Boostpoint fills frontline pipelines with Facebook and Instagram job ads; a clean, consistent screening process keeps the applicants you paid to reach.
Book a demoHiring complianceRead at source, 30 September 2026
Social Media Screening of Job Candidates: What Employers Can Check, and What Gets Them Sued
You may look at a candidate’s public social media, but what you see can hurt you. Posts reveal age, religion, pregnancy, disability, national origin and family medical history, and once you have seen them it is hard to prove they played no part. 28 states bar employers from demanding passwords or login access to applicants’ personal accounts. And if a screening company compiles the report, it is an FCRA consumer report: written disclosure, signed authorization, and pre-adverse and adverse action notices before you reject anyone on it.
What employers look for on social media, and what they must ignore
The defensible list is short: conduct that would matter on the job.
- Threats or violence, including threats against a former employer or coworkers.
- Harassment of individuals, or slurs aimed at people because of a protected characteristic.
- Illegal activity, such as posts showing illegal drug use or selling.
- Confidential information: a former employer’s customer data, patient details or trade secrets posted publicly.
- Claims that contradict the application, such as a license or job the person says they hold that their own posts show they don’t.
What you must ignore is everything the EEOC lists as protected. It is illegal to discriminate against an applicant because of “race, color, religion, sex (including transgender status, sexual orientation, and pregnancy), national origin, age (40 or older), disability or genetic information,” and a profile shows most of those in the first photo. Add two categories people miss: family medical history, which is genetic information under GINA, and posts about pay, working conditions or a union, which federal labor law protects. Some states also protect employees’ lawful off-duty conduct or political activity; California’s Labor Code 96(k) and 1101 are examples.
Is social media screening legal? The federal rules
No federal law bans looking at public posts. The risk is in what you do with them.
Title VII, the ADA and the ADEA apply to hiring decisions however the information arrived. If a hiring manager sees a candidate’s pregnancy announcement, church group or wheelchair, then rejects them, the candidate does not have to prove you went looking; the question is whether what you saw played a part, and you will need a documented, job-related reason to show it didn’t.
GINA goes further than the others. Its rule on acquiring genetic information, 29 CFR 1635.8(a), says a prohibited “request” “includes conducting an Internet search on an individual in a way that is likely to result in a covered entity obtaining genetic information.” A name search that turns up a fundraiser page for a candidate’s parent’s illness puts family medical history in front of you, and GINA bars using genetic information in hiring however you came across it (29 CFR 1635.4).
The National Labor Relations Act protects “concerted activity” for union and non-union workers alike. The NLRB says employees have “the right to address work-related issues and share information about pay, benefits, and working conditions with coworkers on Facebook, YouTube, and other social media.” The Act defines “employee” as not “limited to the employees of a particular employer” (29 U.S.C. 152(3)), and section 8(a)(3) bars discrimination “in regard to hire” to discourage union membership (29 U.S.C. 158(a)(3)). Rejecting a candidate for posts backing a union drive, or complaining with coworkers about pay at a past job, is the textbook risk. The NLRB is equally clear about the limit: “just individually griping about some aspect of work is not ‘concerted activity.’”
The federal laws above apply at different sizes (15 employees for Title VII, the ADA and GINA; 20 for the ADEA), and the NLRA excludes supervisors and agricultural laborers. State laws often reach smaller employers.
State social media privacy laws: where you can’t ask for passwords or access
NCSL’s list is the usual starting point, but it was last updated in 2022, so we checked each state’s own statute on 30 September 2026. New York’s law, added since, took effect in 2024. The count we confirmed today is 28 states: the 27 on NCSL’s list plus New York. Most also bar asking the person to log in while you watch, and several bar making them add you as a contact. The laws target access to private accounts, not looking at what anyone can see; several say so expressly, including Maine (26 M.R.S. 617), New Hampshire (RSA 275:74, VI) and West Virginia (21-5H-1(b)).
| State | Statute | Bars employers from |
|---|---|---|
| Arkansas | Ark. Code 11-2-124 | requiring or requesting a username and password, or a privacy-settings change |
| California | Labor Code 980 | requiring or requesting a username or password, access in your presence, or account content |
| Colorado | C.R.S. 8-2-127 | suggesting, requesting or requiring a username or password |
| Connecticut | Conn. Gen. Stat. 31-40x | requesting or requiring a username and password, or that the person log in in front of you |
| Delaware | 19 Del. C. 709A | requiring or requesting login details, access in your presence, contacts or settings changes |
| Hawaii | HRS 487G-3 (Act 39, 2021) | requiring, coercing or requesting login information, content, a settings change or access in your presence; “employee” includes applicants (487G-2) |
| Illinois | 820 ILCS 55/10 | requesting, requiring or coercing a username and password |
| Louisiana | La. R.S. 51:1953 | requesting or requiring a username or password |
| Maine | 26 M.R.S. 616 | requiring, coercing or requesting a password, access in your presence, or adding you as a contact |
| Maryland | Labor & Employment 3-712 | requesting or requiring a username or password |
| Michigan | MCL 37.273 | requesting access to, observation of, or login information for an account |
| Montana | Mont. Code 39-2-307 | requiring or requesting a username or password, access in your presence, or content |
| Nebraska | Neb. Rev. Stat. 48-3503 | requiring or requesting login details, logging in in front of you, or adding you as a contact |
| Nevada | NRS 613.135 | requiring, requesting, suggesting or causing disclosure of a username or password |
| New Hampshire | RSA 275:74 | requesting or requiring login information for any personal account |
| New Jersey | N.J.S.A. 34:6B-6 (P.L. 2013, c. 155) | requiring or requesting a username, password or any access |
| New Mexico | N.M. Stat. 50-4-34 | requesting or requiring an applicant’s password, or demanding access (applicants only) |
| New York | Labor Law 201-i | requesting, requiring or coercing login details, or access to a personal account in your presence |
| Oklahoma | 40 O.S. 173.2 | requiring a username and password, or a login in front of you that shows non-public content |
| Oregon | ORS 659A.330 | requiring or requesting login details, compelling access in your presence, or adding you as a contact |
| Rhode Island | R.I. Gen. Laws 28-56-2 | requiring, coercing or requesting a password, or access in your presence |
| Tennessee | Tenn. Code 50-1-1003 | requesting or requiring a password to a personal internet account |
| Utah | Utah Code 34-48-201 | requesting a username and password to a personal internet account |
| Vermont | 21 V.S.A. 495l | requiring, requesting or coercing login details, an unlocked device, access or content |
| Virginia | Va. Code 40.1-28.7:5 | requiring a username and password, or adding you as a contact |
| Washington | RCW 49.44.200 | requesting, requiring or coercing login information, access in your presence, or adding you as a contact |
| West Virginia | W. Va. Code 21-5H-1 | requesting, requiring or coercing a username and password, or access in your presence |
| Wisconsin | Wis. Stat. 995.55 | requesting or requiring access information or a look at the account, as a condition of employment |
Sources: each state’s statute as named, read 30 September 2026. Many of these laws include exceptions for workplace-misconduct investigations and for accounts the employer provides. Oklahoma and Virginia bar requiring access; most other states also bar requesting it.
Practical rule: in any state, don’t ask for a password, a friend request, a login in front of you or screenshots of private posts.
Doing it in-house vs hiring a screening company: when the FCRA applies
If your own staff look at public profiles, the FCRA does not apply. If you pay a screening company to do it, it usually does. FTC staff addressed this in 2011. After investigating Social Intelligence Corporation, which sold employers social media background reports, FTC staff wrote that it “is a consumer reporting agency because it assembles or evaluates consumer report information that is furnished to third parties that use such information as a factor in establishing a consumer’s eligibility for employment,” and that FCRA obligations “apply equally in the social networking context.”
So a vendor’s social media report comes with the same steps as any other consumer report under 15 U.S.C. 1681b(b):
- Disclosure: a clear written notice, “in a document that consists solely of the disclosure,” before you order it.
- Authorization: the applicant’s written permission.
- Pre-adverse action notice with a copy of the report and the summary of rights, then time to respond.
- Adverse action notice once you decide. The templates are on our adverse action notice page.
A vendor’s advantage is that it can strip out protected information before you see the report. Ask how, in writing.
A safe social media screening process
Build the process so a protected characteristic never reaches the person who decides.
- Firewall the reviewer. Someone outside the hiring decision, usually HR, does the search and passes on only findings that match the written criteria. The hiring manager never sees the profile.
- Write the criteria first, from the list in the first section, and apply them to the role.
- Same check for every final candidate in that job, at the same stage, ideally after a conditional offer.
- Public content only. No fake friend requests, no asking coworkers to look, no passwords.
- Confirm identity. Common names produce wrong profiles.
- Document the job-related reason for any rejection, with a dated screenshot, and nothing else.
The same discipline applies in the interview. Our guide to illegal interview questions covers what you can’t ask out loud, and the hiring compliance hub links the rest of the hiring rules.
Social media screening for frontline roles: caregivers, drivers, security
For most hourly roles social media screening adds risk and delay, and a warehouse or restaurant applicant who waits a week takes another offer. Where it can earn its place:
- Caregivers and home health aides, who work alone with vulnerable clients. Threats, abuse of others or posting patients’ photos or details are job-related. The licensed checks come first: see healthcare background checks.
- Drivers. The screens that predict risk are the MVR check, the PSP report and a pre-employment drug screen. A social media check rarely adds to them.
- Security officers, where many states license the role and posts showing violence or weapons misuse bear directly on the job. See security guard license requirements by state.
Frequently asked questions
What do employers look for on a candidate's social media?
Job-related conduct: threats or violence, harassment of others, illegal activity, leaked confidential information, and claims that contradict the application. They must ignore anything that reveals a protected characteristic, such as age, religion, pregnancy, disability, national origin or family medical history, and posts about pay or working conditions with coworkers, which federal labor law protects.
Is it legal to check a candidate's Facebook before hiring?
Looking at public posts is legal under federal law. The risk is using what you see: rejecting someone after seeing their religion, pregnancy or disability invites a discrimination claim. Keep the review to public content, have someone outside the decision do it, and use written, job-related criteria.
Can employers ask applicants for social media passwords?
In 28 states, no. Each has a statute barring employers from requiring, and in most cases requesting, login details or access to personal accounts. Even where no law applies, asking is a poor idea: you gain access to exactly the protected information you are trying not to see.
Can I reject an applicant because of their social media posts?
Yes, for a job-related reason applied consistently, such as threats, harassment or illegal activity. No, if the reason is a protected characteristic, union support or complaints about pay with coworkers. If a screening company supplied the posts, send the FCRA pre-adverse and adverse action notices first.
Does the FCRA apply to social media background checks?
It applies when a third party compiles the report. FTC staff concluded in 2011 that Social Intelligence Corporation, a social media screening company, was a consumer reporting agency. You then need a standalone disclosure, written authorization and both adverse action notices. Your own staff’s search is not covered.
Should HR or the hiring manager do the social media review?
HR, or someone else outside the decision. The reviewer passes on only findings that match written, job-related criteria, so the hiring manager never sees protected information. That separation is the strongest evidence you have that a protected characteristic played no part.
How far back should a social media check go?
No law sets a window for your own review, so pick one, write it down and apply it to everyone. Screening companies are bound by the FCRA’s reporting limits: most adverse items older than seven years may not be reported, except for jobs paying $75,000 or more (15 U.S.C. 1681c).
Do employers have to tell candidates they checked social media?
Not when your own staff look at public posts. If a screening company prepares the report, the FCRA requires a written disclosure and the candidate’s authorization before you order it, and notices before you act on it. Telling every candidate up front is good practice either way.
Screen fewer, better applicants
Boostpoint turns your open jobs into Facebook and Instagram ads and collects applicants through a one-minute mobile application, so your screening time goes to the candidates who fit. See pricing.
Book a DemoSources: EEOC, Prohibited Employment Policies/Practices; 29 CFR 1635.8 (eCFR); NLRB, Social media and Protected Concerted Activity pages; 29 U.S.C. 152(3) and 158(a)(3); 15 U.S.C. 1681b(b) and 1681c; FTC staff closing letter to Social Intelligence Corporation, May 9, 2011; NCSL, Privacy of Employee and Student Social Media Accounts (updated 2022); the state statutes named in the table; California Labor Code 96(k) and 1101. General information, not legal advice. Last verified 30 September 2026. Read at source 30 September 2026.