This bill, known as the "Stop Spying Bosses Act," seeks to establish comprehensive regulations governing how employers collect, use, and transfer employee data. It defines "employee data" broadly to include personally identifiable information, workplace activities, communications, device usage, biometric information, and even online activity. The legislation applies to most employers with 11 or more covered individuals, including applicants, and aims to protect workers from intrusive surveillance practices. The bill explicitly prohibits employers from collecting or using employee data for specific purposes, such as identifying individuals involved in labor organization activities or monitoring off-duty conduct, including in sensitive areas like restrooms or at home. It also forbids collecting data to ascertain political opinions, religious views, health status unrelated to job duties, or immigration status. Furthermore, employers are barred from using data to predict behavior unrelated to work or to threaten a covered individual's mental or physical health. Permissible data collection is strictly limited to purposes like enabling essential job functions, ensuring quality, conducting periodic performance assessments, complying with laws, protecting health and safety, or administering wages and benefits. Any such collection must be strictly necessary, the least invasive means, limited to the fewest individuals, and involve the least amount of data. Data retention is capped at three years after an individual's separation or application discontinuation, unless otherwise required by law. The bill imposes significant restrictions on the transfer of employee data. Employers and their service providers are expressly prohibited from selling or licensing employee data. Transfers to service providers are only allowed if the covered individual opts in, and the employer provides disclosure and cybersecurity protections. Transfers to third parties are generally forbidden, except where required by law. Employers are mandated to provide extensive disclosures to covered individuals about their data collection practices. These disclosures must detail what data is collected, how and when it's collected, its storage location, who has access, and the specific purposes for its use. Crucially, employers must also explain how this data affects work-related decisions, such as performance assessments, and provide these disclosures in an accessible, plain language format at hiring or before an application is accepted, with updates for any changes. Covered individuals are granted the right to access any data collected on them within 30 days of a request and to have incomplete or erroneous data updated or corrected. If a work-related decision is made using employee data, the employer must disclose the categories of data used and allow the individual to review their data, compare it with aggregated data of similarly situated individuals, and request reconsideration of the decision based on corrections. To oversee these provisions, the bill establishes a new Worker Protection and Technology Division within the Department of Labor, headed by an Administrator. This division will be supported by various advisory boards composed of experts in consumer protection, privacy, labor, technology, and other relevant fields. The Secretary of Labor, through this division, is authorized to issue orders and guidance and conduct investigations to ensure compliance. The bill provides robust enforcement mechanisms, including investigative authority for the Secretary of Labor, similar to the Fair Labor Standards Act. It also creates a private right of action , allowing adversely affected covered individuals and labor organizations to file civil lawsuits. Successful plaintiffs can receive significant relief, including actual damages, statutory damages ranging from $500 to $100,000 depending on the violation, injunctive relief, equitable relief, and attorney's fees. Strong whistleblower protections are included, prohibiting employers from discriminating or retaliating against individuals for exercising their rights under the Act or reporting violations. Employers must provide notice of these protections. State attorneys general and privacy regulators are also empowered to bring civil actions on behalf of their residents, seeking injunctions, damages, and civil penalties. Notably, the bill invalidates any predispute arbitration agreements or predispute joint-action waivers concerning alleged violations of its provisions. The Secretary, through the Administrator, is also required to conduct and annually report on studies regarding workplace surveillance and employee data collection, offering recommendations to Congress and the President. The Act emphasizes coordination with other federal and state agencies and explicitly states that it does not preempt existing federal or state laws unless otherwise provided.
This bill, known as the "Stop Spying Bosses Act," seeks to establish comprehensive regulations governing how employers collect, use, and transfer employee data. It defines "employee data" broadly to include personally identifiable information, workplace activities, communications, device usage, biometric information, and even online activity. The legislation applies to most employers with 11 or more covered individuals, including applicants, and aims to protect workers from intrusive surveillance practices. The bill explicitly prohibits employers from collecting or using employee data for specific purposes, such as identifying individuals involved in labor organization activities or monitoring off-duty conduct, including in sensitive areas like restrooms or at home. It also forbids collecting data to ascertain political opinions, religious views, health status unrelated to job duties, or immigration status. Furthermore, employers are barred from using data to predict behavior unrelated to work or to threaten a covered individual's mental or physical health. Permissible data collection is strictly limited to purposes like enabling essential job functions, ensuring quality, conducting periodic performance assessments, complying with laws, protecting health and safety, or administering wages and benefits. Any such collection must be strictly necessary, the least invasive means, limited to the fewest individuals, and involve the least amount of data. Data retention is capped at three years after an individual's separation or application discontinuation, unless otherwise required by law. The bill imposes significant restrictions on the transfer of employee data. Employers and their service providers are expressly prohibited from selling or licensing employee data. Transfers to service providers are only allowed if the covered individual opts in, and the employer provides disclosure and cybersecurity protections. Transfers to third parties are generally forbidden, except where required by law. Employers are mandated to provide extensive disclosures to covered individuals about their data collection practices. These disclosures must detail what data is collected, how and when it's collected, its storage location, who has access, and the specific purposes for its use. Crucially, employers must also explain how this data affects work-related decisions, such as performance assessments, and provide these disclosures in an accessible, plain language format at hiring or before an application is accepted, with updates for any changes. Covered individuals are granted the right to access any data collected on them within 30 days of a request and to have incomplete or erroneous data updated or corrected. If a work-related decision is made using employee data, the employer must disclose the categories of data used and allow the individual to review their data, compare it with aggregated data of similarly situated individuals, and request reconsideration of the decision based on corrections. To oversee these provisions, the bill establishes a new Worker Protection and Technology Division within the Department of Labor, headed by an Administrator. This division will be supported by various advisory boards composed of experts in consumer protection, privacy, labor, technology, and other relevant fields. The Secretary of Labor, through this division, is authorized to issue orders and guidance and conduct investigations to ensure compliance. The bill provides robust enforcement mechanisms, including investigative authority for the Secretary of Labor, similar to the Fair Labor Standards Act. It also creates a private right of action , allowing adversely affected covered individuals and labor organizations to file civil lawsuits. Successful plaintiffs can receive significant relief, including actual damages, statutory damages ranging from $500 to $100,000 depending on the violation, injunctive relief, equitable relief, and attorney's fees. Strong whistleblower protections are included, prohibiting employers from discriminating or retaliating against individuals for exercising their rights under the Act or reporting violations. Employers must provide notice of these protections. State attorneys general and privacy regulators are also empowered to bring civil actions on behalf of their residents, seeking injunctions, damages, and civil penalties. Notably, the bill invalidates any predispute arbitration agreements or predispute joint-action waivers concerning alleged violations of its provisions. The Secretary, through the Administrator, is also required to conduct and annually report on studies regarding workplace surveillance and employee data collection, offering recommendations to Congress and the President. The Act emphasizes coordination with other federal and state agencies and explicitly states that it does not preempt existing federal or state laws unless otherwise provided.