Establishing secure connection…Loading editor…Preparing document…

Employee Privacy Information Sheet

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

EMPLOYEE PRIVACY INFORMATION SHEET (HANDOUT)

Drug and Other Testing and Electronic Monitoring

I. Drug Testing

A. How might drug testing infringe upon employees’ privacy interests?

B. Applicable laws

1. Drug Free Workplace Act of 1988 (federal)

a) applies to federal contractors and grantees;

b) requires discouragement of drug use but does not require or regulate drug testing.

2. Certain federal statutes require employers in certain industries (e.g., over-the-road trucking) to drug-test certain categories of employees

3. Special state statutes (23 states): Some require drug testing of certain categories of employees; some limit drug testing to protect employee privacy; some states regulate methods of drug testing.

4. Some cities (e.g., San Francisco) by ordinance restrict private-sector drug testing.

5. Americans with Disabilities Act

a) Does not prohibit most drug testing. However, the testing program must be designed carefully so as to avoid revealing statutorily-covered disabilities;

b) Does not protect current drug users. Protects former users, or people who are erroneously believed to be former users. Even those protected, however, can be tested for drugs on the same terms as other employees.

6. Common law claims

a) Public Policy Tort: Private sector drug testing that contravenes constitutional restrictions on drug testing may be challenged in some states under tort as a violation of public policy.

b) Intentional Infliction of Emotional Distress

(1) Elements

(a) Intent to inflict emotional distress

(b) Extreme and outrageous conduct

(c) Causation

(d) Severe emotional distress

(2) Might be used to challenge extremely offensive method of drug testing.

c) Contract claims: A positive drug testing may not necessarily constitute just cause for discharge, much less willful breach necessary to terminate a stated term contract. Would depend on terms of contract.

7. Federal and some state constitutions restrict some drug testing.

a) Federal constitution applies only to state actors.

(1) 4th Amendment doctrine recognizes drug testing as a search. But the Supreme Court allows much suspicionless drug testing.

(2) Federal 4th Amendment cases on drug testing have been considered persuasive precedent by many courts construing state constitutions and other sources of privacy protection.

b) California and six other states have constitutional provisions that might apply to private sector drug testing.

c) Constitutions with state action requirements might be basis for public policy tort against a private sector employer. E.g., Alaska.

C. Principal method of analysis under the privacy tort

1. First step: “Serious” or “highly offensive” invasion of a legally protected privacy interest

2. Second step: Is there a reasonable expectation of privacy?

3. Third step: Justification

a) Standard used to assess justification: something less than the “narrowly tailored to serve a compelling governmental interest” standard

b) What are the employer interests in drug testing?

II. Polygraphs

A. How might they invade autonomy or informational privacy interests?

B. Sources of regulation

1. Federal regulation: Employee Polygraph Protection Act of 1988

a) Prohibits employers from “accepting or using” polygraphs or applicants except in specified circumstances;

b) Allows polygraphs in investigation of economic loss or misappropriation

(1) Can only ask employees who are reasonably suspected of involvement in a workplace incident that results in economic loss or injury to employer’s business

(2) Cannot ask degrading questions, or questions regarding religious, racial, political, sexual, or union beliefs;

c) Exempts public employers, national defense and security contractors, security firms, and drug firms;

d) Does not preempt more restrictive state law.

2. State statutes: Some states specifically regulate certain forms of testing. For example, California Labor Code § 432.2 prohibits employers from demanding or requiring employees or applicants to submit to polygraph. California Penal Code § 637.3 also prohibits use of “voice stress analysis” without express written consent of employee.

III. Integrity Testing

A. How might integrity testing implicate informational and autonomy privacy?

B. Sources of regulation

1. Federal law: ADA prohibits psych testing to extent it is designed or used to identify mental disabilities, unless employer can demonstrate that freedom from that disability is an essential function of job.

2. State law

a) Some states (Massachusetts, Minnesota, Rhode Island, Wisconsin) prohibit use of psych tests as employment screening device.

b) Other states (California) rely on common law or constitutional claims.

Privacy tort:

(1) Highly offensive invasion: in what respects do psychological or honesty tests invade privacy?

(2) Reasonable expectation of privacy: what is the expectation of privacy, and does it vary depending on the nature of the employment, the nature of the questions asked, or whether the test is administered to applicants rather than employees?

(3) Justification: Note that Soroka adopted a compelling interest standard. A subsequent decision (Loder v. City of Glendale) adopted a lesser “carefully weighs the pertinent interests at stake in an ordered fashion” standard.

IV. Electronic Monitoring

A. Introduction and Overview -- Searching email or computer files:

Comparing electronic and physical searches

1. Expectation of privacy: Do employees have the same expectation of privacy in their email and computer files as they do in their office and regular files?

2. What counts as a sufficient justification?

3. Should a blanket consent as a condition of employment obviate any legal restrictions?

4. See below under Electronic Communications Act and Stored Communications Act for federal regulation.

B. Monitoring - audio, video, computer

1. Invasion of Privacy

a) What is the expectation of privacy?

b) What are the purposes of audio or video monitoring? Deterrence or actual detection? How should this affect the issue of justification?

2. Telephones and audio taping

a) Omnibus Crime Control Act (the so-called Wiretap Act) prohibits electronic monitoring by employers but has exception for listening to an extension phone “in the ordinary course of business.”

b) State laws

(1) California Penal Code § 632 prohibits tape recording conversation without consent of both parties.

(2) Texas state law prohibits tape recording a conversation without the consent of one party

3. Video recording

a) Cal. Lab. Code § 435 prohibits employer from making audio or video recording of employee restrooms or changing rooms.

b) Federal labor law prohibits filming of employees engaged in concerted activity for mutual aid or protection unless necessary because of genuine threat to safety.

4. The Electronic Communications Privacy Act and the Stored Communications Act

a) 18 U.S.C. § 2511 prohibits intentional interception and disclosure of electronic communications, but it exempts person or entity that provides electronic communication service. Thus, if employer is the email provider, it may intercept and disclose messages. In addition, allows interception in “ordinary course of business.”

b) 18 U.S.C. § 2701 prohibits intentionally accessing stored electronic communication, but allows it if authorized by the person or entity providing the service.

c) If the employee consents to monitoring, the employer can freely intercept messages in transit or access and read messages that are stored, thus obviating the task of distinguishing interception from other access, and of determining whether employer is the provider of the service. Consent also eliminates the need to decide whether the employer can rely on the “ordinary course of business” exception. So the crucial question is: what constitutes consent?

(1) If employee consent allows all monitoring, and if consent can be found simply from the existence of an employer policy of monitoring, then there will be no privacy protections for employees if employers get competent legal advice.

(2) Express consent appears to suffice, even when consent must be given as a condition of employment. TBG Ins. Servs. Corp. v. Superior Court, 117 Cal. Rptr. 2d 155 (Cal. App. 2002). Employee signed “policy statement” that he would use computers “for business purposes only and not for personal benefit or non-Company purposes” and that he consented to have his computer “use monitored by authorized company personnel” on an “as needed” basis. Employer fired employee; employer alleged it was for viewing pornography, employee alleged to prevent stock from vesting. In employee’s wrongful termination suit, employer sought discovery of employee’s home computer (which employer had given to employee). Court held computer was discoverable and that employee had no expectation of privacy.

(3) Implied consent was rejected in old cases involving telephone monitoring; legal status of implied consent under Electronic Communications Privacy Act unclear. No consent found where employer had announced policy of monitoring sales calls and said personal calls would not be monitored except to extent necessary to determine nature of call, and no consent found in case in which employees were told “might be forced to monitor calls” if excessive personal calls were not reduced.

 

Signature

 

Date

Enter text✕

What the Employee Privacy Information Sheet Is and When it Applies

The Employee Privacy Information Sheet is an internal disclosure used by employers to explain what personal data the company collects about workers, why it is collected, how it will be used and shared, retention periods, and employees' rights. It documents consent and notice for personnel records, payroll, benefits, background checks, and any special categories (health or biometric data). The sheet helps HR meet federal and state electronic record rules and privacy obligations, and it can be delivered in paper or electronic form consistent with ESIGN (15 U.S.C. ch. 96) and applicable state law.

Why a Clear Privacy Sheet Matters for Employers and Employees

A concise privacy disclosure reduces legal risk, supports regulatory compliance (HIPAA, CCPA, state privacy laws), and improves transparency about data handling. It documents employee consent where required, clarifies retention and access procedures, and helps standardize HR workflows across hires, transfers, and terminations.

Why a Clear Privacy Sheet Matters for Employers and Employees

Who Prepares and Who Receives This Sheet

Use targeted distribution lists and version control to ensure the right sheet reaches each employment category.

  • HR administrators and HRIS teams responsible for personnel records and onboarding processes.
  • Managers and business-unit leads who collect employee data for operational purposes.
  • Employees and contractors who must be informed of collection, use, and retention practices.

Essential Sections to Include on the Employee Privacy Information Sheet

A professional sheet groups information clearly and includes scope, categories of data, legal basis, uses and disclosures, retention, and contact procedures for privacy questions or complaints.

Scope

Describe which workers are covered (employees, contractors, applicants), employment stages included, and whether the policy covers corporate affiliates.

Data Categories

List personal identifiers, contact details, payroll and tax data, benefits and health information, background check results, and any biometric or sensitive categories.

Purpose and Uses

Explain why each category is collected — payroll, benefits administration, compliance, safety, performance management, or security.

Third-Party Sharing

Identify classes of recipients (payroll vendors, benefits carriers, government agencies) and circumstances for disclosures.

Retention

State retention periods, archival rules, and how records are disposed of after legal holds or retention end.

Employee Rights

Explain access, correction, deletion where applicable, withdrawal of consent, and dispute procedures; include contact information for privacy inquiries.

How to Complete and Return the Sheet

Follow these steps to ensure accurate completion and timely submission.

  • 01
    Download or open: Open the current template provided by HR or via the employer portal.
  • 02
    Fill required fields: Complete all mandatory fields and verify spellings and numbers.
  • 03
    Sign and date: Sign electronically or in ink per employer instructions; include the date.
  • 04
    Submit to HR: Return via the secure upload link, HR email, or in-person delivery as directed.

Configuring an Online Workflow for the Sheet

Set up a repeatable digital process to route, authenticate, and archive completed sheets.

Field Configuration
Signing Method Electronic signature enabled; ESIGN-compliant
Authentication Email link or SMS code; add MFA for sensitive roles
Notifications Auto-notify HR and employee on completion
Storage Encrypted archive with access controls

Where the Completed Sheet Goes and Who Sees It

Routing should be limited to essential recipients and logged for audit purposes.

  • HR Records: Primary repository for personnel files and benefits processing.
  • Payroll Vendor: Share only payroll-relevant fields under a written data-processing agreement.
  • Benefits Carrier: Transmit required enrollment data securely for benefits administration.
  • Legal/Compliance: Provide access on a need-to-know basis for audits or legal holds.

Technical Requirements for Secure eSubmission

Ensure the vendor offers encryption in transit and at rest, role-based access, and a clear audit trail for each submission.

  • File formats: PDF, DOCX accepted; preserve original timestamps.
  • Authentication: Email + SMS OTP or SSO for stronger assurance.
  • Integrations: Connectors to HRIS and payroll systems.

Recommended Distribution and Response Timelines

Provide the sheet at hire, when collecting new categories of data, and after material changes to privacy practices.

At hire:

Issue on or before the first day of employment.

Policy changes:

Distribute within 30 days of a significant change to data practices.

Periodic review:

Review and reconfirm consent annually or as required by policy.

Employee updates:

Employees should return corrected sheets within 14 calendar days of change.

Record access requests:

Acknowledge access requests per state law timelines, typically within 30–45 days.

Key Processing Milestones from Issue to Archive

Track milestones so each sheet completes its lifecycle with required approvals and archival.

01

Issue to employee

Employer issues initial sheet at onboarding.

02

Employee completion

Employee fills and signs the sheet.

03

HR review

HR verifies entries and requests corrections if needed.

04

Secure archive

Store final copy in encrypted personnel records.

Common Mistakes to Avoid When Preparing or Submitting the Sheet

  • Failing to specify data categories clearly, which leads to inconsistent collection and later disputes over scope.
  • Using unclear retention language that conflicts with legal requirements or other company records retention policies.
  • Collecting more sensitive data than necessary without documenting legal basis or security measures for processing.
  • Relying on weak authentication for e-signatures where stronger verification is required for sensitive health or payroll data.

Typical Data Elements Captured on the Sheet

Name: Full legal name
Contact: Phone and email
Identifiers: Employee ID or SSN (if needed)
Health Data: HIPAA-protected details
Biometrics: Fingerprint or facial data
Consent Flags: Acknowledgments and opt-ins

Regulatory Risks and Potential Penalties for Noncompliance

HIPAA Violations: Civil and criminal penalties
CCPA Noncompliance: Statutory fines and private right exposure
I-9 Errors: Penalties for incomplete employment verification
Data Breach Costs: Notification and remediation expenses
State Privacy Fines: Variable administrative penalties
Reputational Risk: Employee trust erosion

Typical eSignature Pricing and Feature Comparison

Vendor pricing and feature availability vary by plan; signNow is listed first for comparison across common plan criteria.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Realistic Use Examples for an Employee Privacy Information Sheet

Two brief scenarios show how the sheet works in common organizational settings.

Healthcare Clinic Example

A clinic issues the sheet during onboarding to document PHI handling and Business Associate Agreements

  • Clinic requires signed acknowledgment before scheduling procedures
  • The sheet clarifies PHI purposes, references HIPAA safeguards, and records consent to electronic delivery to meet audit and retention obligations.

Real Estate Firm Example

A property management company provides the sheet to leasing staff and contractors

  • HR collects emergency contact and background-check consent
  • The document explains tenant data sharing, vendor access limits, and retention rules tied to property management and leasing cycles.

Frequently Asked Questions About the Employee Privacy Information Sheet

Answers to common questions about legality, electronic delivery, updates, access, and revocation.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users