HR News | Employer's Guardian

California Consumer Privacy Act (CCPA): What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

The California Consumer Privacy Act is California's core consumer privacy law, enacted in 2018 and substantially expanded by the California Privacy Rights Act. For employers, the detail that matters most is one that took effect on January 1, 2023: the temporary exemption for employee and applicant data expired. Since then, information an employer collects about its own workforce has been treated much like information collected about a customer.

That change caught a large number of California employers unprepared, and many are still operating on the pre-2023 assumption that HR data sits outside the law's scope.

Which employers are covered

The law does not apply to every business. It applies to for-profit entities doing business in California that meet at least one threshold: annual gross revenue above a set amount, buying or selling or sharing the personal information of a large number of California consumers or households, or deriving a majority of annual revenue from selling or sharing personal information.

Two points are commonly misread. First, the revenue threshold is based on total business revenue, not California revenue, so an employer headquartered elsewhere with a modest California workforce can still be covered. Second, "consumers" under the statute includes California residents generally, which since 2023 means employees, applicants, and independent contractors count toward the analysis. The specific thresholds are adjusted over time, so an employer near a boundary should confirm current figures rather than rely on a remembered number.

What covered employers owe their workforce

The obligations fall into two broad groups. The first is disclosure. Employers must provide a notice at collection, at or before the point of collecting personal information, describing the categories collected, the purposes, and the retention period or the criteria used to determine it. In an employment context this generally means a workforce-facing privacy notice delivered during onboarding and maintained thereafter.

The second group is a set of individual rights the employer has to be able to honor:

  • Right to know what personal information has been collected, used, disclosed, and to whom
  • Right to delete personal information, subject to significant exceptions where the employer must retain records
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to limit the use and disclosure of sensitive personal information
  • Right to non-retaliation for exercising any of the above

The deletion right is the one that most often causes confusion. Employers are subject to numerous retention obligations — payroll records, I-9s, tax filings, safety records, benefits documentation — and those obligations generally take precedence. The practical requirement is not to delete everything on request but to have a defensible, documented basis for what is retained and why.

Sensitive personal information in the HR context

The law defines a category of sensitive personal information carrying additional restrictions, and ordinary HR files are full of it: Social Security numbers, driver's license numbers, financial account details, precise geolocation, racial or ethnic origin, union membership, health information, and biometric data. Employers using biometric timekeeping, GPS-enabled field applications, or collecting demographic data for reporting purposes are handling sensitive personal information whether or not they have classified it that way.

The breach exposure that carries the sharpest teeth

Most enforcement runs through California's regulators. But the statute also provides a private right of action for individuals whose non-encrypted, non-redacted personal information is exposed through a breach resulting from a failure to maintain reasonable security. That provision allows statutory damages without proof of actual harm, and it applies on a per-individual basis, which is what makes it viable as a class action.

For an employer, the practical consequence is direct: an HR data breach involving unencrypted employee records can produce claims from every affected employee. Encryption of employee data at rest is therefore not merely a security preference — it bears on whether that exposure is available at all.

Where employers most often fall short

  • No workforce privacy notice, or one that was written for customers and never adapted
  • No inventory of what employee data is held, where it lives, or which vendors receive it
  • No defined process for receiving and responding to an employee rights request within required timeframes
  • Vendor agreements with payroll, benefits, and HRIS providers that lack required contractual terms
  • Retention practiced as "keep everything indefinitely," which is difficult to defend under a law built around purpose limitation
  • Applicant data from candidates never hired, retained without a schedule

A reasonable starting sequence

Employers that are behind generally get furthest fastest by working in this order: determine whether the thresholds are met; inventory what workforce data is held and which vendors touch it; issue or update the notice at collection; establish a documented rights-request process with an owner and a timeline; review vendor contracts for required terms; and set a retention schedule that reconciles privacy obligations against the record-keeping rules employers are separately subject to.

Privacy requirements in California continue to evolve through regulation and enforcement activity, so an employer's position should be confirmed against current rules rather than a point-in-time assessment.

Employer's Guardian helps employers work through these obligations alongside the rest of their state-specific requirements through California HR compliance, including workforce notices, retention practices, and vendor arrangements.

This article provides general educational information, not legal advice. Privacy obligations depend on your specific circumstances and change over time. Consult qualified counsel before making compliance decisions.