
Short answer: In general, yes—reviewing publicly available social media is broadly permitted. The legality turns on how it's done. Done compliantly, social media screening uses public content only, removes protected-class information before review, follows the standard background-check process, and leaves the decision with the employer. Done casually, it can create privacy and discrimination risk.
"Is it legal?" is the wrong yes/no question. Social media screening is broadly permitted if a few conditions are met, and risky if they aren't. This guide lays out the conditions in plain English, followed by expert answers from our legal webinar. For the full process, see our complete guide to social media background checks.
Reviewing content a person has chosen to make public is broadly permitted. What's restricted is demanding access to private accounts. Many states have laws restricting employers from requiring or requesting passwords or private-account access—here's what those laws actually say. A compliant process never asks for credentials and never accesses private accounts—it works from public content only.
Anti-discrimination laws—covering race, religion, age, disability, pregnancy, national origin, and more—apply to hiring decisions regardless of where the information comes from. Social media is unusually likely to expose protected-class information, which is the core legal risk of reviewing it casually.
The compliant answer is to remove that information before a decision-maker sees the file. Protected-class redaction means the review focuses on documented, job-relevant conduct, not on characteristics an employer can't lawfully consider.
When a third party conducts the screening for employment purposes, it generally falls within the standard background-check framework—meaning disclosure, written authorization, and a defined adverse action process if the employer acts on a finding. See our plain-English FCRA overview for employers.
Compliant providers return findings and categorizations—what was found in public content and how it's categorized—rather than a hire/no-hire recommendation. The employer makes the decision. That separation keeps the process defensible.
Social media screening drifts into risk when:
In other words, the risk isn't social media screening itself—it's unstructured social media screening.
The questions below come from our webinar on the legal landscape of social media screening, featuring an employment attorney. Answers are summarized and focus on U.S. law. Watch the full session on demand.
Avoiding negligent hiring claims. When negligent hiring claims arise, they can be explosive. The question becomes whether the employer could have avoided the harm if they'd done more due diligence during hiring. Social media background checks offer a way to reduce that risk because they provide insight that might help an employer head off future harm. More in our negligent hiring liability guide.
Avoiding workplace harassers. Harassers are often repeat offenders. Social media can provide insight into whether someone is engaging in commentary or conduct that suggests they might create harassment issues in the workplace.
Reviewing existing employees. Employers can run social media background checks on current employees to identify potential harassment or other issues, such as one employee harassing another via social media. See where this fits in an insider risk program.
There's no federal law prohibiting employers from running social media background checks. About 35 states have laws restricting employers from accessing private social media pages of applicants or employees. However, these laws don't prevent employers from accessing publicly available social media information.
Some states, like California and New York, prohibit discrimination based on political affiliation, such as participating in a peaceful protest. But behavior like violent protest or harassment is not protected, and Ferretly lets users tailor which behaviors they surface to avoid running afoul of state laws.
Yes, it can if done poorly. Title VII prohibits workplace discrimination, harassment, and retaliation. One risk of social media review is exposing information about protected characteristics, such as religion, medical conditions, or union affiliation. Employers are better off not seeing this information because it could lead to accusations of discrimination. The best approach is to work with a professional screening service that filters out protected information and focuses on relevant behaviors.
Those cases are starting to emerge. The Ninth Circuit considered a case involving an employee whose Instagram page promoted violent content, including specific threats toward a coworker. The court determined that the employer could be held liable for harassment even though the comments were made off-duty, concluding that employers must investigate social media content that bears on the terms and conditions of employment, even if it occurs outside the workplace.
The number one reason is consistency. A store manager in one city might review candidates' profiles very differently than a manager in another. Outsourcing applies the same rules across the organization. Under the Fair Credit Reporting Act (FCRA), using a screening provider also gives candidates a mechanism to dispute incorrect findings, and a good provider filters out information employers shouldn't see.
Yes, the FCRA applies when social media checks are conducted by a third party for employment purposes. It governs how background screening companies, known as consumer reporting agencies, and employers use and handle the information.
It depends on the employer's goals and risk tolerance. Some screen at the conditional offer stage, aligning with how criminal checks are typically handled. Others screen earlier. The best approach balances compliance, risk management, and organizational needs.
Generally, content accessible without a login is considered fair game, while content behind a password or shared privately is typically off-limits unless the individual consents. A recent Ninth Circuit case described public social media as content accessible without a login.
A screening provider shouldn't make judgments. It applies predefined classifications—such as hate speech, violence, or prejudice—and surfaces content that matches them. Employers then evaluate flagged content against their own values, culture, and policies.
The FCRA generally applies to employment, licensing, insurance, and credit purposes. Monitoring the reputation of a public figure who represents a brand could fall outside it. Many organizations still assume the FCRA applies to err on the side of caution.
The general consensus is yes. Federal advisory opinions have interpreted the employment purpose broadly enough to include volunteers, so it's safest to assume compliance is required.
Depending on context, yes. Screening can be part of an internal investigation into concerns about a coworker's conduct. If the issue involves litigation after the employee has left, the permissible purpose becomes less clear and counsel should be consulted.
Is social media screening legal? Broadly, yes—when it uses public content, keeps protected-class information out of the decision, follows the background-check process, and leaves the decision with the employer. The legality lives in the method. Book a demo to see how Ferretly builds those guardrails into the workflow.
This article is for general informational purposes only and is not legal advice. Laws vary by state and change over time. Consult qualified counsel for guidance specific to your situation.