Saltar al contenido principal

State Employee Data Privacy Laws Are Expanding in 2026: HR's New Risk Assessments and Notice Duties

4 min de lecturaMike ThriftMike Thrift
State Employee Data Privacy Laws Are Expanding in 2026: HR's New Risk Assessments and Notice Duties

Employee data privacy is no longer a consumer-only issue. In 2026, a wave of state laws pulls HR data — applicants, employees, and contractors who reside in California and other covered states — into the same privacy regime as customer data, with risk assessments, minimization, and notice duties that HR must own.

The 2026 Change That Matters Most: CCPA HR Risk Assessments

Effective January 1, 2026, employers subject to the California Consumer Privacy Act (as amended by CPRA) must conduct a privacy risk assessment before engaging in many activities involving HR data — the personal information of job applicants, employees, and independent contractors who reside in California.

The California Privacy Protection Agency requires the assessment for activities that present significant risk to privacy, including:

  • Selling or sharing HR data, processing sensitive personal information (biometrics, precise geolocation, health data), or using automated decision-making (AI screening, productivity scoring)
  • Employee monitoring — keystrokes, email, video, location tracking, and AI tools that score performance or flag misconduct

The assessment must identify the purpose, categories of data, retention, access, and mitigations, and be submitted to the CPPA on request. There is no cure period — a missing assessment is a violation at filing, not after notice.

What Else Goes Live in 2026

  • New comprehensive privacy laws — Indiana, Kentucky, and Rhode Island — effective January 1, 2026. Indiana (INCDPA), Kentucky (KCDPA), and Rhode Island (RIDPA) join the 2025 cohort, each requiring a privacy notice for any business with a website that may collect data from in-state residents — including careers pages that collect applicant data. Rights include access, correction, deletion, and portability; Rhode Island provides no cure period.
  • Amendments in Oregon, Connecticut, and Utah. Effective 2026, amendments expand coverage to additional data types (precise location, children's data) and tighten applicability thresholds — bringing mid-market employers newly in scope.
  • Biometrics and AI. Illinois BIPA, CCPA, and a patchwork of automated-employment-decision-tool (AEDT) laws already regulate facial recognition, fingerprint timeclocks, and AI-driven hiring. HR's use of video interviewing that analyzes facial expressions or voice is high-risk in multiple states.

What HR Must Map Now

  1. Inventory HR data flows. For each system — ATS, HRIS, payroll, timekeeping, benefits, monitoring — list what personal data is collected, where it is stored, who can access it, how long it is retained, and whether it is sold, shared, or used for automated decisions.
  2. Conduct the CCPA risk assessment for any high-risk processing of California residents' HR data before the activity continues in 2026. Use the CPPA's template and keep the assessment with the record of processing.
  3. Update privacy notices. Add a standalone HR privacy notice for California residents (and for new-state residents where required) that discloses categories collected through the careers site, purposes, retention, and rights — separate from the consumer notice.
  4. Minimize and limit. Under Maryland's MODPA (effective Oct 1, 2025) and similar minimization principles spreading to other states, collect only what is proportionate to the HR purpose — a career site that requests full SSN before an offer is over-collection.
  5. Add HR to the data-processing register. HR data breaches now trigger the same notification duties as customer data; incident response must include HR systems.

Bookkeeping Touch

Privacy risk assessments are a compliance cost and a contingency. Track assessment preparation, vendor privacy reviews, and breach-response reserves as distinct postings (Expenses:Compliance:Privacy) so the cost of 2026's new duties is visible — and so a future regulatory inquiry can be answered with a ledger trail, not a memory.

Simplify Your Financial Management

Employee data has become regulated data, with assessments that must precede processing, not follow it. Beancount.io keeps HR-system data maps, assessment dates, and vendor-review postings version-controlled — so the notice you publish matches the data you actually process. Get started for free and make privacy a control, not an afterthought.

Comparte este artículo