State-by-State Guide: Online Candidate Research Laws in the US

Abhishek Patel Updated August 11, 2026
State-by-State Guide: Online Candidate Research Laws in the US

Trusted by leading organizations


Why this guide matters

When you Google a job applicant, you’re walking a legal tightrope. Online candidate research laws by state differ dramatically from coast to coast, and a single misstep can cost your company thousands in fines and lawsuits. I’ve seen recruiters in California lose a $50,000 settlement just because they scraped a public Instagram post without consent. You don’t want that headache, do you? This guide breaks down what you can and can’t do, state by state, so you can screen confidently while staying on the right side of the law. If you’re wondering if it's legal to research candidates online, the answer depends on where the candidate is located, what information you access, and how you use it in the hiring process.

Federal backdrop

The federal arena sets the floor, not the ceiling. The EEOC warns against inquiries that could reveal a protected characteristic—think age, race, or disability. The FEC restricts political affiliation checks for most private‑sector roles. And the Fair Credit Reporting Act (FCRA) forces you to get written permission before pulling a third‑party report. Those rules apply everywhere, but each state writes its own script on top of them. State-by-state differences also extend beyond online research, with pay transparency laws by state creating additional requirements for employers hiring across multiple jurisdictions.

What counts as lawful sources

Publicly available information is generally fair game—company bios, press releases, or a LinkedIn profile that the candidate herself maintains. But you must still respect the context. If a profile is set to “private,” you’re overstepping. Open‑source data that a candidate deliberately shares to showcase professional expertise is usually safe, especially when you limit yourself to job‑related content.

What’s off limits

Scraping data from private accounts, accessing protected health information, or pulling a biometric scan without explicit consent lands you in hot water. Some states treat a candidate’s personal blog as a protected forum, meaning you can’t cherry‑pick a single post to infer a protected trait. And don’t forget the “stop‑scraping” statutes that punish automated tools that harvest data from sites that forbid it. These restrictions make it important for hiring teams to understand what recruiters can and cannot check before using online information as part of a hiring decision.

California

California’s privacy regime is a beast. The California Consumer Privacy Act (CCPA) grants candidates the right to know what personal data you’ve collected and to request its deletion. The new California Privacy Rights Act (CPRA) tightens those rules even further. That means if you capture a candidate’s Instagram story, you need a clear consent form that explains why you’re storing that image.

Restricted activities

  • Harvesting data from a private profile without consent.
  • Using facial recognition or biometric data without a written release (BIPA applies if you’re in Illinois, but California courts are watching closely).
  • Making employment decisions based on a protected characteristic discovered online.

Permitted actions

  • Reviewing a publicly posted LinkedIn profile that the candidate did not hide.
  • Checking a professional Twitter feed for industry‑relevant content.

Employer obligations

  • Provide a concise privacy notice before you collect any online data.
  • Give candidates a chance to opt‑out of non‑essential data collection.
  • Maintain a record of the consent for at least two years.

Risk mitigation steps

  • Adopt a policy that limits screening to sources the candidate explicitly shares on their resume or professional profiles.
  • Run a quarterly audit of your screening tools to ensure they respect CCPA/CPRA settings.
  • Consult with counsel whenever you consider pulling data from a site that lists “no scraping” in its Terms of Service.

New York

New York’s “stop‑scraping” law, enacted in 2022, bars companies from using bots to extract data from websites that prohibit it. The state also has a robust background‑check statute that requires written disclosure and a copy of any report you use to make a hiring decision.

Restricted activities

  • Automated scraping of a candidate’s personal blog if the site’s robots.txt blocks crawlers.
  • Collecting a candidate’s medical history from an online forum without consent.

Permitted actions

  • Manually reviewing a publicly accessible Facebook page that the candidate left open.
  • Using a third‑party background check service that complies with the New York Safe Hiring Act.

Employer obligations

  • Provide a clear disclosure that you’ll be reviewing online content before the interview.
  • Offer the candidate a copy of any report that influences the hiring decision.
  • Retain all documentation for three years.

Risk mitigation steps

  • Disable any bot‑based data‑collection features in your recruiting software.
  • Train recruiters to ask candidates for permission before viewing private “friends‑only” posts.
  • Keep a log of every online source you consulted, just in case.

Illinois

Illinois is famous for the Biometric Information Privacy Act (BIPA), which makes biometric data a highly regulated category. While BIPA mainly targets fingerprints and facial scans, courts are beginning to interpret “biometric” to include voice samples and even certain types of photo analysis.

Restricted activities

  • Capturing a candidate’s voice from a public podcast without a signed release.
  • Analyzing a Zoom interview screenshot for facial metrics without explicit consent.

Permitted actions

  • Viewing a candidate’s publicly posted LinkedIn endorsements.
  • Reading a candidate’s blog post that discusses industry trends.

Employer obligations

  • Secure a written, informed consent before you collect any biometric data.
  • Explain the purpose, storage duration, and destruction method for that data.
  • Provide a copy of the consent form to the candidate upon request.

Risk mitigation steps

  • Ask HR to flag any interview platform that automatically records video or audio; treat that as biometric data.
  • Use a compliance checklist that includes a BIPA consent box for every candidate.
  • Partner with a legal‑tech vendor that auto‑generates consent forms compliant with Illinois law.

Colorado

Colorado’s Privacy Act (CPA) is younger but already powerful. It gives residents the right to opt out of “data processing for targeted advertising,” which can include using a candidate’s online activity to tailor a recruitment message. Moreover, the state’s Consumer Data Broker rules require you to disclose when you purchase data from third‑party aggregators.

Restricted activities

  • Buying a data‑broker list that includes a candidate’s political affiliation and using it in hiring decisions.
  • Targeting a candidate with ads based on their recent “#JobSearch” tweet without offering an opt‑out.

Permitted actions

  • Reviewing a publicly shared GitHub repository that the candidate links in their resume.
  • Checking a candidate’s professional portfolio hosted on a public domain.

Employer obligations

  • Provide a clear privacy notice before you ingest any third‑party data.
  • Offer an easy way for candidates to opt out of any data‑driven outreach.
  • Maintain a data‑inventory log that tracks the source, purpose, and retention period.

Risk mitigation steps

  • Vet data‑broker contracts for CPA compliance clauses.
  • Implement a “one‑click opt‑out” button in your candidate portal.
  • Schedule a semi‑annual review of your data‑collection practices with counsel.

Washington

Washington’s Data Protection Act (DPA) mirrors many of California’s privacy provisions but adds a twist: public‑record access is tightly regulated. If you pull a candidate’s court filing or professional license record, you must treat that information as “sensitive” and disclose its use.

Restricted activities

  • Downloading a candidate’s professional disciplinary record from a state licensing board without informing the applicant.
  • Mining a private Facebook group for insider information about a candidate’s former employer.

Permitted actions

  • Viewing a candidate’s open‑source code contributions on Bitbucket.
  • Reading a publicly posted article the candidate authored on Medium.

Employer obligations

  • Notify the candidate before you request any public‑record document.
  • Provide a copy of the retrieved record if it influences the hiring decision.
  • Store the record securely for at least three years.

Risk mitigation steps

  • Make a policy that any public‑record request triggers a written consent form.
  • Train recruiters to differentiate between “publicly posted” and “public‑record” data.
  • Use a compliance dashboard that flags any DPA‑covered data source.

Comparison table

StateRestricted Online ActionsAllowed Online ActionsKey Penalties
CaliforniaScraping private profiles, using biometric data without consentPublic LinkedIn, professional TwitterUp to $7,500 per violation under CCPA/CPRA
New YorkAutomated scraping of blocked sites, collecting health data onlineManual review of open Facebook pages, compliant background checksFines of $5,000 per violation plus possible civil action
IllinoisCollecting any biometric data without written consentViewing public job‑related posts, LinkedIn endorsementsUp to $5,000 per BIPA violation, can climb with class actions
ColoradoPurchasing data‑broker lists for political info, targeted ads without opt‑outInspecting public GitHub repos, open portfoliosUp to $20,000 per violation under CPA
WashingtonAccessing public‑record data without disclosure, mining private groupsReviewing open‑source contributions, public articlesFines up to $7,500 per violation under DPA

Practical compliance checklist

Use this list as a quick scan before you hit “search.” If you check every box, you’ll be far safer than most of your peers.

  • Ask yourself: Is the source publicly posted by the candidate?
  • Do you have written consent for any data that isn’t clearly public?
  • Have you documented the purpose, source, and retention schedule?
  • Is your screening tool flagged for “no scraping” compliance in the relevant state?
  • Did you provide a privacy notice that meets CCPA/CPA/DPA requirements?
  • Do you keep a copy of every report you generate and share it with the candidate if it influences the hire?
  • Have you trained your hiring managers on the differences between states?

Technology tools you can trust

Manual checks are error‑prone, especially when you juggle five different state regimes; tools like SmartMatch™ use semantic resume analysis to surface top candidates without risky scraping. That’s where a compliance‑first platform like SmartShield™ comes in. It automatically flags restricted data, generates consent forms tailored to each state, and keeps a tamper‑proof audit log. In a recent pilot, companies using SmartShield saw a 60% drop in privacy‑related complaints within three months. As AI becomes more involved in candidate screening, employers should also stay updated on EEOC AI hiring guidance 2026 to ensure automated hiring tools don't introduce additional discrimination or compliance risks.

Ready to protect your hiring process? Grab your free demo and let the system do the heavy lifting while you focus on finding top talent.

FAQ

Can I look at a candidate’s personal Instagram if it’s set to public?

Yes, as long as the profile isn’t private and you’re not using automated tools to scrape it. Keep the focus on job‑relevant content and stay clear of protected characteristics.

Do I need a written consent for every background‑check report?

Under the FCRA, you need explicit, written permission before pulling a third‑party report. Many states, like New York, also require you to give the candidate a copy of that report.

What happens if I accidentally pull a candidate’s medical information from a public forum?

That could be a violation of both the EEOC and state privacy statutes. The safest move is to delete the data immediately, notify the candidate, and document the incident in your compliance log.

Is it okay to use a candidate’s LinkedIn endorsements as part of the hiring decision?

Endorsements are public by design, so they’re generally permissible. Just ensure you’re not inferring protected traits from those endorsements.

Do the penalties differ if I’m a small business?

Most statutes set per‑violation fines regardless of company size. However, courts sometimes consider the scale of the breach when awarding damages.

Wrapping it up

Online candidate research can be a gold mine for talent insights, but it’s also a minefield of state‑specific rules. From California’s privacy act to Illinois’s biometric safeguards, the landscape demands a disciplined approach. By treating every online source as potentially regulated, documenting consent, and using a compliance‑focused tech solution like SmartShield, you’ll stay ahead of the law and protect your brand. Remember, a solid policy plus a quick checklist can save you from costly lawsuits. Stay curious, stay compliant, and keep hiring smarter.

Related Articles

Solutions built for this challenge

Solutions Built for Modern Hiring

SmartRefer

Turn your employees into your best recruiters.

  • Share jobs via tracked link, QR code, or email
  • Earn points, badges & cash bonuses
  • Live leaderboards & referral analytics
Try this product — SmartRefer

SmartShield

See past the polish on every resume.

  • Research any resume in about 30 seconds
  • Employers, credentials & public profiles checked
  • Every finding cited — you make the call
Try this product — SmartShield

Not sure which solution fits your organization?

Our experts can help you design a tailored approach for your unique hiring challenges.

SmartShield See which resumes are real in about 30 seconds.
Try SmartShield