A wearable tech policy is the written rule book for any device your company puts on an employee’s body or clothing. It says which devices are covered, what they may measure, who sees the readings, how long the data is kept, and what happens when someone says no.
The reason to write one in 2026 has changed. Employers briefly had a federal cheat sheet. In December 2024 the U.S. Equal Employment Opportunity Commission (EEOC), the agency that enforces workplace discrimination law, published a fact sheet on wearable technologies. It was withdrawn in early 2025, along with the agency’s guidance on artificial intelligence in hiring.
That withdrawal is easy to misread. The guidance is gone; the laws it described are not. The Americans with Disabilities Act, Title VII and GINA still apply in full, and courts still enforce them. What actually happened is that compliance pressure moved from federal guidance to state legislatures and, for anyone with European staff, to the EU AI Act. Colorado, Illinois, Texas, California and Washington have all changed the rules for employee device data since 2024.
The practical question is no longer “what does the EEOC say” but “which rules apply to the readings we want, and can we justify collecting them at all.”
Key Takeaways
- Federal guidance disappeared, the statutes did not: the EEOC’s 2024 wearables fact sheet was withdrawn in 2025, but the ADA, Title VII and GINA still govern what you collect.
- State law is now the binding layer: Colorado, Illinois and Texas set specific consent, retention and damages rules for biometric data.
- Scope beats good intentions: list the exact devices and readings covered, and name the uses you prohibit.
- Emotion tracking and fatigue tracking are legally different: in the EU one is banned at work and the other is not.
- Keep medical readings out of personnel files and set a deletion date before the first device is handed out.
What Counts as a Workplace Wearable
Start with an inventory: you cannot write rules for devices you have not listed. A wearable is any device worn on the body, or built into clothing or protective equipment, that records something and sends it somewhere. The workplace categories are narrower than the consumer market suggests:
- Wrist and finger devices: smartwatches and rings recording heart rate, movement, steps and sleep.
- Posture and motion sensors: clip-on units that flag awkward lifts and twists, common in warehouses.
- Proximity and environmental badges: devices that beep when a worker gets too close to a forklift, or log noise, heat and gas exposure.
- Head-worn devices: helmets with alertness sensors, and smart glasses for hands-free work.
- Exoskeletons and GPS units: frames that take load off the back, and location trackers carried by drivers and field technicians.
Separate telemetry from biometric readings
The single most useful distinction in the whole policy is this one. Telemetry is routine operational data: a step count, a proximity alert, a timestamp, a route. Biometric data is measurement of the body itself: heart rate, skin temperature, fingerprints, face or voice patterns.
They carry different risk. A proximity alert says a worker walked near a machine. A resting heart rate trend can suggest a heart condition, turning a productivity tool into a source of medical information.
- Write down which readings are telemetry and which are biometric, device by device.
- State whether off-duty data is collected. For most programs the honest answer is no, and saying so removes a large share of employee objections.
- Cover employee-owned devices. If someone’s personal smartwatch feeds a company dashboard, your obligations attach to that data too.
Where Employers Actually Use Wearables
Heavy industry, construction and healthcare use posture sensors, fatigue monitors and proximity alerts to cut injuries. A sensor that vibrates when a worker bends with a straight back rather than bent knees is correcting a movement, not diagnosing a person, and that is an easy case to justify.
Logistics and field service use GPS for routing and lone-worker alerts. The genuine safety case is the alert that fires when a technician stops moving in a remote location. Route optimisation is a business case, not a safety case, and should be justified on its own terms.
Corporate offices mostly run voluntary fitness programs, and this is where employers most often overreach. The devices are cheap, the intent is friendly, and nobody asks what happens to the heart rate data afterwards. If the program is closer to a perk than a safety control, treat it like other employee wellbeing benefits and keep the data out of management hands.
The test that cuts through all three: can you tell the affected employee, in one sentence, what specific harm this reading prevents? If the answer takes a paragraph, the justification is weak.
The 2026 Legal Picture: Federal Guidance Gone, State Law Binding
Two federal documents that shaped wearables advice in 2024 are no longer on the agencies’ websites.
The EEOC’s wearables fact sheet was removed in early 2025, together with its 2022 and 2023 technical assistance documents on artificial intelligence and employment. Separately, in February 2025 the National Labor Relations Board’s acting general counsel rescinded memo GC 23-02, which had argued that intrusive electronic monitoring could interfere with employees’ rights to organise (known as Section 7 rights, after the section of the National Labor Relations Act that protects collective action).
Neither withdrawal changed a statute. Guidance memos describe how an agency intends to enforce the law; they are not the law. The ADA still limits medical inquiries, Title VII still prohibits discrimination on protected characteristics, GINA still restricts collection of genetic and family medical history, and Section 7 still protects concerted activity. What changed is the likelihood of federal enforcement, not the underlying exposure. Private lawsuits are unaffected.
Why this makes state law the practical driver
Where a federal agency stepped back, states stepped forward. Four state laws now govern automated decisions about employees, each with its own standard:
- California: regulations under the Fair Employment and Housing Act covering automated decision systems took effect on 1 October 2025, with a four-year record retention duty and liability extending to vendors acting as the employer’s agent.
- Illinois: HB 3773 took effect on 1 January 2026. It bans AI use that has the effect of discriminating and requires employers to tell workers and applicants when AI is used.
- Texas: TRAIGA (HB 149) also took effect on 1 January 2026, but on an intent standard. A disparate impact alone is not enough to establish a violation.
- Colorado: SB 24-205 applies from 30 June 2026, after a delay from February. It requires risk management programs and impact assessments for high-risk systems, with a defence for employers following the NIST AI Risk Management Framework.
If you feed wearable readings into any scoring or ranking tool, these rules apply to that tool. The same analysis you would run for bias in AI recruitment tools applies to a fatigue score that influences who gets assigned to the night shift.
When Wearable Data Becomes a Medical Inquiry Under the ADA
This is the trapdoor most wellness programs fall through. The Americans with Disabilities Act restricts when an employer may ask about an employee’s medical condition or require a medical examination, meaning a procedure that seeks information about a person’s physical or mental impairments or health.
Continuous heart rate, blood pressure, blood oxygen or skin temperature monitoring can meet that description. Once it does, the collection is lawful only if it is job-related and consistent with business necessity, which is the statutory phrase and a genuinely demanding standard.
What business necessity actually requires
It is not enough that the data is useful, or that an insurer offered a discount. You need a documented link between a specific job duty or hazard and the reading you collect.
A workable justification: furnace operators work in ambient temperatures above 45 degrees Celsius, heat illness is a recorded hazard at this site, and core temperature monitoring lets a supervisor pull someone out before they collapse. A weak one: we want to improve staff wellbeing.
- Write the rationale before collection begins, not after a complaint arrives.
- Record the less intrusive options you considered and why they were insufficient. Scheduled breaks, ambient sensors and buddy checks are the obvious alternatives to body monitoring, and a regulator will ask about them.
- Set a review date. A justification that made sense when a process was manual may not survive automation.
Keep medical records out of the personnel file
The ADA requires medical information to be kept in a separate, confidential file with restricted access. In practice the supervisor who sees a fatigue alert should not be able to click through to a heart rate history. Log every access so you can show later who looked, when and why. That is standard in any mature data governance strategy, and wearable data is no exception.
Consent, Transparency, and the Right to Say No
Consent is not a signature you collect once and file away. It is a state you maintain, and it can be withdrawn.
Start with a notice short enough that people read it. One paragraph covering what is collected, why, who sees it and how long it is kept, with a link to the full document, does more for trust than a twelve-page policy nobody opens.
Voluntary and mandatory are not the same conversation
Be explicit about which category each program falls into. A proximity alarm on a forklift aisle can reasonably be mandatory; a step-count challenge cannot. The distinction matters because a voluntary program that quietly penalises non-participants is not voluntary. If declining costs someone a shift preference, a bonus or a place on a team, it is mandatory in everything but name, and will be judged that way.
What a usable consent form covers
- Scope: the exact readings collected, named individually rather than as “health and activity data”.
- Purpose: what each reading is used for, and what it will never be used for.
- Access: which roles can see which data, in plain job titles.
- Retention: a number of days or months, not “as long as necessary”.
- Sharing: whether anything reaches insurers, vendors or a parent company.
- Withdrawal: how to revoke consent, what happens operationally when someone does, and confirmation that there is no penalty.
Wellness incentives have no safe harbour
This is widely misunderstood. The EEOC once set a 30 percent cap on wellness incentives, but a federal court vacated those provisions effective 1 January 2019 in AARP v. EEOC, and the agency removed them from the regulation in December 2018. Replacement rules proposed in January 2021 were withdrawn. So there is no approved percentage. If an incentive is large enough that a reasonable employee would feel unable to refuse, the program risks failing the voluntariness test, and no published number protects you.
Accommodations and complaints
State clearly that employees may decline, request an accommodation or raise a concern without retaliation, via a route that does not run through their own supervisor.
Train managers to pass accommodation requests to HR rather than resolving them informally. Someone who cannot wear a wrist device because of a skin condition or a prosthetic should get an alternative, not a negotiation. The training principles match other employee-facing technology rollouts, such as VR employee training resources.
Emotion Tracking and Fatigue Tracking Are Different
If you have employees in the European Union, this distinction decides whether a feature is legal.
Since 2 February 2025, Article 5 of the EU AI Act has prohibited AI systems that infer a person’s emotions in the workplace from their biometric data. It is a flat prohibition, not a paperwork exercise, and breaching a prohibited practice carries fines of up to 35 million euros or 7 percent of global annual turnover, whichever is higher.
What the ban covers: inferring emotional state. A tool scoring an employee’s voice for frustration, or reading facial expressions for engagement, falls inside it. General wellness monitoring for stress or burnout does not qualify for the narrow safety exception.
What it does not cover: physical states. European Commission guidance confirms that detecting fatigue in pilots or drivers to prevent accidents sits outside the prohibition. Fatigue is a physical condition, not an emotion.
The consequence is sharp. A helmet sensor flagging micro-sleeps in a haul truck driver is defensible in the EU. A dashboard rating the same driver’s mood across a shift is not, however it is marketed. If a vendor cannot tell you which side of that line a feature sits on, that is your answer. Our guide to emotion recognition AI at work covers the wider picture.
Preventing Bias and Inaccurate Readings
Optical sensors do not perform equally on every body. Devices that measure heart rate by shining light through the skin can read less reliably on darker skin tones, and wrist sensors lose accuracy with tattoos, certain motions and poor fit. That is an accuracy problem before it is a legal one, and it becomes a legal one the moment an unreliable reading affects someone’s work.
Test before you deploy, not after
Run a pilot across a mixed group: different skin tones, body sizes, ages and job roles. Compare the output against a reference measurement and record what you find, including the disappointing parts.
- Put accuracy commitments in the vendor contract, with a remediation plan if the pilot shows disparities.
- Set a confidence threshold below which a reading triggers a human check rather than an action.
- Ban adverse decisions on device output alone. Discipline, scheduling penalties and performance ratings should require human review and corroborating evidence.
- Give employees a route to challenge a reading and see the underlying data.
“A number that is wrong for some employees and right for others is worse than no number at all.”
Keep the test records. If a reading is questioned later, documentation of what you tested and fixed separates a defensible program from an indefensible one. These are the same controls that make algorithmic management survivable, and the same reason AI employee monitoring fails audits when validation is skipped.
Privacy, Security and Retention
Two simple principles do most of the work here. Data minimization means collecting only the readings you have a stated use for. Purpose limitation means not repurposing them later without going back to the employee. A safety program that quietly starts feeding attendance data into performance reviews has broken the second, and that is the failure employees notice fastest.
Security controls that match the sensitivity
Biometric data cannot be reissued. A leaked password is replaceable; a leaked fingerprint template is not. Treat it accordingly:
- Encrypt at rest and in transit, with key management held by someone other than the vendor.
- Require multi-factor authentication for administrative access.
- Log access and review the logs on a schedule, not only after an incident.
- Map breach notification duties by state before you need them, and put the timelines in the vendor contract.
The same “cannot be reissued” logic drives the design of biometric authentication for remote work.
Set a deletion date, and automate it
Define retention by data type. Proximity alerts might justify 90 days; a heart rate series almost never justifies years. Automate the purge so it does not depend on someone remembering. Colorado’s law makes this concrete. Biometric identifiers must be deleted at the earliest of three points: when the purpose is fulfilled, 24 months after the person’s last interaction with the employer, or within 45 days of deciding that storage is no longer necessary.
Third parties are your exposure too
Vet vendors on security, accuracy and subprocessors. Require audit rights, breach notice timelines, a ban on using your employees’ data to train their models, and deletion at contract end.
Watch firmware and cloud updates. A device that collected three readings at purchase can collect seven after an update, and your policy no longer describes what is happening. This is the same drift that makes unapproved tools a persistent risk.
State Laws, Location Tracking, and International Rules
Before you expand a pilot to a second state, check which rules follow it there. Biometric obligations in the United States are set state by state, and three of them matter most for wearables.
Illinois, Texas and Colorado
Illinois has the Biometric Information Privacy Act (BIPA), which requires written informed consent before collecting a biometric identifier, plus a published retention and destruction policy. Individuals can sue directly, with statutory damages of 1,000 dollars for negligent violations and 5,000 for reckless or intentional ones. An amendment effective 2 August 2024 limited the exposure: collecting the same identifier from the same person by the same method now counts as a single violation rather than one per scan, taking the worst case for a time clock deployment from tens of millions to a manageable figure.
Texas regulates biometric identifiers under CUBI, enforced by the attorney general rather than private lawsuits.
Colorado is the most specific for employers. Since 1 July 2025, employment may be made conditional on biometric consent only for four purposes: access to secure locations or systems, clocking work hours including breaks over 30 minutes, workplace safety, and public safety during an emergency. For anything else, consent cannot be required and refusing cannot be punished. Employers must also publish a written policy covering retention, incident response and deletion.
Monitoring notices and microchip bans
Three states require written notice before electronic monitoring: New York, Connecticut and Delaware. Delaware accepts either a daily electronic notice or a one-time written notice the employee acknowledges.
On implants, at least 13 states prohibit employers from requiring microchip implantation, including California, Nevada, Wisconsin, Indiana and Montana. Washington joined them with HB 2303, effective 11 June 2026, which bars requiring, requesting or coercing an implant, with fines starting at 10,000 dollars and a private right of action. Voluntary implants and genuine medical devices stay permitted. Most employers will never consider implants, but a one-line prohibition costs nothing.
Employees outside the United States
Under the EU and UK General Data Protection Regulation, biometric data used to identify someone is a special category needing an explicit legal basis. Consent is a weak basis at work, because regulators doubt an employee can refuse an employer freely. Most European deployments therefore rest on a legal obligation or substantial public interest, a narrower footing than many US-designed programs assume. Cross-border transfers need an approved mechanism.
For distributed teams, fold this into the same document as your hybrid work policy and, where staff work across borders, your digital nomad policy.
Writing the Policy
A good policy is short, specific and dated. Aim for something a supervisor reads in ten minutes and a new hire understands without a lawyer.
The six sections it needs
- Scope: covered devices by name, the readings each produces, the authorised uses and, separately, the prohibited ones. Explicit prohibitions are what stop a safety tool becoming a performance tool two years later.
- Collection rules: written justification before any new reading is added, each tied to a job duty or hazard, with an annual review and a fresh look whenever the technology or process changes.
- Privacy and retention: segregated medical records, access defined by role, retention stated as numbers, and named owners for encryption, logging and audit.
- Consent and accommodation: the consent language itself, the withdrawal process, the accommodation route, the non-retaliation commitment and the team that handles requests.
- Complaints and escalation: a contact, a response time and a path that does not run through the employee’s own line manager.
- Vendor standards: accuracy testing, security controls, subprocessor limits, update notification, breach timelines and deletion at contract end, agreed once rather than per deployment.
Governance, Training and Vendor Management
A policy nobody owns stops being true within a year. Assign four owners: legal interprets the rules and signs off new collection, HR owns consent and complaints, IT and security enforce access controls and logging, and the business owner justifies the use case at review.
Train supervisors on the one thing they get wrong
Managers treat a number on a screen as fact. The training has to land the opposite point: a device reading is one input, it has a known error rate, and it never stands alone as a reason for a decision affecting someone’s pay, schedule or record.
Cover the accommodation route, the escalation path and the ban on using safety data in performance conversations. This belongs in the same manager training as your rules for generative AI use and your approach to continuous performance management, because the failure mode is identical: an automated signal treated as a verdict.
Review on a schedule
Review the program annually. Larger organisations route this through an automation ethics board alongside other monitoring and AI decisions, so each department does not invent its own standard.
Track a few simple measures: complaints raised and resolved, accommodation requests and outcomes, recordable incidents, opt-out rate, and time to approve a new use case. A rising opt-out rate is the earliest warning that trust is slipping, and it deserves more attention than any efficiency metric. Programs that hold up are the ones where trust was designed in deliberately.
Conclusion
The federal shortcut is gone. There is no current EEOC fact sheet, and the NLRB memo on monitoring has been rescinded, but the ADA, Title VII and GINA are untouched and state legislatures have filled the space with specific, enforceable rules.
That makes the work more ordinary than it sounds. Collect less than you are able to. Write down why you collect each reading before you start. Keep medical data away from managers. Give people a real way to decline and to complain. Delete on a schedule you automated rather than one you intended.
Do those five things and most of the exposure takes care of itself, because nearly every rule here is a variation on one idea: collect what the job actually requires, and nothing else. For the operational side of these devices, see our companion guide to wearable technology at work, and for duties around staff records generally, our overview of data privacy at work.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







