Workers (employees and applicants):
- You would have to be told what employee data your employer collects and how it’s used.
- You could request and receive your data within 30 days and ask that incorrect or incomplete data be fixed.
- If an employer uses data to make a hiring, firing, or other work decision, you would be told the categories of data used and get at least 7 days to review and request reconsideration.
- Employers could not collect information about your off‑duty activities in many common off‑duty places (home, restrooms, lactation spaces, religious spaces).
- You could sue an employer for violations and seek damages, injunctive relief, and attorney’s fees.
Employers (private and many public employers):
- You must stop certain kinds of data collection and restrict how you use and keep worker data.
- You must publish clear disclosures and maintain records, provide access and correction processes, and delete most data three years after separation (unless law requires longer retention).
- You cannot sell employee data. Transfers to outside vendors require worker opt‑in and encryption.
- You may face investigations by the new Division, state enforcement actions, and private lawsuits with statutory damages for violations.
Service providers and third parties:
- Vendors that process employee data must follow contractual requirements and may be treated as causing employer liability if they violate the rules.
- Transfers to third parties are mostly barred.
Government agencies and public employers:
- Several categories of public employers are covered. The bill assigns enforcement roles for specific federal entities (e.g., Comptroller General for GAO).
- The Department of Labor would establish a new division and produce annual reports on workplace surveillance.