Jul 15, 2026Social Media PrivacyWorkplace Privacy Rights NJEmployee PrivacyNJ Social Media LawEmployee Online Privacy Rights

Can NJ Employers Demand Your Social Media Passwords? The Limits of Workplace Snooping

Concerned employee holding a smartphone while speaking with a manager about access to her private social media account.

Social media privacy disputes in New Jersey workplaces often begin with employers investigating employees’ online activity. Сompanies have legitimate interests in protecting confidential information and workplace policies. 

Requests for social media passwords can go beyond workplace monitoring and create privacy issues under New Jersey law. 

This can create difficult questions for both employers and employees. Our legal team at Brandon J. Broderick builds these claims by examining the difference between an employer viewing public information and requiring access to private accounts. The distinction determines if the request crosses legal boundaries. 

This article explains what employers are prohibited from requesting, what protections employees have when privacy is challenged, and when to reach out to an employment lawyer in New Jersey. 

When NJ Employers Ask for Social Media Passwords: Limits on Account Access

New Jersey law draws a firm line at private social media login information. N.J.S.A. 34:6B-6 prohibits an employer from requesting or requiring a current employee or job applicant to disclose a username or password for a personal social media account. 

It also bars an employer from demanding access through another method. A manager doesn’t avoid the law by leaving the word “password” out of the conversation.

Presentation of the “request” matters. An employer doesn’t have to threaten termination or describe the demand as mandatory. Asking for the information is enough to fall within the statutory language. The protection also starts before employment. An applicant doesn’t have to open pr disclose a private Instagram, Facebook, or TikTok profile as part of an interview or background check.

Prohibited requests include instructions to:

  • Send a username, password, or authentication code to a manager.
  • Log in while a supervisor or interviewer watches.
  • Hand over an unlocked cellphone and open private posts or messages.
  • Share a screen while the employer reviews restricted content.
  • Give another person credentials so management gains entry indirectly.

New Jersey adopted the law as P.L. 2013, c.155, now found at N.J.S.A. 34:6B-5 through 34:6B-10. Rather than naming individual platforms, the statute defines a social networking website by its functions. 

It covers an internet service where users create public or partly public profiles, maintain lists of connections, and view those connections. The language reaches newer platforms offering the same basic features, even if they didn’t exist when the law passed.

Protection depends on the type of account. A “personal account” is one used exclusively for personal communications unrelated to the employer’s business. A private Instagram page used only for family photographs fits the definition. A freelance social media manager may use a personal-looking profile to communicate with customers, which creates a different issue. Mixed personal and business use leads to a harder dispute because the statute places accounts used for business-related communications outside its definition.

N.J.S.A. 34:6B-7 also blocks employers from requiring applicants to surrender these rights. New Jersey law doesn’t allow employers to require workers to waive these protections to obtain a job offer. Any agreement that attempts to do so violates public policy and is unenforceable. 

Coverage has limits. The statute refers to current and prospective employees, not independent contractors. Its definition of employer excludes the New Jersey Department of Corrections, State Parole Board, county corrections departments, and state or local law enforcement agencies. Those exclusions remove the specific protection provided by this law; they do not settle every privacy issue involving those agencies.

An employer asking to view a public LinkedIn page is different from demanding access to a private account. The difference comes down to control over the information: public content is available by choice, while private posts require credentials or another method of bypassing the user’s privacy settings. Brandon J. Broderick addresses these situations by focusing on the access issue, especially when an employer’s request goes beyond reviewing publicly available information. 

“The decision to speak up is powerful. But knowing what happens after — and how to protect yourself — is just as critical.”

— Olivia Rhye

Public Posts, Business Accounts, and Demands for Login Credentials in New Jersey 

Workplace social media privacy does not erase information posted for the public. New Jersey expressly permits employers to view, access, and use information about an employee or applicant obtained from the public domain. 

A recruiter remains free to search a person’s name and review an unrestricted profile. An employer also has no legal obligation to ignore a public post sent by a customer or a coworker.

Privacy settings, therefore, matter. A public post stands in a different position from a friends-only story or a private group discussion. Creating a fake account, borrowing someone else’s password, or pressuring a coworker to reveal restricted content does not turn it into public information. 

Business accounts follow another rule. A company may control its business social media pages, work messaging services, employer-provided devices, and network systems. This includes monitoring the WiFi used for company operations. These rules allow employers to manage tools created for work without giving them unlimited access to an employee’s private accounts. 

An employer-issued device doesn’t convert every account opened on it into a business profile. Account use remains central to the statutory definition. Still, employees should expect less privacy on company phones and computers, especially when a written policy authorizes monitoring. 

New Jersey law preserves targeted workplace investigations. An employer retains the authority to investigate compliance with laws, regulatory requirements, and rules against work-related misconduct. It also permits an investigation after the employer receives specific information about proprietary information or financial data being transferred to an employee’s personal profiles.

“Specific information” limits the exception. A vague suspicion that workers complain online doesn’t count as a report identifying a particular post or transfer. Employers need a valid reason before relying on the investigation provision. 

Regulated employers may still require employees to follow state and federal laws, regulations, case law, and industry rules that require legitimate investigations. A health care provider or government contractor doesn’t violate privacy protections by reviewing information needed to meet a real legal obligation. 

The First Amendment also limits how employers, especially public employers, respond to protected speech or viewpoints. A general claim of “compliance” does not justify a broad search into personal accounts without a specific legal or business reason. 

The law mainly addresses how an employer gets access to online information, not every consequence that follows a social media post. Our legal team considers both parts of the issue: how the information was obtained and how the employer used it. Lawfully obtained posts may support discipline for serious misconduct, but other laws apply if the response involves bias or retaliation. 

corner-linescorner-lines

Not All Silence

Is Golden

Talk to a Lawyer Now

Social Media Content and Employee Privacy Rights in New Jersey Workplaces 

Federal law adds another layer when someone enters a restricted social media account. The Stored Communications Act prohibits intentional unauthorized access to stored electronic communications. Section 2707 provides a civil action for qualifying violations, including actual damages, statutory damages in some circumstances, punitive damages for willful or intentional conduct, and reasonable attorney fees.

A New Jersey federal case illustrates the danger of indirect access. In Pietrylo v. Hillstone Restaurant Group, restaurant employees created an invitation-only MySpace group where workers discussed their jobs and managers. Management obtained login information from another employee who had authorized access. Evidence showed she felt pressured to provide it. Managers then visited the restricted group on five occasions.

Jurors found that management violated the federal Stored Communications Act and its New Jersey counterpart. 

The court upheld the verdict, finding enough evidence for the jury to conclude that the employee’s purported consent resulted from workplace pressure. The 2009 federal court opinion shows why an employer cannot recruit one worker to unlock another worker’s private space.

Source and consent decide the outcome. A screenshot voluntarily sent by a genuine follower differs from a manager ordering an employee to log in and search someone else’s profile. Privacy settings help establish that content was restricted, but they do not stop an authorized recipient from sharing what they saw.

A hiring search can also involve the Fair Credit Reporting Act. When an employer uses a third-party screening company to review an applicant’s social media activity or credit history, the FCRA may apply. 

According to the Federal Trade Commission, the employer must obtain written permission before requesting the report. Before rejecting the applicant based on it, the employer must provide a copy and a summary of FCRA rights, giving the person time to dispute errors. A direct public search performed by the employer does not trigger the same FCRA process.

New Jersey protects workers and job applicants who push back against improper requests for social media passwords or account access. Employers cannot punish someone for refusing to provide login information, reporting a possible violation, taking part in an investigation, or opposing conduct that violates the statute.

Enforcement under the social media statute itself is limited. N.J.S.A. 34:6B-9 authorizes a civil penalty of up to $1,000 for the first violation and $2,500 for every later violation.

A profile often reveals religion, age, disability, pregnancy, national origin, family information, sexual orientation, or gender identity. Employers don’t receive permission to discriminate because they discovered the information online. The New Jersey Law Against Discrimination applies to employment decisions based on actual or perceived protected traits.

Deleting posts, clearing a phone, or closing the account destroys evidence and creates avoidable disputes. Asking the employer to place its request and stated reason in writing also creates a clearer record.

If you have questions about an employer’s request for social media access or believe your privacy rights were violated, contact us today for a free consultation

Svetlana Skvortsova
Reviewed by Denis Sautin
Get Help from Our New Jersey Employment Lawyers Today

Stop wondering about your rights or if you'll be taken seriously. We treat every client with respect, urgency, and honesty. Our lawyers will listen, explain your legal options, and fight for the outcome you deserve.

*
*

By clicking "Schedule Your Free Consultation", you agree to Privacy Policy