The California Privacy Rights Act is the 2020 ballot measure that substantially expanded California's existing consumer privacy law. For employers, its most consequential effect was allowing the temporary exemption for employee and applicant data to expire on January 1, 2023 — bringing workforce information fully within scope for covered businesses.
It also created a dedicated regulator, added a category of sensitive personal information with its own restrictions, introduced a right to correct, and imposed requirements on contracts with service providers.
Before 2023, covered employers had limited obligations toward employee data — essentially a notice at collection and the breach-related private right of action. Since then, employees, applicants, and independent contractors hold substantially the same rights as consumers.
In practice that means an employer must be able to tell an employee what personal information it holds about them, correct it if inaccurate, delete it on request subject to the many exceptions that apply to employment records, explain how long it is retained, and honor limits on the use of sensitive information.
The operational burden is larger than the legal statement suggests. Answering "what do you hold about me" requires knowing every system and vendor holding that person's data. Employers whose workforce data is spread across an HRIS, a payroll provider, a benefits administrator, a training platform, spreadsheets, and email cannot answer accurately — a compliance failure produced by data sprawl rather than by policy.
The law defines a category carrying additional restrictions, and ordinary HR files are full of it: Social Security numbers, driver's license numbers, financial account details, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of communications, health information, and biometric data used for identification.
Individuals may direct a business to limit use of this data to what is necessary to provide the service. In an employment setting, most uses are necessary for the employment relationship, but employers should be able to explain why each collection is necessary — which requires having considered it.
Employers using biometric timekeeping, GPS-enabled field applications, or collecting demographic data are handling sensitive personal information whether or not they have classified it as such. Biometric data in particular carries obligations under multiple overlapping frameworks and warrants specific review.
The law requires disclosing retention periods or the criteria used to determine them, and reflects a principle that data should not be kept longer than reasonably necessary for the disclosed purpose.
This sits awkwardly against employer practice, where "keep everything indefinitely" remains common and is genuinely difficult to defend. It also sits against real record-keeping obligations — payroll records, tax filings, I-9s, safety records, benefits documentation — that require retention for defined periods.
The reconciliation is a documented retention schedule mapping each category to its required period and applying deletion at the outer limit. The most exposed category is usually applicant data for people never hired, which frequently accumulates with no schedule at all.
The law imposes specific contractual requirements on arrangements with vendors processing personal information on a business's behalf. Agreements must include defined terms restricting the vendor's use of the data to the specified purposes, prohibiting retention or use for the vendor's own purposes, requiring equivalent obligations on subcontractors, and permitting the business to take steps to ensure compliance.
Employer agreements with payroll, benefits, HRIS, and screening providers predating these requirements frequently lack the necessary terms. Reviewing and amending those contracts is unglamorous work that carries real exposure if skipped, because a vendor arrangement lacking required terms can affect how data sharing is characterized.
The measure created the California Privacy Protection Agency, giving the state a dedicated regulator with rulemaking and enforcement authority alongside the attorney general. Administrative penalties apply per violation, with higher amounts for intentional violations and those involving minors.
The separate private right of action for breaches of unencrypted personal information remains the sharpest exposure for most employers, because it permits statutory damages without proof of harm on a per-individual basis. For an employer, an HR data breach involving unencrypted employee records can therefore produce claims from the entire affected workforce.
California privacy requirements continue to develop through regulation and enforcement activity, so an employer's position should be confirmed against current rules rather than a point-in-time assessment.
Employer's Guardian helps employers work through these obligations alongside their other state requirements through California HR compliance, including workforce notices, retention practices, and vendor arrangements.
This article provides general educational information, not legal advice. Privacy obligations depend on your specific circumstances and change over time. Consult qualified counsel before making compliance decisions.