1221's failure as a preview of a requirement you may face next year, not as a reason to stop paying attention.

What Maine's New Law Actually Requires

Maine's statute (26 M.R.S. § 620-A) is the one to study closely, because it's both the newest and the most detailed model other states are likely to copy next.

Before monitoring begins. An employer can't use "employer surveillance" — defined broadly to cover electronic monitoring of communications, computer or internet activity, and location tracking — without notifying the affected employee first. No 30-day grace period; the notice has to precede the monitoring.

During the hiring process. If you monitor, you have to disclose that fact to candidates during the interview process — before they've accepted the job, not after their first day.

Every single year. Even if nothing about your monitoring practices has changed, Maine requires a fresh written notice to all current employees at least once per calendar year. A policy buried in an onboarding packet from three years ago doesn't satisfy an annual requirement.

Hard limits regardless of notice. Maine doesn't just require disclosure — it prohibits certain monitoring outright. Employers can't surveil an employee's home, personal vehicle, or personal property unless it's genuinely necessary for the job, and employees can refuse to install employer-mandated tracking software on personal devices. Notice doesn't override these limits; you can't disclose your way into monitoring someone's own car.

Enforcement runs through the Maine Department of Labor, with fines of $100 to $500 per violation — modest individually, but they accrue per employee and per incident, which adds up fast for a company with more than a handful of staff.

The Other States You Need to Track

Connecticut already required electronic monitoring notice, and an amendment (Public Act No. 26-73) takes effect October 1, 2026, raising the bar. The notice now has to specify not just what is monitored but where on the premises monitoring happens, and every employee hired after the effective date must get a written, plain-language statement before starting work — not folded into a 40-page handbook.

New York requires written notice before monitoring begins, a signed employee acknowledgment, and a conspicuously posted physical notice in the workplace. Three separate requirements, all mandatory.

Delaware is comparatively flexible: employers can either send a one-time written notice with acknowledgment, or issue a daily electronic reminder each time an employee logs into a monitored system.

Colorado folds monitoring disclosure into its broader privacy act rather than a standalone statute, so the notice obligation is less prescriptive but still real — and it interacts with the state's general data-processing consent requirements.

If your business has employees in more than one of these states — which is increasingly common even for a 10-person company with a couple of remote hires — you're not choosing the strictest single-state policy and calling it done. You're stacking requirements: Maine's annual re-notice, Connecticut's location specificity, New York's posted notice, and Delaware's acknowledgment tracking, all at once for the employees each rule actually covers.

Building One Policy That Clears Every State

You don't need a different monitoring policy per state. You need one policy detailed enough to satisfy the strictest applicable requirement in each category, then apply it everywhere — both because it's simpler to administer and because a inconsistent policy looks worse in any future dispute than a uniformly generous one.

Be specific about method, not just category. "We may monitor computer usage" no longer passes muster anywhere serious. Say plainly whether you track application usage, capture screenshots, log keystrokes, monitor email content, record video, or track GPS location — and note why each one is in use.

Deliver notice in writing, before monitoring starts, with a signature or acknowledgment on file. This single practice satisfies the "before" requirement in Maine, the written-notice requirement in Connecticut and Delaware, and the acknowledgment requirement in New York.

Post a physical or intranet notice even if your state doesn't strictly require it. It costs nothing and covers you if New York-based staff join later or a state adds a posting requirement, which is the direction the trend is moving.

Calendar an annual re-notice, not because every state requires it yet, but because Maine does and doing it everywhere is easier than tracking which employees fall under which rule.

Exclude personal devices and off-duty conduct by default. Both Maine's carve-outs and general privacy-law trends point toward monitoring personal property being the highest-risk category. If BYOD monitoring is genuinely necessary, get separate, explicit, written consent limited to work applications only — don't fold it into your general monitoring notice.

Keep a signed record for every employee, not just a master policy document. If a violation claim comes in, the question regulators and courts ask isn't "did the company have a policy" — it's "did this specific employee receive notice before monitoring began."

Where This Connects to Your Books

Compliance costs money in ways that are easy to lose track of if you're not recording them separately — the monitoring software subscription itself, any legal review of your policy, and the administrative time spent collecting signed acknowledgments across a growing remote team. None of that is dramatic on its own, but bundled into a generic "software" or "legal fees" line, it becomes invisible when you're trying to see what compliance actually costs your business per employee per year. Tagging these costs distinctly in your books — the way you would tag any other regulatory or HR overhead — makes that number visible the next time you're deciding whether a monitoring tool is worth what it costs to run compliantly.

Simplify Your Financial Management

As you build out HR and compliance processes alongside a growing team, keeping clean, well-organized financial records matters just as much as keeping clean HR ones. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article