If you think about all the different ways your personally identifiable information (PII) could be stolen, a system breach, a database leak, or a cyberattack comes to mind. Few people think of their employer being to blame.
Your employer holds a wealth of private information on you and your coworkers. They have your and your family members’ dates of birth, SSNs, addresses, and phone numbers. They also possess your bank routing information, medical insurance records, and even face or fingerprint information for building or department access.
Suddenly, you learn that your HR database was breached after a phishing email. An administrator lost a laptop during the commute. All of that information is out there, in a stranger’s hands. What happens now?
It’s your employer’s responsibility to keep your PII encrypted and protected. In California and the U.S., workers have rights protecting their personal information. California employment laws hold your employer accountable if your private information is stolen or leaked.
California Employment Laws: The Duty of Care
Under California law, employers may run background checks and monitor phone calls, emails, and messages you send as part of your job or while using workplace equipment, such as company phones or laptops. Employers also collect personal information during the hiring process or when enrolling workers in benefits.
This sensitive information must be secured. Laws also require employers to protect their workers’ personal data. It’s mandated under the California Consumer Privacy Act (CCPA). Under this law, consumers and workers have the right to:
Know what information has been collected and how it is used and shared.
Request that certain personal information be deleted at their request
Opt out of transferring personal information to another entity.
Not be discriminated against or retaliated against for exercising any of those rights.
California Civil Code Section 1798.81.5 requires businesses to take all reasonable steps to destroy or arrange for destruction of any personal information that’s no longer needed.
Suppose your employer never got rid of an old external hard drive that stores past employees’ W-2s and direct deposit information. They had no legal or business need for that data, but they put it in a storage room and forgot about it. Someone took it, and now that data is in a stranger’s hands. The company is liable for violating that civil code.
What Classifies as Personal Information Under California Law?
Generally, there are two levels of personal data. Personally identifiable information (PII) and sensitive personally identifiable information (SPII). Both can be damaging in the wrong hands, but SPII is considered more dangerous due to the higher risk of identity theft.
California’s newer law, Generative AI Data (AB 1008), also protects the personal information that’s processed or stored in a business’s internal generative AI system. If the employer uses generative AI to scan and process resumes during hiring processes, the information processed or stored by that system must also be protected.
PII is less sensitive and includes:
- Dates of birth
- Full names
- IP addresses
- Legal addresses
- Phone numbers
SPII is damaging and includes:
- Bank account numbers and routing information
- Biometric information like fingerprints or retinal scans
- Copies of government-issued photo IDs like a driver’s license or passport
- Medical records
- Social Security Numbers
- Data Breach Notification Laws: There’s a 30-Day Clock
- California law also sets a strict deadline for when employers must report breaches or hacks. Under SB 446, businesses have 30 days to notify consumers or workers.
When an employer notifies current or past workers or contractors of a data breach, the following questions must be answered in plain language.
- What happened?
- What information was potentially stolen in the breach?
- What is the company doing?
- What should employees or former employees do?
- Additional information about the breach.
- Who do you contact for more information?
When a data breach affects more than 500 California residents, the employer must also submit a copy of the notification to the California Attorney General within 15 days of notifying affected workers.
Your Rights as an Employee
If your private information is exposed or lost due to your employer’s errors, you’re entitled to several protections under California law. Join a class-action lawsuit related to the breach or talk to an employment law attorney about your rights following a breach.
The California Constitution
The first article of the California Constitution protects your right to privacy.
“All people are by nature free and independent and have inalienable rights. Among these are enjoying and defending life and liberty, acquiring, possessing, and protecting property, and pursuing and obtaining safety, happiness, and privacy.”
When your employer fails to protect your personal information at work, it’s a violation of your rights. You can seek compensation for the anxiety, emotional distress, and fear you experience as you worry about identity theft.
Claims Under Breach of Implied Contract or Negligence
When you sign an employment contract, there’s an implied contract that your new employer will handle your private data in accordance with privacy laws. If your employer’s data security policies are outdated, you can sue for negligence or breach of contract.
Get reimbursed for all financial losses related to the breach, the cost of credit monitoring, and the time spent correcting your credit records.
Damages Under the CCPA
You’re entitled to actual or statutory damages, whichever is greater. As long as the stolen information includes your name and one of the following, you qualify for damages.
- Driver’s license, military, or passport number
- Financial account numbers
- Medical or health insurance information
- Retina, fingerprint, or other biometric data
- SSN
Take Action: What to Do Next
Once you receive notice of a data breach, keep a log and take action to protect yourself. You want to document everything related to the breach, starting with emails and messages you received about it, as well as the time you spent protecting yourself from identity theft.
Freeze Your Credit
Call or go online to freeze your credit with the three major credit bureaus (Equifax, Experian, and TransUnion). This protects you from anyone opening new accounts in your name using your leaked information. Consider freezing your credit with Innovis too.
Monitor Your Financial Accounts
Take time each day to monitor your bank accounts and other financial accounts, as well as those with the IRS, insurance agencies, and credit card companies. If someone accesses an account without your permission, report it immediately to the financial company and note it in your log.
Contact an Employment Attorney
A common fear among employees is the consequence of taking action against your employer. If you file a complaint after receiving a breach notification, can your employer terminate your position or demote you?
California has some of the nation’s strongest whistleblower protections. California Labor Code Section 1102.5 protects workers from retaliation for speaking with government or law enforcement agencies. You have every right to speak with the attorneys at Shegerian Conniff and learn the next steps.
Our attorneys help you navigate the process of filing labor code complaints or CCPA claims to ensure you’re protected during a stressful time. Schedule a free consultation today.

