Is employee keystroke and screen monitoring legal, and can captures be licensed?
Employee keystroke and screen monitoring is often legal in the US when the employer owns the systems and gives any notice a state requires, but licensing the captures is a separate decision. Screens expose personal and customer data, so SourceX scopes them strictly, and many companies license structured logs instead.
Is employee keystroke and screen monitoring legal?
Often yes in the United States, if the employer owns the systems, gives clear notice where a state requires it, and does not capture communications it has no right to. But legal to monitor is not the same as appropriate to license. Screen and session captures show whatever was on the screen, including personal messages, passwords, medical portals and customer data, so SourceX scopes them strictly before anything is considered.
There is no single federal rule for workplace monitoring, which is why the answer varies by state and by what the tool captures. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Why do AI buyers care about activity captures?
AI is moving from models that answer questions to agents that perform tasks. Training and evaluating those agents needs records of real work: which tools were opened, in what order, what was typed or clicked, and what the outcome was. Screen recordings and session logs are one of the few places that sequence is recorded, so they attract buyer interest.
That interest is exactly why caution is needed. A recording of a workday contains far more than the task: private chats, benefits portals, personal banking tabs and client records.
What legal layers apply to monitoring?
| Layer | What it addresses | What to check |
|---|---|---|
| Federal wiretap law | Intercepting communications; one-party consent | See ECPA for employers |
| State notice statutes | Several states, including New York, Connecticut and Delaware, have statutes that require employers to give employees notice of electronic monitoring in defined circumstances | Read the current statute and confirm which states your employees work in |
| State privacy statutes | Personal information of residents, sometimes including employees | Notices at collection and purpose limits |
| Employment and labor law | Protected activity, union communications, off-duty conduct | Employment counsel |
| Contracts | Client confidentiality, security addenda | Client agreements |
Treat the state row with care: statute text and effective details change, so confirm it against the official legislative source rather than relying on a summary.
What does a capture reveal that a normal record does not?
- Screens with other people's data. A support agent's screen shows a customer account; an accountant's shows a client return.
- Credentials and secrets. Keystroke logs can contain passwords and API keys unless removed.
- Personal activity. Personal email, messaging and health or banking sites opened on a work machine.
- Protected activity. Messages about pay, safety or union matters.
- Health details. An employee opening a benefits or leave portal; see whether employee health information is PHI.
How SourceX scopes captures
Redaction and exclusion rules are agreed with the company before any work begins, and data is delivered only after an executed agreement and the company's authorization. For activity captures that typically means asking counsel and the company:
- Which tools captured the data, for which employees, and for which dates?
- What notice and acknowledgment did those employees receive?
- Can sessions be filtered to approved applications so personal browsing is excluded?
- Can keystroke content be removed while keeping action sequences and timestamps?
- Which clients' screens appear, and do their contracts allow use?
- Should the capture be excluded and only structured tool logs kept?
Many companies conclude that structured logs, tickets and workflow histories carry most of the value with fewer risks. The default exclusion list is a starting point. A data map shows which monitoring tools exist in the first place.
Pre-license checklist for monitoring data
- Written monitoring policy with signed acknowledgments by year and location
- Inventory of capture tools and how long data is kept
- State-by-state list of where monitored employees worked
- Employee notice documents; see the California employee notice template
- Rules for removing credentials, personal sites and client screens
- Clause review of the electronic communications policy
- Counsel sign-off on whether captures are in scope at all
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Treating legal monitoring as permission to license | Different legal question | Ask counsel about disclosure separately |
| Keeping raw screenshots | They expose clients and personal activity | Prefer structured logs |
| Relying on an old policy | May not cover new uses | Review wording and dates |
| Forgetting client promises | FTC staff have said promises about data use are enforceable (staff guidance, not a rule) | Check client contracts and privacy statements |
What to say to an owner
Illustrative example
Illustrative: a fictional 90-person engineering services firm used a productivity tool that took screenshots every few minutes for two years. The owner is tempted to include them. Counsel notes that screenshots show client drawings and employees' personal tabs, that one office lacked a signed acknowledgment, and that only some applications were relevant. The company instead licenses application usage logs and ticket histories, which can be filtered cleanly. The screenshots are deleted under the retention schedule rather than shared.
Questions to ask your counsel
- Which states have notice or consent rules for the employees we monitored, and do our acknowledgments meet them?
- Does our policy describe disclosure to outside parties, or only internal use?
- Can captures be filtered to approved applications before anyone outside the company sees them?
- Are there any union, works-council or protected-activity issues in the captured population?
- Should captured data be deleted under our retention schedule instead of kept?
What this means for referral partners
Do not ask to see captures, and do not describe how a company monitors staff. If an owner says "we record screens", note it as a topic for the company's counsel and move to the broader screen: years of records, many systems, an authorized sponsor and rights to license. Employees rarely expect their screens to leave the company, which is a reason to be conservative.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed.
Red flags
- Employees were never told about monitoring.
- Captures include personal devices.
- The tool vendor claims rights in the recordings.
- Monitored staff include people in states with stricter rules and no local notice was given.
Next step
Screen the company first with the company fit checker, then read how SourceX referrals work. If it looks like a fit with 50+ full-time employees at peak (contractors excluded), register as a partner and make the introduction.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can an employer record employees' screens without telling them?
Rules vary by state. Some states require written notice of electronic monitoring, and other laws can apply depending on what is captured. Employers should have a written policy and acknowledgments. Employment counsel should confirm the requirements for each location before any capture is used for any new purpose.
Is it legal for a company to license employee activity data to AI developers?
There is no single answer. It depends on what was captured, what employees were told, state law and contracts with clients. Many companies exclude screen captures and keep structured logs. Counsel decides what, if anything, is eligible, and SourceX scopes strictly.
Does a monitoring policy cover AI training use?
Not necessarily. A policy written to cover security or productivity may not describe disclosure to third parties for AI development. Counsel reviews the wording and may recommend narrowing the scope, adding notices going forward, or excluding the data.
What is safer to license than screen recordings?
Structured records with clearer boundaries, such as ticket histories, workflow logs, SOPs and decision records with outcomes, are easier to filter and redact. They still need rights and privacy review, but they avoid capturing the personal and third-party content that appears on screens.
Should a referral partner ask a prospect about employee monitoring?
Only to note it as an item for the company's counsel. Partners make introductions and share basic fit information, and never ask to see or describe captured data. The fit screen is about size, history, breadth of systems, rights and an authorized sponsor.
Related pages
- Data mapping for privacy compliance that doubles as data licensing prep
- ECPA for employers: the Wiretap Act, the Stored Communications Act and consent to disclose
- How SourceX US company data referrals work
- Is employee health information in HR files protected health information?
- Electronic communications policy template: clauses to adopt before licensing
- Employee privacy notice template for California employers, clause by clause
Free resources
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- Days sales outstanding calculator — How many days customers take to pay.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment